An isolation device for protocols, access control method, device and medium
By combining dual-motherboard physical isolation and a time-division dual-ferry mechanism, the security and stability issues of data interaction in industrial networks are solved, enabling high-speed and secure data transmission, defending against forged message attacks, and optimizing resource allocation.
Patent Information
- Application Number
- CN202511394279.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-28
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2045-09-28
AI Technical Summary
Existing industrial network isolation solutions suffer from performance fluctuations due to single-motherboard architecture, low protocol parsing efficiency, insufficient physical isolation, and the risk of forged message attacks, failing to meet the high-speed data interaction requirements of the Industrial Internet of Things.
Employing a dual-motherboard physical isolation structure, combined with an isolated switching unit, and through a time-division dual-ferry mechanism and protocol status tracking, ModbusTCP packets achieve multi-dimensional policy verification and intelligent scheduling, ensuring the security and stability of data transmission.
It achieves security and stability for high-speed data interaction in the industrial IoT environment, blocks the risk of network protocol penetration, defends against forged message attacks, optimizes resource allocation, and reduces the latency of emergency command transmission.
Smart Images

Figure CN120880806B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial network boundary security, and in particular to a protocol isolation device, an access control method, equipment and a medium. BACKGROUND
[0002] The rise of the industrial internet enables industrial devices to achieve a higher degree of interconnectivity and data sharing, and the application of cloud computing and cloud platforms enables industrial control systems to better achieve remote monitoring, data storage and analysis. While the development of the above technologies provides convenience, it also brings certain data leakage risks.
[0003] In order to ensure data security, most industrial enterprises install isolation cards, isolation controls and other devices to divide the enterprise into two networks: an internal network and an external network. The internal network is used for internal communication and office automation, and the external network is used to interconnect with external industrial devices and build an industrial internet. However, the existing isolation control scheme has the following problems: 1) Single-board architecture limitations: Due to reliance on software virtualization isolation, the external network / internal network modules share computing resources, which causes performance fluctuations due to memory contention; internal and external network communication relies on external network interfaces, which is susceptible to electromagnetic interference. 2) Protocol parsing efficiency bottleneck: Traditional ferry designs have high latency in high-concurrency request scenarios, which cannot meet real-time control requirements; traditional schemes only check function codes, ignoring transaction ID continuity and register address association, which cannot prevent fake message attacks. 3) Insufficient physical isolation: Traditional ferry schemes use Ethernet communication, which cannot completely block network protocol penetration risks, and attackers may use TCP session hijacking.
[0004] Therefore, there is an urgent need to design a protocol isolation and control scheme that can meet the high-speed data interaction requirements of industrial internet of things and has stable performance and security. SUMMARY
[0005] The present application provides a protocol isolation device, an access control method, equipment and a medium, which can provide a protocol isolation and control scheme that can meet the high-speed data interaction requirements of industrial internet of things and has stable performance and security.
[0006] Therefore, the present application provides a protocol isolation device, an access control method, equipment and a medium, which can provide a protocol isolation and control scheme that can meet the high-speed data interaction requirements of industrial internet of things and has stable performance and security.
[0007] In the external network host system:
[0008] The first message analysis module is configured to analyze and parse the Modbus TCP message of the access device, acquire message information of the Modbus TCP message, and determine whether the Modbus TCP message is prohibited from passing through the isolation exchange unit according to the message information; if not, the Modbus TCP message is sent to the first protocol state module;
[0009] The first protocol state module is configured to check the transaction ID of the access device and record information of the transaction ID; if the checking result is correct, the Modbus TCP message is sent to the first access strategy module;
[0010] The first access strategy module is configured to perform multi-dimensional strategy checking on the Modbus TCP message according to a plurality of preset strategies, encapsulate the Modbus TCP message that passes the checking, and send the encapsulated Modbus TCP message to the first intelligent scheduling module.
[0011] The first intelligent scheduling module is configured to buffer the Modbus TCP message to be transmitted to obtain a first cache queue and set a transmission priority of the Modbus TCP message in the cache queue, adjust the first cache queue according to the transmission priority, and generate a first to-be-transmitted instruction according to the transmission priority and send the instruction to the isolation exchange unit.
[0012] The isolation exchange unit is configured to receive the first to-be-transmitted instruction, control the Modbus TCP message in the first cache queue to be transmitted according to the first to-be-transmitted instruction based on a preset time-sharing double-transport strategy, and ensure that the Modbus TCP message is transmitted from the external network host system to the internal network host system at a certain moment.
[0013] Optionally, the internal network host system comprises a second message analysis module, a second protocol state module, a second access strategy module, and a second intelligent scheduling module.
[0014] In the internal network host system,
[0015] The second message analysis module is configured to receive and parse the Modbus TCP message, and send the parsed information and the Modbus TCP message to the second protocol state module.
[0016] The second protocol state module is configured to check the security header of the Modbus TCP message according to the parsed information; if the checking is passed, the Modbus TCP message is sent to the second access strategy module, otherwise an alarm is issued.
[0017] The second access policy module is used to strip the security header from the verified ModbusTCP packet and send it to the intranet device for execution, and send the execution result of the intranet device to the second intelligent scheduling module;
[0018] The second intelligent scheduling module is used to cache the execution result to be transmitted to obtain a second cache queue and set the transmission priority of the execution result, adjust the second cache queue according to the transmission priority, and generate a second instruction to be transmitted according to the transmission priority and send it to the isolation switching unit.
[0019] The isolation switching unit is used to receive the second instruction to be transmitted, and based on a preset time-division dual-ferry strategy, control the transmission of the execution result in the second cache queue according to the second instruction to be transmitted, so that at a certain time only the execution result is transmitted from the internal network host system to the external network host system.
[0020] Optionally, the isolation switching unit is further configured to:
[0021] When both the first instruction to be transmitted and the second instruction to be transmitted are received simultaneously:
[0022] Based on a preset time-division dual-ferry strategy, the transmission order of the ModbusTCP message and the execution result is determined according to the reception time and transmission priority of the first instruction to be transmitted and the second instruction to be transmitted, so that at a certain time, only the ModbusTCP message is transmitted from the external network host system to the internal network host system, or only the execution result is transmitted from the internal network host system to the external network host system.
[0023] Optionally, determining the transmission order of the ModbusTCP message and the execution result based on the reception time and transmission priority of the first instruction to be transmitted and the second instruction to be transmitted includes:
[0024] When the transmission priorities of the first instruction to be transmitted and the second instruction to be transmitted are the same, the order of the receiving times is determined. When the first instruction to be transmitted received by the isolation switching unit is before the second instruction to be transmitted, the ModbusTCP message is transmitted from the external host system to the internal host system, and then the execution result is transmitted from the internal host system to the external host system.
[0025] Optionally, adjusting the first buffer queue according to the transmission priority includes:
[0026] The position of the ModbusTCP packet in the first buffer queue is adjusted according to the transmission priority of the ModbusTCP packet. The position of the ModbusTCP packet in the first buffer queue corresponds to the order of the transmission priority of the ModbusTCP packets.
[0027] Optionally, the isolation switching unit includes a physical isolation card and a control system;
[0028] The control system is configured to receive the first instruction to be transmitted and, based on a preset time-division dual-ferry strategy, control the physical isolation card to transmit the ModbusTCP packets in the first buffer queue, so that at a certain moment the physical isolation card only transmits the ModbusTCP packets from the external network host system to the internal network host system.
[0029] Optionally, the transmission priorities, from high to low, include: emergency control commands, status reading commands, log writing, and configuration updates.
[0030] The second aspect of this application provides an access control method for a protocol isolation device, applied to the protocol isolation device described in the first aspect above;
[0031] The method includes, in an external network host system:
[0032] The first message analysis module parses the ModbusTCP messages of the accessing device to obtain the message information of the ModbusTCP messages. Based on the message information, it determines whether to prohibit the ModbusTCP messages from passing through the isolation switching unit. Otherwise, the ModbusTCP messages are sent to the first protocol status module.
[0033] The first protocol status module verifies the transaction ID of the access device and records the information of the transaction ID. If the verification result is consistent, the ModbusTCP message is sent to the first access policy module.
[0034] The first access strategy module performs multi-dimensional policy verification on the ModbusTCP packets according to several preset policies, encapsulates the ModbusTCP packets that pass the verification, and sends the encapsulated ModbusTCP packets to the first intelligent scheduling module.
[0035] After the first intelligent scheduling module buffers the ModbusTCP packets to be transmitted to obtain a first buffer queue, it sets the transmission priority of the ModbusTCP packets in the buffer queue, adjusts the first buffer queue according to the transmission priority, and generates a first transmission instruction according to the transmission priority and sends it to the isolation switching unit.
[0036] The first instruction to be transmitted is received by the isolation switching unit, and based on the preset time-division dual-ferry strategy, the ModbusTCP packets in the first buffer queue are controlled to be transmitted according to the first instruction to be transmitted, so that at a certain time only the ModbusTCP packets are transmitted from the external network host system to the internal network host system.
[0037] A third aspect of the present invention provides a control device for an isolation apparatus for a protocol, the device comprising a processor and a memory:
[0038] The memory is used to store program code and transmit the program code to the processor;
[0039] The processor is configured to execute, according to instructions in the program code, the steps of the access control method for the protocol isolation device as described in the first aspect above.
[0040] A fourth aspect of the present invention provides a computer-readable storage medium for storing program code for executing the access control method for an isolation device of a protocol as described in the first aspect above.
[0041] As can be seen from the above technical solutions, the present invention has the following advantages:
[0042] This invention provides a protocol isolation device, comprising: 1) a dual-motherboard physical isolation (external network host system and internal network host system) and an isolation switching unit (physical module), which blocks attack paths at the physical layer and improves anti-interference capabilities through independent hardware modules (external network host system and internal network host system) and the isolation switching unit. 2) A time-sharing dual-ferry mechanism: by hardware-controlled alternating switching of unidirectional channels, the risk of TCP session hijacking is completely eliminated. 3) Protocol state tracking: by dynamically tracking transaction IDs (e.g., ID step size and tolerance), spoofing attacks (e.g., ID skipping or duplication attacks) can be identified. 4) Dynamic policies and intelligent scheduling: by setting transmission priority queues and preset time-sharing dual-ferry policies, the transmission latency of urgent instructions is reduced, while supporting uninterrupted policy updates. The combination of physical isolation and the dual-ferry mechanism can block network protocol penetration, thereby improving security; the combination of protocol state tracking and dynamic policies can perform deep protocol analysis, thereby defending against advanced spoofing attacks; and intelligent scheduling and dual buffers (data caches of the intelligent scheduling module in the internal and external networks) can optimize resource allocation, thus balancing real-time performance and reliability. The isolation device of the present invention provides an isolation and control scheme for protocols that can meet the high-speed data interaction requirements of the Industrial Internet of Things and has stable and secure performance. Attached Figure Description
[0043] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0044] Figure 1 This is a schematic diagram illustrating the result of an isolation device for a protocol provided in an embodiment of the present invention;
[0045] Figure 2 A flowchart of a Modbus TCP protocol message from the external network to the internal network provided in an embodiment of the present invention;
[0046] Figure 3 This is a flowchart illustrating a method for controlling a protocol isolation device according to an embodiment of the present invention. Detailed Implementation
[0047] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described below are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0048] Please see Figure 1 An isolation device for protocols provided in this embodiment of the invention includes: an external network host system, an isolation switching unit, and an internal network host system, wherein the external network host system, the isolation switching unit, and the internal network host system are all physical modules; wherein the external network host system includes: a first packet analysis module, a first protocol status module, a first access policy module, and a first intelligent scheduling module.
[0049] It should be noted that the external network host system and the internal network host system are physical modules, specifically motherboards. The isolation switching unit is composed of physical isolation cards and a control system, such as... Figure 1 As shown, it should be noted that, for ease of description, the present invention distinguishes between modules in the external network host system and the internal network host system by using "first" and "second".
[0050] It should be noted that the following description describes the process by which an external host system sends a message to an internal host system through an isolation unit, such as... Figure 2 As shown, the explanation will be provided through each module of the external network host system, as follows:
[0051] In the external network host system:
[0052] The first message analysis module is used to parse the Modbus TCP messages of the accessed device, obtain the message information of the Modbus TCP messages, and determine whether to prohibit the Modbus TCP messages from passing through the isolation switching unit based on the message information. If not, it sends the Modbus TCP messages to the first protocol status module.
[0053] It should be noted that, firstly, the external host system receives Modbus TCP packets from external access devices via the Ethernet interface (a Modbus TCP packet is a data unit transmitted in the network based on the Modbus TCP protocol. Modbus TCP is an implementation of the Modbus protocol on TCP / IP networks, enabling devices to communicate via Ethernet and is widely used in industrial automation, building automation, and other fields). Then, the first packet analysis module parses the Modbus TCP packets to obtain packet information such as the master address, slave address, transaction ID, protocol identifier, function code, and register address. Then, based on the packet information, it determines whether to prohibit the Modbus TCP packets from passing through the isolation switching unit. For example, it checks whether the master address or slave address is in the pre-stored address. If not, the packet is discarded; if so, the Modbus TCP packet is sent to the first protocol status module.
[0054] Understandably, the above processing flow for Modbus TCP packets is designed to ensure system security and stability. In real-world applications, different industrial environments and network architectures may impose different requirements on packet processing. For example, strict control over packet transmission latency is necessary to ensure that production instructions are delivered to all execution devices in a timely and accurate manner. Furthermore, in environments with complex network topologies, it may be necessary to further optimize the management and judgment mechanisms for source IP addresses to address potential network address conflicts or spoofing attacks.
[0055] The first protocol status module is used to verify the transaction ID of the accessed device and record the transaction ID information. If the verification result is consistent, a ModbusTCP message is sent to the first access strategy module.
[0056] It should be noted that, firstly, the transaction ID of the accessing device is checked to see if it conforms to the verification rules (the ID should be consecutive and allow a certain range of tolerance). If it does not conform, the Modbus TCP packet is discarded, and the source IP is immediately blocked, thereby prohibiting the accessing device from accessing the sensitive register address. If it conforms, a Modbus TCP packet is sent to the first access policy module. Then, the transaction ID and other information are recorded using the address of the accessing device as the primary key.
[0057] It should be noted that, specifically, the functions of the first protocol state module include:
[0058] 1) Maintain access device transaction ID records. Maintain a transaction ID record table for each communication device (identified by MAC address), storing information such as device identifier, last valid transaction ID, timestamp, increment step size, and allowable tolerance.
[0059] 2) When the device communicates for the first time, record its transaction ID as the initial value and set the increment step size and allowable tolerance.
[0060] 3) The verification logic is as follows: verify whether the difference between the transaction ID in the message and the stored transaction ID meets the expectations.
[0061] 4) When the transaction ID reaches the maximum value of 0xFFFF, it is reset to the initial value.
[0062] The first access strategy module is used to perform multi-dimensional policy verification on ModbusTCP packets according to several preset policies, encapsulate the ModbusTCP packets that pass the verification, and send the encapsulated ModbusTCP packets to the first intelligent scheduling module.
[0063] It should be noted that the first access policy module mainly includes policy verification and encapsulation functions. Policy verification: ModbusTCP packets are subjected to multi-dimensional policy verification according to several preset policies, and policy hot loading is supported; for example, the preset policies include: checking the legality of the source IP address and destination IP address to ensure that the packet comes from and is sent to a legitimate network node; verifying the validity of the function code to determine whether it conforms to the ModbusTCP protocol specification and avoid unsupported or illegal function code operations; and verifying the reasonableness of the data length to ensure that the length of the data part is consistent with the function code and protocol specifications to prevent data loss or redundancy. Then, a 32-byte security header is added to the ModbusTCP packet that passes the verification, [timestamp (16B)|sequence number (8B)|reserved field (8B)|; the SM3 hash value of the ModbusTCP packet payload is calculated and appended to the end, and the encapsulated data format is [timestamp (16B)|sequence number (8B)|reserved field (8B)|packet (NB)|hash (32B)|. Finally, the encapsulated ModbusTCP message is given a transmission priority and sent to the first intelligent scheduling module.
[0064] It should be noted that the first access policy module plays the following specific roles in the policy verification function:
[0065] 1) Perform multi-dimensional policy verification on ModbusTCP packets and support hot policy reloading.
[0066] 2) Initialize two buffers. Write the new strategy to Buffer B, and keep the current strategy in Buffer A.
[0067] 3) During incremental updates, switch to Buffer B via atomic operations.
[0068] The first intelligent scheduling module is used to buffer the ModbusTCP packets to be transmitted to obtain the first buffer queue and set the transmission priority of the ModbusTCP packets in the buffer queue. The first buffer queue is adjusted according to the transmission priority, and the first transmission instruction is generated according to the transmission priority and sent to the isolation switching unit. The transmission priorities, from high to low, include: emergency control instruction, status read instruction, log write and configuration update.
[0069] It should be noted that the process of caching Modbus TCP packets to be transmitted is as follows: First, the received Modbus TCP packets to be transmitted are placed into the buffer area of the first intelligent scheduling module in the order of arrival. During the caching process, a unique identifier is assigned to each Modbus TCP packet for subsequent management and scheduling. Simultaneously, the usage of the buffer area is monitored in real time. When the buffer area is close to full capacity, newly arriving packets are evaluated according to transmission priority. High-priority packets are cached first, while low-priority packets can be temporarily discarded or queued, depending on the system configuration, until the buffer area has sufficient space.
[0070] It should be noted that the method for setting the transmission priority of Modbus TCP packets in the buffer queue can be as follows: Based on the type of Modbus TCP packet, if the packet is an urgent control command, its transmission priority should be set to the highest, because urgent control commands are often related to the safe and stable operation of the system and need to be processed promptly; if the packet is a status read command, its priority should be set to the second highest, as status reading helps to understand the current state of the system in a timely manner; for log write and configuration update type packets, their priority should be set to a lower level, as these types of packets usually have relatively lower time urgency requirements. The priority can also be dynamically adjusted based on the real-time load of the system. When the system load is light, the priority of urgent control commands can be appropriately reduced, while when the system load is heavy, the priority of urgent control commands can be further increased to ensure that critical commands are processed first. Those skilled in the art can design the above methods according to actual conditions, and will not be elaborated further here.
[0071] It should be noted that the method for generating the first instruction to be transmitted based on transmission priority can be as follows: Sort the Modbus TCP packets in the buffer queue according to their priority order, and select the packet with the highest priority as the first instruction to be transmitted. If multiple packets with the same highest priority exist, further selection is made based on their arrival time, with the earliest arriving packet being prioritized as the first instruction to be transmitted. Alternatively, the importance of the packets can be considered; for example, instructions involving critical equipment in emergency control instructions take precedence over other emergency control instructions, and the packet that best meets the importance requirements and has the highest priority can be determined as the first instruction to be transmitted. Those skilled in the art can design the above methods according to actual conditions, and will not be elaborated further here.
[0072] In one embodiment, adjusting the first buffer queue according to transmission priority includes:
[0073] Based on the transmission priority of the ModbusTCP message, the position of the ModbusTCP message in the first buffer queue is adjusted. The order of the ModbusTCP message's transmission priority in the first buffer queue corresponds to the order of its transmission priority.
[0074] It should be noted that the intelligent scheduling module first buffers the Modbus TCP packets to be transmitted to obtain a first buffer queue (the "first" in the first buffer queue is for ease of description and to distinguish it from the second buffer queue in the following embodiment); then, it sets the transmission priority of the Modbus TCP packets in the buffer queue according to a preset four-level transmission priority, and generates a first instruction to be transmitted according to the transmission priority and sends it to the isolation switching unit to reduce the transmission latency of critical instructions. (The preset transmission priorities, from high to low, are emergency control instructions, status read instructions, log writes, and configuration updates). Specifically, 1) the buffer queue is adjusted according to the priority, and high-priority packets are moved to the head node of the queue and delivered to the isolation card; 2) the first instruction to be transmitted is sent to the isolation switching unit through a dedicated control signal line, thereby notifying the isolation switching unit.
[0075] Understandably, this operational method of the intelligent scheduling module effectively optimizes the transmission process of Modbus TCP messages. By rationally setting transmission priorities, critical commands such as emergency control instructions can be processed first, ensuring the timeliness and stability of system operation. Simultaneously, this mechanism for adjusting the buffer queue and sending commands ensures the efficient operation of the entire protocol isolation device even in complex situations where different types of messages coexist. It avoids a series of problems that may be caused by improper message processing order, further enhancing the system's ability to cope with various scenarios and ensuring the efficiency and accuracy of data transmission.
[0076] The isolation switching unit is used to receive the first instruction to be transmitted and, based on a preset time-division dual-ferry strategy, control the transmission of ModbusTCP packets in the first buffer queue according to the first instruction to be transmitted, so that at a certain time only ModbusTCP packets are transmitted from the external network host system to the internal network host system.
[0077] In one embodiment, the isolation switching unit includes a physical isolation card and a control system;
[0078] The control system is used to receive the first instruction to be transmitted and, based on a preset time-division dual-ferry strategy, control the physical isolation card to transmit the ModbusTCP packets in the first buffer queue, so that at a certain moment the physical isolation card only transmits ModbusTCP packets from the external host system to the internal host system.
[0079] It should be noted that the physical isolation card and control system together constitute the isolation switching unit, which achieves unidirectional data transmission through time-division dual-ferry technology: during transmission, only one direction of the data channel is allowed to be active (e.g., from the external network to the internal network), while the isolation switching unit in the other direction is prohibited from reading the cached data of the corresponding host during this period; only when the transmission in the current direction is completed and the data channel is closed, the reverse transmission channel is opened. This alternating switching mechanism ensures that only one direction of data flow exists at any given time. Simultaneously, relying on a dedicated hardware isolation switching unit without a management interface, it completely blocks communication and interaction between internal and external network hosts based on network protocols, constructing an insurmountable security isolation barrier at the physical level. Its workflow is as follows:
[0080] 1. After receiving the first transmission command sent by the intelligent scheduling module, the control system arbitrates according to the transmission command (arbitrates according to the transmission priority and other information in the transmission command) to determine the data to be transmitted by the physical isolation card and the transmission direction.
[0081] 2. The physical isolation card reads the cached data from the cache queue (starting from the first section of the cache queue) and transmits it to the peer host.
[0082] In one embodiment, the intranet host system includes: a second packet analysis module, a second protocol status module, a second access policy module, and a second intelligent scheduling module.
[0083] In an intranet host system:
[0084] The second message analysis module is used to receive and parse Modbus TCP messages, and send the parsed information and Modbus TCP messages to the second protocol status module.
[0085] It should be noted that the process first receives and parses Modbus TCP packets; then, it parses the Modbus TCP packets (secure protocol encapsulated packets), and the parsed information includes: [timestamp (16B) | sequence number (8B) | reserved fields (8B) | packet (NB) | hash (32B); finally, the parsed information is sent to the second protocol status module. Understandably, in this process, the timestamp accurately records the moment the packet is received, providing a time basis for subsequent data tracing and analysis. The sequence number helps to accurately sort the packets, ensuring data integrity and consistency. Although the reserved fields are not currently defined in detail, they reserve space for possible future functional expansion. The packet portion carries the actual business data that needs to be transmitted and processed, and the hash is used to verify whether the packet has been tampered with during transmission, ensuring data security. Through this meticulous parsing process, Modbus TCP packets can be further processed in a secure and orderly manner, providing accurate and reliable information to the second protocol status module, enabling the second protocol status module to make reasonable decisions and responses based on this information, thereby ensuring the entire system operates in a secure and stable state.
[0086] The second protocol status module is used to verify the security header of the ModbusTCP packet based on the parsed information. If the verification passes, it is sent to the second access policy module; otherwise, an alarm is issued.
[0087] It's important to note that security header verification is performed, including: determining if the message timestamp differs significantly from the current timestamp; verifying if the sequence number is continuously increasing, triggering an alarm if duplicates are found; and performing message hash verification. These verification steps are crucial. A significant difference between the message timestamp and the current timestamp may indicate abnormal delays in message transmission, affecting data timeliness and real-time performance; discontinuous or duplicate sequence numbers can lead to data disorder, partial data loss, or duplicate reception, compromising data integrity; and a failed message hash verification directly indicates malicious tampering of the message during transmission, seriously threatening system security. Only through comprehensive and rigorous execution of these verifications can the security and reliability of Modbus TCP messages be guaranteed, laying a solid foundation for the subsequent second access policy module to perform reasonable access control based on correct message information.
[0088] The second access strategy module is used to strip the security header from the verified ModbusTCP packets and send them to the intranet devices for execution. The execution results from the intranet devices are then set with transmission priority and sent to the second intelligent scheduling module.
[0089] It should be noted that the ModbusTCP message (security protocol message) that has passed verification is stripped of its security header and sent to the intranet device for execution. The execution result of the intranet device is then sent to the second intelligent scheduling module after setting the transmission priority. It is understood that the execution result needs to be returned to the external host system. During this process, the external host system may need to transmit data to the intranet host system through the isolation switching unit. Therefore, the execution result also needs to be set with a transmission priority so that the control system of the isolation switching unit can make a decision (see the next embodiment for details).
[0090] The second intelligent scheduling module is used to cache the execution results to be transmitted to obtain a second cache queue, adjust the second cache queue according to the transmission priority corresponding to the execution results, and generate a second instruction to be transmitted according to the transmission priority and send it to the isolation switching unit.
[0091] The isolation switching unit is used to receive the second instruction to be transmitted and, based on a preset time-division dual-ferry strategy, control the transmission of the execution results in the second buffer queue according to the second instruction to be transmitted, so that at any given time only the execution results are transmitted from the internal network host system to the external network host system.
[0092] It should be noted that the execution result is returned via a reverse transfer (from the intranet to the external network), and the process is symmetrical to that from the external network to the intranet. This will not be elaborated further here.
[0093] In one embodiment, the isolation switching unit is further configured to:
[0094] When the received instruction to be transmitted includes both a first instruction to be transmitted and a second instruction to be transmitted;
[0095] Based on the preset time-division dual-ferry strategy, the transmission order of ModbusTCP messages and execution results is determined according to the reception time and transmission priority of the first and second instructions to be transmitted, so that at a certain time, only ModbusTCP messages are transmitted from the external host system to the internal host system, or only execution results are transmitted from the internal host system to the external host system.
[0096] Further, in the above embodiments: determining the reception time and transmission priority of the first instruction to be transmitted and the second instruction to be transmitted, and determining the transmission order of ModbusTCP messages and execution results, includes:
[0097] When the transmission priorities of the first and second instructions to be transmitted are the same, the order of reception time is determined. If the first instruction to be transmitted is received by the isolation switching unit before the second instruction to be transmitted, the Modbus TCP message is transmitted from the external host system to the internal host system, and then the execution result is transmitted from the internal host system to the external host system.
[0098] It should be noted that, considering the process of returning the execution result to the external host system, the external host system may need to transmit data to the internal host system through the isolation switching unit, and the execution result and Modbus TCP message have the same priority. Therefore, a second judgment condition is set: the reception time. Specifically, this is the time when the control system of the isolation switching unit receives the instruction to be transmitted, determining the instantaneous order of data transmission. Understandably, in actual operating scenarios, this method of determining the order of data transmission based on reception time can effectively avoid data transmission conflicts and ensure the stability and efficiency of data interaction between the internal and external host systems. For example, when the external host system has an urgent Modbus TCP message to send, and the internal host system also has an execution result to return, comparing the reception times can clearly determine which side's data should be transmitted first, preventing data congestion or chaos. Moreover, this judgment method (a type of time-sharing dual-ferry mechanism) significantly improves the overall operating efficiency of the isolation switching unit. It allows data to be transmitted in an orderly manner in different directions, reducing waiting time and resource waste, thus providing a strong guarantee for the stable operation of the entire system.
[0099] This invention provides a protocol isolation device, comprising: 1) a dual-motherboard physical isolation (external network host system and internal network host system) and an isolation switching unit (physical module), which blocks attack paths at the physical layer and improves anti-interference capabilities through independent hardware modules (external network host system and internal network host system) and the isolation switching unit. 2) A time-sharing dual-ferry mechanism: by hardware-controlled alternating switching of unidirectional channels, the risk of TCP session hijacking is completely eliminated. 3) Protocol state tracking: by dynamically tracking transaction IDs (e.g., ID step size and tolerance), spoofing attacks (e.g., ID skipping or duplication attacks) can be identified. 4) A dynamic policy engine and intelligent scheduling: by setting priority queues and preset time-sharing dual-ferry policies, the latency of emergency command transmission is reduced, while supporting uninterrupted policy updates. The combination of physical isolation and the dual-ferry mechanism can block network protocol penetration, thereby improving security; the combination of protocol state tracking and dynamic policies can perform deep protocol analysis, thereby defending against advanced spoofing attacks; and intelligent scheduling and dual buffers (data caches of the intelligent scheduling module in the internal and external networks) can optimize resource allocation, thus balancing real-time performance and reliability. The isolation device of the present invention provides an isolation and control scheme for protocols that can meet the high-speed data interaction requirements of the Industrial Internet of Things and has stable and secure performance.
[0100] The above describes a protocol isolation device provided in an embodiment of the present invention. The following describes an access control method for the protocol isolation device provided in an embodiment of the present invention.
[0101] Please see Figure 3 The present invention provides a method for controlling a protocol isolation device, the method comprising: in an external network host system:
[0102] Step 101: The Modbus TCP packets of the accessed device are parsed by the first packet analysis module to obtain the packet information of the Modbus TCP packets. Based on the packet information, it is determined whether to prohibit the Modbus TCP packets from passing through the isolation switching unit. Otherwise, the Modbus TCP packets are sent to the first protocol status module.
[0103] Step 102: Verify the transaction ID of the accessed device through the protocol status module and record the transaction ID information. If the verification result is consistent, send a ModbusTCP message to the first access strategy module.
[0104] Step 103: The first access strategy module performs multi-dimensional policy verification on ModbusTCP packets according to several preset policies, encapsulates the verified ModbusTCP packets, and sends the encapsulated ModbusTCP packets to the first intelligent scheduling module.
[0105] Step 104: After the first intelligent scheduling module buffers the ModbusTCP packets to be transmitted, it obtains the first buffer queue and sets the transmission priority of the ModbusTCP packets in the buffer queue. The first buffer queue is adjusted according to the transmission priority of the ModbusTCP packets, and the first transmission instruction is generated according to the transmission priority and sent to the isolation switching unit.
[0106] Step 105: Receive the first instruction to be transmitted through the isolation switching unit, and based on the preset time-division dual-ferry strategy, control the ModbusTCP packets in the first buffer queue to be transmitted according to the first instruction to be transmitted, so that at a certain time only ModbusTCP packets are transmitted from the external network host system to the internal network host system.
[0107] Furthermore, this embodiment of the invention also provides an access control device for an isolation mechanism of a protocol, the device comprising a processor and a memory:
[0108] The memory is used to store program code and transmit the program code to the processor;
[0109] The processor is configured to execute the steps of the access control method for the protocol isolation device as described in the above method embodiments, according to the instructions in the program code.
[0110] Furthermore, this embodiment of the invention also provides a computer-readable storage medium for storing program code, which is used to execute the access control method for the protocol isolation device described in the above method embodiments.
[0111] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the method described above can be referred to the corresponding process in the aforementioned system embodiments, and will not be repeated here.
[0112] In the embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.
[0113] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0114] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0115] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0116] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An isolation device for a protocol, characterized in that, include: The system comprises an external network host system, an isolation switching unit, and an internal network host system, wherein the external network host system, the isolation switching unit, and the internal network host system are all physical modules; wherein the external network host system includes: a first packet analysis module, a first protocol status module, a first access policy module, and a first intelligent scheduling module; In the external network host system: The first message analysis module is used to parse the ModbusTCP messages of the accessing device, obtain the message information of the ModbusTCP messages, determine whether to prohibit the ModbusTCP messages from passing through the isolation switching unit based on the message information, and otherwise send the ModbusTCP messages to the first protocol status module. The first protocol status module is used to verify the transaction ID of the access device and record the information of the transaction ID. If the verification result is consistent, the ModbusTCP message is sent to the first access policy module. The first access policy module is used to perform multi-dimensional policy verification on the ModbusTCP message according to a number of preset policies, encapsulate the ModbusTCP message that passes the verification, and send the encapsulated ModbusTCP message to the first intelligent scheduling module. The first intelligent scheduling module is used to buffer the ModbusTCP packets to be transmitted to obtain a first buffer queue and set the transmission priority of the ModbusTCP packets in the buffer queue, adjust the first buffer queue according to the transmission priority, and generate a first transmission instruction according to the transmission priority and send it to the isolation switching unit. The isolation switching unit is used to receive the first instruction to be transmitted and, based on a preset time-division dual-ferry strategy, control the ModbusTCP packets in the first buffer queue to be transmitted according to the first instruction to be transmitted, so that at a certain time only the ModbusTCP packets are transmitted from the external network host system to the internal network host system.
2. The protocol isolation device according to claim 1, characterized in that, The intranet host system includes: a second packet analysis module, a second protocol status module, a second access policy module, and a second intelligent scheduling module; In the intranet host system: The second message analysis module is used to receive the ModbusTCP message and parse it, and send the parsed information and the ModbusTCP message to the second protocol status module; The second protocol status module is used to verify the security header of the ModbusTCP packet according to the parsed information. If the verification passes, it is sent to the second access policy module; otherwise, an alarm is issued. The second access policy module is used to strip the security header from the verified ModbusTCP packet and send it to the intranet device for execution, and send the execution result of the intranet device to the second intelligent scheduling module; The second intelligent scheduling module is used to cache the execution result to be transmitted to obtain a second cache queue and set the transmission priority of the execution result, adjust the second cache queue according to the transmission priority, and generate a second instruction to be transmitted according to the transmission priority and send it to the isolation switching unit. The isolation switching unit is used to receive the second instruction to be transmitted, and based on a preset time-division dual-ferry strategy, control the transmission of the execution result in the second cache queue according to the second instruction to be transmitted, so that at a certain time only the execution result is transmitted from the internal network host system to the external network host system.
3. The protocol isolation device according to claim 2, characterized in that, The isolation switching unit is also used for: When both the first instruction to be transmitted and the second instruction to be transmitted are received simultaneously: Based on a preset time-division dual-ferry strategy, the transmission order of the ModbusTCP message and the execution result is determined according to the reception time and transmission priority of the first instruction to be transmitted and the second instruction to be transmitted, so that at a certain time, only the ModbusTCP message is transmitted from the external network host system to the internal network host system, or only the execution result is transmitted from the internal network host system to the external network host system.
4. The protocol isolation device according to claim 3, characterized in that, The step of determining the transmission order of the ModbusTCP message and the execution result based on the reception time and transmission priority of the first instruction to be transmitted and the second instruction to be transmitted includes: When the transmission priorities of the first instruction to be transmitted and the second instruction to be transmitted are the same, the order of the receiving times is determined. When the first instruction to be transmitted received by the isolation switching unit is before the second instruction to be transmitted, the ModbusTCP message is transmitted from the external host system to the internal host system, and then the execution result is transmitted from the internal host system to the external host system.
5. The protocol isolation device according to claim 1, characterized in that, The step of adjusting the first buffer queue according to the transmission priority includes: The position of the ModbusTCP packet in the first buffer queue is adjusted according to the transmission priority of the ModbusTCP packet. The position of the ModbusTCP packet in the first buffer queue corresponds to the order of the transmission priority of the ModbusTCP packets.
6. The protocol isolation device according to claim 1, characterized in that, The isolation switching unit includes a physical isolation card and a control system; The control system is configured to receive the first instruction to be transmitted and, based on a preset time-division dual-ferry strategy, control the physical isolation card to transmit the ModbusTCP packets in the first buffer queue, so that at a certain moment the physical isolation card only transmits the ModbusTCP packets from the external network host system to the internal network host system.
7. The protocol isolation device according to any one of claims 1 to 6, characterized in that, The transmission priorities, from highest to lowest, include: emergency control commands, status read commands, log writes, and configuration updates.
8. A method for access control of a protocol isolation device, characterized in that, Applied to the protocol isolation device according to any one of claims 1-7; The method includes, on the external network host system: The first message analysis module parses the ModbusTCP messages of the accessing device to obtain the message information of the ModbusTCP messages. Based on the message information, it determines whether to prohibit the ModbusTCP messages from passing through the isolation switching unit. Otherwise, the ModbusTCP messages are sent to the first protocol status module. The first protocol status module verifies the transaction ID of the access device and records the information of the transaction ID. If the verification result is consistent, the ModbusTCP message is sent to the first access policy module. The first access strategy module performs multi-dimensional policy verification on the ModbusTCP packets according to several preset policies, encapsulates the ModbusTCP packets that pass the verification, and sends the encapsulated ModbusTCP packets to the first intelligent scheduling module. After the first intelligent scheduling module buffers the ModbusTCP packets to be transmitted to obtain a first buffer queue, it sets the transmission priority of the ModbusTCP packets in the buffer queue, adjusts the first buffer queue according to the transmission priority, and generates a first transmission instruction according to the transmission priority and sends it to the isolation switching unit. The first instruction to be transmitted is received by the isolation switching unit, and based on the preset time-division dual-ferry strategy, the ModbusTCP packets in the first buffer queue are controlled to be transmitted according to the first instruction to be transmitted, so that at a certain time only the ModbusTCP packets are transmitted from the external network host system to the internal network host system.
9. An access control device for a protocol isolation mechanism, characterized in that, The device includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to execute the access control method for the protocol isolation device as described in claim 8 according to the instructions in the program code.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store program code for executing the access control method for the protocol isolation device as described in claim 8.
Citation Information
Patent Citations
Isolation device for protocol, access control method, equipment and medium
CN118972167A
Systems configured to enable isolated client device interaction with building automation and control (BAC) networks, including third-party application access framework
US20200396208A1