Industrial internet security access equipment group and automatic security access method thereof

By introducing secure access equipment groups and automatic secure access methods in the industrial Internet, security authentication and management of wireless public access terminals is achieved, and security vulnerabilities and insufficient boundary defense of wireless public access terminals are solved, ensuring the security and integrity of data transmission.

CN120302284APending Publication Date: 2025-07-11CHONGQING JINGXUN INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510270911.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the existing industrial Internet, wireless public network access terminals have not been securely certified, which poses serious security vulnerabilities and data leakage risks. In addition, traditional boundary defense strategies are insufficient, so they cannot effectively defend against horizontal attacks.

Method used

The industrial Internet secure access device group is adopted, including the main station secure access device BNG and the remote secure access device CPE, and the security authentication and IP address allocation are carried out through the AAA server and the DHCP server, and an end-to-end security alliance is established to realize the security authentication and management of wireless public network access terminals.

Benefits of technology

It improves the boundary defense performance of the industrial Internet, ensures that service terminals can be securely accessed through wireless virtual private networks, and solves the problems of security vulnerabilities and insufficient boundary defense in the existing technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120302284A_ABST
    Figure CN120302284A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial internet security access device group and an automatic security access method thereof. The device group comprises a remote security access device CPE deployed on the field side of a service terminal and a master station security access device BNG deployed in a security connection area of a service master station. A master station security access device BNG is deployed in a security connection area of a service master station, and a remote security access device CPE on a service terminal field side firstly encapsulates data and then forwards the data to the master station security access device BNG when a new service terminal initiates request data, so that the service terminal can access the data to the master station security access device BNG. After the data are analyzed and classified through a master station security access device BNG, the classified data are forwarded to a network service unit, and security authentication and IP address allocation are carried out on the wireless public network access terminal; the boundary defensive performance of the industrial internet is improved, it is ensured that the industrial internet service terminal is safely accessed through the wireless virtual private network, and the security vulnerability existing in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial Internet wireless virtual private network applications, and particularly relates to an industrial Internet secure access device group and an automatic secure access method thereof. Background Art

[0002] When industrial Internet services communicate via a wireless virtual private network, various types of service terminals need to access the industrial Internet to interact with a remote master station, and they need to rely on the access capabilities of "wireless public network access terminal devices". For example, in the power industrial Internet, there are dispatching automation service terminals, metering service terminals, marketing service terminals, new energy access service terminals, etc. Through a power communication terminal (if a 5G network is used, its communication terminal is a 5G remote secure access device CPE for transparent transmission of services, and the service data is transmitted to the remote service master station.

[0003] I. Security problems existing in the access of wireless public network access terminals to the industrial Internet at the present stage

[0004] Currently, in some industrial Internet application scenarios, wireless public network access terminals / communication terminals access their industrial Internet networks without security authentication. Specifically, it is manifested as follows: Buying a communication terminal in the market, such as a 5G industrial router, inserting the Internet of Things SIM card provided by the operator, and then connecting the communication terminal to the on-site environment of the industrial Internet, and the network can be accessed to complete information interaction. This network access method has serious security vulnerabilities. For example, industrial Internet on-site data can be forwarded to other master stations through data forwarding; data can also be backed up offline to the communication terminal and then exported, posing serious data security risks.

[0005] In addition, in some industrial Internet of Things (IIoT) application scenarios, when a communication terminal accesses an IIoT network, the legitimacy of its security authentication error is "equivalent to" that of a SIM card. The specific manifestations are as follows: For example, in the case of a 5G industrial router, when the main entity of the industrial Internet purchases a 5G remote secure access device CPE, it also purchases an IoT SIM card as a supporting item. The security of the IoT SIM card is guaranteed by the operator. When the 5G remote secure access device CPE accesses the industrial Internet network, the determination of its legitimacy is made by judging the legitimacy of the IoT card (informed by the operator to the main entity of the industrial Internet). This equivalent security is a misnomer and incorrect. The legitimacy of the IoT card does not mean the legitimacy of the 5G remote secure access device CPE. For example, in an actual on-site environment, another 5G remote secure access device CPE can be inserted into the original IoT SIM card, and communication can still be carried out legally, resulting in data leakage. In this scenario, some operators in certain provinces and cities can provide "SIM-card and device matching" verification services. Such verification can prevent the use of a single IoT SIM card to match different communication terminals, but there are still fundamental structural security access risks because the legitimacy of the communication terminal is equivalent to that of the IoT SIM card, and the legitimacy of the IoT SIM card is informed by the operator to the main entity of the industrial Internet, rather than the main entity of the industrial Internet independently controlling the access legitimacy of the communication terminal.

[0006] II. What is the Zero Trust Architecture (ZTA)?

[0007] As the industrial Internet of Things (IIoT) business becomes more decentralized, the network layout is becoming increasingly complex. This complexity has exceeded traditional network security policies based on perimeter defense because there is no single clearly distinguishable IIoT perimeter. As described in "Security Issues in the Current Stage of Wireless Public Network Access Terminals Accessing the Industrial Internet of Things", the deficiencies in network security control based on perimeter defense are listed. Once an attacker breaks through the perimeter, further lateral attacks will be unhindered. This complexity has led to the emergence of new network security concepts and models, namely "Zero Trust (ZT)". Typical zero trust mainly focuses on data protection but can (and should) be extended to include all IIoT assets (devices, infrastructure components, applications, virtualization, and cloud components) and entities (end-users, applications, and other non-human entities that request resource information). The zero trust security model assumes that there are already attackers on the network and that the enterprise's own network infrastructure (intranet) is no different from other networks (such as the public network), and no longer defaults that the intranet is trustworthy. In this new model, enterprises must continuously analyze and evaluate the risks that their internal assets and business functions may face, and then take measures to mitigate these risks. In a zero trust state, these protections typically involve minimizing authorized access to resources (such as data, computing resources, and applications), providing access only to those users and assets identified as needing access, and continuously verifying identities and permissions for each access request.

[0008] Therefore, in the face of the current problem of insufficient perimeter defense in the industrial Internet of Things, it is an urgent technical problem to be solved to develop an industrial Internet security access device group and its automatic security access method. Summary of the Invention

[0009] The object of the present invention is to provide an industrial Internet security access device group and its automatic security access method to solve the problem of insufficient perimeter defense in the existing industrial Internet of Things.

[0010] To solve the above technical problems, in the first aspect, the present invention provides an industrial Internet security access device group, including:

[0011] The master station security access device BNG is deployed in the secure connection area of the service master station; it is used to parse and classify the data uploaded by the remote security access device CPE, and forward the classified data to the network service unit, so that the network service unit performs security authentication and IP address allocation based on the classified data, and then issues corresponding instructions to the remote security access device CPE according to the data returned by the network service unit;

[0012] The remote secure access device CPE is deployed on the remote side of the business terminal site; it is used to encapsulate the data sent by the business terminal and upload it to the master station secure access device BNG, execute the instructions issued by the master station secure access device BNG, and then establish an end-to-end secure alliance with the communication gateway / firewall according to the service data sent by the business terminal and the security policy issued by the master station secure access device BNG, so that the service data is transmitted to the service master station through the established secure alliance.

[0013] Furthermore, the network service unit includes:

[0014] The AAA server is used to perform security authentication on the remote secure access device CPE and the business terminal according to the data uploaded by the remote secure access device CPE and the business terminal, and issue a security policy to the remote secure access device CPE after the remote secure access device CPE and the business terminal pass the security authentication;

[0015] The DHCP server is used to allocate IP addresses for the business terminals that have passed the security authentication according to the request data uploaded by the business terminals.

[0016] In a second aspect, the present invention provides a method for automatic secure access of the industrial Internet secure access device group provided in the first aspect above. The method includes:

[0017] Security authentication of the remote secure access device CPE: Perform security authentication on the remote secure access device CPE. If the authentication is successful, establish a communication connection between the secure access device remote secure access device CPE and the master station secure access device BNG, and send security policy data to the remote secure access device CPE through the master station secure access device BNG;

[0018] Authentication of the business terminal and IP address assignment: When the business terminal sends request data to the remote secure access device CPE, the remote secure access device CPE encapsulates the request data and forwards it to the master station secure access device BNG. The master station secure access device BNG parses the request data and forwards it to the network service unit, and performs legal authentication and IP address assignment on the business terminal according to the request data through the network service unit;

[0019] Establishing a communication connection: When the business terminal sends service data to the service master station, make the remote secure access device CPE establish an end-to-end secure alliance with the communication gateway / firewall according to the service type data and security policy data in the service data, and transmit the service data to the service master station through the secure alliance.

[0020] Furthermore, the network service unit includes an AAA server and a DHCP server; the remote security access device CPE encapsulates the request data and forwards it to the master security access device BNG; the master security access device BNG parses and classifies the request data to obtain service terminal authentication data and IP address request data, and then forwards the service terminal authentication data to the AAA server. The AAA server performs a security authentication on the legality of the service terminal according to the request data. If the AAA server authenticates that the service terminal is legal, the master security access device BNG forwards the IP address request data to the DHCP server, and forwards the IP address returned by the DHCP server to the remote security access device CPE through the master security access device BNG, so that the remote security access device CPE configures an IP address for the service terminal; otherwise, the remote security access device CPE stops receiving data from the service terminal.

[0021] Furthermore, the security authentication of the remote security access device CPE includes:

[0022] The master security access device BNG performs a security authentication on the legality of the remote security access device CPE according to the legality authentication request information of the remote security access device CPE. If the remote security access device CPE is authenticated as legal, the master security access device BNG sends security policy data to the remote security access device CPE.

[0023] Furthermore, the legality authentication request information of the remote security access device CPE includes:

[0024] The identifier of the remote security access device CPE, SIM card information, and the account password for establishing a communication protocol; when the master security access device BNG compares the received identifier and account password with the preset information entered by the master security access device BNG, if the identifier and account password match the preset information, a communication connection is allowed to be established between the remote security access device CPE and the master security access device BNG; otherwise, the operator is notified to deactivate the SIM card of the current remote security access device CPE.

[0025] Furthermore, the security authentication of the remote security access device CPE also includes:

[0026] Performing a security authentication on the legality of the SIM card of the remote security access device CPE. If the SIM card is authenticated as legal, the SIM card of the remote security access device CPE is allowed to access the network, and the remote security access device CPE sends the legality authentication request information of the remote security access device CPE to the master security access device BNG through the SIM card; otherwise, the SIM card of the remote security access device CPE is prohibited from accessing the network.

[0027] Furthermore, the legitimacy of the SIM card of the remote secure access device CPE is authenticated, specifically including:

[0028] The communication module of the remote secure access device CPE carries the SIM card information to the operator server; the operator server determines whether the SIM card is a legal industrial Internet asset based on the SIM card information. If so, the SIM card is authenticated as legal; otherwise, the SIM card is authenticated as illegal.

[0029] Furthermore, the remote security access device CPE is connected to the master station security access device BNG via the TR-069 protocol.

[0030] The beneficial effects of the present invention are as follows: by deploying the main station security access device BNG in the secure connection area of ​​the business main station, and the remote security access device CPE on the field side of the business terminal, whenever a new business terminal initiates a request for data, the remote security access device CPE first encapsulates the data and then forwards it to the main station security access device BNG, and then parses and classifies the data through the main station security access device BNG, and then forwards the classified data to the network service unit, performs security authentication and IP address allocation for the wireless public network access terminal; improves the boundary defense performance of the industrial Internet, ensures that the industrial Internet business terminals can access securely through the wireless virtual private network, and solves the security loopholes existing in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The same reference numerals are used in these drawings to represent the same or similar parts. The exemplary embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0032] Figure 1 It is a schematic diagram of the network architecture of the secure access zone of the present invention. DETAILED DESCRIPTION

[0033] In the first aspect, the present invention discloses an industrial Internet security access device group, including a master station security access device BNG4 deployed in a security connection zone of a business master station and a remote security access device CPE5 deployed at a remote end of a business terminal field side; the network architecture of the security access zone is as follows: Figure 1 shown.

[0034] The master station security access device BNG4 is deployed in the security connection area of the service master station; it is used to parse and classify the data uploaded by the remote security access device CPE5, and forward the classified data to the network service unit, enabling the network service unit to perform security authentication and IP address allocation based on the classified data, and then issue corresponding instructions to the remote security access device CPE5 according to the data returned by the network service unit. The master station security access device BNG4 classifies all the data flowing through it meticulously and accurately, and this process is based on multiple factors such as the data source, type, sensitivity, and business requirements. Once the data is correctly classified, the master station security access device will intelligently proxy and forward the data to the relevant network service units (such as AAA server 1, DHCP server 2, DNS server 3, etc.) for processing according to these classification information.

[0035] The remote security access device CPE5 is deployed remotely on the field side of the service terminal; it is used to encapsulate the data sent by the service terminal and upload it to the master station security access device BNG4, execute the instructions issued by the master station security access device BNG4, and then establish an end-to-end security alliance with the communication gateway / firewall 6 according to the service data sent by the service terminal and the security policy issued by the master station security access device BNG4, so that the service data is transmitted to the service master station through the established security alliance. The remote security access device CPE5 is responsible for executing a series of complex and refined security policies issued by the master station security access device, and these policies include but are not limited to key security measures such as strict user or device identity authentication processes, implementation of refined access control mechanisms, and high-level encryption protection for sensitive data transmitted by the service terminal. At the same time, it can also ensure the integrity and confidentiality of service data during transmission, achieve transparent transmission (i.e., pass-through) of service data, and thus efficiently complete data exchange and processing tasks on the premise of ensuring security.

[0036] According to an embodiment of the present application, the network service unit includes an AAA server 1 and a DHCP server 2; AAA respectively stands for Authentication, Authorization, and Accounting, and it is a server program that can handle user access requests, provide authentication, authorization, and account services. The main purpose is to manage user access to the network server and provide services to users with access rights. The AAA server 1 in this embodiment is used to perform security authentication on the remote security access device CPE5 and the service terminal according to the data uploaded by the remote security access device CPE5 and the service terminal, and issue a security policy to the remote security access device CPE5 after the remote security access device CPE5 and the service terminal pass the security authentication;

[0037] The DHCP server 2 is a network protocol for a local area network. It means that the server controls a range of IP addresses, and when a client logs in to the server, it can automatically obtain the IP address and subnet mask assigned by the server. The DHCP server 2 in this embodiment is used to assign IP addresses to service terminals that have passed security authentication according to the request data uploaded by the service terminals.

[0038] In some industrial Internet application scenarios, end-to-end communication is completed through domain names, and at this time, the resolution of IP and domain names is required. Since the DNS server 3 performs domain name resolution on demand, this network element is not a necessary component. When introducing the communication methods of 4 typical security access zone network architectures later, it is assumed that end-to-end communication uses IP addresses for communication, and the DNS server 3 is added on demand if domain name resolution is required.

[0039] Before the automatic secure access of the industrial Internet secure access device group disclosed in the foregoing first aspect, the industrial Internet operation and maintenance personnel distinguish and configure relevant secure access policies according to the enterprise's own business categories to prepare basic data for the subsequent automatic access of the industrial Internet secure access device group. Specifically, it includes:

[0040] The operation and maintenance personnel plan the address pool through the web end of the DHCP server 2 according to the enterprise's own business to prepare basic data for the IP address allocation of later business devices.

[0041] The operation and maintenance personnel configure security policies through the web end of the AAA server 1 according to the enterprise's own business for the authentication, authorization, and charging of later business access.

[0042] The operation and maintenance personnel, according to the purchased remote secure access device CPE5 of the enterprise, enter the relevant data of the remote secure access device CPE5 and plan the account password for its corresponding TR-069 protocol connection through the web end of the master station secure access device BNG4 to prepare data for the subsequent access of the remote secure access device CPE5. Then, configure the corresponding security policies according to the enterprise's own business type (for example: configure IPSec VPN for the metering business of electricity, using the channel resources of telecommunications; configure GRE VPN for the dispatching automation business, using the channel resources of mobile, etc.).

[0043] The operation and maintenance personnel configure the url address of the master station secure access device BNG4 and the account password for the subsequent establishment of a TR-069 protocol connection with the master station secure access device BNG4 for the remote secure access device CPE5.

[0044] After completing the above preparations, start the automatic secure access work of the industrial Internet secure access device group.

[0045] Therefore, the present invention also discloses an automatic secure access method for an industrial Internet secure access device group, including:

[0046] Remote security access device CPE5 security authentication: Perform security authentication on the remote security access device CPE5. If the authentication is successful, a communication connection is established between the remote security access device CPE5 and the master security access device BNG4, and security policy data is sent to the remote security access device CPE5 through the master security access device BNG4.

[0047] Service terminal authentication and IP address allocation: When the service terminal sends request data to the remote security access device CPE5, the remote security access device CPE5 encapsulates the request data and forwards it to the main site security access device BNG4. The main site security access device BNG4 parses the request data and forwards it to the network service unit. The network service unit authenticates the legitimacy of the service terminal and allocates an IP address based on the request data.

[0048] Establishing a communication connection: When the service terminal sends service data to the service main station, the remote security access device CPE5 establishes an end-to-end security association with the communication gateway / firewall 6 according to the service type data and security policy data in the service data, and transmits the service data to the service main station through the security association.

[0049] Whenever a new business terminal initiates a data request, the remote security access device CPE5 first encapsulates the data and then forwards it to the main site security access device BNG4. The data is then parsed and classified by the main site security access device BNG4, and then the classified data is forwarded to the network service unit to perform security authentication and IP address allocation on the wireless public network access terminal. This improves the boundary defense performance of the industrial Internet, ensures that the industrial Internet business terminals can securely access the wireless virtual private network, and solves the security vulnerabilities existing in the existing technology.

[0050] According to an embodiment of the present application, the network service unit includes an AAA server 1 and a DHCP server 2; the remote security access device CPE5 encapsulates the request data and forwards it to the master station security access device BNG4; the master station security access device BNG4 parses and classifies the request data to obtain service terminal authentication data and IP address request data, and then forwards the service terminal authentication data to the AAA server 1. By using the AAA server 1 to perform a security authentication on the legitimacy of the service terminal according to the request data, if the AAA server 1 authenticates that the service terminal is legitimate, the master station security access device BNG4 forwards the IP address request data to the DHCP server 2, and forwards the IP address returned by the DHCP server 2 to the remote security access device CPE5 through the master station security access device BNG4, so that the remote security access device CPE5 configures an IP address for the service terminal; otherwise, the remote security access device CPE5 is made to stop receiving data from the service terminal.

[0051] By encapsulating the request data of the service terminal and forwarding it to the master station security access device BNG4, and then parsing and classifying the request data through the master station security access device BNG4 to obtain service terminal authentication data and IP address request data, and then sending the service terminal authentication data and IP address request data to the corresponding servers, data leakage generated during the process of directly sending the request data of the service terminal to the corresponding servers through the remote security access device CPE5 can be avoided.

[0052] According to an embodiment of the present application, performing a security authentication on the remote security access device CPE5 includes: the master station security access device BNG4 performs a security authentication on the legitimacy of the remote security access device CPE5 according to the legitimacy authentication request information of the remote security access device CPE5. If the remote security access device CPE5 is authenticated as legitimate, the master station security access device BNG4 is made to send security policy data to the remote security access device CPE5. The master station security access device BNG4 issues the security policy to the legitimate remote security access device CPE5 so that when a subsequent service terminal accesses, the remote security access device CPE5 can independently determine what strategy to adopt to establish an end-to-end security alliance.

[0053] According to an embodiment of the present application, the legitimacy authentication request information of the remote security access device CPE5 includes: the identifier of the remote security access device CPE5, SIM card information, and the account password for establishing a communication protocol; when the master station security access device BNG4 compares the received identifier and account password with the preset information entered in the master station security access device BNG4, if the identifier and account password match the preset information, a communication connection between the remote security access device CPE5 and the master station security access device BNG4 is allowed; otherwise, the operator is notified to deactivate the SIM card of the current remote security access device CPE5.

[0054] According to an embodiment of the present application, for the security authentication of the remote security access device CPE5, it further includes: performing security authentication on the legality of the SIM card of the remote security access device CPE5. If the SIM card is authenticated as legal, the SIM card of the remote security access device CPE5 is allowed to access the network, and the remote security access device CPE5 sends a remote security access device CPE5 legality authentication request message to the master station security access device BNG4 through the SIM card; otherwise, the SIM card of the remote security access device CPE5 is prohibited from accessing the network. Only after the SIM card authentication is successful can the remote security access device CPE5 establish communication with the master station security access device BNG4, avoiding the threat to communication security posed by illegal SIM cards.

[0055] According to an embodiment of the present application, the security authentication of the legality of the SIM card of the remote security access device CPE5 specifically includes: the communication module of the remote security access device CPE5 carries the SIM card information to the operator server; the operator server determines whether the SIM card is a legal industrial Internet asset according to the SIM card information. If so, the SIM card is authenticated as legal; otherwise, the SIM card is authenticated as illegal.

[0056] According to an embodiment of the present application, the remote security access device CPE5 is connected to the master station security access device BNG4 through the TR-069 protocol. The full name of TR069 is the Remote Security Access Device CPE5 Wide Area Network Management Protocol (Remote Security Access Device CPE5 WAN Management Protocol), and its working principle is mainly based on the RPC (Remote Procedure Call) method of SOAP (Simple Object Access Protocol, Simple Object Access Protocol). The TR-069 protocol supports automated configuration management, which can greatly reduce the complexity and error rate of manual configuration; moreover, the TR-069 protocol provides a secure and reliable communication mechanism, which can ensure the security and integrity of configuration information during transmission; in addition, the TR-069 protocol has good flexibility and scalability, and can adapt to changes in different network environments and business requirements.

[0057] The following specifically shows the working process of the industrial Internet security access device group:

[0058] Step 1: The operation and maintenance personnel plan the address pool through the web interface of the DHCP server 2 according to the enterprise's own business (the address segment for the marketing department is "192.168.2.0 - 192.168.2.255", the address segment for the communication department is "192.168.3.0 - 192.168.3.100", and the address segment for metering automation is "192.168.4.0 - 192.168.4.255", etc.) to prepare the basic data for the IP address allocation of the subsequent business devices.

[0059] Step 2: The operation and maintenance personnel configure the authentication policy through the web interface of the AAA server 1 according to the enterprise's own business (marketing business: configure IPSec VPN, IKE version is "V1, V2", negotiation mode is "main mode", local interface is "10GE0 / 0 / 1", local address is "192.168.2.19", encryption algorithm is "SSF09", authentication algorithm is "VCS", integrity algorithm is "SHA1", PRF algorithm is "SHA1", DH group is "2", SA timeout is "86400", encapsulation mode is "tunnel mode", security protocol is "AH", ESP encryption algorithm is "GCM256", ESP authentication algorithm is "SHA2 - 512", operator is "China Mobile"; metering business: configure GRE VPN, local interface is "10GE0 / 0 / 2", local address is "192.168.4.2", keepalive period is 5 seconds, operator is "China Telecom") for the authentication, authorization, and charging of subsequent business access.

[0060] Step 3: The operation and maintenance personnel enter the relevant data of the remote security access device CPE5 and plan the account password for its corresponding TR - 069 connection through the web interface of the master station security access device BNG4 according to the remote security access device CPE5 purchased by the enterprise (such as:). Then, configure the corresponding security policy according to the enterprise's own business type (such as: configure IPSec VPN for the marketing business of electricity, using the channel resources of China Mobile; configure GRE VPN for the metering business, using the channel resources of China Telecom, etc.).

[0061] Step 4: The operation and maintenance personnel configure the url address "http: / / 10.2.3.8:18001 / tr069" of the master station security access device BNG4 and the account "yx remote security access device CPE5001" and password "yx remote security access device CPE5@2024001" for the subsequent establishment of a TR - 069 connection with the master station security access device BNG4 for the remote security access device CPE5.

[0062] After all the preparations are made, the industrial Internet security access device group will start its automated security access work; proceed to Step 5.

[0063] Step 5: After the remote security access device CPE5 is powered on, the 5G module carries the SIM card information to the operator's server for authentication.

[0064] Step 6: The operator's server determines whether the SIM is a legal industrial Internet asset based on the SIM card information. If the authentication is successful, the SIM is allowed to access the network; if the authentication fails, its network access is prohibited.

[0065] Step 7: Assuming the SIM is a legal industrial Internet enterprise asset, at this time, the remote security access device CPE 5 can communicate with the master station security access device BNG4 through the SIM card. The remote security access device CPE5 carries its own device information, SIM card information, and the account password for establishing TR-069 (such as: {"groupId":"11375576810287104","groupText":"Marketing Department","id":"15951819642544128","imei":"864765070002665","installPosition":"Building A, Zhongke Zhigu","sn":"864765070002665","vendorId":"15642705267281920","vendorName":"Chongqing Jingxun Information Technology Co., Ltd.","vpnChannelType":"3","simIP":"10.2..3.102","simOperator":"China Mobile","simStd":"5G","account":"yx Remote Security Access Device CPE5001","pwd":"yx Remote Security Access Device CPE5@2024001"}) and requests to establish a TR-069 connection with the master station security access device BNG4.

[0066] Step 8: The master station security access device BNG4 compares the device information, SIM card information of the remote security access device CPE5, and the account password for establishing TR-069 with the data of the remote security access device CPE5 and the account password data for establishing TR-069 entered in the master station security access device BNG4 in Step 3. If the master station security access device BNG4 contains the data of this remote security access device CPE5 and the account password matches, it is determined that the remote security access device CPE5 is a legal device, and it is allowed to establish a TR-069 connection with the master station security access device BNG4. If it cannot match the data of the remote security access device CPE5 entered in the master station security access device BNG4, it is determined as an illegal access device. The master station security access device BNG4 will inform the operator to deactivate the SIM of the current device through the API interface and at the same time refuse to establish a connection with it.

[0067] Step 9: Assume that the remote security access device CPE5 is a legal device and has established a TR-069 connection with the master station security access device BNG4. The master station security access device BNG4 sends down the security policies formulated in Step 3) to the remote security access device CPE5 (Marketing service: Configure IPSec VPN, IKE version is "V1, V2", negotiation mode is "main mode", local interface is "10GE0 / 0 / 1", local address is "192.168.2.19", encryption algorithm is "SSF09", authentication algorithm is "VCS", integrity algorithm is "SHA1", PRF algorithm is "SHA1", DH group is "2", SA timeout is "86400", encapsulation mode is "tunnel mode", security protocol is "AH", ESP encryption algorithm is "GCM256", ESP authentication algorithm is "SHA2-512", operator is "China Mobile"; Metering service: Configure GRE VPN, local interface is "10GE0 / 0 / 2", local address is "192.168.4.2", keepalive period is 5 seconds, operator is "China Telecom").

[0068] Step 10: When a new service terminal initiates a DHCP Discover request to the remote secure access device CPE5 to allocate an IP address, the remote secure access device CPE5 encapsulates the data of the service terminal and forwards it through the TR-069 connection to the master station secure access device BNG4. The master station secure access device BNG4 forwards the message of the service terminal to the AAA server 1 through the Radius protocol for authentication. If the AAA server 1 returns an authentication failure, the master station secure access device BNG4 forwards the result to the remote secure access device CPE5. The remote secure access device CPE5 records the service terminal data in the blacklist and starts to stop receiving data from this terminal. If the AAA server 1 returns an authentication success, the master station secure access device BNG4 requests an IP address allocation for the service terminal from the DHCP server 2 through the DHCP proxy. The master station secure access device BNG4 forwards the IP1 "192.168.2.13" returned by the DHCP server 2 to the remote secure access device CPE5, and the remote secure access device CPE5 automatically configures the corresponding interface IP to "192.168.2.13".

[0069] Step 11: When the service terminal sends service data to the service master station, the remote secure access device CPE5 obtains the service type by parsing the service message, establishes an end-to-end security association with the firewall according to the service type and the security policy issued by the master station secure access device BNG4, and transmits the service data to the service master station through the established security association.

[0070] Thus, the authentication and control of the communication terminal, as well as the secure access and data transmission of the service terminal, are completed through the remote secure access device CPE5 and the master station secure access device (master station secure access device BNG4).

[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. An industrial Internet security access device group, characterized in that, Including: The main station secure access device BNG, which is deployed in the secure connection area of the service main station; It is used to parse and classify the data uploaded by the remote secure access device CPE, and forward the classified data to the network service unit, so that the network service unit performs security authentication and IP address allocation according to the classified data, and then issues corresponding instructions to the remote secure access device CPE according to the data returned by the network service unit; The remote secure access device CPE, which is deployed at the remote end of the service terminal site side; it is used to encapsulate and upload the request data sent by the service terminal to the main station secure access device BNG, execute the instructions issued by the main station secure access device BNG, and then establish an end-to-end security alliance with the communication gateway / firewall according to the service data sent by the service terminal and the security policy issued by the main station secure access device BNG, so that the service data is transmitted to the service main station through the established security alliance.

2. The industrial Internet security access device group according to claim 1, wherein The network service unit includes: The AAA server, which is used to perform security authentication on the remote secure access device CPE and the service terminal according to the data uploaded by the remote secure access device CPE and the service terminal, and issue a security policy to the remote secure access device CPE after the remote secure access device CPE and the service terminal pass the security authentication; The DHCP server, which is used to allocate IP addresses for the service terminals that pass the security authentication according to the request data uploaded by the service terminals.

3. An automatic secure access method using the industrial Internet secure access device group according to any one of claims 1 or 2, characterized in that, The method includes: Security authentication of the remote secure access device CPE: Perform security authentication on the remote secure access device CPE. If the authentication is successful, establish a communication connection between the remote secure access device CPE of the secure access device and the main station secure access device BNG, and send security policy data to the remote secure access device CPE through the main station secure access device BNG; Service terminal authentication and IP address allocation: When the service terminal sends request data to the remote secure access device CPE, the remote secure access device CPE encapsulates and forwards the request data to the main station secure access device BNG. The main station secure access device BNG parses the request data and forwards it to the network service unit, and the network service unit performs legal authentication and IP address allocation on the service terminal according to the request data; Establish a communication connection: When the service terminal sends service data to the service main station, make the remote secure access device CPE establish an end-to-end security alliance with the communication gateway / firewall according to the service type data in the service data and the security policy data, and transmit the service data to the service main station through the security alliance.

4. The automatic secure access method according to claim 3, characterized in that, The network service unit includes an AAA server and a DHCP server; the remote security access device CPE encapsulates the request data and forwards it to the master station security access device BNG; the master station security access device BNG parses and classifies the request data to obtain service terminal authentication data and IP address request data, and then forwards the service terminal authentication data to the AAA server. By the AAA server, the legitimacy of the service terminal is securely authenticated according to the request data. If the AAA server authenticates that the service terminal is legitimate, the master station security access device BNG forwards the IP address request data to the DHCP server, and forwards the IP address returned by the DHCP server to the remote security access device CPE through the master station security access device BNG, so that the remote security access device CPE configures an IP address for the service terminal; otherwise, the remote security access device CPE is made to stop receiving data from this service terminal.

5. The automatic secure access method according to claim 3 or 4, characterized in that, Performing security authentication on the remote security access device CPE includes: The master station security access device BNG performs security authentication on the legitimacy of the remote security access device CPE according to the legitimacy authentication request information of the remote security access device CPE. If it is authenticated that the remote security access device CPE is legitimate, the master station security access device BNG is made to send security policy data to the remote security access device CPE.

6. The automatic secure access method according to claim 5, wherein The legitimacy authentication request information of the remote security access device CPE includes: The identifier of the remote security access device CPE, SIM card information, and the account password for establishing a communication protocol; when the master station security access device BNG compares the received identifier and account password with the preset information entered by the master station security access device BNG, if the identifier and account password match the preset information, a communication connection is allowed to be established between the remote security access device CPE and the master station security access device BNG; otherwise, the operator is notified to deactivate the SIM card of the current remote security access device CPE.

7. The automatic secure access method according to claim 5, characterized in that, Performing security authentication on the remote security access device CPE further includes: Performing security authentication on the legitimacy of the SIM card of the remote security access device CPE. If the SIM card is authenticated as legitimate, the SIM card of the remote security access device CPE is allowed to access the network, and the remote security access device CPE is made to send the legitimacy authentication request information of the remote security access device CPE to the master station security access device BNG through the SIM card; otherwise, the SIM card of the remote security access device CPE is prohibited from accessing the network.

8. The automatic security access method according to claim 7, wherein Performing security authentication on the legitimacy of the SIM card of the remote security access device CPE specifically includes: The communication module of the remote security access device CPE carries the SIM card information to the operator server; the operator server determines whether the SIM card is a legitimate industrial Internet asset according to the SIM card information. If so, the SIM card is authenticated as legitimate; otherwise, the SIM card is authenticated as illegitimate.

9. The automatic secure access method according to claim 3, wherein The remote security access device CPE and the master station security access device BNG are connected through the TR-069 protocol.

Citation Information

Cited By

  • Service data transmission method and device and processor readable storage medium

    CN121771697A