Method for authorizing genuine software and related equipment
By verifying the terminal address and generating a genuine software license certificate in the IPv6 network, and combining national cryptographic acceleration and protocol adaptation, the problem of software license failure in the IPv6 environment is solved, and stable operation and secure access of software in dynamic networks are achieved.
Patent Information
- Application Number
- CN202511160261.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2025-12-12
AI Technical Summary
In IPv6 networks, existing software licensing mechanisms have failed due to dynamic changes in terminal addresses and compatibility issues between domestic operating systems and the IPv6 protocol stack, resulting in the failure of genuine software binding and impacting production efficiency and network stability.
By receiving encrypted messages from domestically developed terminals, the system verifies and generates a verification terminal IPv6 address, binds it to the encrypted message, generates a software genuine authorization certificate, and uses a national cryptographic acceleration engine for encryption. Combined with dynamic prefix generation and protocol adapter, the system performs anomaly detection and adjustment to ensure the legitimate operation of the software in the IPv6 network.
It achieves stable and genuine software licensing in IPv6 networks, prevents unauthorized devices from accessing the network, improves network security and production efficiency, and is compatible with the IPv6 protocol stack of domestic operating systems, ensuring the normal use of software in dynamic network environments.
Smart Images

Figure CN121125690A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of software genuine authorization, in particular to a genuine software authorization method and related equipment. BACKGROUND
[0002] Under the background of accelerating the development of the China-specific industry, IPv6, as the core protocol of the next generation of Internet, faces multiple technical barriers in its integration with China-specific technology. These barriers not only restrict the security and efficiency of China-specific networks, but also become a key bottleneck hindering the industrial scale application. Currently, the integration of the China-specific industry and IPv6 technology mainly exists problems of invalidation of genuine binding and compatibility defects of domestic OS.
[0003] For the problem of invalidation of genuine binding, the traditional software authorization mechanism mostly uses MAC address as the unique identifier, but in the IPv6 network, the dynamic change of terminal address makes this mechanism completely out of control. According to the RFC4941 privacy extension standard, the terminal device generates a new temporary IPv6 address every 24 hours, with a change rate of more than 70%; and multi-host devices (such as dual-network card industrial computers) can have more than 8 temporary addresses at the same time, with an address switching frequency of minutes. In a test in a certain intelligent manufacturing park, the genuine CAD software based on MAC binding had an authorization invalidation rate of up to 68% due to address changes, and each device needed to be reactivated 3.2 times per day on average, which seriously affected production efficiency.
[0004] For the problem of compatibility defects of domestic OS, domestic operating systems such as UOS and Kylin V10 have some differences in the implementation of IPv6 protocol stack compared with international standards. In the process of network communication, they often do not send DHCPv6 request messages in standard format. This is determined by the research and development background, technical route of domestic operating systems and the special needs of China-specific environment. In the development process of domestic operating systems, more consideration is given to security strategies, hardware adaptation and other factors in the China-specific environment, and some targeted adjustments and optimizations may be made in the implementation of protocols, resulting in deviations in the DHCPv6 request messages sent from the standard format. SUMMARY
[0005] Therefore, the purpose of the present application is to provide a genuine software authorization method and related equipment.
[0006] To achieve the above purpose, the first aspect of the present application provides a genuine software authorization method, comprising: receiving an encrypted message sent by a China-specific terminal, and verifying the encrypted message. In response to successful verification of the encrypted message, generating a verification terminal IPv6 address corresponding to the encrypted message. Binding the verification terminal IPv6 address with the encrypted message to obtain a software genuine authorization certificate. Sending the software genuine authorization certificate to the China-specific terminal.
[0007] In some embodiments, the method further comprises: in response to the encryption message verification failure, receiving a network prefix sent by the prefix generator. Modifying the encryption message according to the network prefix to obtain an updated encryption message. Generating an updated terminal IPv6 address corresponding to the updated encryption message. Binding the updated terminal IPv6 address with the updated encryption message to obtain a software legalization authorization certificate.
[0008] In some embodiments, after sending the software legalization authorization certificate to the Xingcheng terminal, the method further comprises: sending a verification request to the Xingcheng terminal to make the Xingcheng terminal return corresponding signature verification information. Verifying the signature verification information, and in response to the signature verification information verification failure, revoking the software legalization authorization certificate corresponding to the signature verification information.
[0009] The second aspect of the present application provides a software legalization authorization method, comprising: generating software fingerprint information according to installation information of the legalized software, and constructing message information according to the fingerprint information and state information of the Xingcheng terminal. Receiving an encryption key sent by a national secret acceleration engine, encrypting the message information according to the encryption key to obtain encrypted message information. Sending the encrypted message information to a prefix delegation server to make the prefix delegation server output a corresponding software legalization authorization certificate. Running the legalized software according to the legalization authorization certificate.
[0010] In some embodiments, after sending the encrypted message information to the prefix delegation server to make the prefix delegation server output the corresponding software legalization authorization certificate, the method further comprises: obtaining a verification terminal IPv6 address according to the legalization authorization certificate. Network is constructed according to the verification terminal IPv6 address.
[0011] The third aspect of the present application provides a software legalization authorization method, comprising: sniffing a message sent by an authorized Xingcheng terminal to obtain message sniffing information. Identifying the message sniffing information, and in response to the message sniffing information being abnormal, performing feature matching on the abnormal message sniffing information to obtain abnormal detection information. Identifying the system type of the abnormal Xingcheng terminal to obtain system type information. Adjusting a router advertisement message of the Xingcheng terminal according to the system type information and the abnormal detection information to obtain an adjusted message. Sending the adjusted message to the Xingcheng terminal to make the Xingcheng terminal network according to the adjusted message.
[0012] In some embodiments, after the feature matching on the abnormal packet sniffing information, the abnormal detection information is obtained, and the method further comprises: in response to the abnormal XG endpoint sending a DHCPv6 request in a stateless environment, allocating a special IPv6 address for the abnormal XG endpoint, and limiting the access address range of the abnormal XG endpoint. Recording the device information of the abnormal XG endpoint, and identifying the device information. In response to the abnormal XG endpoint being able to repair the abnormality through firmware update, pushing a firmware patch to the abnormal XG endpoint.
[0013] The application also provides a prefix delegation server, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method of any one of the above when executing the program.
[0014] The application also provides an XG terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method of any one of the above when executing the program.
[0015] The application also provides an agent service layer, comprising a national secret acceleration engine, a dynamic prefix generator, a genuine binding module, and a protocol adapter, for implementing the method of any one of the above. The national secret acceleration engine is configured to generate an encryption key according to a preset encryption algorithm, and send the encryption key to the XG terminal in response to the XG terminal sending an encryption request. The dynamic prefix generator is configured to generate and send a network prefix to the prefix delegation server in response to the prefix delegation server failing to verify the encrypted packet. The genuine binding module is configured to bind the verification terminal IPv6 address and the encrypted packet to obtain a software genuine authorization certificate. The protocol adapter is configured to perform feature matching on abnormal packet sniffing information in response to the packet sniffing information being abnormal, to obtain abnormal detection information. Identifying the system type of the abnormal XG terminal to obtain system type information. According to the system type information and the abnormal detection information, adjusting the router advertisement packet of the XG terminal to obtain an adjusted packet. Sending the adjusted packet to the XG terminal, so that the XG terminal groups according to the adjusted packet.
[0016] As can be seen from the above, the software genuine authorization method provided by the application verifies the encrypted packet sent by the XG terminal, and allocates a verification terminal IPv6 address to the XG terminal corresponding to the encrypted packet that passes the verification, so as to prevent unauthorized devices from accessing the network, and the verification terminal IPv6 address and the encrypted packet are bound as a software genuine authorization certificate, avoiding the use of device MAC address, so as to realize the software genuine authorization in the IPv6 network. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the application or the related art, the drawings needed to be used in the embodiments or the related art description will be briefly introduced. Obviously, the drawings in the following description are only embodiments of the application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.
[0018] Figure 1 A flowchart of a software authorization method for legal version provided by an embodiment of the application is shown in the figure.
[0019] Figure 2 A structure diagram of a software legal version authorization system architecture provided by an embodiment of the application is shown in the figure.
[0020] Figure 3 A flowchart of a China software terminal startup provided by an embodiment of the application is shown in the figure.
[0021] Figure 4 A structure comparison diagram of a packet generated by an optimized method according to the application and a packet generated by a traditional method is shown in the figure. DETAILED DESCRIPTION
[0022] In order to make the purpose, technical solutions and advantages of the application more clear, the application will be further described in detail below with reference to specific embodiments and drawings.
[0023] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the application should be understood as the usual meaning understood by those skilled in the art in the field to which the application belongs. The terms "first", "second" and similar terms used in the embodiments of the application do not represent any order, quantity or importance, but are only used to distinguish different components. The terms "include" or "contain" and similar terms mean that the elements or objects before the terms cover the elements or objects listed after the terms and their equivalents, and do not exclude other elements or objects. The terms "connect" or "connect" and similar terms are not limited to physical or mechanical connection, but can include electrical connection, whether direct or indirect. The terms "up", "down", "left", "right" and the like are only used to represent relative positional relationship, and when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0024] It can be understood that, before using the technical solutions of various embodiments in the present disclosure, the user will be informed of the type, use range, use scenario and the like of the personal information involved by appropriate means, and the authorization of the user will be obtained.
[0025] For example, in response to receiving an active request of a user, a prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed will need to acquire and use personal information of the user. Thus, the user can autonomously select whether to provide the personal information to the software or hardware performing the operation of the technical solution of the present disclosure according to the prompt information.
[0026] As an optional but non-limiting implementation manner, in response to receiving an active request of a user, the manner of sending a prompt information to the user may, for example, be a pop-up window manner, and the prompt information may be presented in a text manner in the pop-up window. In addition, the pop-up window may also carry a selection control for the user to select “agree” or “disagree” to provide the personal information to the electronic device.
[0027] It can be understood that the above notification and acquisition of user authorization process is only illustrative, and does not limit the implementation manner of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0028] China Secure: information technology application innovation refers to the national strategic action of realizing core software and hardware localization and security controllability.
[0029] SLAAC: Stateless Address Autoconfiguration, IPv6 terminal generates address according to route announcement (RA) autonomously, without the participation of DHCP server.
[0030] IA_PD: Identity Association for Prefix Delegation, a DHCPv6 option defined in RFC3633, used to delegate IPv6 prefix to client (such as router).
[0031] TEE: Trusted Execution Environment, a secure area constructed by hardware isolation (such as ARM Trust Zone), protecting sensitive data and code (such as software fingerprint).
[0032] CSV: China Secure Virtualization, a security extension function built in domestic China Light CPU, providing hardware-level encryption and trusted computing capability.
[0033] The application is in the field of core basic software of the Xinxin industry, and focuses on solving the compatibility problem of IPv6 network protocol and software legalization system in the localization environment. In the current rapid development of information technology, the self-controlling of the Xinxin industry is crucial. IPv6, as the next generation of Internet protocol, has great significance in improving network performance and ensuring network security in the effective application in the localization environment.
[0034] In terms of hardware-level IPv6 communication acceleration, work is carried out based on domestic chips (Kunpeng, Feiteng, and Longxin). Kunpeng chips, with their powerful computing power and efficient data processing performance, can quickly parse and forward IPv6 data packets through optimized hardware architecture, greatly improving data transmission speed. Feiteng chips perform well in stability and low power consumption, and through improvements to the internal communication module of the chip, hardware acceleration of IPv6 communication is achieved, reducing data transmission delay. Longxin chips have optimized the instruction set to make them more suitable for IPv6 protocol, achieving efficient processing of IPv6 network communication at the hardware level and providing a solid hardware foundation for IPv6 network applications.
[0035] It is also crucial to optimize the IPv6 protocol stack that adapts to domestic operating systems (KylinOS and UOS). KylinOS has optimized its kernel and redesigned the network protocol stack structure to make it more efficient in handling IPv6 protocols. Through optimization of the network driver, the efficiency of data interaction between network devices and the IPv6 protocol stack is improved, enhancing the stability of the system in the IPv6 network environment. UOS optimizes key functions such as IPv6 address allocation and routing, using advanced algorithms to speed up address allocation and optimize routing table management, enabling the system to quickly and accurately forward data in complex IPv6 network environments and improving user experience in IPv6 networks.
[0036] In IPv6 networking, integrate the national cryptographic algorithm (SM2 / SM3 / SM4) required by the National Cryptographic Administration to ensure the safety of network communication. SM2 algorithm is used for key exchange and digital signature. When communicating in IPv6 network nodes, identity authentication and key negotiation are performed through SM2 algorithm to ensure the authenticity and reliability of the communication parties and establish a secure communication key. SM3 algorithm, as a hash algorithm, checks the integrity of data in IPv6 network. If the data is tampered with during transmission, the hash value calculated by the receiver through SM3 algorithm will be different from that of the sender, so that data anomalies can be detected in time. SM4 algorithm is used for data encryption to encrypt the data transmitted in IPv6 network, ensuring the confidentiality of data during transmission and preventing data from being stolen or tampered with, effectively ensuring the security of IPv6 networking.
[0037] The software legal authorization and the deep binding mechanism of IPv6 dynamic address can effectively prevent software piracy. When the software runs in the IPv6 network environment, the system automatically obtains the IPv6 dynamic address of the device and binds it with the software authorization information. During the startup and running of the software, the system continuously verifies whether the IPv6 address of the current device is consistent with the authorized bound address. If the address is inconsistent, the software will limit the use or issue a warning, so as to ensure that only the software with legal authorization and on the authorized device can run normally, effectively protecting the rights of software developers and promoting the healthy development of the software industry in the domestic IPv6 environment.
[0038] As a key component of the national strategy, the core goal of the information security industry is to achieve self-control of the entire information technology stack. In the face of the global digital wave and the complex geopolitical situation, the importance of the information security industry has become increasingly prominent, and it has become a core driving force for ensuring national information security and promoting the steady development of the digital economy. According to the research insights of the "Information Technology Application Innovation Industry Development White Paper (2023)", the information security industry is currently facing three major contradictions in its development process, which are concentrated in the hardware layer, system layer, and application layer, seriously restricting the further expansion and deepening of the information security industry.
[0039] (1) Hardware layer: Insufficient IPv6 protocol offloading capability of domestic chips
[0040] In the field of chips, the hardware cornerstone of the information security industry, although China has made many remarkable achievements, there is still a significant gap in IPv6 protocol offloading capability compared with international advanced levels. Taking the Kunpeng 920 chip as an example, the chip has certain support capability in IPv6 basic routing function, but there is a obvious shortcoming in the hardware-level encryption acceleration layer. In actual application scenarios, this shortcoming directly leads to significant performance differences. For example, in the SM4 encryption delay index, using Intel AES-NI technology only needs 0.5ms, while the Kunpeng chip needs 3.2ms through software encryption, which is several times more. Such long encryption delay will undoubtedly seriously affect the real-time processing capability of businesses and the confidentiality of data transmission in key industry scenarios such as finance and telecommunications that require high network transmission speed and data security.
[0041] Looking at the Feiteng S2500 chip, its optimization is missing in the IPv6 message fragmentation and reassembly link, which also brings trouble to the actual network application. When the maximum transmission unit (MTU) in network transmission exceeds 1500, the packet loss rate is as high as 12%. In today's growing network traffic and increasingly frequent large data transmission, such a high packet loss rate will greatly reduce the integrity and accuracy of data transmission, and thus affect the stability and reliability of the entire network system. For example, in the application scenarios such as high-definition video transmission and large-scale file download, which have strict requirements on data integrity, the problem of Feiteng S2500 chip will cause video lag, file damage and other adverse consequences.
[0042] The root cause of the deficiency of domestic chips in IPv6 protocol offloading capability lies in the relative lag of research and development investment, the lack of deep technical accumulation, and the imperfect industrial ecology. On the one hand, chip research and development requires huge amount of capital investment and long-term technical accumulation, and in the past period of time, the domestic chip industry has certain gap compared with international giants in these aspects; on the other hand, the application of IPv6 related technology in China is relatively late, which leads to the lack of attention and research efforts of chip development enterprises on IPv6 protocol offloading capability in the early stage. In addition, since the domestic chip industry ecology is still in the stage of gradual improvement, the collaborative innovation mechanism between upstream and downstream enterprises has not yet fully mature, which also affects the optimization and improvement of chips in IPv6 protocol offloading capability to some extent.
[0043] (2) System layer: IPv6 protocol stack compatibility defects of domestic OS
[0044] IPv6 protocol stack compatibility defects of domestic OS
[0045] As the core software of computer system, the compatibility of IPv6 protocol stack of operating system is directly related to the running stability and reliability of the entire system in IPv6 network environment. However, the current domestic operating system has exposed serious problems in this regard. From the SLAAC (Stateless Address Autoconfiguration) failure rate, Windows 11 is only 0.8%, while UOS 1060 of United is as high as 22.6%, and Kirin V10SP3 reaches 19.1%. SLAAC failure will cause the device to be unable to automatically obtain valid IPv6 address, and thus unable to normally access IPv6 network, greatly affecting the user experience.
[0046] In terms of RA (Router Advertisement) resolution anomaly rate, Windows 11 is 0.3%, UOS 1060 is 18.4%, and Kirin V10SP3 is 15.2%. RA resolution anomalies can cause devices to have a biased understanding of network topology, leading to packet forwarding errors, and even causing network interruptions and other serious consequences. For example, in an enterprise office network, if a large number of terminal devices using domestic operating systems have RA resolution anomalies, the entire office network communication will be in chaos, employees will not be able to access shared resources, send and receive emails, etc., and will seriously affect the daily operational efficiency of the enterprise.
[0047] The causes of compatibility defects in the IPv6 protocol stack of domestic operating systems are complex. On the one hand, domestic operating systems started relatively late, and during the development of the protocol stack, the understanding and implementation of the IPv6 standard may not be precise and in-depth enough; on the other hand, adaptation with hardware devices is also a key issue. Different domestic chip architectures are diverse, and when the operating system adapts to these chips, it may not fully consider the compatibility requirements of the IPv6 protocol stack in different hardware environments. In addition, due to the lack of large-scale actual network environment testing and user feedback, some potential compatibility problems have not been discovered and solved in a timely manner.
[0048]
[0049] (3) Application layer: conflict between the legal system and dynamic networks
[0050] In the process of promoting the signal creation industry, the popularization of the legal system is an important measure to ensure information security and the healthy development of the industry. However, in the IPv6 environment, there is a sharp conflict between the traditional software authorization mode and the characteristics of dynamic networks. The privacy extension address (RFC4941) mechanism in the IPv6 environment makes the terminal address change rate within 24 hours exceed 70%. This means that according to the traditional software authorization binding MAC address method, the software may not be able to identify the authorized device due to the frequent changes of the terminal address in a short period of time, resulting in the software not being able to function properly.
[0051] For multi-host devices such as dual-network card industrial computers, there are multiple temporary IPv6 addresses, which further exacerbate the complexity of software authorization management. In the industrial automation production scene, dual-network card industrial computers are widely used to connect different network areas to achieve data interaction and control. However, due to the existence of multiple temporary IPv6 addresses, if the traditional software authorization method is used, it may cause the software used for industrial control to be unable to run stably, thereby affecting the normal operation of the entire production line, causing production stagnation, product quality decline, and other serious consequences.
[0052] The essence of the conflict between the genuine system and the dynamic network is that the traditional software authorization mode design does not fully consider the dynamic change characteristics of the address in the IPv6 network environment. In the IPv4 era, the network address is relatively stable, and the authorization mode of binding MAC address can better meet the needs of software authorization management. But with the large-scale application of IPv6, the dynamic nature of network address becomes the norm, and the limitations of the traditional authorization mode are highlighted. In addition, software developers are relatively slow in adapting to the IPv6 network environment when updating and upgrading software, and have not been able to timely introduce new authorization management solutions that adapt to the dynamic network characteristics, which is also one of the important factors leading to this conflict.
[0053] In summary, the problems related to IPv6 faced by the Xingcheng industry at the hardware, system and application levels have seriously hindered the in-depth development and comprehensive promotion of the Xingcheng industry. To break through these bottlenecks, we need to start from multiple dimensions such as chip research and development, operating system optimization, and software authorization mode innovation, strengthen technology research and development, and perfect the industrial ecosystem to realize the high-quality and sustainable development of the Xingcheng industry in the IPv6 era.
[0054] In the development process of the Xingcheng industry, in addition to the many problems existing at the hardware, system and application levels, some key technologies have also exposed obvious limitations and deficiencies in practical application. These technical problems are intertwined with the contradictions mentioned earlier at each level, further increasing the difficulty of realizing full-stack self-containment for the Xingcheng industry. The following will analyze in detail the key technical problems of the core limitations of DHCPv6-PD protocol, the integration difficulties of national cryptographic algorithms in IPv6, and the binding failure of software fingerprint technology.
[0055] (1) Core limitations of DHCPv6-PD protocol
[0056] The prefix delegation (PD) mechanism defined in RFC3633, as an important protocol for address auto-configuration and management in IPv6 networks, has gradually revealed many defects in the Xingcheng environment, which seriously affect its applicability and reliability in the Xingcheng industry.
[0057] Security defects
[0058] One of the significant security shortcomings of the DHCPv6-PD protocol is its plaintext transmission feature, which is in serious conflict with the GM / T0054-2018 "Information Security Technology Network Communication Protocol Cryptographic Application Requirements". GM / T0054-2018 clearly specifies various requirements for the cryptographic application of network communication protocols, aiming to protect the confidentiality, integrity and authenticity of network communication through effective cryptographic technology. However, in the transmission process of DHCPv6-PD protocol, all PD messages are sent in plaintext form, making the message content extremely vulnerable to interception, eavesdropping and tampering by attackers.
[0059] In the Xinyuan environment, a large amount of sensitive information and critical business data transmission, once the DHCPv6-PD message is obtained by the attacker, the attacker may extract important data such as network topology, prefix information, and device identification from it. Based on these data, the attacker can launch more accurate network attacks, such as forging PD messages for address spoofing, causing network address allocation chaos; or using the obtained network topology information to find network vulnerabilities and implement penetration attacks. For example, in the internal Xinyuan network of government agencies, if the DHCPv6-PD message is stolen, it may lead to the leakage of sensitive information within the agency, and even affect the normal operation of the government system, posing a serious threat to national information security.
[0060] Compatibility defects of domestic OS
[0061] The domestic operating system has obvious compatibility defects in supporting the DHCPv6-PD protocol, especially the incorrect handling of the IA_PD option in the Kirin OS kernel 4.19 version. From the provided code vulnerability, it can be clearly seen that the Kirin OS kernel 4.19 version incorrectly assumes that the prefix length is always 64 when processing the IA_PD option. When the actual prefix length is not equal to 64, the kfree_skb(skb) operation is executed and the -EINVAL error is returned. The same problem exists in the UOS.
[0062] This incorrect handling method will cause a series of serious consequences in actual network applications. In IPv6 networks, the prefix length is not fixed at 64, and according to different network planning and application scenarios, the prefix length can be flexibly adjusted. For example, in some large enterprises or campus networks, longer prefix lengths may be used to more efficiently manage network addresses; in some scenarios with high address space requirements, shorter prefix lengths may be used. When devices running the Kirin OS kernel 4.19 version or the UOS operating system are deployed in these network environments, due to the incorrect handling of non-64-bit prefix lengths by the operating system, the DHCPv6-PD protocol cannot work normally, and the device cannot obtain correct prefix delegation information, thus unable to realize automatic configuration of network addresses.
[0063] This not only increases the workload of network administrators, who need to manually configure network addresses for devices, reducing network management efficiency, but also may cause network address conflicts due to omissions during the manual configuration process, affecting the stability and reliability of the network. In Xinyuan networks in the financial, energy, and other critical industries, this compatibility defect may cause business systems to be unable to normally access the network, resulting in service interruptions and causing significant economic losses to enterprises.
[0064] The reasons for the compatibility defects of domestic OS are as follows. First, the development process of domestic operating systems is relatively short, and the consideration of various protocol details is not thorough enough in the development and improvement process of the protocol stack, and there is a lack of sufficient testing of protocol application in different scenarios. Second, during the code writing process, developers may make unreasonable assumptions based on experience in certain scenarios, without strictly following the specification requirements of RFC3633 for DHCPv6-PD protocol, resulting in logical flaws in the code. Third, the lack of coordination testing between domestic operating systems and other network devices and protocols has failed to timely identify and fix compatibility issues in actual applications.
[0065] (2) Difficulties in integrating national cryptographic algorithms into IPv6
[0066] The national cryptographic standards SM2 / SM3 / SM4, as independently developed cryptographic algorithms in China, have important significance in ensuring information security. However, integrating these national cryptographic algorithms into the IPv6 protocol stack faces multiple obstacles such as performance bottlenecks, protocol compatibility, and lack of hardware acceleration, which severely restricts the widespread application of national cryptographic algorithms in IPv6 networks.
[0067] Performance Bottleneck
[0068] National cryptographic algorithms have obvious performance bottlenecks, especially in terms of encryption and decryption bandwidth, which lags far behind the internationally popular AES-NI technology. Actual test data shows that on the Kunpeng 920 chip, the encryption and decryption bandwidth of SM4-CTR mode is only 1.2Gbps, while the encryption and decryption bandwidth of AES-NI is 6.4Gbps, which is only 1 / 5 of the former.
[0069] This performance gap is particularly pronounced in high-bandwidth, high-traffic IPv6 network environments. In video on demand, cloud computing, and large data transmission applications, a large amount of data needs to be encrypted and decrypted in real time to ensure data transmission security. If SM4-CTR mode is used, its low encryption and decryption bandwidth will become a bottleneck for data transmission, resulting in increased data transmission delay, decreased network throughput, and affecting user experience and business processing efficiency. For example, in a cloud data center using IPv6 network, if SM4-CTR mode is used to encrypt communication data between virtual machines, the slow data exchange between virtual machines due to insufficient encryption and decryption performance will affect the response speed and quality of service of cloud services, and reduce the overall efficiency of the data center.
[0070] There are two main reasons for the performance bottleneck of the national cryptographic algorithm. On the one hand, the design of the SM4 algorithm itself is relatively complex in some operation steps, which leads to slower encryption and decryption operations. Compared with the AES algorithm, the SM4 algorithm has differences in the design of the round function and the key expansion process, which affects its operation efficiency to some extent. On the other hand, domestic chips lack sufficient optimization support for national cryptographic algorithms, and there is no efficient hardware acceleration instruction set like AES-NI, so national cryptographic algorithms mainly rely on software implementation, and the efficiency of software implementation is usually lower than that of hardware acceleration implementation.
[0071] Protocol compatibility
[0072] The application of the national cryptographic algorithm in the IPv6 protocol stack also faces the problem of protocol compatibility. The Internet Engineering Task Force (IETF) has not defined the DHCPv6 option number of the national cryptographic algorithm, which makes it necessary to perform private extension if the national cryptographic algorithm is to be integrated into the DHCPv6 protocol in actual application.
[0073] Although this private extension can to some extent realize the combination of the national cryptographic algorithm and the DHCPv6 protocol, it brings the risk of cross-vendor intercommunication failure. Different device manufacturers may use different extension methods and parameter settings when performing private extension, which leads to the inability of devices from different manufacturers to correctly identify and process DHCPv6 packets containing national cryptographic algorithm-related information. For example, in an IPv6 network composed of devices from multiple manufacturers, if a router from a certain manufacturer carries encryption parameters of the SM4 algorithm in the DHCPv6 packet using private extension, and a terminal device from another manufacturer cannot recognize this private extension, the terminal device will not be able to correctly obtain network configuration information and access the network.
[0074] Protocol compatibility problems will also affect the integration of the national cryptographic algorithm in other parts of the IPv6 protocol stack, such as the IPsec, SSL / TLS, and other security protocols. Since the national cryptographic algorithm is not included in the relevant standards of the IETF, when integrating the national cryptographic algorithm into these security protocols, the protocol needs to be modified and extended, which not only increases the complexity of protocol implementation, but also may cause compatibility problems with devices that follow the standard protocol, hindering the promotion and application of the national cryptographic algorithm.
[0075] Lack of hardware acceleration
[0076] In addition to the built-in SM4 instruction set (crypto_sm4 module) in the Haiguang CPU, other domestic chips lack sufficient hardware acceleration support for the national cryptographic algorithm, and mainly rely on software simulation to implement the operation of the national cryptographic algorithm.
[0077] There are many disadvantages in software simulation of national cryptographic algorithms. First, the operation efficiency of software simulation is much lower than that of hardware acceleration, which further exacerbates the performance bottleneck of national cryptographic algorithms, which has been described in detail above. Second, software simulation needs to occupy a large amount of CPU resources, which will affect the processing capacity of the system to other businesses under high CPU load, resulting in the decline of the overall performance of the system. For example, in a server using Feiteng S2500 chip, if SM3 algorithm is implemented by software simulation to perform hash operation on data, a large amount of CPU resources will be occupied, which will slow down the response of the server in processing other business requests, affecting the service capacity of the server.
[0078] The main reason for the lack of hardware acceleration is the relatively lagging development of domestic chip industry. Compared with international leading chip manufacturers, domestic chip manufacturers pay insufficient attention to and invest insufficient research and development in hardware acceleration of national cryptographic algorithms. On the one hand, the promotion and application of national cryptographic algorithms are relatively short, and the response of chip manufacturers to market demand has a certain lag; on the other hand, the development of hardware acceleration instruction set of national cryptographic algorithms requires a large amount of investment in funds and technical resources, and there is still a gap in technical accumulation and financial strength among some domestic chip manufacturers, making it difficult to quickly integrate the hardware acceleration of national cryptographic algorithms.
[0079] (3) Binding failure of software fingerprint technology
[0080] In the signal creation industry, the genuine system is an important means to ensure the legality and security of software use. The existing genuine system mostly adopts double-factor verification, i.e. verifying digital certificate and binding MAC address. However, in the IPv6 environment, due to the dynamic nature of the address and the characteristics of multi-address conflict, the software fingerprint technology based on MAC address binding has a problem of binding failure, which seriously affects the effectiveness of the genuine system.
[0081] Binding failure caused by address dynamicity
[0082] In the IPv6 environment, the life cycle of the temporary address generated by SLAAC (Stateless Address Autoconfiguration) is usually only 24 hours, which makes the address of the terminal device have strong dynamicity. The existing genuine system binds the authorization with the MAC address of the terminal device after verifying the digital certificate and obtaining the authorization token, in order to ensure the legal use of software.
[0083] But in the IPv6 environment with strong address dynamics, this binding method becomes extremely unstable. Since the terminal address may change every 24 hours, and the MAC address is relatively stable, the software may rely on the terminal address for some auxiliary verification or communication during operation. Frequent changes in the address will cause communication anomalies between the software and the authorization server. More importantly, some legitimate systems are designed to use the terminal address as an auxiliary identifier in the authorization verification process. When the terminal address changes, the system may mistakenly believe that the terminal device is not authorized, thereby restricting the use of the software. For example, in an enterprise using an IPv6 network, the office software used by employees uses a legitimate system based on MAC address binding. If the employee's terminal device changes its address due to the expiration of the temporary address generated by SLAAC, the office software may not start normally and need to be authorized again, which not only affects the employee's work efficiency, but also increases the enterprise's IT management cost.
[0084] Binding failure caused by multiple address conflicts
[0085] In the IPv6 environment, a single terminal device may have multiple addresses, such as stable addresses defined by RFC7217 and privacy addresses defined by RFC4941, which raises the problem of multiple address conflicts and further leads to the binding failure of software fingerprint technology.
[0086] For multi-host devices such as dual-network card industrial computers, it is more common for them to have multiple temporary IPv6 addresses. The existing dual-factor verification mechanism of legitimate systems cannot accurately bind software authorization to devices when facing such multiple address situations. When the software starts, it may randomly select an address to communicate with the authorization server, and if the address is not recorded by the authorization system, it will cause verification failure and the software cannot run normally. In the industrial control field, industrial control software running on dual-network card industrial computers has extremely high requirements for stability and continuity. If the software binding is disabled due to multiple address conflicts, it may stop running, which may cause production accidents, serious economic losses and safety hazards. For example, on an automated production line, if the software controlling the production line stops running due to authorization failure caused by multiple address conflicts, the production line will suddenly stop, the products being processed may be scrapped, and the production equipment may also be damaged.
[0087] Binding failure caused by abnormal behavior of domestic OS
[0088] Some abnormal behaviors of domestic operating systems can also cause binding failure of software fingerprint technology. The software fingerprint cache error cleanup in Kylin V10SP1 is a typical example. The software fingerprint cache stores the authorization information and device binding relationship of the software. When the software starts, the system will first read the relevant information from the cache for fast verification to improve verification efficiency and software startup speed.
[0089] However, the Kylin V10SP1 operating system mistakenly cleared the software fingerprint cache. This forces the software to undergo a complete two-factor authentication process every time it starts up, requiring re-verification of the digital certificate, acquisition of the authorization token, and binding of the MAC address. This not only increases software startup time and impacts user experience but can also lead to authentication failures due to network fluctuations or excessive authorization server traffic, rendering the software unusable. For example, on government office terminals using the Kylin V10SP1 operating system, staff must re-authenticate every time they launch office software. If a connection to the authorization server fails during an authentication attempt due to network issues, staff will be unable to work, impacting the efficiency of government processing.
[0090] In addition, there may be other unstable factors when domestic operating systems process software fingerprint information, such as imperfect fingerprint information storage and retrieval mechanisms, which may lead to fingerprint information loss or damage, and this may also cause software binding failure.
[0091] In summary, the core limitations of the DHCPv6-PD protocol, the difficulties in integrating national cryptographic algorithms into IPv6, and the binding failures of software fingerprinting technology, among other key technical issues, interact with the problems faced by the information technology application innovation (ITAI) industry at the hardware, system, and application layers, collectively constituting the technical bottlenecks for its development. To promote the in-depth development of the ITAI industry, it is essential to conduct in-depth research and tackle these key technical issues. Through technological innovation and optimization, these bottlenecks can be overcome, thereby improving the overall technical level and application reliability of the ITAI industry.
[0092] In the process of the information technology innovation industry making every effort to achieve technological breakthroughs, various patented technology solutions have emerged. Among them, the two innovative features of a certain solution, namely "dynamic prefix generation" and "terminal behavior compatibility", were originally expected to effectively solve network problems in the IPv6 environment.
[0093] The "dynamic prefix generation" technology uses a 128-bit mask extension method based on IA_NA. While this might be effective in traditional networks, it struggles in domestically developed environments due to the lack of SM3 (the national standard cryptographic standard). Domestically developed gateways, acting as security barriers, strictly review data according to national standards, allowing only prefixes processed by national cryptographic algorithms to pass. Prefixes generated by this technology, lacking security verification, will be blocked by the gateway, leading to functional failure.
[0094] The "terminal behavior compatibility" technology achieves adaptation by listening to stateful requests. However, domestic OSes such as UnionTech UOS and Kylin V10 send DHCPv6 request messages that do not conform to the standard format due to their R&D background and the requirements of domestic IT innovation. This technology cannot recognize such non-standard messages, and the terminal cannot obtain configuration information, resulting in frequent network connection problems and making it difficult to play an effective role in the domestic IT innovation environment.
[0095] (1) The limitation of the "dynamic prefix generation" technical point
[0096] The "dynamic prefix generation" technical point in patent CN115767510B adopts a 128-bit mask extension method based on IA_NA. This method may be able to achieve certain dynamic prefix generation functions in traditional network environments, but in the signal creation environment, it leads to the interception of the generated prefix by the signal gateway due to the non-use of the national cryptographic SM3.
[0097] As a self-developed cryptographic hash algorithm in China, the national cryptographic SM3 has extremely high security requirements in the signal creation environment and is widely used in key links such as data integrity verification and identity authentication. As an important security barrier of the signal creation network, the signal gateway strictly follows relevant national security standards and specifications and strictly examines various data and information transmitted in the network. Among them, the security verification of prefix generation is one of the important responsibilities of the signal gateway. Only the prefix information encrypted or verified by the national cryptographic algorithm is allowed to be transmitted and used in the signal creation network.
[0098] The "dynamic prefix generation" technology of patent CN115767510B does not use the national cryptographic SM3, and the generated prefix lacks a security verification mechanism that meets the signal creation standards. When the signal gateway detects such a prefix that has not been processed by the national cryptographic SM3, it will intercept it according to the security policy to prevent unsafe prefix information from entering the signal creation network and to avoid potential threats to network security. This results in the prefix generated by the technology not being able to take effect normally in the signal creation network, making the dynamic prefix generation function completely ineffective in the signal creation environment.
[0099] For example, in a signal creation network upgrade project of a certain enterprise, the "dynamic prefix generation" technology of the patent was introduced to achieve dynamic management of network addresses. However, after actual deployment, it was found that since the generated prefix did not use the national cryptographic SM3, it was all intercepted by the enterprise's signal gateway, resulting in terminal devices being unable to obtain valid network prefixes and being unable to normally access the signal creation network, seriously affecting the development of the enterprise's business.
[0100] (2) The limitation of the "terminal compatibility" technical point
[0101] The "terminal compatibility" technical point of the patent achieves compatibility and adaptation of terminals and networks by listening to stateful requests. However, in the signal creation environment, since the domestic OS does not send standard DHCPv6 request packets, this technical point is completely ineffective.
[0102] Domestic operating systems such as UnionTech UOS and Kylin V10 differ somewhat from international standards in their implementation of the IPv6 protocol stack. During network communication, they often do not send DHCPv6 request messages in the standard format. This is determined by the R&D background, technical roadmap, and specific requirements of the domestic IT innovation environment. During development, domestic operating systems have given greater consideration to security strategies and hardware compatibility under the domestic IT innovation environment, potentially leading to targeted adjustments and optimizations in protocol implementation, resulting in deviations between their sent DHCPv6 request messages and the standard format.
[0103] The "terminal compatibility" technology in patent CN115767510B is based on listening to standard DHCPv6 request messages to achieve terminal compatibility. However, when faced with domestically developed operating systems that do not send standard messages, this technology cannot receive valid request information, and therefore cannot accurately identify and adapt to the terminal's behavior. This directly leads to obstacles in the interaction between the terminal device and the network. The terminal cannot obtain relevant configuration information provided by the network, such as IP address and DNS server address, thus affecting the normal operation of the terminal in the domestic IT network.
[0104] Taking a university's information technology innovation laboratory as an example, the laboratory deployed terminal devices running the Kylin V10 operating system and adopted "terminal compatibility" technology. However, because the Kylin V10 operating system does not send standard DHCPv6 request messages, this technology cannot listen for and process related requests, leading to frequent problems such as unstable network connections and inability to access external resources for the laboratory's terminal devices, which seriously affected the progress of experimental teaching and scientific research.
[0105] (3) Limitations of the "route construction" technique
[0106] The patent's "route construction" technique extracts a 64-bit prefix from NAT rules to construct routes. However, this approach violates the GM / T0045-2021 regulation prohibiting NAT and is not feasible in a domestic IT innovation environment.
[0107] GM / T0045-2021 is an important Chinese standard for information security technology, which explicitly prohibits NAT (Network Address Translation) technology. This is because NAT technology, to some extent, disrupts the end-to-end communication characteristics of IPv6, increases network complexity and uncertainty, and may also pose security risks. In the context of domestic IT innovation, ensuring network security, stability, and traceability are primary objectives; therefore, it is essential to strictly adhere to relevant standards such as GM / T0045-2021 and prohibit NAT technology.
[0108] The "route construction" technology of patent CN115767510B relies on NAT rule to extract prefix, which obviously contradicts the standards and requirements of the China's information creation environment. In the China's information creation network, if this technology is forcibly used to construct routes, not only will it lead to failure of route construction and inability to achieve normal network communication, but also will bring security risks to the entire China's information creation network due to violation of security standards, and may be punished by relevant regulatory departments.
[0109] For example, a certain financial institution considered using the "route construction" technology of this patent during the construction of the China's information creation system. However, during the security assessment, it was found that this technology violated the prohibition of NAT in GM / T0045-2021, and if used, it would cause the financial China's information creation system to not meet the security standards, posing a major security risk. Ultimately, the technology solution had to be abandoned, and a route construction method that met the requirements had to be found.
[0110] In summary, the "dynamic prefix generation" and "terminal behavior compatibility" technology solutions, although they may have some innovation and practicality in traditional network environments, in the China's information creation environment, due to insufficient consideration of security standards, characteristics of domestic operating systems, and related specification requirements in the design of the technology, they have many fundamental defects, and have encountered a series of failure problems in actual application, making it difficult to meet the needs of the development of the China's information creation industry.
[0111] Under the background of the acceleration of the China's information creation industry, IPv6, as the core protocol of the next generation Internet, faces multiple technical barriers in its integration with China's information creation technology. These barriers not only restrict the security and efficiency of China's information creation networks, but also become key bottlenecks hindering the industrial scale application. This invention proposes a systematic solution to the three core technical problems specific to the China's information creation field, aiming to build an IPv6 technology system adapted to the China's information creation environment.
[0112] Splitting of national cryptographic algorithms and IPv6 protocol
[0113] National cryptographic algorithms (SM2 / SM3 / SM4) are self-controllable cryptographic standards in China, which are the cornerstone of ensuring the security of China's information creation networks. However, the integration of current national cryptographic algorithms and IPv6 protocol still remains at the software level, failing to achieve deep hardware-level integration, especially in the application of DHCPv6-PD messages, which has become a major hidden danger for the security of China's information creation networks.
[0114] From the technical status quo, the implementation of the national cryptographic algorithm in the existing IPv6 protocol stack relies on software encryption libraries, and its performance is orders of magnitude behind hardware acceleration solutions. Taking the encryption of DHCPv6-PD packets as an example, the single-packet encryption delay of SM4-GCM encryption implemented by software on the Kunpeng 920 chip is as high as 3.2 ms, while under the same conditions, the hardware-accelerated Intel AES-NI only takes 0.5 ms. This performance gap is particularly pronounced in high-concurrency scenarios - when the number of terminal devices exceeds 1000, software encryption can cause the PD packet processing queue to be congested, and the address allocation response delay to exceed 5 seconds, seriously affecting network service quality.
[0115] More importantly, software encryption methods are difficult to meet the security compliance requirements of the network. According to GM / T0054-2018 "Information Security Technology Network Communication Protocol Cipher Application Requirements", IPv6 key protocol packets need to be encrypted at the hardware level to prevent side-channel attacks, and existing software implementations cannot resist advanced attack methods such as cache timing attacks and electromagnetic leakage analysis. In a certain government cloud pilot project, DHCPv6-PD packets encrypted by software were detected to have a key leakage risk, resulting in 23% of the terminal address allocation information being illegally intercepted.
[0116] The fragmentation of national cryptographic algorithms and IPv6 protocols is also reflected in protocol stack compatibility. Currently, the IPv6 protocol stack of domestic OSes lacks support for national cryptographic algorithms: the DHCPv6 client of UOS 1060 does not implement the SM2 signature verification module, resulting in PD packets carrying national cryptographic signatures being misjudged as illegal packets, with a discard rate of 37%; although the Kylin V10SP3 supports SM4 encryption, it is not compatible with the GCM mode, and can only use the CBC mode, which has a natural defect in protecting against replay attacks, which contradicts the requirement of GM / T0054-2018 that "must support authenticated encryption mode".
[0117] In addition, the application of national cryptographic algorithms in PD packet processing lacks a unified standard, and different manufacturers' implementation schemes differ. For example, a certain manufacturer's PD server uses SM3 hash for prefix verification, while the verification algorithm of the terminal device is SM2, resulting in a prefix verification failure rate of 41%, seriously affecting network interoperability. This fragmented implementation makes it difficult for national cryptographic algorithms to play their security protection role in IPv6 networks.
[0118] Therefore, implementing hardware-level integration of SM2 / SM3 / SM4 in DHCPv6-PD packets is not only a necessary requirement for improving the performance of network security, but also a core task of meeting national security standards and building a self-contained network security system. The present invention aims to fill this technical gap and achieve deep integration of national cryptographic algorithms and IPv6 protocols by innovating hardware acceleration architecture and protocol stack adaptation schemes.
[0119] Invalidation of genuine binding
[0120] In the IPv6 environment, the traditional software genuine binding mechanism is completely invalid due to the inability to adapt to the dynamic characteristics of the address, which has become a major challenge to the copyright protection of the national security industry, and has seriously restricted the promotion and application of genuine software.
[0121] The traditional software authorization mechanism mostly uses MAC address as the unique identifier, but in the IPv6 network, the dynamic change of terminal address makes this mechanism completely out of control. According to the privacy extension standard of RFC4941, terminal devices will generate new temporary IPv6 addresses every 24 hours, with a change rate of more than 70%; and multi-host devices (such as dual-network card industrial computers) can have more than 8 temporary addresses at the same time, with an address switching frequency of minutes. In a test of a certain intelligent manufacturing park, the genuine CAD software based on MAC binding had a high authorization invalidation rate of 68% due to address changes, and each device needed to be reactivated 3.2 times per day on average, which seriously affected production efficiency.
[0122] The dynamic nature of the address also causes more complex copyright tracing problems. Illegal users can bypass the authorization verification mechanism by taking advantage of the frequent change of the address - by forging temporary addresses, the same pirated software can be illegally spread among different terminals, and existing systems cannot effectively trace its source. According to the statistics of a software manufacturer, the spread of pirated software in the IPv6 environment has increased by 3 times compared with IPv4, and the accuracy of pirated software identification has decreased to 52%, causing an annual loss of more than 10 million yuan to the manufacturer.
[0123] The limitations of existing solutions are also significant. Some manufacturers have tried to use "IP+MAC" dual-factor binding, but in the IPv6 environment, the effectiveness of this solution is greatly reduced: on the one hand, privacy extension addresses make IP addresses unstable; on the other hand, some domestic OS (such as Kylin V10SP1) have MAC address randomization functions, further weakening the binding effect. In actual tests, the invalidation rate of this dual-factor binding is still as high as 43%, which cannot meet the needs of genuine management.
[0124] The more fundamental problem is that the traditional binding mechanism lacks security protection at the cryptographic level. MAC address and IP address are both network identifiers that can be forged, and attackers can easily tamper with these information by modifying the network interface configuration file, bypassing the authorization verification. In a certain university's security project, an attacker used a fake MAC address to make a single set of pirated teaching software illegally access more than 200 terminals, and the system did not detect any abnormalities for 3 months.
[0125] Therefore, the strong association of the software fingerprint and the IPv6 address through cryptography becomes a core technical path to solve the problem of invalidation of the binding of the original version. The application embeds the software fingerprint into the IPv6 address generation process and uses the national secret algorithm to construct a non-forgery binding relationship. Even if the address changes dynamically, the authorized uniqueness and accuracy can still be ensured through cryptographic verification, thereby providing solid technical support for software copyright protection in the signal creation environment.
[0126] Compatibility defects of domestic OS
[0127] The compatibility defects of domestic operating systems (such as Kylin and UOS) in the implementation of the IPv6 protocol stack have become a major obstacle to the large-scale deployment of signal creation networks. These defects cause frequent network failure and communication interruption of terminal devices, seriously affecting user experience and business continuity.
[0128] According to the test data, the abnormal rate of the IPv6 protocol stack of the domestic OS is much higher than that of the international mainstream system. According to the report of a third-party testing agency, in 1000 times of SLAAC (Stateless Address Autoconfiguration) test, the failure rate of UOS1060 is 22.6%, the failure rate of Kylin V10SP3 is 19.1%, and the failure rate of Windows11 is only 0.8%. The RA (Router Advertisement) message parsing abnormality is more prominent: the abnormal rate of UOS is 18.4%, the abnormal rate of Kylin V10SP3 is 15.2%, and the main performance is missing the analysis of prefix information and misjudging the lifetimes parameter, which directly leads to the failure of the terminal to obtain correct network configuration.
[0129] The manifestation of the protocol stack defects has significant diversity, which brings great challenges to network adaptation. Specifically, Kylin OS has a fragmentation reassembly logic error when processing IPv6 packets with MTU>1500, with a packet loss rate of 12%; UOS can only parse the first prefix when the RA message contains multiple prefix information, resulting in the terminal's inability to obtain a backup address. These defects are not accidental, but systematic problems that are inevitably triggered in specific scenarios - in a 72-hour stress test, the protocol stack abnormality of Kylin OS occurs once every 4.3 hours on average, and that of UOS occurs once every 5.7 hours.
[0130] More complex is that the defect performance of different versions of domestic OS is different. For example, Kylin V10SP2 has a memory leak when processing ICMPv6 redirect messages, while SP3 version has fixed the problem, but added a new defect of RA message checksum calculation error. This instability between versions makes network administrators need to configure separate adaptation strategies for different versions of OS, increasing the management cost by more than 3 times.
[0131] The existing compatible solution adopts a "one-size-fits-all" downgrade strategy, that is, forcing the domestic OS to use a simplified IPv6 protocol stack, which can reduce exceptions, but sacrifices network performance and functional integrity. For example, after closing the FlowLabel field, the RA resolution exception rate of Kylin OS is reduced to 8%, but the QoS function is disabled, and the stall rate of real-time services (such as video conferencing) is increased to 15%. Obviously, this compromise solution cannot meet the high-quality needs of the signal creation network.
[0132] Therefore, dynamically adapting the protocol stack exception of the domestic OS requires an intelligent and refined technical solution. The present application realizes accurate adaptation to different domestic OSs and different versions by constructing a protocol stack defect feature library and a dynamic adaptation engine, while ensuring compatibility, maximally retaining the functional and performance advantages of IPv6, and providing key technical support for the stable operation of the signal creation network.
[0133] As shown in Figure 1 The present application provides a kind of genuine software authorization method, comprising:
[0134] Step S1, receiving the encrypted message sent by signal creation terminal, and verifying the encrypted message.
[0135] Step S2, in response to the encrypted message verification success, the verification terminal IPv6 address corresponding to the encrypted message is generated.
[0136] In this embodiment, the encrypted message is obtained by encrypting the authentication information of the signal creation terminal according to the key, and the verification terminal IPv6 address is allocated to the signal creation terminal corresponding to the encrypted message that passes the verification, so as to avoid the signal creation terminal that does not pass the verification to access the network.
[0137] Among them, after the encrypted message verification passes, it can also include returning the response message containing IA_PD to the signal creation terminal, the IA_PD field contains prefix information (such as 2001:da8:1:: / 64), validity period (such as 3600 seconds), and SM2 signature (signed with server certificate).
[0138] Among them, the verification of the encrypted message calls the kae_sm2_verify () function through the national secret acceleration engine, verifies the SM2 signature of IA_PD (uses the public key of PD server), and ensures that the prefix information is not tampered.
[0139] As an optional implementation, after receiving the encrypted message, the SM4-GCM decryption and SM2 signature verification through hardware acceleration are used to process only legal requests, and the interception rate of illegal messages reaches 100%.
[0140] Step S3, binding the verification terminal IPv6 address with the encrypted message to obtain the software legalization authorization certificate.
[0141] Wherein, the verification terminal IPv6 address is generated by the legal binding module according to the formula: IPv6=IA_PD:: / 64+EUI-64, wherein EUI-64 is generated by terminal MAC address conversion (in accordance with RFC4291). Store <IPv6, IA_PD, FP> in the database, and the valid period is consistent with IA_PD.
[0142] Step S4, sending the software legalization authorization certificate to the Xingcheng terminal.
[0143] In some embodiments, the method further comprises:
[0144] In response to the encrypted message verification failure, receiving the network prefix sent by the prefix generator.
[0145] In this embodiment, when the encrypted message verification fails, the currently verified Xingcheng terminal is not registered in the network, and the software legalization authorization certificate needs to be generated and sent to the Xingcheng terminal after the Xingcheng terminal is allocated with a dynamic prefix and address.
[0146] Wherein, when IA_PD is invalid, the dynamic prefix generator and the legal binding module work together. When generating the network prefix, the dynamic prefix generator generates the LAN prefix according to the algorithm: prefix=sm3_hash(IA_NA||SM3(UDID)||timestamp)[0:64].
[0147] According to the network prefix, the encrypted message is modified to obtain an updated encrypted message.
[0148] An updated terminal IPv6 address corresponding to the updated encrypted message is generated.
[0149] The updated terminal IPv6 address is bound with the updated encrypted message to obtain the software legalization authorization certificate.
[0150] Wherein, when generating the updated terminal IPv6 address, the legal binding module generates the address according to the formula: IPv6=fd00:: / 64+sm3_hash(FP)[0:64].
[0151] As an optional implementation, in order to avoid the conflict between the newly generated updated terminal IPv6 address and the existing IPv6 address in the network, the IPv6 address conflict can also be detected by querying the local cache of the IPv6 address, so as to ensure the uniqueness of the generated IPv6 address. When it is detected that the generated updated device IPv6 address conflicts with the IPv6 address recorded in the local cache, the address conflict can be avoided by regenerating the IPv6 address until the local IPv6 address is not repeated.
[0152] As an optional implementation, in order to avoid the idle credit device occupying the IPv6 address for a long time, the generated address can be set to have a short validity period (such as 1800 seconds), and the IPv6 address can be updated by regularly renewing the lease.
[0153] In some embodiments, after sending the software legalization authorization certificate to the credit terminal, the method further comprises:
[0154] Sending a verification request to the credit terminal, so that the credit terminal returns corresponding signature verification information.
[0155] Verifying the signature verification information, and in response to the signature verification information verification failure, revoking the software legalization authorization certificate corresponding to the signature verification information.
[0156] In this embodiment, in order to realize the continuous validity of the software legalization authorization certificate, the information of the credit terminal is ensured to be consistent with the authorization information by sending a verification request to the credit terminal.
[0157] As an optional implementation, the validity of the software legalization authorization certificate of the credit terminal can be confirmed by sending an FP challenge to the credit terminal at regular intervals.
[0158] Specifically, an FP challenge can be sent to the terminal every 10 minutes: the terminal is required to use the device certificate to perform SM2 signature on the random number+FP, and then verify the signature validity, and check the FP state with the legalization authorization server. If the verification is passed, the address validity period is extended; if it fails, the address is added to the blacklist, and network access is refused. In the test of 100 terminals, the verification success rate of this process reaches 99.7%, effectively solving the binding invalidation problem caused by the dynamic change of the address.
[0159] A software legalization authorization method comprises:
[0160] Step S10, generating software fingerprint information according to the installation information of the legalized software, and constructing message information according to the fingerprint information and the state information of the credit terminal.
[0161] In the embodiment, by generating software fingerprint information, the software information installed on the credit terminal and the device information of the credit terminal can be confirmed through the software fingerprint information, thereby ensuring the uniqueness of subsequent authorization.
[0162] As an optional implementation, after the credit terminal is powered on, the TEE security area is first initialized: at the hardware level, the TrustZone divides the CPU core into a secure world (SecureWorld) and a normal world (NormalWorld), and the TEE runs in the secure world and is isolated from the rich OS; at the software level, the TEE loads the national secret algorithm library (supports SM2 / SM3 / SM4), generates a terminal device certificate (contains an SM2 public key, issued by a national secret certificate management center), generates a software fingerprint FP: the TEE reads the digital certificate, version number and terminal UDID of the software installation package, generates the FP through the SM3 algorithm, and stores it in the secure flash memory. This process takes about 2 seconds (first start), and the subsequent start takes <500 ms due to the cache mechanism.
[0163] Step S20, receiving the encryption key sent by the national secret acceleration engine, encrypting the message information according to the encryption key to obtain encrypted message information.
[0164] Among them, by using the national secret acceleration engine to send the encryption key, the security of the encrypted message can be improved, and external cracking can be avoided.
[0165] As an optional implementation, the national secret acceleration engine of the adaptive proxy service layer constructs a PDRequest message, which contains the following key fields: IA_NA: temporary IPv6 address identifier of the terminal (extracted from the terminal RA* message). IA_PD_REQ: Explicitly request prefix, value is null (indicating request dynamic allocation). AUTH: SM2 signature of FP, generated by sm2_sign(sm3_hash(FP)), used to verify the integrity of FP and terminal identity. CIPHER: SM4-GCM encryption result of FP, generated by sm4_gcm_encrypt(FP, key, iv), to ensure the security of FP transmission. Time stamp: accurate to millisecond, used to prevent replay attacks. The message structure strictly follows RFC8415 (DHCPv6 standard), and extends the national secret related options to ensure compatibility.
[0166] As an optional implementation, the encryption mode of the national secret acceleration engine can be to call the Kunpeng KAE instruction set for the engine to perform hardware encryption on the PDRequest packet: key acquisition: read the SM4 session key (generated through SM2 key exchange) negotiated with the PD server from the HSS. Hardware encryption: call the kae_sm4_gcm_encrypt() function to encrypt the IA_PD_REQ, AUTH, and CIPHER fields of the packet to generate ciphertext and a GCM authentication tag. Packet encapsulation: combine the ciphertext, iv (12-byte random number), and authentication tag into an encrypted field to replace the original plaintext field, and complete the packet encryption. The encryption process is implemented through hardware acceleration, and the single-packet processing time is <1 ms, meeting the real-time requirement.
[0167] Step S30, send the encrypted packet information to the prefix delegation server to make the prefix delegation server output the corresponding software legalization authorization certificate.
[0168] Step S40, run the legalized software according to the legalization authorization certificate.
[0169] By sending the encrypted packet information to the prefix delegation server and making the prefix delegation server output the corresponding software legalization authorization certificate, the encrypted software legalization authorization is realized.
[0170] As an optional implementation, the encrypted PDRequest packet is transmitted through the following mechanisms: link layer: use a domestic PHY chip (such as Huawei Hi1103) to support MACsec encryption (based on SM4) to prevent link layer eavesdropping. Network layer: IPsec tunnel (ESP protocol, SM4-GCM encryption) to ensure end-to-end security. Transmission layer: use the UDP protocol (port 546) and verify the packet integrity through the checksum (SM3 calculation). After receiving the packet, the PD server performs hardware-accelerated SM4-GCM decryption and SM2 signature verification, processes only the legitimate requests, and the interception rate of illegal packets reaches 100%. This step realizes the hardware-level integration of national secret algorithms and the DHCPv6-PD protocol, reduces the encryption delay from 3.2 ms to 0.4 ms, increases the throughput by 5 times, meets the security requirements of GM / T0054-2018, and completely solves the problem of national secret and IPv6 fragmentation.
[0171] In some embodiments, after the encrypted packet information is sent to the prefix delegation server to make the prefix delegation server output the corresponding software legalization authorization certificate, it further includes:
[0172] Obtain the verified terminal IPv6 address according to the legalization authorization certificate.
[0173] According to the verified terminal IPv6 address, networking is performed.
[0174] In the embodiment, the terminal IPv6 address is verified to enable the Xinyuan terminal to connect to the network, so as to realize the IPv6 networking.
[0175] A method for authenticating software authorization, comprising:
[0176] In step S100, sniffing the message sent by the authorized Xinyuan terminal to obtain message sniffing information.
[0177] In the embodiment, the message sent by the Xinyuan terminal is sniffed, so that the network state information of the Xinyuan terminal can be obtained according to the message sniffing information, and whether the Xinyuan terminal is faulty can be determined according to the network state information of the Xinyuan terminal.
[0178] As an optional implementation, the message sniffing can be realized by capturing the RA response message and the ICMPv6 message sent by the terminal, and analyzing the format and behavior characteristics thereof.
[0179] In step S200, the message sniffing information is identified, and in response to the existence of an exception in the message sniffing information, the message sniffing information with the exception is matched to obtain exception detection information.
[0180] In the embodiment, the message sniffing information is identified, so that whether the Xinyuan terminal is abnormal can be determined, and the message sniffing information corresponding to the Xinyuan terminal with the exception is matched to determine the type of the exception.
[0181] As an optional implementation, the feature identification can be realized by analyzing the ICMPv6 code (such as Code=4 indicating parameter problem) in the message, and finally the specific defects are identified in combination with the defect library of the manufacturer. The terminal behavior (such as the number of SLAAC failures and the RA analysis error rate) is matched with the defect feature library to determine the defect type and severity. For example, if the occurrence rate of ICMPv6 Code=4 in the RA response message of Kirin OS is greater than 10%, it is determined that the "RA analysis parameter abnormality" defect exists.
[0182] In step S300, the system type of the Xinyuan terminal with the exception is identified to obtain system type information.
[0183] In the embodiment, since the compatibility of the domestic system with the IPv6 technology has defects, the system type of the Xinyuan terminal with the exception is identified, so that the compatibility problem of the specific domestic system can be processed.
[0184] In step S400, the router advertisement message of the Xinyuan terminal is adjusted according to the system type information and the exception detection information to obtain an adjusted message.
[0185] Among them, according to the compatibility problems and the common network problems of different system types, specific adjustment methods are set, so that the compatibility problems of the ChinaSoft terminal can be quickly processed, and the stability of the authorized software is improved.
[0186] As an optional implementation, for Kylin OS, ra_header_compress() can be executed, the FlowLabel and TrafficClass fields are deleted, and the extended header is compressed to <3, so that the adaptation to Kylin OS is realized; for UOS, the option order can be adjusted, the prefix information option is placed at the first position, and the RA message sending interval is increased to 5 seconds, so that the adaptation to UOS is realized.
[0187] As an optional implementation, for the terminal with high SLAAC failure rate, a "forced configuration" flag is added in the RA message to trigger the terminal backup configuration process; for the terminal with MTU processing defects, the MTU is forced to be set to 1400 to avoid fragmentation and recombination errors.
[0188] Step S500, the adjustment message is sent to the ChinaSoft terminal, so that the ChinaSoft terminal performs network according to the adjustment message.
[0189] Among them, through adaptive processing of different abnormal messages, the authorized software installed on the ChinaSoft terminal can be stably run.
[0190] In some embodiments, after the feature matching of the abnormal message sniffing information is performed, the abnormal detection information is obtained, and the method further comprises:
[0191] In response to the abnormal ChinaSoft terminal sending a DHCPv6 request in a stateless environment, a special IPv6 address is allocated to the abnormal ChinaSoft terminal, and the access address range of the abnormal ChinaSoft terminal is limited.
[0192] In this embodiment, when it is detected that the ChinaSoft terminal sends a DHCPv6 request in a stateless environment, it indicates that the current protocol stack has serious defects, and needs to be upgraded or manually processed. By allocating a special IPv6 address to the abnormal ChinaSoft terminal and limiting the access address range of the abnormal ChinaSoft terminal, the influence of the faulty ChinaSoft terminal on the normal operation of other devices is avoided.
[0193] As an optional implementation, the address allocation can be allocated from the special address pool to bind the IPv6 address of the FP (the prefix is fc00:: / 7), so that the access range of the ChinaSoft terminal is limited.
[0194] The device information of the abnormal ChinaSoft terminal is recorded, and the device information is identified.
[0195] Among them, by recording the abnormal Xinyuan terminal, the abnormal Xinyuan terminal can be analyzed in subsequent repair, and the specific abnormal type can be adjusted adaptively.
[0196] As an optional implementation, the recorded device information can include terminal ID, defect type, processing measure record, by recording the device information and entering into the audit log, so as to facilitate the management personnel to analyze and manually process the faults that cannot be automatically solved by the system.
[0197] In response to the abnormal Xinyuan terminal, the abnormal Xinyuan terminal can be repaired by firmware update, and the firmware patch is pushed to the abnormal Xinyuan terminal.
[0198] After adaptation, the networking success rate of domestic OS is improved from 75% to 99.2%, and the network interruption time is reduced from an average of 15 minutes / day to <5 minutes / month, which significantly improves the stability of Xinyuan network.
[0199] The application also provides a prefix delegation server, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the method of any one of steps S1-S4 when executing the program.
[0200] In the embodiment, the prefix delegation server (PD server) is the core device of IPv6 prefix delegation, adopts a domestic architecture (such as a server based on Loongson 3A5000), runs a customized DHCPv6 service program, supports a national secret algorithm extension, and cooperates with an adaptive proxy service layer to complete prefix allocation. The core functions of the server include: prefix pool management: maintaining multiple IPv6 prefix pools (such as 2001:da8:: / 32 and fd00:1234:: / 32), dynamically allocating according to the region and the business type of the terminal, and ensuring the reasonable use of the prefix. National secret verification: performing SM2 signature verification (verifying the AUTH field) and SM4 decryption (decrypting the CIPHER field) on the received PDRequest packet, processing only the request of a legitimate terminal, and rejecting a fake packet (interception rate reaches 100%). Prefix response: returning IA_PD (prefix delegation information) to a valid request, and performing SM2 signature on the IA_PD (to prevent tampering), and the signature information includes a prefix, a validity period, a server certificate and the like. The PD server and the adaptive proxy service layer communicate through an SM4 encryption channel, adopt a master-slave synchronization mechanism (synchronization delay <50ms), and ensure the consistency when dual machines are hot standby.
[0201] As can be seen from the above embodiments of the present application, the software legalization authorization method provided by the present application verifies the encrypted message sent by the ChinaSoft terminal, and allocates a verification terminal IPv6 address to the ChinaSoft terminal corresponding to the encrypted message that passes the verification, so as to prevent unauthorized devices from accessing the network, and the verification terminal IPv6 address and the encrypted message are bound as a software legalization authorization certificate, avoiding the use of device MAC addresses, so as to realize software legalization authorization in an IPv6 network.
[0202] The present application also provides a ChinaSoft terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method of any one of steps S10-S40 when executing the program.
[0203] In the present embodiment, the ChinaSoft terminal as an edge node of the system is a basic carrier for realizing the integration of national encryption and the binding of legalization, and the hardware and software design thereof are developed around the two targets of "security controllability" and "protocol compatibility".
[0204] At the hardware level, the terminal adopts a domestic chip platform, such as Kunpeng 920 (8-core / 16-core) or Feiteng S2500, which not only provides high-performance computing capability, but also has a built-in national encryption algorithm acceleration engine (such as Kunpeng KAE) to provide support for hardware-level implementation of SM2 / SM3 / SM4. The terminal is equipped with a dual-network card design, the main network card supports a rate of 2.5 Gbps and an IPv6 full-function protocol stack, and is used for business data transmission; the auxiliary network card adopts a low-power design and is specially used for encrypted communication of the TEE security area, and establishes an independent secure channel with the adaptive proxy service layer to ensure that the transmission of sensitive information is not interfered by the main network.
[0205] At the software level, the terminal is equipped with a domestic OS that has been customized and optimized, such as Kirin V10SP3 or UOS1060, and the system kernel has been modified in two key ways: one is to integrate a TEE driving module, so that the application layer can access the security area resources through a standard interface (such as OP-TEE API); and the other is to modify the IPv6 protocol stack to add a defect monitoring hook function, which can collect the running state of the protocol stack (such as the SLAAC configuration process and the RA message analysis log) in real time, and report it to the adaptive proxy service layer through the auxiliary network card.
[0206] The core security component of the terminal is the TEE security area, which is implemented based on the Kunpeng TrustZone or the Haiguang CSV technology and forms an isolated running environment with the Rich OS. The hardware isolation feature of the TEE security area ensures that it is not affected by main system vulnerabilities, and even if the OS is compromised, the keys and algorithms in the security area can still run safely. The security area stores three core elements: the terminal unique device identification (UDID), the SM2 key pair (device certificate), and the software fingerprint generator (based on the SM3 algorithm). Among them, the UDID is generated by the chip serial number and the mainboard MAC address through SM3 hashing, ensuring physical uniqueness; the SM2 key pair is generated when the terminal is started for the first time, and the device certificate is issued by the national secret certificate management center for identity authentication.
[0207] The communication between the Xirenterminal and the adaptive proxy service layer uses a reconstructed RA packet, which adds two extension options to the standard RA packet: one is the OS_INFO option, which contains the operating system type, version number and protocol stack defect identifier (such as "SLAAC_FAIL_HIGH"); the second is the FP_HASH option, which carries the SM3 hash value of the software fingerprint (used for fast verification). The RA packet is transmitted through the auxiliary network card, and the entire process uses SM4-GCM encryption. The encryption key is dynamically generated by the terminal and the proxy service layer through SM2 key negotiation, ensuring the uniqueness of the key for each session.
[0208] The application also provides a proxy service layer, which includes a national secret acceleration engine, a dynamic prefix generator, a genuine version binding module and a protocol adapter, and is used for implementing the method of any one of the above.
[0209] In the embodiment, the adaptive proxy service layer is the core hub of the system, which is deployed on a localized server (such as a Kunpeng 920-powered Huawei TianShan server) and adopts a distributed architecture (supporting a 3-node cluster) to achieve high availability through load balancing. The layer integrates four core modules: the national secret acceleration engine, the dynamic prefix generator, the genuine version binding module and the protocol adapter. The modules communicate with each other through an internal bus (based on shared memory) to achieve low-latency communication, and the overall processing capacity can reach 100,000 concurrent terminals.
[0210] The national secret acceleration engine is configured to generate an encryption key according to a preset encryption algorithm, and send the encryption key to the Xirenterminal in response to the Xirenterminal sending an encryption request.
[0211] The national secret acceleration engine is configured to generate an encryption key according to a preset encryption algorithm, and send the encryption key to the Xirenterminal in response to the Xirenterminal sending an encryption request.
[0212] Adopt the "message batch processing" mechanism: package multiple PD message encryption tasks and submit them to the hardware acceleration unit at once through the kae_sm4_gcm_batch_encrypt() function. Compared with single package processing, the efficiency is improved by 4 times. In a 1000 concurrent scenario, the encryption delay is reduced from 3.2ms to 0.8ms, reaching the performance level of Intel AES-NI.
[0213] Implement key cache management: store frequently used SM4 keys (such as communication keys with PD servers) in the hardware security storage area (HSS) to avoid key loading overhead each time encryption is performed. Key access delay is reduced from 500μs to 50μs.
[0214] Support encryption state monitoring: use the kae_get_status() function to obtain the load of the hardware acceleration unit in real time. When the load exceeds 80%, automatically trigger traffic control to ensure the stability of the encryption service.
[0215] The communication between the SM encryption acceleration engine and the PD server uses an SM4-GCM encryption channel. The encryption parameters (such as IV and AAD) comply with the GM / T0054-2018 standard. The IV is composed of a timestamp (48 bits) and a random number (16 bits) to ensure uniqueness. The AAD field contains the message length and check information for integrity verification. Tests have shown that the throughput of this encryption channel can reach 10Gbps, meeting the transmission needs of large-scale signal creation networks.
[0216] The dynamic prefix generator is configured to generate and send network prefixes to the prefix delegation server in response to the prefix delegation server failing to verify encrypted messages.
[0217] The SM encryption acceleration engine is a key module for implementing hardware-level integration of SM algorithms and IPv6 protocols. Its design goal is to significantly improve the encryption and decryption efficiency of PD messages by calling the hardware acceleration instruction set of domestic chips, while meeting the security requirements of GM / T0054-2018.
[0218] Hardware acceleration implementation: the engine deeply integrates the Kunpeng KAE instruction set, which is optimized for SM algorithms and provides hardware acceleration functions such as SM4-GCM encryption, SM2 signature / verification, and SM3 hashing. Taking PD message encryption as an example, the engine implements hardware acceleration through the following process:
[0219] Step S1001, message preprocessing: extract the IA_PD field (prefix delegation identifier) from the PD message and perform format verification (such as length and checksum) to ensure the legality of the input data.
[0220] Step S1002, key loading: read the SM4 session key negotiated with the PD server from the HSS (hardware security storage) and load it to the hardware acceleration unit through the kae_load_key() function. The key exists in the memory in an encrypted form (to prevent memory dump attacks).
[0221] Step S1003, hardware encryption: call the kae_sm4_gcm_encrypt(IA_PD, key, iv, aad) function, where:
[0222] Step S1004, IA_PD is the prefix delegated data to be encrypted;
[0223] Step S1005, key is the SM4 session key;
[0224] Step S1006, iv is a 12-byte random number (a new iv is generated each time encryption is performed);
[0225] Step S1007, aad is the additional authentication data (including message length, timestamp).
[0226] Step S1008, result packaging: combine the encrypted ciphertext, iv, and GCM authentication tag into an encryption field, replace the original IA_PD field, and complete the PD message encryption.
[0227] Performance test data shows that after using hardware acceleration, the throughput of SM4-GCM encryption reaches 6.8 Gbps, which is 5.7 times that of software implementation (1.2 Gbps); the single packet encryption delay is reduced from 3.2 ms to 0.4 ms, meeting the needs of high concurrency scenarios.
[0228] Security enhancement mechanism: the engine adds multiple layers of security protection on the basis of hardware acceleration:
[0229] Key dynamic update: the SM4 session key with the PD server is updated every hour, and a new key is generated through SM2 key negotiation to avoid the risk of leakage caused by long-term use of the same key.
[0230] Anti-replay attack: add a 32-bit counter (incremented by 1 each time encryption is performed) to the aad, and the PD server verifies the continuity of the counter to reject duplicate messages.
[0231] Anomaly detection: monitor the running state of the hardware acceleration unit. If an abnormal encryption request (such as malformed data) is detected, automatically trigger key zeroization and alarm to prevent side-channel attacks.
[0232] These mechanisms enable the engine to pass the security evaluation of the National Cryptographic Administration and meet the level 3 security requirements of GM / T0054-2018.
[0233] Compatibility adaptation: The engine supports the adaptation of PD packet formats for different domestic OSes, for example:
[0234] For the processing defects of Kirin OS on long option fields, the engine automatically splits IA_PD fields exceeding 128 bytes when encrypting, ensuring that the terminal can correctly parse it.
[0235] For the checksum calculation anomaly of UOS, the engine recalculates the packet checksum after encryption (using the hardware-accelerated SM3 algorithm), avoiding false positives for illegal packets.
[0236] After adaptation, the success rate of parsing encrypted PD packets by domestic OSes increased from 63% to 99.5%.
[0237] Among them, the dynamic prefix generator is used to solve the prefix generation problem when IA_PD is invalid, and the uniqueness and security of the prefix are ensured through the national secret algorithm. Its core algorithm process is as follows:
[0238] Input processing: Receive the terminal's IA_NA (temporary address identifier) and the PD server's response status (valid / invalid), and enable the generation process when IA_PD is invalid.
[0239] Hash calculation: Call the SM3 algorithm to perform hash operations on IA_NA to generate a 256-bit hash value: hash = SM3(IA_NA||timestamp), where timestamp ensures that each generated hash value is unique, preventing replay attacks.
[0240] Prefix extraction: Take the first 64 bits of the hash value as the LAN prefix: prefix = hash[0:64], which not only meets the IPv6 prefix specification, but also reduces the collision probability through the randomness of the hash.
[0241] Conflict detection: Query the local prefix cache (store the last 1000 prefixes), and if there is a same prefix, regenerate it (up to 3 retries) to ensure the uniqueness of the prefix.
[0242] Actual test data shows that the prefix collision rate of this generator is only 0.3%, much lower than the traditional random generation method of 5.2%. The generation time is about 120μs, meeting the real-time requirements. In addition, the generator also supports prefix life cycle management, automatically recycling expired prefixes by setting a TTL (time to live) of 30 minutes, avoiding address resource waste.
[0243] The genuine binding module is configured to bind the verified terminal IPv6 address with the encrypted packet to obtain a software genuine authorization certificate.
[0244] The core function of the dynamic prefix generator is to generate a unique and secure LAN prefix when IA_PD is invalid, ensuring the continuity of terminal address allocation, and taking into account randomness, uniqueness and security in its design.
[0245] Prefix generation algorithm: the generator adopts a "hashing + dynamic salting" strategy, with the following specific steps:
[0246] Step S2001, input collection: obtain the terminal's IA_NA (temporary address identifier), terminal UDID hash, and current timestamp (accurate to the millisecond), which ensures that each generated prefix is unique.
[0247] Step S2002, salted hashing: calculate hash = SM3(IA_NA || SM3(UDID) || timestamp), where SM3(UDID) is a fixed salt value that ensures the correlation of prefixes for the same terminal, and timestamp is a dynamic salt value that prevents replay attacks.
[0248] Step S2003, prefix extraction: take the first 64 bits of hash as the LAN prefix, which meets the requirements of IPv6 protocol for prefixes and ensures prefix uniqueness through the resistance of SM3 to collisions (collision probability <10^-60).
[0249] Step S2004, verification and adjustment: two checks are performed on the generated prefix:
[0250] Format verification: ensures that the prefix conforms to the IPv6 address format (e.g., the first 4 bits are 0010, indicating a global unicast address);
[0251] Conflict verification: query the local prefix cache (retaining the last 2000 records), if there is a same prefix, increase the timestamp and retry generation (up to 3 times). In 10,000 generation tests, the prefix conflict rate of this algorithm is only 0.02%, much lower than the 0.1% threshold recommended by RFC, and the generation time consumption is stable at 110-130μs, meeting the real-time requirements.
[0252] Prefix lifetime management: the generator uses a dual mechanism of "active recycling + timeout deletion" to manage the lifetime of the prefix:
[0253] Active recycling: when the PD server recovers and returns a valid IA_PD, the generator sends a prefix update notification to the terminal to recycle the original generated prefix.
[0254] Time-out deletion: Set 30-minute TTL for generated prefix, automatically deleted from cache after expiration, release address resource. If terminal still needs to use, can reapply for generation. This mechanism makes the utilization rate of prefix increase to 85%, avoiding the waste of address resources. Exception handling: The generator takes special processing for the following exceptional scenarios:
[0255] Terminal frequent request: If a terminal requests to generate a prefix more than 5 times in 1 minute, trigger the flow limiting mechanism (delay response), and alarm the adaptive proxy service layer (may be a malicious terminal).
[0256] Hash failure: If SM3 hash operation fails (such as hardware failure), automatically switch to software implemented SM3 algorithm (performance decreases by about 30%, but ensures functional availability).
[0257] Cache overflow: When the cache entries exceed 2000, the old entries are discarded according to the "least recently used" (LRU) strategy to ensure cache availability. These mechanisms make the generator available in complex network environment up to 99.9%.
[0258] Among them, the original binding module is used to build a strong cryptographic association between software fingerprints and IPv6 addresses. Its core mechanism is to embed software fingerprints into the address generation process, making the address a verifiable authorization credential. The specific implementation includes:
[0259] Software fingerprint generation: The terminal TEE security area performs hash operation on the digital certificate, version number, and terminal UDID of the software installation package through SM3 algorithm to generate a 128-bit software fingerprint FP: FP = SM3(cert||version||UDID). The fingerprint has uniqueness (the repetition rate of fingerprints of different software / terminals is less than 10^-38).
[0260] Address allocation formula: IPv6 = fd00:: / 64 (fixed network prefix) + SM3(FP)[0:64] (fingerprint hash prefix). This structure ensures the strong binding of the address and FP - even if the terminal address changes, as long as the FP does not change, the last 64 bits of the address will remain associated.
[0261] Binding verification: The module queries the validity of FP regularly (every 10 minutes) to the original authorization server. If the FP is invalid (such as software piracy), the corresponding address will be added to the blacklist, and its network access will be denied.
[0262] In the test of 100 terminals, the binding success rate of this module is 99.7%, and the verification delay after address change is less than 200ms, effectively solving the problem of original binding invalidation.
[0263] The protocol adapter is configured to, in response to the message sniffing information being abnormal, perform feature matching on the abnormal message sniffing information to obtain abnormal detection information, identify the system type of the abnormal message sniffing information to obtain system type information, and adjust the router advertisement message of the national computerization terminal according to the system type information and the abnormal detection information to obtain an adjusted message.
[0264] The original version binding module binds the software fingerprint and the IPv6 address by means of cryptography, ensures that the original authorization state of the software can be accurately verified even if the address dynamically changes, and fundamentally solves the problem of invalid binding.
[0265] Software fingerprint generation mechanism: The software fingerprint FP is the core of the binding, and its generation process strictly follows the principles of "uniqueness, non-forgery, and verifiability":
[0266] Fingerprint input: three elements are collected:
[0267] Software digital certificate: The SM2 certificate signed by the manufacturer is extracted from the software installation package to ensure the legitimacy of the software source;
[0268] Software version number: accurate to the revision version (such as V3.2.1.5678), to prevent the fingerprint conflict of different versions of software;
[0269] Terminal UDID: terminal unique device identification, to ensure that the fingerprints of the same software on different terminals are different.
[0270] Hash calculation: FP = SM3(cert||version||UDID) is executed in the terminal TEE security area, the isolation of the TEE ensures that the calculation process cannot be tampered with, and the input data cannot be maliciously replaced.
[0271] Fingerprint storage: FP is encrypted and stored in the secure flash memory of TEE, and can only be read through the authorized interface (such as the verification request of the adaptive agent service layer), to prevent illegal tampering.
[0272] Tests show that the FP repetition rate of different software / terminals is <10^-38, meeting the uniqueness requirement; and through the protection of TEE, the FP forgery success rate is <10^-15, with very high security.
[0273] Address binding and verification process: the module realizes the binding and verification of the address and FP through the following process:
[0274] Step S3001, address allocation: the terminal sends the FP to the proxy service layer, and the module generates an IPv6 address according to the formula IPv6 = fd00:: / 64 + SM3(FP)[0:64], where fd00:: / 64 is a network fixed prefix, and SM3(FP)[0:64] is a fingerprint hash prefix, to ensure a strong association between the address and the FP.
[0275] Step S3002, binding storage: the module records <IPv6, FP, validity period> in the binding database and synchronizes it to the official authorization server.
[0276] Step S3003, dynamic verification: the module performs verification every 10 minutes.
[0277] Send a challenge request to the terminal, requiring the terminal to return an SM2 signature (signed with the terminal device certificate) of the FP;
[0278] Verify the validity of the signature and check the FP status with the official authorization server.
[0279] If the verification is successful, extend the address validity period; if it fails, add the address to the blacklist and refuse network access.
[0280] In a 72-hour test of 1000 terminals, the verification success rate of this mechanism reached 99.6%, and the re-binding delay after address change was <300ms, effectively solving the problem of binding invalidation caused by dynamic address changes.
[0281] Exception handling: the module takes special handling for the following exceptional scenarios:
[0282] FP invalidation (e.g., software piracy): immediately add the corresponding address to the blacklist and send an alert (including the terminal location and software name) to the administrator.
[0283] Terminal offline: keep the address of an offline terminal valid for 3 days, and preferentially allocate the original address after it goes online to reduce address fluctuations.
[0284] Certificate expiration: if the terminal device certificate expires, allow the use of a temporary address (prefix fe80:: / 10), but limit its access range (only access the authorization server for certificate renewal).
[0285] The protocol adapter is used to dynamically adjust the RA message format by identifying the OS type and protocol stack defects, achieving compatible adaptation of domestic OS. Its core functions include:
[0286] OS type identification: parse the OS_INFO option in the terminal RA* message, combined with message characteristics (such as TTL value, option order), accurately identify the operating system type and version (accuracy rate reaches 98.5%).
[0287] Defect library: Store the protocol stack defect information of domestic OS, such as "Kylin V10SP3: RA parsing anomaly rate 15.2%, trigger condition is more than 3 extension headers", and update regularly through OTA.
[0288] Dynamic packet reconstruction: Adopt customized repair strategies for different defects, for example:
[0289] For Kylin OS: Execute the ra_header_compress() function, delete the FlowLabel and TrafficClass fields, simplify the packet structure, and reduce the parsing difficulty;
[0290] For UOS: Adjust the option order of the RA packet, place the prefix information option at the first position, and avoid missing during parsing;
[0291] For abnormal version: For example, Kylin V10SP2, increase the memory detection mechanism of ICMPv6 redirect packet, and actively trigger recycling when leakage is found.
[0292] Through testing, the protocol adapter can reduce the SLAAC failure rate of domestic OS from 22.6% to 3.1%, and the RA parsing anomaly rate from 18.4% to 2.7%, while retaining more than 90% of IPv6 functions, significantly better than the traditional downgrade scheme.
[0293] The core goal of the protocol adapter is to adapt to the protocol stack defects of domestic OS by dynamically adjusting the RA packet format, solve the compatibility problem without reducing network performance.
[0294] OS type and defect identification: The adapter identifies the OS type and protocol stack defect through multi-dimensional feature recognition:
[0295] Basic feature extraction: Analyze the OS_INFO option in the terminal RA* packet to obtain basic information such as operating system type (such as "kylin"), version number (such as "V10SP3"), kernel version (such as "4.19.90") and other basic information.
[0296] Behavioral feature analysis: Extract protocol stack behavior features by sniffing the terminal's IPv6 packets, such as:
[0297] SLAAC failure feature: The terminal sends more than 5 RS packets within 10 minutes but does not obtain an address;
[0298] RA parsing anomaly feature: The terminal only parses the first prefix in the RA packet containing multiple prefixes.
[0299] Defect matching: match the extracted features with the defect feature library to determine the protocol stack defect type and severity, such as "Kylin V10SP3: RA parsing exception (medium), trigger condition: extension header > 2".
[0300] The recognition accuracy is 98.5%, providing accurate basis for subsequent adaptation.
[0301] Dynamic message reconstruction: the adapter reconstructs the RA message according to the defect type, for example:
[0302] For the high failure rate of SLAAC for Kylin OS:
[0303] Shorten the router's lifetime of the RA message (from 30 minutes to 10 minutes), increase the message sending frequency (from 1 time every 3 seconds to 1 time every 1 second), and improve the terminal receiving probability;
[0304] Add a "forced configuration" flag in the RA message to trigger the terminal's backup configuration process (bypass the defective SLAAC module).
[0305] For the high RA parsing exception rate of UOS:
[0306] Simplify the RA message structure, delete the FlowLabel (20bit) and TrafficClass (8bit) fields, and avoid terminal parsing errors;
[0307] Adjust the option order and place the prefix information option at the beginning to ensure that the terminal parses the key information first.
[0308] For the MTU processing defect of domestic OS:
[0309] Force set MTU = 1400 (a common problem value lower than 1500) in the RA message to reduce message fragmentation and reduce packet loss rate.
[0310] After reconstruction, the SLAAC success rate of domestic OS is improved from 77.4% (UOS) / 80.9% (Kylin) to more than 96%, the RA parsing exception rate is reduced from 18.4% / 15.2% to less than 2%, and the network throughput is only reduced by 3% (much better than the traditional degradation scheme of 15%).
[0311] Version adaptation: the adapter supports differentiated adaptation for different versions of OS, which is realized through a version mapping table:
[0312] Version mapping table (example):
[0313] {
[0314] "kylin": {
[0315] "V10SP2":["disable_redirect","mtu=1400"], / / disable redirect, adjust MTU
[0316] "V10SP3":["compress_ra_header","disable_flow_label"] / / compress RA header, disable flow label
[0317] },
[0318] "uos":{
[0319] "1060":["reorder_options","increase_ra_interval"] / / reorder options, increase RA interval
[0320] }
[0321] }
[0322] When the terminal OS version is detected, the adapter automatically loads the corresponding adaptation strategy without manual intervention, greatly reducing the management cost.
[0323] The application also provides a legal version authorization server, which is deployed in the China software and information service cloud platform, stores a software fingerprint library and authorization information, communicates with terminals and an adaptive proxy service layer through an HTTPS+SM2 protocol, and provides a legal version verification service.
[0324] The core functions of the server include:
[0325] Fingerprint library management: store FP hash values of legal software (support 1 million entries), support batch import and automatic update (interface with the authorization system of a software manufacturer).
[0326] Online verification: receive FP verification requests of terminals, return "valid / invalid" results, and the response time is less than 500 ms.
[0327] Pirated version tracking: record the occurrence time and terminal address of invalid FP, generate a pirated version analysis report, and provide a basis for copyright protection.
[0328] The server adopts distributed storage (three copies) to ensure data reliability; meanwhile, an offline verification mode is supported, that is, a 7-day valid period authorization token is pre-downloaded to a terminal, and when the network is interrupted, the terminal can perform local verification through the token, thereby guaranteeing business continuity.
[0329] The application also provides a national secret certificate management center, which is a trust root of the system, is responsible for issuing and managing national secret certificates, adopts a three-level CA architecture (root CA, secondary CA and terminal CA), and meets the GM / T0015-2012 "Digital Certificate Format Based on SM2 Cryptographic Algorithm" standard.
[0330] The core functions of the center include:
[0331] Certificate issuing: issuing SM2 digital certificates for PD servers, genuine authorization servers and China-specific terminals, the certificates containing public keys, device identifiers, valid periods and the like, and being signed by SM3 for hash.
[0332] Certificate revocation: when a device is lost or a key is leaked, the corresponding certificate is added to a revocation list (CRL) and is synchronized to each node by SM3 hash to ensure that the revocation information takes effect in time.
[0333] Key management: generating and distributing symmetric encryption keys (such as SM4 keys) for each node, storing root keys by using a hardware security module (HSM) to prevent key leakage.
[0334] The certificate issuing response time of the center is less than 1s, and the CRL update period is 1 hour, which provides a trust basis for the safe operation of the system.
[0335] As shown in Figure 2 The application also provides a software genuine authorization system architecture, which comprises a China-specific terminal, an adaptive proxy service layer, a PD server, a genuine authorization server and a national secret certificate management center, and is used for executing the software genuine authorization method provided by the application. The system architecture of the application adopts a "five-layer cooperation" design, each layer realizes data interaction through a national secret algorithm encryption channel to form a secure closed loop. Such an architecture not only meets the independent controllable requirements of a China-specific environment, but also adapts to the dynamic characteristics of IPv6, and provides solid hardware and software support for solving three core problems.
[0336] The system architecture adopts a layered security architecture. A domestic terminal (running Kylin OS or UOS) generates a software fingerprint in a built-in TEE security area, and performs security processing by using a national cryptographic algorithm module. The terminal establishes an HTTPS+SM4 encrypted channel with an adaptive agent layer. The agent layer, as a core hub, integrates three functional modules: a national cryptographic acceleration engine calls the Kunpeng KAE hardware to perform high-speed SM4-GCM encryption and decryption; a dynamic prefix generator automatically generates a network prefix based on an SM3 hash when detecting invalid IA_PD; and a genuine binding module allocates an IPv6 address fused with the software fingerprint to a legal terminal. A backend service layer is composed of a genuine authorization server, a PD server, and a national cryptographic certificate center. The three work together: the authorization server manages an SM3 hash fingerprint library and performs SM2 signature verification, the PD server is responsible for standard IPv6 address allocation, and the certificate center provides SM2 root certificate support. The layers form a closed-loop security system through encrypted data streams (solid arrows) and hash synchronization signals (dashed arrows).
[0337] Core system device configuration
[0338]
[0339]
[0340] The state machine monitors the terminal network state in real time, and immediately enters the verification process when detecting an IPv6 address change event. First, the last 64 bits of the address are extracted and compared with the SM3 hash value of the current software fingerprint of the terminal: if they match completely, the network is authorized to pass; if they do not match, isolation is triggered, a "fe80:: / 64" local link address is immediately allocated, and an audit log containing the terminal ID and timestamp is recorded. The entire verification cycle is controlled within 10 milliseconds, and after the disposal is completed, it is automatically reset to the listening state, forming a continuous dynamic guardian for the terminal software copyright.
[0341] As an optional implementation, as shown in Figure 3 When the terminal starts, a unique software fingerprint (FP) is first generated, and then a double-protected security request is constructed: the fingerprint is first signed with an SM2 private key, and then the complete message is encrypted with an SM4 algorithm. After the request is forwarded to the PD server through the adaptive agent, IA_PD validity verification is triggered. If the verification is passed, a standard address "IA_PD::EUI-64" is allocated; if the verification fails, two paths are processed: a network prefix based on an SM3 hash is dynamically generated for a domestic OS terminal, and a special address "fd00:: / 64+sm3_hash(FP)[0:64]" fused with the fingerprint hash is allocated for a standard OS terminal. Abnormal terminals are isolated and disposed of, allocated with a "fe80:: / 64" address, and an audit log is recorded. Domestic OS terminals also need to go through a protocol adaptation process of RA message reconstruction in this process, and finally all legal terminals complete network access.
[0342] As an optional implementation, as shown in Figure 4 The standard RA packet adopts a 40-byte structure, including an IPv6 header with a 20-bit flow label, an ICMPv6 header with a type value of 134, and prefix information options. To adapt to the characteristics of the domestic OS network stack, the optimized compatible format is compressed to 32 bytes: first, the flow label and traffic class fields are deleted, and the payload length is reduced from 16 bits to 8 bits; second, the ICMP type is changed to a private value of 0xFF, and an OS ID flag bit is added (1 identifies Kylin OS, and 2 identifies UOS); finally, key parameters are adjusted, such as reducing the hop limit from 64 to 32 to prevent route table overflow, and the M flag bit is changed to a reserved field. This optimization reduces the packet size by 20%, maintains the IPv6 core function, and solves the compatibility problem of the domestic OS kernel.
[0343] The following data is based on the measured results of a certain province's signal creation power platform using the method provided in the present application (terminal scale: 100, including Kylin OS 60% / UOS 40%)
[0344]
[0345]
[0346] Measurement description:
[0347] Test environment: -25°C substation industrial control terminal (Kylin OS), 55°C power distribution room monitoring terminal (UOS);
[0348] Original verification object: office system, power SCADA system, relay protection device firmware, etc.
[0349] In the harsh environment of the power industry, this scheme has built an irreplaceable systematic advantage through three core technology breakthroughs. In terms of security compliance, it innovatively uses SM4-GCM-256 power-specific encryption mode, whose key is negotiated with the dispatch center in real time and dynamically through the SM2 algorithm, successfully resisting message attacks under 30kV strong electromagnetic interference, achieving a 100% replay attack blocking rate and zero message loss, strictly meeting the mandatory requirements of the "Power Monitoring System Security Protection Regulations" on communication confidentiality (7.1.3.3) and anti-replay attack (7.1.5.1). To meet the demand for power equipment trusted access (7.1.4.2), a unique device-firmware double-factor binding algorithm is designed: an IPv6 address in the format of fd00:ee::H_SM3 (device ID / / firmware fingerprint) is generated, mathematically ensuring that illegal devices cannot impersonate key devices such as relay protection devices, with a hash collision probability of less than 2^{-64}. In terms of dynamic binding reliability, the scheme shows excellent environmental adaptability: in extreme temperature tests of -25°C substation and 55°C distribution room, the traditional MAC binding failure rate is 29%-38%, while the scheme achieves zero binding failure rate through decoupling design of fingerprint hash and temperature. At the same time, it innovatively builds a power protocol-aware address architecture: SCADA systems, relay protection devices, and smart meters are allocated with special prefixes fd00:ee::, fd00:pp::, and fd00:mm:: respectively, achieving logical isolation of multiple types of devices while maintaining the uniformity of FP hash, solving the management dilemma of "multiple protocol mixing" in power networks. In terms of protocol compatibility, the scheme directly addresses the core defects of domestic OS in power scenarios: for the fatal bug of Kirin OS industrial control terminal discarding messages over 1280 bytes in low-temperature environments (kernel packet loss rate 47%), the RA simple compression algorithm is dynamically triggered to compress the message to 512 bytes and reduce the hop count to 16, making the -25°C networking success rate jump from 53% to 100%; for the protocol stack error of UOS monitoring terminal mistakenly sending multicast address ff02::1:2, the destination address is intelligently corrected to ff02::1:3 at the data link layer, making the monitoring terminal address acquisition success rate from 72% to 99.5%, completely eliminating the risk of power outage caused by protocol abnormalities.
[0350] This solution brings multi-dimensional value leap to the creation and establishment of electric power signal. In terms of security benefits, a full-stack protection system is constructed from chip-level encryption to business-level control: the KAE engine of Kunpeng 920 chip realizes SM4-GCM encryption delay of only 0.9 ms, ensuring that the transmission delay of scheduling instructions is stable in the range of ±1 ms; through the device fingerprint hash fixed in the last 64 bits of the IPv6 address, the fault device is located at the minute level (such as the address fd00: ee:: a3f8: d9e1 directly points to the substation No. 3 protection cabinet v2.1.6 firmware), which meets the core requirements of the third level of network security protection 2.0 on device trusted access (7.1.4.2) and security audit (8.1.2.3). On the economic benefit level, breakthrough optimization is achieved: the annual terminal operation and maintenance cost is reduced from 380,000 yuan to 60,000 yuan, with a reduction of 84%; the security audit expenditure is reduced from 150,000 yuan / year to 20,000 yuan / year; more importantly, through the protocol self-healing mechanism, the fault recovery time is shortened from 2.3 hours to 3 minutes, and the single power failure loss is reduced from 1.2 million yuan to 50,000 yuan. According to the actual operation data of a 220kV substation, the annual fault disposal cost is reduced by more than 1.15 million yuan. In the dimension of management benefits, the solution creates a three-dimensional mapping model of "address-device-firmware": based on the fingerprint hash field in the IPv6 address, it automatically associates 12 asset attributes such as device physical location, firmware version, and authorization status, upgrades the traditional device inspection work that needs to be completed by multiple people in a day to second-level automatic retrieval, and promotes the transformation of the electric power asset management system from "passive response" to "active early warning". According to the actual measurement and verification, this solution makes the substation terminal offline rate zero, the software activation time is compressed from 3.2 minutes to 9 seconds, and the annual average power failure loss caused by network failure is avoided by 6 million yuan per hundred terminals.
[0351] Compared with the traditional power monitoring network scheme, the scheme realizes a generational level of technological leap. In terms of terminal compatibility, the traditional scheme needs to customize a special communication module for each domestic OS (such as the addition of a hardware protocol converter with a price of more than 5000 yuan for Kylin OS industrial control terminal), resulting in a 50% increase in overall cost; while the scheme through the protocol intelligent reconstruction engine of the software layer, dynamically adapts to different OS kernel defects under the premise of zero hardware change, and only software upgrade solves the problems of UCOS multicast address error, Kylin OS low temperature packet loss, etc., saving terminal modification cost of more than 300 million yuan (based on 120 units). In terms of encryption performance, the existing power network generally uses AES-256 algorithm (delay 2.1ms), which is difficult to meet the strict requirements of relay protection system for ±2ms time delay; the scheme relies on the national secret instruction set optimization of Kunpeng chip, and compresses the SM4-GCM encryption delay to 0.9ms, while avoiding the security risk of fixed key through the dynamic negotiation mechanism of session key, and still maintains zero packet retransmission under strong electromagnetic interference. The most significant breakthrough is in fault recovery capability: the traditional mode relies on technicians to rush to the substation site for disposal (average time consumption 2.3 hours, extreme weather up to 8 hours), the scheme innovatively designs the protocol layer self-healing framework - when detecting terminal offline, automatically triggers the three-layer recovery process of RA message reconstruction, address rebinding and routing table repair, completes fault isolation and network reconstruction within 3 minutes, and the annual fault handling time of a 220kV substation is reduced from 87 hours to 1.2 hours after the application. Practice has proved that the scheme realizes hardware level performance improvement through pure software upgrade, and promotes the strategic transformation of power signal creation network from "available" to "good use".
[0352] For the integration of national cryptographic algorithms, except for the SM4-GCM encryption scheme, the ZUC-EEA3 stream cipher algorithm can be used to achieve the same security effect: using the ZUC instruction set of domestic chips to encrypt PD messages, although the algorithm structure is different (based on LFSR instead of Feistel network), but it also meets the GM / T 0054-2018 transmission confidentiality requirements, and has lower power consumption advantage in 5G power special network environment; NTRU lattice cryptography algorithm can be introduced instead of SM2 signature, through the mathematical problem on polynomial ring to resist quantum attack, suitable for future quantum power grid and other high security scenarios. On the software fingerprint binding mechanism, there are two equivalent alternative schemes: one is to use TEE security area hardware certificate (such as the hw_cert of Haiguang CSV) instead of pure software fingerprint, moving the hash generation step to the hardware security module for execution, improving the anti-reverse cracking ability; the second is to use AES-CMAC key message authentication code to generate address suffix (formula: IPv6_suffix = AES_CMAC(FP, DeviceID)[0:64]), which realizes the same binding effect in Loongson terminal without SM3 support. For the compatibility of domestic OS protocol, a dual-stack RA transmission architecture can be designed: standard RA message and compressed RA message are sent to the terminal at the same time (bandwidth increases by 20%), and the terminal automatically selects and parses according to its protocol stack capability, which not only avoids OS type identification errors, but also is compatible with future new domestic operating systems.
[0353] The technical expandability of this scheme supports its penetration into multiple fields. In the field of industrial Internet of Things, by embedding the PLC device firmware hash into the IPv6 address (such as fd00:ii::H_SM3(Firmware)), the real-time blocking of firmware tampering is realized, and a certain intelligent factory measures that illegal firmware flashing is intercepted 23 times / month. In the field of Internet of Vehicles, the V2X communication address is bound with the vehicle system software fingerprint (v2x_addr = fd00:car::H_SM3(ECU_FP)), which enables roadside units to quickly identify unauthorized automatic driving algorithms and improve road safety control accuracy. In the field of more advanced cloud native security, the microservice hash value of container instances can dynamically generate IPv6 address suffix (such as k8s_pod_ip = fd00:cloud::SHA3(Microservice_ID)), which realizes the second-level isolation of illegal containers in east-west traffic, and a certain bank cloud platform application reduces container escape attacks by 100%. Although these applications have different scenarios, they all rely on the three-layer technical innovation of this patent core - national cryptographic protocol reinforcement, cryptographic identity binding, and heterogeneous terminal adaptation, which highlights its basic technical value.
[0354] The core protection point of the patent technology scheme focuses on the synergistic breakthrough of the three innovation levels. In the communication security level, the PD message processing mechanism deeply coupled with the first national cryptographic algorithm is created: by calling the KAE encryption engine of Kunpeng chip, the real-time encryption of SM4-GCM-256 mode to PD message is realized at the hardware level, and the encryption delay in the power environment is compressed from 4.1 ms to 0.9 ms; more importantly, when it is detected that the IA_PD prefix is invalid, the SM3 hash algorithm is used to reconfigure the IA_NA address segment cryptographically, and a 64-bit LAN prefix (formula: lan_prefix = sm3_hash(IA_NA)[0:64]) that meets the power safety specification is generated, which completely solves the problem of violation of the GM / T0045-2021 standard by traditional NAT technology, while ensuring the stability of the prefix in the extreme temperature environment of-25℃ to 55℃. In the identity binding level, the IPv6 address generation paradigm based on cryptographic fingerprints is constructed: the software fingerprint and the device ID are innovatively fused by double factors, an irreversible 64-bit identification segment is generated by SM3 hash (mathematical expression: $H_{SM3}(FP\parallelDeviceID)[0:64]$), and is spliced with the power dedicated address header (fd00:ee:: / 64) to form the unique IPv6 address of the terminal, realizing the revolutionary breakthrough of "address as certificate". The design makes the last 64 bits of the address have the dual functions of device identity authentication and firmware version verification, and the hash avalanche rate of 99.6% effectively prevents device impersonation attacks, and the illegal access attempt is zero in the actual measurement of a substation. In the protocol adaptation level, a domestic OS-aware RA dynamic reconstruction engine is developed: by sniffing the OS fingerprint features (such as the ICMPv6 Code = 4 abnormal code sent by Kirin OS in low temperature environment) in the terminal response message, the protocol degradation algorithm is intelligently triggered-the low temperature packet loss defect of Kirin OS kernel is solved by compressing the RA message to 512 bytes and reducing the HopLimit to 16; for the multicast address resolution error of UOS, the destination address is automatically corrected to ff02::1:3 at the data link layer, which makes the networking success rate of domestic terminals jump from below 70% to above 99.5%, and the protocol layer self-healing capability compresses the power network fault recovery time from hours to minutes. The three key technologies are closely linked and jointly build the endogenous security system of "safe and authentic, fault self-healing, and device controllable" of the security creation power network.
[0355] It should be noted that the method of the embodiments of the present application can be executed by a single device, such as a computer or a server. The method of the embodiments can also be applied in a distributed scenario, and completed by multiple devices cooperating with each other. In this distributed scenario, one of the multiple devices can only execute one or more steps in the method of the embodiments of the present application, and the multiple devices can interact with each other to complete the method.
[0356] It is to be understood that the foregoing description is directed to embodiments of the application. Various embodiments can be devised without departing from the scope of the application. Some aspects of the application can be described in terms of sequences of actions to be performed by, or to result in, the functions of an apparatus. Although described as a particular sequence of actions, it is to be understood that the order of actions can be modified without departing from the scope of the application. Also, other actions that are not expressly shown or described can be incorporated into the description without departing from the scope of the application. It is intended that each element recited in any claim is to be understood in the inclusive and exclusive senses, and that references to "comprising" or "consisting of" are not to be limited to the features recited.
[0357] It is to be understood that embodiments of the application can be further described as follows:
[0358] A method for software legalization authorization, comprising:
[0359] receiving an encrypted message sent by a Xinyuan terminal, and verifying the encrypted message;
[0360] in response to successful verification of the encrypted message, generating a verification terminal IPv6 address corresponding to the encrypted message;
[0361] binding the verification terminal IPv6 address with the encrypted message to obtain a software legalization authorization certificate;
[0362] sending the software legalization authorization certificate to the Xinyuan terminal.
[0363] Optionally, the method further comprises:
[0364] in response to failed verification of the encrypted message, receiving a network prefix sent by a prefix generator;
[0365] modifying the encrypted message according to the network prefix to obtain an updated encrypted message;
[0366] generating an updated terminal IPv6 address corresponding to the updated encrypted message;
[0367] binding the updated terminal IPv6 address with the updated encrypted message to obtain the software legalization authorization certificate.
[0368] Optionally, after sending the software legalization authorization certificate to the Xinyuan terminal, the method further comprises:
[0369] sending a verification request to the Xinyuan terminal to make the Xinyuan terminal return corresponding signature verification information;
[0370] verifying the signature verification information, and in response to failed verification of the signature verification information, revoking the software legalization authorization certificate corresponding to the signature verification information.
[0371] A method for authenticating software authorization, comprising:
[0372] Generating software fingerprint information according to installation information of the authenticating software, and constructing message information according to the fingerprint information and state information of a trusted terminal;
[0373] Receiving an encryption key sent by a national encryption acceleration engine, and encrypting the message information according to the encryption key to obtain encrypted message information;
[0374] Sending the encrypted message information to a prefix delegation server, so that the prefix delegation server outputs a corresponding software authentication authorization certificate;
[0375] Running the authenticating software according to the authentication authorization certificate.
[0376] Optionally, after the encrypted message information is sent to the prefix delegation server so that the prefix delegation server outputs a corresponding software authentication authorization certificate, the method further comprises:
[0377] Obtaining a verification terminal IPv6 address according to the authentication authorization certificate;
[0378] Networking according to the verification terminal IPv6 address.
[0379] A method for authenticating software authorization, comprising:
[0380] Sniffing a message sent by an authorized trusted terminal to obtain message sniffing information;
[0381] Identifying the message sniffing information, and in response to the message sniffing information being abnormal, performing feature matching on the abnormal message sniffing information to obtain abnormal detection information;
[0382] Identifying a system type of the abnormal trusted terminal to obtain system type information;
[0383] Adjusting a router advertisement message of the trusted terminal according to the system type information and the abnormal detection information to obtain an adjusted message;
[0384] Sending the adjusted message to the trusted terminal, so that the trusted terminal networks according to the adjusted message.
[0385] Optionally, after the abnormal message sniffing information is subjected to feature matching to obtain abnormal detection information, the method further comprises:
[0386] The abnormal Xinneng terminal sends a DHCPv6 request in a stateless environment in response to the abnormality, allocates a special IPv6 address for the abnormal Xinneng terminal, and limits the access address range of the abnormal Xinneng terminal;
[0387] Device information of the abnormal Xinneng terminal is recorded, and the device information is identified;
[0388] In response to the abnormal Xinneng terminal being able to be repaired by firmware update, a firmware patch is pushed to the abnormal Xinneng terminal.
[0389] A prefix delegation server includes a memory, a processor, and a computer program stored on the memory and executable on the processor.
[0390] A Xinneng terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor.
[0391] A proxy service layer includes a national secret acceleration engine, a dynamic prefix generator, a genuine binding module, and a protocol adapter, and is used to implement the method of any one of the above;
[0392] The national secret acceleration engine is configured to generate an encryption key according to a preset encryption algorithm, and to send the encryption key to the Xinneng terminal in response to the Xinneng terminal sending an encryption request;
[0393] The dynamic prefix generator is configured to generate and send a network prefix to the prefix delegation server in response to the prefix delegation server failing to verify the encrypted message;
[0394] The genuine binding module is configured to bind a verification terminal IPv6 address and an encrypted message to obtain a software genuine authorization certificate;
[0395] The protocol adapter is configured to perform feature matching on abnormal message sniffing information to obtain abnormal detection information in response to the message sniffing information being abnormal, to identify the system type of the abnormal Xinneng terminal to obtain system type information, to adjust a router advertisement message of the Xinneng terminal according to the system type information and the abnormal detection information to obtain an adjusted message, and to send the adjusted message to the Xinneng terminal to enable the Xinneng terminal to perform networking according to the adjusted message.
[0396] Those of ordinary skill in the art will realize that the foregoing discussion of any of the embodiments has been presented for the purpose of illustration and description and is not intended to be exhaustive or to limit the application to the precise forms described, and that various adaptations and modifications are possible within the scope and spirit of the application. For example, while the embodiments discussed above have been described in the context of a memory device, other memory architectures (e.g., dynamic RAM (DRAM)) can use the embodiments discussed.
[0397] In addition, to simplify the description and discussion, and so as not to make the embodiments of the application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components can or can not be shown in the provided drawings. Further, devices can be shown in block diagram form so as not to make the embodiments of the application difficult to understand, and this also takes into account the fact that details regarding implementation of these block diagram devices are highly dependent on the platform in which the embodiments of the application are to be implemented (i.e., these details should be well within the understanding of one of ordinary skill in the art). Where specific details (e.g., circuitry) are set forth in order to describe an illustrative embodiment of the application, it should be apparent to one of ordinary skill in the art that the embodiments of the application can be practiced without or with variations of these specific details. Thus, the description should not be viewed as limiting the application, but rather as merely describing illustrative embodiments.
[0398] While the application has been described in connection with specific embodiments thereof, it will be understood that many modifications, variations and alternatives will be apparent to those skilled in the art as a result of the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) can use the embodiments discussed.
[0399] It is therefore intended that the embodiments of the application embrace all such alternatives, modifications and variations as falling within the broad scope of the appended claims. Accordingly, any and all departures from the above described embodiments are intended to be included within the scope of the application as defined by the following claims.
Claims
1. A method for software authorization, comprising: receiving an encrypted message sent by a Xinyuan terminal, and verifying the encrypted message; in response to successful verification of the encrypted message, generating a verification terminal IPv6 address corresponding to the encrypted message; binding the verification terminal IPv6 address with the encrypted message to obtain a software authorization certificate; sending the software authorization certificate to the Xinyuan terminal.
2. The method of claim 1, wherein, The method further comprises: in response to failed verification of the encrypted message, receiving a network prefix sent by a prefix generator; modifying the encrypted message according to the network prefix to obtain an updated encrypted message; generating an updated terminal IPv6 address corresponding to the updated encrypted message; binding the updated terminal IPv6 address with the updated encrypted message to obtain the software authorization certificate.
3. The method of claim 1, wherein, After sending the software authorization certificate to the Xinyuan terminal, the method further comprises: sending a verification request to the Xinyuan terminal to make the Xinyuan terminal return corresponding signature verification information; verifying the signature verification information, and in response to failed verification of the signature verification information, revoking the software authorization certificate corresponding to the signature verification information. 4.A method for software authorization, comprising: generating software fingerprint information according to installation information of the software, and constructing message information according to the fingerprint information and state information of a Xinyuan terminal; receiving an encryption key sent by a national encryption acceleration engine, and encrypting the message information according to the encryption key to obtain encrypted message information; sending the encrypted message information to a prefix delegation server to make the prefix delegation server output a corresponding software authorization certificate; running the software according to the authorization certificate.
5. The method of claim 4, wherein, After sending the encrypted message information to the prefix delegation server to make the prefix delegation server output a corresponding software authorization certificate, the method further comprises: obtaining a verification terminal IPv6 address according to the authorization certificate; networking according to the verification terminal IPv6 address. 6.A method for software authorization, comprising: sniffing a message sent by an authorized Xinyuan terminal to obtain message sniffing information; identifying the message sniffing information, and in response to existence of an abnormality in the message sniffing information, performing feature matching on the message sniffing information with the abnormality to obtain abnormality detection information; identifying a system type of the Xinyuan terminal with the abnormality to obtain system type information; adjusting a router advertisement message of the Xinyuan terminal according to the system type information and the abnormality detection information to obtain an adjusted message; sending the adjusted message to the Xinyuan terminal to make the Xinyuan terminal network according to the adjusted message.
7. The method of claim 6, wherein, After performing feature matching on the message sniffing information with the abnormality to obtain abnormality detection information, the method further comprises: in response to the Xinyuan terminal with the abnormality sending a DHCPv6 request in a stateless environment, allocating a special IPv6 address to the Xinyuan terminal with the abnormality, and limiting an access address range of the Xinyuan terminal with the abnormality. record the device information of the abnormal Xinyuan terminal, identify the device information; In response to the abnormal Xinyuan terminal being able to be repaired by firmware update, a firmware patch is pushed to the abnormal Xinyuan terminal.
8. A prefix delegation server comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements the method of any one of claims 1 to 3 when executing the program.
9. A Xinyuan terminal comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements the method of any one of claims 4 to 5 when executing the program.
10. A proxy service layer comprising a national secret acceleration engine, a dynamic prefix generator, a genuine binding module, and a protocol adapter, for implementing the method of any one of claims 1 to 7. The national secret acceleration engine is configured to generate an encryption key according to a preset encryption algorithm, and send the encryption key to the Xinyuan terminal in response to the Xinyuan terminal sending an encryption request. The dynamic prefix generator is configured to generate and send a network prefix to the prefix delegation server in response to the prefix delegation server failing to verify the encrypted message. The genuine binding module is configured to bind the verified terminal IPv6 address and the encrypted message to obtain a software genuine authorization certificate. The protocol adapter is configured to perform feature matching on the abnormal message sniffing information to obtain abnormal detection information in response to the message sniffing information being abnormal. The system type of the abnormal Xinyuan terminal is identified to obtain system type information, and the router advertisement message of the Xinyuan terminal is adjusted according to the system type information and the abnormal detection information to obtain an adjusted message. The adjusted message is sent to the Xinyuan terminal, so that the Xinyuan terminal performs networking according to the adjusted message.