A communication transmission protection method and system based on trusted management and control
By using the two-way dynamic authentication and hashing mechanism of the security management and control platform, combined with the national cryptographic algorithm, the problems of key staticization and insufficient national cryptographic adaptation in the IPsec protocol are solved. An end-to-end secure tunnel is established, realizing the authentication of communication entities and the security of data transmission, which is suitable for complex system network communication.
Patent Information
- Application Number
- CN202511488834.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-17
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-10-17
AI Technical Summary
In existing technologies, protocols such as IPsec use fixed pre-shared keys, which are vulnerable to brute-force attacks. The national cryptographic algorithms are not deeply integrated, and there is a lack of dynamic network isolation mechanisms based on hardware characteristics, resulting in insufficient network communication security.
By using two-way dynamic authentication based on a security management and control platform, a trusted control channel is established by generating random numbers, an end-to-end secure tunnel is established by using a hash mechanism, and data packets are encrypted using the SM4 algorithm. Combined with the IKEv2 protocol framework and the national cryptographic algorithms SM2, SM3, and SM4, the identity authentication and data transmission security of the communicating parties are realized.
It achieves secure verification of the identity of communication entities, ensuring the security of communication channels and the reliability of information transmission, and is suitable for security assurance of complex system network communication.
Smart Images

Figure CN120956541B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network communication security, in particular to a communication transmission protection method and system based on trusted management and control. BACKGROUND
[0002] With the accelerated promotion of digital transformation, network communication security has become a key element to ensure national security, economic development and social stability. In the context of rapid iteration of digital technology, network attack means are constantly evolving, from traditional DDoS attacks to AI-driven deep counterfeit fraud, from IPv4 protocol vulnerabilities to IPv6 new risks, network security threats are showing a trend of diversification and complexity. As a core component of network communication security, trusted network connection ensures the confidentiality, integrity and availability of data transmission process by integrating various security technology means. It not only serves as the foundation for efficient and secure data circulation, reducing cross-domain and cross-industry circulation costs through unified transmission interaction environment, and activating data asset value; it also promotes the integration of data, algorithm and security, and realizes the synergy of data and algorithm, network and security.
[0003] Network security products comply with the trend of domestic substitution, not only supporting domestic hardware, but also supporting national encryption algorithms for IPsec VPN tunnels, supporting interface with mainstream manufacturers in the industry, and realizing deeper compliance and strategic independence. Traditional network communication security adopts private protocols, encrypted tunnels, etc., mainly using VPN based on IPsec security protocol. The existing technical implementation scheme has the following technical bottlenecks: Key static risk: IPsec and other protocols use fixed pre-shared keys, which have the risk of brute force cracking (such as UKey storage still cannot solve the problem of key update). Insufficient national encryption adaptation: SM2 / SM3 / SM4 algorithms are not deeply integrated into the whole process of authentication and key agreement. Fuzzy security boundary: Lack of dynamic network isolation mechanism based on hardware features.
[0004] In view of the above problems, the existing technology needs to be improved. SUMMARY
[0005] The purpose of the present application is to provide a communication transmission protection method and system based on trusted management and control, based on the trusted basis provided by the security management and control platform, through the two-way dynamic authentication of both parties of communication, to ensure the security of the identity of the communication entity; through fast packet encryption transmission, to ensure the security of communication transmission information; and through the hash mechanism, to ensure the security of the communication channel; to ensure the security of the network communication process, to meet the needs of network communication security and communication connection trust. It is suitable for the security guarantee of complex system network communication.
[0006] In the first aspect, the present application provides a communication transmission protection method based on trusted management and control, comprising:
[0007] In the identity authentication stage, two-way dynamic authentication is performed between the client and the security management center platform based on the communication platforms where the two clients are located, to verify the identity of the clients and establish a trusted control channel between the communication platform and the security management center platform; the security management center platform is used to control the communication platform;
[0008] In the channel establishment stage, a random number is generated and distributed by the security management center platform based on the trusted control channel, and an end-to-end security tunnel is established by the two clients based on the random number and using a hash mechanism;
[0009] In the data transmission stage, the client performs packet encryption processing on the data to be transmitted, and realizes secure transmission of communication information through the security tunnel.
[0010] Further, the two-way dynamic authentication between the client and the security management center platform based on the communication platforms where the two clients are located to verify the identity of the clients includes:
[0011] In response to the security management center platform receiving a client authentication request, a first random number and a first timestamp are generated, a first authentication code is calculated based on the first random number, the first timestamp, and the pre-stored client identity parameters of the security management center platform, and the first authentication code, the first random number, and the first timestamp are sent to the communication platform;
[0012] The communication platform calculates and verifies the first authentication code based on the locally stored client identity parameters, the first random number, and the timestamp of the security management center platform, generates a second random number after verification, calculates a second authentication code based on the second random number, the first timestamp, and the client identity parameters, and sends the second authentication code and the second random number to the security management center platform;
[0013] The second authentication code is verified by the security management center platform, and the uniqueness of the second random number within the time period indicated by the first timestamp is checked, thereby completing the final authentication of the client.
[0014] Further, the client includes a first client and a second client; the first client is located in a first communication platform, and the second client is located in a second communication platform;
[0015] The random number is generated and distributed by the security management center platform based on the trusted control channel, and the end-to-end security tunnel is established by the two clients based on the random number and using a hash mechanism, including:
[0016] The random number distributed by the security management center platform is a third random number generated by the encryption machine, which is distributed to the first communication platform and the second communication platform through the trusted control channel established by the identity authentication stage.
[0017] After receiving the third random number, the first communication platform encrypts and hashes the third random number using the public key of the second communication platform, and forwards the result to the second communication platform via the security management center platform.
[0018] The second communication platform hashes the received data to ensure integrity, and uses its own private key to decrypt to obtain the third random number.
[0019] Further, the calculation and verification of the first authentication code includes:
[0020] The communication platform determines a second authentication code according to the locally stored client identity parameter, the first random number, and the security management center platform timestamp; and verifies the trusted state of the security management center platform according to the first authentication code and the second authentication code.
[0021] The method further includes: in response to the security management center platform being in a trusted state, the communication platform generates a second random number; determines a third authentication code according to the second random number, the security management center platform timestamp, and the locally stored client identity parameter, and sends the third authentication code to the security management center platform.
[0022] The security management center platform verifies the validity of the third authentication code to complete the identity authentication of the client.
[0023] Further, based on the trusted control channel, the security management center platform generates and distributes a random number, and the client parties establish an end-to-end secure tunnel based on the random number and using a hash mechanism, including:
[0024] Apply for a plurality of random strings from the encryption machine according to the authentication service of the security management center platform;
[0025] The authentication service encrypts the random strings using the public key of the node card of the first communication platform and transmits them to the first communication platform;
[0026] The security agent of the first communication platform decrypts the encrypted random strings using the private key of the node card and obtains a random string;
[0027] The security agent of the first communication platform encrypts the random string using the public key of the second communication platform and performs a hash calculation using a hash algorithm, distributes the encrypted and hashed random string to the security management center platform through the trusted control channel, and then the security management center platform distributes the random string to the second communication platform through the two-way authentication channel between the security management center platform and the second communication platform.
[0028] The security agent of the second communication platform checks the integrity of the random string using a hash algorithm and decrypts the random string using the node card private key.
[0029] Further, the grouping and encryption processing of the to-be-transmitted data by the client comprises:
[0030] The first client groups the to-be-transmitted data, encrypts the grouped data using the SM4 algorithm, forms ciphertext, and transmits the ciphertext to the second client through the secure tunnel.
[0031] The second client performs SM4 decryption on the received ciphertext and reorganizes the original data.
[0032] Further, the grouping and encryption processing of the to-be-transmitted data by the client comprises:
[0033] The first client generates grouped ciphertext after encrypting each data group of the to-be-transmitted data using the SM4 algorithm, generates an independent integrity check code for the grouped ciphertext using the SM3 algorithm, and appends the check code to the tail of the group.
[0034] The second client strips and checks the integrity check code after receiving each data group; after the check passes, the second client performs SM4 decryption on the grouped data.
[0035] Further, the method is implemented based on the IKEv2 protocol framework, and the national secret algorithms SM2, SM3, and SM4 are respectively applied to the authentication, hash, and encryption links of the protocol.
[0036] Further, the method further comprises: in the IKE_AUTH exchange stage of the IKEv2 protocol, the SM2 digital certificate for identity authentication is read from the USB node card; the USB node card simultaneously provides client identity storage and password operation services for the identity authentication stage.
[0037] In a second aspect, the application further provides a communication transmission protection system based on trusted management and control, comprising:
[0038] An identity authentication module is configured to perform two-way dynamic authentication with a security management center platform based on communication platforms where the two clients are located, to verify the identities of the clients, and to establish a trusted control channel between the communication platforms and the security management center platform; the security management center platform is configured to control the communication platforms;
[0039] A channel establishment module is configured to generate and distribute random numbers by the security management center platform based on the trusted control channel, and the two clients establish an end-to-end secure tunnel based on the random numbers and a hash mechanism;
[0040] A data transmission module is configured to perform packet encryption processing on the data to be transmitted by the clients, and to realize secure transmission of communication information through the secure tunnel.
[0041] As can be seen from the above, the method and system for protecting communication transmission based on trusted control provided by the present application, through the identity authentication stage, perform two-way dynamic authentication with a security management center platform based on communication platforms where the two clients are located, to verify the identities of the clients, and to establish a trusted control channel between the communication platforms and the security management center platform; in the channel establishment stage, generate and distribute random numbers by the security management center platform based on the trusted control channel, and the two clients establish an end-to-end secure tunnel based on the random numbers and a hash mechanism; in the data transmission stage, perform packet encryption processing on the data to be transmitted by the clients, and realize secure transmission of communication information through the secure tunnel. Through two-way dynamic authentication of the two communication parties, the security of the identities of the communication entities is ensured; through fast packet encryption transmission, the security of the communication transmission information is ensured; and through the hash mechanism, the security of the communication channel is ensured; thus the security of the network communication process is ensured, the needs of network communication security and trusted communication connection are met, and the security guarantee for complex system network communication is achieved. BRIEF DESCRIPTION OF DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0043] Figure 1 is a flowchart of the method steps for protecting communication transmission based on trusted control disclosed by the embodiments of the present application;
[0044] Figure 2 is an authentication flowchart of the identity authentication stage disclosed by the embodiments of the present application;
[0045] Figure 3is a schematic diagram of a protection system for realizing communication transmission based on trusted management and control disclosed by an embodiment of the present application.
[0046] Figure 4 is a workflow diagram of a protection system for realizing communication transmission based on trusted management and control disclosed by an embodiment of the present application.
[0047] Figure 5 is a structural schematic diagram of a protection system for realizing communication transmission based on trusted management and control disclosed by an embodiment of the present application. DETAILED DESCRIPTION
[0048] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments belong. The terminology used in the description of the embodiments herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the embodiments. The use herein of terms such as "comprise", "comprising", "comprises", "including", "includes" or "contain" or "containing" is to be interpreted in a non-exclusive or non-limiting sense. The use herein of terms such as "first", "second" and "third" or "a", "an" and "the" is to be interpreted in an at-least open-ended sense.
[0049] The implementation details of the technical solutions of the embodiments are described in detail as follows:
[0050] The present application proposes a method for realizing communication transmission protection based on trusted management and control, as shown in the following figure, the method mainly includes three phases of triple protection executed by the following three phases: identity authentication phase, channel establishment phase, and data transmission phase. The method comprises: Figure 1
[0051] S101, identity authentication phase, based on the communication platform where the client is located, two-way dynamic authentication with the security management center platform is executed to verify the identity of the client, and a trusted control channel between the communication platform and the security management center platform is established; the security management center platform is used to control the communication platform.
[0052] Further, the two-way dynamic authentication with the security management center platform based on the communication platform where the client is located to verify the identity of the client comprises:
[0053] In response to the security management center platform receiving a client authentication request, a first random number and a first timestamp are generated, a first authentication code is calculated according to the first random number, the first timestamp, and the client identity parameters pre-stored by the security management center platform, and the first authentication code, the first random number, and the first timestamp are sent to the communication platform;
[0054] The communication platform calculates and verifies the first authentication code according to the locally stored client identity parameter, the first random number and the security management center platform timestamp, generates a second random number after verification, calculates a second authentication code according to the second random number, the first timestamp and the client identity parameter, and sends the second authentication code and the second random number to the security management center platform.
[0055] The security management center platform verifies the second authentication code and checks the uniqueness of the second random number within the time period indicated by the first timestamp, thereby completing the final authentication of the client.
[0056] Further, the calculation and verification of the first authentication code include:
[0057] The communication platform determines a second authentication code according to the locally stored client identity parameter, the first random number and the security management center platform timestamp, and verifies the trusted state of the security management center platform according to the first authentication code and the second authentication code.
[0058] The method further includes: in response to the security management center platform being in a trusted state, the communication platform generates a second random number; determines a third authentication code according to the second random number, the security management center platform timestamp and the locally stored client identity parameter, and sends the third authentication code to the security management center platform.
[0059] The security management center platform verifies the validity of the third authentication code to complete the identity authentication of the client.
[0060] Specifically, the method for realizing communication transmission security protection based on trusted management and control disclosed in the embodiment includes the following steps. Figure 2 As shown in the authentication flowchart of the identity authentication stage of the embodiment. The authentication process is as follows:
[0061] (1) The client node sends an authentication request (provides the node user number) to the communication platform of the communication subnet where the node is located through an internal trusted transmission channel. The security management center platform is also realized by a server; the communication platform is realized by a server, and the communication platform is managed and controlled by the security management center platform.
[0062] (2) After the communication platform receives the request of the client node, the identity parameter information of the corresponding user in the node card is searched for according to the user number of the client node received by the communication platform. If no corresponding user number is found, the node is an illegal node and communication is prohibited; otherwise, the security agent installed on the communication platform will encrypt the user request using a pre-negotiated encryption algorithm and send it to the security management and control platform.
[0063] (3) After receiving the information, the security management and control platform creates a session for the client node. First, it decrypts the information using the same algorithm to obtain the user's original request information, and then, based on the user ID... Retrieve the pre-stored client node identity parameter information from its own database. Use an encryption machine to generate random strings And obtain the current system timestamp. Using a pre-agreed hash algorithm to... and Perform hash calculation Obtain the authentication code from the security management and control platform. ,and Together they form authentication information, which is then encrypted and sent to the communication platform.
[0064] (4) After the security agent of the communication platform decrypts the received authentication information, it uses the timestamp received from the security management and control platform. and random string Stored in the node card Calculate using the same hash algorithm Get a re-authentication code , and the decrypted result The authentication process is then compared; if they match, the security management and control platform is considered trustworthy; otherwise, the authentication process is interrupted. Once the security management and control platform is confirmed to be trustworthy, the communication platform's security agent uses the user's identity parameter information from the node card to generate a random string. Using the same hash algorithm, and Calculate together Generate authentication codes for client nodes. ,and , Together, they are packaged and encrypted as authentication information and sent to the security management and control platform.
[0065] (5) After decrypting the received authentication information, the security management and control platform performs the following judgments:
[0066] a. The system uses the session identifier and timestamp to determine if the current session is the same one initially established with the client node, to prevent replay attacks. If not, the authentication process is interrupted; otherwise, the process proceeds to the next verification step.
[0067] b. Verify the received random string from the client node. whether the user has been used at the timestamp designated day, if yes, authentication fails, otherwise, go to the next step of verification;
[0068] c. The security management and control platform generates and distributes and Again, using the same hash algorithm to generate authentication code , and the received Comparison, if the same, the client node is a legitimate user, login success can access other nodes; Otherwise, refuse the client node login.
[0069] S102, channel establishment stage, based on the trusted control channel, the security management center platform generates and distributes random numbers, and the client parties establish an end-to-end security tunnel according to the random numbers and using the hash mechanism.
[0070] Further, the client includes a first client and a second client; The first client is located in the first communication platform, and the second client is located in the second communication platform.
[0071] Based on the trusted control channel, the security management center platform generates and distributes random numbers, and the client parties establish an end-to-end security tunnel according to the random numbers and using the hash mechanism, comprising:
[0072] The random number distributed by the security management center platform is a third random number generated by an encryption machine, which is distributed to the first communication platform and the second communication platform through the trusted control channel established in the identity authentication stage.
[0073] After receiving the third random number, the first communication platform encrypts and hashes it using the public key of the second communication platform, and transmits the result to the second communication platform through the security management center platform.
[0074] The second communication platform performs hash check on the received data to ensure integrity, and uses its own private key to decrypt to obtain the third random number.
[0075] Further, based on the trusted control channel, the security management center platform generates and distributes random numbers, and the client parties establish an end-to-end security tunnel according to the random numbers and using the hash mechanism, comprising:
[0076] Apply for multiple random strings from the encryption machine according to the authentication service of the security management center platform;
[0077] The authentication service encrypts the random string using the node card public key of the first communication platform and transmits it to the first communication platform;
[0078] The security agent of the first communication platform decrypts the encrypted random string using the node card private key and obtains a random string;
[0079] The security agent of the first communication platform encrypts the random string using the public key of the second communication platform and performs a hash calculation using a hash algorithm, distributes the encrypted and hashed random string to the security management center platform through the trusted control channel, and then distributes the random string to the second communication platform through the bidirectional authentication channel between the security management center platform and the second communication platform;
[0080] The security agent of the second communication platform checks the integrity of the random string using a hash algorithm and decrypts the random string using the node card private key.
[0081] Specifically, in this embodiment, the double protection is based on the establishment of a secure tunnel (VPN virtual channel) using an improved hash mechanism to ensure the security of the communication channel. On the basis of dynamic bidirectional authentication, both parties of the communication perform bidirectional dynamic authentication through the security management and control platform, and then use an improved hash mechanism to use random numbers (generated by a password machine) to make the transmitted information irregular and unpredictable, establishing a trusted secure communication tunnel between the two parties of the communication, which can resist denial of service and replay attacks.
[0082] The specific process is as follows:
[0083] (1) The authentication service of the security management and control platform applies for a random string from the encryption machine, such as 100;
[0084] (2) The authentication service transmits the applied random string to the communication platform A device using the public key of the node card on the communication platform A (SM2). Alternatively, the communication platform A actively applies for and obtains the random string returned by the encryption machine;
[0085] (3) The security agent on the communication platform A decrypts the encrypted random string using the node card private key, and takes a random string, which is assumed to be: abcdef;
[0086] (4) The security agent on the communication platform A encrypts using the public key of the communication platform B and performs a hash calculation using the SM3 algorithm, and then distributes the random string to the security management and control platform through the channel established by the bidirectional authentication between the communication platform A and the security management and control platform, and then distributes the random string to the communication platform B through the bidirectional authentication channel between the security management and control platform and the communication platform B;
[0087] (5) The security agent on the communication platform B receives the hashed and encrypted random string, then performs a hash verification using the SM3 algorithm, and then the security agent on the communication platform B decrypts using the node card private key to obtain the random string: abcdef.
[0088] S103, in the data transmission stage, packet encryption processing is performed on the data to be transmitted based on the client, and the secure transmission of communication information is realized through the secure tunnel.
[0089] Further, the packet encryption processing performed on the data to be transmitted based on the client comprises:
[0090] The first client groups the data to be transmitted, encrypts the grouped data using an SM4 algorithm, forms ciphertext, and transmits the ciphertext to the second client through the secure tunnel.
[0091] The second client performs SM4 decryption on the received ciphertext and reorganizes the ciphertext into original data.
[0092] Specifically, in this embodiment, the triple protection is based on the fast packet encryption transmission of the lightweight smart card, which ensures the security of the communication transmission information. The smart card with lightweight encryption is used to realize fast packet encryption transmission, which effectively prevents information leakage; and through the trusted integrity verification, the illegal user reading is prevented. The main process is data grouping-data encryption-ciphertext transmission-ciphertext decryption.
[0093] As Figure 3 The protection system structure diagram for realizing communication transmission based on trusted management and control in this embodiment is shown in the figure, which is mainly based on the IKEv2 protocol, and is realized in combination with the SM2, SM3, and SM4 national secret algorithms and the USB node card and the encryption machine. As shown in the following Figure 3 The main functions of the modules are as follows:
[0094] The security management and control platform is the core management part of the entire system, which is responsible for centralized management and control of the security of communication transmission. The LDAP certificate storage is used to store related digital certificates to provide credentials for security operations such as identity authentication; the authentication service undertakes the task of identity verification of communication participants, ensuring that only legal nodes can participate in communication; and the encryption machine is used for encryption processing of communication data, etc., to ensure the confidentiality of data in the transmission process.
[0095] The communication platform (SCP1, SCP2) is used as a carrier for communication, and is connected to different communication subnets (each communication subnet contains different nodes) to realize communication interaction between nodes in different subnets.
[0096] The security agent is distributed on each secure communication platform, calls the key information stored in the node card, and communicates with the security management and control platform, receives the security management and control strategy issued by the security management and control platform and automatically executes it, handles and blocks security events, and reduces the risk of security events to an acceptable level.
[0097] Node card: stores the user number and corresponding identity parameter information of all client nodes in the communication subnet, and stores the hash algorithm for authentication and the national secret algorithm for encryption.
[0098] VPN channel: a virtual private network tunnel is established between communication platforms (such as between SCP1 and SCP2), providing a secure transmission channel for communication data, preventing data from being illegally stolen or tampered with during public network transmission, and further enhancing the security of communication transmission.
[0099] Further, the method is implemented based on the IKEv2 protocol framework, and the national secret algorithms SM2, SM3 and SM4 are respectively applied to the authentication, hash and encryption links of the protocol. Further, the method further comprises: in the IKE_AUTH exchange stage of the IKEv2 protocol, the SM2 digital certificate for identity authentication is read from the USB node card; the USB node card simultaneously provides client identity storage and password operation services for the identity authentication stage.
[0100] Specifically, in the embodiment, the working process of the protection system for communication transmission based on trusted management and control is as shown in Figure 4 , mainly comprising the following steps:
[0101] S1, preparation.
[0102] 1. The node card has been issued by the password subsystem (SYQ20) of the secure management and control platform;
[0103] 2. The certificate has been stored in LDAP;
[0104] 3. The communication platform and the authentication service have completed authentication;
[0105] 4. Based on the ss-gmalg tool, generate national secret certificates (CA and SM2 certificates) for both ends (scp1 / scp2), and store the generated certificates in the following directories:
[0106] CA certificate: etc / swanctl / x509ca / ca.cert.pem;
[0107] SM2 certificate: 1. Secure management center platform: etc / swanctl / private / server.key.pem; etc / swanctl / pubkey / server.pub.key.pem
[0108] 2. Client: / tmp / client.cert.pem; / tmp / client.key.pem
[0109] S2, the first phase of IKE_SA_INIT exchange (initial exchange). Purpose: to negotiate encryption algorithm, exchange Diffie-Hellman public key, generate initial key material. Process as follows:
[0110] 1, the initiator sends the first message (SA proposal, Nonce, DH public key, etc.);
[0111] 2, the responder replies to the accepted SA proposal, his own Nonce and DH public key;
[0112] 3, both sides generate a shared key according to the DH exchange, which is used for encryption and authentication of subsequent communication.
[0113] In this step, the IKEv2 negotiation process is not modified, and the algorithm needs to be replaced (such as AES→SM4, SHA→SM3, ECDSA→SM2).
[0114] S3, the second phase of IKE_AUTH exchange (authentication exchange). Purpose: identity authentication, establishment of the first IKE SA (security association). Process as follows:
[0115] 1, the initiator sends the encrypted authentication message (contains identity information and certificate);
[0116] 2, the responder verifies the initiator's identity and replies with its own authentication information;
[0117] 3, both sides use the SM2 certificate for identity verification (issued by a self-built CA);
[0118] 4, after verification, establish IKE SA.
[0119] The certificate is stored in the Flash of the USB encryption card and read through libusb.
[0120] S4, the third phase of CHILD_SA (tunnel) establishment (IPSec SA). Purpose: to establish IPSec security association (ESP / AH) for data transmission. Process as follows:
[0121] 1, through the CREATE CHILD SA exchange under the protection of IKE SA, negotiate IPSec SA.
[0122] 2, the negotiation includes: encryption algorithm (SM4); authentication algorithm (SM3); SPI (security parameter index); key, etc.
[0123] After completion, both sides can transmit data through the IPSec tunnel encryption.
[0124] S5, fourth stage data transmission. Wherein, the IP packet is encrypted (SM4) and authenticated (SM3) using the established IPSec SA. The data is decrypted through the usb node card. Through the start configuration, the program completes the following work:
[0125] 1, scp1 and scp2 start the daemon process of strongwan;
[0126] 2, the configuration file (security channel configuration) is issued to the strongwan of scp1 / scp2;
[0127] 3, the server (SCP1) pulls up swanctl and waits for the client (scp2) end to connect;
[0128] S6, the fifth stage of synchronizing sm4 symmetric key. Including:
[0129] In the configuration interface of the security management center platform: when the tunnel is not currently enabled, click start tunnel in the security channel configuration interface.
[0130] The security management center platform obtains a random string (key) and distributes it regularly:
[0131] (1) based on hashmac, the random string is calculated by hash;
[0132] (2) then the random string is encrypted and transmitted using the public key of the opposite end (client, scp2) ukey.
[0133] 3, the opposite end decrypts based on the private key of the node card, and then checks the integrity based on hashmac, to ensure that the confidentiality and integrity of data transmission coexist; the opposite end uses the random string synchronized as the encryption key of the tunnel connection sm4 when replacing the tunnel key next time.
[0134] In traditional data security transmission, integrity verification usually acts on the entire data packet or complete message stream. This method has a obvious defect: the receiver must wait for the entire data packet to be received and perform decryption operation before performing integrity verification. If the verification fails, it means that all previous decryption computing resources are wasted, and it is impossible to quickly locate the problem from which data segment. To this end, the embodiment further proposes that the client performs grouping encryption processing on the to-be-transmitted data, including:
[0135] The first client generates grouping ciphertext after encrypting each data grouping of the to-be-transmitted data using the SM4 algorithm, generates an independent integrity check code for the grouping ciphertext using the SM3 algorithm, and attaches the check code to the tail of the grouping;
[0136] The second client peels off and verifies the integrity check code after receiving each data packet; after verification, the SM4 decryption operation is performed on the packet data.
[0137] Specifically, in the data transmission phase, an integrity voucher is generated and attached to each encrypted minimum data unit (i.e., packet). The receiver then performs "verification first, decryption second" processing on each packet, thereby discovering and handling damaged or tampered data at the earliest possible time. At the sender (first client), after the service data to be transmitted is divided into multiple data packets, the SM4 algorithm is first used to encrypt each plaintext packet to obtain the corresponding ciphertext packet. Then, the system immediately uses the SM3 hash algorithm to calculate an independent integrity check code for the just-generated ciphertext packet itself. After the calculation is completed, the sender directly attaches the check code to the tail of the ciphertext packet to form a new, integrity-protected data unit, ready for transmission through a secure tunnel.
[0138] At the receiver (second client), the process corresponds to that of the sender but is critical in sequence. When a data unit is received, the receiver first parses it to separate the ciphertext part in front and the integrity check code attached at the tail. Then, before attempting any decryption operation, the receiver uses the same SM3 algorithm to perform hash calculation on the received ciphertext part to generate a local check code. Then, it compares the calculated check code with the received check code.
[0139] The result of the integrity check directly determines the subsequent operation. If the two check codes are completely identical, it proves that the packet has not been tampered with during transmission, and the integrity is confirmed. At this time, the receiver will pass the ciphertext to the SM4 decryption module for normal decryption to restore the original plaintext data. If the verification fails, it indicates that the packet may have been damaged or attacked, and the receiver will immediately discard the packet and, most importantly, skip the decryption operation. At the same time, the system will record this security event and can optionally alert the upper system or management platform. Through the above "one packet one check" and "verification first, decryption second" fine management, the present embodiment realizes two core benefits. First, it greatly improves system efficiency, avoiding unnecessary decryption algorithm cost for damaged data. Second, it enhances security, enabling immediate discovery and blocking of local tampering attacks on data streams, achieving high-trust protection of transmission data at each level with confidentiality and integrity.
[0140] In summary, the method and system for protecting communication transmission based on trusted management and control according to the embodiment have the following effects: a secure tunnel is established based on dynamic bidirectional authentication and improved hash mechanism, and three protections of fast packet encryption transmission based on a lightweight smart card are provided to ensure the identity security, channel security and transmission data security of both parties. Based on the security management and control platform, the national secret algorithm is used to realize the trusted and controllable network connection and communication process. In addition, the technology of the embodiment can be applied to the security management and control application scenarios of network connection and network communication transmission of complex network systems.
[0141] In a second aspect, the embodiment further provides a system for protecting communication transmission based on trusted management and control, as shown in the following figure: Figure 5 The system comprises:
[0142] An identity authentication module 501 is configured to perform bidirectional dynamic authentication with a security management center platform based on the communication platforms where the client parties are located, to verify the client identity and establish a trusted control channel between the communication platform and the security management center platform; and the security management center platform is configured to manage and control the communication platform.
[0143] A channel establishment module 502 is configured to generate and distribute random numbers by the security management center platform based on the trusted control channel, and the client parties establish an end-to-end secure tunnel according to the random numbers and using a hash mechanism.
[0144] A data transmission module 503 is configured to perform packet encryption processing on the data to be transmitted by the client, and realize the secure transmission of communication information through the secure tunnel.
[0145] The above is only an embodiment of the present application and does not limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A method for protecting communication transmission based on trusted management and control, characterized in that, include: During the identity authentication phase, two-way dynamic authentication is performed between the communication platforms of both clients and the security management center platform to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform. The security management center platform is used to manage and control the communication platform; During the channel establishment phase, based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on the random numbers and using a hash mechanism. During the data transmission phase, the client performs packet encryption on the data to be transmitted, and secure transmission of communication information is achieved through the secure tunnel. The two-way dynamic authentication based on the communication platform and security management center platform of both clients to verify the client's identity includes: In response to the security management center platform receiving a client authentication request, a first random number and a first timestamp are generated, a first authentication code is calculated based on the first random number, the first timestamp, and the client identity parameters pre-stored by the security management center platform, and the first authentication code, the first random number, and the first timestamp are sent to the communication platform. The communication platform calculates and verifies the first authentication code based on the locally stored client identity parameters, the first random number, and the timestamp of the security management center platform. After successful verification, it generates a second random number. The platform then calculates a second authentication code based on the second random number, the first timestamp, and the client identity parameters, and sends the second authentication code and the second random number to the security management center platform. The security management center platform verifies the second authentication code and checks the uniqueness of the second random number within the time period indicated by the first timestamp, thereby completing the final authentication of the client.
2. The method for communication transmission protection based on trusted management and control according to claim 1, characterized in that, The client includes a first client and a second client; the first client is located on a first communication platform, and the second client is located on a second communication platform. Based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and a hash mechanism, including: The random number distributed by the security management center platform is a third random number generated by the encryption machine. This third random number is distributed to the first communication platform and the second communication platform through the trusted control channel established in the identity authentication stage. After receiving the third random number, the first communication platform uses the public key of the second communication platform to encrypt and hash it, and then forwards the result to the second communication platform via the security management center platform. The second communication platform performs hash verification on the received data to ensure its integrity, and decrypts it using its own private key to obtain the third random number.
3. The method for communication transmission protection based on trusted management and control according to claim 2, characterized in that, The calculation and verification of the first authentication code includes: The communication platform determines a second authentication code based on locally stored client identity parameters, the first random number, and the timestamp of the security management center platform; and verifies the trust status of the security management center platform based on the first authentication code and the second authentication code. The method further includes: in response to the security management center platform being in a trusted state, the communication platform generates a second random number; based on the second random number, the timestamp of the security management center platform, and the locally stored client identity parameters, a third authentication code is determined, and the third authentication code is sent to the security management center platform; The security management center platform verifies the validity of the third authentication code to complete the client's identity authentication.
4. The method for communication transmission protection based on trusted management and control according to claim 3, characterized in that, Based on the trusted control channel, the security management center platform generates and distributes random numbers, and both client parties establish an end-to-end secure tunnel based on these random numbers and a hash mechanism, including: Request multiple random strings from the encryption machine based on the authentication service of the security management center platform; The authentication service uses the public key of the node card of the first communication platform to encrypt the random string and transmits it to the first communication platform; The security agent of the first communication platform uses the node card's private key to decrypt the encrypted random string and obtain a random string; The security agent of the first communication platform uses the public key of the second communication platform to encrypt the random string and performs hash calculation using a hash algorithm. The encrypted and hashed random string is then distributed to the security management center platform through the trusted control channel, and then distributed to the second communication platform by the security management center platform through its two-way authentication channel with the second communication platform. The security agent of the second communication platform uses a hash algorithm to verify the integrity of the random string and decrypts it using the node card's private key.
5. The method for communication transmission protection based on trusted management and control according to claim 4, characterized in that, The step of performing block encryption processing on the data to be transmitted based on the client includes: The first client divides the data to be transmitted into groups, encrypts the grouped data using the SM4 algorithm, forms ciphertext, and transmits it to the second client through the secure tunnel; The second client decrypts the received ciphertext using SM4 and reassembles it into the original data.
6. The method for communication transmission protection based on trusted management and control according to claim 5, characterized in that, The step of performing block encryption processing on the data to be transmitted based on the client includes: The first client encrypts each data packet of the data to be transmitted using the SM4 algorithm to generate packet ciphertext, generates an independent integrity check code for the packet ciphertext using the SM3 algorithm, and appends the check code to the end of the packet. After receiving each data packet, the second client strips and verifies the integrity check code; after the verification is successful, it performs an SM4 decryption operation on the data packet.
7. The method for communication transmission protection based on trusted management and control according to any one of claims 1 to 6, characterized in that, The method is implemented based on the IKEv2 protocol framework, and the national cryptographic algorithms SM2, SM3 and SM4 are applied to the authentication, hashing and encryption stages of the protocol, respectively.
8. The method for communication transmission protection based on trusted management and control according to claim 7, characterized in that, The method further includes: during the IKE_AUTH exchange phase of the IKEv2 protocol, the SM2 digital certificate used for authentication is read from the USB node card; the USB node card also provides client identity storage and password calculation services for the authentication phase.
9. A communication transmission protection system based on trusted management and control, characterized in that, include: The identity authentication module is used to perform two-way dynamic authentication with the security management center platform based on the communication platforms of both clients to verify the client's identity and establish a trusted control channel between the communication platform and the security management center platform. The security management center platform is used to manage and control the communication platform; The channel establishment module is used to generate and distribute random numbers by the security management center platform based on the trusted control channel, and the two clients establish an end-to-end secure tunnel based on the random numbers and using a hash mechanism. The data transmission module is used to perform packet encryption processing on the data to be transmitted based on the client, and to achieve secure transmission of communication information through the secure tunnel; The two-way dynamic authentication based on the communication platform and security management center platform of both clients to verify the client's identity includes: In response to the security management center platform receiving a client authentication request, a first random number and a first timestamp are generated, a first authentication code is calculated based on the first random number, the first timestamp, and the client identity parameters pre-stored by the security management center platform, and the first authentication code, the first random number, and the first timestamp are sent to the communication platform. The communication platform calculates and verifies the first authentication code based on the locally stored client identity parameters, the first random number, and the timestamp of the security management center platform. After successful verification, it generates a second random number. The platform then calculates a second authentication code based on the second random number, the first timestamp, and the client identity parameters, and sends the second authentication code and the second random number to the security management center platform. The security management center platform verifies the second authentication code and checks the uniqueness of the second random number within the time period indicated by the first timestamp, thereby completing the final authentication of the client.
Citation Information
Patent Citations
Data trusted transmission protection method based on edge computing and communication system
CN116248410A
Bidirectional authentication security mobile communication method and system based on public key digital fingerprint
CN120475369A