IP data packet transmission and processing method based on network layer
By implementing format conversion and secure processing of IP packets at the network layer, the speed, reliability and security issues in packet transmission and processing are solved, and efficient, simple and real-time packet processing is achieved.
Patent Information
- Application Number
- CN202510686067.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-05-27
AI Technical Summary
The prior art is difficult to effectively solve the problem of speed, reliability and security in packet transmission and processing, especially in IP packet processing at the network layer. The IPSec protocol is complex and inconvenient to use.
Provides an IP packet transmission and processing method based on the network layer, and realizes format conversion, secure algorithm processing and real-time transmission of data packets through the collaborative work of the network processing unit and the algorithm processing unit. The method includes configuring parameters, sending ARP requests, encapsulating custom packets, performing secure processing, and recording audits.
It realizes the rate and security improvement of packet transmission and processing, supports the reconfigurable configuration of algorithms and parameters, simplifies the packet processing process, and directly sinks to the IP layer for processing, avoiding complex transmission layer and upper-layer protocol processing.
Smart Images

Figure CN120223775A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of IP data packet transmission, and more specifically, to a method for transmitting and processing IP data packets based on the network layer. Background Art
[0002] The transmission and processing of data packets are basic elements that all information system devices such as network devices and communication devices must possess. Generally, high throughput and high reliability of data transmission and processing are required. During the transmission of network data packets, they may be illegally tampered with and replayed, resulting in the risk of illegal data intrusion, threatening the security of the entire system, and in severe cases, causing the system processing to crash and become paralyzed.
[0003] Currently, the research on data packet transmission and processing of network devices mainly focuses on the transport layer and the application layer. The IPSec protocol is for processing IP data packets, but it can only receive and process data packets that have also been processed by the IPSec protocol. Similarly, the data packets it sends out can only be received by devices with IPSec functions and cannot process standard IP data packets. Moreover, the IPSec protocol is complex and not very convenient to use.
[0004] Therefore, how to effectively solve problems such as the rate, reliability, and security of data packet transmission and processing is an urgent problem for those skilled in the art. Summary of the Invention
[0005] In view of the above problems, the present invention provides a method for transmitting and processing IP data packets based on the network layer to at least solve some of the technical problems mentioned in the above background art.
[0006] To achieve the above object, the present invention adopts the following technical solutions:
[0007] The present invention provides a method for transmitting and processing IP data packets based on the network layer, which is applied to an IP data packet transmission and processing system; the IP data packet transmission and processing system includes a network processing unit, an algorithm processing unit, and a main control unit; the method includes:
[0008] Configure the parameters of the algorithm processing unit and the network processing unit; after the configuration is completed, the network processing unit sends an ARP request data packet according to the configured IP address to obtain the MAC address of the target router or the target gateway;
[0009] The terminal encapsulates the first IP data packet and forwards the first IP data packet to the network processing unit through the target router or the target gateway;
[0010] After the network processing unit performs format conversion processing on the received first IP data packet, it sends the obtained custom data packet to the algorithm processing unit;
[0011] After the algorithm processing unit performs security algorithm processing on the received custom data packet, it sends the custom data packet and the corresponding security algorithm processing result to the main control unit;
[0012] After the main control unit checks and processes the custom data packet processed by the security algorithm, it sends the obtained second IP data packet to the server and records the corresponding security algorithm processing result in the database for auditing.
[0013] Furthermore, it also includes:
[0014] The server responds to the received data and sends the responded second IP data packet to the main control unit;
[0015] The main control unit performs recovery processing on the received second IP data packet and sends the recovered custom data packet to the algorithm processing unit;
[0016] After the algorithm processing unit performs security algorithm processing on the received custom data packet, it sends the processed custom data packet to the network processing unit;
[0017] The network processing unit performs format conversion processing on the received custom data packet, encapsulates it into a first IP data packet according to the MAC address of the target router or target gateway and the information in the custom packet header, and sends the first IP data packet to the terminal.
[0018] Furthermore, the algorithm processing unit includes an algorithm processing circuit, a parameter storage circuit, and a parameter management circuit.
[0019] Furthermore, parameter configuration for the algorithm processing unit specifically includes:
[0020] Insert the dedicated USB Key storing algorithm-related parameters into the USB interface on the front panel of the algorithm processing unit; the algorithm-related parameters include bitstreams and keys;
[0021] Decrypt the algorithm-related parameters through the parameter management circuit, use the bitstream to configure the algorithm processing circuit after decryption, then send other parameters to the algorithm processing circuit, and at the same time encrypt the sensitive parameters again with random numbers and store them in the parameter storage circuit.
[0022] Furthermore, parameter configuration for the network processing unit specifically includes:
[0023] Configure the MAC address of each network port through the RS232 serial port;
[0024] The main control unit configures each IP address of the network processing unit through the Web management interface.
[0025] Further, the network processing unit sends out an ARP request data packet according to the configured IP address to obtain the MAC address of the target router or target gateway, which specifically includes:
[0026] The network processing unit sends ARP requests to all devices within the local area network according to the configured IP address; the device responsible for this IP address will send an ARP reply packet after responding to the ARP request; the device responsible for this IP address is the target router or target gateway;
[0027] The network processing unit obtains the MAC address of the target router or target gateway according to the received ARP reply packet.
[0028] Further:
[0029] The Ethernet frame format between the network processing unit and the terminal includes: an Ethernet frame header, a first IP header, a first UDP header, a special identifier, an encapsulation header, a second IP header, a second UDP header or TCP header, a payload, and an encapsulation tail; the special identifier is used to indicate whether the data packet conforms to a preset data packet format; the terminal is connected to the network processing unit through a wide area network or an external network and is used to initiate various service requests and obtain data;
[0030] The data packet format between the algorithm processing unit and the network processing unit includes: a custom packet header, an encapsulation header, a second IP header, a second UDP header or TCP header, a payload, and an encapsulation tail;
[0031] The data packet format between the main control unit and the algorithm processing unit includes: a custom packet header, a second IP header, a second UDP header or TCP header, and a payload;
[0032] The Ethernet frame format between the main control unit and the server includes: an Ethernet frame header, a second IP header, a second UDP header or TCP header, and a payload; the server is used to process service requests and data from the terminal.
[0033] Further, the network processing unit processes the received first IP data packet, which specifically includes: removing the first IP header and the first UDP header from the first IP data packet.
[0034] Further, the main control unit performs recovery processing on the received second IP data packet, which specifically includes: the main control unit extracts the relevant information of the received second IP data packet, searches the hash table through the extracted relevant information, matches the first IP header, and then encapsulates it into a custom data packet.
[0035] Furthermore, the master control unit uses a CPU chip; the algorithm processing circuit and the network processing unit use FPGA chips; a PCIE interface is adopted between the CPU chip and the FPGA chips.
[0036] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a method for transmitting and processing IP data packets based on the network layer, and has the following beneficial effects:
[0037] The present invention supports reconfigurable processing algorithms and configurable parameters, and can effectively solve problems such as the rate and security of data packet transmission and processing.
[0038] The present invention adopts a data packet format with two layers of IP headers between the network processing unit and the remote end, ensuring that the processing of network data packets directly sinks to the IP layer for processing, without involving complex transport layer and upper layer protocols, making the processing of data packets simpler and more real-time.
[0039] In the present invention, a PCIE interface is adopted between the CPU and the FPGA. By optimizing the driver and PCIE DMA, the transmission bandwidth for IP data packets (with a size below 1500 bytes) can reach 10 Gbps.
[0040] The technical solutions of the present invention will be further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other accompanying drawings can be obtained according to the provided accompanying drawings without creative efforts.
[0042] Figure 1 It is a schematic diagram of the system framework for transmitting and processing IP data packets provided by an embodiment of the present invention.
[0043] Figure 2 It is a schematic diagram of the method flow for transmitting and processing IP data packets based on the network layer provided by an embodiment of the present invention.
[0044] Figure 3 It is a schematic diagram of the Ethernet frame format between the network processing unit and the remote interface provided by an embodiment of the present invention.
[0045] Figure 4 It is a schematic diagram of the data packet format between the algorithm processing unit and the network processing unit provided by an embodiment of the present invention.
[0046] Figure 5Schematic diagram of the data packet format between the main control unit and the algorithm processing unit provided by the embodiments of the present invention.
[0047] Figure 6 Schematic diagram of the Ethernet frame format between the main control unit and the proximal interface provided by the embodiments of the present invention.
[0048] Figure 7 Schematic diagram of the encapsulation header provided by the embodiments of the present invention.
[0049] Figure 8 Schematic diagram of the implementation framework of the main control unit provided by the embodiments of the present invention.
[0050] Figure 9 Schematic diagram of the implementation framework of the algorithm processing circuit provided by the embodiments of the present invention.
[0051] Figure 10 Schematic diagram of the implementation framework of the network processing unit provided by the embodiments of the present invention.
[0052] Figure 11 Schematic diagram of the implementation framework of the parameter storage circuit provided by the embodiments of the present invention.
[0053] Figure 12 Schematic diagram of the implementation framework of the parameter management circuit provided by the embodiments of the present invention. Detailed implementation manners
[0054] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0055] Embodiment 1:
[0056] The embodiments of the present invention disclose a method for transmitting and processing IP data packets based on the network layer, which is applied to an IP data packet transmission and processing system; see Figure 1 As shown, the IP data packet transmission and processing system includes a network processing unit, an algorithm processing unit, and a main control unit; among them, the algorithm processing unit includes an algorithm processing circuit, a parameter management circuit, and a parameter storage circuit, and the structural form adopts a 6U CPCIE architecture and a plug-in card form.
[0057] A method for transmitting and processing IP data packets based on the network layer provided by the embodiments of the present invention, see Figure 2 As shown, it includes a parameter configuration part and a working part; specifically:
[0058] 1. After the system is powered on, configure the parameters of the algorithm processing unit and the network processing unit; among them:
[0059] (1) Configure the parameters of the algorithm processing unit:
[0060] Insert the dedicated USB Key storing the algorithm-related parameters into the USB interface on the front panel of the algorithm processing unit; the algorithm-related parameters include bitstream and key, etc.;
[0061] Decrypt the algorithm-related parameters through the parameter management circuit, use the bitstream to configure the algorithm processing circuit after decryption, then send other parameters to the algorithm processing circuit, and at the same time encrypt the sensitive parameters again with random numbers and store them in the parameter storage circuit;
[0062] (2) Configure the parameters of the network processing unit:
[0063] Configure the MAC addresses of each network port through the RS232 serial port; the main control unit configures each IP address of the network processing unit through the Web management interface.
[0064] (3) After the configuration is completed, the network processing unit sends an ARP request packet outward according to the configured IP address to obtain the MAC address of the target router or target gateway; specifically: the network processing unit sends an ARP request to all devices in the local area network according to the configured IP address; the device responsible for this IP address will send an ARP reply packet after responding to the ARP request; the device responsible for this IP address is the target router or target gateway; the network processing unit obtains the MAC address of the target router or target gateway connected to the network processing unit according to the received ARP reply packet.
[0065] 2. Working part:
[0066] The terminal encapsulates the first IP packet and forwards the first IP packet to the network processing unit through the target router or target gateway; the network processing unit receives the first IP packet sent by the terminal through the 10Gbps Ethernet SFP, performs format conversion processing, and sends the processed custom packet to the algorithm processing unit through the high-speed GTH interface; after the algorithm processing unit performs security algorithm processing on the received custom packet, it sends the custom packet and the corresponding security algorithm processing result to the main control unit through the PCIE3.0x8 interface; after the main control unit checks and processes the custom packet after security algorithm processing, it sends the obtained second IP packet to the server through the 10Gbps Ethernet SFP, and records the corresponding security algorithm processing result in the database for auditing.
[0067] Similarly, perform reverse processing in the reverse direction; specifically, it includes: the server responds to the received data and sends the second IP data packet of the response to the main control unit; the main control unit performs recovery processing on the received second IP data packet and sends the custom data packet obtained after recovery to the algorithm processing unit; the algorithm processing unit performs security algorithm processing on the received custom data packet and then sends the processed custom data packet to the network processing unit; the network processing unit performs format conversion processing on the received custom data packet, encapsulates it into the first IP data packet according to the MAC address of the target router or target gateway and the information in the custom packet header, and sends the first IP data packet to the terminal.
[0068] Embodiment 2:
[0069] In order to implement the method for transmitting and processing IP data packets based on the network layer provided in the above Embodiment 1, a specific data packet format must be adopted. The specific data packet transmission format defined in this Embodiment 2 specifically includes:
[0070] 1. The Ethernet frame format between the network processing unit and the terminal is shown in Figure 3 and includes: an Ethernet frame header, a first IP header (i.e., IP1 header), a first UDP header (i.e., UDP1 header), a special identifier, an encapsulation header, a second IP header (i.e., IP2 header), a second UDP header (i.e., UDP2 header) or a TCP header (i.e., TCP2 header), a payload, and an encapsulation tail; wherein, the special identifier is used to indicate whether the data packet conforms to the preset data packet format; the terminal is connected to the network processing unit through a wide area network or an external network and is used to initiate various service requests and obtain data.
[0071] Among them, the source IP address of the IP1 header is the IP address of the sending end. This address will change when passing through the NAT traversal device, so the source IP address here cannot be used as the information for data packet inspection; the destination IP address of the IP2 header is the IP address of the receiving end. This address will not change after passing through the NAT device. Therefore, when the network processing unit detects and judges a legal data packet, it mainly detects the destination IP address; thus, in the embodiment of the present invention, a data packet format with two layers of IP headers is adopted. When the network processing unit detects and judges a legal data packet, it can rely on the destination IP address of the inner layer IP2 header; in other words, since the information in the IP2 header will not be affected and changed during transmission, it records the real information and is used for the network communication between the main control unit and the terminal later.
[0072] The IP1 data packet uses the UDP protocol because the UDP protocol is connectionless, and the checksum of the UDP data packet can also not be calculated and can be directly set to 0. After modifying some fields, only the checksum of the IP header needs to be recalculated and then it can be encapsulated into a new IP data packet and sent out, so as to achieve the purpose of fast processing and forwarding;
[0073] The port number in the UDP1 header is not detected here either because it may also change. However, all this information (source IP address, destination IP address, source port, and destination port) needs to be recorded and stored in the custom header so that the returned data packet can re-encapsulate the IP1 header and thus be transmitted to the algorithm processing unit;
[0074] In the embodiments of the present invention, a special identifier is also used to indicate whether the data packet conforms to the data packet format defined here. Since there are a large number of data packets on the network, and there are also many data packets whose destination IP address is a legal address, but most of them are not in this defined format. Therefore, through this special identifier, other data packets that are not in this format can be blocked.
[0075] 2. The data packet format between the algorithm processing unit and the network processing unit is shown in Figure 4 and includes: a custom header, an encapsulation header, a second IP header (i.e., IP2 header), a second UDP header (i.e., UDP2 header) or a TCP header (i.e., TCP2 header), a payload, and an encapsulation tail;
[0076] Among them, the custom header has a fixed size and mainly includes the packet size, the data payload size, the processing result, the source IP address, the destination IP address, the source port, the destination port, and the identifier. This custom header is designed to transfer key information between various units inside the device. The network processing unit needs to extract the key information of the network packet and fill it into the custom header, and at the same time, it needs to use the custom header to encapsulate a new IP data packet. The algorithm processing unit decides what key to use for what algorithm calculation and fills in the processing result information, etc., according to the custom header. The main control unit establishes an information mapping table and fills back the key information according to the custom header.
[0077] The data packet between the above-mentioned network processing unit and the algorithm processing unit and the remote end also contains an encapsulation header and an encapsulation tail. The information in the encapsulation header is mainly for the algorithm processing unit to use, and the algorithm processing result data is written into the encapsulation tail.
[0078] 3. The data packet format between the main control unit and the algorithm processing unit is shown in Figure 5 and includes: a custom header, a second IP header (i.e., IP2 header), a second UDP header (i.e., UDP2 header) or a TCP header (i.e., TCP2 header), and a payload.
[0079] 4. The Ethernet frame format between the main control unit and the server is shown in Figure 6 and includes: an Ethernet frame header, a second IP header (i.e., IP2 header), a second UDP header (i.e., UDP2 header) or a TCP header (i.e., TCP2 header), and a payload; among them, the server is used to process service requests and data from the terminal.
[0080] 5. The above encapsulation header is shown in Figure 7 as follows, including an 8-byte identifier, a 4-byte timestamp, a 1-byte algorithm type, a 1-byte key batch, and a 2-byte data length.
[0081] Based on the above specific data packet transmission format, the network processing unit in the first embodiment above processes the received first IP data packet, specifically including: removing the first IP header and the first UDP header in the first IP data packet.
[0082] Based on the above specific data packet transmission format, the main control unit in the first embodiment above performs a recovery process on the received second IP data packet, specifically including: the main control unit extracts the relevant information of the received second IP data packet, searches the hash table through the extracted relevant information, matches the first IP header, and then encapsulates it into a custom data packet.
[0083] Since the data packet transmission and processing system has powerful functions and complex logic, in the embodiments of the present invention, it is further divided into the following five functional parts:
[0084] (1) Main control unit: Adopting a CPU chip with an x86 architecture to implement functions such as configuring the network processing unit in a web manner, data packet auditing, PCIE data packet transceiver, and network packet transceiver;
[0085] (2) Algorithm processing circuit: Adopting an FPGA chip to implement encryption and decryption algorithms or integrity verification algorithms to ensure the confidentiality and integrity of data, and having the reconfigurability of algorithms and the reconfigurability of parameters;
[0086] (3) Network processing unit: Adopting an FPGA chip to implement the transceiver and processing of terminal IP data packets;
[0087] It can be seen that in the embodiments of the present invention, an architecture of two high-performance FPGAs, one high-performance CPU, and one embedded MCU is adopted and interconnected through a backplane; a PCIE interface is used between the above CPU and FPGA, and through optimizing the driver and PCIE DMA, the transmission bandwidth for IP data packets (with a size of less than 1500 bytes) can reach 10 Gbps;
[0088] (4) Parameter storage circuit: Adopting an SRAM (Static Random-Access Memory) chip to store key parameters, and when necessary, sensitive parameters can be destroyed by cutting off the connection with the battery;
[0089] (5) Parameter Management Circuit: An embedded MCU (Microcontroller Unit) chip is adopted, which communicates with the algorithm processing circuit through the SPI interface to complete the management and configuration of the key parameters required by the algorithm processing circuit.
[0090] Next, the implementation methods of the above five functional parts will be specifically described respectively.
[0091] 1. Implementation Mode of the Main Control Unit:
[0092] The function of the main control unit is to perform necessary parameter configuration on the network processing unit, implement the auditing of data packets, receive and send PCIE interface data packets, receive and send IP packets, and process data packets. The implementation block diagram of the main control unit is as Figure 8 shown.
[0093] The main control unit is implemented by a CPU with an x86 architecture. On the Ethernet side, the DPDK technology for high-performance network data packet processing is adopted, and zero-copy is achieved through the sharing of the memory for storing the packets captured by the network card and the PCIE data packets, so as to obtain high-performance transmission bandwidth; on the PCIE side, the data format adopts the AXI-Stream mode. Through a high-performance driver, the chained DMA method is adopted, with one page (Page) corresponding to one data packet. When the main control unit sends data to the PCIE interface, for however many packet data there are, the corresponding-sized DMA is started to transfer the data to the algorithm processing unit; when the main control unit receives data from the PCIE interface, the size of the fixed number of packets is set for each DMA. During this period, if the number of data packets is less than the set number, when the algorithm processing unit detects that the main control unit has a request for data but there is not enough data to send, invalid data will be sent at this time, with one data being one packet, so that this DMA can be quickly completed. This method avoids using the timeout interrupt method, reduces the waste in processing caused by introducing timeouts, and greatly improves the transmission bandwidth of PCIE DMA;
[0094] After the main control unit receives a data packet from the PCIE interface, it extracts the identifier and IP quadruple in the custom packet header and the IP quadruple in the payload to construct the second set of IP quadruples and identifiers, as well as the hash mapping table of the first set of IP quadruples; among them, the IP quadruple includes the source IP address, destination IP address, source port, and destination port; when the main control unit receives a data packet from the Ethernet interface, it looks up the hash table through the second set of IP quadruples to obtain the first set of IP quadruples and identifier information, and fills them into the custom packet header; the auditing module audits all data packets, mainly recording information such as IP addresses, identifiers, key batches, and processing results.
[0095] 2. Implementation Mode of the Algorithm Processing Circuit:
[0096] The function of the algorithm processing circuit is to perform cryptographic operations or HMAC operations on data packets according to the configured key and the identifier in the data packet, so as to protect network data packets from potential attacks and ensure the authenticity, integrity, and confidentiality of data reading and writing.
[0097] The design principle is to use a reconstruction method to configure the internal algorithm module of the FPGA. Through the configuration of the MCU, the root key is stored in the internal RAM of the FPGA, and other parameters are configured into the internal registers of the FPGA. When a data packet received from the GTH interface passes through a security check first, the legality of the data packet format and key fields is checked. If it is illegal, it is discarded or the data payload is removed, and the length field of the corresponding custom packet header and the processing result are modified. After passing the security check, it enters the algorithm processing module. The root key and the identifier are operated on to obtain an operation key, and the data is processed by the algorithm. If it is a cryptographic algorithm function, decryption is performed, and the decrypted data is CRC-checked and compared with the CRC value in the data packet. If they are consistent, the data packet is legal; if not, the data packet is illegal, the data payload is removed, and the length field of the corresponding custom packet header and the processing result are modified. If it is an HMAC algorithm function, HMAC authentication is performed, and the authentication result is compared with the authentication value in the data packet. If they are consistent, the data packet is legal; if not, the data packet is illegal, the data payload is removed, and the length field of the corresponding custom packet header and the processing result are modified. The processed data packet is sent to the main control unit through the PCIE interface. When receiving a data packet from the PCIE interface, the processing flow is the reverse of that for a data packet received from the GTH interface. However, during the security check, if it is found to be illegal, it is discarded. The implementation diagram of the algorithm processing circuit is as Figure 9 shown.
[0098] To prevent illegal replay attacks, the parameter configuration includes the configuration of time information. The timestamp is checked in the security check module. If the offset between the timestamp in the data packet and the local time is within the legal range, the timestamp of this data packet is considered legal; otherwise, it is considered an illegal timestamp data packet.
[0099] 3. Implementation method of the network processing unit:
[0100] The function of the network processing unit is to achieve the functions of simple data processing, fast and real-time transmission by adopting the IP data packet processing method, and it has the expandable characteristics of the network. The network processing unit mainly consists of an Ethernet data packet transceiver module, an Aurora data packet transceiver module, and a data packet processing module. After receiving the configuration packet from the main control unit or detecting the connection of the Ethernet interface, an ARP request packet is sent according to the configured local IP address and gateway IP address. After receiving the ARP response packet from the other end, the MAC address of the other end is stored; when an Ethernet frame is received from the Ethernet interface, first judge whether the destination MAC address is the local MAC address or the broadcast address. If it is the local MAC address, then process it later. If it is the broadcast address, it is also necessary to judge whether it is an ARP request packet. When an ARP request packet is received and the destination address is a legal address, an ARP response packet is constructed and sent to the other end. When an IP data packet is received, judge whether the destination IP address is legal. The data packet with an illegal IP address is discarded. Then judge whether the protocol number is UDP. The data packet with a protocol other than UDP is also discarded. Calculate the checksum of the IP header. If it is inconsistent with the checksum of the IP header in the data packet, the data packet is discarded. Then judge whether there is a special identifier. The data packet without a special identifier is discarded. Finally, remove the outer IP header and UDP header of the legal data packet, fill the relevant IP address and port into the corresponding fields of the custom header, and regard the subsequent data as the payload. After encapsulating it into a custom data packet, it is sent to the algorithm processing unit through the GTH; similarly, the reverse operation is performed in the opposite direction. The implementation block diagram is as Figure 10 shown.
[0101] 4. Implementation method of the parameter storage circuit:
[0102] The function of the parameter storage circuit is to store key sensitive data. When necessary, the stored parameters can be destroyed by pressing a button or pulling out a card. The parameter storage uses SRAM for storage. The SRAM is powered by a battery. The controller of the parameter storage is implemented in the FPGA of the algorithm processing circuit. Since it is necessary to store the algorithm bit rate of the FPGA and the algorithm bit stream is relatively large, dozens of megabytes, two 8MB SRAMs are required. The implementation method of the parameter storage circuit is as Figure 11 shown.
[0103] 5. Implementation method of the parameter management circuit:
[0104] The parameter management circuit is implemented by using an MCU chip to complete the management, storage, and configuration of various parameters. The implementation block diagram of the parameter management circuit is as Figure 12 shown.
[0105] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the various embodiments can be referred to each other. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0106] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for transmitting and processing IP data packets at the network layer, characterized in that, Applied to the IP data packet transmission and processing system; The IP data packet transmission and processing system includes a network processing unit, an algorithm processing unit, and a main control unit; The method includes: Configure the parameters of the algorithm processing unit and the network processing unit; After the configuration is completed, the network processing unit sends out an ARP request packet according to the configured IP address to obtain the MAC address of the target router or target gateway; The terminal encapsulates the first IP data packet and forwards the first IP data packet to the network processing unit through the target router or target gateway; After the network processing unit performs format conversion processing on the received first IP data packet, it sends the obtained custom data packet to the algorithm processing unit; After the algorithm processing unit performs security algorithm processing on the received custom data packet, it sends the custom data packet and the corresponding security algorithm processing result to the main control unit; After the main control unit performs inspection processing on the custom data packet after security algorithm processing, it sends the obtained second IP data packet to the server and records the corresponding security algorithm processing result in the database for auditing.
2. A method for transmitting and processing IP data packets based on the network layer according to claim 1, characterized in that, It also includes: The server responds to the received data and sends the responded second IP data packet to the main control unit; The main control unit performs recovery processing on the received second IP data packet and sends the recovered custom data packet to the algorithm processing unit; After the algorithm processing unit performs security algorithm processing on the received custom data packet, it sends the processed custom data packet to the network processing unit; After the network processing unit performs format conversion processing on the received custom data packet, it encapsulates it into the first IP data packet according to the MAC address of the target router or target gateway and the information in the custom packet header, and sends the first IP data packet to the terminal.
3. A method for transmitting and processing IP data packets based on the network layer according to claim 1, characterized in that, The algorithm processing unit includes an algorithm processing circuit, a parameter storage circuit, and a parameter management circuit.
4. A method for transmitting and processing IP data packets based on the network layer, as claimed in claim 3, wherein Configuring the parameters of the algorithm processing unit specifically includes: Insert the dedicated USB Key storing the algorithm-related parameters into the USB interface on the front panel of the algorithm processing unit; The algorithm-related parameters include bitstream and key; Decrypt the algorithm-related parameters through the parameter management circuit, use the bitstream to configure the algorithm processing circuit after decryption, then send other parameters to the algorithm processing circuit, and at the same time encrypt the sensitive parameters with random numbers again and store them in the parameter storage circuit.
5. A method for transmitting and processing IP data packets based on the network layer according to claim 1, characterized in that, Configuring the parameters of the network processing unit specifically includes: Configure the MAC address of each network interface through the RS232 serial port; The main control unit configures each IP address of the network processing unit through the Web management interface.
6. A method for transmitting and processing IP data packets based on the network layer, as claimed in claim 1, wherein The network processing unit sends out an ARP request packet according to the configured IP address to obtain the MAC address of the target router or target gateway, specifically including: The network processing unit sends ARP requests to all devices in the local area network according to the configured IP address; The device responsible for this IP address will send an ARP reply packet after responding to the ARP request; The device responsible for this IP address is the target router or target gateway; The network processing unit obtains the MAC address of the target router or target gateway according to the received ARP reply packet.
7. A method for transmitting and processing IP data packets based on the network layer according to claim 1, characterized in that: The Ethernet frame format between the network processing unit and the terminal includes: an Ethernet frame header, a first IP header, a first UDP header, a special identifier, an encapsulation header, a second IP header, a second UDP header or a TCP header, a payload, and an encapsulation tail; the special identifier is used to indicate whether the data packet conforms to a preset data packet format; the terminal is connected to the network processing unit through a wide area network or an external network and is used to initiate various service requests and obtain data; The data packet format between the algorithm processing unit and the network processing unit includes: a custom packet header, an encapsulation header, a second IP header, a second UDP header or a TCP header, a payload, and an encapsulation tail; The data packet format between the main control unit and the algorithm processing unit includes: a custom packet header, a second IP header, a second UDP header or a TCP header, and a payload; The Ethernet frame format between the main control unit and the server includes: an Ethernet frame header, a second IP header, a second UDP header or a TCP header, and a payload; the server is used to process service requests and data from the terminal.
8. A method for transmitting and processing network layer IP data packets according to claim 7, characterized in that, The network processing unit processes the received first IP data packet, specifically including: removing the first IP header and the first UDP header in the first IP data packet.
9. A method for transmitting and processing IP data packets based on the network layer, as claimed in claim 7, wherein The main control unit performs recovery processing on the received second IP data packet, specifically including: the main control unit extracts the relevant information of the received second IP data packet, searches for a hash table through the extracted relevant information, matches the first IP header, and then encapsulates it into a custom data packet.
10. A method for transmitting and processing IP data packets based on the network layer, as claimed in claim 3, wherein The main control unit uses a CPU chip; the algorithm processing circuit and the network processing unit use FPGA chips; a PCIE interface is used between the CPU chip and the FPGA chips.
Citation Information
Patent Citations
Communication link safety reinforcement method
CN110752921A
End-to-end transparent transmission encryption method and device
CN115118503A
Method for realizing neighbor discovery on network by link layer transparent encryption system
CN115277190A
Data security protection method based on link layer transparent encryption
CN119254454A
Network gateway apparatus
US20130195109A1