Local area network data network protocol conversion encryption transmission device and method
By designing a LAN data network protocol conversion encryption transmission device that integrates multi-functions, the network intrusion risk and equipment integration problems of the UAV ground command and control station are solved, efficient and secure data transmission and rapid deployment are achieved, and system complexity and operation and maintenance costs are reduced.
Patent Information
- Application Number
- CN202510738848.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-07-15
AI Technical Summary
The UAV ground command and control station faces problems such as high risk of network intrusion, outstanding equipment integration and operation and maintenance problems, poor deployment efficiency and lack of interface standardization, resulting in high system complexity, high maintenance costs and difficult to deploy quickly.
Design a LAN data network protocol conversion encryption transmission device that integrates multi-functions, including protocol conversion units, switches and cryptographic machines. Through integrated design, network protocol conversion and data encryption are realized, the number of devices and interface complexity is reduced. Embedded platform processors and Linux operating systems are adopted, combined with NAT rules and firewall functions to ensure safe data transmission.
It realizes network interconnection and effective data encryption, reduces the number of equipment and footprint, reduces costs, facilitates maintenance and rapid deployment, improves equipment compatibility and system stability, and ensures the stable flight and normal mission execution of the drone.
Smart Images

Figure CN120321312A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of unmanned aerial vehicle network communication, and more specifically, relates to a local area network data network protocol conversion encryption transmission device and method. Background Art
[0002] The functions of early UAV ground command and control stations were relatively simple, mainly focusing on basic flight control of UAVs. With the development of technology, modern ground command and control stations have all-round functions such as flight monitoring, mission command and planning, mission control and image display, link monitoring and link management, and payload equipment monitoring. At the same time, by installing a variety of application software, the ground command and control station can generate remote control instructions, display telemetry and payload data in real time, store efficiently, and distribute accurately. In order to meet the rapid response requirements of different mission scenarios, the UAV ground command and control station has become more flexible in system deployment, and has achieved the adaptation of multiple modes of transportation such as land, air or sea transportation. It can quickly complete the transfer deployment according to the mission requirements, significantly improving the mobility and emergency response capabilities of the UAV system. The UAV ground command and control station not only needs to achieve efficient communication among the internal components, but also needs to interact with external systems such as line-of-sight ground stations, satellite ground stations, and intelligence processing stations. In terms of communication methods, optical fiber and network communication have become the main data transmission channels, providing a guarantee for high-speed and stable data transmission.
[0003] As the application scope of drones continues to expand, the security threats faced by drone ground command and control stations are also increasing. Illegal users may use the public network or open channels to invade the local area network of drone ground stations, thereby interfering with the normal transmission of telemetry and remote control data, seriously threatening the flight safety of drones. Therefore, when communicating with line-of-sight ground stations, satellite ground stations, and intelligence processing stations, achieving network interconnection and data encryption has become a key issue that needs to be solved urgently.
[0004] Traditional ground control stations do not have customizable protocol conversion units, and firewalls and encryption devices are mostly independent devices, lacking an integrated design. This decentralized equipment layout not only takes up a lot of space and increases the complexity of the system, but also the functions and interfaces of each individual device are complex, which brings great inconvenience to the daily maintenance of operators and cannot meet the ground station's demand for customized integrated equipment.
[0005] Due to the low integration of traditional ground command station equipment and the poor compatibility and coordination between various devices, the maintenance and management costs of the system remain high. In addition, when faced with sudden tasks, traditional ground command stations are difficult to deploy quickly and cannot meet the timeliness requirements of modern drone applications. Summary of the invention
[0006] The object of the present invention is to provide a device and method for converting and encrypting the transmission of local area network data network protocols, which solves the problems faced by current UAV ground command and control stations, such as high risk of network intrusion, prominent problems in equipment integration and operation and maintenance, poor deployment efficiency, and lack of interface standardization. A customized local area network data network protocol conversion and encryption transmission device integrating multiple functions, with unified interfaces, easy to maintain, and capable of rapid deployment is created to ensure effective data encryption while ensuring network interoperability, prevent external illegal intrusion, ensure the stable flight of the UAV and the normal execution of tasks, reduce the number of devices and floor area, and reduce costs.
[0007] To achieve the above object, in the first aspect, the present invention provides a device for converting and encrypting the transmission of local area network data network protocols, including: A protocol conversion unit for performing network protocol conversion on local area network data and external network data; A first switch, communicatively connected to the protocol conversion unit, for transmitting the local area network data to the protocol conversion unit and transmitting the external network data that has completed network protocol conversion to the corresponding address in the local area network; A cipher machine, communicatively connected to the protocol conversion unit, for receiving the local area network data that has completed network protocol conversion transmitted by the protocol conversion unit, encrypting it, and decrypting the external network data and transmitting it to the protocol conversion unit for network protocol conversion; A second switch, communicatively connected to the cipher machine, for transmitting the external network data to the cipher machine for decryption, receiving the encrypted local area network data transmitted by the cipher machine, and transmitting it to the corresponding address in the external network; A power supply module, electrically connected to the protocol conversion unit, the first switch, the cipher machine, and the second switch respectively, for supplying power to the protocol conversion unit, the first switch, the cipher machine, and the second switch.
[0008] Optionally, the protocol conversion unit adopts an embedded platform processor and has an embedded linux operating system built in; The protocol conversion unit further includes a first independent network card and a second independent network card; The protocol conversion unit communicates with the gigabit network port of the first switch through the gigabit network port of the first independent network card; The protocol conversion unit communicates with the gigabit network port of the cipher machine through the gigabit network port of the second independent network card.
[0009] Optionally, the performing network protocol conversion on local area network data and external network data includes: Perform protocol parsing, data repackaging, and redirection on local area network data and external network data.
[0010] Optionally, the protocol conversion unit performs address conversion on the decrypted external network data and local area network data based on the NAT rules using the netfilter framework.
[0011] Optionally, the NAT rules include: SNAT rules, which are used to convert the source IP address of the local area network data into an external network IP address; DNAT rules, which are used to convert the IP address of the decrypted external network data into the corresponding local area network IP address.
[0012] Optionally, the protocol conversion unit has a firewall function and realizes secure access between the local area network and the external network by configuring access control policies; If the access control policy is met, normal network access is carried out between the hosts of the local area network and the external network; If the access control policy is not met, network access between the hosts of the local area network and the external network is blocked.
[0013] Optionally, the packet filtering function is implemented using the FORWARD chain in the filter table of the netfilter framework / iptables user space tool, and the firewall function is realized by configuring filtering rules, thereby realizing the prohibition and enabling of external network data and local area network data.
[0014] Optionally, the cipher machine is used to encrypt and protect network data conforming to the TCP / UDP / IP protocol, decrypt network data conforming to the IP protocol, and configure the IP address of the security device; The cipher machine has functions of clear-text and cipher-text switching and status self-checking, as well as two-way authentication functions with the cipher management center; The cipher machine is provided with a configuration interface for configuring encryption rules.
[0015] Optionally, the protocol conversion unit realizes the switching of multicast destination ports and multicast data forwarding based on UDP proxy; Process different types of data through UDP proxy, and at the same time change the transmission destination port of the data according to the set rules to accurately forward the data from the local area network / external network to the external network / local area network; Among them, duplicate elimination processing is performed on video stream data, and duplicate elimination processing is not performed on telemetry data.
[0016] Second aspect, the present invention proposes a method for local area network data protocol conversion and encrypted transmission. Based on the local area network data network protocol conversion and encryption transmission device described in any one of the first aspect, the method includes: External network data is transmitted to the cipher machine through the second switch for decryption. After the decryption is completed, the external network data is transmitted to the protocol conversion unit for network protocol conversion. The external network data after the network protocol conversion is transmitted to the corresponding address of the local area network through the first switch; Local area network data is transmitted to the protocol conversion unit through the first switch for network protocol conversion. The local area network data after the network protocol conversion is transmitted to the cipher machine for encryption. The encrypted local area network data is transmitted to the corresponding address of the external network through the second switch.
[0017] The beneficial effects of the present invention are as follows: By integrating the protocol conversion unit, the first switch, the cipher machine, the second switch, and the power supply module into one body and conducting a reasonable communication connection design, the present invention reduces the complex interfaces and interaction methods between devices, forming a customized local area network data network protocol conversion and encryption transmission device that integrates multiple functions, has a unified interface, is easy to maintain, and can be quickly deployed. Compared with the traditional independent device layout, this integrated design reduces the physical connections and space occupation between devices, making the device more compact, reducing the number of devices and the floor area; reduces the number and types of devices, reduces the costs of device procurement, installation, and debugging, and is a customized local area network data network protocol conversion and encryption transmission device that is easy to maintain and can be quickly deployed, ensuring effective data encryption while ensuring network interconnection and preventing external illegal intrusion, guaranteeing the stable flight of the unmanned aerial vehicle and the normal execution of tasks. The protocol conversion unit realizes the network protocol conversion between local area network data and external network data. It can uniformly convert data of different protocols, enabling the smooth interaction of data between different networks. To a certain extent, this realizes the normalization and standardization of the interconnection interface, improves the compatibility and interoperability between devices, and facilitates the expansion and upgrade of the system; at the same time, due to the high integration of the device, the compatibility and coordination between each module are better, reducing the failures and maintenance costs caused by device incompatibility, thereby effectively reducing the overall operation and maintenance costs of the system.
[0018] The system of the present invention has other characteristics and advantages, which will be obvious from the accompanying drawings incorporated herein and the subsequent specific embodiments, or will be described in detail in the accompanying drawings incorporated herein and the subsequent specific embodiments. These accompanying drawings and specific embodiments are jointly used to explain the specific principles of the present invention. Description of the Drawings
[0019] The above and other objects, features, and advantages of the present invention will become more apparent by describing the exemplary embodiments of the present invention in more detail with reference to the accompanying drawings. In the exemplary embodiments of the present invention, the same reference numerals generally represent the same components.
[0020] Figure 1 FIG. shows a schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0021] Figure 2a FIG. shows a front panel schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0022] Figure 2b FIG. shows a top panel schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0023] Figure 2c FIG. shows a rear panel schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0024] Figure 3 FIG. shows an internal layout schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0025] Figure 4 FIG. shows a device hardware design topology diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0026] Figure 5 FIG. shows an internal and external communication software architecture schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0027] Figure 6 FIG. shows a multicast forwarding port switching processing flowchart of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0028] Figure 7 FIG. shows a firewall architecture schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention.
[0029] Figure 8 FIG. shows a software overall architecture schematic diagram of a local area network data network protocol conversion and encryption transmission device according to Embodiment 1 of the present invention. Detailed Embodiments
[0030] The present invention will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to make the present invention more thorough and complete, and to fully convey the scope of the present invention to those skilled in the art.
[0031] Embodiment 1
[0032] As Figure 1 shown, a local area network data network protocol conversion and encryption transmission device according to the present invention includes: A protocol conversion unit for performing network protocol conversion on local area network data and external network data; A first switch communicatively connected to the protocol conversion unit, the first switch for transmitting local area network data to the protocol conversion unit, and transmitting the external network data that has completed network protocol conversion to the corresponding address of the local area network; A cipher machine communicatively connected to the protocol conversion unit, the cipher machine for receiving the local area network data that has completed network protocol conversion transmitted by the protocol conversion unit, encrypting it, and decrypting the external network data and transmitting it to the protocol conversion unit for network protocol conversion; A second switch communicatively connected to the cipher machine, the second switch for transmitting external network data to the cipher machine for decryption, and receiving the encrypted local area network data transmitted by the cipher machine and transmitting it to the corresponding address of the external network; A power supply module electrically connected to the protocol conversion unit, the first switch, the cipher machine, and the second switch respectively, the power supply module for supplying power to the protocol conversion unit, the first switch, the cipher machine, and the second switch.
[0033] Specifically, the local area network data network protocol conversion and encryption transmission device of the present invention consists of a protocol conversion unit, a first switch, a cipher machine, a second switch, and a power supply module; in network communication, different networks may use different network protocols. The role of the protocol conversion unit is to achieve protocol conversion between local area network data and external network data. For example, a local area network may use a specific internal protocol to transmit data, while the external network uses another standard Internet protocol. When data in the local area network needs to be transmitted to the external network, the protocol conversion unit will convert its original local area network protocol into a protocol suitable for external network transmission; conversely, when data from the external network enters the local area network, it will convert the external network protocol into a protocol that the local area network can recognize and process; the first switch establishes a communication connection with the protocol conversion unit. In terms of local area network data transmission, the first switch is responsible for collecting data generated by each device in the local area network and accurately transmitting this data to the protocol conversion unit to prepare for subsequent protocol conversion work. After the protocol conversion unit completes the protocol conversion of external network data, the first switch will then accurately transmit this data to the corresponding address in the local area network according to the address information of the devices in the local area network to ensure that the data can reach the target device accurately; the cipher machine is communicatively connected to the protocol conversion unit. When the protocol conversion unit transmits the local area network data that has completed protocol conversion to the cipher machine, it will use an advanced encryption algorithm to encrypt it, converting the original plaintext data into ciphertext to increase the security of the data during transmission and prevent the data from being stolen or tampered with; for data received from the external network, the cipher machine first performs a decryption operation, restores the ciphertext to plaintext, and then transmits it to the protocol conversion unit for network protocol conversion so that the data can be correctly transmitted and processed in the local area network; the second switch communicates with the cipher machine, and its main function is to transmit external network data to the cipher machine for the cipher machine to decrypt it; after the cipher machine completes the encryption of the local area network data, the second switch receives this encrypted local area network data and transmits it to the corresponding address in the external network to achieve accurate transmission of the data in the external network; the power supply is electrically connected to the protocol conversion unit, the first switch, the cipher machine, and the second switch respectively to provide power support for these devices. Generally speaking, these devices work together. The protocol conversion unit is responsible for network protocol conversion, the first switch and the second switch are responsible for data transmission in different network areas, the cipher machine ensures the security of the data, and the power supply module provides power for all devices, jointly constituting a system that can achieve secure and efficient data interaction between the local area network and the external network.The present invention integrates a protocol conversion unit, a first switch, a cryptographic machine, a second switch, and a power supply module, and designs a reasonable communication connection, reducing the complex interfaces and interaction methods between devices, forming a customized local area network data network protocol conversion and encryption transmission device that integrates multiple functions, has a unified interface, is easy to maintain, and can be quickly deployed. Compared with the traditional independent device layout, this integrated design reduces the physical connections and space occupation between devices, making the device more compact, reducing the number of devices and floor area; reducing the number and types of devices, lowering the costs of device procurement, installation, and debugging, and being a customized local area network data network protocol conversion and encryption transmission device that is easy to maintain and can be quickly deployed, ensuring network interconnection and realizing effective data encryption while preventing external illegal intrusion, guaranteeing the stable flight of the unmanned aerial vehicle and the normal execution of tasks. The protocol conversion unit realizes the network protocol conversion between local area network data and external network data. It can uniformly convert data of different protocols, enabling the smooth interaction of data between different networks. To a certain extent, this realizes the normalization and standardization of the interconnection interface, improves the compatibility and interoperability between devices, and facilitates the expansion and upgrade of the system; at the same time, due to the high integration of the device, the compatibility and coordination between each module are better, reducing the failures and maintenance costs caused by device incompatibility, thus effectively reducing the overall operation and maintenance costs of the system.
[0034] In this embodiment, the protocol conversion unit adopts an embedded platform processor and has an embedded linux operating system built in; The protocol conversion unit further includes a first independent network card and a second independent network card; The protocol conversion unit communicates with the gigabit network port of the first switch through the gigabit network port of the first independent network card; The protocol conversion unit communicates with the gigabit network port of the cryptographic machine through the gigabit network port of the second independent network card.
[0035] Specifically, the protocol conversion unit adopts an embedded platform processor. The embedded platform processor is a processor specifically designed for specific applications. It has the characteristics of small size, low power consumption, and stable performance, and is very suitable for devices such as the protocol conversion unit that have certain requirements for space, energy consumption, and need to run stably. An embedded Linux operating system is built-in. The Linux operating system is an open-source, powerful, and flexible operating system. Using it in an embedded system can facilitate customization and development to meet the specific function requirements of the protocol conversion unit for network protocol processing, etc. And this unit includes 2 independent network cards, namely the first independent network card and the second independent network card. The independent network cards can work independently without interference, providing more channels and higher flexibility for data transmission. The protocol conversion unit communicates with the gigabit network port of the first switch through the gigabit network port of the first independent network card. The gigabit network port means that the data transmission rate can reach 1000 megabits per second. This is a high-speed data transmission interface. This connection method enables the protocol conversion unit to quickly interact with the first switch, quickly transmit local area network data to the protocol conversion unit for protocol conversion, and at the same time quickly transmit the external network data that has completed protocol conversion from the protocol conversion unit to the first switch, and then distribute it to the target address within the local area network. The protocol conversion unit communicates with the gigabit network port of the cipher machine through the gigabit network port of the second independent network card. Similarly, the gigabit network port ensures the high speed of data transmission. Through this connection, the protocol conversion unit can quickly transmit the local area network data that has completed network protocol conversion to the cipher machine for encryption, and can timely receive the external network data decrypted by the cipher machine for further network protocol conversion. The two independent network cards are respectively connected to different devices, making the data transmission path clearer and more independent, improving the data processing and transmission efficiency of the entire system, and enhancing the stability and reliability of the system.
[0036] In this embodiment, the network protocol conversion of the local area network data and the external network data includes: Performing protocol parsing, data repackaging, and redirection on the local area network data and the external network data.
[0037] Specifically, in network communication, different network protocols have specific formats and structures. Protocol parsing is to analyze the protocols followed by local area network data and external network data. Taking local area network data as an example, assume that a specific internal protocol is adopted in the local area network to transmit data. The protocol conversion unit needs to identify each part of the data, such as the header information (including identification information such as source address, destination address, data type, etc.), data content, and checksum information at the end. The same principle applies to external network data. For example, when receiving data based on the TCP / IP protocol from the Internet, the protocol conversion unit should be able to accurately parse the meanings of each field such as the IP header and TCP header. Through protocol parsing, the protocol conversion unit can understand the structure and content of the data under the original protocol and prepare for subsequent processing. After completing protocol parsing, since data interaction between the local area network and the external network needs to be achieved, the data needs to be repackaged according to the protocol format of the target network. For example, when local area network data needs to be transmitted to the external network, the protocol conversion unit will, according to the protocol used by the external network (such as the TCP / IP protocol), reassemble the previously parsed local area network data content into a data packet conforming to the TCP / IP protocol format, which includes adding new header information such as IP addresses (source IP address and destination IP address), port numbers, and other protocol-related fields that may be required. On the contrary, when external network data needs to enter the local area network, the data will be repackaged according to the protocol format used by the local area network, adding header, tail, and other information required by the local area network protocol. The process of data repackaging enables the data to be correctly transmitted and recognized in networks with different protocols. Redirection means that after the protocol conversion unit completes protocol parsing and repackaging of the data, it guides the data to the correct target address. When local area network data needs to be sent to the external network after protocol conversion, the protocol conversion unit will, according to the destination address information in the repackaged data packet, send the data through an appropriate network path to the corresponding device or server in the external network. Similarly, for external network data, after being converted into the local area network protocol format, the protocol conversion unit will, according to the address information within the local area network, accurately redirect the data to the target device within the local area network to ensure that the data can reach the correct receiving end. These three steps of protocol parsing, data repackaging, and redirection are the key links in realizing network protocol conversion between local area network data and external network data. They cooperate with each other to enable effective data communication between networks with different protocols.
[0038] In this embodiment, the protocol conversion unit performs address conversion on the decrypted external network data and local area network data based on the netfilter framework using NAT rules.
[0039] Specifically, netfilter is a powerful network packet processing framework in the Linux kernel. It provides a series of hook functions that allow users to insert custom processing logic at different stages of the kernel's handling of network packets. These hook functions are distributed at different positions during the inflow, outflow, and forwarding of packets, such as the INPUT hook when packets enter the system, the FORWARD hook when packets are forwarded, and the OUTPUT hook when packets leave the system. By using the netfilter framework, the protocol conversion unit can conveniently perform various operations on network packets, such as filtering, modification, and address conversion, providing basic support for implementing network protocol conversion.
[0040] In this embodiment, the NAT rules include: The SNAT rule, which is used to convert the source IP address of the local area network data to the external network IP address; The DNAT rule, which is used to convert the IP address of the decrypted external network data to the corresponding local area network IP address.
[0041] Specifically, in a local area network (LAN) environment, devices typically use private IP addresses for communication. However, when these LAN devices need to access the external network, the devices on the external network cannot directly recognize these private IP addresses. This is where the SNAT rule comes into play. When a device within the LAN sends a data packet to the external network, the protocol conversion unit, according to the SNAT rule, converts the source IP address in the data packet into a public IP address that can be recognized by the external network. In this way, the source IP address of the data packet received by the external network is the converted public IP address, enabling the external network to process the data packet normally. When the external network returns a response data packet, the protocol conversion unit will, based on the previously established mapping relationship, convert the destination IP address back to the private IP address of the device within the LAN to ensure that the response data packet can accurately reach the device that sent the request. The SNAT rule allows multiple devices within the LAN to share a limited number of public IP addresses to access the external network, saving public IP address resources and, to a certain extent, hiding the internal network structure of the LAN and the true IP addresses of the devices, thus enhancing network security. When the data from the external network enters the protocol conversion unit after being decrypted by the cryptographic machine, since the destination IP address of this data is the public IP address of the external network while the actual device to be accessed is within the LAN, address conversion is required. The protocol conversion unit, according to the DNAT rule, converts the destination IP address (public IP address) of the external network data into the corresponding private IP address of the device within the LAN. For example, when the external network sends a data packet with a destination IP address, the protocol conversion unit, through the DNAT rule, converts its destination IP address into the private IP address of a device within the LAN, enabling the data packet to be correctly transmitted within the LAN and reach the target device. The DNAT rule allows devices on the external network to access specific devices within the LAN, realizing the access of the external network to internal services within the LAN. For example, the access requests from the external network to the public IP address can be forwarded to web servers, FTP servers, etc. within the LAN, providing the ability for the servers within the LAN to offer external services. The SNAT rule and the DNAT rule are important components of the NAT technology. They respectively achieve address adaptation and communication interaction between the LAN and the external network from the perspectives of source IP address and destination IP address conversion, ensuring the normal operation of the network and the accurate transmission of data.
[0042] In this embodiment, the protocol conversion unit has a firewall function and realizes secure access between the LAN and the external network by configuring access control policies; If the access control policy is met, normal network access is carried out between the hosts of the LAN and the external network; If the access control policy is not met, network access between the hosts of the LAN and the external network is blocked.
[0043] Specifically, a firewall is a network security device located between a local area network (LAN) and an external network. Its main function is to monitor and control network traffic, protecting the internal network from unauthorized access and attacks from the external network. The protocol conversion unit integrates the firewall function, meaning it can not only perform network protocol conversion but also conduct security control over the network data passing through it, enhancing the security of the entire network system. An access control policy is a set of pre-set rules used to define which network traffic is allowed to pass through and which is prohibited. In the protocol conversion unit, an administrator can configure the access control policy according to actual security requirements and network usage. These policies can be formulated based on various factors. For example, it can be specified that only external network devices from certain specific IP address ranges are allowed to access the LAN, or certain devices within the LAN are restricted to accessing only specific external IP addresses. It can be stipulated which external network IP addresses the devices within the LAN can access, such as only allowing access to specific website server addresses and prohibiting access to other unauthorized websites. Different network services use different port numbers. By configuring the access control policy, the traffic of specific ports can be allowed or prohibited. It can be specified to allow or prohibit specific network protocols, such as only allowing TCP protocol traffic and prohibiting certain types of UDP protocol traffic because there may be some security risks in the UDP protocol compared to the TCP protocol. When the data transmitted between the LAN and the external network complies with the pre-configured access control policy, the protocol conversion unit will allow this data to pass through, enabling normal network access between the hosts of the LAN and the external network. If the data transmitted between the LAN and the external network does not conform to the access control policy, the protocol conversion unit will block the transmission of this data, thereby prohibiting network access between the hosts of the LAN and the external network. By having the firewall function and configuring the access control policy, the protocol conversion unit can effectively ensure secure access between the LAN and the external network, providing an important security protection mechanism for the network system while implementing network protocol conversion.
[0044] In this embodiment, the packet filtering function is implemented using the FORWARD chain in the filter table of the netfilter framework / iptables user space tool. The firewall function is achieved by configuring filtering rules, and then the prohibition and enabling of external network data and LAN data are realized.
[0045] Specifically, netfilter is a general packet filtering, processing, and address translation framework in the Linux kernel, and iptables is a user-space tool used in conjunction with the netfilter framework. It allows system administrators to configure and manage the rules in the netfilter framework through the command line. Through the iptables tool, administrators can easily add, delete, and modify various filtering rules, address translation rules, etc., so as to achieve the control and management of network traffic. In iptables, a table is a collection of rules, and different tables are used to implement different functions. The filter table is mainly used for packet filtering. It contains a series of rules that determine whether a packet is allowed to pass or be discarded. In addition to the filter table, there are also the nat table (used for address translation), the mangle table (used for modifying packet header information), etc.; a chain is a sequence of rules in a table. In the filter table, the FORWARD chain is used to process packets that need to be forwarded between different network interfaces. That is, when a packet enters the system from one network interface and needs to be forwarded out through another network interface (for example, from the external network into the local area network, or from the local area network to the external network), it will pass through the FORWARD chain of the filter table. Other chains such as the INPUT chain are used to process packets entering the local host, and the OUTPUT chain is used to process packets sent by the local host; by configuring the rules of the FORWARD chain in the filter table of iptables, the packets passing through this chain can be filtered. For example, rules can be set to allow or prohibit packets with specific source IP addresses, destination IP addresses, port numbers, protocol types, etc.; by configuring appropriate filtering rules, it is possible to prohibit or enable the entry of external network data into the local area network and the sending of local area network data to the external network. For example, if you want to prohibit a certain IP address segment in the external network from accessing all devices in the local area network, corresponding rules can be added; if you want to allow certain devices in the local area network to access specific external servers, it can also be achieved by configuring rules. In this way, according to the actual security requirements and network usage conditions, the flow of external network data and local area network data can be flexibly controlled to ensure the security and normal operation of the network.
[0046] In this embodiment, the cryptographic machine is used to encrypt and protect network data conforming to the TCP / UDP / IP protocol, decrypt network data conforming to the IP protocol, and configure the IP address of the security device; The cryptographic machine has the functions of clear-text and cipher-text switching, status self-checking, and two-way authentication with the cipher management center; The cryptographic machine is provided with a configuration interface for configuring encryption rules.
[0047] Specifically, the cipher machine can encrypt network data conforming to the TCP (Transmission Control Protocol), UDP (User Datagram Protocol), and IP (Internet Protocol) protocols. TCP and UDP are transport layer protocols that run on top of the IP protocol and are responsible for transmitting data between applications on different hosts. The IP protocol is responsible for addressing and routing data packets in the network. Encrypting the data carried by these protocols means converting the original plaintext data into ciphertext form, so that even if the data is intercepted during network transmission, attackers cannot directly read its content. The cipher machine can decrypt network data conforming to the IP protocol. When the data sent by the external network enters the local area network after encryption and these data are transmitted based on the IP protocol, the cipher machine can decrypt it and restore it to plaintext so that the devices within the local area network can correctly understand and process this data. The cipher machine allows the configuration of the IP addresses of security devices. The IP address is the unique identifier of a network device in the network. By configuring appropriate IP addresses, the cipher machine can communicate with other devices within the local area network (such as protocol conversion units, switches, etc.) and relevant devices in the external network. For example, configure the IP address of the cipher machine so that it can establish a connection with the protocol conversion unit to achieve encrypted and decrypted data transmission; or configure the IP address for communication with the cipher management center (password management center) to perform related operations such as key management. The cipher machine has a clear / ciphertext switching function, which means that it can switch between plaintext transmission and ciphertext transmission according to actual needs. In some cases, it may not be necessary to encrypt the data (such as transmitting some public and non-sensitive information), and at this time, the cipher machine can be set to the plaintext transmission mode; while when transmitting sensitive data, it is switched to the ciphertext transmission mode to encrypt and protect the data. This flexibility enables the cipher machine to adapt to different network application scenarios. The cipher machine can perform a status self-check to regularly or under specific circumstances check whether its own operating status is normal. For example, check whether the encryption and decryption algorithms are working properly, whether the keys are valid, and whether there are faults in the hardware devices. Through the status self-check, the cipher machine can promptly discover problems with itself and take corresponding measures, such as issuing an alarm or stopping working, to ensure its effective role in network security. Two-way authentication means that the cipher machine and the cipher management center mutually verify each other's identities. On the one hand, the cipher machine needs to verify the identity of the cipher management center to ensure that the key updates, configuration instructions, etc. it receives come from a legitimate cipher management center, preventing malicious attacks and illegal instructions. On the other hand, the cipher management center also needs to verify the identity of the cipher machine to ensure that the device communicating with it is a legitimate cipher machine, preventing fake devices from accessing the system. Through the two-way authentication function, the security and reliability of the communication between the cipher machine and the cipher management center are enhanced, ensuring the normal progress of important operations such as key management. The cipher machine is equipped with a configuration interface, which can be a physical interface (such as an Ethernet interface) or a software interface (through specific configuration tools).Through this configuration interface, the administrator can configure the encryption rules of the cipher machine. The encryption rules determine which data to encrypt, which encryption algorithm to use, the key update period, etc. For example, the administrator can set to encrypt the network data of a specific source IP address or destination IP address using a specific encryption algorithm, or configure rules such as automatically updating the key after a certain period of time to meet different security requirements and network environments. These functions of the cipher machine cooperate with each other to provide comprehensive protection for the secure transmission of network data and play a key security protection role in the communication between the local area network and the external network.
[0048] In this embodiment, the protocol conversion unit realizes the switching of the multicast destination port and the multicast data forwarding based on the UDP proxy; The UDP proxy processes different types of data and changes the transmission destination port of the data according to the set rules, so as to accurately forward the data from the local area network / external network to the external network / local area network; Among them, duplicate elimination processing is performed on the video stream data, and no duplicate elimination processing is performed on the telemetry data.
[0049] Specifically, UDP (User Datagram Protocol) is a connectionless transport protocol. It features fast transmission speed and low overhead. As an important part of the protocol conversion unit, the UDP proxy is responsible for handling the forwarding of multicast data and the switching of target ports. Multicast is a network transmission method that allows a data source to send data to multiple target addresses simultaneously and is commonly used for the transmission of real-time data such as video streams and audio streams. In the communication between a local area network and an external network, different application programs may use different ports for data transmission. The protocol conversion unit can change the target port of data transmission according to the set rules through the UDP proxy. For example, a certain multicast application program within the local area network sends data using port 1234, but the receiving end in the external network needs to receive this data on port 5678. The UDP proxy will switch the target port from 1234 to 5678 when forwarding the data to ensure that the data can be accurately received by the receiving end in the external network. The UDP proxy is responsible for forwarding the received multicast data from one network (local area network or external network) to another network (external network or local area network). It listens to specific multicast addresses and ports. After receiving the data, it forwards the data to the corresponding multicast addresses and ports of the target network according to the configured rules. Video stream data usually has a certain degree of redundancy and may cause packet duplication due to packet retransmission and network jitter during network transmission. The UDP proxy will perform duplicate elimination processing on the video stream data. By maintaining a list of packet records and checking the identification information (such as sequence numbers) of each received packet, if a duplicate packet is found, it will be discarded, and only one valid packet will be retained for forwarding. This can reduce the occupancy of network bandwidth and improve the efficiency and quality of video stream transmission. Telemetry data usually refers to data for real-time monitoring of device status, environmental parameters, etc. The timeliness and integrity of this data are very important. Each piece of telemetry data may represent the device status or environmental information at a specific moment. Even if there is some duplication in the data, it may have different timestamps or other key information. Therefore, the UDP proxy does not perform duplicate elimination processing on telemetry data to ensure that all received telemetry data can be forwarded to the target network for accurate data analysis and processing. By the UDP proxy performing targeted processing on different types of data and changing the target port of data transmission according to the set rules, the protocol conversion unit can accurately forward data from the local area network to the external network or from the external network to the local area network. This process ensures that application programs in different network environments can communicate normally, meeting the requirements of various business scenarios such as video surveillance and remote device telemetry. Based on the multicast target port switching and multicast data forwarding functions of the UDP proxy, combined with the differential processing of different types of data, the protocol conversion unit provides an efficient and accurate solution for data communication between the local area network and the external network.
[0050] The external shape of a local area network data network protocol conversion and encryption transmission device in this embodiment is as Figures 2a - 2c shown. The external shape of this device conforms to the 19-inch 1U rack-mounted structure, as Figure 2a shown. The front panel of this device is provided with a power switch 1, a power indicator 2, a key injection port 3, a cryptographic machine configuration port 4, a protocol conversion unit configuration port 5, a cryptographic machine key status indicator 6, a cryptographic machine self-check status indicator 7, a protocol conversion unit power indicator 8, a protocol conversion unit working status indicator 9, a reset button 10, and a clear key button 11; as Figure 2c shown. The rear panel of this device is provided with a grounding post 12, a power input terminal 13, a fuse 14, a cryptographic machine configuration port 15, a protocol conversion unit configuration port 25, a first switch network interface 16, and a second switch network interface 17; as Figure 2b shown. The top panel of this device is provided with a grounding working status indicator 18, a power working status indicator 19, a fuse working status indicator 20, a first switch network interface working status 21, a second switch network interface working status 22, a cryptographic machine configuration working status 23, and a protocol conversion unit configuration working status indicator 24.
[0051] The internal layout of a local area network data network protocol conversion and encryption transmission device in this embodiment is as Figure 3 shown; the device hardware design topology of a local area network data network protocol conversion and encryption transmission device in this embodiment is as Figure 4 shown; the power supply module of this device can realize AC / DC power conversion and filtering, and provide corresponding power for each internal module. The protocol conversion unit adopts an embedded platform processor and is built with an embedded linux operating system. The protocol conversion unit contains 2 independent network cards, which are respectively connected to the internal-facing switch and the external-facing switch. Through the built-in processing technology, it realizes the protocol parsing, data repackaging, and redirection of internal and external network data, so as to realize network protocol conversion. The protocol conversion unit also has a firewall function and realizes the secure access of the internal and external networks according to the configured control strategy. The cryptographic machine realizes the encryption and decryption functions of the transmitted data, encrypts and protects the information conforming to the TCP / UDP / IP protocol, contains 3 standard Ethernet interfaces, conforms to the IEEE802.3 standard, is adaptive to 100M / 1000M, adopts the international common AES+OFB standard, reserves a hardware interface, and can embed a private algorithm according to the provided format. The key distribution communication design KDMC distributes the key pool to each secure device, which is a one-to-many multicast communication form.
[0052] The internal and external communication software architecture of a local area network data network protocol conversion and encryption transmission device in this embodiment is as Figure 5As shown in the figure; the protocol conversion is implemented by using the NAT technology in the netfilter framework supported by the linux system kernel. The data protocol conversion from the internal network (local area network) to the external network uses the SNAT source address conversion technology to convert the source IP of the data packet accessing the external network from the internal network into the external network IP. The access from the external network to the internal network uses the DNAT destination address conversion technology to map the external network access IP and port to the internal network (local area network). The Linux kernel packet processing uses a mature framework NETFILTER, and the corresponding IPTATLES command of this framework can implement functions such as packet filtering firewall, packet redirection, and network address translation (NAT) on the Linux platform.
[0053] The multicast forwarding port switching processing flow of a local area network data network protocol conversion and encryption transmission device in this embodiment is as Figure 6 shown; The UDP proxy method is used to implement multicast target port switching and multicast data forwarding (converting video data and telemetry data). Duplicate elimination operations need to be performed on the video stream data, and no duplicate elimination processing is performed on the telemetry data. By parsing the corresponding relationship between the configured machine number and port, the UDP proxy program listens on the corresponding port. When receiving data sent from the corresponding machine number, it modifies the multicast destination port to the port after conversion of the corresponding machine number and forwards the data to the external network port.
[0054] The firewall architecture of a local area network data network protocol conversion and encryption transmission device in this embodiment is as Figure 7 shown. The protocol conversion unit serves as a gateway device connecting the internal and external networks, and controls the access traffic of the external network and the internal network by setting access control policies. The FORWARD chain in the filter table of netfilter / iptables is used to implement packet filtering, and the firewall function is implemented by configuring filtering rules, including configuring protocols (TCP, UDP, ICMP), source IP addresses and ports, destination addresses and ports, etc. to enable or disable data.
[0055] The overall software architecture of a local area network data network protocol conversion and encryption transmission device in this embodiment is as Figure 8 shown. The overall software architecture is configured and interacted in the B / S mode based on the linux system. The system mainly consists of modules such as video stream multicast data conversion, local area network access to the external network, external network access to the local area network, and firewall.
[0056] Embodiment 2
[0057] This embodiment provides a method for local area network data protocol conversion and encryption transmission. Based on the local area network data network protocol conversion and encryption transmission device described in Embodiment 1, the method includes: External network data is transmitted to the cipher machine through the second switch for decryption. After the decryption is completed, the external network data is transmitted to the protocol conversion unit for network protocol conversion. The external network data after the network protocol conversion is transmitted to the corresponding address of the local area network through the first switch; Local area network data is transmitted to the protocol conversion unit through the first switch for network protocol conversion. The local area network data after the network protocol conversion is transmitted to the cipher machine for encryption. The local area network data after the encryption is transmitted to the corresponding address of the external network through the second switch.
[0058] The embodiments of the present invention have been described above. The above description is exemplary and not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments.
Claims
1. A local area network data network protocol conversion and encrypted transmission device, characterized in that Including: A protocol conversion unit for performing network protocol conversion on local area network data and external network data; A first switch communicatively connected to the protocol conversion unit, the first switch being used to transmit the local area network data to the protocol conversion unit and transmit the external network data after completing network protocol conversion to the corresponding address of the local area network; A cipher machine communicatively connected to the protocol conversion unit, the cipher machine being used to receive the local area network data that has completed network protocol conversion transmitted by the protocol conversion unit, encrypt it, and transmit the decrypted external network data to the protocol conversion unit for network protocol conversion; A second switch communicatively connected to the cipher machine, the second switch being used to transmit the external network data to the cipher machine for decryption, receive the encrypted local area network data transmitted by the cipher machine, and transmit it to the corresponding address of the external network; A power supply module electrically connected to the protocol conversion unit, the first switch, the cipher machine, and the second switch respectively, the power supply module being used to provide power to the protocol conversion unit, the first switch, the cipher machine, and the second switch.
2. The local area network data network protocol conversion and encryption transmission device according to claim 1, wherein, The protocol conversion unit adopts an embedded platform processor and has an embedded linux operating system built in; The protocol conversion unit further includes a first independent network card and a second independent network card; The protocol conversion unit communicates with the gigabit network port of the first switch through the gigabit network port of the first independent network card; The protocol conversion unit communicates with the gigabit network port of the cipher machine through the gigabit network port of the second independent network card.
3. The local area network data network protocol conversion and encryption transmission device according to claim 1, characterized in that, The performing network protocol conversion on local area network data and external network data includes: Performing protocol parsing, data re - encapsulation, and redirection on local area network data and external network data.
4. The local area network data network protocol conversion encryption transmission device according to claim 1, wherein, The protocol conversion unit performs address conversion on the decrypted external network data and local area network data based on the NAT rules in the netfilter framework.
5. The local area network data network protocol conversion and encryption transmission device according to claim 4, characterized in that, The NAT rules include: The SNAT rule for converting the source IP address of the local area network data to the external network IP address; The DNAT rule for converting the IP address of the decrypted external network data to the corresponding local area network IP address.
6. The local area network data network protocol conversion and encryption transmission device according to claim 1, wherein The protocol conversion unit has a firewall function and realizes secure access between the local area network and the external network by configuring access control policies; If the access control policy is met, normal network access is carried out between the hosts of the local area network and the external network; If the access control policy is not met, network access between the hosts of the local area network and the external network is blocked.
7. The local area network data network protocol conversion and encryption transmission device according to claim 6, characterized in that, The packet filtering function is realized by using the FORWARD chain in the filter table of the netfilter framework / iptables user - space tool, and the firewall function is realized by configuring filtering rules, thereby realizing the prohibition and enabling of external network data and local area network data.
8. The local area network data network protocol conversion and encryption transmission device according to claim 1, characterized in that, The cipher machine is used to encrypt and protect network data conforming to the TCP / UDP / IP protocol, decrypt network data conforming to the IP protocol, and configure the IP address of the security device; The cipher machine has the functions of plaintext / ciphertext switching and status self-checking, as well as the two-way authentication function with the cipher management center; The cipher machine is provided with a configuration interface for configuring encryption rules.
9. The local area network data network protocol conversion and encryption transmission device according to claim 1, characterized in that, The protocol conversion unit realizes the switching of multicast destination ports and multicast data forwarding based on UDP proxy; Process different types of data through UDP proxy, and at the same time change the transmission destination port of the data according to the set rules, so as to accurately forward the data from the local area network / external network to the external network / local area network; Among them, duplicate elimination processing is performed on the video stream data, and no duplicate elimination processing is performed on the telemetry data.
10. A method for local area network data protocol conversion and encrypted transmission, characterized in that, Based on the local area network data network protocol conversion and encryption transmission device according to any one of claims 1-9, the method includes: The external network data is transmitted to the cipher machine through the second switch for decryption, and the decrypted external network data is transmitted to the protocol conversion unit for network protocol conversion. The external network data after network protocol conversion is transmitted to the corresponding address of the local area network through the first switch; The local area network data is transmitted to the protocol conversion unit through the first switch for network protocol conversion. The local area network data after network protocol conversion is transmitted to the cipher machine for encryption. The encrypted local area network data is transmitted to the corresponding address of the external network through the second switch.
Citation Information
Cited By
Multifunctional network protocol converter
CN121334269A