Customized network interface card oriented to intranet security access and design method thereof
By embedding client certificates and private keys in the network interface card and integrating the EAP-TLS module, the problem of insufficient hardware-level automation support in secure intranet access is solved, achieving highly secure and automated intranet access authentication, suitable for enterprise-level network environments.
Patent Information
- Application Number
- CN202511386870.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-26
- Publication Date
- 2025-12-12
AI Technical Summary
Existing network interface cards lack hardware-level automation support for secure intranet access, resulting in a complex authentication process that is susceptible to insufficient human intervention or configuration errors, making it difficult to meet the high security requirements of enterprise or carrier-grade networks.
By embedding client certificates and private keys into the network interface card and storing the certificates, keys, and related sensitive data in a protected non-volatile area, and integrating the EAP-TLS client module, automated TLS handshake and certificate verification at the hardware level are achieved, reducing reliance on the software level.
It improves the reliability and anti-attack capabilities of device authentication, reduces the complexity of manual configuration, and enhances the security and automation level of intranet access, making it suitable for intranet environments with high security requirements, such as enterprise data centers and financial institutions.
Smart Images

Figure CN121125282A_ABST
Abstract
Description
Technical Field
[0001] This invention discloses a customized network interface card (NIC) and its design method for secure intranet access. The NIC embeds a client certificate and corresponding private key, storing the certificate, key, and related sensitive data in a protected non-volatile area as a unique identifier for users accessing the network. Based on its data transmission and reception functions, the NIC integrates an EAP-TLS client module, enabling automatic TLS handshake and certificate verification with the authentication gateway, achieving automated authentication interaction on the device side. This design integrates basic NIC business functions, certificate management, and protocol authentication processes, ensuring both the unique reliability of the NIC's identity and improving the security and automation of the access authentication process. It is suitable for enterprise / carrier-level intranet access control and security management, possessing significant application value and economic benefits. It belongs to the field of intranet security authentication technology. Background Technology
[0002] A Network Interface Card (NIC) is a core hardware component for computers or devices to access a network. It is responsible for implementing network communication functions at the physical and data link layers, including the sending and receiving of data frames. As the primary link in network access, the security of the NIC directly determines the strength of the first line of defense for intranet security. In traditional network environments, NIC design primarily focuses on performance optimization, hardware compatibility, and data transmission efficiency. However, with the increasing complexity of network security threats, especially the constantly evolving attack methods targeting intranet environments, traditional NIC designs are no longer sufficient to meet the high security requirements of enterprise or carrier-grade networks. Secure intranet access involves critical mechanisms such as device authentication, encrypted data transmission, and prevention of unauthorized access. Authentication schemes relying solely on software are vulnerable to malware tampering, physical attacks, side-channel attacks, or social engineering attacks, potentially leading to device identity forgery, sensitive information leakage, or network service interruption.
[0003] EAP-TLS (Extensible Authentication Protocol-TLS), an extension of Transport Layer Security (TLS), is a certificate-based two-way authentication protocol widely used in authentication interactions across wireless and wired networks, providing a standardized solution for secure communication. However, existing EAP-TLS implementations suffer from several drawbacks. Some rely on host-side software processing, lacking automated hardware support; others have critical credentials and authentication logic scattered across multiple software and hardware modules, lacking a unified hardware platform. This not only increases deployment and maintenance complexity but also limits the overall improvement in security. This reliance leads to a complex and inefficient authentication process, especially during device restarts, network fluctuations, or large-scale device management scenarios, where authentication may be interrupted due to insufficient human intervention or configuration errors.
[0004] Protected non-volatile storage (NVS) is a storage technology that retains data after power loss and features advanced security mechanisms to prevent unauthorized access or tampering. Through encryption, access control, and tamper-proof design, it is widely used in security chips, IoT devices, and mobile devices to protect sensitive data such as keys and certificates. Despite higher cost and performance overhead, it provides high security and reliability for mission-critical applications.
[0005] Due to the complexity of secure intranet access, the limitations of existing technologies, and the involvement of humans during the access process, existing solutions are prone to problems such as leakage of critical authentication information and unauthorized user forgery. Therefore, this invention proposes a customized network interface card (NIC) design method for high-security requirements. This method achieves seamless integration of hardware physical protection and automated authentication by embedding digital certificates, private keys, and flash encryption mechanisms in protected non-volatile storage and integrating an EAP-TLS authentication module. Compared to traditional NICs, this design significantly improves the reliability and attack resistance of device authentication, reduces reliance on the software layer, and lowers the complexity of manual configuration. This technology is particularly suitable for intranet environments with extremely high security requirements, such as enterprise data centers, financial institutions, and government agencies, and can effectively improve the security management level and operational efficiency of network systems.
[0006] In summary, this invention provides an innovative intranet security access solution that combines hardware-level security authentication with efficient management through customized NIC design. This technology has broad application prospects, is adaptable to various network devices, and not only improves the security and automation level of intranet access but also provides strong support for network system stability. In both academic research and industrial applications, this technology has significant theoretical and practical value, providing a novel technical path for the future development of intranet security authentication. Summary of the Invention
[0007] This invention provides a network interface card for autonomous access authentication, which aims to effectively achieve hardware-level authentication of device identity, protection of sensitive data, and automated access interaction, prevent physical attacks and protocol vulnerabilities, and ensure intranet security.
[0008] This invention provides a customized network interface card design method for secure intranet access, comprising: The client certificate and corresponding private key are embedded inside the network card, and the certificate, key and related sensitive data are stored in a protected non-volatile area; the EAP-TLS client module is integrated on the basis of its data transmission and reception function, and the hardware level realizes automated TLS handshake and certificate verification with the authentication gateway.
[0009] The steps for embedding the client certificate and corresponding private key include: generating or importing the client certificate and private key pair; writing the certificate, private key, and related sensitive data (such as configuration parameters) into the non-volatile storage area of the network card, and setting access control permissions to ensure that only authorized firmware can read them.
[0010] The steps for integrating the EAP-TLS client module include: embedding the EAP-TLS protocol stack based on the network card firmware framework; implementing the TLS handshake logic on the client side, including certificate exchange, key negotiation, and authentication; and interacting with the authentication gateway to achieve automated authentication on the device side without host software intervention. In a real-world environment, this requires configuration with a router and RADIUS server, such as setting the router's WiFi to WPA-EAP mode, specifying the RADIUS IP address and shared secret, and enabling TLS configuration and generating certificates in RADIUS.
[0011] A customized network interface card for secure intranet access, which applies the above-mentioned design method for customized network interface cards for secure intranet access, also includes a custom network card.
[0012] The customized network interface card design method for secure intranet access proposed in this invention has the following advantages compared with existing methods: 1. Enhanced security for intranet access. The identity identifier is fully bound to the network interface card (NIC), making the NIC the sole credential for accessing the intranet. Only devices using this NIC can successfully connect to the intranet, strictly limiting intranet access.
[0013] 2. Achieve automated and efficient network access. Integrating the EAP-TLS module into the network interface card (NIC) eliminates the need for manual intervention in the authentication process, improving the automation level of intranet access and making it suitable for large-scale deployment scenarios such as enterprise intranet environments. Optimized identity management avoids security risks associated with the management side.
[0014] 3. Highly compatible, fully compatible with existing systems, and can be deployed and used immediately. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of the system architecture of the present invention, which includes: a client (101), a custom network card (102), an authentication gateway (103), and an intranet (104). Figure 2 The internal module structure diagram of the custom network card includes: host control logic (201), TinyUSB driver module (202), Wi-Fi control module (203), NVS configuration storage module (204), and EAP-TLS protocol module (205). Figure 3 A schematic diagram of the workflow for a customized network interface card for secure intranet access; Figure 4 Pseudocode for the algorithm used to build a custom network card based on the ESP32S3 development board. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of this invention clearer and more understandable, the invention will be described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0017] To provide effective and comprehensive hardware-level protection for secure intranet access, this invention provides a customized network interface card design method for secure intranet access. Figure 1 This is a general schematic diagram illustrating the workflow of the customized network interface card for secure intranet access proposed in this invention, specifically including: Initialize hardware access control mechanisms and integrate non-volatile memory permission management access verification and protection mechanisms to protect certificates and private keys from the hardware level.
[0018] Specifically, a non-volatile storage partition is initialized in the network interface card (NIC) to store client certificates, private keys, and network configuration parameters. This partition should be protected by hardware access control, allowing firmware to read and write only via a dedicated API to prevent unauthorized access. Before loading the certificate and private key, the firmware performs an integrity check on this partition, calculating the hash value of the stored data and comparing it with a pre-stored value. If the check fails, indicating that the data may have been tampered with, the NIC aborts loading and enters a secure failure mode.
[0019] EAP-TLS authentication is performed, and the network card automatically interacts with the authentication server through the intranet gateway. Only when both authentications are successful will the network card successfully access the intranet.
[0020] Specifically, the network interface card (NIC) firmware embeds a lightweight EAP-TLS protocol stack, supporting TLS 1.2 / 1.3 protocols and optimizing memory usage for embedded environments. The protocol stack should include certificate parsing, key negotiation, and encrypted communication functions. During authentication, the NIC initiates a TLS handshake, sending a ClientHello message to the authentication gateway, containing supported cipher suites and the client certificate. The gateway responds with a ServerHello message, sending the server certificate and requesting client certificate verification. The NIC completes certificate exchange and key negotiation, generating a session key.
[0021] The authentication gateway forwards client certificates to the RADIUS server for authentication via the RADIUS protocol. The server verifies the certificate chain, ensuring the certificate was issued by a trusted CA, and checks if the device's identity is on the authorized list. If verification succeeds, the gateway returns Access-Accept, granting the network interface card (NIC) network access; otherwise, it returns Access-Reject, the NIC logs the failure, and attempts to reconnect.
[0022] Data transmission and reception are continuously monitored; the network card enters normal data transmission and reception mode; network connection status is monitored in real time; and anomalies are handled.
[0023] Specifically, after successful authentication, the network interface card (NIC) performs general physical layer and data link layer data frame processing and monitors the transmission and reception status of data packets. If an anomaly is detected, the buffer is cleared, the NIC is reinitialized, the network is reconnected, and the authentication process is repeated.
[0024] In this embodiment, the network card is implemented based on the ESP32 microcontroller (MCU) and the ESP-IDF development framework.
[0025] It should be noted that the ESP32 series MCUs are high-performance embedded processing chips independently developed by Espressif Systems. They have native Wi-Fi wireless communication capabilities, stable multi-tasking performance, and rich peripheral interfaces, which can meet the core requirements of network cards for data processing and wireless connectivity. As the official supporting development framework for this series of MCUs, ESP-IDF supports developers to write firmware programs, develop hardware drivers, and customize functions using the C language, providing underlying technical support for the modular design and flexible expansion of network cards.
[0026] Figure 2 This is pseudocode for the firmware algorithm used to build a customized network interface card (NIC) based on the ESP32S3 development board, and it is also the NIC design algorithm used in this invention. Figure 2 As shown, the main process of the algorithm can be summarized as follows: (1) Prioritize the activation of hardware-level security mechanisms, including completing the initialization of the NVS (non-volatile storage) module (used for persistent storage of Wi-Fi configuration, encryption credentials, client private keys and certificates, and other key data) and the initialization of the TinyUSB driver (providing driver support for the USB-NET virtual network interface); finally, configure the working parameters of the Wi-Fi module and the network parameters of the USB-NET interface, start the Wi-Fi network connection process, and complete the network card function readiness preparation.
[0027] (2) Handle Wi-Fi events, including STA_START (read MAC address), STA_CONNECTED (register RX callback), and STA_DISCONNECTED (unregister callback and reconnect). This establishes a Wi-Fi data transmission channel to the USB interface and ensures network connectivity continuity.
[0028] (3) Configure SSID and EAP-TLS credentials, perform network connection, and handle timeout and failure scenarios.
[0029] (4) Establish a bidirectional data forwarding channel between the Wi-Fi interface and the USB-NET interface, and optimize data transmission efficiency through strategies such as data packet fragmentation and reassembly and dynamic adjustment of transmission buffer; at the same time, introduce a data verification mechanism (such as CRC verification) to perform integrity checks on data packets during the forwarding process. If data errors are found, a retransmission mechanism is triggered to ensure data transmission reliability and avoid network communication anomalies caused by data loss or damage.
[0030] The technical solution of this invention can be dynamically adjusted through hardware and firmware, and the specific implementation depends on the application scenario and system constraints. For example, in high-performance scenarios, the encryption algorithm can be upgraded (e.g., an algorithm with a longer key) or more complex TLS encryption suites can be supported; in resource-constrained scenarios, protocol stack functions can be trimmed to reduce memory usage. Those skilled in the art can adjust parameters or steps according to actual needs, such as optimizing key length, adjusting retry strategies, or expanding logging functions; all such improvements fall within the scope of protection of this invention.
[0031] The implementation examples listed in this document are intended to illustrate the implementation of this technical solution through specific application scenarios, rather than to limit the scope of patent protection. It should be specifically noted that, based on the innovative core of this technical solution, those skilled in the art, within the scope of existing technical knowledge, may make adaptive adjustments to the implementation schemes, including but not limited to the optimization of technical parameters, reasonable changes to implementation steps, or equivalent conversions of technical features. Such reasonable evolutions and improvements based on the essence of this technical solution are all considered to have not departed from the design concept and protection boundaries of this patent. The final legal protection scope is subject to the definition of the claims approved by the State Intellectual Property Office.
Claims
1. A method for designing a customized network interface card for intranet security access, characterized in that: the client certificate is strictly bound to the network card device, and the client certificate and the corresponding private key are embedded in the non-volatile storage module inside the network interface card; the EAP-TLS protocol stack module is integrated on the basis of the data transceiving function of the network interface card, and the TLS handshake and certificate verification are automatically completed with the authentication gateway to realize the automatic authentication interaction of the device end.
2. The customized network interface card design method for Intranet security access according to claim 1, further characterized by, The client certificate and the corresponding private key are embedded in the network interface card, and the content includes: relying on the PKI to generate or import the client certificate and the private key pair; writing the certificate, the private key and related sensitive data into the NVS parameter storage area.
3. The customized network interface card design method for Intranet security access according to claim 1, further characterized by, The EAP-TLS protocol stack module is integrated in the network interface card firmware framework, including: embedding the EAP-TLS protocol stack in the network interface card firmware framework to support certificate parsing, key negotiation and encrypted communication of the TLS protocol; realizing the TLS handshake logic on the client side to support EAP-TLS bidirectional authentication.
4. The customized network interface card design method for intranet security access according to claim 1, further characterized by, The data transceiving function and the continuous monitoring step are realized by the cooperation of the main control logic module, including: after successful authentication, performing data frame transceiving processing of the physical layer and the data link layer; communicating with the client through the WiFi control module and the TinyUSB drive interface module to monitor the network connection state in real time and detect abnormal data packets or connection interruption; if an abnormality is detected, clearing the buffer, reinitializing and repeating the authentication process.
5. A customized network interface card for Intranet security access, characterized in that, The above-mentioned method for designing a customized network interface card for intranet security access further includes a self-defined network card (102).
Citation Information
Patent Citations
Security assessment method for wireless local area network card based on penetration test
CN102905256A
Message transmission method and device
CN116743455A
Method and system for simplifying remote authentication of trusted execution environment by using digital certificate authentication, and medium
CN117097487A
Scalable key state for network encryption
CN118381621A
Data encryption transmission method based on zero-trust architecture
CN119966746A
Cited By
Client-free authentication method and system based on network card firmware
CN122027367A