Terminal network secure transmission method and platform for switch

By building a dual-mapping module and introducing a software-defined network, combining logical management network for forwarding storm evaluation and traffic control, the security problems of traditional network security management methods in dynamic environments are solved, and efficient and reliable data transmission of the network is achieved.

CN120342772AActive Publication Date: 2025-07-18QIDONG SHUJIE SOFTWARE ENGINEERING CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510750347.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-18
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

Traditional network security management methods rely on fixed rules and static security policies, and are difficult to cope with dynamically changing network environments, resulting in poor security in the data transmission process.

Method used

Build a dual-mapping module for security verification and screening, introduce a software-defined network for logical programming, combine it with a logical management network for forwarding storm evaluation and trigger traffic control, and dynamically adjust the flow control strategy.

Benefits of technology

It improves the security and stability of the network, can timely identify and prevent network storms, ensure the normal transmission of key services, and improves the efficiency and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342772A_ABST
    Figure CN120342772A_ABST
Patent Text Reader

Abstract

The invention provides a terminal network secure transmission method and platform for a switch, and relates to the technical field of secure transmission, and the method comprises the steps: constructing a dual-mapping module for a target switch, and configuring a screening packaging layer at a first module end; receiving source address information, performing security check screening and storage, and determining security address information; introducing a software defined network, performing division and logic programming on a physical communication network, and determining a logic management network; performing forwarding storm assessment based on the first time node, and determining a storm assessment result; if the storm probability meets a probability threshold value, triggering a storm control mechanism to perform flow control, and determining a flow control strategy; and performing terminal network security transmission management. The technical problem that a traditional network security management method generally depends on a fixed rule and a static security policy, and a dynamically changing network environment is difficult to adjust and respond in time, so that the security of a data transmission process is poor is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of secure transmission, and in particular to a terminal network secure transmission method and platform for switches. Background Art

[0002] With the expansion of network scale and the increase in complexity, especially in enterprise and data center environments, the network faces more and more security challenges. Existing switches and network management methods have some problems when dealing with these challenges. On the one hand, with the diversification of network devices and terminals, network security threats are constantly increasing. These threats take advantage of the openness and complexity of the network and often invade the network by forging source addresses, broadcast storms, etc. Existing single security mechanisms are difficult to effectively cope with. On the other hand, traditional network management methods usually rely on fixed rules and static security policies, which are difficult to adjust and respond in a timely manner in the face of a dynamically changing network environment, resulting in security vulnerabilities in the data transmission process. Summary of the Invention

[0003] This application provides a terminal network secure transmission method and platform for switches, aiming to solve the technical problem that traditional network security management methods usually rely on fixed rules and static security policies, which are difficult to adjust and respond in a timely manner in a dynamically changing network environment, resulting in poor security in the data transmission process.

[0004] In the first aspect disclosed in this application, a terminal network secure transmission method for switches is provided. The method includes: for a target switch, constructing a dual mapping module, where the dual mapping module is determined based on the twin mapping of the built-in system module of the switch, and a screening encapsulation layer is configured at the first module end; receiving source address information, performing security verification screening and storage based on the dual mapping module to determine the secure address information received by the switch, where the verification screening is based on the pre-storage screening at the first module end and the mapping storage at the second module end; introducing software-defined network, partitioning and logically programming the physical communication network to determine a logical management network, where the logical management network is a virtualized management network and is scalable; for the secure address information, combining the logical management network, performing a forwarding storm assessment based on a first time node to determine a storm assessment result, where the first time node is any address forwarding time node, and the forwarding methods include broadcast, unicast, and multicast packets; identifying the storm assessment result, if the storm probability meets the probability threshold, triggering a storm control mechanism for traffic control to determine a traffic control strategy; based on the traffic control strategy, performing terminal network secure transmission management.

[0005] The second aspect disclosed in this application provides a terminal network security transmission platform for a switch. The platform is used for the above-mentioned terminal network security transmission method for a switch. The platform includes: a dual mapping module construction unit, which is used to construct a dual mapping module for a target switch. Among them, the dual mapping module is determined based on the twin mapping of the built-in system module of the switch, and a screening encapsulation layer is configured at the first module end; a security verification and screening unit, which is used to receive source address information, perform security verification, screening and storage based on the dual mapping module, and determine the secure address information received by the switch. Among them, the verification and screening is based on the pre-storage screening at the first module end and the mapping storage at the second module end; a logical programming unit, which is used to introduce software-defined network, divide and logically program the physical communication network, and determine a logical management network. Among them, the logical management network is a virtualized management network and is scalable; a forwarding storm evaluation unit, which is used to perform a forwarding storm evaluation based on the first time node for the secure address information in combination with the logical management network, and determine a storm evaluation result. Among them, the first time node is any address forwarding time node, and the forwarding methods include broadcast, unicast and multicast packets; a traffic control unit, which is used to identify the storm evaluation result. If the storm probability meets the probability threshold, trigger a storm control mechanism to perform traffic control and determine a traffic control strategy; a secure transmission management unit, which is used to perform terminal network security transmission management based on the traffic control strategy.

[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages: Build a dual mapping module for the target switching mechanism, which can strictly screen the source address information of data packets. The first module end is configured with a screening encapsulation layer, which can initially filter all incoming data to ensure that only data packets meeting the security standards can enter the next step of processing, improving the network security; after receiving the source address information, through the security verification screening by the dual mapping module, unsafe address information can be effectively filtered. This method combining the pre-storage screening at the first module end and the mapping storage at the second module end further enhances the network security; introduce software-defined network, divide the physical communication network and perform logical programming to build a virtualized logical management network. This network not only supports the logical division of the physical network but also allows dynamic management and configuration of the network. The logical management network is scalable and can be dynamically adjusted and optimized according to actual needs to adapt to the changing network environment and business requirements; for the secure address information, combined with the logical management network, perform real-time forwarding storm assessment, which can quickly identify possible storms in the network, such as broadcast storms, unicast storms, and multicast storms, and trigger the storm control mechanism when necessary. This can timely take traffic control measures to prevent the occurrence or spread of network storms, greatly improving the network stability and anti-attack ability; according to the storm assessment results, dynamically adjust the traffic control strategy to ensure that in the case of storms, the key services of the network can be preferentially guaranteed. Based on the traffic control strategy, comprehensively manage the secure transmission of the terminal network to ensure that all data packets meet the preset security standards during the transmission process. This comprehensive management method not only protects the network security but also improves the efficiency and reliability of data transmission, providing users with higher-quality network services.

[0007] The above description is only an overview of the technical solution of this application. In order to be able to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of this application more obvious and understandable, the following specifically gives the specific implementation manners of this application. Brief Description of the Drawings

[0008] Figure 1 It is a schematic flowchart of the method for secure transmission of the terminal network for the switch provided by the embodiment of this application; Figure 2 It is a schematic structural diagram of the terminal network secure transmission platform for the switch provided by the embodiment of this application.

[0009] Description of the reference numerals: Dual mapping module construction unit 10, security verification screening unit 20, logical programming unit 30, forwarding storm assessment unit 40, traffic control unit 50, secure transmission management unit 60. Detailed Description of the Invention

[0010] Embodiments of the present application provide a terminal network security transmission method and platform for switches, which solve the technical problem that traditional network security management methods usually rely on fixed rules and static security policies, and it is difficult to adjust and respond in a timely manner to a dynamically changing network environment, resulting in poor security during the data transmission process.

[0011] After introducing the basic principles of the present application, various non-limiting embodiments of the present application will be specifically introduced below in conjunction with the accompanying drawings of the specification. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0012] Embodiment 1, as Figure 1 shown, embodiments of the present application provide a terminal network security transmission method for switches, and the method includes: For a target switch, a dual mapping module is constructed, wherein the dual mapping module is determined based on the twin mapping of the built-in system module of the switch, and a screening encapsulation layer is configured at the first module end.

[0013] The target switch is determined, and based on the built-in system module of the switch, a dual mapping module is constructed in the way of twin mapping. The dual mapping module includes two parts, namely the first module end and the second module end. The first module end is used for the preliminary screening and security verification of data, and the second module end is used for storing and managing the screened security data. The collaborative work of the two modules can enhance the security of the network and the efficiency of management.

[0014] Based on the characteristics of the built-in system module of the switch, twin mapping is performed. Specifically, by analyzing the functions and data flows of the built-in modules of the switch, a corresponding twin module is constructed to obtain the dual mapping module. In this way, it can be ensured that the new dual mapping module is seamlessly integrated with the existing functions of the switch and can update and synchronize data in real time.

[0015] Among them, a screening encapsulation layer is configured at the first module end. The screening encapsulation layer is a logical layer responsible for preliminary screening and filtering, and is used to check the address information and data packets received from the network to determine whether they are secure and trustworthy. This layer can include at least a trusted platform, permission detection, obligation detection, and condition detection based on different screening methods.

[0016] The source address information is received, and security verification screening and storage are performed based on the dual mapping module to determine the secure address information received by the switch, wherein the verification screening is based on the prior storage screening of the first module end and the mapping storage of the second module end.

[0017] When the switch receives data packets from the network, the source address information in these data packets is extracted, usually including the MAC address and the IP address. The MAC address is used for communication at the data link layer, while the IP address is used for communication at the network layer.

[0018] After receiving the source address information, the constructed dual mapping module is used to perform security verification screening and storage operations. Specifically, when the source address information of a data packet enters the switch, it is first transmitted to the first module end of the dual mapping module. Here, the source address information is temporarily stored for further screening. The first module end is configured with a screening encapsulation layer, which performs network security verification and screening on the stored source address information according to preset security policies. The security policies can include MAC address whitelists, IP address blacklists, specific protocol checks, etc. Through these policies, the first module end can quickly screen out the source addresses of data packets that do not meet the security requirements and retain the valid address information.

[0019] Then, the first module end maps and stores the valid address information to the second module end. The process of mapping and storage includes transmitting data from the first module end to the second module end and storing it in a specific data structure at the second module end. The second module end is responsible for maintaining and managing these valid address information, enabling the switch to quickly and accurately find and use this information during subsequent data packet processing and forwarding.

[0020] Introduce software-defined networking to partition and logically program the physical communication network to determine the logical management network. Among them, the logical management network is a virtualized management network and is scalable.

[0021] Software-defined networking is a network management method that allows the behavior and rules of a network to be defined through software programming. It decouples the control layer (control plane) of the network from the data forwarding layer (data plane), making network management more flexible and centralized. The physical communication network is a network structure composed of actual network devices and links, such as switches, routers, physical connection cables, etc.

[0022] After software-defined networking takes over the control plane in the network, a large physical communication network is partitioned into multiple small logical networks through software programming. These logical networks are based on different partitioning criteria, which can be different dimensions such as departments, functions, business requirements, etc.

[0023] Then, specific behaviors and management rules are defined for each logical network through programming. These rules can include routing policies, access control policies, traffic priorities, etc. This logical programming enables each logical network to operate independently, be customized and optimized according to actual needs, and is not restricted by the physical network topology. This method provides higher flexibility and manageability for the network. After partitioning and logical programming, the physical communication network is transformed into a virtualized logical management network, which consists of multiple independent logical subnets, each with its own independent control and management rules. The logical management network is a virtualized management network because it has nothing to do with the actual connection of the physical network, but is defined and managed by software. This virtualized network can flexibly adjust its topology and management rules when needed to adapt to the changing network requirements.

[0024] Moreover, since the logical management network is defined and controlled by software, it has strong scalability. Network administrators can dynamically add or reduce logical subnets, or adjust the network management rules according to actual needs, without making large-scale changes to the physical network devices. This flexibility improves the adaptability and scalability of the network.

[0025] For the security address information, in combination with the logical management network, a forwarding storm assessment based on the first time node is carried out to determine the storm assessment result, where the first time node is any address forwarding time node, and the forwarding methods include broadcast, unicast, and multicast packets.

[0026] The time node refers to the time node when the switch processes the data packet during the forwarding process of the data packet. The entry, processing, and forwarding of each data packet can be regarded as a time node, and an analysis object is randomly extracted from them as the first time node. A forwarding storm means that within a short period of time, the network device receives a large number of broadcast, unicast, or multicast packets, resulting in limited forwarding capabilities of the device and full occupancy of the network bandwidth, thereby causing a decline or even paralysis of network performance.

[0027] At the first time node, the switch, through the built-in monitoring module, collects and analyzes the traffic data of each port in real time, especially the quantity and type of broadcast, unicast, and multicast data packets. According to the actual needs and historical data of the network, the detection threshold of the forwarding storm is set. For example, the maximum number of broadcast packets allowed per second. These thresholds can be dynamically adjusted according to the network load and changes. Based on the detection threshold, the current network state is evaluated to detect whether there is abnormal traffic. Through the network state evaluation, a storm assessment result is generated, which includes the current network traffic status and the risk assessment of potential storms.

[0028] Identify the storm assessment result. If the storm probability meets the probability threshold, trigger the storm control mechanism for traffic control and determine the traffic control strategy.

[0029] The storm probability is the likelihood of a forwarding storm occurring in the network. This probability is calculated based on real-time traffic data, historical traffic patterns, and a preset storm detection threshold. The currently calculated storm probability is compared with a preset probability threshold, which is set according to the network's tolerance and historical data and is used to determine whether there is sufficient storm risk to require measures. If the storm probability meets or exceeds the preset probability threshold, the switch immediately triggers the storm control mechanism. The activation of this mechanism indicates that the current traffic situation poses a potential risk that may lead to a decline or even paralysis of network performance, and protective measures need to be taken.

[0030] Determine the traffic control strategy, which includes restricting the forwarding rate, adjusting priorities, blocking data streams, etc. Specifically, adjust the priorities, set higher forwarding priorities for important unicast traffic to ensure that critical business traffic is not affected; block specific data streams. When abnormal data streams with certain specific source addresses or destination addresses are detected, temporarily block these data streams to prevent them from triggering storms.

[0031] Based on the traffic control strategy, conduct terminal network security transmission management.

[0032] Based on the determined traffic control strategy, control the switch to dynamically adjust its internal forwarding rules and traffic management algorithms, execute this traffic control strategy, and ensure that legal and critical data streams can continue to be transmitted safely when the network is affected by abnormal traffic. During this process, the switch continuously monitors the network's traffic situation and overall performance. According to the real-time monitoring data, it can judge the effectiveness of the traffic control strategy. If the impact of certain strategies on network performance is not ideal, or new abnormal traffic appears, the switch can dynamically adjust these strategies to ensure the continuous and stable operation of the network.

[0033] Furthermore, configure the screening encapsulation layer, including: Determine the screening method based on terminal network security. Among them, the screening method at least includes a trusted platform, privilege detection, obligation detection, and condition detection; based on the MAC mode, conduct hierarchical integration and encapsulation of the screening method to determine the first screening encapsulation layer; based on the IP mode, conduct hierarchical integration and encapsulation of the screening method to determine the second screening encapsulation layer; integrate the first screening encapsulation layer and the second screening encapsulation layer to determine the screening encapsulation layer.

[0034] To ensure network security, it is necessary to strictly screen the traffic entering the network. The screening method is designed to verify and filter data packets through a multi-level inspection mechanism to prevent illegal traffic from entering the network. The screening method at least includes a trusted platform, permission detection, obligation detection, and condition detection. Among them, the trusted platform verifies the credibility of the terminal device to ensure that the device is certified and not controlled by malware or malicious users. The screening of the trusted platform can be achieved through technologies such as hardware trust roots and software signature verification; permission detection checks the access permissions of terminal users or devices to ensure that they have the corresponding permissions to access specific network resources or perform specific operations. Permission detection can be based on user authentication, access control lists, etc.; obligation detection confirms whether the terminal device or user meets specific obligations or conditions, such as compliance requirements, usage policies, or network behavior norms. This detection can be achieved through policy management and compliance tools; condition detection checks the behavior of the terminal device or user based on real-time network and environmental conditions. For example, according to conditions such as network load, device geographical location, and time, it decides whether to allow specific network operations.

[0035] The MAC mode is a method of screening and filtering based on the Media Access Control address (MAC address) at the data link layer. The MAC address is the physical address of a network device used for communication between devices in a local area network. In the MAC mode, the screening mainly targets the source MAC address and destination MAC address of the data packet to determine whether these addresses are within the allowed range.

[0036] Based on the MAC mode, different screening methods, including the trusted platform, permission detection, obligation detection, and condition detection, are combined in layers. Each layer of the screening method targets specific security requirements and is carried out in a specific order. The purpose of layering is to ensure that each security check step can be carried out independently and the results complement each other to form a complete security check process. Then, all the layered screening methods are uniformly encapsulated in a logically independent encapsulation layer. The role of the encapsulation layer is to integrate all the screening methods into an executable security module for easy invocation by the switch during the data packet processing process. Finally, the first screening encapsulation layer based on the MAC mode is obtained. The first screening encapsulation layer is mainly responsible for security checks based on the MAC address.

[0037] The IP mode is a method of screening and filtering based on the IP address at the network layer. The IP address is used to identify the location and identity of each device in the network and is the core identifier for Internet communication. In the IP mode, the screening mainly targets the source IP address and destination IP address of the data packet to determine whether these addresses are within the allowed range and ensure that they comply with the network security policy.

[0038] Based on the IP mode, different screening methods, including trusted platforms, privilege detection, obligation detection, and condition detection, are hierarchically combined. Similarly, all hierarchical screening methods are uniformly encapsulated in a logically independent encapsulation layer to obtain a second screening encapsulation layer based on the IP mode. The second screening encapsulation layer is mainly responsible for security checks based on IP addresses.

[0039] Integrate the first screening encapsulation layer and the second screening encapsulation layer. During the integration of the encapsulation layers, they can be arranged according to the priority of data processing. For example, the screening in MAC mode can be executed first, and then the screening in IP mode. This priority setting can be adjusted according to the actual needs of the network. Finally, a complete screening encapsulation layer is formed. This integration process aims to achieve comprehensive screening and verification of data packets through a multi-level and multi-mode security check mechanism.

[0040] Furthermore, configure the screening encapsulation layer at the first module end, where the first module end is the first interaction system module of the dual mapping module.

[0041] The first module end is the first interaction system module of the dual mapping module, responsible for initially receiving and processing all data packets entering the switch. By configuring the screening encapsulation layer at the first module end, strict security checks can be implemented at the initial stage of data packet processing, effectively filtering out all traffic that does not meet security requirements and only allowing verified legitimate data packets to enter the next processing process.

[0042] Furthermore, perform security verification screening and storage based on the dual mapping module, including: Receive the source address information and temporarily store the source address information at the first module end; based on the screening encapsulation layer configured at the first module end, perform network security verification and screening on the source address information to determine valid address information, where the verification method is any one or at least one of the MAC mode and the IP mode; based on the mapping relationship between the first module end and the second module end, map and store the valid address information at the second module end, and delete the source address information stored at the first module end.

[0043] When a data packet arrives at the switch, the first module end first receives these data packets. The data packets contain various information, where the source address information is the MAC address and / or IP address of the sender of the data packet. The MAC address is used for communication at the data link layer, and the IP address is used for communication at the network layer. After receiving the source address information, the first module end temporarily stores this information in a fast storage area inside. The purpose of this temporary storage is to retain the original information of the data packet before performing security screening.

[0044] After the source address information is temporarily stored, the first module end calls various security screening mechanisms of the screening encapsulation layer to verify and screen the source address information layer by layer. Specifically, at the data link layer, screening and filtering are performed based on the MAC address, and at the network layer, screening and filtering are performed based on the IP address. After multiple levels of verification by the screening encapsulation layer, valid address information, that is, address information that meets the network security requirements, is determined, and these addresses can continue to enter the next network processing process.

[0045] In the dual mapping module, there is a mapping relationship between the first module end and the second module end. This relationship is to ensure that data and status are synchronized and consistent between the two modules. The mapping relationship can be implemented through a specific data structure to ensure that information is not lost or tampered with during the transmission process.

[0046] After confirming the valid address information, the first module end maps and stores this information at the second module end. The process of mapping and storing includes transmitting data from the first module end to the second module end and storing it in a specific data structure at the second module end. The second module end is responsible for maintaining and managing this valid address information, enabling the switch to quickly and accurately search for and use this information during subsequent packet processing and forwarding.

[0047] After confirming that the valid address information is stored at the second module end, the source address information is deleted from the temporary storage area of the first module end. This operation aims to clean up the storage space of the first module end and prevent the accumulation of invalid data. By deleting the processed source address information in a timely manner, storage resources can be released, improving the processing efficiency and performance of the first module end.

[0048] Furthermore, the determination of the logical management network includes: Traverse the physical communication network, divide the physical communication network based on the communication characteristics of communication terminals, and determine multiple divided networks; traverse the multiple divided networks, determine communication logic rules; map the multiple divided networks and the communication logic rules to construct the logical management network.

[0049] The physical communication network is a network structure composed of actual network devices and links, such as switches, routers, physical connection cables, etc. Traverse the physical communication network and check and analyze each network device and its connection method one by one.

[0050] The communication characteristics of communication terminals refer to devices connected to the network, such as computers, mobile phones, Internet of Things devices, etc., and their behaviors and characteristics in network communication. These characteristics include device type, communication protocol used, data transmission rate, service quality requirements, geographical location, etc.

[0051] During the network partitioning process, based on these communication characteristics, the physical communication network is divided into multiple sub-networks. The principle of partitioning is to allocate terminal devices with similar communication characteristics or similar requirements to the same sub-network for better targeted management. For example, terminal devices with high bandwidth requirements (such as video streaming servers) are divided into one network, and terminal devices with low-latency requirements (such as real-time communication devices) are divided into another network. Through the partitioning of the physical communication network, multiple partitioned networks are finally determined, and each partitioned network contains a group of terminal devices with similar communication characteristics.

[0052] After the partitioned networks are determined, each partitioned network is traversed and analyzed. This traversal process mainly examines the topology structure, device type, number of terminals, data traffic characteristics, etc. within each partitioned network to determine the specific characteristics of each partitioned network.

[0053] Communication logic rules refer to the strategies and rules for managing and optimizing network communication within a partitioned network. According to the specific characteristics of each partitioned network, corresponding logic rules are formulated to optimize the performance and security of the network. Exemplarily, corresponding communication rules are formulated based on the type of terminal device, such as computers, mobile devices, etc. For example, higher bandwidth and low-latency communication paths are set for high-priority terminal devices; by analyzing data traffic characteristics, load balancing and traffic control strategies are formulated to avoid network overload and congestion. For example, in a high-traffic partitioned network, dynamic traffic control and load balancing strategies are adopted to ensure the stable operation of the network. Through the formulation of communication logic rules for partitioned networks, distributed targeted management can be achieved.

[0054] Map multiple partitioned networks to their corresponding communication logic rules to construct a logical management network. This process establishes the correspondence between the partitioned networks and the communication logic rules, enabling each partitioned network to apply corresponding management strategies based on its specific attributes and operate according to predetermined rules.

[0055] Furthermore, mapping the multiple partitioned networks to the communication logic rules to construct the logical management network includes: Map the multiple partitioned networks to the communication logic rules to determine an initial management network; traverse the initial management network, decouple and separate the control plane and the data plane to determine a parallel management layer, where the parallel management layer includes a control management layer and a data transmission management layer; traverse the parallel management layer and perform programming processing on the communication logic rules mapped by the partitioned networks within the layer to determine the logical management network.

[0056] Map multiple partitioned networks to communication logic rules. The mapping process is to associate each partitioned network with its corresponding communication logic rule. This process ensures that each network operates according to its characteristics, forming an initial management network as the initial network management state.

[0057] Traverse the initial management network to check its configuration and operation status. The purpose of traversal is to determine information such as the role, connection status, and data flow direction of each network node. The control plane is responsible for managing the configuration and operation of network devices, controlling the routing and scheduling of network traffic. The data plane is responsible for the actual packet forwarding and processing, which is the main path for data flow. In traditional network architectures, the control plane and the data plane are tightly coupled, which limits the flexibility and scalability of the network. The decoupling process is to separate the control plane and the data plane to form independent management layers. This enables network administrators to manage network policies and data flow paths separately, increasing the flexibility and response speed of the network.

[0058] Through decoupling, the network architecture is divided into two parallel management layers, including a control management layer and a data transmission management layer. The control management layer is responsible for formulating and distributing network policies such as routing policies, access control, and load balancing. The data transmission management layer is responsible for the actual packet forwarding and processing, operating according to the policies of the control management layer.

[0059] Programming processing uses programming techniques, i.e., software-defined networking, to apply the previously defined communication logic rules to each partitioned network. After completing the programming processing of the parallel management layers, a logical management network is determined. It combines the actual topology of the physical network and logical management policies, enabling efficient utilization of network resources and ensuring the flexibility, performance, and security of the network.

[0060] Furthermore, trigger the storm control mechanism for traffic control and determine the traffic control strategy, including: Traverse the logical management network to determine the storm network partitions and determine the traffic control ratio; traverse the storm network partitions and, based on the communication logic rules of network transmission, determine the priority method of traffic control; based on the priority and the traffic control ratio, perform a traffic limiting decision analysis to determine the traffic control strategy.

[0061] Traverse the logical management network, check the status of each network node and subnet, and determine the storm network partition. The storm network partition is a specific network area in the network where an abnormal increase in data traffic is identified. The traffic control ratio refers to the ratio of traffic that needs to be restricted or allowed during a storm within the storm network partition, based on traffic characteristics and network policies. The determination of the traffic control ratio is based on an analysis of various aspects such as the current network load, terminal device types, and data transmission requirements. By setting a reasonable traffic control ratio, certain types of data packets can be restricted during a storm to ensure the normal operation of critical services with priority.

[0062] Traverse the storm network partition and analyze its internal traffic characteristics and communication behaviors. Communication logic rules are various rules applied during network transmission, which define the transmission paths, priorities, bandwidth allocations, etc. of different types of data packets. Based on the communication logic rules, determine the priority method of traffic control, that is, during a storm, set the transmission priorities for different types of data flows according to the preset communication logic rules to ensure that critical data flows can be processed first, while unimportant or secondary data flows can be delayed or restricted.

[0063] Comprehensively analyze the priority and traffic control ratio, and conduct flow-limiting decision-making analysis. Specifically, when conducting flow-limiting decision-making analysis, first, based on the priority information, analyze how to limit the flow of different types of data flows. The goal of this analysis is to ensure that high-priority data flows can be processed first in the event of a network storm or high load, while low-priority data flows can be appropriately restricted or delayed. Then, based on the traffic control ratio, determine the specific flow-limiting measures and strategies. This process includes calculating the bandwidth ratio that each type of data flow can use, deciding which traffic needs to be restricted or completely blocked, and finally determining the traffic control strategy, aiming to ensure network stability and service quality.

[0064] In summary, the terminal network security transmission method for a switch provided by the embodiments of this application has the following technical effects: Build a dual mapping module for the target switching mechanism, which can strictly screen the source address information of data packets. The first module is configured with a screening encapsulation layer, which can preliminarily filter all incoming data to ensure that only data packets meeting the security standards can enter the next step of processing, improving the network security; after receiving the source address information, through the security verification screening by the dual mapping module, it can effectively filter out insecure address information. This method combining the pre-storage screening at the first module and the mapping storage at the second module further enhances the network security; introduce software-defined network, divide and logically program the physical communication network to build a virtualized logical management network. This network not only supports the logical division of the physical network but also allows dynamic management and configuration of the network. The logical management network is scalable and can be dynamically adjusted and optimized according to actual needs to adapt to the changing network environment and business requirements; for the secure address information, combined with the logical management network, conduct real-time forwarding storm assessment, which can quickly identify possible storms in the network, such as broadcast storms, unicast storms, and multicast storms, and trigger the storm control mechanism when necessary. This can timely take traffic control measures to prevent the occurrence or spread of network storms, greatly improving the network stability and anti-attack ability; according to the storm assessment results, dynamically adjust the traffic control strategy to ensure that in the case of storms, the critical services of the network can be preferentially guaranteed. Based on the traffic control strategy, comprehensively manage the secure transmission of the terminal network to ensure that all data packets meet the preset security standards during transmission. This comprehensive management method not only protects the network security but also improves the efficiency and reliability of data transmission, providing users with higher-quality network services.

[0065] Embodiment 2, based on the same inventive concept as the method for secure transmission of the terminal network for a switch in the foregoing embodiment, as Figure 2 shown, the embodiment of the present application provides a platform for secure transmission of the terminal network for a switch, and the platform includes: Dual - mapping module construction unit 10, which is used to construct a dual - mapping module for the target switch. Among them, the dual - mapping module is determined based on the twin mapping of the built - in system module of the switch, and the first module end is configured with a screening and encapsulation layer; Security verification and screening unit 20, which is used to receive source address information, perform security verification, screening and storage based on the dual - mapping module, and determine the security address information received by the switch. Among them, the verification and screening is based on the pre - storage screening of the first module end and the mapping storage of the second module end; Logic programming unit 30, which is used to introduce software - defined network, divide and logically program the physical communication network, and determine the logical management network. Among them, the logical management network is a virtualized management network and is scalable; Forwarding storm evaluation unit 40, which is used to perform a forwarding storm evaluation based on the first time node for the security address information in combination with the logical management network, and determine the storm evaluation result. Among them, the first time node is any address forwarding time node, and the forwarding methods include broadcast, unicast and multicast packets; Flow control unit 50, which is used to identify the storm evaluation result. If the storm probability meets the probability threshold, trigger the storm control mechanism to perform flow control and determine the flow control strategy; Secure transmission management unit 60, which is used to perform terminal network secure transmission management based on the flow control strategy.

[0066] Furthermore, the platform further includes a screening and encapsulation layer determination unit to perform the following operation steps: Determine the screening methods based on terminal network security. Among them, the screening methods at least include trusted platform, permission detection, obligation detection and condition detection; Based on the MAC mode, hierarchically integrate and encapsulate the screening methods to determine the first screening and encapsulation layer; Based on the IP mode, hierarchically integrate and encapsulate the screening methods to determine the second screening and encapsulation layer; Integrate the first screening and encapsulation layer and the second screening and encapsulation layer to determine the screening and encapsulation layer.

[0067] Furthermore, configure the screening and encapsulation layer at the first module end, where the first module end is the pre - interaction system module of the dual - mapping module.

[0068] Furthermore, the platform further includes a mapping storage unit to perform the following operation steps: Receive the source address information, temporarily store the source address information at the first module end; based on the screening encapsulation layer configured at the first module end, perform network security verification and screening on the source address information to determine valid address information, where the verification method is any one or at least one of the MAC mode and the IP mode; based on the mapping relationship between the first module end and the second module end, map and store the valid address information at the second module end, and delete the source address information stored at the first module end.

[0069] Furthermore, the platform further includes a logical management network construction unit to perform the following operation steps: Traverse the physical communication network, divide the physical communication network based on the communication characteristics of the communication terminals, and determine multiple divided networks; traverse the multiple divided networks, determine the communication logic rules; map the multiple divided networks and the communication logic rules to construct the logical management network.

[0070] Furthermore, the platform further includes a logical management network determination unit to perform the following operation steps: Map the multiple divided networks and the communication logic rules to determine the initialization management network; traverse the initialization management network, decouple and separate the control plane and the data plane to determine the parallel management layer, where the parallel management layer includes a control management layer and a data transmission management layer; traverse the parallel management layer, perform programming processing on the communication logic rules mapped by the divided networks within the layer to determine the logical management network.

[0071] Furthermore, the platform further includes a traffic control policy determination unit to perform the following operation steps: Traverse the logical management network, determine the storm network partition, and determine the traffic control ratio; traverse the storm network partition, determine the priority method of traffic control based on the communication logic rules of network transmission; based on the priority and the traffic control ratio, perform throttling decision analysis to determine the traffic control policy.

[0072] Through the foregoing detailed description of the terminal network security transmission method for a switch in this specification, those skilled in the art can clearly know the terminal network security transmission platform for a switch in this embodiment. Since it corresponds to the method disclosed in the embodiment, it is described relatively simply. For related parts, refer to the description in the method section.

[0073] The foregoing description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A terminal network security transmission method for a switch, characterized in that The method includes: For a target switch, a dual mapping module is constructed, where the dual mapping module is determined based on the twin mapping of the built-in system module of the switch, and a screening encapsulation layer is configured at the first module end; Receive source address information, perform security verification screening and storage based on the dual mapping module to determine the secure address information received by the switch, where the verification screening is based on the pre-storage screening at the first module end and the mapping storage at the second module end; Introduce software-defined network, partition and logically program the physical communication network to determine the logical management network, where the logical management network is a virtualized management network and is scalable; For the secure address information, in combination with the logical management network, perform a forwarding storm assessment based on the first time node to determine the storm assessment result, where the first time node is any address forwarding time node, and the forwarding methods include broadcast, unicast, and multicast packets; Identify the storm assessment result, if the storm probability meets the probability threshold, trigger the storm control mechanism for traffic control to determine the traffic control strategy; Based on the traffic control strategy, perform terminal network security transmission management.

2. The terminal network security transmission method for a switch according to claim 1, characterized in that, Configure the screening encapsulation layer, including: Determine the screening method based on terminal network security, where the screening method includes at least a trusted platform, permission detection, obligation detection, and condition detection; Taking the MAC mode as a benchmark, perform hierarchical integration and encapsulation on the screening method to determine the first screening encapsulation layer; Taking the IP mode as a benchmark, perform hierarchical integration and encapsulation on the screening method to determine the second screening encapsulation layer; Integrate the first screening encapsulation layer and the second screening encapsulation layer to determine the screening encapsulation layer.

3. The terminal network security transmission method for a switch according to claim 2, characterized in that, Configure the screening encapsulation layer at the first module end, where the first module end is the pre-interaction system module of the dual mapping module.

4. The terminal network security transmission method for a switch according to claim 1, characterized in that Performing security verification screening and storage based on the dual mapping module includes: Receive the source address information and temporarily store the source address information at the first module end; Based on the screening encapsulation layer configured at the first module end, perform network security verification and screening on the source address information to determine the valid address information, where the verification method is any one or at least one of the MAC mode and the IP mode; Based on the mapping relationship between the first module end and the second module end, map and store the valid address information at the second module end, and delete the source address information stored at the first module end.

5. The terminal network security transmission method for a switch according to claim 1, characterized in that, The determination of the logical management network includes: Traverse the physical communication network, and based on the communication characteristics of the communication terminals, partition the physical communication network to determine multiple partition networks; Traverse the multiple partition networks to determine the communication logic rules; Map the multiple partition networks and the communication logic rules to construct the logical management network.

6. The terminal network security transmission method for a switch according to claim 5, wherein Mapping the multiple partition networks and the communication logic rules to construct the logical management network includes: Map the multiple partition networks and the communication logic rules to determine the initialization management network; Traverse the initialized management network, decouple and separate the control plane and the data plane, and determine the parallel management layer, where the parallel management layer includes a control management layer and a data transmission management layer; Traverse the parallel management layer, program the communication logic rules for partitioning the network mapping within the layer, and determine the logical management network.

7. The terminal network security transmission method for a switch according to claim 1, wherein Trigger the storm control mechanism for traffic control, and determine the traffic control strategy, including: Traverse the logical management network, determine the storm network partition, and determine the traffic control ratio; Traverse the storm network partition, and determine the priority mode of traffic control based on the communication logic rules of network transmission; Based on the priority and the traffic control ratio, perform throttling decision analysis to determine the traffic control strategy.

8. A terminal network security transmission platform for a switch, characterized in that, For implementing the terminal network security transmission method for a switch according to any one of claims 1-7, the platform includes: A dual mapping module construction unit, which is used to construct a dual mapping module for the target switch, where the dual mapping module is determined based on the twin mapping of the built-in system module of the switch, and the first module end is configured with a screening encapsulation layer; A security verification and screening unit, which is used to receive the source address information, perform security verification and screening and storage based on the dual mapping module, and determine the security address information received by the switch, where the verification and screening is based on the pre-storage screening of the first module end and the mapping storage of the second module end; A logical programming unit, which is used to introduce software-defined network, partition and logically program the physical communication network, and determine the logical management network, where the logical management network is a virtualized management network and is scalable; A forwarding storm evaluation unit, which is used to perform a forwarding storm evaluation based on the first time node for the security address information in combination with the logical management network, and determine the storm evaluation result, where the first time node is any address forwarding time node, and the forwarding methods include broadcast, unicast and multicast packets; A traffic control unit, which is used to identify the storm evaluation result, and if the storm probability meets the probability threshold, trigger the storm control mechanism for traffic control and determine the traffic control strategy; A security transmission management unit, which is used to perform terminal network security transmission management based on the traffic control strategy.

Citation Information

Patent Citations

  • Method and system for implementation of safety resource pool based on SDN

    CN107911258A

  • Network area boundary security protection system, method and equipment

    CN111711616A

  • Network configuration management method and device, program product and medium

    CN119402345A

  • End-to-end traffic health management storm control method and device, equipment and storage medium

    CN119496726A

  • Method and system for IP address virtualization in SDN-based network virthalization platform

    KR101794719B1