Method and system for realizing communication transmission protection based on trusted management and control

By introducing two-way dynamic authentication and national cryptographic algorithms into network communication, combined with the IKEv2 protocol, a trusted control channel and an end-to-end secure tunnel are established, solving the problems of key staticization and security boundary ambiguity in network communication, and improving the security of authentication and communication channels.

CN120956541AActive Publication Date: 2025-11-14SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511488834.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-17
Publication Date
2025-11-14
Estimated Expiration
2045-10-17

AI Technical Summary

Technical Problem

Existing network communication security technologies suffer from risks such as static key encoding, insufficient compatibility with national cryptographic standards, and ambiguous security boundaries. They also lack dynamic network isolation mechanisms, resulting in inadequate communication security.

Method used

A trusted control channel is established through two-way dynamic authentication based on a security management and control platform. The national cryptographic algorithms SM2, SM3, and SM4 are used in conjunction with the IKEv2 protocol to achieve client identity authentication and end-to-end secure tunnel establishment. A hash mechanism is used to ensure the security of the communication channel and to perform packet-encrypted transmission.

Benefits of technology

It achieves secure verification of the identity of communication entities, ensures the security of communication transmission information and the integrity of the channel, improves the trustworthiness and security of network communication, and is suitable for security assurance of network communication in complex systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956541A_ABST
    Figure CN120956541A_ABST
Patent Text Reader

Abstract

The invention provides a method and a system for realizing communication transmission protection based on credible management and control, and the method comprises the steps: executing bidirectional dynamic authentication with a security management center platform based on a communication platform where both sides of a client side are located, so as to verify the identity of the client side, and building a credible control channel between the communication platform and the security management center platform; based on the trusted control channel, the security management center platform generates and distributes a random number, and both clients establish an end-to-end security tunnel according to the random number and by adopting a hash mechanism; and performing packet encryption processing on to-be-transmitted data based on the client, and realizing secure transmission of communication information through the secure tunnel. The identity security of the communication entity is ensured through bidirectional dynamic authentication of two communication parties; through rapid packet encryption transmission, the security of communication transmission information is ensured, the requirements of network communication security and communication connection credibility are met, and the method is suitable for security assurance of complex system network communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication security, and more specifically, to a method and system for communication transmission protection based on trusted management and control. Background Technology

[0002] With the accelerated advancement of digital transformation, network communication security has become a key element in safeguarding national security, economic development, and social stability. In today's rapidly evolving digital technology landscape, network attack methods are constantly evolving, from traditional DDoS attacks to AI-driven deepfake scams, from IPv4 protocol vulnerabilities to new IPv6 risks; network security threats are becoming increasingly diversified and complex. Trusted network connectivity, as a core component of network communication security, ensures the confidentiality, integrity, and availability of data transmission by integrating various security technologies. It not only forms the foundation for efficient and secure data flow, reducing cross-domain and cross-industry circulation costs and activating the value of data assets through a unified transmission and interaction environment, but also promotes the integration of data, computing, and network security, achieving synergy between data, computing power, networks, and security.

[0003] Network security products are adapting to the trend of domestic substitution, supporting not only domestically produced hardware but also Chinese cryptographic algorithms for IPsec VPN tunnels in their software. They also support integration with mainstream industry vendors, achieving a deeper level of compliance and strategic autonomy. Traditional network communication security relies on proprietary protocols and encrypted tunnels, primarily using VPNs based on the IPsec security protocol. Existing solutions suffer from the following technical bottlenecks: Static key risk: Protocols like IPsec use fixed pre-shared keys, which are vulnerable to brute-force attacks (e.g., even with UKey storage, key update issues remain unresolved). Insufficient Chinese cryptographic compatibility: SM2 / SM3 / SM4 algorithms are not deeply integrated into the entire authentication and key negotiation process. Ambiguous security boundaries: A lack of dynamic network isolation mechanisms based on hardware characteristics.

[0004] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention

[0005] The purpose of this application is to provide a method and system for communication transmission protection based on trusted management and control. Based on the trusted foundation provided by a security management and control platform, it ensures the security of the communicating entities' identities through two-way dynamic authentication between the communicating parties; ensures the security of transmitted information through fast packet encryption; and ensures the security of the communication channel through a hash mechanism. This guarantees the security of the network communication process and meets the needs of network communication security and trusted communication connections. It is applicable to the security assurance of network communication in complex systems.

[0006] Firstly, this application provides a method for protecting communication transmission based on trusted management and control, including: During the identity authentication phase, two-way dynamic authentication is performed between the communication platforms of both clients and the security management center platform to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform; the security management center platform is used to manage and control the communication platform. During the channel establishment phase, based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on the random numbers and using a hash mechanism. During the data transmission phase, the client performs packet encryption on the data to be transmitted, and secure transmission of communication information is achieved through the secure tunnel.

[0007] Furthermore, the two-way dynamic authentication based on the communication platforms of both clients and the security management center platform to verify the client's identity includes: In response to the security management center platform receiving a client authentication request, a first random number and a first timestamp are generated, a first authentication code is calculated based on the first random number, the first timestamp, and the client identity parameters pre-stored by the security management center platform, and the first authentication code, the first random number, and the first timestamp are sent to the communication platform. The communication platform calculates and verifies the first authentication code based on the locally stored client identity parameters, the first random number, and the timestamp of the security management center platform. After successful verification, it generates a second random number. The platform then calculates a second authentication code based on the second random number, the first timestamp, and the client identity parameters, and sends the second authentication code and the second random number to the security management center platform. The security management center platform verifies the second authentication code and checks the uniqueness of the second random number within the time period indicated by the first timestamp, thereby completing the final authentication of the client.

[0008] Furthermore, the client includes a first client and a second client; the first client is located on a first communication platform, and the second client is located on a second communication platform; Based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and a hash mechanism, including: The random number distributed by the security management center platform is a third random number generated by the encryption machine. This third random number is distributed to the first communication platform and the second communication platform through the trusted control channel established in the identity authentication stage. After receiving the third random number, the first communication platform uses the public key of the second communication platform to encrypt and hash it, and then forwards the result to the second communication platform via the security management center platform. The second communication platform performs hash verification on the received data to ensure its integrity, and decrypts it using its own private key to obtain the third random number.

[0009] Furthermore, the calculation and verification of the first authentication code includes: The communication platform determines a second authentication code based on locally stored client identity parameters, the first random number, and the timestamp of the security management center platform; and verifies the trust status of the security management center platform based on the first authentication code and the second authentication code. The method further includes: in response to the security management center platform being in a trusted state, the communication platform generates a second random number; based on the second random number, the timestamp of the security management center platform, and the locally stored client identity parameters, a third authentication code is determined, and the third authentication code is sent to the security management center platform; The security management center platform verifies the validity of the third authentication code to complete the client's identity authentication.

[0010] Furthermore, based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and using a hash mechanism, including: Request multiple random strings from the encryption machine based on the authentication service of the security management center platform; The authentication service uses the public key of the node card of the first communication platform to encrypt the random string and transmits it to the first communication platform; The security agent of the first communication platform uses the node card's private key to decrypt the encrypted random string and obtain a random string; The security agent of the first communication platform uses the public key of the second communication platform to encrypt the random string and performs hash calculation using a hash algorithm. The encrypted and hashed random string is then distributed to the security management center platform through the trusted control channel, and then distributed to the second communication platform by the security management center platform through its two-way authentication channel with the second communication platform. The security agent of the second communication platform uses a hash algorithm to verify the integrity of the random string and decrypts it using the node card's private key.

[0011] Furthermore, the step of performing block encryption processing on the data to be transmitted based on the client includes: The first client divides the data to be transmitted into groups, encrypts the grouped data using the SM4 algorithm, forms ciphertext, and transmits it to the second client through the secure tunnel; The second client decrypts the received ciphertext using SM4 and reassembles it into the original data.

[0012] Furthermore, the step of performing block encryption processing on the data to be transmitted based on the client includes: The first client encrypts each data packet of the data to be transmitted using the SM4 algorithm to generate packet ciphertext, generates an independent integrity check code for the packet ciphertext using the SM3 algorithm, and appends the check code to the end of the packet. After receiving each data packet, the second client strips and verifies the integrity check code; after the verification is successful, it performs an SM4 decryption operation on the data packet.

[0013] Furthermore, the method is implemented based on the IKEv2 protocol framework, and the national cryptographic algorithms SM2, SM3, and SM4 are applied to the authentication, hashing, and encryption stages of the protocol, respectively.

[0014] Furthermore, the method also includes: during the IKE_AUTH exchange phase of the IKEv2 protocol, an SM2 digital certificate for authentication is read from a USB node card; the USB node card simultaneously provides client identity storage and password calculation services for the authentication phase.

[0015] Secondly, this application also proposes a communication transmission protection system based on trusted management and control, comprising: The identity authentication module is used to perform two-way dynamic authentication with the security management center platform based on the communication platforms of both clients to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform; the security management center platform is used to manage and control the communication platform. The channel establishment module is used to generate and distribute random numbers by the security management center platform based on the trusted control channel, and the two clients establish an end-to-end secure tunnel based on the random numbers and using a hash mechanism. The data transmission module is used to perform packet encryption processing on the data to be transmitted based on the client, and to achieve secure transmission of communication information through the secure tunnel.

[0016] As described above, the communication transmission protection method and system based on trusted control provided in this application, through the following steps: In the identity authentication phase, bidirectional dynamic authentication is performed between the communication platforms of both clients and the security management center platform to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform; in the channel establishment phase, based on the trusted control channel, the security management center platform generates and distributes random numbers, and both clients establish an end-to-end secure tunnel using this random number and a hash mechanism; in the data transmission phase, the client performs packet encryption processing on the data to be transmitted, and secure transmission of communication information is achieved through the secure tunnel. Through bidirectional dynamic authentication between the communicating parties, the security of the communicating entity's identity is guaranteed; through fast packet encryption transmission, the security of the transmitted communication information is guaranteed; and through the hash mechanism, the security of the communication channel is guaranteed; thus, the security of the network communication process is ensured, meeting the needs of network communication security and trusted communication connections. It is suitable for security assurance of complex system network communication. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a flowchart illustrating the steps of the communication transmission protection method based on trusted management disclosed in an embodiment of the present invention; Figure 2 This is a flowchart of the authentication process during the identity authentication stage disclosed in an embodiment of the present invention; Figure 3 This is a schematic diagram of a protection system for communication transmission based on trusted management disclosed in an embodiment of the present invention; Figure 4 This is a flowchart of the communication transmission protection system based on trusted management disclosed in an embodiment of the present invention; Figure 5 This is a schematic diagram of the communication transmission protection system structure based on trusted management and control disclosed in an embodiment of the present invention. Detailed Implementation

[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which these embodiments belong; the terminology used herein and in the specification of the application is for the purpose of describing particular embodiments only and is not intended to limit these embodiments; the terms "comprising" and "having," and any variations thereof, in the specification of these embodiments and the foregoing drawings, are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification of these embodiments and the foregoing drawings are used to distinguish different objects, not to describe a particular order.

[0020] The implementation details of the technical solution in this embodiment are described in detail below: This application proposes a method for communication transmission protection based on trusted management and control, such as... Figure 1 As shown, the method mainly includes three phases of triple protection: authentication phase, channel establishment phase, and data transmission phase. The method includes: S101, Identity Authentication Phase: Based on the communication platforms of both clients, two-way dynamic authentication is performed with the security management center platform to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform; the security management center platform is used to manage the communication platform.

[0021] Furthermore, the two-way dynamic authentication based on the communication platforms of both clients and the security management center platform to verify the client's identity includes: In response to the security management center platform receiving a client authentication request, a first random number and a first timestamp are generated, a first authentication code is calculated based on the first random number, the first timestamp, and the client identity parameters pre-stored by the security management center platform, and the first authentication code, the first random number, and the first timestamp are sent to the communication platform. The communication platform calculates and verifies the first authentication code based on the locally stored client identity parameters, the first random number, and the timestamp of the security management center platform. After successful verification, it generates a second random number. The platform then calculates a second authentication code based on the second random number, the first timestamp, and the client identity parameters, and sends the second authentication code and the second random number to the security management center platform. The security management center platform verifies the second authentication code and checks the uniqueness of the second random number within the time period indicated by the first timestamp, thereby completing the final authentication of the client.

[0022] Furthermore, the calculation and verification of the first authentication code includes: The communication platform determines a second authentication code based on locally stored client identity parameters, the first random number, and the timestamp of the security management center platform; and verifies the trust status of the security management center platform based on the first authentication code and the second authentication code. The method further includes: in response to the security management center platform being in a trusted state, the communication platform generates a second random number; based on the second random number, the timestamp of the security management center platform, and the locally stored client identity parameters, a third authentication code is determined, and the third authentication code is sent to the security management center platform; The security management center platform verifies the validity of the third authentication code to complete the client's identity authentication.

[0023] Specifically, the method for secure communication transmission based on trusted management disclosed in this embodiment provides one layer of protection: two-way dynamic authentication between the communicating parties based on a security management and control platform ensures the security of the communicating entities' identities. Two-way dynamic authentication is implemented using smart card authorization tokens and TPM, preventing attackers from impersonating other users to participate in the communication. For example... Figure 2 The diagram shown illustrates the authentication process during the identity authentication phase of this embodiment. The authentication process is as follows: (1) The client node sends an authentication request (providing the node user number) to the communication platform of its communication subnet through the internal trusted transmission channel. The security management center platform is also implemented by a server; the communication platform is implemented by a server and is controlled by the security management center platform.

[0024] (2) After receiving the request from the client node, the communication platform uses the received user number of the client node to look up the identity parameter information of the corresponding user in the node card. If no corresponding user number is found, the node is an illegal node and communication is prohibited; otherwise, the security agent installed on the communication platform will encrypt the user request using a pre-negotiated encryption algorithm and send it to the security management and control platform. (3) After receiving the information, the security management and control platform creates a session for the client node. First, it decrypts the information using the same algorithm to obtain the user's original request information, and then, based on the user ID... Retrieve the pre-stored client node identity parameter information from its own database. Use an encryption machine to generate random strings And obtain the current system timestamp. Using a pre-agreed hash algorithm to and Perform hash calculation Obtain the authentication code from the security management and control platform. ,and Together they form authentication information, which is then encrypted and sent to the communication platform. (4) After the security agent of the communication platform decrypts the received authentication information, it uses the timestamp received from the security management and control platform. and random string Stored in the node card Calculate using the same hash algorithm Get a re-authentication code , and the decrypted result The authentication process is then compared; if they match, the security management and control platform is considered trustworthy; otherwise, the authentication process is interrupted. Once the security management and control platform is confirmed to be trustworthy, the communication platform's security agent uses the user's identity parameter information from the node card to generate a random string. Using the same hash algorithm, and Calculate together Generate authentication codes for client nodes. ,and , Together, they are packaged and encrypted as authentication information and sent to the security management and control platform.

[0025] (5) After decrypting the received authentication information, the security management and control platform performs the following judgments: a. The system uses the session identifier and timestamp to determine if the current session is the same one initially established with the client node, to prevent replay attacks. If not, the authentication process is interrupted; otherwise, the process proceeds to the next verification step. b. Verify the received random string from the client node. Has it been timestamped by the user? If the specified date was used, authentication will fail; otherwise, proceed to the next verification step. c. Security management and control platform according to and The same hash algorithm is used again to generate the authentication code. , and received The two are compared. If they are the same, the client node is a legitimate user and can log in successfully to access other nodes; otherwise, the client node login is rejected.

[0026] S102, Channel Establishment Phase: Based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on the random numbers and a hash mechanism.

[0027] Furthermore, the client includes a first client and a second client; the first client is located on a first communication platform, and the second client is located on a second communication platform; Based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and a hash mechanism, including: The random number distributed by the security management center platform is a third random number generated by the encryption machine. This third random number is distributed to the first communication platform and the second communication platform through the trusted control channel established in the identity authentication stage. After receiving the third random number, the first communication platform uses the public key of the second communication platform to encrypt and hash it, and then forwards the result to the second communication platform via the security management center platform. The second communication platform performs hash verification on the received data to ensure its integrity, and decrypts it using its own private key to obtain the third random number.

[0028] Furthermore, based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and using a hash mechanism, including: Request multiple random strings from the encryption machine based on the authentication service of the security management center platform; The authentication service uses the public key of the node card of the first communication platform to encrypt the random string and transmits it to the first communication platform; The security agent of the first communication platform uses the node card's private key to decrypt the encrypted random string and obtain a random string; The security agent of the first communication platform uses the public key of the second communication platform to encrypt the random string and performs hash calculation using a hash algorithm. The encrypted and hashed random string is then distributed to the security management center platform through the trusted control channel, and then distributed to the second communication platform by the security management center platform through its two-way authentication channel with the second communication platform. The security agent of the second communication platform uses a hash algorithm to verify the integrity of the random string and decrypts it using the node card's private key.

[0029] Specifically, in this embodiment, the double protection is based on an improved hash mechanism to establish a secure tunnel (VPN virtual channel) to ensure the security of the communication channel. Building upon dynamic two-way authentication, both communicating parties perform two-way dynamic authentication through a security management and control platform. Then, an improved hash mechanism is used, employing random numbers (generated by a cryptographic machine) to make the transmitted information irregular and unpredictable, establishing a trusted and secure communication tunnel between the two parties, resistant to repudiation and replay attacks.

[0030] The specific process is as follows: (1) The authentication service of the security management and control platform requests a random string from the encryption machine, such as 100 strings; (2) The authentication service encrypts the obtained random string using the public key of the node card on communication platform A (SM2) and transmits it to the communication platform A device. Alternatively, communication platform A actively requests and obtains the random string returned by the encryption machine; (3) The security agent on communication platform A calls the node card's private key to decrypt the encrypted random string and takes a random string, assuming it is: abcdef; (4) The security agent on communication platform A uses the public key on communication platform B to encrypt and hash using the SM3 algorithm; then it distributes the random string to the security management and control platform through the channel established by the two-way authentication between communication platform A and security management and control platform, and then the security management and control platform distributes the random string to communication platform B through the two-way authentication channel between the platform and communication platform B. (5) When the security agent on communication platform B receives the hashed and encrypted random string, it uses the SM3 algorithm to perform a hash check. Then, the security agent on communication platform B uses the node card private key to decrypt the random string: abcdef.

[0031] S103, Data transmission phase: Based on the client, the data to be transmitted is subjected to packet encryption processing, and secure transmission of communication information is achieved through the secure tunnel.

[0032] Furthermore, the step of performing block encryption processing on the data to be transmitted based on the client includes: The first client divides the data to be transmitted into groups, encrypts the grouped data using the SM4 algorithm, forms ciphertext, and transmits it to the second client through the secure tunnel; The second client decrypts the received ciphertext using SM4 and reassembles it into the original data.

[0033] Specifically, in this embodiment, triple protection is based on fast packet encryption transmission using a lightweight smart card to ensure the security of transmitted information. A smart card with lightweight encryption is used to achieve fast packet encryption transmission, effectively preventing information leakage; and trusted integrity verification prevents unauthorized users from reading the data. The main process is data packetization – data encryption – ciphertext transmission – ciphertext decryption.

[0034] like Figure 3 The diagram shows the architecture of the communication transmission protection system based on trusted management in this embodiment. It is mainly based on the IKEv2 protocol, combined with Chinese cryptographic algorithms (SM2, SM3, SM4), a USB node card, and an encryption machine. See below. Figure 3 As shown, the main functions of the modules are as follows: Security Management and Control Platform: This is the core management component of the entire system, responsible for centralized control of communication transmission security. The LDAP certificate store stores relevant digital certificates, providing credentials for secure operations such as identity authentication; the authentication service verifies the identities of communication participants, ensuring that only legitimate nodes can participate in communication; and the encryption machine encrypts communication data, ensuring data confidentiality during transmission.

[0035] Communication platforms (SCP1, SCP2): Serving as communication carriers, they connect to different communication subnets (each communication subnet contains different nodes), enabling communication and interaction between nodes in different subnets.

[0036] Security Agent: The security agent is deployed in a distributed manner on various secure communication platforms. It calls the key information stored in the node card to communicate securely with the security management and control platform, receives security control policies issued by the security management and control platform and executes them automatically, handles and blocks security incidents, and reduces the risk of security incidents to an acceptable level.

[0037] Node card: Stores the user ID and corresponding identity parameter information of all client nodes within the communication subnet, and stores the hash algorithm used for authentication and the national cryptographic algorithm used for encryption.

[0038] VPN tunnels: Establish virtual private network tunnels between communication platforms (such as between SCP1 and SCP2) to provide a secure transmission channel for communication data, prevent data from being illegally stolen or tampered with when transmitted over the public network, and further enhance the security of communication transmission.

[0039] Furthermore, the method is implemented based on the IKEv2 protocol framework, and the Chinese national cryptographic algorithms SM2, SM3, and SM4 are applied to the authentication, hashing, and encryption stages of the protocol, respectively. Furthermore, the method also includes: during the IKE_AUTH exchange phase of the IKEv2 protocol, the SM2 digital certificate used for identity authentication is read from the USB node card; the USB node card simultaneously provides client identity storage and password computation services for the identity authentication phase.

[0040] Specifically, in this embodiment, the workflow of the communication transmission protection system based on trusted management and control is as follows: Figure 4 As shown, the main steps include the following: S1. Preparations.

[0041] 1. The node card has been issued through the cryptographic subsystem (SYQ20) of the security management and control platform; 2. The certificate is already stored in LDAP; 3. Authentication has been completed between the communication platform and the authentication service; 4. Generate two-end (scp1 / scp2) national cryptographic certificates, namely CA and SM2 certificates, using the ss-gmalg tool, and store the generated certificates in the following directories respectively: CA certificate: etc / swanctl / x509ca / ca.cert.pem; SM2 Certificate: 1. Security Management Center Platform: etc / swanctl / private / server.key.pem; etc / swanctl / pubkey / server.pub.key.pem 2. Client: / tmp / client.cert.pem; / tmp / client.key.pem S2, Phase 1: IKE_SA_INIT Exchange (Initial Exchange). Purpose: To negotiate the encryption algorithm, exchange the Diffie-Hellman public key, and generate initial key materials. The process is as follows: 1. The initiator sends the first message (SA proposal, Nonce, DH public key, etc.); 2. The responder replies with an accepted SA proposal, its own Nonce, and DH public key; 3. Both parties exchange and generate a shared key based on DH, which is used for encryption and authentication in subsequent communications.

[0042] This step does not modify the IKEv2 negotiation process, but requires replacing the algorithm (such as AES→SM4, SHA→SM3, ECDSA→SM2).

[0043] S3, Phase Two IKE_AUTH Exchange (Authentication Exchange). Purpose: Identity authentication, establishing the first IKE SA (Security Association). The process is as follows: 1. The initiator sends an encrypted authentication message (containing identity information and certificate); 2. The responder verifies the initiator's identity and replies with their authentication information; 3. Both parties use the national cryptographic SM2 certificate for identity verification (issued by a self-built CA); 4. After successful verification, establish IKE SA.

[0044] The certificate is stored in the Flash memory of the USB encryption card and read via libusb.

[0045] S4. Third Phase: CHILD_SA (Tunnel) Establishment (IPSec SA). Purpose: To establish an IPSec security association (ESP / AH) for data transmission. The process is as follows: 1. Exchange and negotiate IPSec SA through CREATE CHILD SA protected by IKE SA.

[0046] 2. The negotiated content includes: encryption algorithm (SM4); authentication algorithm (SM3); SPI (Security Parameter Index); key, etc.

[0047] Once completed, both parties can transmit data encrypted via an IPSec tunnel.

[0048] S5, Phase Four Data Transmission. This involves using the established IPSec SA to encrypt IP packets (SM4) and authenticate them (SM3). Data is decrypted via the USB node card. By starting the configuration, the program performs the following tasks: 1. scp1 and scp2 start the StrongWAN daemon process; 2. Distribute the configuration file (secure channel configuration) to the strongwan of scp1 / scp2; 3. The server (SCP1) initiates swanctl, waiting for the client (SCP2) to connect; S6, Phase 5 synchronization of the SM4 symmetric key. Includes: In the configuration interface of the security management center platform: if the tunnel is not currently enabled, click "Start Tunnel" in the security channel configuration interface.

[0049] The security management center platform periodically retrieves and distributes random strings (keys): (1) Perform hash calculation on random strings based on hashmac; (2) Then the random string is encrypted and transmitted using the public key of the peer (client, scp2)ukey.

[0050] 3. The peer decrypts the data based on the node card's private key and then verifies its integrity based on hashmac, ensuring both confidentiality and integrity of the data transmission. When the peer changes the tunnel key again, it uses the synchronized random string as the encryption key for the tunnel connection sm4.

[0051] In traditional secure data transmission, integrity verification typically applies to the entire data packet or message stream. This approach has a significant drawback: the receiver must wait for the entire data packet to be received and decrypted before performing integrity verification. If verification fails, all previous decryption computational resources are wasted, and it's impossible to quickly pinpoint the data segment where the problem originated. To address this, this embodiment further proposes that the step of performing block encryption processing on the data to be transmitted based on the client includes: The first client encrypts each data packet of the data to be transmitted using the SM4 algorithm to generate packet ciphertext, generates an independent integrity check code for the packet ciphertext using the SM3 algorithm, and appends the check code to the end of the packet. After receiving each data packet, the second client strips and verifies the integrity check code; after the verification is successful, it performs an SM4 decryption operation on the data packet.

[0052] Specifically, in this embodiment, during the data transmission phase, an integrity credential is generated and appended to each encrypted smallest data unit (i.e., packet). The receiver then performs a "verification first, decryption later" process on each packet, thereby detecting and handling damaged or tampered data at the earliest possible time. At the sender (first client), after the business data to be transmitted is divided into multiple data packets, each plaintext packet is first encrypted using the SM4 algorithm to obtain the corresponding ciphertext packet. Subsequently, the system immediately uses the SM3 hash algorithm to calculate an independent integrity check code for this newly generated ciphertext packet itself. After the calculation is completed, the sender directly appends this check code to the end of the ciphertext packet, forming a brand new, integrity-protected data unit, ready to be sent through a secure tunnel.

[0053] At the receiver (second client), the process corresponds to that of the sender, but the order is crucial. Upon receiving a data unit, the receiver first parses it, separating the ciphertext portion from the appended integrity checksum. Next, before attempting any decryption, the receiver hashes the received ciphertext portion using the same SM3 algorithm to generate a local checksum. It then compares the calculated checksum with the received checksum.

[0054] The result of the integrity check directly determines subsequent operations. If the two check codes match perfectly, it proves that the packet has not been tampered with during transmission, and its integrity is confirmed. Only then will the receiver pass the ciphertext to the SM4 decryption module for normal decryption, restoring the original plaintext data. If the check fails, it indicates that the packet may be corrupted or attacked. The receiver will immediately discard the packet, and most importantly, skip the decryption operation. Simultaneously, the system will record this security event and can choose to alert the upper-layer system or management platform. Through the above-mentioned refined management of "one packet, one check" and "check before decryption," this implementation achieves two core benefits. First, it greatly improves system efficiency, avoiding unnecessary decryption computational costs for corrupted data. Second, it enhances security, enabling immediate detection and blocking of local tampering attacks on the data stream, achieving high-reliability protection of transmitted data at each level, ensuring both confidentiality and integrity.

[0055] In summary, the communication transmission protection method and system based on trusted management and control involved in this embodiment has the following effects: It establishes a secure tunnel based on dynamic two-way authentication and an improved hash mechanism; and it provides triple protection through fast packet encryption transmission based on a lightweight smart card, ensuring the security of the identities of both communicating parties, the channel security, and the security of transmitted data. Based on a security management and control platform, and employing national cryptographic algorithms, it achieves trusted and controllable network connection and communication processes. Furthermore, the technology of this embodiment is applicable to security management and control application scenarios for network connections and network communication transmission in complex network systems.

[0056] Secondly, this embodiment also proposes a communication transmission protection system based on trusted management and control, such as... Figure 5 As shown, the system includes: The identity authentication module 501 is used to perform two-way dynamic authentication with the security management center platform based on the communication platforms of both clients to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform; the security management center platform is used to manage the communication platform. The channel establishment module 502 is used to generate and distribute random numbers by the security management center platform based on the trusted control channel, and the two clients establish an end-to-end secure tunnel based on the random numbers and using a hash mechanism. The data transmission module 503 is used to perform packet encryption processing on the data to be transmitted based on the client, and to realize secure transmission of communication information through the secure tunnel.

[0057] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for protecting communication transmission based on trusted management and control, characterized in that, include: During the identity authentication phase, two-way dynamic authentication is performed between the communication platforms of both clients and the security management center platform to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform. The security management center platform is used to manage and control the communication platform; During the channel establishment phase, based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on the random numbers and using a hash mechanism. During the data transmission phase, the client performs packet encryption on the data to be transmitted, and secure transmission of communication information is achieved through the secure tunnel.

2. The method for communication transmission protection based on trusted management and control according to claim 1, characterized in that, The two-way dynamic authentication based on the communication platform and security management center platform of both clients to verify the client's identity includes: In response to the security management center platform receiving a client authentication request, a first random number and a first timestamp are generated, a first authentication code is calculated based on the first random number, the first timestamp, and the client identity parameters pre-stored by the security management center platform, and the first authentication code, the first random number, and the first timestamp are sent to the communication platform. The communication platform calculates and verifies the first authentication code based on the locally stored client identity parameters, the first random number, and the timestamp of the security management center platform. After successful verification, it generates a second random number. The platform then calculates a second authentication code based on the second random number, the first timestamp, and the client identity parameters, and sends the second authentication code and the second random number to the security management center platform. The security management center platform verifies the second authentication code and checks the uniqueness of the second random number within the time period indicated by the first timestamp, thereby completing the final authentication of the client.

3. The method for communication transmission protection based on trusted management and control according to claim 2, characterized in that, The client includes a first client and a second client; the first client is located on a first communication platform, and the second client is located on a second communication platform. Based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and a hash mechanism, including: The random number distributed by the security management center platform is a third random number generated by the encryption machine. This third random number is distributed to the first communication platform and the second communication platform through the trusted control channel established in the identity authentication stage. After receiving the third random number, the first communication platform uses the public key of the second communication platform to encrypt and hash it, and then forwards the result to the second communication platform via the security management center platform. The second communication platform performs hash verification on the received data to ensure its integrity, and decrypts it using its own private key to obtain the third random number.

4. The method for communication transmission protection based on trusted management and control according to claim 2, characterized in that, The calculation and verification of the first authentication code includes: The communication platform determines a second authentication code based on locally stored client identity parameters, the first random number, and the timestamp of the security management center platform; and verifies the trust status of the security management center platform based on the first authentication code and the second authentication code. The method further includes: in response to the security management center platform being in a trusted state, the communication platform generates a second random number; based on the second random number, the timestamp of the security management center platform, and the locally stored client identity parameters, a third authentication code is determined, and the third authentication code is sent to the security management center platform; The security management center platform verifies the validity of the third authentication code to complete the client's identity authentication.

5. The method for communication transmission protection based on trusted management and control according to claim 3, characterized in that, Based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and a hash mechanism, including: Request multiple random strings from the encryption machine based on the authentication service of the security management center platform; The authentication service uses the public key of the node card of the first communication platform to encrypt the random string and transmits it to the first communication platform; The security agent of the first communication platform uses the node card's private key to decrypt the encrypted random string and obtain a random string; The security agent of the first communication platform uses the public key of the second communication platform to encrypt the random string and performs hash calculation using a hash algorithm. The encrypted and hashed random string is then distributed to the security management center platform through the trusted control channel, and then distributed to the second communication platform by the security management center platform through its two-way authentication channel with the second communication platform. The security agent of the second communication platform uses a hash algorithm to verify the integrity of the random string and decrypts it using the node card's private key.

6. The method for communication transmission protection based on trusted management and control according to claim 5, characterized in that, The step of performing block encryption processing on the data to be transmitted based on the client includes: The first client divides the data to be transmitted into groups, encrypts the grouped data using the SM4 algorithm, forms ciphertext, and transmits it to the second client through the secure tunnel; The second client decrypts the received ciphertext using SM4 and reassembles it into the original data.

7. The method for communication transmission protection based on trusted management and control according to claim 6, characterized in that, The step of performing block encryption processing on the data to be transmitted based on the client includes: The first client encrypts each data packet of the data to be transmitted using the SM4 algorithm to generate packet ciphertext, generates an independent integrity check code for the packet ciphertext using the SM3 algorithm, and appends the check code to the end of the packet. After receiving each data packet, the second client strips and verifies the integrity check code; after the verification is successful, it performs an SM4 decryption operation on the data packet.

8. The method for communication transmission protection based on trusted management and control according to any one of claims 1 to 7, characterized in that, The method is implemented based on the IKEv2 protocol framework, and the national cryptographic algorithms SM2, SM3 and SM4 are applied to the authentication, hashing and encryption stages of the protocol, respectively.

9. The method for communication transmission protection based on trusted management and control according to claim 8, characterized in that, The method further includes: during the IKE_AUTH exchange phase of the IKEv2 protocol, the SM2 digital certificate used for authentication is read from the USB node card; the USB node card also provides client identity storage and password calculation services for the authentication phase.

10. A communication transmission protection system based on trusted management and control, characterized in that, include: The identity authentication module is used to perform two-way dynamic authentication with the security management center platform based on the communication platforms of both clients to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform. The security management center platform is used to manage and control the communication platform; The channel establishment module is used to generate and distribute random numbers by the security management center platform based on the trusted control channel, and the two clients establish an end-to-end secure tunnel based on the random numbers and using a hash mechanism. The data transmission module is used to perform packet encryption processing on the data to be transmitted based on the client, and to achieve secure transmission of communication information through the secure tunnel.

Citation Information

Patent Citations

  • Data trusted transmission protection method based on edge computing and communication system

    CN116248410A

  • Bidirectional authentication security mobile communication method and system based on public key digital fingerprint

    CN120475369A

  • Internet-of-vehicles communication security authentication method, system and device based on national cryptographic algorithm

    WO2023147785A1

  • Chinese national cryptographic algorithm-based identity authentication and data encryption method for coap

    WO2025000590A1