Industrial switch operation system based on port access security verification
By analyzing the connection status and indication of switch ports, combined with electrical and operating conditions, the impact on safety supervision and performance of industrial switches is reduced, and the problems of low port supervision efficiency and difficult to detect safety hazards in the existing technology are solved, and the operation stability and efficiency of switches are improved.
Patent Information
- Application Number
- CN202510627725.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-08-05
AI Technical Summary
Existing industrial switches are difficult to effectively regulate port connection status and connection security, resulting in an increase in potential risks, reducing port supervision efficiency and industrial switch operation efficiency, and lacking monitoring of the overall performance and individual performance of the port, making it difficult to detect security risks in advance.
Through the combination of the access processor, access supervision unit, access security unit, single point access unit, operation impact unit and security response unit, the connection status and indication of each port of the switch are analyzed, divided and managed, and the port access switching warning is performed based on information feedback, and the port normality is evaluated from the electrical and operating conditions dimensions to reduce the performance impact.
It improves the operating stability and supervision efficiency of industrial switches, ensures port docking compatibility, reduces the impact of port access equipment on switch performance, and enhances security and operation efficiency.
Smart Images

Figure CN120434211A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of switch supervision, and in particular to an industrial switch operation system based on port access security verification. Background Art
[0002] Ethernet switch equipment used in the industrial control field has become the main communication standard in the industrial control field due to its openness, wide application, low price, and transparent and unified TCP / IP protocol.
[0003] Industrial switches play a vital role in industrial networks. The security of their port access is directly related to the stable operation and data security of the industrial network. However, existing industrial switches struggle to effectively monitor the connection status and security of their ports, increasing potential risks associated with port connection and reducing port monitoring efficiency and the operational efficiency of the industrial switches. Furthermore, existing industrial switches lack the ability to monitor both the overall and individual performance of ports, making it difficult to proactively identify potential security risks and take timely action, impacting the operational performance of the industrial switches.
[0004] In view of the above technical defects, a solution is now proposed. Summary of the Invention
[0005] The purpose of the present invention is to provide an industrial switch operation system based on port access security verification to solve the technical defects mentioned above. The present invention initially analyzes the connection status and indication status of each port of the industrial switch. On the one hand, it intuitively connects to the docking status of each docking port, and on the other hand, it helps to divide and manage the ports in a targeted manner. Based on information feedback, a port access switching warning is issued to the equipment connected to the normal port, so as to reasonably and accurately perform port docking on the access equipment. The normal port is further evaluated from the two dimensions of electrical and working conditions of the normal port to determine whether it is normal, so as to rationally manage the normal port and reduce the impact of the normal port on subsequent access. At the same time, analysis is conducted from the two points of access performance and statistics to reduce the impact of the port access equipment on the performance of the industrial switch.
[0006] The object of the present invention can be achieved by the following technical solutions: an industrial switch operation system based on port access security verification, comprising an access processor, an access supervision unit, an access security unit, a single point access unit, an operation impact unit, and a security response unit;
[0007] The access processor is used to retrieve the basic port data of each port of the industrial switch, and send the basic port data to the access supervision unit for validity access division management analysis, and perform discrimination processing on the obtained indication status information to obtain normal ports and loose ports;
[0008] The access security unit is used to track and monitor access security based on the collected basic data of devices connected to normal ports. The obtained device connection protocol names are compared with the connection protocol list to determine whether the signal is available or unavailable.
[0009] The single-point access unit is used to evaluate and analyze the basic access characteristics of the security supervision data collected from normal ports, identify the obtained electrical evaluation index and working condition defect coefficient, and obtain risk signals or stability signals;
[0010] The operation impact unit is used to perform operation access performance impact analysis on the collected access performance information of normal ports and error statistics of normal ports, judge and process the obtained resource occupancy level and error interference depth, and obtain normal operation signals or operation defect signals.
[0011] Preferably, the validity access division management analysis process is as follows: the operating time period of the industrial switch is collected, and the operating time period of the industrial switch is set as a time threshold, and the port basic data of each port of the industrial switch within the time threshold is obtained. The port basic data includes a connection state and an unconnected state. The connection state indicates that a connection line is plugged in, and the unconnected state indicates that no connection line is plugged in. The port basic data is judged and processed. If the port basic data is a connection state, the corresponding port is set as a docking port. If the port basic data is an unconnected state, the corresponding port is set as an idle port.
[0012] Preferably, the indication status information of each docking port within the time threshold is obtained, and the indication status information includes the connection indicator light on and the connection indicator light off. The indication status information is judged and processed. If the indication status information is that the connection indicator light is on, it is judged to be a normal port and a connection signal is generated. If the indication status information is that the connection indicator light is off, it is judged to be a loose port and a disconnection signal is generated.
[0013] Preferably, the access security tracking, supervision and analysis process is as follows: obtain the basic docking data of the equipment connected to each normal port within the time threshold, the docking basic data includes MAC address and IP address, and at the same time obtain the basic docking data of the equipment connected to all ports of the historical industrial switch that have passed security verification, build a historical docking authentication list based on the docking basic data, and compare and analyze the docking basic data with the docking authentication list: if the docking basic data belongs to the docking authentication list, generate a configuration signal; if the docking basic data does not belong to the docking authentication list, generate an unauthorized signal.
[0014] Preferably, when a configuration signal is generated, the docking protocol name supported by the normal port within the time threshold is obtained, a docking protocol list is constructed based on the docking protocol name supported by the normal port, the docking protocol name of the device connected to the normal port is obtained, and the device docking protocol name is compared and analyzed with the docking protocol list. If the device docking protocol name belongs to the docking protocol list, an available signal is generated; if the device docking protocol name does not belong to the docking protocol list, an unavailable signal is generated.
[0015] Preferably, the basic access feature evaluation and analysis process is as follows: obtain the safety supervision data of each normal port within the time threshold, the safety supervision data includes the electrical evaluation index and the operating condition defect coefficient, and judge the electrical evaluation index and the operating condition defect coefficient: if the electrical evaluation index is not equal to the preset electrical evaluation index threshold, or the operating condition defect coefficient is not equal to the preset operating condition defect coefficient threshold, then a risk signal is generated; if the electrical evaluation index is equal to the preset electrical evaluation index threshold, and the operating condition defect coefficient is equal to the preset operating condition defect coefficient threshold, then a stable signal is generated.
[0016] Preferably, the electrical evaluation index indicates that the corresponding values of the parameters in the electrical parameters of the normal port meet the corresponding number within the set range, and the electrical parameters include voltage, current, and power. The operating condition defect coefficient indicates that the corresponding values of the parameters in the network traffic of the normal port meet the corresponding number within the set range, and the network traffic includes upload traffic and download traffic.
[0017] Preferably, the operation access performance impact analysis process is as follows:
[0018] Access performance information of normal ports within a time threshold is obtained, including memory percentage and CPU percentage. The sum of the memory percentage and CPU percentage of each normal port is then obtained, and the sum of the memory percentage and CPU percentage is set as the resource utilization level.
[0019] Obtain error statistics of each normal port within the time threshold, including CRC errors and frame errors. Obtain the total number of error statistics of each normal port and set it as the error statistics. Set the proportion of the total number of normal ports whose error statistics are greater than the preset error statistics threshold as the error interference depth. Discriminate and process the resource occupancy level and the error interference depth to obtain a normal operation signal or an operation defect signal.
[0020] The beneficial effects of the present invention are as follows:
[0021] (1) The present invention initially analyzes the connection status and indication status of each port of the industrial switch. On the one hand, it intuitively connects to the docking status of each docking port, and on the other hand, it helps to divide and manage the ports in a targeted manner, thereby improving the operational stability of the industrial switch. Access security tracking and supervision analysis is further performed in an information progressive manner, so that port access switching warnings can be issued to devices connected to normal ports based on information feedback, so as to reasonably and accurately perform port docking of access devices. On the one hand, it ensures port docking compatibility, and on the other hand, it helps to improve port supervision efficiency and the operational efficiency of the industrial switch;
[0022] (2) The present invention further evaluates whether the normal port is normal from the two dimensions of electrical and working conditions of the normal port, so as to rationally manage the normal port and reduce the impact of the normal port on subsequent access. At the same time, it analyzes from the two points of access performance and statistics to determine the risk of access equipment affecting the performance of the industrial switch, so as to manage the normal ports of the industrial switch and reduce the impact of the port access equipment on the performance of the industrial switch. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The present invention will be further described below with reference to the accompanying drawings;
[0024] Figure 1 It is a flow chart of the system of the present invention;
[0025] Figure 2 It is a reference diagram for local analysis of the present invention. DETAILED DESCRIPTION
[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0027] References to "embodiments" herein mean that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments;
[0028] Example 1:
[0029] See also Figures 1 to 2As shown, the present invention is an industrial switch operation system based on port access security verification, including an access processor, an access supervision unit, an access security unit, a single-point access unit, an operation-affecting unit, and a security response unit. The access processor is connected to the access supervision unit in a bidirectional communication manner, the access processor is connected to the access security unit in a unidirectional communication manner, the access supervision unit is connected to the security response unit in a unidirectional communication manner, the access security unit is connected to both the single-point access unit and the operation-affecting unit in a unidirectional communication manner, the operation-affecting unit is connected to the security response unit in a unidirectional communication manner, and the single-point access unit is connected to the security response unit in a unidirectional communication manner.
[0030] The access processor is used to retrieve the basic port data of each port of the industrial switch and send the basic port data to the access supervision unit for effective access partition management analysis. On the one hand, it can intuitively connect to the docking status of each docking port. On the other hand, it helps to divide and manage the ports in a targeted manner, thereby improving the operational stability of the industrial switch. The specific effective access partition management analysis process is as follows:
[0031] The operating time period of the industrial switch is collected and set as a time threshold. The basic port data of each port of the industrial switch within the time threshold is obtained. The basic port data includes a connection state and an unconnected state. The connection state indicates that a connection cable is plugged in, and the unconnected state indicates that no connection cable is plugged in. The basic port data is judged and processed. If the basic port data indicates a connection state, the corresponding port is set as a docking port. If the basic port data indicates an unconnected state, the corresponding port is set as an idle port.
[0032] The indication status information of each docking port within the time threshold is obtained, and the indication status information includes the connection indicator light and the connection indicator light off. The indication status information is judged and processed. If the indication status information shows that the connection indicator light is on, it is determined to be a normal port and a connection signal is generated. If the indication status information shows that the connection indicator light is off, it is determined to be a loose port and a disconnection signal is generated. The security response unit is used to respond to the connection signal and the disconnection signal, so as to divide and manage the normal port and the loose port based on the connection signal and the disconnection signal. On the one hand, the docking status of each docking port is intuitively connected, and on the other hand, it helps to divide and manage the ports in a targeted manner, thereby improving the operational stability of the industrial switch;
[0033] When a connection signal is generated, the access security unit is used to perform access security tracking, supervision, and analysis on the collected basic data of the devices connected to the normal ports. This allows for port access switching warnings for the devices connected to the normal ports based on information feedback, allowing for reasonable and accurate port docking of the access devices. This ensures port docking compatibility and helps improve port supervision efficiency and the operating efficiency of the industrial switch. The specific access security tracking, supervision, and analysis process is as follows:
[0034] The system obtains basic docking data of devices connected to each normal port within the time threshold. The docking basic data includes MAC addresses, IP addresses, etc., and also obtains basic docking data of devices connected to all ports of the industrial switch that have passed security verification. Based on the docking basic data, a historical docking authentication list is constructed. The docking basic data is compared and analyzed with the docking authentication list. If the docking basic data belongs to the docking authentication list, a configuration signal is generated. If the docking basic data does not belong to the docking authentication list, an unauthorized signal is generated. The security response unit is used to respond to the unauthorized signal and apply for security authentication or deny access to the device corresponding to the unauthorized signal, thereby improving the operational security of the industrial switch.
[0035] When a configuration signal is generated, the names of the docking protocols supported by the normal port within the time threshold are obtained, a docking protocol list is constructed based on the names of the docking protocols supported by the normal port, the names of the docking protocols of the devices connected to the normal port are obtained, and the device docking protocol names are compared and analyzed with the docking protocol list. If the device docking protocol name belongs to the docking protocol list, an available signal is generated; if the device docking protocol name does not belong to the docking protocol list, an unavailable signal is generated. The security response unit is used to respond to the available signal or the unavailable signal, so as to provide a port access switching warning for the device connected to the normal port based on information feedback, so as to reasonably and accurately perform port docking on the access device, thereby ensuring port docking compatibility on the one hand and helping to improve port supervision efficiency and industrial switch operation efficiency on the other hand.
[0036] For example, the interconnection protocol name is TCP / IP, Modbus, Profinet, etc.
[0037] Example 2:
[0038] When a usable signal is generated, the single-point access unit is used to perform basic access feature evaluation and analysis on the collected security supervision data of the normal port. That is, the normal port is further evaluated in terms of electrical and working conditions to determine whether it is normal. This allows for rational management of the normal port to reduce its impact on subsequent access. The specific basic access feature evaluation and analysis process is as follows:
[0039] Obtain the safety supervision data of each normal port within the time threshold, the safety supervision data including the electrical evaluation index and the working condition defect coefficient, and judge the electrical evaluation index and the working condition defect coefficient: if the electrical evaluation index is not equal to the preset electrical evaluation index threshold, or the working condition defect coefficient is not equal to the preset working condition defect coefficient threshold, then generate a risk signal; if the electrical evaluation index is equal to the preset electrical evaluation index threshold, and the working condition defect coefficient is equal to the preset working condition defect coefficient threshold, then generate a stable signal. The safety response unit is used to respond to the risk signal or the stable signal, so as to further perform security division on the normal port, and then perform targeted management on the normal port with risk, thereby improving the port status security;
[0040] The electrical evaluation index indicates the number of normal ports whose electrical parameters (including voltage, current, and power) fall within the set range. The operating condition defect coefficient indicates the number of normal ports whose network traffic (including upload and download traffic) falls within the set range. It should be noted that the normality of a normal port is further assessed from both the electrical and operating condition perspectives to rationalize its management and reduce its impact on subsequent access.
[0041] When the available signal and stable signal are generated, the operation impact unit is used to perform operation access performance impact analysis on the collected access performance information and error statistics of normal ports to determine the performance impact risk of the access device on the industrial switch, so as to manage the normal ports of the industrial switch and reduce the performance impact of the port access device on the industrial switch. The specific operation access performance impact analysis process is as follows:
[0042] Access performance information of normal ports within the time threshold is obtained. Access performance information includes memory percentage and CPU percentage. The sum of the memory percentage and CPU percentage of each normal port is obtained and set as the resource utilization level. The larger the resource utilization level, the greater the impact on the performance and stability of the industrial switch.
[0043] Obtain error statistics for each normal port within a time threshold. Error statistics include CRC errors, frame errors, etc. Obtain the total number of error statistics for each normal port and set it as the error statistics. Set the percentage of normal ports with error statistics greater than the preset error statistics threshold as the error interference depth. The larger the error interference depth, the greater the impact on the performance of the industrial switch.
[0044] The resource occupancy level and error interference depth are judged and processed: if the resource occupancy level is less than a preset resource occupancy level threshold, and the error interference depth is less than a preset error interference depth threshold, a normal operation signal is generated; if the resource occupancy level is greater than or equal to the preset resource occupancy level threshold, or the error interference depth is greater than or equal to the preset error interference depth threshold, an operation defect signal is generated. The security response unit is used to respond to the normal operation signal or the operation defect signal and immediately manage the normal ports of the industrial switch to reduce the impact of the port access device on the performance of the industrial switch, thereby improving the operational safety and efficiency of the industrial switch;
[0045] To sum up, the present invention preliminarily analyzes the connection status and indication status of each port of the industrial switch. On the one hand, it intuitively connects to the docking status of each docking port, and on the other hand, it helps to divide the ports and manage them in a targeted manner, thereby improving the operating stability of the industrial switch. Access security tracking and supervision analysis is further performed in an information progressive manner, so that port access switching warnings can be issued to devices connected to normal ports based on information feedback, so as to reasonably and accurately perform port docking of access devices. On the one hand, it ensures port docking compatibility, and on the other hand, it helps to improve port supervision efficiency and the operating efficiency of the industrial switch. Whether the normal port is normal is further evaluated from the two dimensions of electrical and working conditions of the normal port, so as to rationally manage the normal port to reduce the impact of the normal port on subsequent access. At the same time, analysis is performed from the access performance and statistics to judge the risk of access equipment affecting the performance of the industrial switch, so as to manage the normal ports of the industrial switch to reduce the degree of impact of the port access equipment on the performance of the industrial switch.
[0046] The threshold is set for result comparison and analysis to determine whether it is good or bad. The value of the threshold is set based on a combination of large-scale model analysis of sample data and manual experience to enter and store data. It can also be appropriately adjusted based on seasonal or common sense influencing conditions.
[0047] The size of the coefficient is to quantify each parameter to obtain a specific numerical value, which is convenient for subsequent comparison. The size of the coefficient depends on the amount of sample data and the preliminary setting of the corresponding operating coefficient for each set of sample data by technical personnel in this field; as long as it does not affect the proportional relationship between the parameter and the quantized value.
[0048] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.
Claims
1. An industrial switch operation system based on port access security verification, characterized in that: Includes access processor, access supervision unit, access security unit, single point access unit, operation impact unit and security response unit; The access processor is used to retrieve the basic port data of each port of the industrial switch, and send the basic port data to the access supervision unit for validity access division management analysis, and perform discrimination processing on the obtained indication status information to obtain normal ports and loose ports; The access security unit is used to track and monitor access security based on the collected basic data of devices connected to normal ports. The obtained device connection protocol names are compared with the connection protocol list to determine whether the signal is available or unavailable. The single-point access unit is used to evaluate and analyze the basic access characteristics of the security supervision data collected from normal ports, identify the obtained electrical evaluation index and working condition defect coefficient, and obtain risk signals or stability signals; The operation impact unit is used to perform operation access performance impact analysis on the collected access performance information of normal ports and error statistics of normal ports, judge and process the obtained resource occupancy level and error interference depth, and obtain normal operation signals or operation defect signals.
2. The industrial switch operation system based on port access security verification according to claim 1, characterized in that: The effectiveness access partitioning management analysis process is as follows: the operating time period of the industrial switch is collected, and the operating time period of the industrial switch is set as a time threshold, and the port basic data of each port of the industrial switch within the time threshold is obtained. The port basic data includes a connection state and an unconnected state. The connection state indicates that a connection line is plugged in, and the unconnected state indicates that no connection line is plugged in. The port basic data is judged and processed. If the port basic data is a connection state, the corresponding port is set as a docking port. If the port basic data is an unconnected state, the corresponding port is set as an idle port.
3. The industrial switch operation system based on port access security verification according to claim 2, characterized in that: The indication status information of each docking port within the time threshold is obtained. The indication status information includes the connection indicator light on and the connection indicator light off. The indication status information is judged and processed. If the indication status information shows that the connection indicator light is on, it is determined to be a normal port and a connection signal is generated. If the indication status information shows that the connection indicator light is off, it is determined to be a loose port and a disconnection signal is generated.
4. The industrial switch operation system based on port access security verification according to claim 1, characterized in that: The access security tracking, supervision and analysis process is as follows: obtain the basic docking data of the devices connected to each normal port within the time threshold, the docking basic data includes MAC address and IP address, and at the same time obtain the basic docking data of the devices connected to all ports of the historical industrial switch that have passed security verification, build a historical docking authentication list based on the docking basic data, and compare and analyze the docking basic data with the docking authentication list: if the docking basic data belongs to the docking authentication list, generate a configuration signal; if the docking basic data does not belong to the docking authentication list, generate an unauthorized signal.
5. The industrial switch operation system based on port access security verification according to claim 4 is characterized in that: When the configuration signal is generated, the docking protocol names supported by the normal port within the time threshold are obtained, a docking protocol list is constructed based on the docking protocol names supported by the normal port, the docking protocol name of the device connected to the normal port is obtained, and the device docking protocol name is compared and analyzed with the docking protocol list. If the device docking protocol name belongs to the docking protocol list, an available signal is generated. If the device docking protocol name does not belong to the docking protocol list, an unavailable signal is generated.
6. The industrial switch operation system based on port access security verification according to claim 1, characterized in that: The basic access feature evaluation and analysis process is as follows: obtain the security supervision data of each normal port within the time threshold, the security supervision data includes the electrical evaluation index and the operating condition defect coefficient, and judge the electrical evaluation index and the operating condition defect coefficient: if the electrical evaluation index is not equal to the preset electrical evaluation index threshold, or the operating condition defect coefficient is not equal to the preset operating condition defect coefficient threshold, then a risk signal is generated; if the electrical evaluation index is equal to the preset electrical evaluation index threshold, and the operating condition defect coefficient is equal to the preset operating condition defect coefficient threshold, then a stable signal is generated.
7. The industrial switch operation system based on port access security verification according to claim 6, characterized in that: The electrical evaluation index indicates that the corresponding values of the electrical parameters of the normal port are within the set range. The electrical parameters include voltage, current, and power. The operating condition defect coefficient indicates that the corresponding values of the parameters in the network traffic of the normal port are within the set range. The network traffic includes upload traffic and download traffic.
8. The industrial switch operation system based on port access security verification according to claim 1, characterized in that: The operation access performance impact analysis process is as follows: Access performance information of normal ports within a time threshold is obtained, including memory percentage and CPU percentage. The sum of the memory percentage and CPU percentage of each normal port is then obtained, and the sum of the memory percentage and CPU percentage is set as the resource utilization level. Obtain error statistics of each normal port within the time threshold, including CRC errors and frame errors. Obtain the total number of error statistics of each normal port and set it as the error statistics. Set the proportion of the total number of normal ports whose error statistics are greater than the preset error statistics threshold as the error interference depth. Discriminate and process the resource occupancy level and the error interference depth to obtain a normal operation signal or an operation defect signal.
Citation Information
Patent Citations
Fault diagnosis method for Ethernet switch of intelligent substation
CN110417623A
Switch port state indication method and equipment
CN116800702A
Switch port state monitoring method
CN118233795A
Security detection method based on Internet of Things security switch and related device
CN118353921A
Operation state detection early warning system suitable for optical network communication equipment
CN119109511A
Cited By
Intelligent monitoring method for butt joint state of communication equipment connector
CN121309391A