Password defines security architecture and rule execution method

By designing a multi-plane architecture and enforcing security rules through cryptographic protocols, the internal threats and lateral attacks inherent in VPN network security architecture are addressed, thereby achieving controllable, measurable, and observable business processes and improving system security.

CN120342588BActive Publication Date: 2026-01-02ZHENGZHOU XINDA YUNGU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510324125.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2026-01-02
Estimated Expiration
2045-03-19

AI Technical Summary

Technical Problem

In the existing network security architecture, VPNs cannot effectively defend against internal threats and lateral attacks. Implicit trust relationships increase the difficulty of security management, VPN devices become targets of attacks, and passwords are used improperly, thus failing to play a role in system security.

Method used

It adopts a multi-plane architecture design, including device plane, security plane, computing plane, network plane, data plane, rule plane and application plane. It executes security rules through cryptographic protocols, builds CDX cryptographic security service mesh and CDX trusted computing system, and achieves comprehensive system security.

Benefits of technology

It comprehensively covers the security requirements of business scenarios, enables controllable, measurable and observable business processes, prevents unauthorized external connections and lateral attacks, and improves the overall security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342588B_ABST
    Figure CN120342588B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network information security, and particularly relates to a password definition security architecture and a rule execution method, the architecture comprising a device plane, a security plane, a calculation plane, a network plane, a data plane, a rule plane and an application plane, each plane implementing execution of a security rule through a password protocol mode. The rule execution method of the password definition security architecture comprises, after initialization of an information system, planning a routing path, authenticating password definition security devices on the path, establishing a secure access channel between adjacent devices to guarantee routing security of data on the path, then encapsulating each packet of data based on business data identification to implement business slicing and protocol filtering based on an authorized credential, then performing secure forwarding according to a routing path specified by the authorized credential to prevent hidden channels and rule violations, and the security of an entire access request session depends on the security rule of the authorized credential. The present application can ensure security and compliance of business data in a flow process.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network information security, and particularly relates to a password definition security architecture and a rule execution method. BACKGROUND

[0002] As a mature network security architecture technology, boundary protection is a classic paradigm of network security. The classic network security solution first establishes a boundary protection facility with the boundary as the center to encrypt and protect the network communication inside and outside the boundary, that is, the commonly used "boundary + VPN" mode. This mode cannot resist threats occurring inside the boundary and horizontal attacks after single-point breakthrough; with the development of industrial internet and internet of things, network architecture continues to change, and the boundary becomes more and more blurred and undefined. At the same time, with the change of network scale, the boundary becomes more and more thick and complex, and it is a challenging work to implement network security policy and configure security policy. It is more difficult to eliminate security management loopholes, and the management cost is higher and higher.

[0003] Generally, a classic VPN is used for network communication protection, but its disadvantages become more and more obvious with the complex evolution of network architecture, and the prominent disadvantages are as follows:

[0004] (1) As a security product in the boundary protection era, VPN implicitly uses a specific assumed trust relationship, that is, it implicitly divides the network into a trust domain (intranet), a boundary domain, a non-trust domain (carrier network), and a conditional trust domain (i.e. remote users obtain the same trust as the intranet through VPN authentication). This implicit trust relationship is the basis for using VPN, which means that once remote users are authenticated, they can freely access resources in the enterprise network, which opens a gap for "horizontal attacks";

[0005] (2) Implicit trust is a high-risk trust relationship. One of the typical manifestations is that the risk of "illegal cross-border access" by internal users is high, which increases the difficulty of security management; the second typical manifestation is the risk of "illegal access" by unsafe external users, which is usually a typical attack mode against VPN; the third typical risk is that the granularity and accuracy of access control cannot be improved, and the authorization of access users is either too fine, which affects business and reduces user experience, or too large, which causes security management loopholes. The third risk is derived from the inherent risk of the boundary mode, which VPN inherits.

[0006] (3) VPN devices themselves may become a security problem. Like boundary security facilities, because of the difficulty in management, the boundary domain is usually considered as a trust domain by default, which leads to the management of VPN as a trusted device. But VPN is a typical target of attackers, and the risk of being attacked is very high, which becomes a "trusted" management loophole;

[0007] (4)VPN uses the password neither systematically nor systematically, and it is difficult to standardize. This is a big gap with the requirements of cryptography theory and engineering, so the security of the password cannot be effectively played, leaving a lot of space for attackers. For VPN, the typical attack mode of the attacker is not to crack the password, and most attacks will break through the VPN through the boundary and the vulnerability of the VPN system.

[0008] These weaknesses of VPN are both the problems of VPN itself and the problems of the existing network security architecture paradigm. After using VPN, the existing network security architecture is a combination mode of "network security + communication security", and network security and communication security are separated. Similarly, although VPN applies password to communication security, VPN cannot care about the systematic and standardized use of password, and the existing security architecture mode does not play the systematic security role of password. SUMMARY

[0009] In view of the current network security status and the problems existing in the prior art, the present application adopts a multi-plane architecture design, proposes a password-defined security architecture and a rule execution method, adopts a security rule-driven manner, and uses a password protocol to execute the rules, fully plays the comprehensive and systematic role of password in network security, solves the problems of hidden channel, rule violation external connection, horizontal attack and the like, and ensures the security and compliance of business data in the flow process.

[0010] To achieve the above object, the technical scheme adopted is:

[0011] A password-defined security architecture, which comprises seven planes of device plane, security plane, computing plane, network plane, data plane, rule plane and application plane, each plane implements the execution of security rules in a password protocol manner, and the seven planes jointly act to guarantee the security of the information system.

[0012] According to the password-defined security architecture of the present application, further, the device plane constructs a platform device security protection level protocol, realizes self-protection based on password through a hardware password module, and provides password service upwardly; the security rules defined for the device plane include that the hardware password module has an independent random number generation function; the device plane also monitors a device security baseline and reports the result to a log and audit module of the application plane for checking; the rules define the detection of the software and hardware function range of the device plane; the rules also define the content, recording process, storage security and uploading security of the evidence log, and ensure the security protection of the log file; and the rules require the device plane to synchronize time with an NTP server.

[0013] According to the application, the security architecture is defined by cryptography, further, the security plane uses reconfigurable cryptography technology to build a CDX cryptography security service grid to provide security services upwardly; the security rules of the security plane include: the rules define a multi-factor authentication mechanism, and different cryptography algorithms and key sources are used for identity authentication according to security protection levels and threat levels; the security rules of key negotiation include protocol name, protocol version, algorithm suite and protocol parameters; the security plane uses attribute-based access control, and after an access request, the rule plane issues authorization credentials, network routing rules, cryptography rules and log rules to the security routing devices on the access subject and path.

[0014] According to the application, the security architecture is defined by cryptography, further, the computing plane performs trust management on application behaviors to build a CDX trust computing system; the security rules of the computing plane include: the computing plane ensures that an application program cannot be dynamically written or modified during execution; the rules stipulate that the application program must check the version and signature of the executable program before execution; the rules stipulate the minimum set of installed software; the computing plane manages the version and signature of firmware.

[0015] According to the application, the security architecture is defined by cryptography, further, the network plane establishes an access path and a session channel for each service session to build a CDX identity exchange network; the security rules of the network plane include: the security rules run at the link layer, network layer and transport layer, and by comparing the header information of each inbound or outbound packet, network communication flows are blocked or passed; the rules define how peer communication entities use security services to perform secure communication; the rules also define the process of key exchange protocol, and stipulate the life cycle management of device keys, working keys and session keys; the security rules also define a NAT traversal protocol.

[0016] According to the application, the security architecture is defined by cryptography, further, the security rules of the data plane include: the data plane identifies and labels data; the data plane provides data access authentication services; the data plane authorizes data flow transfer paths according to access control results; the data plane uses cryptography technology to perform non-repudiation identification on data senders and receivers during data delivery.

[0017] According to the application, the security architecture is defined by cryptography, further, the security rules of the rule plane include: the rule plane decomposes the security policies input by users into security rules executed by each plane, and monitors the execution of these rules; the rule plane provides identity, identification and policy management services; the rule plane realizes measurable, controllable and measurable policy execution, and sends control instructions to the device plane when policy execution is abnormal or a high-risk security threat occurs; the rule plane receives analysis feedback from the application plane log and audit module to adjust and optimize the execution of security policies.

[0018] According to the password-defined security architecture, further, the security rules of the application plane are defined, including: the log and audit module of the application plane receives the log information reported by each plane, performs abnormal event analysis and audit, and automatically generates security rules to block abnormal access in linkage with the rule engine of the rule plane; the application plane provides a visual module to display network traffic, channel status, and security policy execution results; the application plane allows users to arrange security policies according to business requirements, and decomposes these policies to each plane for execution; and the application plane provides a time synchronization service to ensure the time consistency of each plane.

[0019] Further, the application also provides a rule execution method of the password-defined security architecture, including:

[0020] In the system initialization phase, the administrator registers the CDX client gateway, the CDX identification router, the CDX server gateway, the CDX security controller, the CDX client, and the CDX server, obtains identity credentials and initial security rules; the identity, identification and policy management module of the rule plane collects attribute information of security devices and user assets, which is used for rule engine matching rules;

[0021] The administrator logs in the security management system of the rule plane, and configures business security rules for the CDX client to access the CDX server;

[0022] The CDX client gateway and the CDX server gateway authenticate each other based on the initial security rules and the CDX security controller, and establish a CDX security channel; the CDX client gateway and the CDX server gateway authenticate each other and establish a CDX security channel; the CDX client and the CDX client gateway, and the CDX server and the CDX server gateway respectively authenticate and establish a CDX security channel;

[0023] The user requests to access the server resource through the client, the CDX security controller of the rule plane makes access control decision according to the data identification of the user access resource and the attribute of the access request, and issues authorization credentials to the client and the server after authorization;

[0024] The client encapsulates the access request data using the authorization credentials, and sends it to the server through the gateway and the router; the server verifies the request, encapsulates the resource security, and returns it to the client according to the path specified by the authorization credentials.

[0025] The above technical scheme has the following beneficial effects:

[0026] 1. Comprehensive coverage of security requirements of business scenarios

[0027] Business activities involve interactions among multiple entities within a business scenario, and the application defines business security rules through multiple dimensions of attributes (such as user activities, network environment, time, physical location, data flow characteristics, etc.), maximally covers the endogenous security requirements of the business scenario, and ensures the security of business activities.

[0028] 2. Systematization and standardized use of cryptographic technology

[0029] By using cryptographic identification for business data, converting business behavior into cryptographic behavior, and describing business security based on the standardization of cryptography, the deterministic security flow of business data between business entities is realized, and the controllability, measurability and observability are achieved, and the system security role of cryptographic technology is fully played.

[0030] 3. Multi-plane architecture for deep defense

[0031] The multi-plane method is used to define the cryptographic definition security architecture, which comprehensively solves a series of attack problems faced by the multi-protocol stack stacking system, and realizes flexible and targeted deep defense for security problems at each level.

[0032] 4. Controllable, measurable and observable business flow

[0033] Through the cryptographic definition security architecture, the business flow topology is determined, the controllability, measurability and observability of the business are realized, and the security and compliance of the business data in the flow process are ensured.

[0034] 5. Close combination of security and business

[0035] The application realizes the combination of security and business, solves the problem of separation of security and business in the traditional security architecture, ensures that the security policy can flexibly adapt to the business requirements, and improves the overall security of the system.

[0036] 6. Preventing illegal external connection and horizontal attack

[0037] Through business slicing and protocol filtering based on authorized credentials, and then performing security forwarding according to the routing path of the authorized credentials, illegal external connection and horizontal attack are prevented, and the security of the access request session is ensured to depend on the security rules of the authorized credentials. After the expiration of the authorized credentials, new authentication and authorization will be performed. BRIEF DESCRIPTION OF DRAWINGS

[0038] In order to more clearly illustrate the technical solutions of the embodiments of the application, the drawings of the embodiments of the application will be briefly introduced below. The drawings are only used to show some embodiments of the application, and not to limit all embodiments of the application to this.

[0039] Figure 1 is the framework diagram of the cryptographic definition security architecture of the first embodiment of the application;

[0040] Figure 2 This is a flowchart of the rule execution method of the cryptographically defined security architecture according to Embodiment 1 of the present invention;

[0041] Figure 3 This is a device registration example diagram from Embodiment 2 of the present invention;

[0042] Figure 4 This is an example diagram of generating a contact list according to Embodiment 2 of the present invention;

[0043] Figure 5 This is an example diagram of the logical connection topology of Embodiment 2 of the present invention;

[0044] Figure 6 This is a user login example diagram of Embodiment 2 of the present invention;

[0045] Figure 7 This is an example diagram of email sending according to Embodiment 2 of the present invention; Detailed Implementation

[0046] The exemplary solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Unless otherwise defined, the technical or scientific terms used in this invention should have the ordinary meaning understood by one of ordinary skill in the art.

[0047] Example 1

[0048] This embodiment discloses a cryptographically defined security architecture, employing a multi-plane architecture design, comprising seven planes: device plane, security plane, computation plane, network plane, data plane, rules plane, and application plane. Figure 1 As shown, the security rules for each plane are defined. The seven planes work together to implement the security rules in a cryptographic protocol, giving full play to the advantages of cryptographic technology and ensuring the security of the information system.

[0049] (1) The device plane specifies the construction method of the underlying device of the cryptographic security architecture. First, the platform device security protection level protocol (SLA) is constructed. For different security environment requirements, the hardware cryptographic module is the core to realize cryptographic self-protection and provide cryptographic services to the upper level.

[0050] (2) The security plane uses reconfigurable cryptography to construct a CDX cryptographic security service mesh, providing security services such as authentication, access control, availability, confidentiality, integrity, non-repudiation, and availability. CDX (Cryptography Defined X) means that X represents computing, network, data, and device; the Chinese meaning of CDX is: cryptography-defined computing, cryptography-defined network, cryptography-defined data, and cryptography-defined device, which constitute the complete concept and implementation method of cryptography-defined security.

[0051] (3)Computing plane conducts trust management for application behavior, constructs a CDX trust computing system, and ensures the security of data in the entire computing process.

[0052] (4)Network plane establishes an access path and a session channel for each service session, maintains the visibility of the session process, protects the compliance security of the session process, constructs a CDX identity exchange network, and according to the access control policy, compiles and executes network functions for each independent service session traffic.

[0053] (5)Data plane identifies data, provides data access authentication services, routing control services, and data delivery non-repudiation security services.

[0054] (6)Rule plane decomposes the security policy input by the user into security rules executed by each plane, monitors rule execution, and provides identity, identification and access management, policy management, log and evidence management services for entities (including devices, people, resources), access requests, etc.

[0055] (7)Application plane is user-oriented, allowing users to compile rules and policies according to their own needs and business conditions, perform log auditing, and visualize management, etc.

[0056] The following focuses on the description of the security rules of the seven planes of the password-defined security architecture. These security rules are input by the application plane, decomposed by the rule plane into each plane, and monitored and executed, which jointly support the password-defined security architecture.

[0057] (1) Security rules of the device plane

[0058] In the device plane, the security rules define the security measures to protect the device. The administrator performs vulnerability scanning, antivirus scanning, and software patch update cycle and frequency on the security device, and reports the scanning results to the security policy module of the application plane for device security level assessment. The security device monitors the device security baseline, including device login weak password check, unauthorized device login access, CPU, memory, non-volatile storage medium, network bandwidth, and other resource usage, and reports to the log and audit module of the application plane for checking, which is also used as the basis for device security level assessment.

[0059] The security rules of the device plane define that the hardware password module has an independent random number generation function to meet the security requirements of password operation. The security rules define the storage security of password algorithms, keys, and critical data, and the physical security of the hardware module.

[0060] The security rules of the device plane define the detection of the software and hardware function range of the device plane to ensure the normal work of the components.

[0061] The security rules of the device plane define the content, recording process, storage security and uploading security of the forensic log. The content of the forensic log includes the identification of the three-member user identity, date and time, three-member sensitive operation information, certificate information, data identification, executed policy identification, abnormal event dictionary, etc. The rules define the triggering time of the recording process, recording frequency, whether to upload in real time, compression of uploading, authentication and encryption conditions, etc. The rules define the security protection of the log file. According to different security levels of the log file, the corresponding cryptographic requirements of confidentiality, integrity, authentication, verifiability and non-repudiation are met to resist malicious modification, illegal access and network forensics, etc. The rules require the device plane and the NTP server to synchronize time to ensure accurate date and event.

[0062] (2) Security rules of the security plane

[0063] The cryptographic services provided by the security plane include authentication, key agreement, access control, confidentiality, integrity, non-repudiation and availability, provide key management services, and ultimately implement execution in the form of cryptographic protocols. Next, the security rules are described from the aspects of authentication, key agreement, access control, confidentiality, integrity, non-repudiation, etc.

[0064] ① Authentication

[0065] In the cryptographic definition of the security architecture, the logical connection is the entity using the same protocol, which provides identity trustability. The entity here generally refers to a person (PE) or a device (non-person, NPE). The authentication rules are described as follows:

[0066] Authentication entities: A, B.

[0067] Authentication goal: A authenticates whether B is the claimed entity? Yes / No.

[0068] Security protection level: Security_level

[0069] 1: Single-factor authentication can be used without using cryptographic mechanisms;

[0070] 2: At least two-factor authentication requires the use of symmetric cryptographic mechanisms;

[0071] 3: At least two-factor authentication requires the use of asymmetric cryptographic mechanisms;

[0072] 4: At least two-factor authentication requires the use of asymmetric cryptographic mechanisms and requires the use of hardware cryptographic modules such as smart cryptographic keys.

[0073] Threat level: Threat_level

[0074] 1: Entity B is normal with no bad record;

[0075] 2: Entity B authentication failure record accumulates more than 3 times, and returns to normal;

[0076] 3: Entity B authentication failure record accumulates more than 3 times, and has an alarm record of being attacked.

[0077] Password algorithm suite: Alg: 01: symmetric algorithm + HASH, 02: asymmetric algorithm + HASH.

[0078] Key source: Key: 01: B's identity certificate; 02: symmetric key bound to B's identity.

[0079] ②Rule constraints

[0080] Table 1 Password mechanism code

[0081] Index Cryptographic algorithm Key source Crypto_0102 01 02 Crypto_0201 02 01 Crypto_0000 "” 0

[0082] Table 2 Authentication rule constraints

[0083]

[0084]

[0085] ③Key agreement

[0086] The purpose of key agreement is for both parties to agree on a session key. In a secure key agreement, both parties have recognized each other, that is, they have been authenticated. In the case of using asymmetric cryptography system, both parties know each other's public key. In the case of using symmetric cryptography mechanism, both parties share a symmetric key and the same MAC function.

[0087] The following security rules need to be specified in the process of key agreement:

[0088] {

[0089] Protocol name: DH, ECDH, ECDHE, etc.

[0090] Protocol version: V.x

[0091] Algorithm suite:

[0092] Protocol parameters: key length, minimum acceptable parameter set, such as (p, q, g) in DH, etc.

[0093] }

[0094] ④Access control and authorization

[0095] The security plane adopts attribute-based access control (ABAC). No detailed description is given to the access control rules themselves, and the focus is on the obligations and operations to be performed after an access request is passed in the information system.

[0096] After the access request is passed, the rule plane issues authorization credentials, network routing rules, password rules, and log rules to the access subject and the security routing devices on the path, supporting data security, computing security, and network security during the access process.

[0097] (i) Authorization credential network function: security routing path.

[0098] Password policy: peer-to-peer connection; adjacent routing devices; data security; device itself trusted. Log policy: log classification, format, reporting period, etc.

[0099] Credential signature: signature of the authorization credential issuing authority on the authorization credential.

[0100] Table 3: Description of authorization credential content

[0101] Serial number Credential content Description 1 Credential unique identifier Identifier of authorized credential 2 Subject unique identifier Access subject unique identifier 3 Object unique identifier Access object unique identifier 4 Object attribute Accessible object attribute information 5 Operation Action of authorized operation 6 Edge exchange routing device information (TSR1) Close to subject 7 Edge exchange routing device information (TSR2) Close to object 8 Authorized credential public key information Authorized credential public key information 9 Authorized credential private key ciphertext information Authorized credential private key ciphertext 10 Pre-shared key encryption key ciphertext For encapsulating data (one-way) 11 Pre-shared key decryption key ciphertext For encapsulating data (one-way) 12 Pre-shared key MAC1 key ciphertext For encapsulating data (one-way) 13 Pre-shared key MAC2 key ciphertext For encapsulating data (one-way) 14 Initial vector IV1 For encapsulating data (one-way) 15 Initial vector IV2 For encapsulating data (one-way) 16 Authorized credential validity period Validity period ends, this authorization ends 17 Cryptographic algorithm suite For example: SM2_SM3_SM4 18 Signature value Rule system signature value

[0102] (ii) Network rules

[0103] The network rules for a single security routing device are as shown in Table 4.

[0104] Table 4: Network rules for a single security routing device

[0105]

[0106]

[0107] (3) Security rules of the computing plane

[0108] In the computing plane, the application program cannot be dynamically written or modified during execution. The application program checks the version and signature of the executable program, and if the check is correct, the original program is replaced and executed. If the check fails, a program upgrade exception event log is generated, and the log and audit module of the application plane is reported, and the execution of the application program for non-upgrade business is stopped.

[0109] In the computing plane, the security rules specify the minimum set of installed software, and these software need to be registered and recorded in the identification and policy management module of the rule plane, reducing potential security risks. The computing plane manages the version and signature of the firmware to ensure the security and reliability of the firmware and prevent unauthorized firmware upgrades.

[0110] (4) Security rules of the network plane

[0111] The security design principle of network plane adopts the structured design method, and is based on the network 7-layer model design principle and the security rules set by the Internet protocol.

[0112] The packet filtering security rules run at the link layer, network layer and transport layer, and determine to block or pass the network communication flow by comparing the packet header information of each inbound or outbound packet, including the source and destination MAC addresses, source and destination IP addresses, ports, protocol numbers (such as TCP, UDP, ICMP), communication direction (inbound, outbound) and the interface of the security device through which the packet is received and sent, to achieve the ability to block denial-of-service attacks, ACL control and related attacks.

[0113] The security rules of the network plane define how the peer communication entities communicate securely using security services. All information required for network security services is defined, such as 3-layer, i.e. IP layer security services, such as authentication header identification, identification header defining data packet data integrity, data source identification, anti-replay attack; 4-layer transport layer providing encapsulated security payload, providing data packet confidentiality, data integrity and other functions. The security rules define the process of key exchange protocol, which can be based on IPSec, SSL or custom security protocol. The security rules define data padding rules, such as padding alignment, obfuscation and the like of identification data. The security rules also define the security requirements of each stage of the life cycle of the device key, working key and session key, such as defining key update, updating the working key and session key according to time period and message flow.

[0114] The security rules of the network plane also define the NAT traversal protocol for ensuring network availability.

[0115] (5) Security rules of the data plane

[0116] In the data plane, rules for defining data identification are defined, data is labeled, data access authentication and access control rules are specified according to data identification, data flow path is authorized according to access control results, and in the process of data delivery, cryptographic techniques are used to perform non-repudiation identification of data senders (original) and data receivers (destination), to ensure the trusted delivery of data.

[0117] The data plane provides data identification services, data access services, routing control services and data delivery services to ensure the security of data throughout its life cycle.

[0118] (6) Security rules of the rule plane

[0119] The identity, identification and policy management module of the rule plane stores the port and service list submitted by the device plane, the vulnerability library scanning version and scanning time, the virus library scanning version and scanning time, and the software patch version as the basis for security level judgment. The identity, identification and policy management module of the rule plane stores the reasonable value range of the resources of the device plane, such as CPU, memory, hard disk and network bandwidth, as the basis for security level judgment. The identity, identification and policy management module of the rule plane stores the version and signature of the firmware submitted by the computing plane as a part of the security rules.

[0120] The identity, identification and policy management module of the rule plane provides a registration service for the attributes of each plane.

[0121] The policy execution and management module of the rule plane realizes the measurability, controllability and measurability of policy execution, and sends instructions such as shutdown, restart and fault diagnosis control to the device plane when there is an abnormal policy execution or a sudden high-risk security threat; views the security policies being executed by each plane; receives the feedback of policy execution analyzed by the log and audit module of the application plane, and realizes the closed-loop control of policy execution.

[0122] (7) Security rules of the application plane

[0123] In the application plane, the log and audit module receives the weak password check reported by the device plane, the unauthorized device login access exception event log, analyzes the abnormal events, and automatically generates security rules with the security action of blocking access in cooperation with the rule engine of the rule plane. The log and audit module receives the firmware upgrade abnormal event log reported by the computing plane, analyzes the log, locates the information of the firmware upgrade device identifier, firmware version and upgrade failure reason, and alarms the administrator through the visualization module of the application plane. The visualization module provides version rollback selection for restoring the use of a firmware version on the computing plane.

[0124] The log and audit module receives the network traffic and channel state (establishment time, encrypted traffic and validity period) periodically reported by the network plane, and displays them through the visualization module. When an abnormality is found in the log analysis, the administrator is alarmed through the visualization module, and the rule execution and management module of the rule plane is notified of the rule execution abnormality. The log and audit module receives the security policy execution result information reported by the network plane, reports the security policy execution measurement result to the policy execution and management module of the rule plane, including the policy identification, execution result and periodic report of the channel state.

[0125] The time synchronization module of the application plane provides a time synchronization service to the device plane to meet the time requirements in the security rules.

[0126] The embodiment also discloses a rule execution method of the security architecture, like Figure 2As shown, the user logs in the client program, securely accesses the server data, and describes the rule execution method under the password definition security architecture, involving entities such as users, administrators, CDX clients, client application programs, CDX client gateways, CDX identification routers, CDX servers, CDX server application programs, security management systems, identity, identification and policy management modules, and CDX security controllers. The entities are described as follows:

[0127] User: CDX information system user, responsible for business access and processing;

[0128] Administrator: CDX information system administrator, responsible for security policy arrangement and issuance;

[0129] CDX client: a client device based on the password definition security architecture, including function components of the password definition security device plane, the security plane, the computing plane, the network plane and the data plane, responsible for security rule execution;

[0130] CDX client application program: a program running on the CDX client;

[0131] CDX client gateway: a gateway close to the CDX client, executing security rules of the security device plane, the security plane, the computing plane, the network plane and the data plane, and guaranteeing data security flow;

[0132] CDX identification router: a secure routing device on the data flow path, similar to the CDX client gateway;

[0133] CDX server: a server based on the password definition security architecture, including function components of the password definition security device plane, the security plane, the computing plane, the network plane and the data plane, storing resources to be accessed, and responsible for security rule execution;

[0134] CDX server program: a program running on the CDX server;

[0135] Security management system: on the rule plane, responsible for CDX security device registration, information management and policy execution monitoring functions;

[0136] Identity, identification and policy management module: identity management, credential management and access control management;

[0137] CDX security controller: policy decision.

[0138] Specifically comprising the following steps:

[0139] Step S101, in the system initialization phase, the administrator registers the CDX client gateway, the CDX identification router, the CDX server gateway and the CDX security controller to the identity, identification and policy management module, and these passwords define the identity credentials obtained by the security device and the initial security rules of the device power-on. The administrator registers the user assets such as the CDX client and the CDX server to the identity, identification and policy management module to obtain the identity credentials and the local authentication security rules. The identity, identification and policy management module obtains the attribute information of the security device and the user assets, which are used for the rule engine to match the rules.

[0140] Step S102, the administrator logs in the security management system and configures the business security rules of the CDX client accessing the CDX server. These security rules are related to specific businesses and include but are not limited to the business access time limit, the business operation limit, the business security level, the various plane security rules of the business session associated device and the like.

[0141] Step S103, the CDX client gateway and the CDX server gateway are authenticated to each other based on the registered identity credentials and negotiate to establish the CDX security channel according to the initial security rules of the device power-on. The CDX client gateway and the CDX server gateway are authenticated to each other based on the registered identity credentials and negotiate to establish the CDX security channel according to the initial security rules of the device power-on.

[0142] Step S104, the user logs in the CDX client application, the CDX client application authenticates the user according to the local authentication security rules, and after the authentication, the user is allowed to access the services of the CDX server through the CDX client. The CDX client and the CDX client gateway are authenticated to each other based on the registered identity credentials and negotiate to establish the CDX security channel.

[0143] Step S105, when the CDX server is powered on, the CDX server is authenticated to the CDX server gateway based on the registered identity credentials and negotiates to establish the CDX security channel.

[0144] Step S106, the user requests to access the server resource through the client, the CDX security controller makes the access control decision according to the data identification of the user accessing the resource and the attribute of the access request, and issues the authorization credentials to the user access request through the identity, identification and policy management module. At the same time, the CDX security controller issues the access credentials to the server for verification.

[0145] Step S107, the client encapsulates the access request data packet with the authorization credentials, and the access request is encapsulated with the access request data and sent to the server through the client gateway, the CDX identification router and the server gateway according to the routing route specified by the authorization credentials.

[0146] Step S108: The server verifies the source and authenticity of the access request, securely encapsulates the resource to be accessed, and sends it to the client according to the path and security method specified in the authorization credential.

[0147] Example 2

[0148] Taking a secure email system as an example, the entities involved include email client devices, email server devices, client email gateway devices, server email gateway devices, a secure email management system, email client programs, and email server programs. Key business processes involved include system initialization, user login, sending emails, and receiving emails.

[0149] (1) System initialization

[0150] The administrator starts and logs into the email management system.

[0151] ①For example Figure 3 As shown, device registration. Administrators register devices such as mail servers, mail clients, client gateways, server gateways, and management gateways through the secure email management system. Unique identifiers are generated for registered devices, and identity credentials, neighboring gateway or device information, are issued. Identity credentials are also issued to email client applications and mail servers.

[0152] ② Assign personal accounts, grant read and write authorizations, assign email clients to use, and generate recipient lists, such as... Figure 4 As shown.

[0153] ③ Generate the device logical connection topology.

[0154] After device registration is complete and the device goes online, CDX secure channels are established between the client gateway and the management gateway, the client gateway and the server gateway, the server gateway and the management gateway, and the server gateway and the mail server, generating a logical secure connection topology (e.g., Figure 5 As shown in the figure, an overlay secure network is built for email services.

[0155] (2) User Login

[0156] The user launches the email client application, enters their username and password as prompted, and then enters the email interface. The user login process is as follows: Figure 6 As shown.

[0157] ① The user launches the email client application and enters authentication information (username / password, smart password key + password) according to the authentication rules;

[0158] ② The email client establishes a CDX secure channel with the client gateway;

[0159] ③ Mail client application establishes a secure connection with the secure mail management system;

[0160] ④ Mail client application passes user authentication information and mail client information to the secure mail management system through the secure connection;

[0161] ⑤ The secure mail management system authenticates the mailbox account, access control authentication, and issues a CDX authorization credential after passing;

[0162] ⑥ The secure mail management system issues security rules under the relevant security gateway;

[0163] ⑦ Mail client application and mail server establish a mail security sending and receiving path (CDX-Path) to prepare for the secure forwarding of mail.

[0164] (3) Send mail

[0165] The user triggers the mail sending command, and the client application sends the mail content to the server. The mail sending process is shown in Figure 7 .

[0166] Business rules - prerequisite: user login, establish CDX-Path security path.

[0167] ① The client application uses the CDX authorization credential to encapsulate the mail sending content into the CDX mail encapsulation format;

[0168] ② The client application sends the mail to the server application through the CDX-Path;

[0169] ③ The server application CDX authorization credential verifies whether the client has write permission, and verifies and receives the mail.

[0170] (4) Receive mail

[0171] The user triggers the mail receiving command, and the client application sends a read request form to the mail server. The mail server sends the mail to the client application.

[0172] Business rules - prerequisite: user CDX authorization credential contains "read" authorization.

[0173] ① The client application uses the CDX authorization credential to encapsulate the read mail request form into the CDX mail encapsulation format;

[0174] ② The client application sends the encapsulated request form to the server application through the CDX-Path;

[0175] ③The server application verifies if there is a "read" permission, and after verification, encapsulates the mail using CDX authorization credentials and sends it back to the client application.

[0176] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present application, which are used to illustrate the technical solutions of the present application, but not to limit the same. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can modify the technical solutions recorded in the foregoing embodiments or equivalently replace some of the technical features within the technical range disclosed by the present application. The modification or replacement does not make the corresponding technical solution deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A password-defined security architecture system, characterized by, The architecture comprises seven planes, i.e., a device plane, a security plane, a computing plane, a network plane, a data plane, a rule plane and an application plane, each of which implements execution of security rules in a manner of a cryptographic protocol, and the seven planes jointly work to guarantee security of the information system; wherein: The device plane constructs a platform device security protection level protocol, implements self-protection based on cryptography through a hardware cryptographic module, and provides cryptographic services for the security, computing, network, data, rule and application planes; the security rules defined for the device plane include that the rule defines that the hardware cryptographic module has an independent random number generation function; the device plane also monitors a device security baseline and reports a result to a log and audit module of the application plane for checking; the rule defines a detection function range of the device plane on the cryptographic components; the rule also defines content, a recording process, storage security and uploading security of a forensic log, and ensures security protection of the log file; and the rule requires the device plane to synchronize time with an NTP server; The security plane uses a reconfigurable cryptographic technology to construct a CDX cryptographic security service grid, and provides security services for the computing, network, data, rule and application planes; the Chinese meaning of CDX is: cryptographic definition of computing, cryptographic definition of network, cryptographic definition of data, cryptographic definition of device, which constitutes a complete concept and implementation method of cryptographic definition of security; the security rules defined for the security plane include that the rule defines a multi-factor authentication mechanism, and uses different cryptographic algorithms and key sources for identity authentication according to a security protection level and a threat level; the security rules of key negotiation include a protocol name, a protocol version, an algorithm suite and protocol parameters; the security plane adopts attribute-based access control, and after an access request passes, the rule plane issues authorization credentials, network routing rules, cryptographic rules and log rules to a security routing device on an access subject and a path; The computing plane performs trust management on application program behaviors, and constructs a CDX trust computing system; the security rules defined for the computing plane include that the computing plane ensures that an application program cannot be dynamically written or modified during execution; the rule stipulates that the application program must check a version and a signature of an executable program before execution; the rule stipulates a minimum set of installed software; and the computing plane manages a version and a signature of firmware; The network plane establishes an access path and a session channel for each service session, and constructs a CDX identity exchange network; the security rules defined for the network plane include that the security rules run at a link layer, a network layer and a transport layer, and block or pass network communication flows by comparing packet header information of each inbound packet or outbound packet; the rule defines how a peer communication entity uses a security service to perform secure communication; the rule also defines a process of a key exchange protocol, and stipulates life cycle management of a device key, a working key and a session key; and the security rules also define a NAT traversal protocol; The security rules defined for the data plane include that the data plane identifies and labels data; the data plane provides data access authentication services; the data plane authorizes a data flow transfer path according to an access control result; and the data plane uses cryptographic technology to perform non-repudiation identification on a data sender and a receiver in a data delivery process. The security rules of the rule plane include: the rule plane decomposes the security policy input by the user into security rules executed by each plane, and monitors the execution of the rules; the rule plane provides identity, identification and policy management services; the rule plane realizes measurable, controllable and measurable policy execution, and sends control instructions to the device plane when there is an abnormal policy execution or a sudden high-risk security threat; the rule plane receives analysis feedback from the log and audit module of the application plane, and adjusts and optimizes the execution of the security policy; The security rules of the application plane include: the log and audit module of the application plane receives the log information reported by each plane, analyzes and audits abnormal events, and automatically generates security rules to block abnormal access in cooperation with the rule engine of the rule plane; the application plane provides a visualization module to display network traffic, channel status and security policy execution results; the application plane allows users to arrange security policies according to business needs, and decomposes the policies into each plane for execution; the application plane provides a time synchronization service to ensure the time consistency of each plane.

2. A method of rule execution of a security architecture system defined by a password according to claim 1, characterized by, Comprise: In the system initialization phase, the administrator registers the CDX client gateway, the CDX identification router, the CDX server gateway, the CDX security controller, the CDX client and the CDX server, obtains identity credentials and initial security rules; the identity, identification and policy management module of the rule plane collects attribute information of security devices and user assets for rule engine matching rules; The administrator logs in to the security management system of the rule plane, and configures the business security rules for the CDX client to access the CDX server; The CDX client gateway and the CDX server gateway authenticate each other based on the initial security rules and the CDX security controller to establish a CDX security channel; the CDX client gateway and the CDX server gateway authenticate each other and establish a CDX security channel; the CDX client and the CDX client gateway, the CDX server and the CDX server gateway respectively authenticate and establish a CDX security channel; The user requests to access the server resource through the client, and the CDX security controller of the rule plane makes access control decision according to the data identification of the user accessing the resource and the attribute of the access request, and issues authorization credentials to the client and the server after authorization; The client encapsulates the access request data using the authorization credentials, and sends it to the server through the gateway and the router; the server verifies the request, encapsulates the resource security and returns it to the client according to the path specified by the authorization credentials.

3. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the method of claim 2.

Citation Information

Patent Citations

  • Password definition network security system construction method, system architecture and data forwarding method

    CN114024767A

  • Service oriented security device management network

    US20060282886A1