SDP gateway access authentication data transmission method based on multi-link aggregation

Through the multi-link aggregation of SDP gateway access authentication data transmission method, dynamically bind links and real-time monitoring, the problem of single point failure and insufficient security in traditional SDP architecture is solved, and the reliability and security of data transmission are improved.

CN120281589AActive Publication Date: 2025-07-08SGCC GENERAL AVIATION

Patent Information

Application Number
CN202510772946.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-07-08
Estimated Expiration
2045-06-11

AI Technical Summary

Technical Problem

Traditional SDP architecture relies on a single link for authentication and data transmission, poses a risk of single point of failure, cannot fully utilize multi-link bandwidth resources, and lacks cross-link security protection and intelligent scheduling strategies, resulting in low resource utilization and insufficient security.

Method used

The SDP gateway access authentication data transmission method based on multi-link aggregation is adopted, and the terminal identity is verified through the two-way authentication protocol and the link quality is evaluated. The main link and backup link are dynamically bound to the main link and the backup link are transmitted, and the link status is monitored in real time for switching. The dynamic token and redundant verification code are used for security protection.

Benefits of technology

Improves the reliability and security of data transmission, improves bandwidth utilization, reduces failover time, enhances resistance to link hijacking attacks, and realizes cross-link redundancy checks and millisecond-level failover.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281589A_ABST
    Figure CN120281589A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an SDP gateway access authentication data transmission method based on multi-link aggregation, which is characterized in that an SDP architecture and a multi-link aggregation technology are deeply fused, link quality evaluation and dynamic binding are completed in a bidirectional authentication stage, and data fragmentation encryption transmission is realized based on service requirements and security scores. According to the method, cross-link redundancy check and millisecond fault switching are supported, the problems of single-point fault, low bandwidth utilization rate and insufficient safety protection in a traditional scheme are solved, and the reliability, the safety and the efficiency of data transmission are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the technical fields of network security and data transmission, and particularly to a method for transmitting SDP gateway access authentication data based on multi-link aggregation. Background Art

[0002] With the complexity of the network environment, the traditional SDP architecture relies on a single link for authentication and data transmission, which has the risk of single point of failure and cannot fully utilize the bandwidth resources of multiple links. In the prior art, multi-link aggregation technologies mainly focus on bandwidth stacking, but lack deep integration with the SDP security framework, resulting in the fixed binding of the authentication process and the data transmission link, and it is difficult to dynamically adapt to network fluctuations or security threats.

[0003] In addition, the traditional solutions have certain defects in three aspects: link selection, load balancing, and cross-link security protection:

[0004] Separation of authentication and link: After authentication, the link is fixed and cannot be dynamically adjusted according to the real-time network status;

[0005] Insufficient security redundancy: In a multi-link scenario, no cross-link protection mechanism is designed for link hijacking or man-in-the-middle attacks;

[0006] Low resource utilization: Lack of intelligent scheduling strategies based on service types and link quality, resulting in conflicts between high-priority services and low-security links. Summary of the Invention

[0007] Therefore, the embodiments of the present invention provide a method for transmitting SDP gateway access authentication data based on multi-link aggregation to solve the technical problems in the prior art, such as the blurred network boundary, inability to cope with dynamic and distributed network environments, lack of fine-grained control, complex policy maintenance, and difficulty in adapting to multi-cloud environments.

[0008] To achieve the above object, the embodiments of the present invention provide the following technical solutions:

[0009] According to the first aspect of the embodiments of the present invention, a method for transmitting SDP gateway access authentication data based on multi-link aggregation is provided, and the method includes:

[0010] S1. Obtain user requirements, verify the identities of the terminal and the SDP gateway according to the mutual authentication protocol and the user requirements, and synchronously report the available link information and link quality scores of the terminal during the authentication process;

[0011] S2. The SDP controller dynamically binds the primary link and the backup link according to the link quality scores and service requirements, and generates a dynamic token bound to the link;

[0012] S3. The sender fragments the data according to the link bandwidth ratio. After data fragmentation, the data is encrypted and transmitted in parallel through multiple links. The sender dynamically adjusts the fragmentation ratio according to the real-time bandwidth of each link, and the receiver reconstructs the data based on the redundant check code;

[0013] S4. Monitor the link status in real time. When a link anomaly or security threat is detected, trigger the process of switching the link to the standby link, and update the dynamic token and encryption key;

[0014] Among them, the calculation method of the link quality score is to calculate the weight based on the delay, packet loss rate, historical security record, and encryption strength.

[0015] Furthermore, the two-way authentication protocol is the TLS1.3 protocol, and the terminal and the SDP gateway complete two-way identity verification through digital certificates.

[0016] Furthermore, the SDP controller dynamically binds the primary link and the standby link according to the link quality score and service requirements, and generates a dynamic token bound to the link, including:

[0017] The dynamic token contains a link identifier, an encryption key, and a validity period, and is used to verify the data transmission permission and the link legality.

[0018] Furthermore, the encrypted transmission after data fragmentation uses the IPSec protocol or the MACsec protocol, and each fragment is transmitted through an independent encrypted channel.

[0019] Furthermore, the receiver reconstructs the data based on the redundant check code, including:

[0020] The redundant check code uses forward error correction coding, and the receiver triggers a cross-link retransmission request when a fragment loss is detected.

[0021] Furthermore, the link anomaly includes that the link quality score is lower than the preset threshold, a DDoS attack is detected, or the packet loss rate exceeds the service tolerance threshold range.

[0022] Furthermore, the encryption key is dynamically rotated according to a preset time threshold or data transmission volume threshold, and the maximum rotation period is 24 hours.

[0023] Furthermore, the service requirements include real-time performance, bandwidth requirements, and data sensitivity, and high-security links are preferentially assigned sensitive data transmission tasks.

[0024] Furthermore, when the standby link is switched, the SDP controller synchronously updates the link identifier and encryption key of the dynamic token, and notifies the terminal to re-bind the link.

[0025] Further, the method further includes obtaining the current network topology and the binding policies of each link, and dynamically optimizing the network topology according to the current network topology and the binding policies.

[0026] The embodiments of the present invention have the following advantages:

[0027] In the embodiments of the present invention, by deeply integrating the SDP architecture with the multi-link aggregation technology, link quality assessment and dynamic binding are completed in the two-way authentication stage, and data fragmentation encryption transmission is realized based on service requirements and security scores. This method supports cross-link redundancy verification and millisecond-level fault switching, solves the problems of single-point failure, low bandwidth utilization, and insufficient security protection in traditional solutions, and significantly improves the reliability, security, and efficiency of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only exemplary, and for those of ordinary skill in the art, without creative efforts, other implementation drawings can be obtained based on the provided drawings.

[0029] The structures, proportions, sizes, etc. shown in this specification are only used to cooperate with the content disclosed in the specification for those who are familiar with this technology to understand and read, and are not used to limit the limited conditions under which the present invention can be implemented. Therefore, they do not have technical essence. Any modification of the structure, change of the proportional relationship, or adjustment of the size should still fall within the scope that can be covered by the technical content disclosed in the present invention without affecting the effects that the present invention can produce and the purposes that can be achieved.

[0030] Figure 1 It is a schematic diagram of the change of the network security boundary in the prior art;

[0031] Figure 2 It is a schematic flowchart of a method for SDP gateway access authentication data transmission based on multi-link aggregation provided by the embodiments of the present invention;

[0032] Figure 3 It is a schematic diagram of the construction of a method for SDP gateway access authentication data transmission based on multi-link aggregation provided by the embodiments of the present invention;

[0033] Figure 4 It is a schematic diagram of the architecture of a method for SDP gateway access authentication data transmission based on multi-link aggregation provided by the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] The following specific embodiments illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0035] Reference Figure 1 , with the emergence of new IT technologies such as cloud computing and BYOD (Bring Your Own Device), it has become increasingly difficult to define the network security boundary. The complex network access environment, the large number of network assets, and the ubiquitous security threats (such as DDOS, phishing attacks, APT, scanning, penetration, and credential stuffing) constantly threaten enterprise security. In recent years, with the rapid development and application of mobile Internet technologies, more and more enterprise employees tend to work remotely; users' network usage is highly dynamic. A user may have different roles simultaneously, and the application services and resources accessed between different roles may be different or overlapping. This new working mode has also caused changes in the new system boundary, making the boundary more complex and blurred. Traditional protection schemes based on fixed boundaries have gradually become ineffective, and a new security model is needed to address the security threats brought about by enterprises' migration to the cloud.

[0036] Traditional network security relies on a series of products such as FW, WAF, IDS, and IPS connected in series for security protection. Although it seems comprehensive, it is outperformed in actual use. It has high requirements for security operation and maintenance personnel. Even if various security products are deployed, it is still unable to effectively avoid potential threats such as APT and 0day vulnerabilities. Traditional security protection measures seem inadequate; in addition, the TCP / IP architecture has provided impetus for the rapid development of the Internet, but it has also become a weakness in Internet usage; the security issue of remote connections has been somewhat improved after the emergence of VPNs, but it has also led to the problem of difficult refined control; at the same time, the lack of a perfect access mechanism is also one of the core problems in establishing effective security protection in network usage.

[0037] In the TCP / IP network architecture, due to the overemphasis on its openness and convenience in the initial design stage, its security was not carefully considered; the characteristic of connecting first and then verifying inevitably exposes network assets and network facilities to the public network. Although its convenience has accelerated the development of the Internet, with the development of existing Internet technologies, its security problems have become more and more. Network assets and facilities exposed to the public network are very vulnerable to network attacks, resulting in problems such as service termination, data theft, and information leakage. The characteristic of connecting first and then verifying requires a better solution to address this weakness.

[0038] In the process of using the Internet, due to the limitations of the existing technical foundation and management mechanism, key network assets and facilities are inevitably exposed to the Internet environment without protection, including IP addresses, ports, etc.; and the exposed surface of Internet assets includes open websites, systems, applications, APP interfaces, etc. Network assets themselves may not necessarily have security problems, but being exposed to the Internet increases security risks. In the traditional network architecture, a firewall is used to build a wall to enclose the organizational network into an intranet. However, the firewall itself has become the weak link between the internal and external networks. With the development of business moving to the cloud, the network boundary becomes blurred, and the role of the firewall gradually becomes smaller. The application ports providing services are always exposed to the Internet due to the dynamic requirements of business use. When such network assets and facilities are exposed to the public network, they will directly face various security threats on the Internet, such as DDOS attacks, port scans, brute force cracking, etc.

[0039] To some extent, the traditional boundary-based network security architecture assumes or defaults that the intranet is secure, believing that security is to build a digital moat for the enterprise. It heavily protects the enterprise network export through boundary security products / solutions such as firewalls, WAFs, and IPSs while ignoring the security of the enterprise intranet. At the same time, the traditional security protection concept is to trust but verify, which results in the fact that the key security method of protecting the boundaries of terminals and networks cannot protect against identity- and credential-based threats, and account theft attacks become a perfect cover for data leakage. The core idea of zero trust is that by default, no one / device / system inside or outside the network should be trusted, and it is necessary to reconstruct the trust foundation of access control based on authentication and authorization. Zero trust subverts the paradigm of access control, guiding the security architecture from network-centric to identity-centric, and its essential requirement is to perform access control centered on identity.

[0040] SDP is the English abbreviation of Software Defined Perimeter, which is a brand-new network boundary concept. Defined by the CSA (Cloud Security Alliance), its core idea is that through the SDP architecture, core network assets and facilities can be hidden so that they are not exposed to the Internet and are greatly protected from various attack behaviors and security threats.

[0041] However, the traditional SDP architecture relies on a single link for authentication and data transmission, has a single point of failure risk, and cannot make full use of the bandwidth resources of multiple links. Multi-link aggregation technology mostly focuses on bandwidth aggregation, but lacks deep integration with the SDP security framework, resulting in the fixed binding of the authentication process and the data transmission link, and it is difficult to dynamically adapt to network fluctuations or security threats.

[0042] In addition, the traditional solutions have deficiencies in link selection, load balancing, and cross-link security protection. For example:

[0043] Authentication and link separation: After authentication is completed, the link is fixed and cannot be dynamically adjusted according to the real-time network status.

[0044] Insufficient security redundancy: In a multi-link scenario, no cross-link protection mechanism against link hijacking or man-in-the-middle attacks is designed.

[0045] Low resource utilization: Lack of intelligent scheduling strategies based on service type and link quality, resulting in conflicts between high-priority services and low-security links.

[0046] To solve the above technical problems that rely on a single link for authentication and data transmission, there is a risk of single-point failure, and the bandwidth resources of multiple links cannot be fully utilized. The authentication process is fixedly bound to the data transmission link, making it difficult to dynamically adapt to network fluctuations or security threats.

[0047] Reference Figure 2 , the present invention discloses a method for SDP gateway access authentication data transmission based on multi-link aggregation. By dynamically binding authentication and multi-link resources, it realizes the collaborative optimization of security authentication, link quality evaluation, data sharding transmission and dynamic protection, and solves the problems of single-point failure, low bandwidth utilization and insufficient security protection in traditional solutions. The method includes:

[0048] S1. Obtain user requirements, verify the identities of the terminal and the SDP gateway according to the mutual authentication protocol and the user requirements, and synchronously report the available link information and link quality score of the terminal during the authentication process;

[0049] S2. The SDP controller dynamically binds the primary link and the backup link according to the link quality score and service requirements, and generates a dynamic token bound to the link;

[0050] S3. The sending end shards the data according to the link bandwidth ratio, and after data sharding, performs encrypted transmission in parallel through multiple links. The sending end dynamically adjusts the sharding ratio according to the real-time bandwidth of each link, and the receiving end recombines the data based on the redundancy check code;

[0051] S4. Monitor the link status in real time. When a link anomaly or a security threat is detected, trigger the link switching process to adjust to the backup link, and update the dynamic token and the encryption key.

[0052] Among them, the calculation method of the link quality score is to perform weighted calculation based on delay, packet loss rate, historical security record and encryption strength.

[0053] Furthermore, the mutual authentication protocol is the TLS1.3 protocol, and the terminal and the SDP gateway complete mutual identity authentication through digital certificates.

[0054] Furthermore, the SDP controller dynamically binds the primary link and the backup link according to the link quality score and service requirements, and generates a dynamic token bound to the link, including: the dynamic token contains a link identifier, an encryption key, and a validity period, and is used to verify data transmission permissions and link legality.

[0055] Furthermore, the encrypted transmission after data fragmentation uses the IPSec protocol or the MACsec protocol, and each fragment is transmitted through an independent encrypted channel.

[0056] Furthermore, the receiving end reconstructs the data based on the redundancy check code, including: the redundancy check code uses forward error correction coding, and when the receiving end detects that a fragment is lost, it triggers a cross-link retransmission request.

[0057] Furthermore, the link anomaly includes that the link quality score is lower than a preset threshold, a DDoS attack is detected, or the packet loss rate exceeds the service tolerance threshold range.

[0058] Furthermore, the encryption key is dynamically rotated according to a preset time threshold or data transmission volume threshold, and the maximum value of the rotation period is 24 hours.

[0059] Furthermore, the service requirements include real-time performance, bandwidth requirements, and data sensitivity, and the high-security link is preferentially assigned sensitive data transmission tasks.

[0060] Furthermore, when the backup link is switched, the SDP controller synchronously updates the link identifier and encryption key of the dynamic token, and notifies the terminal to rebind the link.

[0061] Furthermore, the method further includes obtaining the current network topology structure and the binding policy of each link, and dynamically optimizing the network topology according to the current network topology structure and the binding policy.

[0062] The embodiments of the present invention have the following beneficial effects:

[0063] Performance improvement: Multi-link aggregation increases the effective bandwidth by 40%-60% and reduces the latency by 20%-30%.

[0064] Security enhancement: The dynamic token and key rotation mechanism can resist more than 99% of link hijacking attacks.

[0065] High reliability: The link failure switching time ≤ 50ms, and the packet integrity rate ≥ 99.9%.

[0066] Reference Figure 3 and Figure 4 , the architecture of the embodiments of the present invention includes:

[0067] SDP controller: Responsible for terminal identity authentication, policy distribution, and link security score calculation.

[0068] Multi-link Aggregation Gateway: Integrates a multi-link management module, a dynamic encryption module, and an anomaly detection module, and supports the aggregation of wired, wireless, and SD-WAN links.

[0069] Terminal Device: Deploys a lightweight SDP client and supports multi-link detection and dynamic token management.

[0070] Please refer to Figures 2 to 4 For reference, the process of the embodiments of the present invention includes:

[0071] Step 1: Two-way authentication with multi-link awareness

[0072] The terminal initiates an authentication request to the SDP gateway, and the gateway completes two-way certificate authentication with the terminal through the TLS 1.3 protocol.

[0073] During the authentication process, the terminal synchronously reports available link information (such as Wi-Fi, 5G, Ethernet), and the gateway generates a link quality score based on latency, packet loss rate, and historical security records.

[0074] Step 2: Dynamic link binding and token allocation

[0075] The SDP controller allocates a primary link and a backup link for the terminal according to the link score and service requirements (such as real-time performance, bandwidth requirements), and generates a dynamic token (Token) bound to the link.

[0076] The token contains a link identifier (Link ID), an encryption key, and a validity period, and is used for permission verification of subsequent data transmission.

[0077] Step 3: Fragmentation encryption and multi-link transmission

[0078] The sender fragments the data according to the link bandwidth ratio, and each fragment is transmitted through an independent encryption channel (IPSec or MACsec).

[0079] The receiver recombines the data packets based on a redundancy check code (such as FEC). If a fragment loss is detected, a cross-link retransmission request is triggered.

[0080] Step 4: Dynamic security protection and link switching

[0081] The link status is monitored in real time. If abnormal traffic (such as a DDoS attack) or link quality below the threshold is detected, the terminal immediately switches to the backup link and updates the token.

[0082] The encryption key is dynamically rotated according to time or data volume thresholds to avoid security risks caused by long-term use.

[0083] In the embodiments of the present invention, authentication and link binding are integrated. Link quality assessment and binding are completed during the SDP authentication phase, avoiding the defects of the separation of authentication and transmission in traditional solutions; Cross-link redundancy and security mechanism: Through sharding encryption, redundant verification, and dynamic tokens, seamless switching and data integrity protection under single-link failures or attacks are achieved; Service-driven intelligent scheduling: Based on service types (such as video, file transfer) and link security scores, traffic is dynamically allocated, and high-security links are preferentially used to transmit sensitive data.

[0084] For example, in the scenario of cross-regional data transmission in enterprises, system configuration is first performed: The SDP gateway is deployed at the enterprise headquarters, integrating dedicated lines, 5G, and SD-WAN links; Digital certificates are pre-installed on the terminals of branch offices to support multi-link access.

[0085] Then, authentication and link binding are carried out: After the terminal initiates authentication, the gateway detects its available links (5G latency is 30ms, dedicated line latency is 10ms), calculates the link scores (dedicated line security score is 90, 5G score is 70); A high-security dedicated line is allocated for video conferencing, and a 5G and SD-WAN aggregated link is allocated for file transfer.

[0086] Data transmission and protection are carried out: Video streams are transmitted through dedicated lines, and file shards are encrypted and transmitted in parallel via 5G and SD-WAN; When the packet loss rate of the dedicated line is detected to exceed 5%, the video traffic is automatically switched to the 5G link, and the token key is updated.

[0087] The SDP workflow is as follows:

[0088] (1) The SDP client goes online and sends a Single Packet Authentication (SPA) request to the SDP controller, Controller;

[0089] (2) After receiving the SPA authentication request from the Client, the SDP controller can forward the authentication to a third-party IAM for identity authentication and authorization;

[0090] (3) After the IAM passes the identity authentication, it will inform the Controller. Only users who pass the identity authentication will receive the SPA response message. Before the Single Packet Authentication (SPA) fails, the controller does not respond to any requests, realizing the hiding of the controller to prevent illegal user connections and attacks;

[0091] (4) After the Client passes the authentication, the Controller will inform the Client through an encrypted channel about the gateway, Gateway, and resources to be connected. At the same time, after performing SPA authentication with the gateway, it dynamically informs the admitted users and the information of the accessed resources;

[0092] After receiving the controller's response, the Client initiates a TLS tunnel connection request to the security gateway Gateway and sends another SPA authentication request.

[0093] When the security gateway Gateway receives the Client's TLS tunnel connection request, it verifies the client's identity and the information about the client sent by the controller. After successful verification, a secure TLS tunnel connection is established between the client and the security gateway.

[0094] Based on the control policy information, the security gateway Gateway controls the connection between the client and the backend resources.

[0095] SPA (Single-Packet Authorization) single-packet authentication is a lightweight authentication protocol that follows RFC4226. SPA is an important core component of SDP. SPA single-packet authentication is used for authentication between Client-Controller, Controller-Gateway, and Client-Gateway. The advantages of using single-packet authentication are as follows:

[0096] 1. Hide services and assets. By combining with the dynamic firewall function, non-authenticated users, hackers, or attackers cannot discover the controller's IP and service ports through port scanning, achieving service and asset invisibility. In contrast, traditional VPN servers will inevitably expose server IP and port information, unable to avoid malicious scanning and exposure to penetration and other attack risks.

[0097] 2. Zero-trust security protection. Only authenticated users will receive message responses, and no response will be made in case of authentication failure.

[0098] 3. Resist DDoS attacks. Through service and asset invisibility, DDoS attacks against the controller and gateway can be effectively resisted.

[0099] 4. SPA supports OTP one-time passwords and MFA multi-factor authentication to enhance authentication security.

[0100] Identity and Access Manager (IAM for short) can centrally integrate the account, authentication, access control, and auditing of resources such as application systems, databases, hosts, network devices, and security devices in an enterprise network environment. Through technical means such as account synchronization, strong authentication, authorization, access control, and single sign-on, it brings the users using resources and the accounts on various resources under unified management. IAM provides the enterprise with a unified perspective on account management, centrally manages all account-based management, authentication, authorization, and auditing, improves the security of account management, helps system administrators improve work efficiency, reduces management burdens, and at the same time improves the repetitive and cumbersome process of ordinary users' login authentication in different resources, providing higher security for daily work.

[0101] In the new network environment, applications and services are constantly iterated and updated, and the security boundary protection is no longer fixed. Only by accelerating the deployment and adjustment of policies at different levels (network, host, application, data) can we truly achieve boundary security defense and requirement review and detection.

[0102] The old protection architecture has the following problems:

[0103] Users have different needs: Different users, such as Internet users, internal employees, partners, and outsourced personnel, have different needs due to different roles. The diverse types of user roles lead to complex security defense strategies.

[0104] Application systems have different needs: For different types of systems such as core business systems, production systems, and external service systems, different levels of security defense mechanisms need to be formed to ensure the stable operation of the systems and protect the system data from being tampered with and stolen.

[0105] Data has different protection levels: For different types of data with different security and confidentiality levels, different levels of security defense strategies are also required to meet different protection requirements in terms of data integrity, availability, and confidentiality.

[0106] Dynamic firewall technology can solve the above problems. According to various differential requirements such as different users, different data, and different application systems, it can quickly establish security defense strategies and access control strategies through dynamic firewall technology, improving the security protection availability of the overall network environment.

[0107] To achieve secure data transmission among the client, control end, and server, real-time protection of data transmission is realized through secure transmission tunnel technology, creating a trusted and controllable channel between users and the server to escort information security.

[0108] For the construction of new large-scale networks, there are usually multiple branches distributed in various regions, and there are also resources in the cloud. Each branch needs to be securely and reliably connected to form a multi-region enterprise office intranet. The VPN-HUB technology effectively solves this type of requirement.

[0109] The application scenarios of the embodiments of the present invention are very diverse and are widely applicable to various application scenarios such as the Internet of Things (IOT), network security access, remote secure connection, secure APP, secure access, etc.:

[0110] Internet of Things security:

[0111] Block malicious controls such as APT, protect cloud security (stealth), and filter illegal protocols.

[0112] Application APP security:

[0113] Professional APPs can embed SDKs, dynamically access the secure network after authentication, and ensure data and network security.

[0114] Secure access to the office system:

[0115] SDP Client, PC, BYOD remote secure access, flexible permission control for users, ports, and IPs, and secure Internet access (anti-phishing, anti-virus).

[0116] API secure access:

[0117] Hide the real server IP, perform refined permission control, and prevent data leakage.

[0118] Application security access control (replacing VPN):

[0119] Traditional VPNs use network and IP as the center for permission control, that is, isolation is carried out through the IP network. Simple network policies can be maintained, but complex networks become difficult to maintain (firewalls have tens of thousands of policies), and even special policy management tools are required for verification. Policies are often omitted, resulting in serious vulnerabilities; once a VPN accesses the network, it is considered trusted, and the access scope is not precisely isolated, posing risks of penetration and viruses (such as WannaCry); unregulated access by internal network users poses security threats and causes uncontrollable hazards. With the deployment of public clouds, private clouds, and hybrid clouds and the requirement for elastic scaling capabilities, VPN access control cannot respond quickly, affecting application delivery.

[0120] The embodiments of the present invention replace VPNs and have the following advantages:

[0121] Security access control centered on user permissions, zero-trust security model, hiding core network assets, cost savings for BYOD devices, operation and behavior auditing, simple and convenient management mode, and excellent user experience.

[0122] Browser secure access: By embedding the embodiment of the present invention, any location and any device can securely access the Internet and corporate offices through a browser. The embodiment of the present invention can establish a trusted security authentication tunnel between the client and the server without worrying about network environment issues.

[0123] This application can provide professional client software across multiple platforms. The client software can implement mobile security management functions, implement multiple functional modules and components such as unified portal, operation and maintenance audit, cloud desktop, data leakage prevention, etc., realize unified management of enterprise mobile security EMM, and provide enterprise users with a better access experience under the premise of ensuring secure access.

[0124] In the field of Internet of Things and Internet of Vehicles, information related to the sensors of the Internet of Things and Internet of Vehicles will be transmitted to the cloud platform via the Internet. At the same time, the client performs remote access control through the APP. There is a risk of exposure of key assets in the cloud, and the security of the client APP cannot be fully guaranteed. Based on the SDP architecture, end-to-end security protection of the Internet of Things and Internet of Vehicles cloud-pipe-end can be achieved to ensure the overall security of the Internet of Things infrastructure and architecture.

[0125] The solution proposed in this application can help users achieve network asset invisibility while ensuring secure communication connections between devices of both parties on the Internet, and strictly control network access permissions, prohibiting services and ports outside the access permissions.

[0126] API data interface protection:

[0127] When implementing data interaction, many services or applications acquire data on the Internet through API interfaces. When the server is open to different business systems for access, various types of middleware have many vulnerabilities. Once the host where the middleware is located is infected, when the middleware calls the business system database, the data is threatened by malicious hijacking. The embodiment of the present invention effectively hides and controls access to backend assets, only opens corresponding access ports and dynamically controls access, closes all open ports after the data call is completed, and blocks other malicious file transmissions.

[0128] Remote security operation and maintenance:

[0129] In the operation and maintenance work, the network security strategy is based on the network as the center, allowing remote operation and maintenance personnel to enter the network. There are the following problems:

[0130] 1. Open security strategy centered on the network, with rough strategy causing threats to intranet devices;

[0131] 2. After the third-party operation and maintenance personnel enter the intranet through VPN, they cannot perform refined permission control;

[0132] 3. The remote desktop access port is open and unsafe and vulnerable to attacks;

[0133] 4. Internet exposure issues of some important system services.

[0134] By deploying the SDP system proposed in the embodiments of the present invention, dynamic access control based on identity and permissions is realized, ensuring the security of remote operation and maintenance access. At the same time, based on application-level access and secure encrypted tunnels, the security of remote access data is guaranteed.

[0135] SDP follows the zero-trust security architecture, realizes access control centered on users and permissions through architecture adjustment, circumvents the defects of the TCP / IP protocol, better realizes enterprise security protection, and realizes the following advantages and values:

[0136] 1) Asset hiding

[0137] Combined with functions such as dynamic firewalls and SPA single-pack authentication, the hiding of important services and assets is realized, reducing the attack exposure surface, and ensuring the security of the overall architecture through the method of authenticating first and then connecting;

[0138] 2) Resistance to network attacks

[0139] The default Drop firewall policy does not open any access IPs and ports for untrusted users or illegal users such as hackers. Hackers cannot attack invisible network assets and targets, and thus can prevent typical attack behaviors such as illegal port scanning, SQL injection, brute force cracking, DDOS attacks, and APT infiltration;

[0140] 3) Centered on user permissions

[0141] Traditional network access and control are network-centered. By default, the external network, that is, outside the firewall, is untrusted access, while the internal network, that is, inside the firewall, is trusted access. However, 70% of network attacks or data leaks are initiated by the internal network. The zero-trust architecture believes that even users accessing within the internal network should not access all network assets or services. Instead, it should be centered on user permissions. Whether inside or outside the internal network, identity and permissions should be verified first to achieve minimum-privilege access control for users;

[0142] 4) Enhancement of existing security solutions

[0143] SDP is an enhancement rather than a mutual exclusion of existing security solutions. SDP can be flexibly formed into an SDP architecture by deploying software-defined methods on the basis of traditional security devices, and then cooperate with traditional security devices to achieve the enhancement of enterprise network security;

[0144] 5) Simplify security operation and maintenance

[0145] SDP centrally manages the gateways and access policies across the entire network through a centralized controller, reducing the maintenance work of the original firewall ACL policies and greatly simplifying the daily work of security operation and maintenance personnel;

[0146] 6) Adapt to multi-cloud environment management

[0147] Enterprise applications are gradually migrating to the cloud, and the assets in the traditional DMZ area are gradually migrating to private or public clouds. When enterprise IT managers face the complex IT environments of multi-cloud and hybrid cloud, the traditional maintenance and management models are severely challenged. Different cloud providers have different security and operation and maintenance solutions. Enterprise IT personnel expect to manage multi-cloud environments through a consistent access experience. SDP can exactly meet the management needs of enterprise IT personnel. By deploying a software-defined perimeter, it can be quickly extended to each cloud, conveniently, quickly, and securely solving the problem of enterprise multi-cloud access;

[0148] 7) Meet the requirements of equal protection

[0149] With the implementation of the Network Security Law, the regulatory authorities have become more and more strict with the compliance requirements such as equal protection for enterprises. Enterprises need to spend a lot of manpower and material resources to purchase various expensive security protection devices to meet the equal protection compliance requirements. Through the SDP solution, the equal protection compliance requirements can be met from multiple dimensions, such as secure access control, operation and maintenance security auditing, and resistance to various network attacks, thus quickly meeting the compliance requirements at the lowest cost;

[0150] 8) Better user experience

[0151] SDP provides a better access experience for customers. It can achieve access across different platforms and terminals. At the same time, it can also be integrated with the enterprise's original APP and quickly opened through the SDK security suite, further enhancing security without changing the user's access habits.

[0152] Although the present invention has been described in detail above with general descriptions and specific embodiments, on the basis of the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.

Claims

1. A method for transmitting SDP gateway access authentication data based on multi-link aggregation, characterized in that, The method includes: S1. Obtain user requirements, verify the identities of the terminal and the SDP gateway according to the mutual authentication protocol and the user requirements, and synchronously report the available link information and link quality score of the terminal during the authentication process; S2. The SDP controller dynamically binds the primary link and the backup link according to the link quality score and service requirements, and generates a dynamic token bound to the link; S3. The sending end fragments the data according to the link bandwidth ratio, and after data fragmentation, encrypts and transmits it in parallel through multiple links. The sending end dynamically adjusts the fragmentation ratio according to the real-time bandwidth of each link, and the receiving end reconstructs the data based on the redundant check code; S4. Continuously monitor the link status. When a link anomaly or a security threat is detected, trigger the link switching process to switch to the backup link, and update the dynamic token and the encryption key; Among them, the calculation method of the link quality score is to calculate the weight based on delay, packet loss rate, historical security record, and encryption strength.

2. The method for transmitting authentication data of an SDP gateway access based on multi-link aggregation according to claim 1, wherein, The mutual authentication protocol is the TLS1.3 protocol, and the terminal and the SDP gateway complete mutual identity verification through digital certificates.

3. The SDP gateway access authentication data transmission method based on multi-link aggregation according to claim 1, wherein, The SDP controller dynamically binds the primary link and the backup link according to the link quality score and service requirements, and generates a dynamic token bound to the link, including: The dynamic token contains a link identifier, an encryption key, and a validity period, and is used to verify data transmission permissions and link legality.

4. The method for transmitting authentication data of SDP gateway access based on multi-link aggregation according to claim 1, wherein The encrypted transmission after data fragmentation uses the IPSec protocol or the MACsec protocol, and each fragment is transmitted through an independent encrypted channel.

5. A method for transmitting authentication data of an SDP gateway access based on multi-link aggregation according to claim 1, characterized in that, The receiving end reconstructs the data based on the redundant check code, including: The redundant check code uses forward error correction coding, and when the receiving end detects a lost fragment, it triggers a cross-link retransmission request.

6. The method for transmitting authentication data of an SDP gateway access based on multi-link aggregation according to claim 1, wherein The link anomaly includes that the link quality score is lower than a preset threshold, a DDoS attack is detected, or the packet loss rate exceeds the service tolerance threshold range.

7. The method for transmitting authentication data of an SDP gateway access based on multi-link aggregation according to claim 3, characterized in that The encryption key is dynamically rotated according to a preset time threshold or data transmission volume threshold, and the maximum rotation period is 24 hours.

8. A method for transmitting SDP gateway access authentication data based on multi-link aggregation according to claim 3, characterized in that The service requirements include real-time performance, bandwidth requirements, and data sensitivity, and high-security links are preferentially assigned sensitive data transmission tasks.

9. The method for transmitting authentication data of SDP gateway access based on multi-link aggregation according to claim 3, wherein When the backup link is switched, the SDP controller synchronously updates the link identifier and the encryption key of the dynamic token, and notifies the terminal to rebind the link.

10. A method for transmitting authentication data of an SDP gateway access based on multi-link aggregation according to claim 1, characterized in that, The method further includes obtaining the current network topology structure and the binding policies of each link, and dynamically optimizing the network topology according to the current network topology structure and the binding policies.

Citation Information

Patent Citations

  • Systems and methods for multilink wan connectivity for saas applications

    CN113169935A

  • Multi-link transmission method and device, computer readable storage medium and terminal equipment

    CN113993178A

  • MBB multipath local aggregation superposition transmission method and system

    CN119485497A

  • Network application access method and security protection system

    CN119966902A

  • Systems and methods for multilink wan connectivity for saas applications

    US20200106699A1

Cited By

  • Distributed photovoltaic data acquisition method and device based on adaptive encryption communication and multi-link redundancy

    CN120956456A