Terminal network security transmission method and platform for switch

By constructing a dual-mapping module in the switch and introducing software-defined networking, combined with screening encapsulation layer and flow control strategies, the security problems of traditional network management methods in dynamic environments are solved, and efficient, reliable and secure network transmission is achieved.

CN120342772BActive Publication Date: 2026-06-02QIDONG SHUJIE SOFTWARE ENGINEERING CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
QIDONG SHUJIE SOFTWARE ENGINEERING CO LTD
Filing Date
2025-06-06
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Traditional network security management methods rely on fixed rules and static security policies, which are difficult to cope with dynamically changing network environments, resulting in poor security during data transmission.

Method used

A dual-mapping module based on the switch's built-in system modules is constructed. Combining the screening encapsulation layer and software-defined networking, it performs security verification screening, logical programming, and forwarding storm assessment, triggers traffic control policies, and dynamically adjusts network management.

Benefits of technology

It improves network security and stability, enables timely identification and prevention of network storms, ensures the normal transmission of critical business operations, and enhances the efficiency and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342772B_ABST
    Figure CN120342772B_ABST
Patent Text Reader

Abstract

The application provides a terminal network security transmission method and platform for an exchange, relates to the technical field of security transmission, and comprises the following steps: for a target exchange, a double-mapping module is constructed, and a screening encapsulation layer is configured at the first module end; source address information is received, security check screening and storage are performed, and safe address information is determined; a software-defined network is introduced, a physical communication network is divided and logically programmed, and a logical management network is determined; a forwarding storm evaluation based on a first time node is performed, and a storm evaluation result is determined; if the storm probability meets a probability threshold value, a storm control mechanism is triggered to perform flow control, and a flow control strategy is determined; and terminal network security transmission management is performed. The application solves the technical problem that the conventional network security management method usually relies on fixed rules and static security strategies, is difficult to adjust and respond to a dynamically changing network environment in time, and results in poor security in the data transmission process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of secure transmission technology, and more specifically to a method and platform for secure terminal network transmission for switches. Background Technology

[0002] As networks grow in scale and complexity, especially in enterprise and data center environments, they face increasing security challenges. Existing switches and network management methods have some limitations in addressing these challenges. On the one hand, with the diversification of network devices and terminals, network security threats are constantly increasing. These threats exploit the openness and complexity of networks, often infiltrating them through methods such as source address spoofing and broadcast storms, which existing single security mechanisms struggle to effectively counter. On the other hand, traditional network management methods typically rely on fixed rules and static security policies, which are difficult to adjust and respond to in a timely manner when facing dynamically changing network environments, leading to security vulnerabilities in data transmission. Summary of the Invention

[0003] This application provides a terminal network security transmission method and platform for switches, aiming to solve the technical problem that traditional network security management methods usually rely on fixed rules and static security policies, which are difficult to adjust and respond to in a timely manner in the face of dynamically changing network environments, resulting in poor security in the data transmission process.

[0004] The first aspect disclosed in this application provides a method for secure transmission of terminal network for a switch. The method includes: constructing a dual-mapping module for a target switch, wherein the dual-mapping module is determined based on a twin mapping of the switch's built-in system modules, and a screening and encapsulation layer is configured on the first module end; receiving source address information, performing security verification screening and storage based on the dual-mapping module, and determining secure address information received by the switch, wherein the verification screening is based on the pre-stored screening on the first module end and the mapping storage on the second module end; introducing a software-defined network to divide and logically program the physical communication network, determining a logical management network, wherein the logical management network is a virtualized management network and is scalable; performing a forwarding storm assessment based on a first time node for the secure address information, combined with the logical management network, and determining a storm assessment result, wherein the first time node is any address forwarding time node, and the forwarding method includes broadcast, unicast, and multicast packets; identifying the storm assessment result, and if the storm probability meets a probability threshold, triggering a storm control mechanism to perform flow control and determining a flow control strategy; and performing secure transmission management of the terminal network based on the flow control strategy.

[0005] The second aspect of this application discloses a terminal network security transmission platform for a switch. The platform is used in the aforementioned terminal network security transmission method for a switch. The platform includes: a dual-mapping module construction unit, which constructs a dual-mapping module for a target switch, wherein the dual-mapping module is determined based on a twin mapping of the switch's built-in system modules, and a screening and encapsulation layer is configured on the first module end; a security verification and screening unit, which receives source address information, performs security verification and screening based on the dual-mapping module, and determines the security address information received by the switch, wherein the verification and screening is based on the pre-stored screening on the first module end and the mapping storage on the second module end; and a logic programming unit, which introduces software definition. The system comprises: a network, which divides and logically programs the physical communication network to determine a logical management network, wherein the logical management network is a virtualized management network and is scalable; a forwarding storm assessment unit, which performs a forwarding storm assessment based on a first time node, taking into account the secure address information and the logical management network, and determines the storm assessment result, wherein the first time node is any address forwarding time node, and the forwarding method includes broadcast, unicast, and multicast packets; a traffic control unit, which identifies the storm assessment result, and if the storm probability meets a probability threshold, triggers a storm control mechanism to perform traffic control and determines a traffic control strategy; and a secure transmission management unit, which performs secure transmission management for the terminal network based on the traffic control strategy.

[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0007] A dual-mapping module is constructed for the target switch, enabling strict security screening of the source address information of data packets. The first module is equipped with a screening and encapsulation layer, which performs preliminary filtering on all incoming data, ensuring that only data packets that meet security standards can proceed to the next stage of processing, thus improving network security. After receiving the source address information, the security verification and screening performed by the dual-mapping module effectively filters out insecure address information. This combination of the first module's initial screening and the second module's mapping storage further enhances network security. Software-defined networking is introduced, dividing and logically programming the physical communication network to construct a virtualized logical management network. This network not only supports the logical division of the physical network but also allows for dynamic management and configuration. The logical management network is scalable and can be dynamically adjusted according to actual needs. Adjustments and optimizations are made to adapt to the ever-changing network environment and business needs. Based on secure address information and combined with logical network management, real-time forwarding storm assessments are performed, enabling rapid identification of potential network storms, such as broadcast storms, unicast storms, and multicast storms. Storm control mechanisms are triggered when necessary, allowing for timely traffic control measures to prevent the occurrence or spread of network storms, significantly improving network stability and attack resistance. Based on storm assessment results, traffic control strategies are dynamically adjusted to ensure that critical network services are prioritized during storms. Based on traffic control strategies, comprehensive management of secure transmission on the terminal network ensures that all data packets comply with preset security standards during transmission. This comprehensive management approach not only protects network security but also improves data transmission efficiency and reliability, providing users with higher-quality network services.

[0008] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0009] Figure 1 A schematic flowchart of a terminal network security transmission method for a switch provided in an embodiment of this application;

[0010] Figure 2 This is a schematic diagram of a terminal network security transmission platform structure for a switch provided in an embodiment of this application.

[0011] Figure labeling: Dual mapping module construction unit 10, security verification and screening unit 20, logic programming unit 30, forwarding storm assessment unit 40, traffic control unit 50, secure transmission management unit 60. Detailed Implementation

[0012] This application provides a terminal network security transmission method and platform for switches, which solves the technical problem that traditional network security management methods usually rely on fixed rules and static security policies, making it difficult to adjust and respond in a timely manner to dynamically changing network environments, resulting in poor security during data transmission.

[0013] After introducing the basic principles of this application, various non-limiting embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.

[0014] Example 1, as Figure 1 As shown in the figure, this application provides a method for secure terminal network transmission for a switch, the method comprising:

[0015] For the target switch, a dual mapping module is constructed, wherein the dual mapping module is determined based on the twin mapping of the switch's built-in system modules, and the first module is configured with a screening encapsulation layer.

[0016] The target switch is identified, and a dual-mapping module is constructed based on the switch's built-in system modules using a twin mapping approach. The dual-mapping module consists of two parts: a first module end and a second module end. The first module end is used for preliminary data screening and security verification, while the second module end is used for storing and managing the screened security data. The collaborative work of the two modules can enhance network security and management efficiency.

[0017] Based on the characteristics of the switch's built-in system modules, a twin mapping is performed. Specifically, by analyzing the functions and data flows of the switch's built-in modules, a corresponding twin module is constructed to obtain a dual-mapping module. This ensures that the new dual-mapping module is seamlessly integrated with the switch's existing functions and can update and synchronize data in real time.

[0018] The first module is equipped with a screening and encapsulation layer, which is a logical layer responsible for preliminary screening and filtering. It is used to check the address information and data packets received from the network to determine whether they are safe and trustworthy. This layer can be based on different screening methods, including at least trusted platform, permission detection, obligation detection and condition detection.

[0019] The source address information is received, and security verification screening and storage are performed based on the dual mapping module to determine the security address information received by the switch. The verification screening is based on the first module's storage screening and the mapping storage on the second module.

[0020] When a switch receives data packets from the network, it extracts the source address information from these packets, which typically includes the MAC address and IP address. The MAC address is used for communication at the data link layer, while the IP address is used for communication at the network layer.

[0021] After receiving the source address information, the constructed dual-mapping module is used to perform security verification, screening, and storage operations. Specifically, when the source address information of a data packet enters the switch, it is first passed to the first module of the dual-mapping module. Here, the source address information is temporarily stored for further screening. The first module is configured with a screening encapsulation layer. This layer performs network security verification and screening on the stored source address information according to a preset security policy. The security policy may include MAC address whitelists, IP address blacklists, specific protocol checks, etc. Through these policies, the first module can quickly filter out the source addresses of data packets that do not meet security requirements and retain valid address information.

[0022] Then, the first module maps and stores the valid address information to the second module. The mapping and storage process includes transmitting data from the first module to the second module and storing it in a specific data structure on the second module. The second module is responsible for maintaining and managing this valid address information, so that the switch can quickly and accurately find and use this information in subsequent packet processing and forwarding.

[0023] Software-defined networking is introduced to divide and logically program the physical communication network, thereby determining the logical management network. The logical management network is a virtualized management network and is scalable.

[0024] Software-defined networking (SDN) is a network management approach that allows network behavior and rules to be defined through software programming. It decouples the network's control layer (control plane) from the data forwarding layer (data plane), making network management more flexible and centralized. A physical communication network is the actual network structure comprised of network devices and links, such as switches, routers, and physical cables.

[0025] After software-defined networking takes over the control plane in the network, it divides a large physical communication network into multiple smaller logical networks through software programming. These logical networks are divided based on different criteria, such as departments, functions, business requirements, etc.

[0026] Then, specific behaviors and management rules are defined for each logical network programmatically. These rules can include routing policies, access control policies, traffic priorities, etc. This logical programming allows each logical network to operate independently, customized and optimized according to actual needs, without being limited by the physical network topology. This approach provides the network with greater flexibility and manageability.

[0027] After being partitioned and logically programmed, the physical communication network is transformed into a virtualized logical management network. This logical management network consists of multiple independent logical subnets, each with its own control and management rules. The logical management network is a virtualized management network because it is independent of the actual connection of the physical network and is defined and managed by software. This virtualized network can flexibly adjust its topology and management rules as needed to adapt to ever-changing network requirements.

[0028] Furthermore, since logical management networks are defined and controlled by software, they are highly scalable. Network administrators can dynamically add or remove logical subnets or adjust network management rules according to actual needs without making large-scale changes to physical network devices. This flexibility improves the adaptability and scalability of the network.

[0029] Based on the secure address information and the logical management network, a forwarding storm assessment is performed based on a first time node to determine the storm assessment result. Here, the first time node is any address forwarding time node, and the forwarding method includes broadcast, unicast, and multicast packets.

[0030] A time node refers to the point in time when a switch processes a data packet during the forwarding process. The arrival, processing, and forwarding of each data packet can be considered a time node. A random sample can be extracted for analysis and designated as the first time node. A forwarding storm refers to a situation where network devices receive a large number of broadcast, unicast, or multicast packets within a short period, limiting the device's forwarding capacity, saturating network bandwidth, and ultimately leading to network performance degradation or even paralysis.

[0031] At the first point in time, the switch collects and analyzes traffic data from each port in real time through its built-in monitoring module, especially the number and type of broadcast, unicast, and multicast packets. Based on the actual needs of the network and historical data, it sets detection thresholds for forwarding storms, such as the maximum number of broadcast packets allowed per second. These thresholds can be dynamically adjusted according to network load and changes. Based on the detection thresholds, the current network status is assessed to detect whether abnormal traffic is occurring. Through the network status assessment, a storm assessment result is generated, which includes the current network traffic status and a risk assessment of potential storms.

[0032] The storm assessment results are identified. If the storm probability meets the probability threshold, the storm control mechanism is triggered to perform traffic control and determine the traffic control strategy.

[0033] Storm probability is the likelihood of a forwarding storm occurring in the network. This probability is calculated based on real-time traffic data, historical traffic patterns, and a preset storm detection threshold. The calculated storm probability is compared with the preset probability threshold, which is set according to network capacity and historical data. This threshold is used to determine whether there is sufficient storm risk to take action. If the storm probability meets or exceeds the preset probability threshold, the switch immediately triggers the storm control mechanism. The activation of this mechanism means that there is a potential risk in the current traffic situation, which may lead to a decrease in network performance or even paralysis, requiring protective measures to be taken.

[0034] Determine traffic control strategies, including limiting forwarding rates, adjusting priorities, and blocking data streams. Specifically, adjust priorities by setting higher forwarding priorities for important unicast traffic to ensure that critical business traffic is not affected; block specific data streams by temporarily blocking them when abnormal data streams from certain source or destination addresses are detected to prevent them from triggering a storm.

[0035] Based on the aforementioned traffic control strategy, terminal network security transmission management is performed.

[0036] Based on a defined flow control policy, the control switch dynamically adjusts its internal forwarding rules and flow management algorithms to execute the flow control policy, ensuring that legitimate and critical data flows can continue to be transmitted securely when the network is affected by abnormal traffic. During this process, the switch continuously monitors network traffic conditions and overall performance. Based on real-time monitoring data, it can determine the effectiveness of the flow control policy. If certain policies have an unsatisfactory impact on network performance, or if new abnormal traffic occurs, the switch can dynamically adjust these policies to ensure the continued stable operation of the network.

[0037] Furthermore, configuring the screening encapsulation layer includes:

[0038] A screening method based on terminal network security is determined, wherein the screening method includes at least trusted platform, permission detection, obligation detection and condition detection; the screening method is layered, integrated and encapsulated based on MAC mode to determine a first screening encapsulation layer; the screening method is layered, integrated and encapsulated based on IP mode to determine a second screening encapsulation layer; the first screening encapsulation layer and the second screening encapsulation layer are integrated to determine the screening encapsulation layer.

[0039] To ensure network security, rigorous screening of incoming traffic is necessary. The screening method is designed to verify and filter data packets through a multi-layered inspection mechanism, preventing illegitimate traffic from entering the network. Screening methods include at least trusted platforms, permission checks, obligation checks, and condition checks. Trusted platforms verify the trustworthiness of terminal devices, ensuring they are authenticated and not controlled by malicious software or users. Trusted platform screening can be achieved through technologies such as hardware roots of trust and software signature verification. Permission checks examine the access permissions of terminal users or devices, ensuring they have the appropriate permissions to access specific network resources or perform specific operations. Permission checks can be based on user authentication and access control lists. Obligation checks confirm whether terminal devices or users meet specific obligations or conditions, such as compliance requirements, usage policies, or network behavior guidelines. This type of check can be implemented through policy management and compliance tools. Condition checks examine the behavior of terminal devices or users based on real-time network and environmental conditions. For example, based on network load, device geographic location, and time, they determine whether to allow specific network operations.

[0040] MAC mode is a screening and filtering method based on the Media Access Control address (MAC address) at the data link layer. The MAC address is the physical address of a network device and is used for communication between devices in a local area network. In MAC mode, screening mainly targets the source MAC address and destination MAC address of the data packet to determine whether these addresses are within the allowed range.

[0041] Based on MAC mode, different screening methods, including trusted platform, permission detection, obligation detection, and condition detection, are layered and combined. Each layer of screening methods targets specific security needs and is performed sequentially in a specific order. The purpose of layering is to ensure that each security check step can be performed independently and that the results complement each other to form a complete security check process. Then, all layered screening methods are uniformly encapsulated in a logically independent encapsulation layer. The role of the encapsulation layer is to integrate all screening methods into an executable security module, which is convenient for the switch to call during packet processing. Finally, the first screening encapsulation layer based on MAC mode is obtained. The first screening encapsulation layer is mainly responsible for security checks based on MAC addresses.

[0042] IP mode is a method of screening and filtering based on IP addresses at the network layer. IP addresses are used to identify the location and identity of each device in the network and are the core identifier of Internet communication. In IP mode, screening mainly targets the source IP address and destination IP address of data packets to determine whether these addresses are within the allowed range and to ensure that they comply with network security policies.

[0043] Based on the IP model, different screening methods, including trusted platforms, permission checks, obligation checks, and condition checks, are layered and combined. Similarly, all the layered screening methods are uniformly encapsulated in a logically independent encapsulation layer to obtain the second screening encapsulation layer based on the IP model. The second screening encapsulation layer is mainly responsible for security checks based on IP addresses.

[0044] The first screening encapsulation layer and the second screening encapsulation layer are integrated. During the integration process, the data processing priority can be arranged. For example, MAC mode screening can be performed first, followed by IP mode screening. This priority setting can be adjusted according to the actual needs of the network, ultimately forming a complete screening encapsulation layer. This integration process aims to achieve comprehensive screening and verification of data packets through a multi-layered, multi-mode security inspection mechanism.

[0045] Furthermore, the screening encapsulation layer is configured on the first module end, wherein the first module end is the first interaction system module of the dual mapping module.

[0046] The first module is the first interactive system module of the dual mapping module, which is responsible for initially receiving and processing all data packets entering the switch. By configuring a screening encapsulation layer on the first module, strict security checks can be implemented in the initial stage of data packet processing, thereby effectively filtering out all traffic that does not meet security requirements and only allowing verified legitimate data packets to enter the next processing step.

[0047] Furthermore, security verification, screening, and storage based on the dual mapping module include:

[0048] The system receives the source address information and temporarily stores it in the first module. Based on the screening and encapsulation layer configured in the first module, it performs network security verification and screening on the source address information to determine valid address information. The verification method is either MAC mode or IP mode. Based on the mapping relationship between the first module and the second module, the valid address information is mapped and stored in the second module, and the source address information stored in the first module is deleted.

[0049] When data packets arrive at the switch, the first module receives them. These packets contain various information, including the source address information: the sender's MAC address and / or IP address. The MAC address is used for data link layer communication, while the IP address is used for network layer communication. After receiving the source address information, the first module temporarily stores this information in an internal fast storage area. This temporary storage is intended to preserve the original information of the data packets before security screening.

[0050] After the source address information is temporarily stored, the first module calls various security screening mechanisms in the screening and encapsulation layer to verify and filter the source address information layer by layer. Specifically, at the data link layer, screening and filtering are performed based on MAC addresses, and at the network layer, screening and filtering are performed based on IP addresses. After multi-level verification by the screening and encapsulation layer, valid address information, that is, address information that meets network security requirements, is determined. These addresses can continue to enter the next step of the network processing flow.

[0051] In the dual-mapping module, there is a mapping relationship between the first module and the second module. This relationship is to ensure that data and state remain synchronized and consistent between the two modules. The mapping relationship can be implemented through a specific data structure to ensure that information is not lost or tampered with during transmission.

[0052] After confirming the valid address information, the first module maps and stores this information to the second module. The mapping and storage process includes transmitting data from the first module to the second module and storing it in a specific data structure on the second module. The second module is responsible for maintaining and managing this valid address information, so that the switch can quickly and accurately find and use this information in subsequent packet processing and forwarding.

[0053] After confirming that the valid address information is stored in the second module, the source address information is deleted from the temporary storage area of ​​the first module. This operation aims to clean up the storage space of the first module and prevent the accumulation of invalid data. By timely deleting the source address information that has been processed, storage resources can be released, and the processing efficiency and performance of the first module can be improved.

[0054] Furthermore, the determination logic management network includes:

[0055] The physical communication network is traversed, and based on the communication characteristics of the communication terminals, the physical communication network is divided to determine multiple partitioned networks; the multiple partitioned networks are traversed to determine communication logic rules; the multiple partitioned networks are mapped to the communication logic rules to construct the logic management network.

[0056] A physical communication network is a network structure consisting of actual network devices and links, such as switches, routers, and physical connection cables. The process involves traversing the physical communication network and examining and analyzing each network device and its connection method.

[0057] The communication characteristics of a communication terminal refer to the behavior and features of devices connected to a network, such as computers, mobile phones, and IoT devices, in network communication. These features include device type, communication protocol used, data transmission rate, quality of service requirements, and geographical location.

[0058] During network partitioning, based on these communication characteristics, the physical communication network is divided into multiple subnetworks. The principle of partitioning is to assign terminal devices with similar communication characteristics or similar needs to the same subnetwork for better targeted management. For example, terminal devices with high bandwidth requirements (such as video streaming servers) are assigned to one network, while terminal devices with low latency requirements (such as real-time communication devices) are assigned to another network. Through the partitioning of the physical communication network, multiple partitioned networks are ultimately determined, each containing a group of terminal devices with similar communication characteristics.

[0059] After the network partitioning is determined, each partition is traversed and analyzed. This traversal process mainly involves checking the internal topology, device type, number of terminals, data traffic characteristics, etc. of each partition to determine the specific characteristics of each partition.

[0060] Communication logic rules refer to the strategies and rules for managing and optimizing network communication within a segmented network. Based on the specific characteristics of each segmented network, corresponding logic rules are formulated to optimize network performance and security. For example, communication rules are formulated based on the type of terminal device, such as computers and mobile devices. For instance, higher bandwidth and lower latency communication paths are allocated to high-priority terminal devices. By analyzing data traffic characteristics, load balancing and flow control strategies are developed to avoid network overload and congestion. For example, in high-traffic segmented networks, dynamic flow control and load balancing strategies are employed to ensure stable network operation. By formulating communication logic rules for segmented networks, distributed and targeted management can be achieved.

[0061] By mapping multiple partitioned networks to their corresponding communication logic rules, a logical management network is constructed. This process establishes a correspondence between partitioned networks and communication logic rules, enabling each partitioned network to apply corresponding management strategies based on its specific attributes and operate according to predetermined rules.

[0062] Furthermore, mapping the multiple partitioning networks to the communication logic rules to construct the logical management network includes:

[0063] Map the multiple partitioned networks to the communication logic rules to determine the initialization management network; traverse the initialization management network to decouple the control plane and data plane to determine the parallel management layer, wherein the parallel management layer includes the control management layer and the data transmission management layer; traverse the parallel management layer and program the communication logic rules mapped by the partitioned networks within the layer to determine the logic management network.

[0064] Multiple partitioned networks are mapped to communication logic rules. The mapping process involves associating each partitioned network with its corresponding communication logic rule. This process ensures that each network operates according to its characteristics, forming an initial management network as the initial network management state.

[0065] The initialization and management network is traversed to check its configuration and operational status. The purpose of this traversal is to determine the role, connection status, and data flow direction of each network node. The control plane is responsible for managing the configuration and operation of network devices, controlling the routing and scheduling of network traffic, while the data plane is responsible for the actual packet forwarding and processing, serving as the main path for data flow. In traditional network architectures, the control plane and data plane are tightly coupled, which limits the network's flexibility and scalability. Decoupling separates the control plane and data plane into independent management layers, allowing network administrators to manage network policies and data flow paths separately, increasing network flexibility and responsiveness.

[0066] By decoupling and separating, the network architecture is divided into two parallel management layers: a control management layer and a data transmission management layer. The control management layer is responsible for formulating and issuing network policies, such as routing policies, access control, and load balancing. The data transmission management layer is responsible for the actual packet forwarding and processing, and operates according to the policies of the control management layer.

[0067] Programming processing utilizes programming techniques, namely software-defined networking, to apply previously defined communication logic rules to each partitioned network. After completing the programming processing of the parallel management layer, the logical management network is determined. It combines the actual topology of the physical network with logical management strategies, enabling efficient use of network resources and ensuring network flexibility, performance, and security.

[0068] Furthermore, triggering the storm control mechanism to perform traffic control and determining the traffic control strategy includes:

[0069] Traverse the logical management network to determine the storm network partition and the flow control ratio; traverse the storm network partition and determine the flow control priority method based on the communication logic rules of network transmission; perform flow limiting decision analysis based on the priority and the flow control ratio to determine the flow control strategy.

[0070] The logical management network is traversed, and the status of each network node and subnet is checked to identify storm network partitions. A storm network partition is a specific network area identified as experiencing an abnormal increase in data traffic. The traffic control ratio refers to the proportion of traffic that needs to be restricted or allowed during a storm within the storm network partition, based on traffic characteristics and network policies. Determining the traffic control ratio is based on analysis of current network load, terminal device types, data transmission requirements, and other factors. By setting a reasonable traffic control ratio, certain types of data packets can be restricted during a storm, prioritizing the normal operation of critical services.

[0071] Traverse the storm network partitions and analyze their internal traffic characteristics and communication behaviors. Communication logic rules are various rules applied during network transmission. These rules define the transmission paths, priorities, bandwidth allocation, etc. of different types of data packets. Based on the communication logic rules, determine the priority method of flow control. That is, when a storm occurs, according to the preset communication logic rules, the transmission priority of different types of data streams is set to ensure that critical data streams can be processed first when a storm occurs, while unimportant or secondary data streams can be delayed or restricted.

[0072] By comprehensively analyzing the priority and flow control ratio, a flow limiting decision analysis is conducted. Specifically, the flow limiting decision analysis first analyzes how to limit different types of data flows based on priority information. The goal of this analysis is to ensure that high-priority data flows can be processed first under network storms or high load conditions, while low-priority data flows can be appropriately restricted or delayed. Then, based on the flow control ratio, specific flow limiting measures and strategies are determined. This process includes calculating the bandwidth ratio that each type of data flow can use, deciding which traffic needs to be restricted or completely blocked, and finally determining the flow control strategy, which aims to ensure network stability and service quality.

[0073] In summary, the terminal network security transmission method for switches provided in this application has the following technical effects:

[0074] A dual-mapping module is constructed for the target switch, enabling strict security screening of the source address information of data packets. The first module is equipped with a screening and encapsulation layer, which performs preliminary filtering on all incoming data, ensuring that only data packets that meet security standards can proceed to the next stage of processing, thus improving network security. After receiving the source address information, the security verification and screening performed by the dual-mapping module effectively filters out insecure address information. This combination of the first module's initial screening and the second module's mapping storage further enhances network security. Software-defined networking is introduced, dividing and logically programming the physical communication network to construct a virtualized logical management network. This network not only supports the logical division of the physical network but also allows for dynamic management and configuration. The logical management network is scalable and can be dynamically adjusted according to actual needs. Adjustments and optimizations are made to adapt to the ever-changing network environment and business needs. Based on secure address information and combined with logical network management, real-time forwarding storm assessments are performed, enabling rapid identification of potential network storms, such as broadcast storms, unicast storms, and multicast storms. Storm control mechanisms are triggered when necessary, allowing for timely traffic control measures to prevent the occurrence or spread of network storms, significantly improving network stability and attack resistance. Based on storm assessment results, traffic control strategies are dynamically adjusted to ensure that critical network services are prioritized during storms. Based on traffic control strategies, comprehensive management of secure transmission on the terminal network ensures that all data packets comply with preset security standards during transmission. This comprehensive management approach not only protects network security but also improves data transmission efficiency and reliability, providing users with higher-quality network services.

[0075] Example 2, based on the same inventive concept as the terminal network security transmission method for switches in the foregoing examples, such as... Figure 2 As shown in the embodiment of this application, a terminal network security transmission platform for a switch is provided, the platform comprising:

[0076] A dual-mapping module construction unit 10 is used to construct a dual-mapping module for a target switch. The dual-mapping module is determined based on the twin mapping of the switch's built-in system modules, and the first module is configured with a screening and encapsulation layer. A security verification and screening unit 20 is used to receive source address information, perform security verification and screening based on the dual-mapping module, and determine the security address information received by the switch. The verification and screening is based on the first module's pre-stored screening and the mapping storage at the second module. A logic programming unit 30 is used to introduce software-defined networking, divide and logically program the physical communication network, and determine the logical management network. The logical management network is a virtualized management network and is scalable; the forwarding storm assessment unit 40 is used to perform a forwarding storm assessment based on a first time node for the secure address information and the logical management network, and determine the storm assessment result, wherein the first time node is any address forwarding time node, and the forwarding method includes broadcast, unicast and multicast packets; the traffic control unit 50 is used to identify the storm assessment result, and if the storm probability meets the probability threshold, trigger the storm control mechanism to perform traffic control and determine the traffic control strategy; the secure transmission management unit 60 is used to perform terminal network security transmission management based on the traffic control strategy.

[0077] Furthermore, the platform also includes a screening and encapsulation layer determination unit to perform the following operational steps:

[0078] A screening method based on terminal network security is determined, wherein the screening method includes at least trusted platform, permission detection, obligation detection and condition detection; the screening method is layered, integrated and encapsulated based on MAC mode to determine a first screening encapsulation layer; the screening method is layered, integrated and encapsulated based on IP mode to determine a second screening encapsulation layer; the first screening encapsulation layer and the second screening encapsulation layer are integrated to determine the screening encapsulation layer.

[0079] Furthermore, the screening encapsulation layer is configured on the first module end, wherein the first module end is the first interaction system module of the dual mapping module.

[0080] Furthermore, the platform also includes a mapping storage unit to perform the following operational steps:

[0081] The system receives the source address information and temporarily stores it in the first module. Based on the screening and encapsulation layer configured in the first module, it performs network security verification and screening on the source address information to determine valid address information. The verification method is either MAC mode or IP mode. Based on the mapping relationship between the first module and the second module, the valid address information is mapped and stored in the second module, and the source address information stored in the first module is deleted.

[0082] Furthermore, the platform also includes a logical management network construction unit to perform the following operational steps:

[0083] The physical communication network is traversed, and based on the communication characteristics of the communication terminals, the physical communication network is divided to determine multiple partitioned networks; the multiple partitioned networks are traversed to determine communication logic rules; the multiple partitioned networks are mapped to the communication logic rules to construct the logic management network.

[0084] Furthermore, the platform also includes a logic management network determination unit to perform the following operational steps:

[0085] Map the multiple partitioned networks to the communication logic rules to determine the initialization management network; traverse the initialization management network to decouple the control plane and data plane to determine the parallel management layer, wherein the parallel management layer includes the control management layer and the data transmission management layer; traverse the parallel management layer and program the communication logic rules mapped by the partitioned networks within the layer to determine the logic management network.

[0086] Furthermore, the platform also includes a traffic control policy determination unit to perform the following operational steps:

[0087] Traverse the logical management network to determine the storm network partition and the flow control ratio; traverse the storm network partition and determine the flow control priority method based on the communication logic rules of network transmission; perform flow limiting decision analysis based on the priority and the flow control ratio to determine the flow control strategy.

[0088] Through the foregoing detailed description of the terminal network security transmission method for a switch, those skilled in the art can clearly understand the terminal network security transmission platform for a switch in this embodiment. Since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and relevant parts can be referred to the method section.

[0089] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A terminal network security transmission method for a switch, characterized by, The method includes: For the target switch, a dual mapping module is constructed, wherein the dual mapping module is determined based on the twin mapping of the switch's built-in system modules, and the first module is configured with a screening encapsulation layer. The source address information is received, and security verification screening and storage are performed based on the dual mapping module to determine the security address information received by the switch. The verification screening is based on the first module's first storage screening and the mapping storage on the second module. Software-defined networking is introduced to divide and logically program the physical communication network, thereby determining a logical management network. The logical management network is a virtualized management network and is scalable. Based on the secure address information and the logical management network, a forwarding storm assessment is performed based on the first time node to determine the storm assessment result. The first time node is any address forwarding time node, and the forwarding method includes broadcast, unicast, and multicast packets. The storm assessment result is identified. If the storm probability meets the probability threshold, the storm control mechanism is triggered to perform traffic control and determine the traffic control strategy. Based on the aforementioned traffic control strategy, terminal network security transmission management is performed; Security verification, screening, and storage are performed based on the aforementioned dual-mapping module, including: Receive the source address information and temporarily store the source address information in the first module. Based on the screening encapsulation layer configured in the first module, network security verification and screening are performed on the source address information to determine valid address information, wherein the verification method is at least one of MAC mode and IP mode; Based on the mapping relationship between the first module and the second module, the valid address information is mapped and stored in the second module, and the source address information stored in the first module is deleted.

2. The terminal network security transmission method for a switch as described in claim 1, characterized in that, Configure the screening encapsulation layer, including: The screening method based on terminal network security is determined, wherein the screening method includes at least trusted platform, permission detection, obligation detection and condition detection; Based on the MAC mode, the screening method is layered, integrated, and encapsulated to determine the first screening encapsulation layer; Based on the IP mode, the screening method is layered, integrated, and encapsulated to determine the second screening encapsulation layer; The screening encapsulation layer is determined by integrating the first screening encapsulation layer and the second screening encapsulation layer.

3. The terminal network security transmission method for a switch as described in claim 2, characterized in that, The screening encapsulation layer is configured on the first module end, wherein the first module end is the first interaction system module of the dual mapping module.

4. The terminal network security transmission method for a switch as described in claim 1, characterized in that, The determined logic management network includes: Traverse the physical communication network and, based on the communication characteristics of the communication terminals, divide the physical communication network to determine multiple partitioned networks; Traverse the multiple partitioned networks to determine the communication logic rules; The logical management network is constructed by mapping the multiple partitioning networks with the communication logic rules.

5. The terminal network security transmission method for a switch as described in claim 4, characterized in that, Mapping the multiple partitioning networks with the communication logic rules to construct the logical management network includes: Map the multiple partitioned networks to the communication logic rules to determine the initialization management network; The initialization management network is traversed to decouple the control plane and data plane and determine the parallel management layer, which includes the control management layer and the data transmission management layer. The parallel management layer is traversed, and the communication logic rules for dividing the network mapping within the layer are processed by programming to determine the logical management network.

6. The terminal network security transmission method for a switch as described in claim 1, characterized in that, Trigger the storm control mechanism to perform traffic control and determine the traffic control strategy, including: Traverse the logical management network, determine the storm network partition, and determine the flow control ratio; Traverse the storm network partitions and determine the priority method for flow control based on the communication logic rules of network transmission; Based on the priority and the flow control ratio, a flow limiting decision analysis is performed to determine the flow control strategy.

7. A terminal network security transmission platform for switches, characterized in that, For implementing the terminal network security transmission method for a switch according to any one of claims 1-6, the platform comprises: A dual mapping module construction unit is used to construct a dual mapping module for a target switch. The dual mapping module is determined based on the twin mapping of the switch's built-in system modules, and the first module is configured with a screening encapsulation layer. A security verification and screening unit is used to receive source address information, perform security verification and screening and storage based on the dual mapping module, and determine the security address information received by the switch. The verification and screening is based on the first module's storage screening and the second module's mapping storage. The system receives the source address information and temporarily stores it in the first module. Based on the screening and encapsulation layer configured in the first module, it performs network security verification and screening on the source address information to determine valid address information. The verification method is either MAC mode or IP mode. Based on the mapping relationship between the first module and the second module, the valid address information is mapped and stored in the second module, and the source address information stored in the first module is deleted. A logic programming unit is used to introduce software-defined networking, divide and logically program the physical communication network, and determine the logical management network, wherein the logical management network is a virtualized management network and is scalable; A forwarding storm assessment unit is used to perform a forwarding storm assessment based on a first time node for the security address information and the logical management network, and to determine the storm assessment result. The first time node is any address forwarding time node, and the forwarding method includes broadcast, unicast and multicast packets. A flow control unit is used to identify the storm assessment result. If the storm probability meets the probability threshold, the storm control mechanism is triggered to perform flow control and determine the flow control strategy. A secure transmission management unit is used to manage the secure transmission of the terminal network based on the traffic control policy.