Chain store double-domain intelligent networking method and device based on 5G + SD-WAN
By using the multi-level identity authentication and dynamic optimization model of the 5G smart gateway, the problems of gateway access authentication and transmission link policy fixation for chain stores have been solved, thus realizing the security and reliability of the chain store network and ensuring the security of core business data and the flexibility of Internet access.
Patent Information
- Application Number
- CN202511634979.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-10
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-11-10
AI Technical Summary
In the existing 5G+SD-WAN networking solution for chain stores, the gateway network access authentication lacks hardware uniqueness association and status verification, resulting in significant security risks. Furthermore, the dual-domain transmission link strategy is fixed and cannot match the differentiated needs of the two types of businesses.
By adopting 5G secure access protocol and SD-WAN virtualization technology, multi-level identity authentication is performed through 5G smart gateway, combined with GPS location verification and hardware root key generation, a dual-domain encrypted transmission channel is constructed, and a dynamic optimization model is introduced for traffic scheduling and isolation, so as to achieve logical and physical isolation between the business intranet domain and the public network access domain.
Effectively intercepts devices with forged identities from accessing the network, ensuring the security of core business data, balancing the needs of dual-domain businesses, achieving stability in data transmission and flexibility in internet access, and adapting to the network security and reliability of chain stores.
Smart Images

Figure CN121078464A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of wireless communication, in particular to a 5G+SD-WAN-based dual-domain intelligent networking method and device for chain stores. BACKGROUND
[0002] As a decentralized operation scenario, the network of chain stores needs to carry two types of key businesses at the same time: one is the interaction with the headquarters core system (such as cash register data synchronization, inventory information upload, ERP system access, etc.), which requires high data transmission security and link stability; the other is the Internet access of store terminals (such as employee office inquiries, customer temporary Wi-Fi access, etc.), which focuses more on access flexibility and bandwidth adaptability. With the advantages of 5G technology in wide-area coverage and low latency, and the mature application of SD-WAN technology in virtualized networking and traffic scheduling, the combination of the two has become the main direction of chain store networking, but the current solution still does not fully match the risk prevention and control and business protection needs in actual store operations in terms of gateway access security and dual-domain link adaptation.
[0003] The existing 5G+SD-WAN networking solution for chain stores has two typical technical shortcomings that restrict network security and reliability: first, the gateway access authentication lacks hardware uniqueness correlation and state verification, with significant security risks: the gateway access authentication mechanism has vulnerabilities, and most solutions only verify the identity through device serial numbers or basic network information, without correlating the unique features of the gateway hardware, and without verifying the actual deployment location and running health status of the device (such as hardware temperature and system integrity), resulting in risks such as illegal devices accessing the network by forging their identities, and abnormal state devices (such as tampered systems and overloaded hardware) accessing the network, directly threatening the security of core business data at headquarters; second, the dual-domain transmission link strategy is fixed and cannot match the differentiated needs of the two types of businesses: the dual-domain transmission link strategy lacks dynamic adaptation capabilities, and the business intranet domain (connected to headquarters) and the public network access domain (connected to the Internet) use unified link selection logic, without adjusting the strategy based on the different needs of the two types of businesses and the real-time performance of the link (such as packet loss rate, latency, and bandwidth fluctuation), resulting in either core businesses being affected by link congestion or interruption, or public network access being affected by unreasonable allocation of link resources, making it difficult to balance the transmission needs of the two types of businesses. In view of this, we propose a 5G+SD-WAN-based dual-domain intelligent networking method and device for chain stores. SUMMARY
[0004] The purpose of the present application is to provide a 5G+SD-WAN-based dual-domain intelligent networking method and device for chain stores to solve the problems of lack of hardware uniqueness correlation and state verification in gateway access authentication, significant security risks, and fixed dual-domain transmission link strategy that cannot match the differentiated needs of the two types of businesses.
[0005] To achieve the above technical problems, one of the purposes of the present application is to provide a 5G+SD-WAN-based dual-domain intelligent networking method for chain stores, which comprises the following steps: S100, dual-domain security substrate construction: based on 5G security access protocol and SD-WAN virtualization technology, the business intranet domain and the public network access domain of the chain store are divided, the business intranet domain serves the communication between the store and the headquarters core system, and the public network access domain serves the Internet access of the store terminal; the encryption algorithm and access control rules of the business intranet domain and the public network access domain are initialized; S200, intelligent network access of store gateway: the 5G intelligent gateway deployed in the store completes network access through a multi-level identity authentication system, submits the unique identity information generated by the hardware to the cloud management platform for basic verification; after passing the dynamic scene verification and challenge-response authentication, the basic configuration parameters of the business intranet domain and the public network access domain are automatically obtained, and the whole-process authentication log is synchronized to the security audit node; S300, dynamic construction of dual-domain transmission channel: based on SD-WAN tunnel encapsulation technology, a dynamic optimization model combining 5G link characteristics and SD-WAN tunnel performance is introduced, a 5G main link encryption transmission channel is established for the business intranet domain, and a 5G and 4G adaptive link transmission channel is established for the public network access domain; the classification identification rules of the business intranet domain and the public network access domain traffic are configured; S400, dual-domain traffic intelligent scheduling and isolation: through the SD-WAN intelligent scheduling engine, the store terminal data is distributed to the corresponding domain transmission channel according to the traffic classification identification; the physical link isolation of dual-domain data is realized by using the hardware-level isolation mechanism; S500, dynamic optimization of network state: the cloud management platform collects the link performance data of the transmission channel of the business intranet domain and the public network access domain in real time; when the link performance is detected to be abnormal, the SD-WAN controller is triggered to perform path reselection and parameter adjustment, and adaptive optimization of the transmission channel is completed.
[0006] As a further improvement of the technical solution, in the S100, the division of the business intranet domain and the public network access domain of the chain store, and the initialization of the encryption algorithm and the access control rules of the business intranet domain and the public network access domain, comprises the following steps: S100.1, dual-domain division: based on the 5G access layer security protocol defined by 3GPP to establish a bottom-layer security connection; through the SD-WAN controller, a virtual network identifier VNI=1001 is allocated to the business intranet domain, and a virtual network identifier VNI=2001 is allocated to the public network access domain, and the logical isolation of the business intranet domain and the public network access domain is realized based on the two VNI respectively; S100.2, business intranet domain encryption algorithm initialization: using the SM4 symmetric encryption algorithm, the key length is set to 128 bits; the cloud management platform encrypts the key by the SM2 asymmetric encryption algorithm and issues it to the chain store gateway, and the gateway stores the key in the secure storage area of the built-in hardware encryption chip; S100.3, public network access domain encryption algorithm initialization: using the AES-256 symmetric encryption algorithm, the key is generated by the chain store gateway based on the built-in random number generator, and the key is automatically replaced every 24 hours; S100.4, business intranet domain access control rule initialization: based on network five-tuple (source IP address, destination IP address, source port, destination port, transmission protocol) setting; only allow store local IP network segment to access headquarters core system IP network segment, and only open the preset business port; S100.5, public network access domain access control rule initialization: based on network five-tuple setting; prohibit the traffic of public network access domain to access the headquarters core system IP network segment; only allow access to the IP address corresponding to the preset Internet domain name whitelist, and limit the maximum bandwidth occupation value of single terminal in public network access domain to 100Mbps.
[0007] As a further improvement of the technical solution, in the S200, the generation process of the unique identity information generated by the hardware includes the following steps: S210.1, information extraction: the 5G intelligent gateway extracts the device serial number SN and the 5G module international mobile equipment identity IMEI through the built-in SM4 encryption chip, and collects the output characteristic value of the SM4 encryption chip physical unclonable function PUF; S210.2, hash fusion root key generation: the encryption chip performs hash fusion operation on the device serial number SN, 5G module IMEI code and PUF characteristic value to generate a unique hardware root key; S210.3, key secure storage and access control: the hardware root key is stored in the non-rewritable secure storage area of the chip after being processed by the internal fuse mechanism of the chip, and only allowed to be called through the internal interface of the chip, and external instruction reading is prohibited.
[0008] As a further improvement of the technical solution, in the S200, the specific process of dynamic scene verification includes the following steps: S220.1, position information collection: the 5G intelligent gateway collects real-time longitude and latitude data through the built-in GPS module, and uploads it to the cloud management platform through the encrypted channel; S220.2, position deviation verification: the cloud management platform calculates the difference between the received longitude and latitude data and the pre-stored store preset position longitude and latitude, and when the absolute value of the deviation is within the preset threshold range, the position verification passes; S220.3, device running state data collection: the 5G intelligent gateway collects the running state data of itself in real time, including CPU temperature, memory occupancy rate and SHA256 hash value of the gateway operating system image; S220.4, health state benchmark verification: the cloud management platform verifies that the CPU temperature, memory occupancy rate meet the preset safety baseline, and the gateway operating system image hash value is consistent with the pre-stored benchmark value, and the health state verification passes; S220.5, dynamic scene verification result determination: after the position verification and the health state verification pass, the dynamic scene verification is completed.
[0009] As a further improvement of the technical solution, in the S200, the process of challenge-response authentication and configuration parameter acquisition, log synchronization includes the following steps: S230.1, challenge code generation and encryption delivery: the cloud management platform generates a binary challenge code of a preset length through an encrypted random number generator , and sends it to the 5G intelligent gateway through the TLS encryption channel; S230.2, hardware-level response value calculation: the 5G intelligent gateway calls the built-in SM4 encryption chip to read the hardware root key in the secure storage area , and processes the " " through the chip internal operation unit to generate the response value and feedback to the cloud management platform through the encryption channel; S230.3, response value consistency verification: the cloud management platform calls the local stored hardware root key copy to perform the same SM4 encryption operation as the 5G intelligent gateway, and if the local calculation result is consistent with the received response value , the challenge-response authentication passes; S230.4, double-domain networking parameter pushing: after the authentication passes, the cloud management platform pushes the networking basic configuration parameters of the business intranet domain and the public access domain to the 5G intelligent gateway, including the VNI identifier of the double domain, the tunnel encapsulation format, the encryption algorithm key parameter and the traffic scheduling priority; S230.5, full-process log encryption synchronization: after the 5G intelligent gateway completes the local writing of the configuration parameters, it packages the basic verification records, the dynamic scene verification results and the key data of the challenge-response authentication process, and synchronizes them to the security audit node through the security audit special encryption channel.
[0010] As a further improvement of the technical solution, in the S300, the construction and application process of the dynamic optimization model includes the following steps: S310.1, feature parameter mapping: the 5G intelligent gateway maps the feature parameters of the 5G link and the 4G link into influence factors respectively, including the packet loss rate influence factor , time delay influence factor , bandwidth influence factor ; S310.2, comprehensive score calculation: based on the preset weight coefficient , meet and , the link comprehensive score is calculated by a dynamic optimization model ; S310.3, link adaptation selection: set score threshold for public network access domain , when the 5G link comprehensive score , the 5G link is preferentially selected; when , automatically switch to the 4G link; the internal network domain of the business is fixed as the comprehensive score of the 5G link as the main link validity judgment basis.
[0011] As a further improvement of the technical solution, in the S300, the configuration process of the classification identification rule of the traffic of the business internal network domain and the public network access domain includes the following steps: S320.1, marking mechanism determination: adopt "VLANID+DSCP" double-layer marking mechanism, VLANID is used to distinguish the business internal network domain and the public network access domain, and DSCP is used to mark the priority of different service traffic in the same domain; S320.2, business internal network domain marking configuration: allocate exclusive VLANID for the traffic of the business internal network domain, mark the corresponding DSCP priority according to the service importance of different service traffic in the domain, and the marking rule is bound with the headquarters core system IP network segment; S320.3, public network access domain marking configuration: allocate exclusive VLANID for the traffic of the public network access domain, mark the corresponding DSCP priority according to the service importance of different service traffic in the domain, and the marking rule is bound with the preset Internet IP network segment; S320.4, marking execution: the 5G intelligent gateway realizes real-time analysis on the inbound data packet through the built-in hardware forwarding unit, matches the corresponding marking rule according to the source and destination IP network segment and application type of the data packet, and completes the automatic marking at the hardware level.
[0012] As a further improvement of the technical solution, in the S400, the specific process of dual-domain traffic intelligent scheduling and isolation includes the following steps: S410.1, traffic identification matching: the SD-WAN intelligent scheduling engine realizes real-time analysis on the received store terminal data, extracts the VLANID and DSCP marking in the data packet, and matches the business internal network domain or the public network access domain to which the data packet belongs; S410.2, Intra-domain routing: For traffic matching the intranet domain, the scheduling engine routes the traffic to the 5G main link encryption transmission channel; for traffic matching the public network access domain, it is routed to the 5G and 4G adaptive link transmission channel, and the transmission queue in the channel is allocated according to the DSCP priority; S410.3, Hardware-level physical isolation: The 5G intelligent gateway separates the physical transmission links of the intranet domain and the public network access domain through a built-in dedicated isolation chip, wherein the intranet domain traffic is forwarded through the first group of independent MAC interfaces and corresponding physical ports of the main chip, and the public network access domain traffic is forwarded through the second group of independent MAC interfaces and corresponding physical ports of the main chip. The signal paths of the two groups of links have no cross-connection at the hardware level; S410.4, Isolation state verification: The 5G intelligent gateway periodically checks the signal isolation degree of the two groups of physical links to ensure that there is no leakage or mixed flow of data packets of the intranet domain and the public network access domain in the transmission process. The verification result is synchronized to the cloud management platform.
[0013] As a further improvement of the technical solution, in the S500, the specific process of network state dynamic optimization includes the following steps: S510.1, Link performance data collection: The 5G intelligent gateway collects the link performance data of the transmission channels of the intranet domain and the public network access domain in real time, including real-time delay, packet loss rate, and bandwidth occupancy rate. After collection is completed, it is uploaded to the cloud management platform through an encrypted channel. The collection period is a preset fixed time length; S510.2, Performance anomaly determination: The cloud management platform continuously analyzes the received link performance data. When any of the following conditions occurs in the dual-domain link, it is determined to be a performance anomaly: the packet loss rate or the bandwidth occupancy rate reaches or exceeds the corresponding preset threshold for multiple collection periods in a row, or the real-time delay reaches or exceeds the preset delay threshold; S510.3, Adaptive optimization trigger: After performance anomaly determination, the cloud management platform sends an optimization instruction to the SD-WAN controller to trigger adaptive optimization of the transmission channel; S510.4, Path reselection and parameter adjustment: The SD-WAN controller reevaluates the available links based on the dynamic optimization model to complete transmission path reselection; at the same time, dynamically adjusts the tunnel encapsulation parameters to ensure that the new path adapts to the current link characteristics; S510.5, Optimization result feedback: After optimization is completed, the SD-WAN controller synchronizes the new path information and parameter adjustment results to the cloud management platform, and the cloud management platform updates the network state record and pushes it to the 5G intelligent gateway. The second object of the present application is to provide a 5G+SD-WAN-based dual-domain intelligent networking device for chain stores, which is loaded with a 5G+SD-WAN-based dual-domain intelligent networking system for chain stores.
[0014] Compared with the prior art, the present application has the following advantages: 1. The present application extracts the equipment serial number, 5G module international mobile equipment identity, and the output characteristic value of the physical unclonable function of the SM4 encryption chip through the 5G intelligent gateway, generates a unique hardware root key through hash fusion and stores it in a non-rewritable secure area; at the same time, combined with the GPS position latitude and longitude deviation check, the device CPU temperature, memory occupancy rate, and operating system image hash value health state check, and through the challenge-response authentication based on SM4 encryption between the cloud management platform and the gateway, a multi-level network access verification mechanism is constructed, which effectively intercepts fake identity devices and abnormal state devices access, from the network access source to guarantee the security of data interaction between chain stores and headquarters core systems (such as cash register data, inventory information synchronization system), and adapt to the gateway identity precise control needs of chain store scattered deployment; 2. The present application combines the dual-domain business needs of chain stores, such as "business intranet domain service headquarters core communication, public network access domain service Internet access", and introduces a dynamic optimization model based on SD-WAN tunneling technology: converts the packet loss rate, delay, bandwidth, etc. of 5G and 4G links into influence factors, calculates the comprehensive score of the link through the preset weight coefficient, establishes a 5G main link encryption transmission channel for the business intranet domain (allocates a dedicated virtual network identifier), and establishes a 5G and 4G adaptive switching link transmission channel for the public network access domain (allocates a dedicated virtual network identifier), which not only guarantees the dedicated stable link for chain stores and headquarters core business data transmission, but also realizes the flexible switching of the link when the store terminal accesses the Internet, balances the needs of chain store dual-domain business in data transmission stability and Internet access flexibility, and adapts to the dual-domain network usage scenarios in chain store daily operation. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 The figure is a schematic diagram of the chain store dual-domain intelligent networking method of the present application. DETAILED DESCRIPTION
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0017] like Figure 1 As shown, this embodiment provides a dual-domain intelligent networking method for chain stores based on 5G+SD-WAN, including the following steps: S100, Dual-Domain Security Infrastructure Construction: Based on 5G secure access protocol and SD-WAN virtualization technology, the system divides the chain stores into "business intranet domain" and "public network access domain". The business intranet domain serves the communication between the store and the headquarters core system, while the public network access domain serves the store terminal's Internet access; the encryption algorithm and access control rules for the business intranet domain and the public network access domain are initialized. Understandably, after the chain stores complete the deployment of 5G smart gateway hardware, the first step is to start the dual-domain security foundation construction process. The core is to realize the physical isolation of the "business intranet domain" and the "public network access domain" based on the 5G security access protocol and SD-WAN virtualization technology, and at the same time complete the initialization of dual-domain encryption protection and access control, laying a security foundation for subsequent networking.
[0018] In this step, S100 involves dividing the chain store business intranet domain and public network access domain, and initializing the encryption algorithms and access control rules for the business intranet domain and public network access domain, including the following steps: S100.1 Dual-domain partitioning: Establish a low-level secure connection based on the 5G access layer security protocol defined by 3GPP; allocate a virtual network identifier (VNI) of 1001 to the business intranet domain and a virtual network identifier (VNI) of 2001 to the public network access domain through the SD-WAN controller, and realize logical isolation between the business intranet domain and the public network access domain based on the two VNIs respectively. Specifically, based on the 5G access layer security protocol defined by the 3GPP TS33.501 standard (including user identity privacy protection, data transmission encryption, and integrity protection mechanisms), the 5G smart gateway establishes a low-level secure connection with the operator's 5G core network to ensure the security of the link for stores to access the 5G network; at the same time, the store gateway establishes a control plane connection with the SD-WAN controller deployed at headquarters through an IPsec tunnel to receive dual-domain configuration commands.
[0019] Specifically, a centralized controller based on an SD-WAN virtualization architecture is adopted, the controller assigns a fixed virtual network identifier VNI=1001 to the "intra-business network domain" of the store and a fixed virtual network identifier VNI=2001 to the "public network access domain" according to the unique identifier (such as the store number) submitted by the store; the controller binds the VNI to the physical port of the store gateway (such as binding the gigabit electrical port 1 of the gateway to the intra-business network domain and binding the gigabit electrical port 2 of the gateway to the public network access domain) and configures VNI routing rules in the global routing table of the SD-WAN to ensure that the same domain VNI of different stores will not cause routing conflicts, and finally realizes the logical isolation of the VNI to prevent the mixing of dual-domain data during transmission.
[0020] S100.2, Intra-business network domain encryption algorithm initialization: the SM4 symmetric encryption algorithm is adopted, and the key length is set to 128 bits; the key is encrypted by the cloud management platform through the SM2 asymmetric encryption algorithm and then delivered to the chain store gateway, and the gateway stores the key in the secure storage area of the built-in hardware encryption chip; Specifically, the cloud management platform pre-generates an SM2 asymmetric key pair (public key PK and private key SK) that meets the national standard GM / T0002, the public key PK is preloaded into all 5G intelligent gateways of chain stores, and the private key SK is stored in the hardware security module (HSM) of the cloud management platform; the cloud management platform generates a 128-bit SM4 symmetric key K1 (intra-business network domain data encryption key) through a random number generator, encrypts K1 using the private key SK to generate an encrypted key ciphertext K1-Enc, and delivers K1-Enc to the store gateway through an encrypted control channel (based on the TLS1.3 protocol).
[0021] Specifically, after receiving K1-Enc, the store gateway calls the built-in hardware encryption chip that meets the national standard GM / T0028, decrypts K1-Enc using the preloaded SM2 public key PK to obtain the original SM4 key K1, and stores K1 in the non-rewritable secure storage area inside the hardware encryption chip (the storage area only supports reading by the encryption operation unit inside the chip, and external bus and debugging interface access is prohibited), and at the same time, destroys the temporary key data generated during the decryption process through the chip's internal fuse mechanism to prevent key leakage.
[0022] S100.3, Public network access domain encryption algorithm initialization: the AES-256 symmetric encryption algorithm is adopted, and the key is generated by the chain store gateway based on the built-in random number generator and automatically rotated every 24 hours. Specifically, the 5G intelligent gateway is built-in with a true random number generator conforming to the NIST SP800-140 standard. When the gateway is powered on and initialized, the random number generator automatically generates a 256-bit AES symmetric key K2 (public network access domain data encryption key). The generation process is completed entirely within the hardware encryption chip and does not pass through the gateway's main CPU memory, avoiding the key from being stolen by memory grabbing tools.
[0023] Specifically, the gateway is built-in with a timer, which is set to 24 hours as the key rotation period. At midnight every day, the timer triggers, and the gateway's hardware encryption chip generates a new 256-bit AES key K2'. At the same time, through the chip's internal key erasure instruction, all traces of the old key K2 in the secure storage area are completely removed. After the new key K2' is generated, it is automatically synchronized to the gateway's traffic encryption module for subsequent data encryption transmission of the public network access domain, without the need for manual intervention.
[0024] S100.4, Business Intranet Domain Access Control Rule Initialization: Based on network five-tuple (source IP address, destination IP address, source port, destination port, transmission protocol) setting; only allow local IP network segment of stores to access headquarters core system IP network segment, and only open preset business ports; Specifically, based on network five-tuple (source IP address, destination IP address, source port, destination port, transmission protocol), the cloud management platform configures access control rules for store gateways, for example: Source IP address range: local IP network segment of stores, uniformly planned as 192.168.X.0 / 24 (X is the store number, such as 01 representing the first store, i.e., 192.168.01.0 / 24); Destination IP address range: headquarters core system IP network segment, fixed as 10.0.0.0 / 16 (including core business servers such as POS system, inventory system, ERP system, etc.); Transmission protocol: only allow TCP protocol (core business data transmission uses TCP protocol to ensure reliability); Destination port: only open preset business ports, among which the POS data synchronization port is TCP8080, the inventory information upload port is TCP8081, and the ERP system access port is TCP8082; Source port: no limit (store terminals use random source ports when initiating business requests).
[0025] Specifically, the cloud management platform encapsulates the above five-tuple rules into an access control list (ACL) and issues it to the store gateway through an encrypted control channel. The gateway loads the ACL rules into the built-in hardware packet filtering module, which executes rule matching at the hardware level, ensuring that only traffic that meets the rules can enter the business intranet domain, and traffic that does not meet the rules is discarded directly.
[0026] S100.5, Public network access domain access control rule initialization: based on network five-tuple settings; prohibit public network access domain traffic from accessing headquarters core system IP network segment; only allow access to IP addresses corresponding to the preset Internet domain name whitelist, and limit the maximum bandwidth occupancy value of a single terminal in the public network access domain to 100 Mbps.
[0027] Specifically, also based on the network five-tuple described above, the cloud management platform configures the access control rules of the public network access domain for the store gateway: Prohibition rule: all traffic with a destination IP address of the headquarters core system IP network segment (10.0.0.0 / 16), regardless of source IP, port, or protocol, is directly discarded; Allow rule: the destination IP address is the IP address corresponding to the preset Internet domain name whitelist, which includes domain names required for store office work (such as enterprise OA system domain names, supply chain query domain names), and public service domain names required for customer temporary Wi-Fi (such as payment platform domain names, map service domain names); the cloud management platform synchronizes the IP addresses corresponding to the domain names in the whitelist to the store gateway by periodically resolving the domain names in the whitelist, ensuring timely updates of the IP addresses; in addition, when the synchronization of the preset Internet domain name whitelist fails, a fault tolerance mechanism is activated: first, retry 3 times (with an interval of 10 seconds each time), and if the retry fails, switch to a backup resolution server (such as 114.114.114.114, 8.8.8.8) to ensure uninterrupted domain name resolution service.
[0028] Transmission protocol: allow TCP and UDP protocols (to meet the diversification needs of Internet access, such as TCP for web browsing and UDP for video caching).
[0029] Specifically, the store gateway has a built-in traffic control module, and the cloud management platform issues a single-terminal bandwidth limit parameter to the traffic control module: the maximum bandwidth occupancy value of a single terminal in the public network access domain is 100 Mbps (downlink + uplink); the traffic control module calculates the real-time bandwidth occupancy based on the MAC address of the terminal, and when the bandwidth occupancy of a certain terminal exceeds 100 Mbps for 5 seconds in a row, the traffic control module automatically triggers the flow limiting mechanism to limit the downlink bandwidth of the terminal to 80 Mbps and the uplink bandwidth to 20 Mbps (total bandwidth does not exceed 100 Mbps), and when the terminal bandwidth occupancy falls below 90 Mbps, the normal bandwidth allocation is restored, preventing a single terminal from excessively occupying bandwidth and affecting the use of other terminals.
[0030] Further, the ACL rules and bandwidth limit parameters of the public network access domain are issued to the hardware packet filtering module and the traffic control module of the store gateway through an encrypted control channel, and the rules take effect immediately after being issued; the gateway periodically (every 1 hour) compares the currently effective rules with the latest rules from the cloud management platform, and if there is a difference, it automatically synchronizes and updates to ensure rule consistency.
[0031] S200, store gateway intelligent network access: the 5G intelligent gateway deployed in the store completes network access through a multi-level identity authentication system, submits the unique identity information generated by the hardware to the cloud management platform to complete the basic verification; after passing the dynamic scene verification and challenge-response authentication, it automatically obtains the basic configuration parameters of the business intranet domain and public network access domain networking, and synchronizes the whole process log to the security audit node; It can be understood that after the store completes the hardware deployment of the 5G intelligent gateway (such as fixed installation in the store weak electric box, access to stable power supply and 5G signal receiving antenna), the 5G intelligent gateway starts the initialization process for the first time, and automatically triggers the network access operation. This network access process is composed of a multi-level identity authentication system of "hardware unique identity verification-dynamic scene verification-challenge-response authentication", which strictly verifies the legality and safety of the running environment of the 5G intelligent gateway accessing the network, and finally completes the configuration of the networking parameters of the business intranet domain and the public network access domain, and synchronizes the whole process log to the security audit node, ensuring the safety and stability of the subsequent dual-domain networking.
[0032] In this step, in the S200, the generation process of the unique identity information generated by the hardware includes the following steps: The unique identity information generated by the hardware is the core identity certificate of the 5G intelligent gateway network access, which is generated based on the inherent tamper-proof characteristics of the 5G intelligent gateway hardware, ensuring that the identity information of each 5G intelligent gateway is unique, unforgeable and non-reproducible. The generation process of this identity information is automatically executed by the built-in SM4 encryption chip of the 5G intelligent gateway when it is powered on for the first time, without human intervention.
[0033] S210.1, information extraction: the 5G intelligent gateway extracts the device serial number SN and the 5G module international mobile equipment identity IMEI through the built-in SM4 encryption chip, and collects the output characteristic value of the physical unclonable function PUF of the SM4 encryption chip; Specifically, the device serial number SN of the 5G intelligent gateway is a 16-bit unique identifier composed of letters and numbers, which has been pre-programmed in the BIOS storage area of the main chip of the 5G intelligent gateway before it is shipped. The built-in SM4 encryption chip of the 5G intelligent gateway sends a read instruction conforming to the I2C protocol to the BIOS storage area through the internal I2C standard communication bus of the main chip, which carries the storage address identifier of the device serial number SN, to accurately obtain the original data of the device serial number SN; during the whole reading process, the 5G intelligent gateway automatically closes the external debugging interface (such as JTAG interface) to prevent the device serial number SN from being illegally intercepted or tampered with during the reading transmission process.
[0034] Specifically, the 5G communication module (such as the high-pass SDX55 model 5G communication module) built in the 5G intelligent gateway supports the AT instruction set communication protocol, the SM4 encryption chip sends the "AT+GSN" instruction (the instruction is a standard instruction for obtaining the IMEI of the 5G communication module) to the 5G communication module through the UART serial communication link; the 5G communication module returns the 15-digit IMEI after receiving the instruction, and the SM4 encryption chip performs format checking (verifies whether it is 15 pure digits) on the returned IMEI, confirms that the format is correct, extracts the valid IMEI information and temporarily stores it.
[0035] Specifically, the SM4 encryption chip physical unclonable function PUF output characteristic value collection: the SM4 encryption chip integrated with the physical unclonable function PUF circuit built in the 5G intelligent gateway automatically generates a 64-byte unique output characteristic value when the 5G intelligent gateway is powered on for the first time due to the random physical differences such as transistor threshold voltage and wire resistance in the chip manufacturing process; the SM4 encryption chip performs cyclic redundancy check CRC32 on the 64-byte output characteristic value, and after confirming that the characteristic value has no transmission or generation error, it is stored in the temporary buffer area of the SM4 encryption chip, providing basic data for subsequent hash fusion operation.
[0036] S210.2, Hash fusion generates root key: the encryption chip performs hash fusion operation on the device serial number SN, 5G module IMEI code and PUF characteristic value to generate a unique hardware root key; Specifically, the SM4 encryption chip retrieves the extracted device serial number, 5G module international mobile equipment identity and physical unclonable function output characteristic value from the temporary buffer area, and splices the data in the fixed order of "device serial number -> 5G module international mobile equipment identity -> physical unclonable function output characteristic value"; wherein the device serial number is 16 bytes, the 5G module international mobile equipment identity is 15 bytes, and 1 byte 0x00 data needs to be added at the end of the 5G module international mobile equipment identity to fill it to 16 bytes, and the physical unclonable function output characteristic value is 64 bytes, finally forming a total length of 16+16+64=96 bytes of original data string.
[0037] Specifically, the SM4 encryption chip calls the built-in hash operation unit, adopts the SHA256 hash algorithm conforming to the NIST FIPS180-4 standard, performs hash operation on the original data string of 96 bytes, and generates a 32-byte (256-bit) hash value; the SM4 encryption chip converts the 32-byte hash value into a binary data stream, and the binary data stream is the unique hardware root key K of the 5G intelligent gateway, which is used in the subsequent challenge-response authentication link.
[0038] S210.3, key secure storage and access control: after the hardware root key is processed by the internal fuse mechanism of the encryption chip, it is stored in the non-rewritable secure storage area of the chip, and only the internal interface of the chip is allowed to call, and external instruction reading is prohibited.
[0039] Specifically, after the hardware root key is generated, the SM4 encryption chip automatically starts the internal fuse program, applies a preset high voltage to the internal debugging interface fuse (such as the JTAG interface fuse) to permanently burn the debugging interface fuse, and completely closes the debugging access permission of the external device (such as a debugging computer) to the internal storage area of the SM4 encryption chip; at the same time, the SM4 encryption chip automatically executes the temporary cache area data clearing instruction, completely deletes the device serial number, 5G module international mobile equipment identity and physical unclonable function output characteristic value original data stored in the temporary cache area, and only retains the hardware root key.
[0040] Specifically, the SM4 encryption chip writes the hardware root key into its internal one-time programmable secure storage area, which has the characteristics of "single write, permanent read". After writing the hardware root key is completed, the SM4 encryption chip automatically locks the write permission of the storage area, and any instruction (including the instruction of the unauthorized module inside the SM4 encryption chip) cannot modify or delete the hardware root key.
[0041] Specifically, the SM4 encryption chip constructs an access permission control mechanism through a hardware logic circuit, and only allows the internal SM4 encryption operation unit to call the hardware root key through a dedicated internal bus for encryption operation in the challenge-response authentication link; for the hardware root key reading instruction sent by the 5G intelligent gateway main chip and external communication interface (such as Ethernet port and USB port), the hardware firewall module of the SM4 encryption chip will automatically intercept and return a "permission denied" response signal, ensuring that the hardware root key is not leaked or illegally called by the outside.
[0042] In this step, in the S200, the specific process of dynamic scene verification includes the following steps: The dynamic scene verification is used to verify the consistency of the actual deployment position of the 5G intelligent gateway and the preset position of the chain stores, and the health of the current running state of the 5G intelligent gateway, so as to avoid that the illegal equipment accesses the networking system in an unauthorized position, or the 5G intelligent gateway in an abnormal running state (such as the operating system is tampered, the hardware is overloaded) accesses the network. The verification process is dominated by the cloud management platform as the core, and the 5G intelligent gateway completes data collection and feedback.
[0043] S220.1, position information collection: the 5G intelligent gateway collects the current latitude and longitude data in real time through the built-in GPS module, and uploads the data to the cloud management platform through an encrypted channel; Specifically, after the 5G intelligent gateway completes the generation of the hardware unique identity information, it automatically sends a start instruction to the built-in GPS module. After the GPS module is started, it enters a satellite search mode, continuously searches for at least four navigation satellites to obtain stable positioning signals. In a normal case, the stable positioning signal acquisition time is ≤60 seconds. If the 5G intelligent gateway is deployed in an indoor scene (such as the basement of a shopping mall), the satellite signal received by the GPS module is weak and cannot complete positioning. At this time, the GPS module automatically switches to an assisted global satellite positioning system (AGPS) mode, accesses the 5G network through the 5G communication module of the 5G intelligent gateway, and obtains base station assisted positioning data (such as the position and signal strength of the surrounding 5G base station) from the AGPS assisted positioning server provided by the operator, and improves the positioning accuracy by combining the weak satellite signals received by itself, to ensure the effectiveness of the position information collection.
[0044] Specifically, after the GPS module obtains the latitude and longitude data based on the WGS84 coordinate system, it transmits the latitude and longitude data to the national SM4 encryption chip. The national SM4 encryption chip uses the business intranet domain temporary key initialized in step S100 to perform SM4 symmetric encryption operation on the latitude and longitude data, to generate an encrypted data string. The 5G intelligent gateway uploads the encrypted data string to the cloud management platform through an encrypted control channel based on the TLS1.3 protocol, and at the same time, attaches the serial number (SN) of the 5G intelligent gateway to the uploaded data, so as to facilitate the association and identification of the cloud management platform.
[0045] S220.2, position deviation verification: the cloud management platform calculates the difference between the received latitude and longitude data and the pre-stored store preset position latitude and longitude. When the absolute value of the deviation is within the preset threshold range, the position verification is passed. Specifically, after receiving the encrypted data string and the device serial number SN uploaded by the 5G intelligent gateway, the cloud management platform calls the built-in SM4 decryption module, uses the same business intranet domain temporary key as the 5G intelligent gateway to decrypt the encrypted data string, and obtains the latitude and longitude plaintext data; at the same time, the cloud management platform retrieves the preset position latitude and longitude data of the chain store corresponding to the device serial number SN from the chain store information database according to the device serial number SN (the preset position latitude and longitude is the central coordinates of the registered address of the chain store business license).
[0046] Specifically, the cloud management platform calculates the deviation value (unit: meter) of the actual latitude and longitude of the 5G intelligent gateway and the preset latitude and longitude of the store by using the Euclidean distance formula, and the specific calculation formula is as follows: ; Among them, represents the deviation value of the actual latitude and longitude of the 5G intelligent gateway and the preset latitude and longitude of the store; represents the actual latitude; represents the preset latitude; represents the actual longitude; represents the preset longitude; represents the ratio of the equatorial circumference of the earth to 360° (π / 180), and represents that the distance of 1° latitude on the earth's surface is about 111319.9 meters; represents the radian cosine value of the preset latitude, which is used to convert the longitude difference into the corresponding ground distance (the ground distance corresponding to the longitude difference changes with the latitude).
[0047] Specifically, the cloud management platform sets the position deviation preset threshold according to the deployment scene of the chain store: the position deviation preset threshold of the street independent store is ±50 meters (considering the possible device installation fine tuning around the store), and the position deviation preset threshold of the store in the mall is ±20 meters (affected by the shielding of the mall building structure, the GPS positioning accuracy is slightly reduced); when the calculated deviation value is ≤ the preset threshold of the corresponding scene, it is determined that the position verification is passed; if the absolute value of the deviation value exceeds the preset threshold, the cloud management platform immediately sends a "position verification failed" instruction to the 5G intelligent gateway, terminates the network access process, and records the failure reason (such as "position deviation exceeds 50 meters") to the exception log.
[0048] S220.3, device running state data acquisition: the 5G intelligent gateway collects real-time running state data of itself, including CPU temperature, memory occupancy rate and SHA256 hash value of gateway operating system image; Specifically, when the position verification passes, the cloud management platform sends a "start device running state collection" instruction to the 5G intelligent gateway. After receiving the instruction, the 5G intelligent gateway starts the device running state data collection task, sets the collection period to 10 seconds, and continuously collects data for 3 times (to avoid misjudgment caused by abnormal single collection data due to transient interference).
[0049] Specifically, the 5G intelligent gateway real-time collects its own running state data, which specifically includes: CPU temperature collection: The 5G intelligent gateway has a built-in temperature sensor in the main chip (such as Mediatek MT7986 model main chip). The 5G intelligent gateway reads the register value corresponding to the internal temperature sensor of the main chip to obtain the real-time CPU temperature value (unit: ℃). After continuously collecting 3 times, the arithmetic mean of the 3 temperature values is calculated as the final CPU temperature data according to the following formula to eliminate the influence of transient temperature fluctuations: Memory usage rate collection: The operating system (such as OpenWRT operating system) supported by the 5G intelligent gateway supports command line data query. By executing the "free-m" command, the total memory capacity (unit: MB) and the used memory capacity (unit: MB) are obtained. The memory usage rate is calculated according to the following formula, and the arithmetic mean of the 3 times is taken as the final memory usage rate data: Gateway operating system image SHA256 hash value collection: The 5G intelligent gateway performs SHA256 hash operation on the complete image file (file suffix is.img) of the operating system stored in the flash memory (such as 16GB capacity eMMC flash memory). The operation process is completed in the memory of the 5G intelligent gateway. After the operation is completed, the memory data clearing instruction is executed to delete the temporarily stored operating system image data in the memory to avoid image data leakage. Finally, a 64-bit hexadecimal format SHA256 hash value is generated.
[0050] Specifically, the 5G intelligent gateway uploads the CPU temperature average value, memory usage rate average value, and gateway operating system image SHA256 hash value calculated once to the cloud management platform through an encrypted control channel based on the TLS1.3 protocol. The collection timestamp is attached to the uploaded data to facilitate the cloud management platform to trace the data validity.
[0051] S220.4, health status benchmark verification: when the CPU temperature and memory usage rate meet the preset safety baseline, and the gateway operating system image hash value is consistent with the pre-stored benchmark value, the health status verification passes. Specifically, after the cloud management platform receives the device running state data uploaded by the 5G intelligent gateway, the cloud management platform retrieves the preset health and safety baseline corresponding to the 5G intelligent gateway from the 5G intelligent gateway hardware specification database. The specific baseline parameters are as follows: CPU temperature safety range: (the range is set based on the industrial level working temperature standard of the main chip of the 5G intelligent gateway, to ensure that the CPU runs stably at a safe temperature); Memory occupancy safety threshold: ≤80% (the threshold is set to avoid high memory occupancy leading to 5G intelligent gateway operating system lag or crash); Gateway operating system image reference SHA256 hash value: Before the 5G intelligent gateway is shipped, the device manufacturer has uploaded the operating system image SHA256 hash value of the batch of 5G intelligent gateways to the cloud management platform, and the cloud management platform stores the association according to the device serial number SN. At this time, the reference SHA256 hash value matching the current 5G intelligent gateway device serial number SN is retrieved.
[0052] Specifically, the verification of CPU temperature, memory occupancy, and gateway operating system image SHA256 hash value is as follows: CPU temperature verification: if the average CPU temperature uploaded by the 5G intelligent gateway is within the range of 0-70°C, it is determined that the CPU temperature verification is passed; if it exceeds the range, it is determined to be "hardware temperature abnormal"; Memory occupancy verification: if the average memory occupancy uploaded by the 5G intelligent gateway is ≤80%, it is determined that the memory occupancy verification is passed; if it exceeds the threshold, it is determined to be "memory overload"; Operating system integrity verification: if the gateway operating system image SHA256 hash value uploaded by the 5G intelligent gateway is completely consistent with the reference SHA256 hash value pre-stored in the cloud management platform, it is determined that the operating system integrity verification is passed; if it is not consistent, it is determined to be "operating system tampered"; In summary, when the above three verifications are passed, it is determined that the 5G intelligent gateway health status verification is passed; if any of the verifications fails, the cloud management platform sends a "health status verification failure" instruction to the 5G intelligent gateway, terminates the network access process, and records the failure type (such as "operating system tampered") to the exception log.
[0053] S220.5, dynamic scene verification result determination: after the position verification and health status verification are passed, the dynamic scene verification is completed.
[0054] Specifically, the cloud management platform aggregates the location verification result and the health status verification result: if both verifications pass, the cloud management platform generates a "dynamic scene verification pass" instruction, which includes a verification pass timestamp and a device serial number (SN), and sends it to the 5G intelligent gateway through an encrypted control channel based on the TLS1.3 protocol; if either the location verification or the health status verification fails, the cloud management platform records the verification failure reason (such as "memory overload" or "position deviation exceeds 20 meters") in the exception log and synchronizes it to the security audit node. After receiving the "dynamic scene verification failure" instruction, the 5G intelligent gateway automatically enters the "abnormal network access" state, and technical personnel need to troubleshoot the problem on site (such as checking the 5G intelligent gateway operating environment and reinstalling the operating system) before restarting the network access process.
[0055] In this step, in the S200, the challenge-response authentication and configuration parameter acquisition, log synchronization process includes the following steps: Challenge-response authentication is the final security verification link of the 5G intelligent gateway network access process. Through encrypted data interaction between the cloud management platform and the 5G intelligent gateway, the legality of the 5G intelligent gateway hardware root key is verified to ensure that the access to the networking system is an authorized 5G intelligent gateway. After authentication, the cloud management platform pushes the dual-domain networking basic configuration parameters to the 5G intelligent gateway, and the 5G intelligent gateway synchronizes the network access full-process log to the security audit node.
[0056] S230.1, challenge code generation and encryption delivery: the cloud management platform generates a binary challenge code of a preset length through an encrypted random number generator , which is sent to the 5G intelligent gateway through a TLS encrypted channel; Specifically, the cloud management platform calls an encrypted random number generator that meets the NISTSP800-90A standard to generate a 128-bit binary challenge code ; To facilitate data transmission and processing, the cloud management platform converts the 128-bit binary challenge code to a 32-bit hexadecimal string format.
[0057] Specifically, the cloud management platform sends the 32-bit hexadecimal format challenge code to the 5G intelligent gateway through an encrypted control channel based on the TLS1.3 protocol (consistent with the channel for uploading location information and device running state data in S220); To ensure that the challenge code is not tampered with during transmission, the cloud management platform appends a 4-byte cyclic redundancy check code to the data sent. After receiving the data, the 5G intelligent gateway needs to first verify the cyclic redundancy check code to confirm the data integrity before performing subsequent operations.
[0058] S230.2, hardware level response value calculation: 5G intelligent gateway calls built-in national secret SM4 encryption chip, reads hardware root key of security storage area , executes SM4 encryption algorithm on " by chip internal operation unit, generates response value , and feeds back to cloud management platform through encryption channel; Specifically, 5G intelligent gateway receives challenge code And verifies that the cyclic redundancy check CRC32 code passes, sends "hardware root key calling" instruction to the built-in national secret SM4 encryption chip; the national secret SM4 encryption chip receives the instruction, reads the hardware root key K32 byte binary stream from the one-time programmable OTP security storage area through the internal exclusive bus, and the reading process does not pass through the 5G intelligent gateway main memory, and the hardware root key Is directly transmitted to the SM4 encryption operation unit of the national secret SM4 encryption chip, avoiding the leakage of the hardware root key .
[0059] Specifically, the SM4 encryption operation unit of the national secret SM4 encryption chip first performs data matching processing on the challenge code And the hardware root key Challenge code It is 128-bit binary, that is, 16 bytes, so the first 16 bytes of the hardware root key Is performed with the challenge code Bitwise XOR operation, and the XOR result is recorded as ) 16 bytes; then, the SM4 encryption operation unit adopts the SM4 symmetric encryption algorithm conforming to the GM / T0002-2012 standard to perform encryption operation on the XOR result ) "Electronic Cipher Block Mode ECB", because the XOR result It has randomness, and does not need to add an initial vector IV, to generate a 16-byte binary format encryption result.
[0060] Specifically, the national secret SM4 encryption chip converts the 16-byte binary encryption result into a 32-bit hexadecimal string, which is recorded as the response value ; 5G intelligent gateway sends the response value And its own device serial number SN to the cloud management platform through the encryption control channel based on the TLS1.3 protocol, and records the generation timestamp of the response value , to facilitate the cloud management platform to check the timing consistency.
[0061] S230.3, response value consistency verification: the cloud management platform calls the local stored hardware root key copy to execute the same SM4 encryption operation as the 5G intelligent gateway, and if the local calculation result is inconsistent with the received response value consistent, then the challenge-response authentication is passed; Specifically, the cloud management platform receives the response value uploaded by the 5G intelligent gateway After the device serial number SN, the hardware root key corresponding to the device serial number SN is called from the hardware security module ; The hardware security module and the hardware security module storing the SM2 asymmetric private key in S100 step are the same device, and the hardware root key copy is the backup key synchronized to the hardware security module by the device manufacturer when the 5G intelligent gateway is manufactured, which is completely consistent with the hardware root key stored locally by the 5G intelligent gateway (32-byte binary stream).
[0062] Specifically, the encryption operation module of the cloud management platform performs operations according to the same logic as the 5G intelligent gateway: first, take the first 16 bytes of the hardware root key copy , and perform bitwise XOR operation with the challenge code C128-bit binary to get the XOR result ) 16 bytes; Then, using the SM4 symmetric encryption algorithm ECB mode conforming to the GM / T0002-2012 standard, the XOR result ) is executed to generate a local response value, denoted as ) 32-bit hexadecimal string; The cloud management platform compares the locally generated response value ) with the response value reported by the 5G intelligent gateway bit by bit, if they are completely consistent, it is determined that the challenge-response authentication is passed; if they are not consistent, it is determined that the "key does not match", and the process of entering the network is immediately terminated, and the abnormal information such as "response value and ) is inconsistent" is recorded to the security audit log.
[0063] S230.4, dual-domain networking parameter pushing: after the authentication is passed, the cloud management platform pushes the networking basic configuration parameters of the business intranet domain and the public access domain to the 5G intelligent gateway, including the VNI identifier of the dual-domain, the tunnel encapsulation format, the encryption algorithm key parameters and the traffic scheduling priority; Specifically, when the challenge-response authentication is passed, the cloud management platform associates the chain store number corresponding to the device serial number (SN) of the 5G intelligent gateway to retrieve the dual-domain networking basic configuration parameters corresponding to the chain store from the dual-domain networking configuration database. The specific parameter contents are as follows: Dual-domain VNI identifier: business intranet domain virtual network identifier VNI=1001, public access domain virtual network identifier VNI=2001 (consistent with the virtual network identifier VNI allocated in S100.1 step); Tunnel encapsulation format: VXLAN tunnel encapsulation technology conforming to the standard of RFC7348 is adopted, VXLAN tunnel port number is set as 4789, and a virtual network identifier VNI field is embedded in the VXLAN data frame header to identify the domain to which the data belongs; Encryption algorithm key parameters: the SM4 symmetric encryption key (i.e. the key generated in S100.2) adopted by the intranet domain, and the automatic rotation period (24 hours, consistent with the rotation period set in S100.3) of the AES-256 symmetric encryption key adopted by the public network access domain; Traffic scheduling priority: the dual-domain traffic is divided into three priority levels, priority level 1 (highest priority) corresponds to the interlocking store cash register data synchronization traffic, priority level 2 corresponds to the interlocking store inventory system and ERP system access traffic, and priority level 3 (lowest priority) corresponds to the interlocking store employee office query traffic and customer Wi-Fi access traffic.
[0064] Specifically, the cloud management platform arranges the above-mentioned dual-domain networking basic configuration parameters into a JSON format configuration file, performs encryption operation on the JSON format configuration file using the SM2 asymmetric public key pre-stored in the 5G intelligent gateway in S100.2, to generate an encrypted configuration file; the encrypted configuration file is pushed to the 5G intelligent gateway through an encrypted control channel based on the TLS1.3 protocol; after receiving the encrypted configuration file, the 5G intelligent gateway calls the built-in national encryption SM4 chip, and uses the SM2 asymmetric private key stored by itself to perform decryption on the encrypted configuration file, to obtain a JSON format plaintext configuration file; the 5G intelligent gateway writes the parameters in the plaintext configuration file into the flash memory (such as the partition 2 of the eMMC flash memory, which is a special configuration storage area), and after the parameter writing is completed, the 5G intelligent gateway sends a "dual-domain networking parameter configuration success" confirmation instruction to the cloud management platform, which contains a configuration completion timestamp.
[0065] S230.5, full-process log encryption synchronization: after completing the local writing of the configuration parameters, the 5G intelligent gateway packages the basic verification records, dynamic scene verification results, and key data of the challenge-response authentication process, and synchronizes them to the security audit node through a secure audit dedicated encryption channel.
[0066] Specifically, after completing the dual-domain networking parameter configuration, the 5G intelligent gateway automatically starts the network access full-process log collection task, and the collected log content includes: Basic verification records: hardware unique identity information generation timestamp, first 8 characters of device serial number, first 8 characters of 5G module international mobile equipment identity, and first 8 bytes of physical unclonable function output characteristic value; Dynamic scene verification results: location verification timestamp, location deviation value, average CPU temperature, average memory occupancy rate, and first 8 bits of gateway operating system image SHA256 hash value; Challenge-response authentication process: challenge code reception timestamp, response value generation timestamp, challenge-response authentication successful timestamp; Finally, the 5G smart gateway organizes the above logs into a TXT format log file according to the fixed format of "timestamp-log type-log content", and uses the public network access domain AES-256 symmetric encryption key initialized in step S100.3 to perform encryption operation on the TXT format log file to generate an encrypted log packet.
[0067] Specifically, the 5G smart gateway uploads encrypted log packets to the security audit node deployed at the chain store headquarters through a dedicated encrypted channel for security audit (this channel is built based on the IPsec protocol and has been pre-established with the security audit node before the 5G smart gateway leaves the factory). After receiving the encrypted log packet, the security audit node decrypts it using the same public network access domain AES-256 symmetric encryption key to obtain a TXT format log file. The security audit node performs integrity checks on the log files by verifying whether the timestamps in the logs are continuous (ensuring that the logs have not been deleted or tampered with). If the verification is successful, the log files are stored in the security audit database, and a unique audit log ID is generated for the log files. The security audit node sends a "network access process log synchronization successful" command to the 5G smart gateway. After receiving the command, the 5G smart gateway officially completes the smart network access process for the store gateway and enters the dual-domain smart networking ready state, which can then begin subsequent dual-domain data transmission and scheduling operations.
[0068] S300, Dynamic Construction of Dual-Domain Transmission Channels: Based on SD-WAN tunnel encapsulation technology, a dynamic optimization model integrating 5G link characteristics and SD-WAN tunnel performance is introduced to establish a 5G main link encrypted transmission channel for the business intranet domain and a 5G and 4G adaptive link transmission channel for the public network access domain; and to configure classification and identification rules for traffic in the business intranet domain and the public network access domain. After the 5G smart gateway completes the S200 step for intelligent network access, the system automatically initiates the dual-domain traffic intelligent scheduling and security audit process. This process is based on the centralized control and distributed forwarding architecture of SD-WAN. Through a three-level mechanism of "traffic classification and labeling - dynamic path scheduling - real-time security auditing", it achieves traffic isolation, intelligent scheduling, and end-to-end security control between the business intranet domain and the public network access domain. The core technical details are consistent with the dual-domain identifiers, encryption strategies, and device characteristics defined in the S100 and S200 steps.
[0069] In this step, the construction and application process of the dynamic optimization model in S300 includes the following steps: S310.1, Feature parameter mapping: the 5G intelligent gateway maps the feature parameters of the 5G link and the 4G link into influence factors respectively, including a packet loss rate influence factor , a delay influence factor , and a bandwidth influence factor ; Specifically, the 5G intelligent gateway first starts a link feature parameter collection function, and collects the basic performance parameters of the 5G link and the 4G link in real time: packet loss rate, delay, and current available bandwidth, and then converts these basic parameters into corresponding influence factors according to a preset mapping rule. Among them: The mapping logic of the packet loss rate influence factor is: when the packet loss rate is less than or equal to 1% , 1% < the packet loss rate ≤ 3% , and the packet loss rate > 3% ; The mapping logic of the delay influence factor is: when the delay is less than or equal to 50ms , 50ms < the delay ≤ 100ms , and the delay > 100ms ; The mapping logic of the bandwidth influence factor is: when the available bandwidth is greater than or equal to 200Mbps , 100Mbps ≤ the available bandwidth < 200Mbps , and the available bandwidth < 100Mbps ; The mapping process is automatically executed by the parameter operation unit built in the 5G intelligent gateway, without human intervention. The mapping results are stored in the link state cache area of the gateway in real time, and the update period is consistent with the parameter collection period (updated every 10 seconds).
[0070] S310.2, Comprehensive score calculation: based on a preset weight coefficient , satisfying and , the link comprehensive score is calculated through a dynamic optimization model ; Specifically, the cloud management platform pre-configures a fixed weight coefficient for the dynamic optimization model, wherein (packet loss rate influence factor weight), (delay influence factor weight), (bandwidth influence factor weight), satisfying and constraint conditions. The weight coefficient is set based on the business characteristics of the chain stores (the core business is more sensitive to packet loss rate and delay than bandwidth), and is synchronized to all 5G intelligent gateways through an encrypted control channel; Meanwhile, the scoring calculation unit of the 5G intelligent gateway retrieves the real-time packet loss rate influence factor from the link state cache area , the delay influence factor , and the bandwidth influence factor , performs comprehensive score calculation according to the formula , wherein is the link comprehensive score (value range 0~1.0), and after the calculation is completed, the 5G link comprehensive score and the 4G link comprehensive score are reported to the cloud management platform through a TLS1.3 encrypted channel together with the calculation timestamp for subsequent link selection.
[0071] S310.3, Link adaptive selection: set score threshold for public network access domain When the 5G link comprehensive score , the 5G link is preferentially selected; when , the 4G link is automatically switched to; and the comprehensive score of the 5G link is fixed as the main link effectiveness determination basis for the business intranet domain.
[0072] Specifically, the cloud management platform presets the link comprehensive score threshold for the public network access domain (the threshold is verified through historical transmission data of typical businesses such as e-commerce platform access, OA system interaction, and video monitoring backhaul of the public network access domain of the chain stores in the past 12 months, to ensure that the link can meet the business needs of the public network access domain when the score is greater than or equal to 0.6), and synchronizes it to the 5G intelligent gateway; the 5G intelligent gateway compares calculated locally with in real time: When , the link switching unit of the gateway automatically schedules the public network access domain traffic to the 5G link, at this time, the public network access domain transmission channel is constructed based on the 5G link, and the AES-256 encryption algorithm consistent with the public network access domain encryption strategy in S100.3 is adopted; When , the link switching unit immediately triggers the 4G link switching process, first detects the 4G link connectivity through the ICMP protocol, and after confirming the connectivity, seamlessly switches the public network access domain traffic to the 4G link, avoids data loss through the traffic caching mechanism during the switching process, and after the switching is completed, the gateway sends a "link switching notification" to the cloud management platform; For the business intranet domain, in order to ensure the stability of communication with the headquarters core system, the 5G link is fixed as the transmission channel, and the is taken as the main link effectiveness determination basis, and when When the threshold of the validity of the intranet domain is exceeded, the gateway automatically starts the 5G link fault repair process (such as restarting the 5G module and re-accessing the 5G core network), and synchronously triggers an alarm to the cloud management platform, to ensure that the transmission channel of the intranet domain is continuously available.
[0073] Further, in the 5G link fault repair process, the 5G module is restarted by AT+CFUN=1,1 (a standard AT instruction in the field of mobile communication), and the challenge-response authentication process of the first access to the network is reused when re-accessing (i.e., the cloud management platform issues a random challenge value, the 5G intelligent gateway returns a response by encrypting the challenge value using the SM2 algorithm of the national cryptography, and the 5G security connection is re-established after verification).
[0074] In this step, in the S300, the configuration process of the classification identification rules of the intranet domain and the public network access domain traffic includes the following steps: S320.1, the marking mechanism is determined: a "VLANID+DSCP" double-layer marking mechanism is adopted, VLANID is used to distinguish the intranet domain and the public network access domain, and DSCP is used to mark the priority of different service traffic in the same domain; Specifically, the system adopts a "VLANID+DSCP" double-layer marking mechanism, wherein VLANID is used to distinguish the intranet domain and the public network access domain (to realize domain-level traffic isolation), and DSCP is used to mark the priority of different service traffic in the same domain (to guarantee the priority of high-importance service transmission); the double-layer marking mechanism is implemented by the hardware forwarding unit of the 5G intelligent gateway, the marking process does not occupy the main CPU resources, the single-packet marking delay is controlled within microseconds, the influence on service transmission efficiency is avoided, and the marking rules are consistent with the double-domain division logic in S100 and the traffic scheduling priority rules in S230.4, to ensure the coherence of the technical solution.
[0075] S320.2, intranet domain marking configuration: the intranet domain traffic is allocated a special VLANID, and different service traffic in the domain is marked with corresponding DSCP priority according to service importance; the marking rules are bound with the IP network segment of the headquarters core system; Specifically, the cloud management platform allocates a special VLANID=10 to the intranet domain traffic (the VLANID is unique in the whole network and is associated with VNI=1001 of the intranet domain), and configures DSCP priority for different service traffic in the domain based on service importance: The cash register data synchronization service of chain stores (communicates with the headquarters cash register system) has the highest priority and is marked with DSCP "101110" (corresponding to the EF class in the DiffServ service level, to guarantee low-latency transmission); The inventory system access service (communicates with the headquarters inventory management system) has the second priority and is marked with DSCP "010110" (corresponding to the AF31 class). ERP system access business (communication with headquarters ERP system) priority third, DSCP marked as "010010" (corresponding to AF21 class); The above marking rules are stored in the rule library of the cloud management platform in combination with the headquarters core system IP network segment (consistent with the headquarters core system IP network segment in S100.4), and the binding relationship is recorded in the form of "IP network segment-service type-VLAN ID-DSCP" four-tuple, ensuring that the business traffic corresponding to each headquarters core system IP network segment can match a unique marking rule.
[0076] S320.3, public network access domain marking configuration: allocate a dedicated VLAN ID for public network access domain traffic, and mark the DSCP priority of different business traffic in the domain according to business importance, and the marking rule is bound with the preset Internet IP network segment; Specifically, the cloud management platform allocates a dedicated VLAN ID=20 for public network access domain traffic (the VLAN ID is associated and bound with the public network access domain VNI=2001, and does not overlap with the business intranet domain VLAN ID=10), and configures DSCP priority for different business traffic in the domain based on business importance: The chain store office OA system access business (accessing the IP corresponding to the preset office domain name) has the highest priority, and the DSCP is marked as "001110" (corresponding to AF11 class); The customer temporary Wi-Fi access business (accessing the Internet public service) has the second priority, and the DSCP is marked as "000110" (corresponding to CS1 class); The store advertisement push business (accessing the advertisement server) has the lowest priority, and the DSCP is marked as "000010" (corresponding to BE class); The above marking rules are bound with the preset Internet IP network segment (i.e. the IP address after the preset Internet domain name whitelist resolution in S100.5), and the binding relationship is also stored in the cloud management platform rule library in the form of "IP network segment-service type-VLAN ID-DSCP" four-tuple, and the rule library is updated once every 24 hours with the domain name resolution result, ensuring that the marking rule is still effective after the IP network segment changes.
[0077] S320.4, marking execution: the 5G intelligent gateway performs real-time analysis on the inbound data packet through the built-in hardware forwarding unit, matches the corresponding marking rule according to the source and destination IP network segment and application type of the data packet, and completes the hardware-level automatic marking.
[0078] Specifically, after the 5G intelligent gateway is powered on and runs, the built-in hardware forwarding unit automatically starts the data packet analysis function, and captures all inbound data packets (including terminal data packets accessed through the LAN port and terminal data packets accessed through Wi-Fi) in real time. The hardware forwarding unit first analyzes the source IP address and the destination IP address of the data packet, matches the "IP network segment-service type-VLAN ID-DSCP" four-tuple rule issued by the cloud management platform: if the destination IP address belongs to the headquarters core system IP network segment (10.0.0.0 / 16), it is determined as intranet domain traffic, and VLAN ID=10 and the corresponding service DSCP tag are automatically added; If the destination IP address belongs to the preset Internet IP network segment, it is determined as public network access domain traffic, and VLAN ID=20 and the corresponding service DSCP tag are automatically added. After the marking is completed, the hardware forwarding unit embeds the marking information in the Ethernet header (VLAN ID) and the IP header (DSCP) of the data packet, and then forwards the data packet to the corresponding transmission channel (intranet domain 5G channel or public network access domain adaptive channel). If the IP address of the data packet does not match any preset network segment, the hardware forwarding unit marks it as "unauthorized traffic" and intercepts it, and records the interception log to the local storage of the gateway and synchronizes it to the cloud management platform regularly.
[0079] S400, dual-domain traffic intelligent scheduling and isolation: through the SD-WAN intelligent scheduling engine, the store terminal data is distributed to the transmission channel of the corresponding domain according to the traffic classification identifier; a hardware-level isolation mechanism is used to realize physical link isolation of dual-domain data. After the 5G intelligent gateway completes the S300 dual-domain transmission channel dynamic construction, the system automatically starts the S400 dual-domain traffic intelligent scheduling and isolation process. This process takes the SD-WAN intelligent scheduling engine as the core, realizes accurate distribution based on the dual-domain traffic classification identifier configured in S300, and ensures strict isolation of dual-domain data at the physical link level through a hardware-level isolation mechanism.
[0080] In this step, in the S400, the specific process of dual-domain traffic intelligent scheduling and isolation includes the following steps: S410.1, traffic identification matching: the SD-WAN intelligent scheduling engine analyzes the received store terminal data in real time, extracts the VLAN ID and DSCP tag in the data packet, and matches the intranet domain or public network access domain to which the data packet belongs. Specifically, the SD-WAN intelligent scheduling engine is integrated in the 5G intelligent gateway main chip and connected with the hardware forwarding unit through an internal high-speed bus; after the store terminal data enters the gateway, the hardware forwarding unit pushes the data packet to the scheduling engine in real time, the scheduling engine starts the data packet analysis module, extracts the VLAN ID from the Ethernet header and the DSCP from the IP header; then, the built-in identification mapping table (synchronized with the "VLAN ID-domain attribution" rule issued by the S320 cloud management platform, recording that VLAN ID=10 corresponds to the business intranet domain and VLAN ID=20 corresponds to the public network access domain) is called to determine the domain to which the data packet belongs through VLAN ID matching; if the VLAN ID is not recorded in the identification mapping table, the scheduling engine marks the data packet as "illegal traffic" and intercepts it, while recording the interception time and source MAC address to the local log.
[0081] S410.2, Intra-domain routing: for traffic matched to the business intranet domain, the scheduling engine routes the traffic to the 5G main link encrypted transmission channel; for traffic matched to the public network access domain, it is routed to the 5G and 4G adaptive link transmission channel, and the transmission queue in the channel is allocated according to the DSCP priority; Specifically, for traffic matched to the domain attribution, the scheduling engine distributes it according to the domain routing, as follows: Traffic matched to the business intranet domain (VLAN ID=10) is forwarded to the 5G main link channel entrance buffer through the internal routing table (which has been bound with the 5G main link encrypted transmission channel constructed in S310.3), and is transmitted to the headquarters UPF node through the SD-WAN tunnel after SM4 encryption (in line with the encryption policy in S100.2); Traffic matched to the public network access domain (VLAN ID=20) is allocated to the transmission queue according to the DSCP marking: DSCP "001110" (office OA business) to the high-priority queue, "000110" (customer Wi-Fi business) to the medium-priority queue, and "000010" (advertising push business) to the low-priority queue; the scheduling engine uses the weighted fair queue algorithm for scheduling, with the high, medium and low priority queues having weights of 50%, 30% and 20% respectively, to ensure that high-priority business is transmitted first; After routing is completed, the scheduling engine reports traffic distribution statistics to the cloud management platform every 5 minutes, including the proportion of traffic in each domain and the queue usage rate.
[0082] S410.3, Hardware-level physical isolation: the 5G intelligent gateway separates the physical transmission links of the business intranet domain and the public network access domain through a built-in dedicated isolation chip, wherein the business intranet domain traffic is forwarded through the first group of independent MAC interfaces and corresponding physical ports of the main chip, the public network access domain traffic is forwarded through the second group of independent MAC interfaces and corresponding physical ports of the main chip, and the signal paths of the two groups of links have no cross-connection at the hardware level. Specifically, the 5G intelligent gateway is built-in with a special isolation chip, which is connected with the main chip through a PCIe bus and supports hardware-level signal isolation. The chip divides the physical transmission link into two independent channels: the first group is a link dedicated to the intranet domain, which is composed of the first group of independent MAC interfaces of the main chip, corresponding PHY chips and physical ports, and the PCB is independently wired, carrying only traffic with VLAN ID = 10; the second group is a link dedicated to the public network access domain, which is composed of the second group of independent MAC interfaces of the main chip, corresponding PHY chips and physical ports, and the PCB is independently wired, carrying only traffic with VLAN ID = 20; the two groups of links have no shared signal amplification circuit and no shared buffer, and the special isolation chip blocks signal interaction through hardware logic circuit to realize no cross connection at the physical layer.
[0083] S410.4, Isolation state verification: The 5G intelligent gateway regularly self-checks the signal isolation degree of the two groups of physical links to ensure that the data packets of the intranet domain and the public network access domain have no leakage or mixed flow in the transmission process, and the verification result is synchronized to the cloud management platform.
[0084] Specifically, the isolation state verification module built-in the 5G intelligent gateway starts self-checking every hour, generating two types of test data packets: one type is marked with VLAN ID = 10 to simulate intranet domain traffic, which is sent to the intranet domain link through the first group of MAC interfaces, while monitoring whether the second group of MAC interfaces receives; the other type is marked with VLAN ID = 20 to simulate public network access domain traffic, which is sent to the public network access domain link through the second group of MAC interfaces, while monitoring whether the first group of MAC interfaces receives; if neither type of data packet is received on the non-corresponding link, it is determined that the isolation is normal; if any type of data packet is received on the non-corresponding link, it is determined that the isolation is abnormal; the verification result is synchronized to the cloud management platform through a TLS1.3 encrypted channel, and when an exception occurs, the platform triggers an "isolation fault alarm" and generates an operation and maintenance work order, and the gateway locally records fault time, abnormal link identifier and other information to the log.
[0085] S500, Network state dynamic optimization: The cloud management platform collects link performance data of the transmission channel of the intranet domain and the public network access domain in real time; when detecting link performance abnormalities, triggers the SD-WAN controller to perform path reselection and parameter adjustment, and completes adaptive optimization of the transmission channel.
[0086] After the 5G intelligent gateway completes S400 dual-domain traffic intelligent scheduling and isolation, the system enters the S500 network state dynamic optimization phase. In this phase, through the cooperation of the cloud management platform and the SD-WAN controller, the performance of the dual-domain transmission channel is monitored in real time, and the optimization mechanism is automatically triggered when the link is abnormal, ensuring the stability and efficiency of dual-domain traffic transmission.
[0087] In this step, in the S500, the specific process of network state dynamic optimization includes the following steps: S510.1, link performance data collection: the 5G intelligent gateway collects link performance data of the transmission channel of the business intranet domain and the public network access domain in real time, including real-time delay, packet loss rate, bandwidth occupancy rate, and uploads the collected data to the cloud management platform through an encrypted channel after the collection is completed, and the collection period is a preset fixed time length; Specifically, the 5G intelligent gateway starts the link performance collection module, and collects three types of core performance data for the 5G main link encrypted transmission channel of the business intranet domain and the 5G and 4G adaptive link transmission channel of the public network access domain: real-time delay (referring to the round-trip time of data packets from the gateway to the target node), packet loss rate (referring to the proportion of lost data packets in the total sent data packets in the transmission process), and bandwidth occupancy rate (referring to the proportion of the currently used bandwidth in the total available bandwidth of the link); the collection period is set to a preset fixed time length (consistent with the parameter collection period in S310, 10 seconds / time), and the collected data is uploaded to the cloud management platform in real time through a TLS1.3 encrypted channel (consistent with the data reporting channel in S310), and the uploaded data packet is attached with a gateway serial number and a timestamp for data correlation and verification.
[0088] S510.2, performance abnormality determination: the cloud management platform continuously analyzes the received link performance data, and determines that the performance is abnormal when any of the following conditions occurs in the dual-domain link: the packet loss rate or the bandwidth occupancy rate reaches or exceeds the corresponding preset threshold value for continuous multiple collection periods, or the real-time delay reaches or exceeds the preset delay threshold value; Specifically, the performance analysis module of the cloud management platform continuously analyzes the received dual-domain link performance data, and determines the abnormal state based on the preset threshold value and the business characteristics. Among them: The determination threshold value of the business intranet domain is: packet loss rate ≥ 1%, bandwidth occupancy rate ≥ 80%, real-time delay ≥ 100ms; The determination threshold value of the public network access domain is: packet loss rate ≥ 3%, bandwidth occupancy rate ≥ 90%, real-time delay ≥ 200ms (the threshold value is set based on the different needs of dual-domain business for stability, and is consistent with the link scoring threshold value logic in S310); When any of the following conditions occurs in the link of any domain, it is determined that the performance is abnormal: the packet loss rate or the bandwidth occupancy rate reaches or exceeds the corresponding threshold value for continuous 3 collection periods (i.e. 30 seconds), or the real-time delay reaches or exceeds the corresponding threshold value at a time; the determination result is stored in the performance log library of the cloud management platform in real time, and is associated with the corresponding gateway identifier and timestamp.
[0089] S510.3, adaptive optimization triggering: after the performance abnormality determination, the cloud management platform sends an optimization instruction to the SD-WAN controller to trigger the adaptive optimization of the transmission channel; Specifically, the cloud management platform generates an optimization instruction immediately after determining that the link performance is abnormal. The instruction content includes key information such as the domain identifier (intranet domain or public network access domain) to which the abnormal link belongs, the current abnormal performance parameter value, and the abnormal duration. At the same time, the optimization instruction is sent to the SD-WAN controller through an encrypted control channel (consistent with the weight coefficient synchronization channel in S310). Meanwhile, the cloud management platform marks the link as "optimizing" on the local state board and records the instruction sending time.
[0090] S510.4, path reselection and parameter adjustment: the SD-WAN controller re-evaluates the available links based on the dynamic optimization model and completes the transmission path reselection; at the same time, dynamically adjusts the tunnel encapsulation parameters to ensure that the new path adapts to the current link characteristics; Specifically, after receiving the optimization instruction, the SD-WAN controller calls the dynamic optimization model defined in S310 to re-evaluate the link performance: for abnormal links in the intranet domain, the controller selects the link with the highest comprehensive score from the pre-set backup 5G link list (consistent with the multi-link configuration in S100.3) as the new transmission path; for abnormal links in the public network access domain, the controller compares the comprehensive scores of the current 5G link and the 4G link and selects the link with a higher score to complete the path switching.
[0091] At the same time, the controller dynamically adjusts the tunnel encapsulation parameters: when the link packet loss rate is high, the MTU (maximum transmission unit) of the SD-WAN tunnel is reduced to 1200 bytes (to avoid packet loss caused by fragmentation); when the delay is large, the tunnel TTL (time to live) value is increased to 64 (to ensure that the data packet is not discarded prematurely in a long delay link); the parameter adjustment is calculated in real time based on the current link performance data to ensure adaptation to the characteristics of the new path.
[0092] S510.5, optimization result feedback: after optimization is completed, the SD-WAN controller synchronizes the new path information and parameter adjustment results to the cloud management platform, and the cloud management platform updates the network state record and pushes it to the 5G intelligent gateway.
[0093] Specifically, after path reselection and parameter adjustment are completed, the SD-WAN controller generates an optimization result report, which includes the link type (5G or 4G) of the new path, the new path comprehensive score, the adjusted tunnel encapsulation parameter value, the optimization completion time, etc. The report is synchronized to the cloud management platform through an encrypted channel, and the cloud management platform updates the new path information and parameter adjustment results to the network state database and associates the historical performance record of the corresponding gateway. At the same time, the cloud management platform pushes the new path configuration instruction to the 5G intelligent gateway, and the gateway updates the local routing table and tunnel parameters after receiving it to ensure that subsequent traffic is transmitted according to the optimized path. The entire feedback process is completed within 10 seconds, avoiding affecting business continuity.
[0094] The embodiment also provides a 5G+SD-WAN-based dual-domain intelligent networking device for chain stores, loaded with a 5G+SD-WAN-based dual-domain intelligent networking system for chain stores, and a computer program of the 5G+SD-WAN-based dual-domain intelligent networking system for chain stores, which is used to execute the steps of the above-mentioned 5G+SD-WAN-based dual-domain intelligent networking method for chain stores when running.
[0095] Those skilled in the art can understand that the process of implementing all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by program to instruct relevant hardware to complete.
[0096] The basic principles, main features and advantages of the present application are shown and described above. Those skilled in the art should understand that the present application is not limited by the above-mentioned embodiments, and the above-mentioned embodiments and descriptions in the specification are only preferred examples of the present application and are not intended to limit the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.
Claims
1. A method for dual-domain intelligent networking of chain stores based on 5G+SD-WAN, characterized in that, Comprising the following steps: S100, dual-domain security substrate construction: based on 5G security access protocol and SD-WAN virtualization technology, divide the chain store "business intranet domain" and "public network access domain", the business intranet domain serves the store and the headquarters core system communication, the public network access domain serves the store terminal internet access; initialize the encryption algorithm and access control rules of the business intranet domain and the public network access domain; S200, store gateway intelligent access: the 5G intelligent gateway deployed in the store completes the access through the multi-level identity authentication system, submits the unique identity information generated by the hardware to the cloud management platform to complete the basic verification; After passing the dynamic scene verification and challenge-response authentication, automatically obtain the basic configuration parameters of the business intranet domain and the public network access domain networking, and synchronize the authentication whole process log to the security audit node; S300, dynamic construction of dual-domain transmission channel: based on SD-WAN tunnel encapsulation technology, introduce a dynamic optimization model combining 5G link characteristics and SD-WAN tunnel performance, establish a 5G main link encrypted transmission channel for the business intranet domain, and a 5G and 4G adaptive link transmission channel for the public network access domain; Configure the classification identification rules of business intranet domain and public network access domain traffic; S400, dual-domain traffic intelligent scheduling and isolation: through the SD-WAN intelligent scheduling engine, according to the traffic classification identification, the store terminal data is shunted to the corresponding domain transmission channel; The physical link isolation of dual-domain data is realized by using the hardware level isolation mechanism; S500, dynamic optimization of network state: the cloud management platform collects the link performance data of the transmission channel of the business intranet domain and the public network access domain in real time; When detecting link performance anomalies, trigger the SD-WAN controller to perform path reselection and parameter adjustment to complete the adaptive optimization of the transmission channel.
2. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S100, dividing the chain store business intranet domain and the public network access domain, initializing the encryption algorithm and the access control rules of the business intranet domain and the public network access domain, comprising the following steps: S100.1, dual-domain division: based on the 5G access layer security protocol defined by 3GPP to establish the underlying security connection; Through the SD-WAN controller, assign a virtual network identifier VNI=1001 to the business intranet domain and a virtual network identifier VNI=2001 to the public network access domain, respectively based on the two VNIs to realize the logical isolation of the business intranet domain and the public network access domain; S100.2, business intranet domain encryption algorithm initialization: use the SM4 symmetric encryption algorithm with a key length of 128 bits; The cloud management platform encrypts the key through the SM2 asymmetric encryption algorithm and then issues it to the chain store gateway, which stores the key in the secure storage area of the built-in hardware encryption chip; S100.3, public network access domain encryption algorithm initialization: use the AES-256 symmetric encryption algorithm, the key is generated by the chain store gateway based on the built-in random number generator, and the key is automatically rotated every 24 hours; S100.4, business intranet domain access control rule initialization: based on network quintuple settings; Only allow the store local IP network segment to access the headquarters core system IP network segment, and only open the preset business port; S100.5, Public network access domain access control rule initialization: based on network five tuple setting; prohibit the traffic of public network access domain from accessing the headquarters core system IP network segment; only allow access to the IP addresses corresponding to the preset Internet domain name whitelist, and limit the maximum bandwidth occupation value of a single terminal in the public network access domain to 100 Mbps.
3. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S200, the generation process of the unique identity information generated by the hardware includes the following steps: S210.1, information extraction: the 5G intelligent gateway extracts the device serial number SN and the 5G module international mobile equipment identity IMEI through the built-in national SM4 encryption chip, and collects the output characteristic value of the physical unclonable function PUF of the national SM4 encryption chip; S210.2, hash fusion to generate root key: the encryption chip performs hash fusion operation on the device serial number SN, 5G module IMEI code and PUF characteristic value to generate a unique hardware root key; S210.3, secure storage of key and access control: after the hardware root key is processed by the internal fuse mechanism of the encryption chip, it is stored in the non-rewritable secure storage area of the chip, and only allowed to be called through the internal interface of the chip, and external instruction reading is prohibited.
4. The 5G+SD-WAN based dual-domain intelligent networking method for chain stores according to claim 3, characterized in that, In the S200, the specific process of dynamic scene verification includes the following steps: S220.1, position information collection: the 5G intelligent gateway collects real-time longitude and latitude data through the built-in GPS module, and uploads them to the cloud management platform through an encrypted channel; S220.2, position deviation verification: the cloud management platform calculates the difference between the received longitude and latitude data and the pre-stored store pre-set position longitude and latitude, and when the absolute value of the deviation is within the pre-set threshold range, the position verification is passed; S220.3, device running state data collection: the 5G intelligent gateway collects real-time running state data of itself, including CPU temperature, memory occupancy and SHA256 hash value of gateway operating system image; S220.4, health status benchmark verification: the cloud management platform verifies that the CPU temperature, memory occupancy meet the pre-set safety baseline, and the gateway operating system image hash value is consistent with the pre-stored benchmark value, and the health status verification is passed; S220.5, dynamic scene verification result determination: after the position verification and health status verification are passed, the dynamic scene verification is completed.
5. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 4, wherein, In the S200, the process of challenge-response authentication and configuration parameter acquisition, log synchronization includes the following steps: S230.1, challenge code generation and encryption issue: the cloud management platform generates a preset length of binary challenge code through an encrypted random number generator , and sends it to the 5G intelligent gateway through a TLS encrypted channel; S230.2, hardware level response value calculation: 5G intelligent gateway calls built-in national secret SM4 encryption chip, reads hardware root key of security storage area , executes SM4 encryption algorithm on " through the internal operation unit of the chip to generate response value and feedback to the cloud management platform through the encryption channel; S230.3, response value consistency verification: the cloud management platform calls the locally stored hardware root key copy, performs the same SM4 encryption operation as the 5G intelligent gateway, and if the local calculation result is consistent with the received response value , the challenge-response authentication is passed; S230.4, double-domain networking parameter pushing: after the authentication is passed, the cloud management platform pushes the networking basic configuration parameters of the business intranet domain and the public network access domain to the 5G intelligent gateway, including the VNI identifier of the double-domain, the tunnel encapsulation format, the encryption algorithm key parameter and the traffic scheduling priority; S230.5, full-process log encryption synchronization: after the 5G intelligent gateway completes the local writing of the configuration parameters, it packages the basic verification records, dynamic scene verification results and key data of the challenge-response authentication process, and synchronizes them to the security audit node through a secure audit special encryption channel.
6. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 5, wherein, In the S300, the construction and application process of the dynamic optimization model includes the following steps: S310.1, feature parameter mapping: the 5G intelligent gateway respectively maps feature parameters of the 5G link and the 4G link into influence factors, including a packet loss rate influence factor , a time delay influence factor , and a bandwidth influence factor ; S310.2, comprehensive score calculation: based on preset weight coefficient , meet and , the link comprehensive score is calculated by a dynamic optimization model ; S310.3, link adaptation selection: set score threshold for public network access domain When the 5G link comprehensive score is greater than the score threshold, the 5G link is preferentially selected; when the 5G link comprehensive score is less than the score threshold, the 4G link is automatically switched to; the service intranet domain is fixed to the comprehensive score of the 5G link as the main link validity determination basis.
7. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 6, wherein, In the S300, the classification identification rule configuration process of the business intranet domain and the public network access domain traffic includes the following steps: S320.1, Marking mechanism determination: adopt the "VLANID+DSCP" double-layer marking mechanism, VLANID is used to distinguish the business intranet domain and the public network access domain, and DSCP is used to mark the priority of different service traffic in the same domain; S320.2, Business intranet domain marking configuration: allocate a dedicated VLANID for the business intranet domain traffic, and mark the corresponding DSCP priority according to the importance of different service traffic in the domain, and the marking rule is bound with the headquarters core system IP network segment; S320.3, Public network access domain marking configuration: allocate a dedicated VLANID for the public network access domain traffic, and mark the corresponding DSCP priority according to the importance of different service traffic in the domain, and the marking rule is bound with the preset Internet IP network segment; S320.4, Marking execution: the 5G intelligent gateway performs real-time analysis on the inbound data packet through the built-in hardware forwarding unit, matches the corresponding marking rule according to the source and destination IP network segment and application type of the data packet, and completes the automatic marking at the hardware level.
8. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S400, the specific process of intelligent scheduling and isolation of dual-domain traffic includes the following steps: S410.1, Traffic identification matching: the SD-WAN intelligent scheduling engine performs real-time analysis on the received store terminal data, extracts the VLANID and DSCP marking in the data packet, and matches the business intranet domain or the public network access domain to which the data packet belongs; S410.2, In-domain routing: for the traffic matched to the business intranet domain, the scheduling engine routes the traffic to the 5G main link encrypted transmission channel; For the traffic matched to the public network access domain, route to the 5G and 4G adaptive link transmission channel, and allocate transmission queues in the channel according to the DSCP priority; S410.3, Hardware-level physical isolation implementation: the 5G intelligent gateway separates the physical transmission links of the business intranet domain and the public network access domain through the built-in special isolation chip; S410.4, Isolation state verification: the 5G intelligent gateway periodically checks the signal isolation degree of the two groups of physical links, and the verification result is synchronized to the cloud management platform.
9. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S500, the specific process of network state dynamic optimization includes the following steps: S510.1, Link performance data collection: the 5G intelligent gateway collects the link performance data of the transmission channel of the business intranet domain and the public network access domain in real time, including real-time delay, packet loss rate, and bandwidth occupancy rate. After the collection is completed, it is uploaded to the cloud management platform through an encrypted channel, and the collection period is a preset fixed time length; S510.2, Performance anomaly determination: the cloud management platform continuously analyzes the received link performance data, and determines that the performance is abnormal when any of the following conditions occurs in the dual-domain link: the packet loss rate or the bandwidth occupancy rate reaches or exceeds the corresponding preset threshold for multiple collection periods in a row, or the real-time delay reaches or exceeds the preset delay threshold; S510.3, Adaptive optimization triggering: after the performance anomaly determination, the cloud management platform sends an optimization instruction to the SD-WAN controller to trigger adaptive optimization of the transmission channel; S510.4, path reselection and parameter adjustment: the SD-WAN controller reevaluates the available links based on the dynamic optimization model, completes the transmission path reselection, and dynamically adjusts the tunnel encapsulation parameters to ensure that the new path adapts to the current link characteristics; S510.5, optimization result feedback: after the optimization is completed, the SD-WAN controller synchronizes the new path information and parameter adjustment result to the cloud management platform, the cloud management platform updates the network state record and pushes it to the 5G intelligent gateway.
10. A 5G+SD-WAN-based dual-domain intelligent networking device for chain stores, loaded with a 5G+SD-WAN-based dual-domain intelligent networking system for chain stores, characterized in that, The computer program of the 5G+SD-WAN-based dual-domain intelligent networking system for chain stores runs to execute the steps of the 5G+SD-WAN-based dual-domain intelligent networking method for chain stores in any of claims 1-9.
Citation Information
Patent Citations
Network attack defense method and device, electronic equipment and storage medium
CN117955675A
Security protection system, method, device, equipment, storage medium and program product
CN119603025A
Industrial firewall isolation method of DCS system
CN119603047A
Data encryption transmission method based on zero-trust architecture
CN119966746A
Internet of Things card intelligent management method and system based on multiple operators
CN120675849A