Autonomous controllable security reinforcement VPN gateway for cloud environment and method thereof
By deploying FPGA modules in VPN gateway devices, the vulnerability of VPN devices under network attacks is solved, and more secure and reliable VPN access is achieved, improving security and performance in cloud environments.
Patent Information
- Application Number
- CN202510133272.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-07-18
AI Technical Summary
Existing VPN gateway devices have vulnerability problems when facing network attacks, especially in cloud scenarios, and face greater security challenges. The hardware structure and processing mechanism have security risks, which are easily broken by attackers to steal data or use as a springboard to invade private industrial control clouds.
FPGA is deployed between the CPU of the VPN gateway device and the external network interface, and the packets are filtered and encrypted and decrypted by the configuration management module, the VPN negotiation module, the security policy module and the message filtering module to achieve independent and controllable security reinforcement.
Effectively intercept illegal access, reduce the risk of data stealing after VPN devices are invaded, reduce CPU performance consumption, and improve the overall performance and security of VPN gateway devices.
Smart Images

Figure CN120342803A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to an autonomous and controllable security-enhanced VPN gateway and system for a cloud environment. Background Art
[0002] Today, with the rapid development of information technology, virtual private network (VPN) technology has become one of the key technologies for ensuring secure data transmission. By establishing a logical tunnel over a public network such as the Internet, VPN enables secure data transmission, and its core value lies in providing an economical and efficient remote access solution. With the rise of cloud computing and the industrial Internet, the application of VPN technology in the industrial control cloud environment has become particularly widespread. It can not only connect dispersed network resources but also protect sensitive data from network attacks. However, despite the significant progress made in the security of VPN technology, there are still some inherent defects in its hardware structure and processing mechanism.
[0003] Existing VPN gateway devices usually adopt a hardware structure with a direct connection between the CPU and the network card. This design allows the CPU to directly send and receive packets through the network card. However, this direct hardware connection also brings security risks. Since the operating system and its network protocol stack have numerous functions and complex logics, they are the main targets of network attacks. Once an attacker breaks through the security defense of the operating system, they can obtain VPN service configuration information and plaintext service data, and even use the VPN device as a springboard for further intrusion into the private industrial control cloud. In addition, the openness of the industrial control network in the cloud scenario increases the threat of network attacks, making the VPN gateway device face greater security challenges. Therefore, the existing technology has obvious deficiencies in terms of security and reliability, especially its vulnerability is particularly prominent when facing complex network attacks. Summary of the Invention
[0004] In view of the problems existing in the prior art, the present invention is proposed.
[0005] The problem to be solved by the present invention is to solve the vulnerability problem of existing VPN gateway devices when facing network attacks, and provide a more secure and reliable VPN access solution for the industrial control cloud environment.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, an embodiment of the present invention provides a domestically controllable and secure enhanced VPN gateway for a cloud environment, which includes that all packets from the Internet are sent to the CPU after being filtered by the FPGA. The FPGA includes: a configuration management module for performing configuration management of various service functions of the FPGA; a VPN negotiation module for completing key negotiation for a VPN tunnel or connection; a security policy module for matching outbound packets through a five-tuple, selecting tunnel encryption and encapsulation, and supporting parsing of the five-tuple of internal packets of the VXLAN protocol; a packet filtering module for filtering inbound and outbound packets according to rules and discarding non-compliant packets; and a packet processing module for performing encapsulation, decapsulation, encryption and decryption processing on packets.
[0008] As a preferred solution of the domestically controllable and secure enhanced VPN gateway for a cloud environment of the present invention, wherein: FPGA refers to a field programmable gate array, which consists of programmable logic units, programmable interconnection resources and some fixed circuits, and users can configure these resources through programming to achieve specific logic functions or algorithms.
[0009] As a preferred solution of the domestically controllable and secure enhanced VPN gateway for a cloud environment of the present invention, wherein: the configuration management module is used to receive instructions issued by the CPU, including security policies, packet filtering rules, VPN negotiation parameters, etc. In the FPGA configuration distribution process, the configuration management module first receives the configuration information issued by the CPU, and then applies these configuration information to different functional modules of the FPGA respectively to complete the configuration distribution.
[0010] As a preferred solution of the domestically controllable and secure enhanced VPN gateway for a cloud environment of the present invention, wherein: the VPN negotiation module is responsible for negotiating keys with remote clients, including receiving and sending security association payloads, working key calculation materials and working key confirmation information;
[0011] The negotiation process of the VPN negotiation module when establishing a VPN tunnel includes two stages: the first stage is key exchange, and the second stage is negotiation of security association and session keys.
[0012] As a preferred solution of the domestically controllable and secure enhanced VPN gateway for a cloud environment of the present invention, wherein: the five-tuple refers to source IP, destination IP, source port, destination port, and protocol type; the security policy module performs policy matching on outbound packets through the five-tuple, and selects a specified tunnel to encrypt and encapsulate the packets according to the matched policy configuration. For inbound packets, the security policy module also performs policy matching and discards packets that do not conform to the security policy to ensure that only packets that conform to the policy can enter the VPN gateway device; at the same time, the security policy module supports parsing and policy matching of the five-tuple of internal packets encapsulated by the VXLAN protocol.
[0013] As a preferred solution of the self - controllable and secure enhanced VPN gateway for cloud environment of the present invention, the packet filtering module is responsible for filtering the packets entering and leaving the VPN gateway according to rules, ensuring that only the packets meeting specific rules can be further processed or forwarded. For the packets not meeting the specified rules, the packet filtering module will discard them.
[0014] As a preferred solution of the self - controllable and secure enhanced VPN gateway for cloud environment of the present invention, the packet processing module is responsible for encrypting, decrypting, encapsulating, and decapsulating network packets to ensure the security of data transmission; the packet processing module processes the packets according to the tunnel or connection information negotiated by the VPN negotiation module, and decides how to encrypt, decrypt, encapsulate, or decapsulate specific packets according to the negotiation result.
[0015] In a second aspect, an embodiment of the present invention provides a method for a self - controllable and secure enhanced VPN gateway for cloud environment, which includes deploying an FPGA between the CPU of the VPN gateway device and the external network interface;
[0016] Configuring the FPGA, including a configuration management module, a VPN negotiation module, a security policy module, a packet filtering module, and a packet processing module.
[0017] Through the collaborative cooperation of each part of the FPGA module, the FPGA configuration is issued, the VPN negotiation process, the packet sending process, and the packet receiving process are carried out.
[0018] In a third aspect, an embodiment of the present invention provides a computer device, including a memory and a processor, and the memory stores a computer program, where: when the computer program instructions are executed by the processor, the steps of the self - controllable and secure enhanced VPN gateway for cloud environment as in the first aspect of the present invention are implemented.
[0019] In a fourth aspect, an embodiment of the present invention provides a computer - readable storage medium, on which a computer program is stored, where: when the computer program instructions are executed by the processor, the steps of the self - controllable and secure enhanced VPN gateway for cloud environment as in the first aspect of the present invention are implemented.
[0020] The beneficial effects of the present invention are as follows: By adding an FPGA between the CPU of the VPN gateway device and the external network interface, and implementing functions such as VPN negotiation, packet encapsulation / decapsulation, encryption / decryption, and packet security filtering on the FPGA. The FPGA can intercept illegal access from the external network, reducing the risk that the VPN device is further exploited to steal sensitive information or plaintext service data after being invaded from the external network and using the VPN device as a springboard to invade the internal network system; at the same time, this solution can also make full use of the resources of the FPGA, reduce the performance consumption of the CPU, and improve the overall performance of the VPN gateway device. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0022] Figure 1 It is a FPGA module diagram of an autonomously controllable and securely fortified VPN gateway for a cloud environment;
[0023] Figure 2 It is the basic structure of a securely fortified VPN gateway of an autonomously controllable and securely fortified VPN gateway for a cloud environment;
[0024] Figure 3 It is a flowchart of a method for an autonomously controllable and securely fortified VPN gateway for a cloud environment;
[0025] Figure 4 It is a diagram of a computer device for an autonomously controllable and securely fortified VPN gateway for a cloud environment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification.
[0027] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0028] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an individual or alternative embodiment that is mutually exclusive with other embodiments.
[0029] Embodiment 1
[0030] Referring to Figures 1 to 2 , this is the first embodiment of the present invention. This embodiment provides an autonomously controllable and securely fortified VPN gateway for a cloud environment. By deploying an autonomously controllable FPGA between the CPU of the VPN gateway device and the external network interface, effective filtering of illegal packets is achieved, thereby significantly reducing the risk of the VPN gateway device being invaded.
[0031] Specifically, all packets from the Internet are sent to the CPU after being filtered by the FPGA. The FPGA includes: a configuration management module for configuring and managing various service functions of the FPGA; a VPN negotiation module for completing the key negotiation of VPN tunnels or connections; a security policy module for matching the direction of packets through the five-tuple, selecting tunnel encapsulation and encryption, and supporting the parsing of the five-tuple of the internal packets of the VXLAN protocol; a packet filtering module for filtering incoming and outgoing packets according to rules and discarding non-compliant packets; and a packet processing module for performing encapsulation, decapsulation, encryption, and decryption processing on packets.
[0032] Specifically, FPGA refers to a field-programmable gate array. The FPGA consists of programmable logic units, programmable interconnect resources, and some fixed circuits. Users can configure these resources through programming to achieve specific logic functions or algorithms.
[0033] Specifically, the configuration management module is used to receive instructions sent by the CPU, including security policies, packet filtering rules, and VPN negotiation parameters, etc. In the FPGA configuration distribution process, the configuration management module first receives the configuration information sent by the CPU, and then applies these configuration information to different functional modules of the FPGA respectively to complete the configuration distribution.
[0034] Furthermore, the configuration management module can apply it to the security policy module of the FPGA to ensure that the FPGA can correctly process packets according to these policies;
[0035] Furthermore, the configuration management module is also responsible for applying the packet filtering rules configured by the CPU to the packet filtering module of the FPGA, so that the FPGA can filter incoming and outgoing packets according to these rules.
[0036] Furthermore, the configuration management module is also responsible for receiving the VPN negotiation parameters sent by the CPU and applying them to the VPN negotiation module of the FPGA to ensure that the VPN tunnel or connection can be correctly established.
[0037] Specifically, the VPN negotiation module is responsible for negotiating keys with remote clients, including receiving and sending security association payloads, working key calculation materials, and working key confirmation information;
[0038] Specifically, the negotiation process of the VPN negotiation module when establishing a VPN tunnel includes two stages: the first stage is key exchange, and the second stage is the negotiation of security association and session keys.
[0039] Furthermore, the steps of the key exchange in the first stage of the VPN negotiation module are as follows:
[0040] The VPN negotiation module receives the security association payload encapsulated with the proposed payload sent by the remote client and returns the security association payload and the local certificate;
[0041] The VPN negotiation module receives the calculation material of the encrypted protected working key part sent by the remote client and returns the corresponding calculation material;
[0042] The VPN negotiation module receives and returns the working key confirmation information to confirm that the working keys of both parties have been successfully negotiated.
[0043] Furthermore, the steps for the VPN negotiation module to negotiate the security association and session key in the second phase are as follows:
[0044] After the exchange of the calculation material of the working key is completed, the VPN negotiation module continues to negotiate the security association and the calculation material of the session key part, and completes the key negotiation after receiving the session key confirmation information from the remote client;
[0045] The VPN negotiation module ensures the security of the entire key negotiation process by encrypting and protecting the calculation material of the working key to prevent the key from being intercepted or tampered with during the negotiation process.
[0046] Specifically, the five-tuple refers to the source IP, destination IP, source port, destination port, and protocol type; the security policy module performs policy matching on the outbound packets through the five-tuple, and encrypts and encapsulates the packets using the specified tunnel according to the matched policy configuration. For the inbound packets, the security policy module also performs policy matching and discards the packets that do not conform to the security policy to ensure that only the packets that conform to the policy can enter the VPN gateway device; at the same time, the security policy module supports parsing and policy matching of the five-tuple of the internal packets encapsulated by the VXLAN protocol.
[0047] Furthermore, the security policy module supports parsing and policy matching of the five-tuple of the internal packets encapsulated by the VXLAN protocol, which enables the VPN gateway to be more flexible in applying to the industrial control cloud scenario, where the VXLAN protocol is commonly used in virtualized environments.
[0048] Preferably, by implementing the security policy, the security policy module effectively reduces the risk of the VPN device being further invaded from the external network to steal sensitive information or plaintext service data, or using the VPN device as a springboard to invade the internal network system.
[0049] Specifically, the packet filtering module is responsible for filtering the packets entering and leaving the VPN gateway to ensure that only the packets that conform to specific rules can be further processed or forwarded. For the packets that do not meet the specified rules, the packet filtering module will discard them.
[0050] Preferably, by implementing packet filtering on the FPGA, the performance consumption of the CPU can be reduced, and the overall performance of the VPN gateway device can be improved because the FPGA can efficiently handle a large number of packet filtering tasks.
[0051] Preferably, the packet filtering module works in cooperation with the security policy module. The security policy module performs security policy matching based on the five-tuple, while the packet filtering module is responsible for executing specific filtering rules.
[0052] Specifically, the packet processing module is responsible for encrypting, decrypting, encapsulating, and decapsulating network packets to ensure the security of data transmission;
[0053] Specifically, the packet processing module processes packets according to the tunnel or connection information negotiated by the VPN negotiation module. This means that the module will decide how to encrypt, decrypt, encapsulate, or decapsulate specific packets based on the negotiation result.
[0054] Preferably, by implementing the functions of packet encapsulation / decapsulation and encryption / decryption on the FPGA, the burden on the CPU can be reduced, and the efficiency and performance of the VPN gateway device in processing packets can be improved.
[0055] Preferably, the packet processing module enhances the security of the VPN gateway because it ensures that only correctly encapsulated and encrypted packets can be transmitted in the network, and at the same time ensures that the received packets have been correctly decrypted and decapsulated before being passed to the CPU.
[0056] In summary, the FPGA logic is more concise than the operating system and network protocol stack, and the risk of backdoors and vulnerabilities is much lower than that of the operating system. At the same time, the FPGA logic is easier to perform formal verification, ensuring from a mathematical principle that there are no defects or vulnerabilities in the FPGA logic. Therefore, using the FPGA to filter packets from the external network can effectively ensure the running security of the operating system and network protocol stack on the CPU of the VPN gateway device, effectively reduce potential vulnerabilities that can be exploited by attackers, and also make it difficult for attackers to steal device configuration information and plaintext service data, and difficult to use the VPN gateway device as a springboard to access the internal network.
[0057] Embodiment 2
[0058] This is the second embodiment of the present invention, which provides the main business processes of the secure and fortified VPN gateway through the present invention.
[0059] S1: FPGA configuration download, including:
[0060] ① The CPU completes the boot and startup of the operating system;
[0061] ②The CPU recognizes the FPGA device and sends the VPN negotiation configuration, security policy configuration, packet filtering rule configuration, etc. to the configuration management module of the FPGA;
[0062] ③The FPGA configuration management module applies the VPN negotiation configuration to the VPN negotiation module, applies the security policy configuration to the security policy module, and applies the packet filtering rule configuration to the packet filtering module;
[0063] ④The FPGA completes the configuration distribution process.
[0064] S2: VPN negotiation process. The present invention is applicable to multiple VPN protocols. Only the IPSec VPN is taken as an example to illustrate the VPN negotiation process, including:
[0065] ①(The first stage) The VPN negotiation module receives the security association payload encapsulated with the proposed payload sent by the remote client;
[0066] ②The VPN negotiation module returns the security association payload and the local certificate;
[0067] ③The VPN negotiation module receives the encrypted protected working key part calculation material sent by the remote client;
[0068] ④The VPN negotiation module returns the encrypted protected working key part calculation material;
[0069] ⑤The VPN negotiation module receives the working key confirmation information sent by the remote client;
[0070] ⑥The VPN negotiation module returns the working key confirmation information;
[0071] ⑦(The second stage) The VPN negotiation module receives the security association and session key part calculation material sent by the remote client;
[0072] ⑧The VPN negotiation module returns the security association and session key part calculation material;
[0073] ⑨The VPN negotiation module receives the session key confirmation information sent by the remote client;
[0074] ⑩Complete the IPSec negotiation.
[0075] S3: Packet sending process, including:
[0076] ①The CPU sends the service packet to the FPGA;
[0077] ②The security policy module performs security policy matching according to the five-tuple. If no policy is matched, the packet is discarded. If a policy is matched, the subsequent process continues;
[0078] ③Encrypt and encapsulate the message according to the VPN negotiation status;
[0079] ④Send the encrypted and encapsulated message through the network interface.
[0080] S4: Message receiving process, including:
[0081] ①The FPGA receives the message from the network interface;
[0082] ②Decapsulate and decrypt the message according to the VPN negotiation status;
[0083] ③Filter the message according to the message filtering rules, discard the messages that do not conform to the rules, and the messages that conform to the rules continue with the subsequent process;
[0084] ④The security policy module performs security policy matching according to the five-tuple. If no policy is matched or the matched policy does not correspond to the message source tunnel / connection, the message is discarded. If the matching is successful, the subsequent process continues;
[0085] ⑤The FPGA sends the service message to the CPU.
[0086] Embodiment 3
[0087] Refer to Figure 3 , which is the third embodiment of the present invention. This embodiment provides a method for an autonomous and controllable security-enhanced VPN gateway for a cloud environment, including,
[0088] S1: Deploy an FPGA between the CPU of the VPN gateway device and the external network interface;
[0089] Furthermore, the FPGA adopts a whitelist mechanism, which defaults to intercepting all inbound network messages, and only allows the network messages permitted by the rules to be sent to the CPU after receiving the release rules issued by the CPU.
[0090] Furthermore, the FPGA supports VPN protocols such as IPSec or SSL, and can perform encryption, decryption, encapsulation, and decapsulation operations on network messages, which not only ensures security but also improves the message processing performance of the VPN gateway device.
[0091] It should be noted that the core components such as the CPU, memory, storage, and FPGA on the internal and external network motherboards all use domestic components, and the domestic operating system is used at the software level to further ensure the overall security and reliability of the VPN gateway device.
[0092] Preferably, by adding an FPGA between the CPU of the VPN gateway device and the external network network interface, the interception of illegal access is realized, effectively reducing the risk that after the VPN device is invaded by the external network, sensitive information or plaintext service data is further stolen, and the internal network system is invaded with the VPN device as a springboard. At the same time, this solution can also make full use of the resources of the FPGA, reduce the performance consumption of the CPU, and improve the overall performance of the VPN gateway device.
[0093] S2: Configure the FPGA, including a configuration management module, a VPN negotiation module, a security policy module, a packet filtering module, and a packet processing module.
[0094] Furthermore, the configuration management module is responsible for the configuration management of each service function of the FPGA, affecting the security policies issued by the CPU instructions, packet filtering rules, VPN negotiation parameters, etc.
[0095] Furthermore, the VPN negotiation module completes the key negotiation of the VPN tunnel or connection.
[0096] Furthermore, the security policy module uses the five-tuple to perform policy matching on the outbound packets, and encrypts and encapsulates the packets according to the selected policy of the matching.
[0097] Furthermore, the packet filtering module filters the rules of the inbound and outbound packets, and discards the packets that do not meet the specified rules.
[0098] Furthermore, the packet processing module performs encapsulation, de-encapsulation, encryption, and decryption processing on the packets according to the tunnel or connection information negotiated by the VPN negotiation module.
[0099] S3: Through the collaborative cooperation of each part of the FPGA module, perform FPGA configuration download, VPN negotiation process, send packet process, and receive packet process.
[0100] Furthermore, in the FPGA configuration download process, after the CPU completes the operating system boot and recognizes the FPGA device, it downloads the VPN negotiation configuration, security policy configuration, packet filtering rule configuration, etc. to the configuration management module of the FPGA.
[0101] Furthermore, in the VPN negotiation process, the VPN negotiation module receives and processes the security association payload from the remote client and completes the key negotiation.
[0102] Specifically, in the send packet process, the CPU sends the service packets to the FPGA, the security policy module performs security policy matching according to the five-tuple, then encrypts and encapsulates the packets, and finally sends them through the network interface.
[0103] Specifically, in the process of receiving packets, the FPGA receives packets from the network interface, performs de-encapsulation and decryption, filters the packets according to the packet filtering rules, and then sends the service packets to the CPU.
[0104] In summary, the present invention adds an FPGA between the CPU of the VPN gateway device and the external network interface, and implements functions such as VPN negotiation, packet encapsulation / de-encapsulation and encryption / decryption, and packet security filtering on the FPGA, thereby improving security and performance. The FPGA logic is simpler than the operating system and network protocol stack, and the risk of backdoors and vulnerabilities is much lower than that of the operating system. At the same time, the FPGA logic is easier to formalize verification, ensuring that there are no defects and vulnerabilities in the FPGA logic from a mathematical principle. Therefore, using the FPGA to filter the packets of the external network can effectively protect the operation security of the operating system and network protocol stack on the CPU of the VPN gateway device, effectively reduce potential vulnerabilities that can be exploited by attackers, and also make it difficult for attackers to steal device configuration information and plaintext service data, and difficult to use the VPN gateway device as a springboard to access the internal network.
[0105] Embodiment 4
[0106] Refer to Figure 4 , which is the fourth embodiment of the present invention. The difference between this embodiment and the previous embodiment is:
[0107] This embodiment also provides a computer device, which is applicable to the situation of an autonomous and controllable security-enhanced VPN gateway for the cloud environment, including a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the autonomous and controllable security-enhanced VPN gateway for the cloud environment as proposed in the above embodiment.
[0108] The computer device can be a terminal. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WLAN , a cellular network, NFC (Near Field Communication) or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.
[0109] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the autonomous and controllable security-enhanced VPN gateway for the cloud environment as proposed in the above embodiment.
[0110] If the above functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the essence of the technical solution of the present invention, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0111] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. An autonomously controllable and secure enhanced VPN gateway for cloud environment, characterized in that: All packets from the Internet are sent to the CPU after being filtered by the FPGA. The FPGA includes: A configuration management module for performing configuration management of various service functions of the FPGA; A VPN negotiation module for completing key negotiation for VPN tunnels or connections; A security policy module that matches outbound packets through a five-tuple, selects a tunnel for encryption and encapsulation, and supports parsing the five-tuple of internal packets of the VXLAN protocol; A packet filtering module for filtering inbound and outbound packets according to rules and discarding non-compliant packets; A packet processing module for performing encapsulation, decryption and encapsulation, and encryption and decryption processing on packets.
2. The domestically controllable and secure hardened VPN gateway for cloud environment according to claim 1, characterized in that: The FPGA refers to a field programmable gate array. The FPGA consists of programmable logic units, programmable interconnection resources, and some fixed circuits. Users can configure these resources through programming to achieve specific logic functions or algorithms.
3. The domestically controllable and secure hardened VPN gateway for cloud environment according to claim 2, characterized in that: The configuration management module is used to receive instructions issued by the CPU, including security policies, packet filtering rules, and VPN negotiation parameters, etc. In the FPGA configuration download process, the configuration management module first receives the configuration information issued by the CPU, and then applies these configuration information to different functional modules of the FPGA respectively to complete the configuration download.
4. The domestically controllable and secure hardened VPN gateway for cloud environment according to claim 3, characterized in that: The VPN negotiation module is responsible for negotiating keys with remote clients, including receiving and sending security association payloads, working key calculation materials, and working key confirmation information; The negotiation process of the VPN negotiation module when establishing a VPN tunnel includes two stages: the first stage is key exchange, and the second stage is negotiation of security association and session keys.
5. The domestically controllable and secure hardened VPN gateway for cloud environment according to claim 4, characterized in that: The five-tuple refers to source IP, destination IP, source port, destination port, and protocol type; The security policy module performs policy matching on outbound packets through the five-tuple, and selects a specified tunnel to encrypt and encapsulate the packets according to the matched policy configuration. For inbound packets, the security policy module also performs policy matching and discards the packets that do not conform to the security policy to ensure that only packets that conform to the policy can enter the VPN gateway device; At the same time, the security policy module supports parsing and policy matching of the five-tuple of internal packets encapsulated by the VXLAN protocol.
6. The domestically controllable and secure hardened VPN gateway for cloud environment according to claim 5, characterized in that: The packet filtering module is responsible for filtering the packets entering and leaving the VPN gateway according to rules to ensure that only packets that conform to specific rules can be further processed or forwarded. For packets that do not meet the specified rules, the packet filtering module will discard them.
7. The domestically controllable and secure hardened VPN gateway for cloud environment according to claim 6, characterized in that: The packet processing module is responsible for performing encryption / decryption and encapsulation / de-encapsulation operations on network packets to ensure the security of data transmission; The packet processing module processes the packets according to the tunnel or connection information negotiated by the VPN negotiation module, and decides how to encrypt, decrypt, encapsulate, or de-encapsulate specific packets based on the negotiation result.
8. A method for an autonomous and controllable security-enhanced VPN gateway for a cloud environment, based on the autonomous and controllable security-enhanced VPN gateway for a cloud environment according to any one of claims 1 to 7, characterized in that: An FPGA is deployed between the CPU of the VPN gateway device and the external network interface; Configure the FPGA, including a configuration management module, a VPN negotiation module, a security policy module, a packet filtering module, and a packet processing module. Through the collaborative cooperation of each part of the FPGA module, perform FPGA configuration distribution, VPN negotiation process, packet sending process, and packet receiving process.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the autonomous and controllable security-enhanced VPN gateway for a cloud environment according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the autonomous and controllable security-enhanced VPN gateway for a cloud environment according to any one of claims 1 to 7.