Chain store dual-domain intelligent networking method and device based on 5G+SD-WAN
By using multi-level identity authentication and SD-WAN virtualization technology in 5G smart gateways, the problems of gateway access authentication and link policy fixation in chain store networking are solved, achieving a balance between security and flexibility.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-10
- Publication Date
- 2026-03-17
AI Technical Summary
In the existing 5G+SD-WAN networking solution for chain stores, the gateway network access authentication lacks hardware uniqueness association and status verification, resulting in significant security risks. Furthermore, the dual-domain transmission link strategy is fixed and cannot match the differentiated needs of the two types of businesses.
Through the multi-level identity authentication system of the 5G smart gateway, combined with SD-WAN virtualization technology, the business intranet domain and public network access domain are divided. Encryption algorithms and access control rules are adopted to dynamically build transmission channels. Traffic classification and isolation are achieved through the SD-WAN intelligent scheduling engine, and network status is dynamically optimized.
Effectively intercepts devices with forged identities from accessing the network, ensuring data exchange security, balancing the transmission needs of the business intranet domain and the public network access domain, and achieving network security and flexibility.
Smart Images

Figure CN121078464B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless communication technology, and more specifically, to a method and apparatus for dual-domain intelligent networking of chain stores based on 5G+SD-WAN. Background Technology
[0002] As a decentralized business scenario, chain stores' networks need to simultaneously support two types of critical business: first, interaction with the headquarters' core system (such as POS data synchronization, inventory information uploading, ERP system access, etc.), which places extremely high demands on data transmission security and link stability; second, internet access for store terminals (such as employee office inquiries, customer temporary Wi-Fi access, etc.), which emphasizes access flexibility and bandwidth adaptability. With the increasing prominence of 5G technology's advantages in wide-area coverage and low latency, and the mature application of SD-WAN technology in virtualized networking and traffic scheduling, the combination of the two has become the main direction for chain store networking. However, current solutions still do not fully meet the risk control and business assurance needs of actual store operations in terms of gateway access security and dual-domain link adaptation.
[0003] Existing 5G+SD-WAN networking solutions for chain stores suffer from two typical technical shortcomings that hinder network security and reliability: First, gateway network access authentication lacks unique hardware identification and status verification, posing significant security risks. The store gateway network access authentication mechanism has vulnerabilities; most solutions only verify identity through device serial numbers or basic network information, failing to link unique characteristics at the gateway hardware level or verify the actual deployment location and operational health status (such as hardware temperature and system integrity). This leads to unauthorized devices forging identities and devices in abnormal states (such as system tampering or hardware overload). The risks associated with network access directly threaten the security of core business data at headquarters. Secondly, the rigid dual-domain transmission link strategy cannot match the differentiated needs of the two types of businesses: the dual-domain transmission link strategy lacks dynamic adaptation capabilities. The business intranet domain (connecting to headquarters) and the public network access domain (connecting to the internet) often use a unified link selection logic, failing to adjust strategies based on the different needs of the two types of businesses and real-time link performance (such as packet loss rate, latency, and bandwidth fluctuations). This either leads to core businesses being affected by link congestion or interruptions, or causes public network access to experience lag due to unreasonable link resource allocation, making it difficult to balance the transmission needs of the two types of businesses. In view of this, we propose a dual-domain intelligent networking method and device for chain stores based on 5G+SD-WAN. Summary of the Invention
[0004] The purpose of this invention is to provide a dual-domain intelligent networking method and device for chain stores based on 5G+SD-WAN, so as to solve the problems mentioned in the background art, such as the lack of hardware uniqueness association and status verification of gateway network access authentication, prominent security risks, and the fixed dual-domain transmission link strategy, which cannot match the differentiated needs of the two types of services.
[0005] To address the aforementioned technical problems, one objective of this invention is to provide a dual-domain intelligent networking method for chain stores based on 5G+SD-WAN, comprising the following steps:
[0006] S100, Dual-Domain Security Infrastructure Construction: Based on 5G secure access protocol and SD-WAN virtualization technology, the system divides the chain stores into "business intranet domain" and "public network access domain". The business intranet domain serves the communication between the store and the headquarters core system, while the public network access domain serves the store terminal's Internet access; the encryption algorithm and access control rules for the business intranet domain and the public network access domain are initialized.
[0007] S200, Smart Network Access for Store Gateways: The 5G smart gateways deployed in stores complete network access through a multi-level identity authentication system, submitting the unique identity information generated by the hardware to the cloud management platform to complete basic verification; after passing dynamic scenario verification and challenge-response authentication, the basic configuration parameters of the business intranet domain and public network access domain are automatically obtained, and the authentication process logs are synchronized to the security audit node.
[0008] S300, Dynamic Construction of Dual-Domain Transmission Channels: Based on SD-WAN tunnel encapsulation technology, a dynamic optimization model integrating 5G link characteristics and SD-WAN tunnel performance is introduced to establish a 5G main link encrypted transmission channel for the business intranet domain and a 5G and 4G adaptive link transmission channel for the public network access domain; and to configure classification and identification rules for traffic in the business intranet domain and the public network access domain.
[0009] S400, Dual-Domain Traffic Intelligent Scheduling and Isolation: Through the SD-WAN intelligent scheduling engine, store terminal data is diverted to the corresponding domain's transmission channel based on traffic classification identifiers; a hardware-level isolation mechanism is used to achieve physical link isolation of dual-domain data;
[0010] S500, Dynamic Network Status Optimization: The cloud management platform collects link performance data of the transmission channel between the business intranet domain and the public network access domain in real time; when abnormal link performance is detected, the SD-WAN controller is triggered to reselect the path and adjust the parameters to complete the adaptive optimization of the transmission channel.
[0011] As a further improvement to this technical solution, in step S100, the following steps are included: dividing the chain store business intranet domain and public network access domain, and initializing the encryption algorithms and access control rules for the business intranet domain and public network access domain:
[0012] S100.1 Dual-domain partitioning: Establish a low-level secure connection based on the 5G access layer security protocol defined by 3GPP; allocate a virtual network identifier (VNI) of 1001 to the business intranet domain and a virtual network identifier (VNI) of 2001 to the public network access domain through the SD-WAN controller, and realize logical isolation between the business intranet domain and the public network access domain based on the two VNIs respectively.
[0013] S100.2 Business intranet domain encryption algorithm initialization: The national standard SM4 symmetric encryption algorithm is adopted, and the key length is set to 128 bits. The cloud management platform encrypts the key using the SM2 asymmetric encryption algorithm and then sends it to the chain store gateway. The gateway stores the key in the secure storage area of the built-in hardware encryption chip.
[0014] S100.3, Public network access domain encryption algorithm initialization: AES-256 symmetric encryption algorithm is adopted. The key is generated automatically by the chain store gateway based on the built-in random number generator, and the key is automatically rotated every 24 hours.
[0015] S100.4 Initialization of intranet access control rules: Based on network 5-tuple (source IP address, destination IP address, source port, destination port, transport protocol); only allow local IP network segments of stores to access the IP network segments of the headquarters core system, and only open preset business ports;
[0016] S100.5, Initialization of public network access domain access control rules: Based on network 5-tuple settings; prohibit traffic from the public network access domain from accessing the IP network segment of the headquarters core system; only allow access to IP addresses corresponding to the preset Internet domain name whitelist, and limit the maximum bandwidth usage of a single terminal in the public network access domain to 100Mbps.
[0017] As a further improvement to this technical solution, in S200, the process of generating the unique identity information generated by the hardware includes the following steps:
[0018] S210.1 Information Extraction: The 5G smart gateway extracts the device serial number (SN) and the 5G module's International Mobile Equipment Identity (IMEI) through the built-in national cryptographic SM4 encryption chip, and collects the output feature value of the Physical Unclonable Function (PUF) of the national cryptographic SM4 encryption chip.
[0019] S210.2 Hash Fusion to Generate Root Key: The encryption chip performs hash fusion operation on the device serial number SN, 5G module IMEI code and PUF feature value to generate a unique hardware root key;
[0020] S210.3 Key Security Storage and Access Control: After the hardware root key is processed by the internal fuse mechanism of the encryption chip, it is stored in the chip's unwritable secure storage area, and can only be accessed through the chip's internal interface, and is prohibited from being read by external commands.
[0021] As a further improvement to this technical solution, the specific process of dynamic scene verification in S200 includes the following steps:
[0022] S220.1 Location Information Collection: The 5G smart gateway collects current latitude and longitude data in real time through its built-in GPS module and uploads it to the cloud management platform through an encrypted channel;
[0023] S220.2 Location Deviation Verification: The cloud management platform will calculate the difference between the received latitude and longitude data and the pre-stored store location latitude and longitude. When the absolute value of the deviation is within the preset threshold range, the location verification is passed.
[0024] S220.3, Device Operation Status Data Acquisition: The 5G smart gateway collects its own operation status data in real time, including CPU temperature, memory usage, and the SHA256 hash value of the gateway operating system image;
[0025] S220.4 Health Status Baseline Verification: The health status verification is passed when the cloud management platform verifies that the CPU temperature and memory usage meet the preset security baseline, and the gateway operating system image hash value is consistent with the pre-stored baseline value.
[0026] S220.5 Dynamic Scene Verification Result Judgment: Dynamic scene verification is completed after both location verification and health status verification pass.
[0027] As a further improvement to this technical solution, in S200, the challenge-response authentication and configuration parameter acquisition, and log synchronization process includes the following steps:
[0028] S230.1 Challenge Code Generation and Encrypted Distribution: The cloud management platform generates a binary challenge code of preset length using an encrypted random number generator. It is sent to the 5G smart gateway via a TLS encrypted channel;
[0029] S230.2 Hardware-level response value calculation: The 5G smart gateway calls the built-in national standard SM4 encryption chip to read the hardware root key in the secure storage area. The SM4 encryption algorithm is executed by the chip's internal processing unit to process the encryption. Process and generate response values. And it is fed back to the cloud management platform through an encrypted channel;
[0030] S230.3, Response Value Consistency Verification: The cloud management platform calls the locally stored hardware root key copy and performs the same SM4 encryption operation as the 5G smart gateway. If the local calculation result matches the received response value... If they match, the challenge-response certification is passed;
[0031] S230.4 Dual-domain networking parameter push: After authentication, the cloud management platform pushes the basic networking configuration parameters of the business intranet domain and the public network access domain to the 5G smart gateway, including the dual-domain VNI identifier, tunnel encapsulation format, encryption algorithm key parameters and traffic scheduling priority.
[0032] S230.5, Full-process log encryption and synchronization: After the 5G smart gateway completes the local writing of configuration parameters, it packages the basic verification records, dynamic scenario verification results, and key data of the challenge-response authentication process, and synchronizes them to the security audit node through a dedicated encrypted channel for security audit.
[0033] As a further improvement to this technical solution, the process of constructing and applying the dynamic optimization model in S300 includes the following steps:
[0034] S310.1 Feature Parameter Mapping: The 5G smart gateway maps the feature parameters of the 5G link and the 4G link into influencing factors, including the packet loss rate influencing factor. Time delay impact factor Bandwidth Influence Factor ;
[0035] S310.2 Comprehensive score calculation: based on preset weighting coefficients ,satisfy and The link comprehensive score is calculated through a dynamic optimization model. ;
[0036] S310.3, Link Adaptive Selection: Setting a scoring threshold for public network access domains. When the 5G link comprehensive score When, prioritize 5G links; when When necessary, it automatically switches to the 4G link; the service intranet domain is fixed based on the comprehensive score of the 5G link. As a basis for determining the validity of the main link.
[0037] As a further improvement to this technical solution, the configuration process for classifying and identifying traffic in the business intranet domain and the public network access domain in S300 includes the following steps:
[0038] S320.1, Tagging Mechanism Determination: A two-layer tagging mechanism of "VLANID + DSCP" is adopted. VLANID is used to distinguish between the business intranet domain and the public network access domain, and DSCP is used to tag the priority of different business traffic within the same domain.
[0039] S320.2, Business Intranet Domain Tagging Configuration: Assign a dedicated VLAN ID to business intranet domain traffic, and tag different business traffic within the domain with corresponding DSCP priorities according to business importance. The tagging rules are bound to the IP network segment of the headquarters core system.
[0040] S320.3 Public network access domain labeling configuration: Assign a dedicated VLAN ID to public network access domain traffic, and label different service traffic within the domain with corresponding DSCP priority according to service importance. The labeling rules are bound to the preset Internet IP network segment.
[0041] S320.4, Marking Execution: The 5G smart gateway performs real-time parsing of inbound data packets through its built-in hardware forwarding unit, and matches the corresponding marking rules based on the source and destination IP network segments and application types of the data packets to complete hardware-level automatic marking.
[0042] As a further improvement to this technical solution, the specific process of intelligent scheduling and isolation of dual-domain traffic in S400 includes the following steps:
[0043] S410.1 Traffic Identifier Matching: The SD-WAN intelligent scheduling engine performs real-time analysis on the received store terminal data, extracts the VLAN ID and DSCP tag in the data packet, and matches the business intranet domain or public network access domain to which the data packet belongs.
[0044] S410.2 Intra-domain channel routing: For traffic matched to the business intranet domain, the scheduling engine routes the traffic to the 5G main link encrypted transmission channel; for traffic matched to the public network access domain, it routes the traffic to the 5G and 4G adaptive link transmission channel, and allocates the transmission queue in the channel according to the DSCP priority.
[0045] S410.3 Hardware-level physical isolation implementation: The 5G smart gateway separates the physical transmission links of the business intranet domain and the public network access domain through a built-in dedicated isolation chip. The traffic of the business intranet domain is forwarded through the first set of independent MAC interfaces and corresponding physical ports of the main chip, while the traffic of the public network access domain is forwarded through the second set of independent MAC interfaces and corresponding physical ports of the main chip. The signal paths of the two sets of links have no cross connection at the hardware level.
[0046] S410.4 Isolation Status Verification: The 5G smart gateway periodically self-checks the signal isolation of the two physical links to ensure that data packets between the business intranet domain and the public network access domain are not leaked or mixed during transmission, and the verification results are synchronized to the cloud management platform.
[0047] As a further improvement to this technical solution, the specific process of dynamic network state optimization in S500 includes the following steps:
[0048] S510.1 Link Performance Data Collection: The 5G smart gateway collects link performance data of the transmission channel between the business intranet domain and the public network access domain in real time, including real-time latency, packet loss rate, and bandwidth utilization. After collection, the data is uploaded to the cloud management platform through an encrypted channel. The collection period is a preset fixed duration.
[0049] S510.2 Performance Anomaly Judgment: The cloud management platform continuously analyzes the received link performance data. When any of the following situations occur in the dual-domain link, it is judged as a performance anomaly: the packet loss rate or bandwidth utilization rate reaches or exceeds the corresponding preset threshold for multiple consecutive collection cycles, or the real-time latency reaches or exceeds the preset latency threshold.
[0050] S510.3 Adaptive Optimization Trigger: After performance anomaly is determined, the cloud management platform sends an optimization command to the SD-WAN controller to trigger adaptive optimization of the transmission channel;
[0051] S510.4 Path Reselection and Parameter Adjustment: The SD-WAN controller re-evaluates available links based on a dynamic optimization model and completes the transmission path reselection; at the same time, it dynamically adjusts tunnel encapsulation parameters to ensure that the new path is adapted to the characteristics of the current link.
[0052] S510.5 Optimization Result Feedback: After optimization, the SD-WAN controller will synchronize the new path information and parameter adjustment results to the cloud management platform. The cloud management platform will update the network status record and push it to the 5G smart gateway.
[0053] The second objective of this invention is to provide a dual-domain intelligent networking device for chain stores based on 5G+SD-WAN, which is equipped with a dual-domain intelligent networking system for chain stores based on 5G+SD-WAN. When the computer program of the dual-domain intelligent networking system for chain stores based on 5G+SD-WAN is run, it is used to execute the steps of the above-mentioned dual-domain intelligent networking method for chain stores based on 5G+SD-WAN.
[0054] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0055] 1. This invention extracts the device serial number, 5G module international mobile device identification code, and output feature value of the physical unclonable function of the national cryptographic SM4 encryption chip through a 5G smart gateway. These are then hashed and fused to generate a unique hardware root key, which is stored in an unalterable secure area. Simultaneously, it combines GPS location latitude and longitude deviation verification, device CPU temperature, memory usage, and operating system image hash value health status verification. Furthermore, it constructs a multi-level network access verification mechanism through challenge-response authentication based on national cryptographic SM4 encryption between the cloud management platform and the gateway. This effectively intercepts devices with forged identities and devices in abnormal states from accessing the network, ensuring the security of data interaction between chain stores and the headquarters core system (such as POS data and inventory information synchronization system) from the source of network access. This is suitable for the precise gateway identity control needs when chain stores are deployed in a decentralized manner.
[0056] 2. This invention addresses the dual-domain business needs of chain stores, namely "internal business network domain serving headquarters core communication and public network access domain serving internet access." Based on SD-WAN tunnel encapsulation technology, it introduces a dynamic optimization model: it transforms the packet loss rate, latency, and bandwidth characteristics of 5G and 4G links into influencing factors, calculates a comprehensive link score using preset weighting coefficients, establishes a 5G main link encrypted transmission channel for the internal business network domain (assigning a dedicated virtual network identifier), and establishes a 5G and 4G adaptive switching link transmission channel for the public network access domain (assigning a dedicated virtual network identifier). This ensures both a dedicated and stable link for data transmission between chain stores and headquarters' core business, and flexible link switching for store terminals accessing the internet. It balances the needs of chain stores for data transmission stability and internet access flexibility in dual-domain business, adapting to the dual-domain network usage scenarios in the daily operations of chain stores. Attached Figure Description
[0057] Figure 1 This is a schematic diagram illustrating the steps of the dual-domain intelligent networking method for chain stores according to the present invention. Detailed Implementation
[0058] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0059] like Figure 1 As shown, this embodiment provides a dual-domain intelligent networking method for chain stores based on 5G+SD-WAN, including the following steps:
[0060] S100, Dual-Domain Security Infrastructure Construction: Based on 5G secure access protocol and SD-WAN virtualization technology, the system divides the chain stores into "business intranet domain" and "public network access domain". The business intranet domain serves the communication between the store and the headquarters core system, while the public network access domain serves the store terminal's Internet access; the encryption algorithm and access control rules for the business intranet domain and the public network access domain are initialized.
[0061] Understandably, after the chain stores complete the deployment of 5G smart gateway hardware, the first step is to start the dual-domain security foundation construction process. The core is to realize the physical isolation of the "business intranet domain" and the "public network access domain" based on the 5G security access protocol and SD-WAN virtualization technology, and at the same time complete the initialization of dual-domain encryption protection and access control, laying a security foundation for subsequent networking.
[0062] In this step, S100 involves dividing the chain store business intranet domain and public network access domain, and initializing the encryption algorithms and access control rules for the business intranet domain and public network access domain, including the following steps:
[0063] S100.1 Dual-domain partitioning: Establish a low-level secure connection based on the 5G access layer security protocol defined by 3GPP; allocate a virtual network identifier (VNI) of 1001 to the business intranet domain and a virtual network identifier (VNI) of 2001 to the public network access domain through the SD-WAN controller, and realize logical isolation between the business intranet domain and the public network access domain based on the two VNIs respectively.
[0064] Specifically, based on the 5G access layer security protocol defined by the 3GPP TS33.501 standard (including user identity privacy protection, data transmission encryption, and integrity protection mechanisms), the 5G smart gateway establishes a low-level secure connection with the operator's 5G core network to ensure the security of the link for stores to access the 5G network; at the same time, the store gateway establishes a control plane connection with the SD-WAN controller deployed at headquarters through an IPsec tunnel to receive dual-domain configuration commands.
[0065] Specifically, a centralized controller based on an SD-WAN virtualization architecture is adopted. The controller assigns a fixed virtual network identifier (VNI) of 1001 to the "business intranet domain" and a fixed virtual network identifier (VNI) of 2001 to the "public network access domain" based on the unique identifier submitted by the store (such as the store number). The controller binds the VNI to the physical port of the store gateway (e.g., the business intranet domain is bound to the gateway's gigabit port 1, and the public network access domain is bound to the gateway's gigabit port 2), and configures VNI routing rules in the SD-WAN global routing table to ensure that the same domain VNIs of different stores will not cause routing conflicts. Finally, through the logical isolation feature of VNI, the dual-domain data will not be mixed during transmission.
[0066] S100.2 Business intranet domain encryption algorithm initialization: The national standard SM4 symmetric encryption algorithm is adopted, and the key length is set to 128 bits. The cloud management platform encrypts the key using the SM2 asymmetric encryption algorithm and then sends it to the chain store gateway. The gateway stores the key in the secure storage area of the built-in hardware encryption chip.
[0067] Specifically, the cloud management platform pre-generates an SM2 asymmetric key pair (public key PK, private key SK) conforming to the national cryptographic standard GM / T0002. The public key PK is pre-installed in the 5G smart gateways of all chain stores, and the private key SK is stored in the hardware security module (HSM) of the cloud management platform. The cloud management platform generates a 128-bit SM4 symmetric key K1 (business intranet domain data encryption key) through a random number generator, and uses the private key SK to encrypt K1 using SM2 to generate the encrypted key ciphertext K1-Enc. The cloud management platform distributes K1-Enc to the store gateway through an encrypted control channel (based on the TLS1.3 protocol).
[0068] Specifically, after receiving K1-Enc, the store gateway calls the built-in hardware encryption chip that conforms to the national cryptographic standard GM / T0028, and uses the preset SM2 public key PK to decrypt K1-Enc to obtain the original SM4 key K1. The hardware encryption chip stores K1 in its internal unwritable secure storage area (this storage area can only be read by the encryption operation unit inside the chip, and external bus and debugging interface access are prohibited). At the same time, the temporary key data generated during the decryption process is destroyed through the chip's internal fuse mechanism to prevent key leakage.
[0069] S100.3, Public network access domain encryption algorithm initialization: AES-256 symmetric encryption algorithm is adopted. The key is generated automatically by the chain store gateway based on the built-in random number generator, and the key is automatically rotated every 24 hours.
[0070] Specifically, the 5G smart gateway has a built-in true random number generator that conforms to the NISTSP800-140 standard. When the gateway is powered on and initialized, the random number generator automatically generates a 256-bit AES symmetric key K2 (public network access domain data encryption key). The entire generation process is completed inside the hardware encryption chip and does not go through the memory of the gateway's main CPU, thus preventing the key from being stolen by memory grabbing tools.
[0071] Specifically, the gateway has a built-in timer set to a 24-hour key rotation cycle. Every day at midnight, after the timer is triggered, the gateway's hardware encryption chip regenerates a new 256-bit AES key K2'. At the same time, the key erasure command inside the chip completely removes all traces of the old key K2 in the secure storage area. After the new key K2' is generated, it is automatically synchronized to the gateway's traffic encryption module for subsequent encrypted data transmission in the public network access domain, without the need for manual intervention.
[0072] S100.4 Initialization of intranet access control rules: Based on network 5-tuple (source IP address, destination IP address, source port, destination port, transport protocol); only allow local IP network segments of stores to access the IP network segments of the headquarters core system, and only open preset business ports;
[0073] Specifically, based on the network 5-tuple (source IP address, destination IP address, source port, destination port, and transport protocol), the cloud management platform configures access control rules for the store gateway, as shown in the example below:
[0074] Source IP address range: Local IP network segment of the store, uniformly planned as 192.168.X.0 / 24 (X is the store number, such as 01 representing the first store, i.e. 192.168.01.0 / 24).
[0075] Destination IP address range: Headquarters core system IP network segment, fixed at 10.0.0.0 / 16 (including core business servers such as POS system, inventory system, ERP system, etc.);
[0076] Transmission protocol: Only TCP protocol is allowed (core business data transmission uses TCP protocol to ensure reliability);
[0077] Destination ports: Only the preset business ports are open, of which the POS data synchronization port is TCP8080, the inventory information upload port is TCP8081, and the ERP system access port is TCP8082;
[0078] Source port: No restriction (a random source port is used when a store terminal initiates a business request).
[0079] Specifically, the cloud management platform encapsulates the aforementioned five-tuple rules into an access control list (ACL) and sends it to the store gateway through an encrypted control channel. The gateway loads the ACL rules into its built-in hardware packet filtering module, and the hardware performs rule matching to ensure that only traffic that conforms to the rules can enter the business intranet domain, while traffic that does not conform to the rules is directly discarded.
[0080] S100.5, Initialization of public network access domain access control rules: Based on network 5-tuple settings; prohibit traffic from the public network access domain from accessing the IP network segment of the headquarters core system; only allow access to IP addresses corresponding to the preset Internet domain name whitelist, and limit the maximum bandwidth usage of a single terminal in the public network access domain to 100Mbps.
[0081] Specifically, based on the aforementioned network 5-tuple, the cloud management platform configures access control rules for the public network access domain for the store gateway:
[0082] Block rule: All traffic destined for the headquarters core system IP network segment (10.0.0.0 / 16) will be dropped regardless of the source IP, port, or protocol.
[0083] Allowed rules: The destination IP address is the IP address corresponding to the preset Internet domain name whitelist. The whitelist includes domain names required for store office use (such as enterprise OA system domain name, supply chain query domain name) and public service domain names required for temporary Wi-Fi for customers (such as payment platform domain name, map service domain name). The cloud management platform obtains the corresponding IP address by periodically resolving the whitelist domain names and synchronizes it to the store gateway to ensure timely IP address updates. In addition, when the preset Internet domain name whitelist synchronization fails, a fault tolerance mechanism is activated: First, it retryes 3 times (each time with a 10-second interval). If the retry fails, it switches to the backup resolution server (such as 114.114.114.114, 8.8.8.8) to ensure that the domain name resolution service is not interrupted.
[0084] Transport protocols: Allows TCP and UDP protocols (to meet the diverse needs of Internet access, such as TCP for web browsing and UDP for video caching).
[0085] Specifically, the store gateway has a built-in traffic control module. The cloud management platform sends single-terminal bandwidth limit parameters to the traffic control module—the maximum bandwidth usage of a single terminal in the public network access domain is 100Mbps (downlink + uplink). The traffic control module counts real-time bandwidth usage based on the terminal's MAC address. When the bandwidth usage of a terminal exceeds 100Mbps for 5 consecutive seconds, the flow limiting mechanism is automatically triggered, limiting the terminal's downlink bandwidth to 80Mbps and uplink bandwidth to 20Mbps (total bandwidth not exceeding 100Mbps). Once the terminal's bandwidth usage drops below 90Mbps, normal bandwidth allocation is restored to avoid excessive bandwidth usage by a single terminal affecting the use of other terminals.
[0086] Furthermore, the ACL rules and bandwidth limit parameters for the public network access domain are all sent to the hardware packet filtering module and traffic control module of the store gateway through an encrypted control channel, and the rules take effect immediately after being sent. The gateway regularly (every hour) compares the currently effective rules with the latest rules of the cloud management platform. If there are differences, it will automatically synchronize and update to ensure rule consistency.
[0087] S200, Smart Network Access for Store Gateways: The 5G smart gateways deployed in stores complete network access through a multi-level identity authentication system, submitting the unique identity information generated by the hardware to the cloud management platform to complete basic verification; after passing dynamic scenario verification and challenge-response authentication, the basic configuration parameters of the business intranet domain and public network access domain are automatically obtained, and the authentication process logs are synchronized to the security audit node.
[0088] Understandably, after the store completes the hardware deployment of the 5G smart gateway (such as fixed installation in the store's low-voltage box, connected to a stable power supply and a 5G signal receiving antenna), the 5G smart gateway will initiate the initialization process upon its first power-on, automatically triggering the network access operation. This network access process uses a multi-level identity authentication system consisting of "hardware unique identity verification - dynamic scenario verification - challenge - response authentication" to strictly verify the legitimacy of the 5G smart gateway and the security of its operating environment. Ultimately, it completes the network parameter configuration for the business intranet domain and the public network access domain, and synchronizes the entire process log to the security audit node to ensure the security and stability of the subsequent dual-domain network.
[0089] In this step, the process of generating the unique identity information generated by the hardware in S200 includes the following steps:
[0090] The unique identity information generated by the hardware is the core identity credential for 5G smart gateways to access the network. It is generated based on the inherent immutable characteristics of 5G smart gateway hardware, ensuring that the identity information of each 5G smart gateway is unique, unforgeable, and uncopyable. The generation process of this identity information is automatically executed by the built-in national cryptographic SM4 encryption chip when the 5G smart gateway is powered on for the first time, without the need for manual intervention.
[0091] S210.1 Information Extraction: The 5G smart gateway extracts the device serial number (SN) and the 5G module's International Mobile Equipment Identity (IMEI) through the built-in national cryptographic SM4 encryption chip, and collects the output feature value of the Physical Unclonable Function (PUF) of the national cryptographic SM4 encryption chip.
[0092] Specifically, the device serial number (SN) of the 5G smart gateway is a unique 16-digit combination of letters and numbers. This SN is pre-programmed into the BIOS storage area of the main chip before the 5G smart gateway leaves the factory. The SM4 encryption chip built into the 5G smart gateway sends a read command conforming to the I2C protocol to the BIOS storage area through the internal I2C standard communication bus of the main chip. The command carries the storage address identifier of the device serial number (SN) to accurately obtain the original data of the device serial number (SN). During the entire reading process, the 5G smart gateway automatically closes external debugging interfaces (such as JTAG interfaces) to prevent the device serial number (SN) from being illegally intercepted or tampered with during the reading and transmission process.
[0093] Specifically, the 5G communication module built into the 5G smart gateway (such as the Qualcomm SDX55 5G communication module) supports the AT command set communication protocol. The national cryptographic SM4 encryption chip sends the "AT+GSN" command (the standard command for obtaining the International Mobile Equipment Identity (IMEI) of the 5G communication module) to the 5G communication module through the UART serial communication link. After receiving the command, the 5G communication module returns the IMEI in 15-digit format. The national cryptographic SM4 encryption chip performs format verification on the returned IMEI (verifying whether it is a 15-digit pure number). After confirming that the format is correct, it extracts the valid IMEI information and temporarily stores it.
[0094] Specifically, the physical unclonable function (PUF) output feature value acquisition of the SM4 encryption chip: The SM4 encryption chip built into the 5G smart gateway integrates a physical unclonable function (PUF) circuit. When the 5G smart gateway is powered on for the first time, the PUF circuit automatically generates a unique 64-byte output feature value due to random physical differences such as transistor threshold voltage and wire resistance during chip manufacturing. The SM4 encryption chip performs a cyclic redundancy check (CRC32) on this 64-byte output feature value. After verifying that the feature value has not been transmitted or generated incorrectly, it stores it in the temporary buffer area of the SM4 encryption chip to provide basic data for subsequent hash fusion operations.
[0095] S210.2 Hash Fusion to Generate Root Key: The encryption chip performs hash fusion operation on the device serial number SN, 5G module IMEI code and PUF feature value to generate a unique hardware root key;
[0096] Specifically, the SM4 encryption chip retrieves the extracted device serial number, 5G module international mobile equipment identification code, and physical unclonable function output feature value from the temporary buffer. The data is then concatenated in a fixed order: "device serial number → 5G module international mobile equipment identification code → physical unclonable function output feature value". The device serial number is 16 bytes, the 5G module international mobile equipment identification code is 15 bytes, and 1 byte of 0x00 data needs to be added to the end of the 5G module international mobile equipment identification code to make it 16 bytes. The physical unclonable function output feature value is 64 bytes, resulting in a raw data string with a total length of 16 + 16 + 64 = 96 bytes.
[0097] Specifically, the national standard SM4 encryption chip calls its built-in hash operation unit and uses the SHA256 hash algorithm conforming to the NISTFIPS180-4 standard to perform a hash operation on the 96-byte original data string, generating a 32-byte (256-bit) hash value. The national standard SM4 encryption chip converts this 32-byte hash value into a binary data stream, which is the unique hardware root key K of the 5G smart gateway, used in the subsequent challenge-response authentication process.
[0098] S210.3 Key Security Storage and Access Control: After the hardware root key is processed by the internal fuse mechanism of the encryption chip, it is stored in the chip's unwritable secure storage area, and can only be accessed through the chip's internal interface, and is prohibited from being read by external commands.
[0099] Specifically, after generating the hardware root key, the SM4 encryption chip automatically initiates an internal fuse-breaking procedure. By applying a preset high voltage to the internal debug interface fuse (such as the JTAG interface fuse), the debug interface fuse is permanently burned out, completely disabling external devices (such as debug computers) from debugging access to the internal storage area of the SM4 encryption chip. At the same time, the SM4 encryption chip automatically executes a temporary buffer data clearing command, completely deleting the original data of the device serial number, 5G module international mobile equipment identification code, and physical unclonable function output feature value stored in the temporary buffer, retaining only the hardware root key.
[0100] Specifically, the national standard SM4 encryption chip writes the hardware root key into its internal one-time programmable secure storage area. This one-time programmable secure storage area has the characteristics of "single write, permanent read". After the hardware root key is written, the national standard SM4 encryption chip automatically locks the write permission of the storage area. No instruction (including instructions from unauthorized modules inside the national standard SM4 encryption chip) can modify or delete the hardware root key.
[0101] Specifically, the national standard SM4 encryption chip constructs an access control mechanism through hardware logic circuits, allowing only its internal SM4 encryption operation unit to call the hardware root key through a dedicated internal bus for encryption operations in the challenge-response authentication process. For hardware root key read commands sent by the 5G smart gateway main chip and external communication interfaces (such as Ethernet ports and USB ports), the hardware firewall module of the national standard SM4 encryption chip will automatically intercept them and return a "permission denied" response signal to ensure that the hardware root key is not leaked or illegally accessed externally.
[0102] In this step, the specific process of dynamic scene verification in S200 includes the following steps:
[0103] Dynamic scenario verification is used to confirm the consistency between the actual deployment location of the 5G smart gateway and the preset location in the chain stores, as well as the health of the 5G smart gateway's current operating status. This prevents unauthorized devices from accessing the network system in unauthorized locations, or prevents 5G smart gateways in abnormal operating states (such as tampered operating systems or hardware overload) from entering the network. This verification process is led by the cloud management platform, with the 5G smart gateway assisting in data collection and feedback.
[0104] S220.1 Location Information Collection: The 5G smart gateway collects current latitude and longitude data in real time through its built-in GPS module and uploads it to the cloud management platform through an encrypted channel;
[0105] Specifically, after the 5G smart gateway generates its unique hardware identity information, it automatically sends a start command to the built-in GPS module. Once started, the GPS module enters satellite search mode and continuously searches for at least four navigation satellites to obtain a stable positioning signal. Under normal circumstances, the stable acquisition time for the positioning signal is ≤60 seconds. If the 5G smart gateway is deployed in an indoor scenario (such as a store on the basement floor of a shopping mall), and the satellite signal received by the GPS module is too weak to complete the positioning, the GPS module automatically switches to Assisted Global Positioning System (AGPS) mode. It accesses the 5G network through the 5G communication module of the 5G smart gateway and obtains base station assisted positioning data (such as the location and signal strength of surrounding 5G base stations) from the AGPS assisted positioning server provided by the operator. Combined with the weak satellite signals it receives, it improves the positioning accuracy and ensures the effectiveness of location information collection.
[0106] Specifically, after the GPS module acquires latitude and longitude data based on the WGS84 coordinate system, it transmits the latitude and longitude data to the national cryptographic SM4 encryption chip. The national cryptographic SM4 encryption chip uses the temporary key of the business intranet domain initialized in step S100 to perform SM4 symmetric encryption operation on the latitude and longitude data to generate an encrypted data string. The 5G smart gateway uploads the encrypted data string to the cloud management platform through an encrypted control channel built based on the TLS1.3 protocol, and attaches the device serial number (SN) of the 5G smart gateway to the uploaded data to facilitate the cloud management platform's association and identification.
[0107] S220.2 Location Deviation Verification: The cloud management platform will calculate the difference between the received latitude and longitude data and the pre-stored store location latitude and longitude. When the absolute value of the deviation is within the preset threshold range, the location verification is passed.
[0108] Specifically, after receiving the encrypted data string and device serial number (SN) uploaded by the 5G smart gateway, the cloud management platform calls the built-in SM4 decryption module and uses the same business intranet domain temporary key as the 5G smart gateway to decrypt the encrypted data string, extracting the plaintext latitude and longitude data. At the same time, based on the device serial number (SN), the cloud management platform retrieves the preset location latitude and longitude data of the chain store corresponding to the device serial number (SN) from the chain store information database (the preset location latitude and longitude are the center coordinates of the registered address on the chain store's business license).
[0109] Specifically, the cloud management platform uses the Euclidean distance formula to calculate the deviation (in meters) between the actual latitude and longitude of the 5G smart gateway and the preset latitude and longitude of the store. The specific calculation formula is as follows:
[0110] ;
[0111] in, This indicates the deviation between the actual latitude and longitude of the 5G smart gateway and the preset latitude and longitude of the store; Indicates the actual latitude; Indicates the preset latitude; Indicates the actual longitude; Indicates the preset longitude; This represents the ratio of the Earth's equatorial circumference to 360°. (), indicating that 1° latitude corresponds to a distance of approximately 111,319.9 meters on the Earth's surface; The cosine value in radians represents the preset latitude, used to convert the longitude difference into the corresponding surface distance (the surface distance corresponding to the longitude difference varies with latitude).
[0112] Specifically, the cloud management platform sets preset location deviation thresholds based on the deployment scenarios of chain stores: the preset location deviation threshold for independent street-side stores is ±50 meters (considering possible minor adjustments to equipment installation around the store), and the preset location deviation threshold for stores inside shopping malls is ±20 meters (due to the influence of the mall's building structure, GPS positioning accuracy is slightly reduced); when the absolute value of the calculated deviation is ≤ the preset threshold for the corresponding scenario, the location verification is considered successful; if the absolute value of the deviation exceeds the preset threshold, the cloud management platform immediately sends a "location verification failed" command to the 5G smart gateway, terminates the network access process, and records the reason for the failure (such as "location deviation exceeds 50 meters") in the exception log.
[0113] S220.3, Device Operation Status Data Acquisition: The 5G smart gateway collects its own operation status data in real time, including CPU temperature, memory usage, and the SHA256 hash value of the gateway operating system image;
[0114] Specifically, once the location verification is successful, the cloud management platform sends a "start device operation status collection" command to the 5G smart gateway. After receiving the command, the 5G smart gateway starts the device operation status data collection task, sets the collection period to 10 seconds, and collects data three times in a row (to avoid misjudgment due to abnormalities caused by momentary interference in a single data collection).
[0115] Specifically, the real-time collection of its own operational status data by the 5G smart gateway includes:
[0116] CPU Temperature Acquisition: The main chip of the 5G smart gateway (such as the MediaTek MT7986 model main chip) has a built-in temperature sensor. The 5G smart gateway obtains the real-time CPU temperature value (unit: °C) by reading the register value corresponding to the temperature sensor inside the main chip. After collecting the data three times consecutively, the arithmetic mean of the three temperature values is calculated according to the following formula as the final CPU temperature data to eliminate the influence of instantaneous temperature fluctuations: ;
[0117] Memory usage data collection: The operating system (such as OpenWRT) on the 5G smart gateway supports command-line data query. By executing the "free -m" command, the total memory capacity (unit: MB) and the used memory capacity (unit: MB) can be obtained. The memory usage rate is calculated according to the following formula. After collecting the data three times consecutively, the arithmetic mean is taken as the final memory usage rate data: ;
[0118] Gateway operating system image SHA256 hash value collection: The 5G smart gateway performs SHA256 hash operation on the complete operating system image file (file extension .img) stored in flash memory (such as 16GB eMMC flash memory). This operation is completed entirely in the memory of the 5G smart gateway. After the operation is completed, a memory data clearing command is immediately executed to delete the temporarily stored operating system image data in memory to avoid image data leakage; finally, a 64-bit hexadecimal format SHA256 hash value is generated.
[0119] Specifically, the 5G smart gateway will upload the average CPU temperature and average memory usage obtained from three data collections, as well as the SHA256 hash value of the gateway operating system image obtained from one calculation, to the cloud management platform via an encrypted control channel based on the TLS1.3 protocol. The uploaded data will include a data collection timestamp to facilitate the cloud management platform in tracing the validity of the data.
[0120] S220.4 Health Status Baseline Verification: The health status verification is passed when the cloud management platform verifies that the CPU temperature and memory usage meet the preset security baseline, and the gateway operating system image hash value is consistent with the pre-stored baseline value.
[0121] Specifically, after receiving the device operating status data uploaded by the 5G smart gateway, the cloud management platform retrieves the preset health and safety baseline corresponding to that model of 5G smart gateway from the 5G smart gateway hardware specification database. The specific baseline parameters are as follows:
[0122] CPU temperature safety range: (This range is based on the industrial-grade operating temperature standard setting of the 5G smart gateway main chip to ensure that the CPU operates stably at a safe temperature.)
[0123] Memory usage safety threshold: ≤80% (This threshold is set to avoid excessive memory usage causing the 5G smart gateway operating system to lag or crash).
[0124] Gateway operating system image baseline SHA256 hash value: Before the 5G smart gateway leaves the factory, the equipment manufacturer has uploaded the SHA256 hash value of the operating system image of this batch of 5G smart gateways to the cloud management platform. The cloud management platform establishes associated storage according to the device serial number SN, and at this time retrieves the baseline SHA256 hash value that matches the current 5G smart gateway device serial number SN.
[0125] Specifically, the verification of CPU temperature, memory usage, and the SHA256 hash value of the gateway operating system image is as follows:
[0126] CPU temperature verification: If the average CPU temperature uploaded by the 5G smart gateway is within the range... If the temperature is within the specified range, the CPU temperature verification is considered successful; if it exceeds the specified range, it is considered an "abnormal hardware temperature".
[0127] Memory usage verification: If the average memory usage uploaded by the 5G smart gateway is ≤80%, the memory usage verification is considered successful; if it exceeds this threshold, it is considered "memory overload".
[0128] Operating system integrity verification: If the SHA256 hash value of the gateway operating system image uploaded by the 5G smart gateway is completely consistent with the baseline SHA256 hash value pre-stored on the cloud management platform, the operating system integrity verification is deemed to have passed; if they are inconsistent, it is determined that "the operating system has been tampered with".
[0129] In summary, when all three verifications above pass, the 5G smart gateway health status verification is considered successful; if any verification fails, the cloud management platform sends a "health status verification failed" command to the 5G smart gateway, terminates the network access process, and records the failure type (such as "operating system tampered with") in the anomaly log.
[0130] S220.5 Dynamic Scene Verification Result Judgment: Dynamic scene verification is completed after both location verification and health status verification pass.
[0131] Specifically, the cloud management platform aggregates the location verification results and health status verification results. If both verifications pass, the cloud management platform generates a "Dynamic Scene Verification Passed" instruction, which includes a verification pass timestamp and device serial number (SN). This instruction is sent to the 5G smart gateway via an encrypted control channel based on the TLS 1.3 protocol. If either the location verification or the health status verification fails, the cloud management platform records the reason for the verification failure (such as "memory overload" or "location deviation exceeding 20 meters") in the anomaly log and synchronizes it to the security audit node. After receiving the "Dynamic Scene Verification Failed" instruction, the 5G smart gateway automatically enters the "Network Access Anomaly" state. Technical personnel need to investigate the problem on-site (such as checking the 5G smart gateway's operating environment and reinstalling the operating system) before restarting the network access process.
[0132] In this step, the challenge-response authentication, configuration parameter acquisition, and log synchronization process in S200 includes the following steps:
[0133] Challenge-Response Authentication is the final security verification step in the 5G smart gateway's network access process. It verifies the 5G smart gateway's hardware root key through encrypted data interaction between the cloud management platform and the 5G smart gateway. The legitimacy of the access network is verified to ensure that the network access system is accessed by an authorized 5G smart gateway. After authentication, the cloud management platform pushes the dual-domain networking basic configuration parameters to the 5G smart gateway, and the 5G smart gateway synchronizes the entire network access process log to the security audit node.
[0134] S230.1 Challenge Code Generation and Encrypted Distribution: The cloud management platform generates a binary challenge code of preset length using an encrypted random number generator. It is sent to the 5G smart gateway via a TLS encrypted channel;
[0135] Specifically, the cloud management platform calls a cryptographic random number generator conforming to the NISTSP800-90A standard to generate a 128-bit binary challenge code. To facilitate data transmission and processing, the cloud management platform will use the 128-bit binary challenge code. Convert to a 32-bit hexadecimal string format.
[0136] Specifically, the cloud management platform transmits the 32-bit hexadecimal challenge code through an encrypted control channel based on the TLS 1.3 protocol (the same channel used for uploading location information and device operating status data in step S220). Send to the 5G smart gateway; to ensure the challenge code To prevent tampering during transmission, the cloud management platform adds a 4-byte cyclic redundancy check code to the data being sent. After receiving the data, the 5G smart gateway needs to verify the cyclic redundancy check code first to confirm the data integrity before performing subsequent operations.
[0137] S230.2 Hardware-level response value calculation: The 5G smart gateway calls the built-in national standard SM4 encryption chip to read the hardware root key in the secure storage area. The SM4 encryption algorithm is executed by the chip's internal processing unit to process the encryption. Process and generate response values. And it is fed back to the cloud management platform through an encrypted channel;
[0138] Specifically, the 5G smart gateway receives the challenge code. After verifying the CRC32 code, a "hardware root key retrieval" command is sent to the built-in SM4 encryption chip. Upon receiving the command, the SM4 encryption chip reads the 32-byte binary stream of the hardware root key K from the one-time programmable OTP secure storage area via its internal dedicated bus. The reading process bypasses the 5G smart gateway's main memory and directly retrieves the hardware root key. The SM4 encryption processing unit of the national standard SM4 encryption chip is used to avoid hardware root keys. Give way.
[0139] Specifically, the SM4 encryption processing unit of the national standard SM4 encryption chip first processes the challenge code. With hardware root key Perform data matching processing: Challenge Code It is 128 bits, or 16 bytes, therefore the hardware root key is obtained. The first 16 bytes and the challenge code Perform a bitwise XOR operation and the result is denoted as ( 16 bytes; subsequently, the SM4 encryption unit uses the SM4 symmetric encryption algorithm conforming to the GM / T0002-2012 standard, and performs an XOR operation on the result in "Electronic Codebook Mode ECB" ( ) Perform encryption operation based on the XOR result ( The result already possesses randomness and does not require an additional initialization vector (IV), generating a 16-byte binary encrypted result.
[0140] Specifically, the SM4 encryption chip converts the 16-byte binary encryption result into a 32-bit hexadecimal string, which is recorded as the response value. The 5G smart gateway transmits the response value through an encrypted control channel based on the TLS 1.3 protocol. The device is sent to the cloud management platform along with its own serial number (SN), and the response value is recorded simultaneously. The generated timestamps facilitate the cloud management platform in verifying time sequence consistency.
[0141] S230.3, Response Value Consistency Verification: The cloud management platform calls the locally stored hardware root key copy and performs the same SM4 encryption operation as the 5G smart gateway. If the local calculation result matches the received response value... If they match, the challenge-response certification is passed;
[0142] Specifically, the cloud management platform receives the response value uploaded by the 5G smart gateway. After obtaining the device serial number (SN), retrieve the hardware root key copy corresponding to the device serial number (SN) from the hardware security module. The hardware security module is the same device as the hardware security module that stores the SM2 asymmetric private key in step S100, and the hardware root key copy is... The backup key synchronized by the device manufacturer to the hardware security module when the 5G smart gateway leaves the factory, and the hardware root key stored locally on the 5G smart gateway. Completely identical (32-byte binary stream).
[0143] Specifically, the encryption computing module of the cloud management platform performs operations according to the same logic as the 5G smart gateway: first, it retrieves a copy of the hardware root key. The first 16 bytes are XORed bitwise with the 128-bit binary code C to obtain the XOR result. 16 bytes; then, the SM4 symmetric encryption algorithm in ECB mode, conforming to the GM / T0002-2012 standard, is XORed with the result ( Perform encryption operations and generate a local response value, denoted as ( A 32-bit hexadecimal string; the cloud management platform will use the locally generated response value ( ) and the response value reported by the 5G smart gateway A bit-by-bit comparison is performed. If the two are completely identical, the challenge-response authentication is deemed successful; if they are inconsistent, it is determined that "key mismatch" occurs, the network access process is immediately terminated, and abnormal information such as "response value" is transmitted. and( "Inconsistency" is recorded in the security audit log.
[0144] S230.4 Dual-domain networking parameter push: After authentication, the cloud management platform pushes the basic networking configuration parameters of the business intranet domain and the public network access domain to the 5G smart gateway, including the dual-domain VNI identifier, tunnel encapsulation format, encryption algorithm key parameters and traffic scheduling priority.
[0145] Specifically, once the challenge-response authentication is successful, the cloud management platform retrieves the basic dual-domain networking configuration parameters corresponding to the chain store from the dual-domain networking configuration database based on the chain store number associated with the 5G smart gateway's device serial number (SN). The specific parameter content is as follows:
[0146] Dual-domain VNI identifier: Business intranet domain virtual network identifier VNI=1001, public network access domain virtual network identifier VNI=2001 (consistent with the virtual network identifier VNI assigned in step S100.1).
[0147] Tunnel encapsulation format: VXLAN tunnel encapsulation technology conforming to RFC7348 is adopted, the VXLAN tunnel port number is set to 4789, and the Virtual Network Identifier (VNI) field is embedded in the VXLAN data frame header to identify the domain to which the data belongs.
[0148] Encryption algorithm key parameters: The automatic rotation period of the SM4 symmetric encryption key used in the business intranet domain (i.e. the key generated in step S100.2) and the AES-256 symmetric encryption key used in the public network access domain (24 hours, consistent with the rotation period set in step S100.3).
[0149] Traffic scheduling priority: Dual-domain traffic is divided into 3 priority levels. Priority 1 (highest priority) corresponds to the traffic for POS data synchronization in chain stores, priority 2 corresponds to the traffic for accessing the inventory system and ERP system in chain stores, and priority 3 (lowest priority) corresponds to the traffic for employee office queries and customer Wi-Fi access in chain stores.
[0150] Specifically, the cloud management platform organizes the aforementioned dual-domain networking basic configuration parameters into a JSON format configuration file. Using the SM2 asymmetric public key pre-configured in step S100.2 on the 5G smart gateway, it performs encryption operations on the JSON format configuration file to generate an encrypted configuration file. The encrypted configuration file is then pushed to the 5G smart gateway via an encrypted control channel based on the TLS 1.3 protocol. After receiving the encrypted configuration file, the 5G smart gateway calls its built-in national standard SM4 encryption chip and uses its stored SM2 asymmetric private key to decrypt the encrypted configuration file, obtaining a plaintext JSON configuration file. The 5G smart gateway writes the parameters from the plaintext configuration file into flash memory (such as partition 2 of the eMMC flash memory, which is a dedicated configuration storage area). After the parameters are written, the 5G smart gateway sends a "Dual-domain networking parameter configuration successful" confirmation command to the cloud management platform, which includes a configuration completion timestamp.
[0151] S230.5, Full-process log encryption and synchronization: After the 5G smart gateway completes the local writing of configuration parameters, it packages the basic verification records, dynamic scenario verification results, and key data of the challenge-response authentication process, and synchronizes them to the security audit node through a dedicated encrypted channel for security audit.
[0152] Specifically, after the 5G smart gateway completes the dual-domain networking parameter configuration, it automatically starts the full-process log collection task for network access. The collected log content includes:
[0153] Basic verification records: hardware unique identity information generation timestamp, the first 8 characters of the device serial number, the first 8 characters of the 5G module's International Mobile Equipment Identity (IMEI), and the first 8 bytes of the physical unclonable function output feature value;
[0154] Dynamic scene verification results: location verification timestamp, location deviation value, average CPU temperature, average memory usage, and the first 8 bits of the SHA256 hash value of the gateway operating system image;
[0155] Challenge-response authentication process: challenge code reception timestamp, response value generation timestamp, challenge-response authentication successful timestamp;
[0156] Finally, the 5G smart gateway organizes the above logs into a TXT format log file according to the fixed format of "timestamp-log type-log content", and uses the public network access domain AES-256 symmetric encryption key initialized in step S100.3 to perform encryption operation on the TXT format log file to generate an encrypted log packet.
[0157] Specifically, the 5G smart gateway uploads encrypted log packets to the security audit node deployed at the chain store headquarters through a dedicated encrypted channel for security audit (this channel is built based on the IPsec protocol and has been pre-established with the security audit node before the 5G smart gateway leaves the factory).
[0158] After receiving the encrypted log packet, the security audit node decrypts it using the same public network access domain AES-256 symmetric encryption key to obtain a TXT format log file.
[0159] The security audit node performs integrity checks on the log files by verifying whether the timestamps in the logs are continuous (ensuring that the logs have not been deleted or tampered with). If the verification is successful, the log files are stored in the security audit database, and a unique audit log ID is generated for the log files.
[0160] The security audit node sends a "network access process log synchronization successful" command to the 5G smart gateway. After receiving the command, the 5G smart gateway officially completes the smart network access process for the store gateway and enters the dual-domain smart networking ready state, which can then begin subsequent dual-domain data transmission and scheduling operations.
[0161] S300, Dynamic Construction of Dual-Domain Transmission Channels: Based on SD-WAN tunnel encapsulation technology, a dynamic optimization model integrating 5G link characteristics and SD-WAN tunnel performance is introduced to establish a 5G main link encrypted transmission channel for the business intranet domain and a 5G and 4G adaptive link transmission channel for the public network access domain; and to configure classification and identification rules for traffic in the business intranet domain and the public network access domain.
[0162] After the 5G smart gateway completes the S200 step for intelligent network access, the system automatically initiates the dual-domain traffic intelligent scheduling and security audit process. This process is based on the centralized control and distributed forwarding architecture of SD-WAN. Through a three-level mechanism of "traffic classification and labeling - dynamic path scheduling - real-time security auditing", it achieves traffic isolation, intelligent scheduling, and end-to-end security control between the business intranet domain and the public network access domain. The core technical details are consistent with the dual-domain identifiers, encryption strategies, and device characteristics defined in the S100 and S200 steps.
[0163] In this step, the construction and application process of the dynamic optimization model in S300 includes the following steps:
[0164] S310.1 Feature Parameter Mapping: The 5G smart gateway maps the feature parameters of the 5G link and the 4G link into influencing factors, including the packet loss rate influencing factor. Time delay impact factor Bandwidth Influence Factor ;
[0165] Specifically, the 5G smart gateway first activates the link characteristic parameter collection function, collecting basic performance parameters of the 5G and 4G links in real time: packet loss rate, latency, and current available bandwidth. Then, it converts these basic parameters into corresponding influencing factors according to preset mapping rules. Among these:
[0166] Packet loss rate influencing factors The mapping logic is: when the packet loss rate is ≤1%. When 1% < packet loss rate ≤ 3% When the packet loss rate is >3% ;
[0167] Delay Influence Factor The mapping logic is as follows: when the latency is ≤50ms When 50ms < delay ≤ 100ms When the latency is >100ms ;
[0168] Bandwidth Influence Factor The mapping logic is as follows: when available bandwidth ≥ 200Mbps When 100Mbps ≤ available bandwidth < 200Mbps When available bandwidth is less than 100Mbps ;
[0169] The mapping process is automatically executed by the parameter calculation unit built into the 5G smart gateway without manual intervention. The mapping results are stored in the gateway's link status cache in real time, and the update cycle is consistent with the parameter acquisition cycle (updated every 10 seconds).
[0170] S310.2 Comprehensive score calculation: based on preset weighting coefficients ,satisfy and The link comprehensive score is calculated through a dynamic optimization model. ;
[0171] Specifically, the cloud management platform pre-configures fixed weight coefficients for the dynamic optimization model. ,in (Weight of packet loss rate impact factor) (Weight of time delay impact factor) (Bandwidth impact factor weight), satisfying and The constraints are set based on the characteristics of chain store business (core business is more sensitive to packet loss rate and latency than bandwidth) and are synchronized to all 5G smart gateways through encrypted control channels.
[0172] Meanwhile, the scoring calculation unit of the 5G smart gateway retrieves the real-time packet loss rate influencing factor from the link state buffer. Time delay impact factor Bandwidth Influence Factor According to the formula Perform a comprehensive score calculation, in which The comprehensive link score (range 0~1.0) is calculated, and the gateway will then assign the 5G link comprehensive score. 4G link comprehensive score Along with the calculated timestamp, it is reported to the cloud management platform via a TLS 1.3 encrypted channel for use by subsequent links.
[0173] S310.3, Link Adaptive Selection: Setting a scoring threshold for public network access domains. When the 5G link comprehensive score When, prioritize 5G links; when When necessary, it automatically switches to the 4G link; the service intranet domain is fixed based on the comprehensive score of the 5G link. As a basis for determining the validity of the main link.
[0174] Specifically, the cloud management platform presets a comprehensive link scoring threshold for public network access domains. (This threshold is verified using historical transmission data from typical business operations such as e-commerce platform access, OA system interaction, and video surveillance backhaul within the public network access domain of chain stores over the past 12 months, ensuring that the link can meet the business requirements of the public network access domain when the score is ≥0.6), and synchronized to the 5G smart gateway; the 5G smart gateway compares the locally calculated data in real time. and :
[0175] when At this time, the gateway's link switching unit automatically schedules public network access domain traffic to the 5G link. At this time, the public network access domain transmission channel is built on the 5G link and adopts the AES-256 encryption algorithm consistent with the public network access domain encryption strategy in S100.3.
[0176] when When the link switching unit triggers the 4G link switching process, it first detects the connectivity of the 4G link through the ICMP protocol. After confirming the connectivity, it seamlessly switches the public network access domain traffic to the 4G link. During the switching process, a traffic caching mechanism is used to avoid data loss. After the switching is completed, the gateway sends a "link switching notification" to the cloud management platform.
[0177] For the business intranet domain, to ensure stable communication with the headquarters' core system, a 5G link is consistently used as the transmission channel, and the 5G smart gateway will... As a basis for determining the validity of the main link, when When the threshold for the validity of the intranet domain is reached, the gateway automatically initiates the 5G link failure repair process (such as restarting the 5G module and reconnecting to the 5G core network) and simultaneously triggers an alarm to the cloud management platform to ensure the continuous availability of the intranet domain transmission channel.
[0178] Furthermore, in the 5G link fault repair process, the 5G module is restarted by AT+CFUN=1,1 (the standard AT command in the field of mobile communication). When reconnecting, the challenge-response authentication process of the first network access is reused (that is, the cloud management platform issues a random challenge value, the 5G smart gateway encrypts the challenge value through the national cryptographic SM2 algorithm and returns a response, and the 5G secure connection is re-established after verification).
[0179] In this step, the configuration process of the classification and identification rules for traffic in the business intranet domain and the public network access domain in S300 includes the following steps:
[0180] S320.1, Tagging Mechanism Determination: A two-layer tagging mechanism of "VLANID + DSCP" is adopted. VLANID is used to distinguish between the business intranet domain and the public network access domain, and DSCP is used to tag the priority of different business traffic within the same domain.
[0181] Specifically, the system adopts a "VLANID+DSCP" two-layer marking mechanism. VLANID is used to distinguish between the business intranet domain and the public network access domain (achieving domain-level traffic isolation), while DSCP is used to mark the priority of different business traffic within the same domain (ensuring priority transmission of high-importance services). This two-layer marking mechanism is implemented through the hardware forwarding unit of the 5G smart gateway. The marking process does not occupy main CPU resources, and the single packet marking latency is controlled at the microsecond level to avoid affecting business transmission efficiency. Moreover, the marking rules are consistent with the dual-domain partitioning logic in S100 and the traffic scheduling priority rules in S230.4, ensuring the consistency of the technical solution.
[0182] S320.2, Business Intranet Domain Tagging Configuration: Assign a dedicated VLAN ID to business intranet domain traffic, and tag different business traffic within the domain with corresponding DSCP priorities according to business importance. The tagging rules are bound to the IP network segment of the headquarters core system.
[0183] Specifically, the cloud management platform assigns a dedicated VLAN ID=10 to the business intranet domain traffic (this VLAN ID is unique across the entire network and is associated with and bound to the business intranet domain VNI=1001), and configures DSCP priority for different business traffic within the domain based on business importance:
[0184] The chain store POS data synchronization business (communication with the headquarters POS system) has the highest priority and is marked as "101110" in DSCP (corresponding to EF class in DiffServ service level, ensuring low latency transmission).
[0185] The inventory system access service (communicating with the headquarters inventory management system) has the second highest priority and is marked as "010110" in DSCP (corresponding to AF31 class).
[0186] The ERP system access service (communication with the headquarters ERP system) has the third priority and is marked with "010010" in DSCP (corresponding to AF21 class).
[0187] The above marking rules are bound to the IP network segments of the headquarters core system (which are consistent with the IP network segments of the headquarters core system in S100.4) and stored in the rule base of the cloud management platform. The binding relationship is recorded in the form of a four-tuple of "IP network segment-service type-VLANID-DSCP" to ensure that the service traffic corresponding to each headquarters core system IP network segment can match the unique marking rule.
[0188] S320.3 Public network access domain labeling configuration: Assign a dedicated VLAN ID to public network access domain traffic, and label different service traffic within the domain with corresponding DSCP priority according to service importance. The labeling rules are bound to the preset Internet IP network segment.
[0189] Specifically, the cloud management platform assigns a dedicated VLAN ID=20 to public network access domain traffic (this VLAN ID is associated and bound to public network access domain VNI=2001, and does not overlap with the business intranet domain VLAN ID=10), and configures DSCP priority for different business traffic within the domain based on business importance:
[0190] The access business of the chain store office OA system (accessing the IP corresponding to the preset office domain name) has the highest priority and is marked as "001110" by DSCP (corresponding to AF11 class).
[0191] Temporary Wi-Fi access for customers (access to public internet services) has the next lowest priority and is marked with DSCP "000110" (corresponding to CS1 class).
[0192] The store advertising push service (accessing the advertising server) has the lowest priority and is marked as "000010" in DSCP (corresponding to BE class).
[0193] The above marking rules are bound to the preset Internet IP network segments (i.e., the IP addresses resolved by the preset Internet domain name whitelist in S100.5). The binding relationship is also stored in the rule base of the cloud management platform in the form of a four-tuple of "IP network segment-service type-VLANID-DSCP". The rule base is updated synchronously with the domain name resolution results every 24 hours to ensure that the marking rules are still effective after the IP network segment changes.
[0194] S320.4, Marking Execution: The 5G smart gateway performs real-time parsing of inbound data packets through its built-in hardware forwarding unit, and matches the corresponding marking rules based on the source and destination IP network segments and application types of the data packets to complete hardware-level automatic marking.
[0195] Specifically, after the 5G smart gateway is powered on, the built-in hardware forwarding unit automatically starts the data packet parsing function to capture all inbound data packets in real time (including terminal data packets accessed through the LAN port and terminal data packets accessed through Wi-Fi). The hardware forwarding unit first parses the source IP address and destination IP address of the data packet and matches the "IP network segment-service type-VLAN ID-DSCP" four-tuple rule issued by the cloud management platform: if the destination IP address belongs to the headquarters core system IP network segment (10.0.0.0 / 16), it is determined to be business intranet traffic and automatically adds VLAN ID=10 and the corresponding DSCP tag of the service.
[0196] If the destination IP address belongs to the preset Internet IP network segment, it is determined to be public network access domain traffic, and VLANID=20 and the corresponding DSCP tag of the service are automatically added; after the tag is completed, the hardware forwarding unit embeds the tag information into the Ethernet header (VLANID) and IP header (DSCP) of the data packet, and then forwards the data packet to the corresponding transmission channel (service intranet domain 5G channel or public network access domain adaptive channel).
[0197] If the IP address of a data packet does not match any preset network segment, the hardware forwarding unit marks it as "unauthorized traffic" and intercepts it, while recording the interception log to the gateway's local storage and periodically synchronizing it to the cloud management platform.
[0198] S400, Dual-Domain Traffic Intelligent Scheduling and Isolation: Through the SD-WAN intelligent scheduling engine, store terminal data is diverted to the corresponding domain's transmission channel based on traffic classification identifiers; a hardware-level isolation mechanism is used to achieve physical link isolation of dual-domain data;
[0199] After the 5G smart gateway completes the dynamic construction of the S300 dual-domain transmission channel, the system automatically initiates the S400 dual-domain traffic intelligent scheduling and isolation process. This process uses the SD-WAN intelligent scheduling engine as its core, achieves accurate traffic distribution based on the dual-domain traffic classification identifiers configured in the S300, and ensures strict isolation of dual-domain data at the physical link level through a hardware-level isolation mechanism.
[0200] In this step, the specific process of intelligent scheduling and isolation of dual-domain traffic in S400 includes the following steps:
[0201] S410.1 Traffic Identifier Matching: The SD-WAN intelligent scheduling engine performs real-time analysis on the received store terminal data, extracts the VLAN ID and DSCP tag in the data packet, and matches the business intranet domain or public network access domain to which the data packet belongs.
[0202] Specifically, the SD-WAN intelligent scheduling engine is integrated into the main chip of the 5G intelligent gateway and connected to the hardware forwarding unit via an internal high-speed bus. After the data from the store terminal enters the gateway, the hardware forwarding unit pushes the data packets to the scheduling engine in real time. The scheduling engine starts the data packet parsing module to extract the VLAN ID from the Ethernet header and the DSCP from the IP header. Then, it calls the built-in identifier mapping table (synchronized with the "VLAN ID-domain affiliation" rule issued by the S320 cloud management platform, recording the business intranet domain corresponding to VLAN ID=10 and the public network access domain corresponding to VLAN ID=20) to determine the domain to which the data packet belongs by matching the VLAN ID. If the VLAN ID is not recorded in the identifier mapping table, the scheduling engine marks the data packet as "illegal traffic" and intercepts it, while recording the interception time and source MAC address in the local log.
[0203] S410.2 Intra-domain channel routing: For traffic matched to the business intranet domain, the scheduling engine routes the traffic to the 5G main link encrypted transmission channel; for traffic matched to the public network access domain, it routes the traffic to the 5G and 4G adaptive link transmission channel, and allocates the transmission queue in the channel according to the DSCP priority.
[0204] Specifically, for traffic that has been matched to a domain, the scheduling engine distributes it by domain route, as follows:
[0205] Traffic matching the business intranet domain (VLANID=10) is forwarded to the 5G main link channel ingress buffer via the internal routing table (which is already bound to the 5G main link encrypted transmission channel built with S310.3), and then transmitted to the headquarters UPF node via the SD-WAN tunnel after being encrypted with SM4 (compliant with the S100.2 encryption policy).
[0206] Traffic from the public network access domain (VLANID=20) is matched and allocated into transmission queues based on DSCP tags: DSCP "001110" (office OA business) goes into the high-priority queue, "000110" (customer Wi-Fi business) goes into the medium-priority queue, and "000010" (ad push business) goes into the low-priority queue; the scheduling engine uses a weighted fair queue algorithm for scheduling, with high, medium, and low priority queues having weights of 50%, 30%, and 20% respectively, to ensure that high-importance services are transmitted first;
[0207] After routing is completed, the scheduling engine reports traffic distribution statistics to the cloud management platform every 5 minutes, including the traffic share of each domain and queue utilization rate.
[0208] S410.3 Hardware-level physical isolation implementation: The 5G smart gateway separates the physical transmission links of the business intranet domain and the public network access domain through a built-in dedicated isolation chip. The traffic of the business intranet domain is forwarded through the first set of independent MAC interfaces and corresponding physical ports of the main chip, while the traffic of the public network access domain is forwarded through the second set of independent MAC interfaces and corresponding physical ports of the main chip. The signal paths of the two sets of links have no cross connection at the hardware level.
[0209] Specifically, the 5G smart gateway has a built-in dedicated isolation chip connected to the main chip via a PCIe bus, supporting hardware-level signal isolation. This chip divides the physical transmission link into two independent channels: the first group is a dedicated link for the business intranet domain, consisting of the main chip's first independent MAC interface, the corresponding PHY chip, and physical ports, with independent PCB wiring, carrying only traffic with VLAN ID=10; the second group is a dedicated link for the public network access domain, consisting of the main chip's second independent MAC interface, the corresponding PHY chip, and physical ports, with independent PCB wiring, carrying only traffic with VLAN ID=20. The two links do not share signal amplification circuits or buffers. The dedicated isolation chip blocks signal interaction through hardware logic circuits, achieving no cross-connection at the physical layer.
[0210] S410.4 Isolation Status Verification: The 5G smart gateway periodically self-checks the signal isolation of the two physical links to ensure that data packets between the business intranet domain and the public network access domain are not leaked or mixed during transmission, and the verification results are synchronized to the cloud management platform.
[0211] Specifically, the isolation status verification module built into the 5G smart gateway starts a self-test every hour, generating two types of test data packets: one type, labeled VLANID=10, simulates traffic within the business intranet domain and is sent to the business intranet domain link through the first set of MAC interfaces, while monitoring whether the second set of MAC interfaces receives it; the other type, labeled VLANID=20, simulates traffic accessing the public network domain and is sent to the public network access domain link through the second set of MAC interfaces, while monitoring whether the first set of MAC interfaces receives it. If neither type of data packet is received on the non-corresponding link, the isolation is considered normal; if either type is received on the non-corresponding link, the isolation is considered abnormal. The verification result is synchronized to the cloud management platform through a TLS1.3 encrypted channel. When an abnormality occurs, the platform triggers an "isolation fault alarm" and generates an operation and maintenance work order. The gateway locally records the fault time, abnormal link identifier, and other information to the log.
[0212] S500, Dynamic Network Status Optimization: The cloud management platform collects link performance data of the transmission channel between the business intranet domain and the public network access domain in real time; when abnormal link performance is detected, the SD-WAN controller is triggered to reselect the path and adjust the parameters to complete the adaptive optimization of the transmission channel.
[0213] After the 5G smart gateway completes the intelligent scheduling and isolation of S400 dual-domain traffic, the system enters the S500 network status dynamic optimization phase. In this phase, through the collaboration of the cloud management platform and the SD-WAN controller, the performance of the dual-domain transmission channels is monitored in real time. In the event of link anomalies, an optimization mechanism is automatically triggered to ensure the stability and efficiency of dual-domain traffic transmission.
[0214] In this step, the specific process of dynamic network state optimization in S500 includes the following steps:
[0215] S510.1 Link Performance Data Collection: The 5G smart gateway collects link performance data of the transmission channel between the business intranet domain and the public network access domain in real time, including real-time latency, packet loss rate, and bandwidth utilization. After collection, the data is uploaded to the cloud management platform through an encrypted channel. The collection period is a preset fixed duration.
[0216] Specifically, the 5G smart gateway activates the link performance collection module to collect three types of core performance data for the 5G main link encrypted transmission channel in the business intranet domain and the 5G and 4G adaptive link transmission channel in the public network access domain: real-time latency (the round-trip time for a data packet to be sent from the gateway to the target node), packet loss rate (the proportion of data packets lost during transmission to the total number of data packets sent), and bandwidth utilization rate (the proportion of currently used bandwidth to the total available bandwidth of the link). The collection period is set to a preset fixed duration (consistent with the parameter collection period in S310, which is 10 seconds / time). After the collected data is cached locally by the gateway, it is uploaded to the cloud management platform in real time through the TLS1.3 encrypted channel (consistent with the data reporting channel in S310). The uploaded data packet is appended with the gateway sequence number and timestamp for data association and verification.
[0217] S510.2 Performance Anomaly Judgment: The cloud management platform continuously analyzes the received link performance data. When any of the following situations occur in the dual-domain link, it is judged as a performance anomaly: the packet loss rate or bandwidth utilization rate reaches or exceeds the corresponding preset threshold for multiple consecutive collection cycles, or the real-time latency reaches or exceeds the preset latency threshold.
[0218] Specifically, the cloud management platform's performance analysis module continuously analyzes the received dual-domain link performance data and determines abnormal states based on preset thresholds and business characteristics. Among these:
[0219] The thresholds for determining the business intranet domain are: packet loss rate ≥1%, bandwidth utilization rate ≥80%, and real-time latency ≥100ms;
[0220] The thresholds for judging public network access domains are: packet loss rate ≥3%, bandwidth utilization rate ≥90%, and real-time latency ≥200ms (the thresholds are set based on the different stability requirements of dual-domain services, and are consistent with the link scoring threshold logic in S310).
[0221] When any link in any domain experiences the following conditions, it is determined to be a performance anomaly: the packet loss rate or bandwidth utilization rate reaches or exceeds the corresponding threshold for three consecutive collection cycles (i.e., 30 seconds), or the real-time latency reaches or exceeds the corresponding threshold in a single instance; the determination result is stored in real time in the performance log library of the cloud management platform, and associated with the corresponding gateway identifier and timestamp.
[0222] S510.3 Adaptive Optimization Trigger: After performance anomaly is determined, the cloud management platform sends an optimization command to the SD-WAN controller to trigger adaptive optimization of the transmission channel;
[0223] Specifically, after determining that the link performance is abnormal, the cloud management platform immediately generates an optimization command. The command includes key information such as the domain identifier of the abnormal link (business intranet domain or public network access domain), the current abnormal performance parameter value, and the duration of the abnormality. At the same time, the optimization command is sent to the SD-WAN controller through an encrypted control channel (consistent with the weight coefficient synchronization channel in S310). Meanwhile, the cloud management platform marks the link as "optimizing" on the local status dashboard and records the command sending time.
[0224] S510.4 Path Reselection and Parameter Adjustment: The SD-WAN controller re-evaluates available links based on a dynamic optimization model and completes the transmission path reselection; at the same time, it dynamically adjusts tunnel encapsulation parameters to ensure that the new path is adapted to the characteristics of the current link.
[0225] Specifically, after receiving the optimization command, the SD-WAN controller calls the dynamic optimization model defined in S310 to re-evaluate the performance of available links: for abnormal links in the business intranet domain, the controller selects the link with the highest comprehensive score from the preset list of backup 5G links (consistent with the multi-link configuration in S100.3) as the new transmission path; for abnormal links in the public network access domain, the controller compares the comprehensive scores of the current 5G link and the 4G link, and selects the link with the higher score to complete the path switching.
[0226] Meanwhile, the controller dynamically adjusts tunnel encapsulation parameters: when the link packet loss rate is high, the MTU (Maximum Transmission Unit) of the SD-WAN tunnel is reduced to 1200 bytes (to avoid packet loss caused by fragmentation); when the latency is large, the tunnel TTL (Time to Live) value is increased to 64 (to ensure that packets are not prematurely dropped in long-latency links); parameter adjustments are calculated in real time based on the current performance data of the link to ensure adaptation to the characteristics of the new path.
[0227] S510.5 Optimization Result Feedback: After optimization, the SD-WAN controller will synchronize the new path information and parameter adjustment results to the cloud management platform. The cloud management platform will update the network status record and push it to the 5G smart gateway.
[0228] Specifically, after the path reselection and parameter adjustment are completed, the SD-WAN controller generates an optimization result report, which includes the link type of the new path (5G or 4G), the comprehensive score of the new path, the adjusted tunnel encapsulation parameter values, the optimization completion time, etc. The report is synchronized to the cloud management platform through an encrypted channel. The cloud management platform updates the new path information and parameter adjustment results to the network status database and associates them with the historical performance records of the corresponding gateway.
[0229] Meanwhile, the cloud management platform pushes a new path configuration command to the 5G smart gateway. After receiving the command, the gateway updates its local routing table and tunnel parameters to ensure that subsequent traffic is transmitted along the optimized path. The entire feedback process is completed within 10 seconds to avoid affecting business continuity.
[0230] This embodiment also provides a chain store dual-domain intelligent networking device based on 5G+SD-WAN, which is equipped with a chain store dual-domain intelligent networking system based on 5G+SD-WAN. When the computer program of the chain store dual-domain intelligent networking system based on 5G+SD-WAN is run, it is used to execute the steps of the chain store dual-domain intelligent networking method based on 5G+SD-WAN described above.
[0231] Those skilled in the art will understand that the process of implementing all or part of the steps of the above embodiments can be carried out by hardware or by a program instructing the relevant hardware.
[0232] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for dual-domain intelligent networking of chain stores based on 5G+SD-WAN, characterized in that, Comprise the following steps: S100, dual-domain security substrate construction: based on 5G security access protocol and SD-WAN virtualization technology, the business intranet domain and public network access domain of chain store are divided, the business intranet domain serves the communication between store and headquarters core system, and the public network access domain serves store terminal internet access; the encryption algorithm and access control rule of the business intranet domain and the public network access domain are initialized; S200, store gateway intelligent access: the 5G intelligent gateway deployed in the store completes access through a multi-level identity authentication system, specifically, the unique identity information generated by the hardware is submitted to the cloud management platform to complete the basic verification, after passing the dynamic scene verification and challenge-response authentication, the basic configuration parameters of the business intranet domain and the public network access domain networking are automatically obtained, and the authentication log of the whole process is synchronized to the security audit node; S300, dynamic construction of dual-domain transmission channel: based on SD-WAN tunnel encapsulation technology, a dynamic optimization model combining 5G link characteristics and SD-WAN tunnel performance is introduced, a 5G main link encrypted transmission channel is established for the business intranet domain, and a 5G and 4G adaptive link transmission channel is established for the public network access domain; the classification identification rules of the business intranet domain and the public network access domain traffic are configured; S400, dual-domain traffic intelligent scheduling and isolation: through the SD-WAN intelligent scheduling engine, the store terminal data is shunted to the transmission channel of the corresponding domain according to the traffic classification identification; the physical link isolation of dual-domain data is realized by using the hardware-level isolation mechanism; S500, dynamic optimization of network state: the cloud management platform collects the link performance data of the transmission channel of the business intranet domain and the public network access domain in real time; when the link performance is detected to be abnormal, the SD-WAN controller is triggered to perform path reselection and parameter adjustment, and adaptive optimization of the transmission channel is completed.
2. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S100, the business intranet domain and the public network access domain of chain store are divided, and the encryption algorithm and the access control rule of the business intranet domain and the public network access domain are initialized, comprising the following steps: S100.1, dual-domain division: a bottom layer security connection is established based on the 5G access layer security protocol defined by 3GPP; the SD-WAN controller is used to allocate a virtual network identifier VNI=1001 for the business intranet domain and a virtual network identifier VNI=2001 for the public network access domain, and the logical isolation of the business intranet domain and the public network access domain is realized based on the two VNI respectively; S100.2, business intranet domain encryption algorithm initialization: the SM4 symmetric encryption algorithm is used, and the key length is set to 128 bits; the key is encrypted by the cloud management platform through the SM2 asymmetric encryption algorithm and then sent to the chain store gateway, and the gateway stores the key in the security storage area of the built-in hardware encryption chip; S100.3, public network access domain encryption algorithm initialization: the AES-256 symmetric encryption algorithm is used, and the key is generated by the chain store gateway based on the built-in random number generator, and the key is automatically replaced every 24 hours; S100.4, Intra-business network domain access control rule initialization: based on network five tuple setting; only allow store local IP network segment to access headquarters core system IP network segment, and only open preset business port; S100.5, Public network access domain access control rule initialization: based on network five tuple setting; prohibit public network access domain traffic to access headquarters core system IP network segment; only allow access to IP addresses corresponding to preset Internet domain name whitelist, and limit the maximum bandwidth occupation value of single terminal in public network access domain to 100Mbps.
3. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S200, the generation process of the unique identity information generated by the hardware includes the following steps: S210.1, Information extraction: the 5G intelligent gateway extracts the device serial number SN and the 5G module international mobile equipment identity IMEI through the built-in national secret SM4 encryption chip, and collects the output characteristic value of the physical unclonable function PUF of the national secret SM4 encryption chip; S210.2, Hash fusion generates root key: the encryption chip performs hash fusion operation on the device serial number SN, 5G module IMEI code and PUF characteristic value to generate a unique hardware root key; S210.3, Key secure storage and access control: the hardware root key is stored in the non-rewritable secure storage area of the chip after being processed by the internal fuse mechanism of the chip, and only allowed to be called through the internal interface of the chip, and external instruction reading is prohibited.
4. The 5G+SD-WAN based dual-domain intelligent networking method for chain stores according to claim 3, characterized in that, In the S200, the specific process of dynamic scene verification includes the following steps: S220.1, Position information collection: the 5G intelligent gateway collects real-time longitude and latitude data through the built-in GPS module, and uploads it to the cloud management platform through an encrypted channel; S220.2, Position deviation verification: the cloud management platform calculates the difference between the received longitude and latitude data and the pre-stored store preset position longitude and latitude, and when the absolute value of the deviation is within the preset threshold range, the position verification passes; S220.3, Device running state data collection: the 5G intelligent gateway collects real-time running state data, including CPU temperature, memory occupancy and SHA256 hash value of gateway operating system image; S220.4, Health state benchmark verification: the cloud management platform verifies that the CPU temperature, memory occupancy meet the preset safety baseline, and the gateway operating system image hash value is consistent with the pre-stored benchmark value, and the health state verification passes; S220.5, Dynamic scene verification result determination: after the position verification and health state verification pass, the dynamic scene verification is completed.
5. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 4, wherein, In the S200, the process of challenge-response authentication and configuration parameter acquisition, log synchronization includes the following steps: S230.1, challenge code generation and encryption issue: the cloud management platform generates a preset length of binary challenge code through an encrypted random number generator , and sends it to the 5G intelligent gateway through a TLS encrypted channel; S230.2, hardware level response value calculation: 5G intelligent gateway calls built-in national secret SM4 encryption chip, reads the hardware root key of the security storage area , executes SM4 encryption algorithm on " through the internal operation unit of the chip to generate response value and feedback to the cloud management platform through the encryption channel; S230.3, response value consistency verification: the cloud management platform calls the locally stored hardware root key copy, performs the same SM4 encryption operation as the 5G intelligent gateway, and if the local calculation result is consistent with the received response value , the challenge-response authentication is passed; S230.4, Dual-domain networking parameter pushing: after authentication, the cloud management platform pushes the networking basic configuration parameters of the business intranet domain and the public network access domain to the 5G intelligent gateway, including the VNI identifier of the dual-domain, the tunnel encapsulation format, the encryption algorithm key parameter and the traffic scheduling priority; S230.5, Full-process log encryption synchronization: After the 5G intelligent gateway completes the local writing of the configuration parameters, the basic verification records, dynamic scene verification results, and key data of the challenge-response authentication process are packaged and synchronized to the security audit node through a secure audit special encryption channel.
6. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 5, wherein, In the S300, the construction and application process of the dynamic optimization model includes the following steps: S310.1, feature parameter mapping: the 5G intelligent gateway respectively maps feature parameters of the 5G link and the 4G link into influence factors, including a packet loss rate influence factor , a time delay influence factor , and a bandwidth influence factor ; S310.2, comprehensive score calculation: based on preset weight coefficient , meet and , the link comprehensive score is calculated by a dynamic optimization model ; S310.3, link adaptation selection: set score threshold for public network access domain When the 5G link comprehensive score , the 5G link is preferentially selected; when , automatically switch to the 4G link; the service intranet domain is fixed to the comprehensive score of the 5G link as the main link validity determination basis.
7. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 6, wherein, In the S300, the configuration process of the classification and identification rules of the traffic in the intranet domain and the public network access domain includes the following steps: S320.1, Marking mechanism determination: A "VLANID+DSCP" double-layer marking mechanism is adopted, VLANID is used to distinguish the intranet domain and the public network access domain, and DSCP is used to mark the priority of different service traffic in the same domain; S320.2, Intranet domain marking configuration: The intranet domain traffic is allocated with a dedicated VLANID, and different service traffic in the domain is marked with corresponding DSCP priority according to the service importance, and the marking rule is bound with the headquarters core system IP network segment; S320.3, Public network access domain marking configuration: The public network access domain traffic is allocated with a dedicated VLANID, and different service traffic in the domain is marked with corresponding DSCP priority according to the service importance, and the marking rule is bound with the preset Internet IP network segment; S320.4, Marking execution: The 5G intelligent gateway performs real-time analysis on the inbound data packet through the built-in hardware forwarding unit, matches the corresponding marking rule according to the source and destination IP network segment and application type of the data packet, and completes the automatic marking at the hardware level.
8. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S400, the specific process of intelligent scheduling and isolation of dual-domain traffic includes the following steps: S410.1, Traffic identification matching: The SD-WAN intelligent scheduling engine performs real-time analysis on the received store terminal data, extracts the VLANID and DSCP marking in the data packet, and matches the business intranet domain or public network access domain to which the data packet belongs; S410.2, In-domain routing: For traffic matched to the intranet domain, the scheduling engine routes the traffic to the 5G main link encryption transmission channel; For traffic matched to the public network access domain, route to the 5G and 4G adaptive link transmission channel, and allocate transmission queues in the channel according to the DSCP priority; S410.3, Hardware-level physical isolation implementation: The 5G intelligent gateway separates the physical transmission links of the intranet domain and the public network access domain through the built-in special isolation chip; S410.4, Isolation state verification: The 5G intelligent gateway periodically checks the signal isolation degree of the two physical links, and the verification result is synchronized to the cloud management platform.
9. The 5G+SD-WAN based multi-chain store dual-domain intelligent networking method of claim 1, wherein, In the S500, the specific process of dynamic optimization of network state includes the following steps: S510.1, Link performance data collection: The 5G intelligent gateway collects the link performance data of the transmission channel of the intranet domain and the public network access domain in real time, including real-time delay, packet loss rate, and bandwidth occupancy rate. After the collection is completed, it is uploaded to the cloud management platform through an encrypted channel, and the collection period is a preset fixed time length; S510.2, Performance anomaly determination: the cloud management platform continuously analyzes the received link performance data, and determines that the performance is abnormal when any of the following conditions occurs in the dual-domain link: the packet loss rate or bandwidth occupancy rate reaches or exceeds the corresponding preset threshold for consecutive multiple collection periods, or the real-time time delay reaches or exceeds the preset time delay threshold; S510.3, Adaptive optimization triggering: after the performance anomaly determination, the cloud management platform sends an optimization instruction to the SD-WAN controller to trigger adaptive optimization of the transmission channel; S510.4, Path reselection and parameter adjustment: the SD-WAN controller re-evaluates the available links based on the dynamic optimization model to complete the transmission path reselection; at the same time, dynamically adjusts the tunnel encapsulation parameters to ensure that the new path adapts to the current link characteristics; S510.5, Optimization result feedback: after the optimization is completed, the SD-WAN controller synchronizes the new path information and parameter adjustment result to the cloud management platform, and the cloud management platform updates the network state record and pushes it to the 5G intelligent gateway.
10. A 5G+SD-WAN-based dual-domain intelligent networking device for chain stores, loaded with a 5G+SD-WAN-based dual-domain intelligent networking system for chain stores, characterized in that, The computer program of the 5G+SD-WAN-based dual-domain intelligent networking system for chain stores is used to execute the steps of the 5G+SD-WAN-based dual-domain intelligent networking method for chain stores according to any one of claims 1-9.
Citation Information
Patent Citations
Network attack defense method and device, electronic equipment and storage medium
CN117955675A
Security protection system, method, device, equipment, storage medium and program product
CN119603025A