Transmission, storage and encryption all-in-one machine for password application security assessment

By implementing network traffic, key data and boundary isolation of the password module in one device, the problems of dispersed equipment resources and security risks in the information system are solved, and efficient password application security assessment and transformation solutions are provided.

CN120408678APending Publication Date: 2025-08-01ZHONGAN WANGMAI (BEIJING) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510532947.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In the security assessment and transformation of password applications, existing information systems have problems such as dispersed equipment resources, complex management, large transformation project volume, high business continuity risk, and increased security risk, which is difficult to meet the needs of rapid online launch.

Method used

Using the isolation technology combined with software and hardware, the network traffic, key data and password boundary isolation between password modules is achieved through Docker containers and 4-port network cards. Two password cards are used to provide exclusive key management and computing capabilities, and firewall rules are configured to achieve network traffic isolation at different levels.

Benefits of technology

It realizes clear boundaries of multiple types of password modules, secure storage of multiple types of keys, and secure transmission of multi-level traffic, meeting the comprehensive password function needs of the information system, simplifying the transformation process, and reducing security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408678A_ABST
    Figure CN120408678A_ABST
Patent Text Reader

Abstract

The invention discloses a transmission, storage and encryption all-in-one machine oriented to password application security evaluation and an implementation method, and belongs to the field of password engineering. The all-in-one machine comprises an industrial personal computer, two sets of password cards and a plurality of functional modules. VPN service, database encryption, basic password service and resource isolation of a management program are achieved through a Docker container. The two sets of password cards respectively provide key management and calculation functions of physical isolation; the four-port network card is combined with a virtual network bridge and a firewall rule to divide an extranet communication channel, an intranet application channel and a management flow channel. By means of containerization, hardware-level isolation and network hierarchical design, the functions of identity authentication, transmission encryption, storage encryption and the like are integrated in a single device, the problems of high transformation cost, fuzzy password boundary and complex management caused by traditional multi-device stacking are solved, and password application compliance and implementation efficiency are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptography engineering, and more specifically, to a transmission and storage encryption all-in-one machine for evaluating the security of cryptographic applications. Background Art

[0002] The popularization, promotion, evaluation, and supervision and inspection of cryptographic applications have become the key tasks of the cryptographic industry. Traditional cryptographic products can only solve the cryptographic requirements of a single point or a single layer, and it is difficult to solve the cryptographic requirements of multiple layers of information systems. The integration of multiple cryptographic products and information systems also causes difficulties in the transformation of information systems, which is exactly the difficulty in promoting the current cryptographic evaluation.

[0003] In existing solutions, for example, in the journal article "Research on the Commercial Cryptography Transformation of County-level Converged Media Systems" published by Zhang Dongdong and Zhang Xueqi in Television Engineering, multiple cryptographic devices such as security authentication gateways, signature verification servers, and server cryptographic machines need to be deployed to provide services such as channel encryption, identity authentication, signature verification, data encryption, and key management for the system, and to upgrade the cryptographic application transformation of the converged media system and converged media editing and production; in the special journal article "Exploration of the Path for the National Cryptography Transformation of Campus Information Systems" published by Tang Wenjun and Huang Jianbo in China Education Network, multiple cryptographic devices such as signature verification servers, secure access gateways, operation and maintenance bastion hosts, and timestamp servers need to be deployed to provide data encryption and decryption services, identity authentication services, key management services, etc. for the information system.

[0004] The current security evaluation and transformation solutions for cryptographic applications in information systems generally have the following defects: at the technical implementation level, they highly rely on the stacked deployment mode of heterogeneous cryptographic devices, resulting in scattered cryptographic service resources and complex management, significantly increasing the construction cost; in terms of system adaptability, since the current solutions require architectural-level transformation of the information system to adapt to multiple types of cryptographic device interfaces, the transformation workload surges, thereby triggering business continuity risks; in terms of implementation efficiency, the entire process from cryptographic device selection, system transformation to joint debugging and testing requires multi-link collaboration, objectively causing the implementation cycle to be uncontrollably extended, and it is difficult to meet the timeliness requirements of the rapid online of business systems. This multi-dimensional implementation bottleneck has severely restricted the large-scale application efficiency of cryptographic technologies in actual business scenarios.

[0005] The integration of multiple cryptographic functions in one device may cause problems such as blurred cryptographic boundaries and mixed internal and external network traffic due to different security protection requirements for each function. This will increase the security risks of cryptographic products, and not only cannot provide security protection for information systems, but may also cause security vulnerabilities by itself.

[0006] "Taking cryptographic technology as the core and integrating multiple security technologies" is becoming the mainstream idea, and integrated cryptographic products have become a significant trend in current technological development and product evolution. Through encryption technology, a protection boundary is defined for the flowing data, and technologies such as identity authentication, access control, channel encryption, and data encryption are applied at the boundary to achieve one-stop cryptographic security protection, create an integrated cryptographic security application and support system, and make the password easy to use and manage, which is increasingly becoming an urgent requirement for cryptographic applications. Summary of the Invention

[0007] The purpose of the present invention is to provide a transmission and storage encryption all-in-one machine for cryptographic application security assessment. By using a software and hardware combination isolation technology, it realizes the mutual isolation of network traffic, key data, and cryptographic boundaries between different cryptographic modules within one device, ensuring clear boundaries of multiple types of cryptographic modules inside the device, secure storage of various types of keys, and secure transmission of multi-level traffic; for cryptographic boundary isolation, a container-based isolation technology is adopted to provide isolated CPU, memory, and storage for each cryptographic module, clarifying the boundaries of each cryptographic module; for key data isolation, a hardware isolation mechanism with two cryptographic cards is adopted. One card provides exclusive key management and cryptographic calculation capabilities for the VPN service module, and the other card provides exclusive key management and cryptographic calculation capabilities for the database encryption module and the basic cryptographic service module, realizing key and calculation isolation for cryptographic functions at the network layer and application layer; for network traffic isolation, a 4-port network card is adopted, providing one exclusive internal and external network port for the VPN module, one exclusive internal network port for the database encryption module and the basic cryptographic service module, and one exclusive management network port for the management program module, realizing the mutual isolation of network traffic at different levels.

[0008] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0009] A transmission and storage encryption all-in-one machine for cryptographic application security assessment, characterized by comprising:

[0010] An industrial control computer configured with Docker containers and a 4-port network card;

[0011] A first cryptographic card and a second cryptographic card, both having PCI-E interfaces, independently providing key management and cryptographic calculation functions;

[0012] A VPN service module, a database encryption module, a basic cryptographic service module, and a management program module, respectively deployed in independent Docker containers of the industrial control computer;

[0013] Wherein:

[0014] The Docker containers provide isolated CPU, memory, and storage space for each module through Linux namespaces and Cgroups technologies;

[0015] The second password card provides exclusive key storage and password calculation functions for the VPN service module, and the first password card provides exclusive key storage and password calculation functions for the database encryption module and the basic password service module;

[0016] The 4-port network card is allocated as follows:

[0017] The external network port (port 3) is bound to the VPN service module for establishing an encrypted transmission channel with the VPN client;

[0018] The internal network port 2 (port 4) is bound to the VPN service module for forwarding the decrypted traffic to the internal network application;

[0019] The internal network port 1 (port 1) is bound to the database encryption module and the basic password service module for communicating with the internal network application;

[0020] The management network port (port 2) is bound to the management program module for device management;

[0021] The network traffic of each module is bound to an independent network port through virtual network bridges (bridge1~bridge4), and firewall rules are configured to prohibit cross-virtual network bridge communication to achieve network traffic isolation.

[0022] Preferably: The first password card and the second password card are connected to the industrial control computer through the PCI-E interface, and the password card driver program allocates independent character device interfaces ( / dev / sdf1_1, / dev / sdf1_2, / dev / sdf1_3, / dev / sdf2_1, / dev / sdf2_2) for each module, and provides independent device handles for each module through the dynamic link library (libsdf.so) to achieve physical isolation of key storage and calculation.

[0023] Preferably: The VPN service module implements the SSL VPN protocol based on the GM / T 0024 standard, specifically including:

[0024] According to the mutual authentication mechanism in Section 5.3.3 of the GB / T 15843.3 standard, perform two-way identity authentication on the VPN client and the server;

[0025] Negotiate a working key with the client through the external network port (port 3) and encrypt the communication data using the SM4 algorithm;

[0026] Forward the decrypted plaintext traffic to the internal network application through the internal network port 2 (port 4), and the encryption / decryption operations are completed by the second password card.

[0027] Preferably, the database encryption module intercepts SQL statements through a database encryption plug-in, and transparently encrypts and decrypts specified database fields according to the policy configuration issued by the management program module, specifically including:

[0028] When writing data, intercept sensitive fields (such as ID card numbers and mobile phone numbers) in the SQL statement, send them through the internal network port 1 (port 1) to the first password card for encryption and then store them;

[0029] When reading data, intercept the encrypted fields, decrypt them through the first password card and return the plaintext;

[0030] The encryption and decryption policy includes field names, algorithm types (SM4 / SM1), and modes (CBC / ECB), and the key is stored in the first password card.

[0031] Preferably, the management program module provides two-factor identity authentication based on USB Key, specifically including:

[0032] Verify the administrator's identity according to the one-way authentication mechanism in section 5.2.3 of the GB / T 15843.3 standard;

[0033] Receive operation instructions from the management terminal through the management network port (port 2) to complete password card initialization, log auditing, and full life cycle management of the key;

[0034] Communicate with other modules through the virtual bridge (bridge2), and configure firewall rules to prohibit non-management traffic from accessing.

[0035] Preferably, the basic password service module provides national cryptography algorithm services for internal network applications through the API, including:

[0036] Call the first password card to complete SM2 asymmetric encryption, SM3 hash calculation, and SM4 symmetric encryption and decryption;

[0037] Receive application requests through the internal network port 1 (port 1) and return the calculation results, and the key is stored in the first password card in a module-isolated manner.

[0038] The present invention also discloses an implementation method of a transmission and storage encryption all-in-one machine for password application security evaluation, including the following steps:

[0039] Step 1: Deploy the database encryption module, the basic password service module, the management program module, and the VPN service module in independent Docker containers of the industrial control computer respectively, isolate CPU and memory resources through namespaces, and limit the storage space through Cgroups;

[0040] Step 2: Allocate the first password card to the database encryption module, the basic password service module, and the management program module. Through the driver, allocate independent character device interfaces ( / dev / sdf1_2, / dev / sdf1_3) to each module, and store the keys in the first password card in a module-isolated manner;

[0041] Step 3: Allocate the second password card to the VPN service module. Through the driver, allocate an independent character device interface ( / dev / sdf2_2), and store the key independently in the second password card;

[0042] Step 4: Create a virtual bridge bridge1 and bind it to the internal network port 1 (port 1). Connect the database encryption module and the basic password service module to bridge1, and configure the firewall rules to prohibit bridge1 from communicating with other bridges;

[0043] Step 5: Create a virtual bridge bridge2 and bind it to the management network port (port 2). Connect the management program module to bridge2, and configure the firewall rules to only allow access from the management terminal IP;

[0044] Step 6: Create virtual bridges bridge3 and bridge4, bind them to the external network port (port 3) and the internal network port 2 (port 4) respectively. Connect the VPN service module to bridge3 and bridge4, and configure the firewall rules to only allow encrypted traffic forwarding between bridge3 and bridge4.

[0045] Preferably: In Steps 2 and 3, after each module exclusively occupies a different character device when starting up, call the SDF_OpenDevice function through the dynamic link library (libsdf.so) to return an independent device handle for each module, ensuring the isolation of the password card operation instruction transmission channels.

[0046] Preferably: In Steps 4 - 6, the firewall rules are configured through iptables, specifically including:

[0047] Prohibit packet forwarding between bridge1 and bridge2, bridge3, and bridge4; only allow traffic between bridge3 (external network port) and bridge4 (internal network port 2) to be transmitted through the SM4 encryption tunnel.

[0048] Preferably: The transparent encryption and decryption policy of the database encryption module is configured through the management program module. An example of the policy is: encrypt the "id_card" field in the database table "user_info" using the SM4-CBC mode, and the initialization vector (IV) is generated and stored by the first password card.

[0049] Beneficial effects:

[0050] (1) Multiple cryptographic modules and functions are integrated within a single device. By using one device, the cryptographic evaluation requirements of the information system are met, and cryptographic requirements such as identity authentication, transmission encryption, and storage encryption are realized.

[0051] (2) Based on container isolation technology, mutually isolated CPUs, memories, and storages are provided for each cryptographic module to clarify the boundaries of each cryptographic module.

[0052] (3) Based on hardware isolation technology, dedicated key management and cryptographic computing capabilities are provided for the VPN service module, database encryption module, and basic cryptographic service module respectively, to achieve key and computing isolation for cryptographic functions at the network layer and application layer.

[0053] (4) Based on hardware isolation technology, network traffic at different levels is mutually isolated and securely transmitted. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 It is the overall structure diagram of the present invention;

[0055] Figure 2 It is the architecture diagram of the isolation mechanism of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention.

[0057] Embodiment 1

[0058] The present invention discloses a transmission and storage encryption integrated machine for cryptographic application security evaluation, which includes an industrial control computer, 2 cryptographic cards, a VPN service module, a database encryption module, a basic cryptographic service module, and a management program module.

[0059] The industrial control computer is a customized server device that carries other software and hardware modules. This device is configured with Docker containers and a 4-port network card. Among them, the Docker containers are used to carry the database encryption module, basic cryptographic module, management program module, and VPN service module to achieve boundary isolation between cryptographic modules; the 4-port network card is used to achieve isolation of network traffic. Among them, 2 ports are used for the internal and external network traffic transmission of the VPN service module, 1 port is used for the management traffic transmission of the management program, and 1 port is used for the internal network application traffic transmission of the database encryption module and the basic cryptographic module.

[0060] The two cryptographic cards mentioned above have PCI-E interfaces and are PCI-E cryptographic card products that have obtained commercial cryptographic product certification certificates. One cryptographic card is used to implement key generation, key storage, and cryptographic calculations for the basic cryptographic module and data encryption module, and is called Cryptographic Card 1; one cryptographic card is used to implement key generation, key storage, and cryptographic calculations for the VPN service module, and is called Cryptographic Card 2; both cryptographic cards are managed by a management program.

[0061] Advantages of setting the two cryptographic cards separately: It realizes the division of different cryptographic operation units and key data storage spaces for the cryptographic module (VPN service module) in the external network environment and the cryptographic modules (basic cryptographic module, data encryption module) in the internal network environment, and achieves physical security isolation of the cryptographic components (referring to cryptographic cards) used by the cryptographic modules in the internal and external network environments; further security isolation can be achieved by the unified cryptographic card driver to allocate the specified character device of the specified cryptographic card to different cryptographic modules to achieve security isolation of the data and control command transmission channels of the cryptographic component interface (referring to the PCI-E interface of the cryptographic card).

[0062] Advantages of using the PCI-E interface: 1) Bandwidth performance: The cryptographic card uses a PCI-E interface based on the PCIe 3.0x4 channel, which has a bandwidth advantage of 16Gbps compared to the USB3.0 interface (theoretical bandwidth of 5Gbps), and can meet the requirements of the VPN service module, basic cryptographic module, and data encryption module for large data throughput when applying national cryptographic algorithms; 2) Resource occupancy: Zero-copy transmission can be achieved between the cryptographic card and the industrial control computer through the DMA engine, significantly reducing the CPU occupancy rate of the industrial control computer; 3) Reliability: As a board-level interconnection bus, PCI-E has a short transmission path and is protected by the shielding of the industrial control computer, with less signal attenuation and interference, and the bit error rate is 10 -12 Below, it is more reliable than interfaces such as USB. Due to its advantages in bandwidth, resource occupancy, and reliability, the PCI-E interface has become the preferred choice for the cryptographic card in this patent.

[0063] The described VPN service module establishes a secure channel and conducts information interaction with the VPN client through the external network interface, and forwards information to the protected application through the internal network interface 2. The VPN service module is a network access control service based on the C / S architecture, and enables users to remotely and securely access internal applications of the information system through the established secure channel. The establishment and information interaction process of the secure channel strictly comply with the requirements of "GB / T 38636-2020 Information Security Technology - Transport Layer Cryptographic Protocol (TLCP)": The mutual authentication of the identities of the VPN server and the VPN client is performed through the three-pass authentication mechanism in the mutual authentication in Section 5.3.3 of the standard "GB / T 15843.3-2016 Information Technology - Security Techniques - Entity Authentication - Part 3: Mechanisms Using Digital Signature Techniques"; The working key is negotiated according to the handshake protocol in "GM / T 0024-2023 SSL VPN Technical Specification"; The national cipher SM4 algorithm is used to encrypt and protect the communication data with the negotiated working key. The information system can deploy an all-in-one machine and use the functions of the VPN server module to meet the requirements of identity authentication and communication data security at the network and communication levels in the cryptographic evaluation, and alleviate the requirements of identity authentication and important data transmission security at the application and data levels.

[0064] The information forwarding process is as follows: Request uplink: The access request from the user terminal (PC / mobile device) is routed to the VPN client through the virtual network card tun. The VPN client encrypts the access request data and sends it to the external network interface of the all-in-one machine through the physical network card of the user terminal; After decryption by the all-in-one machine (using the password card 2 to complete the decryption operation), it is directly connected to the internal network application service of the information system through the internal network interface 2, realizing the seamless penetration of ciphertext transmission - plaintext delivery.

[0065] Response downlink: The data returned by the internal network application is received through the internal network interface 2 of the all-in-one machine. The all-in-one machine automatically identifies the target address of the virtual network card tun, triggers encryption (using the password card 2 to complete the encryption), and then sends it back to the user terminal through the external network interface; The VPN client decrypts the data and transmits it through the virtual network card tun to the user application, forming a request - response full-closed-loop encrypted tunnel.

[0066] The management program module is used to manage the initialization of the password card in the all-in-one machine, the configuration of each module, administrator management, log auditing, key management, etc. The management program module is a web service based on the B / S architecture. The administrator of the all-in-one machine logs in to the all-in-one machine system through the management terminal to perform management operations. The administrator uses the browser on the management terminal to perform identity authentication and then accesses the management program on the all-in-one machine through a secure channel. The management program manages other modules or password cards based on the management requests received from the management port. By deploying the all-in-one machine, the information system, based on the all-in-one machine's identity authentication, remote management channel, access control information integrity, and log record integrity capabilities, basically meets the requirements of identity authentication, remote management channel security, and related information integrity at the device and computing levels in the key assessment.

[0067] The all-in-one machine administrator logs in to the all-in-one machine management interface through a browser and uses a two-factor entity authentication method based on a USB KEY smart password key. The administrator's identity is authenticated according to the one-way authentication mechanism of two-pass authentication in section 5.2.3 of the GB / T15843.3-2016 "Information Technology Security Technology Entity Authentication Part 3: Mechanisms Using Digital Signature Technology" standard.

[0068] The all-in-one appliance creates a shared virtual bridge (a virtual bridge is a virtual network device working at the data link layer, used to connect multiple network interfaces and forward data frames between them. Its core function is similar to that of a physical switch and can be used to implement communication between containers and between containers and external networks). Container 1 with the basic cryptographic module deployed, container 2 with the database encryption module deployed, container 3 with the hypervisor module deployed, and container 4 with the VPN service module deployed are all connected to the virtual bridge at the same time. A firewall is configured to strictly isolate cross-virtual bridge communications and communications between the virtual bridge and the physical network port, so that the hypervisor module can communicate with other modules only through the virtual bridge.

[0069] After the password card driver is installed on the all-in-one machine, several character device interfaces for password card 1 and password card 2 will be automatically created. The password card provides an API dynamic link library (libsmf.so) for password card management. When the all-in-one machine management program module starts, it will independently occupy the specific character devices of 2 password cards respectively and load the corresponding API dynamic libraries. During the operation of the management program module, by calling the interface function (specifically SMF_OpenDevice) in the dynamic library, the independent device handles of 2 password cards are obtained, and based on these handles, the secure management of 2 password cards is realized, and operations such as initialization and key management are completed. By implementing a dual access control mechanism at the driver layer (exclusively occupying specific character devices) and the API layer (obtaining different device handles), it is ensured that the control command transmission channel of the password card is securely isolated, effectively guaranteeing the security of the input and output control commands during the process of the module managing the password card.

[0070] The character device allocation logic of the password card driver is as follows: After the password card driver is installed, it automatically creates character devices / dev / sdf1_1, / dev / sdf1_2, / dev / sdf1_3 for the first password card, and creates character devices / dev / sdf2_1, / dev / sdf2_2 for the second password card; when the management program module starts, it exclusively occupies / dev / sdf1_1 and / dev / sdf2_1, and calls the SMF_OpenDevice function through the dynamic link library (libsmf.so) to obtain the device handle; when the database encryption module and the basic password service module start, they respectively exclusively occupy / dev / sdf1_2 and / dev / sdf1_3, and call the SDF_OpenDevice function through the dynamic link library (libsdf.so) to obtain independent handles.

[0071] The described database encryption module is configured according to the policy issued by the management program module to provide transparent encryption and decryption services for the application for database table fields. When the application adds data to the database, the database encryption module intercepts the SQL statement according to the policy and encrypts the corresponding table fields. When the application views the database data, the database encryption module intercepts the SQL statement according to the policy and decrypts the corresponding table fields; the transparent encryption policy configuration is as follows: encrypt the "phone" field in the database table "employee" in the SM4-ECB mode, and the key is generated and stored by the first password card, and the key identifier is "KEY_DB_ENC".

[0072] The strategies include database fields that require encryption protection (such as mobile phone numbers, ID numbers, etc.), encryption and decryption algorithms (such as SM4, SM1, etc.), encryption and decryption modes (ECB, CBC, CFB, OFB, etc.), etc. The transparent encryption and decryption service realizes the security protection of data storage through a database encryption plug-in deployed on the application server in the intranet of the information system (which can be understood as an enhanced JDBC driver). The database encryption plug-in is directly connected to the database without additional dependencies. When writing data, it automatically parses the SQL statement, identifies sensitive fields in the predefined strategy (such as mobile phone numbers, ID numbers, etc.), sends the plaintext to the all-in-one machine for encryption through the intranet port 1 (completes the encryption operation using password card 1), and then reorganizes the SQL statement containing the ciphertext and stores it in the database; when reading data, it intercepts the ciphertext in reverse, decrypts it by the all-in-one machine (completes the decryption using password card 1), and returns the plaintext to the database encryption plug-in. The entire application process is unaware. The database encryption plug-in realizes the two-way transparent conversion of storing ciphertext in the database and using plaintext in the application through the dynamic interception mechanism of the JDBC layer, while ensuring zero transformation of the application service, meeting the access control information and storage security requirements of important data at the application and data levels during the cryptographic evaluation of the information system.

[0073] The basic cryptographic service module provides cryptographic services such as encryption and decryption, signature verification, and random numbers for applications. The application calls the basic cryptographic services through the API.

[0074] The basic cryptographic service module adopts a C / S architecture design and consists of a client API library deployed on the application terminal and a server program integrated in the all-in-one machine. Its operating mechanism can be summarized as follows: The client API library receives password service requests such as key management, algorithm operation, or file operation initiated by the user through a programming interface that complies with the GM / T 0018 standard, and then transmits the request data to the basic cryptographic service server program in the all-in-one machine through the network; after receiving the request, the server program parses the request type, completes the specific cryptographic service processing through password card 1, and finally returns the processing result to the client API library through the intranet port 1 of the all-in-one machine. After the API library parses the response data, it feeds back the execution result to the user through the programming interface. The information system can deploy an all-in-one machine and use the functions of the basic cryptographic service module, and adopt a message authentication code mechanism based on symmetric algorithms or cryptographic hash algorithms to meet the requirements for the integrity of electronic access control and video recording data storage at the physical and environmental levels during the cryptographic evaluation.

[0075] Embodiment 2

[0076] As Figure 1 shown, a method for implementing a transmission and storage encryption all-in-one machine for cryptographic application security evaluation disclosed by the present invention includes the following steps:

[0077] Step 1: Deploy the database encryption module, basic password service module, hypervisor module, and VPN service module in separate Docker containers of the industrial control computer. Isolate CPU and memory resources through namespaces and limit storage space through Cgroups.

[0078] The basic password module is deployed in Container 1, the database encryption module is deployed in Container 2, the hypervisor module is deployed in Container 3, and the VPN service module is deployed in Container 4.

[0079] The four containers have different structures and are all built based on the sandbox mechanism to create isolated environments. Resource isolation for processes, networks, etc. is achieved through Linux Namespaces, and resource quotas are controlled by Cgroups. The base image layer of the four containers uses the same base image, but different runtime environments (Python / Java) are installed in the dependency layer, and different business codes and configuration files are packaged in the application layer.

[0080] Advantages and effects of deploying each module in a different container: 1) Resource isolation and independence. Each module runs in an independent container, and resources (CPU, memory, storage space, etc.) are securely isolated through namespaces and Cgroups, while avoiding resource preemption issues between modules. 2) Fault isolation and quick recovery. A single module crashing or malfunctioning will not directly affect the stability of other modules and the overall all-in-one machine. The container can be automatically restarted within 10 seconds, which has a shorter recovery time and less impact compared to a physical restart of the all-in-one machine. 3) Simplified dependency management. The dependency libraries of each module (such as Python version, Java environment, etc.) can be independently encapsulated in the container, avoiding global dependency conflicts, etc.

[0081] Step 2: Allocate the first password card to the database encryption module, basic password service module, and hypervisor module. Through the driver, assign independent character device interfaces ( / dev / sdf1_2, / dev / sdf1_3) to each module, and the keys are stored isolated by module within the first password card.

[0082] The database encryption module, basic password module, and hypervisor module share the use of Password Card 1 for password calculation, and the keys of each module are stored encrypted and isolated within Password Card 1. The database encryption module and basic password module of the all-in-one machine respectively provide storage encryption and basic password service functions for the application services in the intranet environment of the information system. The hypervisor module is responsible for managing the all-in-one machine in the intranet environment. Due to the actual situation that the above three modules all work in the intranet environment of the information system and meet the requirements of information system cryptographic evaluation, Password Card 1 has perfect key isolation and protection capabilities, and sharing the same password card resource complies with the compliance requirements of relevant cryptographic evaluation specifications such as "GB / T 39786-2021 Information Security Technology - Basic Requirements for Cryptographic Applications in Information Systems".

[0083] After the password card driver is installed on the all-in-one machine, several character device interfaces for password card 1 and password card 2 will be automatically created. Password card 1 strictly follows the "Password Device Application Interface Specification" (GM / T 0018) standard and provides a compliant API dynamic link library (libsdf.so). When the all-in-one machine management program module, database encryption module, and basic password service module are started, they will respectively and independently occupy specific character devices of password card 1 and load the corresponding API dynamic libraries. During the business operation, each module obtains independent device handles by calling the standard interface functions (specifically SDF_OpenDevice) in the dynamic library, and based on these handles, realizes secure calls to password card 1, and completes password operation services including symmetric, asymmetric, and hashing algorithms. By implementing a dual access control mechanism at the driver layer (allocating different character devices) and the API layer (obtaining different device handles), it ensures the secure isolation of the data transmission channel of password card 1 and effectively guarantees the security of the input and output data during the password operation of different modules.

[0084] Step 3: Allocate a second password card for the VPN service module, and allocate an independent character device interface ( / dev / sdf2_2) through the driver. The key is independently stored in the second password card.

[0085] The VPN service module uses password card 2 for password calculation, and the key used by the VPN service module is encrypted and stored in password card 2;

[0086] The VPN service module in the all-in-one machine strictly follows the "SSL VPN Technology Specification" (GM / T0024), provides password functions such as identity authentication and transmission encryption, and effectively guarantees the security of users' remote access to internal application services of the information system through the Internet. Given that the VPN client runs on the terminal device on the Internet side and needs to establish a secure channel with the VPN server through the external network port of the all-in-one machine, its network environment is essentially different from other modules working in the internal network. To meet the compliance requirements of password resource isolation in relevant cryptographic evaluation specifications such as "GB / T 39786-2021", the VPN service module uses an independent password card 2 for password operation, implementing multiple access control mechanisms at the driver layer (allocating different character devices), API layer (obtaining different device handles), and hardware layer, ensuring the secure isolation of the data transmission channel of password card 2, and effectively guaranteeing the security of the input and output data during the password operation of the VPN service module. Step 4: Create a virtual bridge bridge1 and bind it to the internal network port 1 (port 1), connect the database encryption module and the basic password service module to bridge1, and configure the firewall rules to prohibit bridge1 from communicating with other bridges.

[0087] Container 1 and container 2 are connected to network card port 1 through virtual bridge bridge1, and provide database encryption services and basic password services to intranet applications through network card port 1; basic password modules and database encryption modules are deployed in containers 1 and 2 respectively, both of which work in the information system intranet environment and meet the requirements of information system key assessment. Sharing the same network card port (intranet port 1) is in compliance with / does not violate the compliance requirements of network traffic security isolation in relevant key assessment specifications such as "GB / T 39786-2021".

[0088] The specific design process is to create a virtual bridge bridge1 for the all-in-one machine and bind it to network card port 1 (intranet port 1). Container 1 and container 2 are connected to virtual bridge bridge1 at the same time. A firewall is configured to strictly isolate cross-virtual bridge communications, ensuring that the basic password module and database encryption module can only communicate with the external network through intranet port 1. The firewall rules for the virtual bridge are configured through iptables as follows:

[0089] Forward chain communication between bridge1 and bridge2, bridge3, and bridge4 is prohibited; only traffic between bridge3 and bridge4 is allowed to be transmitted through TCP port 443, and the data must be encrypted by SM4.

[0090] Step 5: Create a virtual bridge bridge2 and bind it to the management network port (port 2), connect the management program module to bridge2, and configure firewall rules to allow access only to the management terminal IP.

[0091] Container 3, which deploys a hypervisor module and operates within the information system intranet environment and meets the requirements of information system security assessments, occupies a dedicated network card port (management port) and complies with / does not violate the network traffic security isolation compliance requirements of relevant security assessment standards such as "GB / T 39786-2021." Furthermore, national security product specifications such as the "Security Authentication Gateway Product Specification" (GM / T 0026) and the "Server Cryptography Machine Technical Specification" (GM / T 0030) require a management interface for external hardware interfaces.

[0092] The specific design process is to create a virtual bridge bridge2 on the all-in-one machine and bind the network card port 2 (management port), connect container 3 to the virtual bridge bridge2, configure the firewall to strictly isolate cross-virtual bridge communication, and implement the management program module to communicate with the external network only through the management port.

[0093] Step 6: Create virtual bridges bridge3 and bridge4, bind them to the external network interface (port 3) and the internal network interface 2 (port 4) respectively, connect the VPN service module to bridge3 and bridge4, and configure the firewall rules to only allow encrypted traffic forwarding between bridge3 and bridge4.

[0094] Container 4 is connected to network card port 3 through virtual bridge bridge3, and connected to the external network through network card port 3, providing a transmission encryption channel service for VPN clients to access internal network applications; Container 4 is connected to network card port 4 through virtual bridge bridge4, and connected to internal network applications through network card port 4, forwarding the decrypted access traffic for the applications; Container 4 realizes isolation between the external and internal networks and encrypted communication through different network card ports.

[0095] The VPN service module deployed inside Container 4 follows the "SSL VPN Technical Specification" (GM / T 0024). The product external hardware interface requirements in the relevant "SSLVPN Gateway Product Specification" (GM / T 0025) have working network interfaces, and there should be at least two working network interfaces, namely the internal network interface and the external network interface. At the same time, considering that the network environment in which the VPN service module operates is essentially different from other modules of the all-in-one machine, in order to meet the compliance requirements for network traffic isolation in relevant cryptographic evaluation specifications such as "GB / T 39786-2021", the VPN service module requires two exclusive network card ports, namely network card port 3 (external network interface) and network card port 4 (internal network interface 2).

[0096] The specific design process is to create a virtual bridge bridge3 for the all-in-one machine and bind it to network card port 3 (external network interface), create a virtual bridge bridge4 and bind it to network card port 4 (internal network interface 2), connect Container 4 to virtual bridges bridge3 and bridge4 respectively, and configure the firewall to strictly isolate cross-virtual bridge communication, so that the VPN service module can only communicate with VPN clients in the Internet environment through the external network interface, and can only communicate with application services in the internal network environment of the information system through internal network interface 2.

[0097] An example of the key negotiation of the VPN service module is as follows: The VPN client and the server negotiate the working key based on the GM / T 0024 standard: The client sends a ClientHello message containing a list of supported cipher suites (such as TLS_SM4_SM3); The server returns a ServerHello message, selects a cipher suite and sends an SM2 certificate; After the client verifies the certificate, it generates a pre-master key, encrypts it with the server's SM2 public key and sends it; Both parties generate a session key based on the pre-master key for SM4 data encryption.

[0098] The present invention adopts a software-hardware combined isolation technology to achieve the mutual isolation of network traffic, key data, and cryptographic boundaries among different cryptographic modules within a single device, ensuring clear boundaries for multiple types of cryptographic modules inside the device, secure storage of various types of keys, and secure transmission of multi-level traffic, providing an integrated comprehensive cryptographic function for information systems, capable of meeting the technical requirements in cryptographic evaluation with a single device, and enabling the transformed information system to pass the cryptographic evaluation without modification.

[0099] The above has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, various changes and improvements will occur to the present invention, and all these changes and improvements fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.

Claims

1. A transmission and storage encryption all-in-one machine for the security evaluation of password applications, characterized in that Including: An industrial control computer, configured with a Docker container and a 4-port network card; A first cryptographic card and a second cryptographic card, both having PCI-E interfaces, independently providing key management and cryptographic calculation functions respectively; A VPN service module, a database encryption module, a basic cryptographic service module, and a management program module, which are respectively deployed in independent Docker containers of the industrial control computer; The Docker container provides isolated CPU, memory, and storage space for each module through Linux namespaces and Cgroups technology; The second cryptographic card provides exclusive key storage and cryptographic calculation functions for the VPN service module, and the first cryptographic card provides exclusive key storage and cryptographic calculation functions for the database encryption module and the basic cryptographic service module; The 4-port network card is allocated as follows: The external network port is bound to the VPN service module for establishing an encrypted transmission channel with the VPN client; The internal network port 2 is bound to the VPN service module for forwarding the decrypted traffic to the internal network application; The internal network port 1 is bound to the database encryption module and the basic cryptographic service module for communicating with the internal network application; The management network port is bound to the management program module for device management; The network traffic of each module is bound to an independent network port through a virtual bridge, and firewall rules are configured to prohibit cross-virtual bridge communication to achieve network traffic isolation.

2. The integrated transmission, storage and encryption machine according to claim 1, characterized in that: The first cryptographic card and the second cryptographic card are connected to the industrial control computer through PCI-E interfaces, and the cryptographic card driver assigns independent character device interfaces to each module and provides independent device handles for each module through a dynamic link library to achieve physical isolation of key storage and calculation.

3. The transmission and storage encryption integrated machine according to claim 1, characterized in that: The VPN service module implements the SSLVPN protocol based on the GM / T 0024 standard, specifically including: performing two-way authentication on the VPN client and the server according to the mutual authentication mechanism; negotiating a working key with the client through the external network port and encrypting communication data using the SM4 algorithm; forwarding the decrypted plaintext traffic to the internal network application through the internal network port 2, and the encryption / decryption operation is completed by the second cryptographic card.

4. The transmission and storage encryption all-in-one machine according to claim 1, wherein: The database encryption module intercepts SQL statements through a database encryption plug-in and performs transparent encryption and decryption on specified database fields according to the policies configured by the management program module, specifically including: When writing data, intercept sensitive fields in the SQL statement, send them to the first cryptographic card for encryption through the internal network port 1 and then store them; When reading data, intercept the encrypted fields, decrypt them through the first cryptographic card and return the plaintext; The encryption and decryption policies include field names, algorithm types, and modes, and the keys are stored in the first cryptographic card.

5. The transmission and storage encryption integrated machine according to claim 1, characterized in that: The management program module provides two-factor authentication based on a USB Key, specifically including: verifying the administrator's identity according to the one-way authentication mechanism; Receiving operation instructions from the management terminal through the management network port to complete cryptographic card initialization, log auditing, and full life cycle management of keys; Communicating with other modules through a virtual bridge, and configuring firewall rules to prohibit non-management traffic access.

6. The integrated transmission, storage, and encryption machine according to claim 1, wherein: The basic cryptographic service module provides national cryptographic algorithms services for intranet applications through APIs, including: Invoking the first cryptographic card to complete SM2 asymmetric encryption, SM3 hash calculation, and SM4 symmetric encryption and decryption; Receiving application requests through the intranet port 1 and returning calculation results, and the keys are stored in isolation by module in the first cryptographic card.

7. An implementation method of a transmission and storage encryption integrated machine for the security evaluation of password applications, characterized in that, It includes the following steps: Step 1: Deploy the database encryption module, basic cryptographic service module, management program module, and VPN service module in independent Docker containers of the industrial control computer, isolate CPU and memory resources through namespaces, and limit storage space through Cgroups; Step 2: Allocate the first cryptographic card to the database encryption module, basic cryptographic service module, and management program module, allocate independent character device interfaces of the first cryptographic card created after installing the driver for each module, and the keys are stored in isolation by module within the first cryptographic card; Step 3: Allocate the second cryptographic card to the VPN service module, allocate an independent character device interface of the second cryptographic card created after installing the driver, and the keys are stored independently within the second cryptographic card; Step 4: Create a virtual bridge bridge1 and bind it to the intranet port 1, connect the database encryption module and the basic cryptographic service module to bridge1, and configure firewall rules to prohibit bridge1 from communicating with other bridges; Step 5: Create a virtual bridge bridge2 and bind it to the management network port, connect the management program module to bridge2, and configure firewall rules to only allow access from the management terminal IP; Step 6: Create virtual bridges bridge3 and bridge4, bind them to the external network port and the intranet port 2 respectively, connect the VPN service module to bridge3 and bridge4, and configure firewall rules to only allow encrypted traffic forwarding between bridge3 and bridge4.

8. The method according to claim 7, wherein: In the said Step 2 and Step 3, after each module exclusively occupies different character devices when starting up, the SDF_OpenDevice function is called through the dynamic link library to return independent device handles for each module, ensuring the isolation of the password card operation instruction transmission channels.

9. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored program, wherein the program, when running, controls the device where the non-volatile storage medium is located to execute the method described in claim 7.

10. A terminal device, characterized in that, The terminal device includes: a processor, a memory, a communication interface, and a bus; the processor, the memory, and the communication interface are connected through the bus and complete communication with each other; the memory stores executable program code; the processor runs the program corresponding to the executable program code by reading the executable program code stored in the memory to be used to execute the method described in claim 7 above.