National secret security edge gateway system for multimode redundancy communication
By differentiating service flow priorities in a multi-mode redundant communication gateway system and employing hardware and software-based national cryptographic processing modules, the impact of national cryptographic security processing on access service quality is resolved, deterministic access for critical service flows is achieved, and stable transmission of high-priority services is ensured.
Patent Information
- Application Number
- CN202511807340.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-03
- Publication Date
- 2026-02-10
AI Technical Summary
Existing multi-mode redundant communication gateway systems fail to effectively distinguish service flow priorities during national cryptographic security processing. This results in a significant increase in processing latency for high-priority service flows as they wait for low-priority data packets to be encrypted, thus affecting the quality of access services.
A service priority identification unit is used to distinguish data packets into critical instruction service flows and batch data service flows. These are then processed separately by hardware-based and software-based national cryptographic processing modules. The critical instruction service flows are processed with constant latency in the hardware module, while the batch data service flows are processed with dynamic latency in the software module. Combined with static and dynamic access multiplexing units, deterministic access of critical service flows is ensured.
It achieves deterministic access quality of service for critical business flows under the dual constraints of national cryptographic security processing and multi-mode redundant communication, avoiding priority reversal and latency fluctuations caused by national cryptographic processing, and ensuring stable transmission of high-priority services.
Smart Images

Figure CN121509999A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a national cryptographic security edge gateway system with multi-mode redundant communication, belonging to the field of multi-mode redundant communication and secure access technology. Background Technology
[0002] In existing multi-mode redundant communication gateway systems, ensuring the quality of service for critical services is a technical objective. Common technical approaches include using time-division multiplexing or frequency-division multiplexing mechanisms at the access layer. This provides deterministic low-latency access guarantees by reserving fixed, dedicated access resources, such as specific time slots or subcarriers, for high-priority critical services. The effectiveness of this traditional access service mechanism is based on the technical premise that the processing latency of data packets within the gateway is constant or extremely low and predictable before they reach the access layer multiplexer. With the increasing security requirements for critical infrastructure, national cryptographic security processing has become a necessary function for edge gateways. When handling sudden batches of services, the process itself is characterized by high load, high latency, and significant latency fluctuations.
[0003] Currently, most industry solutions focus on establishing secure channels using Chinese cryptographic standards, neglecting the profound impact of encryption on service quality. For example, Chinese invention patent CN114553548A discloses a communication method, device, equipment, and storage medium. This solution primarily addresses authentication and secure channel establishment between cloud and edge devices, as well as secure communication between different functional modules within the edge device. However, this design approach fails to differentiate service flow priorities and does not consider the dynamic latency introduced by Chinese cryptographic encryption itself, making it challenging to apply in high-real-time, high-reliability hybrid service scenarios. When the Chinese cryptographic security processing function is introduced into the existing system architecture, a technical problem arises. In conventional system design, all service flows, regardless of priority, typically queue for encryption in the Chinese cryptographic processing module before transmission, leading to priority reversal at the processing layer: a high-priority instruction packet that should be sent immediately is queued after a low-priority data block for encryption, causing the internal processing latency to increase dramatically from a negligible state to an uncontrollable dynamic value.
[0004] Therefore, the technical problem to be solved by this invention is how to design a new gateway system architecture to solve the pollution problem caused by the dynamic national cryptographic processing latency to static access reuse resources, and to ensure that critical services obtain deterministic access service quality under the dual constraints of national cryptographic security processing and multi-mode redundant communication. Summary of the Invention
[0005] To address the problems mentioned in the background art, the technical solution of the present invention is as follows: A national cryptographic security edge gateway system with multi-mode redundant communication, the system comprising:
[0006] Multimode communication interfaces are used to access multiple communication links;
[0007] The service priority identification unit is used to distinguish data packets into critical instruction service flows and batch data service flows;
[0008] The multimode link quality detection unit is used to acquire the transmission quality of multiple communication links in real time;
[0009] Key instruction channels, including:
[0010] Hardware-based national cryptographic processing modules are used to encrypt critical instruction business flows with constant processing latency and rated throughput;
[0011] The static access multiplexing unit, coupled with the national cryptographic processing module and the multimode communication interface, is used to: configure the capacity and time window of static multiplexing resources on multiple communication links to match the constant processing delay and rated throughput of the national cryptographic processing module; dynamically select a target communication link from multiple communication links based on the real-time transmission quality obtained by the multimode link quality detection unit when a critical instruction service flow needs to be sent; and allocate static multiplexing resources for the critical instruction service flow on the target communication link.
[0012] Batch data channels, which include:
[0013] The software-based shared national cryptographic processing module is used to dynamically process latency-encrypted batch data business flows;
[0014] The dynamic access multiplexing unit, which is coupled with a shared national cryptographic processing module and a multi-mode communication interface, is used to transmit batch data service streams by utilizing the remaining available resources on multiple communication links.
[0015] Preferably, the multi-mode link quality detection unit is replaced by the transmission acknowledgment timestamp matching logic module integrated on the dynamic access multiplexing unit of the batch data channel; the transmission acknowledgment timestamp matching logic module is used to calculate and generate the round-trip delay, jitter and packet loss rate of a certain link based on the sending timestamp of the batch data service flow through a certain link and the receiving timestamp of the acknowledgment packet corresponding to the batch data service flow returned from a certain link, as the transmission quality.
[0016] Preferably, the system further includes a perception policy arbitrator, which is used to monitor the transmission activity of batch data service flows, wherein the perception policy arbitrator is used to... When the transmission activity of a batch data service stream is determined to be below a quiet threshold, the threshold is then set. The current system time. The logic module for matching transmission acknowledgment timestamps records the receive timestamp of the last received acknowledgment packet. The silent threshold is set as follows: when the transmission activity is determined to be lower than the silent threshold, the active probing function is activated to obtain the transmission quality of multiple communication links; otherwise, the active probing function is disabled and the transmission quality is used.
[0017] Preferably, the static access multiplexing unit is used to allocate fixed time slots of time division multiplexing (TDM) as static multiplexing resources; the dynamic access multiplexing unit is used to allocate the remaining available resources using a statistical multiplexing strategy.
[0018] Preferably, the system includes a preemptive multiplexing arbitration unit, which is used to detect the output queue status of the national cryptographic processing module; when the output queue is empty, it authorizes the dynamic access multiplexing unit to use the static multiplexing resources allocated by the static access multiplexing unit.
[0019] Preferably, the preemptive multiplexing arbitration unit revokes the authorization for the dynamic access multiplexing unit when the output queue of the national cryptographic processing module is no longer empty; the static access multiplexing unit restores its attribute of serving only the critical instruction channel after the authorization is revoked, ensuring that the critical instruction service flow has priority to occupy the static multiplexing resources.
[0020] Preferably, the system further includes a hardware status self-test unit and a fault switching arbitrator; the hardware status self-test unit is used to detect the failure status of the national cryptographic processing module; the fault switching arbitrator is used to: a command service priority identification unit to redirect the key command service flow to the shared national cryptographic processing module when the national cryptographic processing module fails; and a command dynamic access multiplexing unit to process and allocate the remaining available resources to the redirected key command service flow.
[0021] Preferably, the system further includes a source authentication logic unit, which is located upstream of the service priority identification unit; the source authentication logic unit performs cryptographic source authentication verification on data packets that are claimed to be critical instruction service flows; and if the verification fails, the data packet is redirected to the batch data channel.
[0022] Preferably, the hardware-based national cryptographic processing module includes a national cryptographic encryption engine implemented by an FPGA.
[0023] Preferably, the hardware-based national cryptographic processing module includes a national cryptographic encryption engine implemented by ASIC.
[0024] Compared with the prior art, the beneficial effects of the present invention are:
[0025] 1. By setting up a business priority identification unit, the architecture constructs mutually isolated critical instruction channels and batch data channels. Before entering the access layer, different business flows are processed by national cryptographic processing modules with different characteristics. The hardware-based dedicated processing method used by the critical instruction business flow keeps the processing latency constant and predictable. The software-based shared processing method used by the batch data business flow results in dynamically changing processing latency. This rigid physical separation based on business priority at the processing layer avoids queuing and blocking caused by high-priority businesses waiting for low-priority businesses such as video and logs to complete encryption processing, and avoids the priority reversal problem of encryption steps that have already occurred before access reuse.
[0026] 2. This invention strongly binds the multiplexing strategy of the access layer with the latency characteristics of the processing layer (national cryptography). The static access multiplexing unit in the critical instruction channel is specifically coupled to the national cryptography processing module with constant latency characteristics; the dynamic access multiplexing unit in the batch data channel is coupled to the shared national cryptography processing module with dynamic latency characteristics. This architectural latency matching design ensures that after the critical instruction service flow completes constant latency processing, the corresponding static multiplexing resources, such as TDM time slots or FDM subchannel time windows, are always valid and accurately matched, guaranteeing the determinism of static access services and avoiding silent interruption of access services due to processing latency polluting access time slots.
[0027] 3. The dual-isolation heterogeneous access architecture constructed in this invention enables two access services with different service qualities to run in parallel and without interference. The critical instruction channel is statically reserved to ensure deterministic latency access for high-priority services. The batch data channel uses statistical multiplexing or opportunistic access strategies to transmit data using the remaining available resources on all links, decoupling the load pressure of the two services from processing to access end-to-end. This makes the access service quality of critical services completely independent of the load pressure of batch data services. Under the dual constraints of multi-mode redundant communication and national cryptographic security processing, it provides true hard QoS access service capabilities. Attached Figure Description
[0028] Figure 1 This is a diagram illustrating the dual-channel isolation and arbitration functional architecture of the national cryptographic security gateway of this invention.
[0029] Figure 2 This is a timing diagram for hardware module fault switching and automatic recovery management in this invention;
[0030] Figure 3 This is a diagram illustrating the heterogeneous hardware and software deployment architecture of the secure gateway of this invention. Detailed Implementation
[0031] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0032] This invention provides a national cryptographic security edge gateway system with multi-mode redundant communication. Physically, it includes a multi-mode communication interface for accessing multiple communication links. In terms of system architecture, it includes a service priority identification unit, and key command channels and batch data channels that are isolated from each other at the processing and access levels. The system also includes a multi-mode link quality detection unit to provide real-time link status data for access decisions of the key command channel. The key command channel provides access services with deterministic latency guarantees for high-priority service flows, while the batch data channel processes low-priority service flows in a best-effort manner. At the access service level, it solves the problem of dynamic latency in national cryptographic processing polluting static multiplexing resource allocation. The multi-mode communication interface realizes the physical connection between the edge gateway and the external network, integrating physical layer (PHY) and data link layer controllers for accessing different network standards. The multiple communication links may include one or more combinations of satellite links, 5G private network links, and terrestrial fiber optic links, providing redundant physical transmission paths for upper-layer data multiplexing and dynamic selection. The service priority identification unit is located at the gateway's data entry point, and it identifies data packets entering any processing queue. Previously, inbound data packets underwent initial parsing. Using pre-defined Access Control Lists (ACLs) or flow classification rules, inbound data packets were rigidly divided into critical command flow and batch data flow based on the packet's five-tuple information, such as protocol port number, source / destination IP address, or specific service identifier. For example, a packet with a specific control server IP address and a destination port such as UDP10001 (a remote control command port) was identified as a critical command flow, while a packet with a destination port such as TCP8080 (a video return port) was identified as a batch data flow. The results guided the packets to different processing channels. The flow classification rules used by the service priority identification unit are stored in a dynamically readable and writable configuration area, including a secure configuration management channel. Authorized control centers or service servers send an updated set of flow classification rules to the configuration area through this channel. Upon receiving the updated rules, the service priority identification unit performs an atomic replacement operation, enabling the updated flow classification rules without interrupting the forwarding of existing service flows, and distinguishing and redirecting all newly arriving data packets according to their service flow.
[0033] The critical instruction channel is used to process critical instruction traffic. It includes a hardware-based national cryptographic processing module, dedicated to processing critical instruction traffic, implemented by a Field-Programmable Gate Array (FPGA) or Application-Specific Integrated Circuit (ASIC). Its hardware-based nature ensures a constant and predictable encryption processing latency, fixed within 5ms, unaffected by the system's main processor (CPU) load or sudden bursts of batch data traffic. This module has a rated throughput, such as 10Mbps, matching the expected peak bandwidth of the critical instruction traffic, ensuring no queuing occurs due to insufficient module processing capacity during peak traffic. The constant processing latency of the hardware-based national cryptographic processing module is quantified through standardized factory calibration procedures. This includes continuously injecting critical instruction test streams with a predetermined packet size, such as 1KB, into the critical instruction channel at its rated throughput (e.g., 10Mbps) when the shared national cryptographic processing module in the batch data channel is under designed saturation load. Using a hardware logic analyzer or a timestamp probe integrated within the module, the time interval from the moment the test packet is received in the module's input queue to the moment it is completely transmitted from the module's output queue is captured and recorded with high precision. From at least 10,000 time interval samples, the maximum value is taken as the constant processing latency benchmark parameter for this module, which is then fixed and used in the static access multiplexing unit for time slot matching calculation and latency budgeting. A batch data channel is used to process batch data service flows. The core includes a software-defined shared national cryptographic processing module, implemented through software algorithms using the system's main processor (CPU) or general-purpose computing resources in a System-on-a-Chip (SoC). It processes all remaining batch data service flows, boasting strong processing capabilities and high total throughput. Because resources are shared, when batch data services such as video and logs experience sudden bursts, the processing latency is reduced. It is dynamic and unpredictable, potentially fluctuating from a few milliseconds to hundreds of milliseconds; the multi-mode link quality detection unit actively and periodically sends probe packets to multiple communication links. The probe packets can be ICMPPing packets or UDP probe packets of a specific format; by measuring the round-trip time (RTT), jitter, and packet loss rate of the probe packets, it generates transmission quality vectors describing all available links in real time, for example, {Link 1: RTT=50ms, packet loss=0%; Link 2: RTT=300ms, packet loss=1%}, which are provided to the static access multiplexing unit as a basis for decision-making.
[0034] The critical command channel, comprising a static access multiplexing unit, a national cryptographic processing module, and a multimode communication interface, is the core component ensuring access service quality. This unit performs two key functional tasks: First, it matches processing-access latency. During system initialization, the capacity and time window of static multiplexing resources on multiple communication links are configured to match the constant processing latency and rated throughput of the national cryptographic processing module. If the constant processing latency of the national cryptographic processing module is 5ms and the rated throughput is 10Mbps, then the static configuration of the fixed time slot length and period of the time division multiplexing (TDM) or the bandwidth of the FDM subchannel reserved by the static access multiplexing unit is sufficient to handle the latency within 5ms. The internally processed data packets ensure that the corresponding access resources are always valid and available after the critical instruction packets are encrypted. Secondly, it performs optimal link dynamic mapping. When a critical instruction service flow needs to be sent, this unit queries the real-time transmission quality obtained by the multi-mode link quality detection unit and dynamically selects a target communication link from multiple communication links. This target communication link is the link with the best current transmission quality, such as the link with the lowest overall latency and a packet loss rate of 0. On the selected target communication link, this unit allocates the aforementioned reserved static multiplexing resources for the critical instruction service flow and sends it out. The batch data channel includes a dynamic access multiplexing unit, a shared national cryptographic processing module, and... A multi-mode communication interface; this unit employs a statistical multiplexing strategy, aggregating all remaining available resources on all links, except for unused resources on critical command channels, to transmit batch data service streams in a best-effort manner. The core objective is to maximize bandwidth utilization, without providing latency guarantees. In another embodiment, to reduce the overhead of active probing, the multi-mode link quality detection unit is replaced by the transmission acknowledgment timestamp matching logic module integrated into the dynamic access multiplexing unit of the batch data channel. This logic module passively monitors the transmission process of the batch data service stream and records... Batch data packets, after passing through a link such as a 5G link, wait for the corresponding transport layer acknowledgment packet (e.g., TCPACK) to return from that link, recording the reception timestamp. The module passively and faithfully calculates the time difference between the sending and receiving timestamps to generate the actual round-trip time, jitter, and packet loss rate of the link, serving as transmission quality data. This passively sensed quality data is also shared with the static access multiplexing unit. To address the issue of dynamic sensing failing during service quiet periods, a sensing strategy arbitrator is included. This arbitrator monitors the transmission activity of batch data service flows and can reuse the timestamp matching logic module to obtain the reception timestamp of the last received acknowledgment packet. Arbitrator has a built-in silent threshold. For example, check periodically every 60 seconds. Whether it is valid; among them The system time is the current system time. When the inequality is true, the arbitrator determines that the system has entered a silent state, the passively sensed data is outdated, and the arbitrator activates a lightweight active detection function, such as the multi-mode link quality detection unit mentioned above, to obtain the latest transmission quality. When the inequality is false, the system is in a normal state, the arbitrator disables the active detection function, and the passively sensed transmission quality is generated by the timestamp matching logic module.
[0035] To further improve the utilization rate of access resources, a preemptive multiplexing arbitration unit is included. Logically, the arbitration unit connects the critical instruction channel and the batch data channel, continuously monitoring the output queue status of the national cryptographic processing module. Most of the time, critical instructions are sparse, and the output queue is empty. The arbitration unit immediately issues a resource availability authorization to the dynamic access multiplexing unit of the batch data channel, temporarily borrowing static multiplexing resources, such as TDM time slots, allocated by the static access multiplexing unit to transmit batch data. Once the output queue of the national cryptographic processing module is no longer empty, and the critical instructions have finished processing and are waiting to be sent, the preemptive multiplexing arbitration unit unconditionally... The authorization for the dynamic access multiplexing unit is revoked; the static access multiplexing unit is restored to its original attribute of serving only the critical command channel, ensuring that the critical command service flow occupies its dedicated static multiplexing resources with absolute priority and without any conflict; to cope with extreme conditions such as hardware failure of the critical command channel itself, a hardware status self-test unit and a fault switching arbitrator are included; the hardware status self-test unit detects the functional integrity and failure status of the national cryptographic processing module such as FPGA through heartbeat or encryption-decryption self-loop test; when the national cryptographic processing module is detected as failing, the fault switching arbitrator is activated and performs two actions simultaneously: command service The priority identification unit redirects newly arriving critical instruction service flows from their original path to the input queue of the (software-based) shared national cryptographic processing module. The instruction dynamic access multiplexing unit enters an absolute priority mode. In this mode, the dynamic access multiplexing unit must prioritize processing, for example, clearing other batch data queues and allocating access resources to the redirected critical instruction service flow, functionally temporarily rebuilding a QoS-guaranteed channel. To prevent spoofed denial-of-service attacks targeting the critical instruction channel, a source authentication logic unit, located upstream of the service priority identification unit and at the forefront of the data entry point, is included. This source authentication logic unit... Incoming data packets are inspected. If a data packet claims to be a critical instruction service flow based on the port number, the unit does not trust it. Instead, it requires the data packet to additionally include an authentication label, such as an HMAC hash value, to verify the authenticity of the source. The label is then used to perform a cryptographic source authentication verification using a locally preset key. If the verification passes, the (genuine) data packet is allowed to pass through the service priority identification unit. If the verification fails, the forged data packet is considered an attack and will be forcibly redirected to the lowest priority queue of the batch data channel or discarded directly, thus protecting the hardware cryptographic resources and static access resources of the critical instruction channel from malicious occupation.
[0036] Example 1: In a specific industrial internet remote control scenario, a national cryptographic security edge gateway system deployed at the edge connects to a high-latency, narrow-bandwidth but stable satellite link (Link A) and a low-latency, high-bandwidth but occasionally congested 5G link (Link B). This gateway handles two types of service flows: one is an emergency braking critical command service flow delivered within 100ms, and the other is a batch data service flow from video surveillance. When a factory workshop begins transmitting a historical surveillance video file, it causes a sudden surge in the batch data service flow from video surveillance, generating traffic as high as 500Mbps. After this traffic enters the batch data channel, it saturates the CPU resources of the software-defined shared national cryptographic processing module, causing the module's encryption processing latency to increase from the usual 20ms. The latency surged to 550ms. At the same time, in response to the emergency, the control center issued an emergency braking command with a data packet size of 1KB. As a critical command service flow, it arrived at the gateway, where the service priority identification unit identified it and immediately sent it to the critical command channel. The command packet entered the hardware-based national cryptographic processing module. Due to the physical isolation of this module, the processing was not affected by the high load of the shared national cryptographic processing module. The inherent constant processing delay of 5ms completed the national cryptographic encryption. After encryption, the emergency braking command packet arrived at the static access multiplexing unit. The unit obtained the real-time transmission quality display from the multi-mode link quality detection unit: {Link A: RTT=300ms, packet loss=0%; Link B: RTT=20ms, packet loss=0.5%}.
[0037] The static access multiplexing unit, based on its optimal link dynamic mapping logic, determines zero packet loss as the highest priority and therefore dynamically selects the satellite link (link A) as the target communication link. The function of the static access multiplexing unit in this gateway system is to match the transmission window of the reserved TDM static multiplexing resources, such as the fixed time slot on link A, with the 5ms constant processing delay of the national cryptographic processing module. The emergency braking command packet, after encryption, arrives at the multiplexing unit at a time synchronized with the transmission window of the TDM time slot reserved for it on the satellite link. The emergency braking command packet utilizes the reserved satellite TDM time slot to complete transmission without conflict or packet loss. The total processing and access delay within the gateway is 5ms. The encryption latency and link selection and multiplexing latency of less than 1ms are combined to be within 6ms, meeting the 100ms business indicator requirement. Large-capacity video surveillance batch data traffic continues to queue in the batch data channel, utilizing the remaining available resources on the 5G link (link B) for best-effort transmission. Through the isolation between the processing layer (hardware and software) and the access layer (static and dynamic), combined with constant latency processing and precise matching of static multiplexing resources, the timing mismatch problem between dynamic encryption latency and static access time slots is solved. The QoS guarantee capability of the critical command channel does not degrade under the dual conditions of batch service load pressure and physical link quality fluctuations, achieving deterministic access service.
[0038] Example 2: To quantitatively evaluate the effectiveness of the system architecture of this invention in solving the priority inversion problem of encryption steps at the access layer, an experimental platform was built, including a data packet transceiver analyzer, a control group gateway, and the sample gateway of this invention. The data packet transceiver analyzer is used to simulate and generate two types of service flows, and to capture and measure the end-to-end latency of key instruction data packets with high precision (0.1ms). The control group gateway represents the prior art and adopts a single software-based shared national cryptographic processing module to uniformly process all service flows. Key instructions and batch data are queued and encrypted in this module. The sample gateway of this invention adopts the dual-channel isolation architecture of this invention, with the key instruction channel (hardware-based national cryptographic processing module) and the batch data channel (software-based shared national cryptographic processing module) coexisting. The two types of service flows are encrypted in parallel. Physical isolation was implemented at the encryption processing level. The test parameters were set as follows: the critical instruction service flow was set to a constant rate of 1pps and a packet size of 1KB; the load of the batch data service flow was used as a gradient pressure variable, with load setting points of 0Mbps, 100Mbps, 300Mbps, and 500Mbps, the latter simulating the saturation load of the shared national cryptographic processing module; the access time window of the static access multiplexing unit (TDM) of both gateways was set to 20ms, and any data packet with a processing delay exceeding 20ms was considered a TDM time slot failure and recorded as an access failure; under the above test platform and parameter settings, the end-to-end latency of the critical instruction service flow of the control group and the sample group of this invention were tested under different batch data loads, and the test data are recorded in Table 1.
[0039] Table 1: Comparison of Key Instruction Latency Test Data under Different Loads
[0040]
[0041] Referring to the experimental data in Table 1, the critical command latency of the control group gateway showed a strong correlation with the batch data load. At a baseline load of 0 Mbps, the software encryption latency (18.2 ms) was close to the 20 ms TDM window boundary. When the batch data load increased to only 100 Mbps, the latency (23.5 ms) exceeded the TDM window, resulting in a silent interruption and access failure. As the load increased, the latency deteriorated sharply, completely losing the determinism of access service. The data from the sample gateway of this invention showed that the critical command latency remained stable in the range of 5.1 ms to 5.3 ms under all load gradients (0 Mbps to 500 Mbps saturated load), far below the 20 ms TDM window threshold, and always maintained a normal access state. This latency value (approximately 5 ms) was determined by the constant processing latency of the hardware-based national cryptographic processing module in the critical command channel, and this latency was not affected by any batch data channel load (up to 500 Mbps).
[0042] Example 3: This example combines Figures 1 to 3This document describes a national cryptographic security edge gateway system with multi-mode redundant communication, such as... Figure 1 As shown, inbound data packets are classified into critical instruction service flows and batch data service flows based on their service attributes by the service priority identification unit. The critical instruction service flows are sent to the critical instruction channel, which consists of a hardware-based national cryptographic processing module and a static access multiplexing unit. This hardware module provides constant processing latency to ensure QoS. The static access multiplexing unit, based on real-time link quality data provided by the multi-mode link quality detection unit, matches static multiplexing resources such as TDM time slots. The batch data service flows are sent to the batch data channel, which consists of a software-based shared national cryptographic processing module and a dynamic access multiplexing unit. This software module uses shared resources and has dynamic processing latency. The dynamic access multiplexing unit is responsible for transmitting data using the remaining available resources of all links. The system also includes a preemptive multiplexing arbitration unit, which coordinates the borrowing of static resources when the output queue of the hardware-based national cryptographic processing module is detected to be empty, authorizing the dynamic access multiplexing unit to temporarily use the static resources, and immediately revoking the authorization when a critical instruction arrives. The data of both channels are dynamically connected to multiple communication links through the multi-mode communication interface, such as link A (e.g., a satellite link) and link B (e.g., a 5G link).
[0043] like Figure 2 As shown, the horizontal axis represents the number of self-test rounds, and the vertical axis represents the status or number of self-tests. In the initial normal state of the system (e.g., self-test rounds 0-3), the national cryptographic processing module is in a high state, the number of self-test passes is 1, and the fault switching status is 0. When a fault is detected in the 4th self-test round, the national cryptographic processing module status drops to 0, the number of self-test passes also drops to 0, and the fault switching status is immediately set to 1, indicating that the system has started fault switching. During the recovery phase (e.g., self-test rounds 5-9), the national cryptographic processing module status gradually recovers, the number of self-test passes remains 0, and the fault switching status also remains 1, indicating that the system is in fault degradation mode. This continues until the 10th self-test round, when the national cryptographic processing module status fully recovers to a high state, the number of self-test passes returns to 1, and the fault switching status returns to 0, signifying that the system has executed the back-switch procedure and recovered to the dual-channel isolated operation state. Figure 3 As shown, the gateway is internally divided into a software-based shared national cryptographic processing module carried by the main processor CPU, and a hardware-based national cryptographic processing module implemented by a field-programmable gate array (FPGA) or application-specific integrated circuit (ASIC). The software-based shared national cryptographic processing module usually interacts with the control center or business server, while the hardware-based national cryptographic processing module prioritizes serving the critical business of industrial sites or edge devices. The gateway connects to various physical links, such as terrestrial fiber optic links, 5G private network links, and satellite links, through a multi-mode communication interface.
[0044] Example 4: In the Perception Policy Arbitrator This refers to the silent threshold, the value of which is used to balance the overhead of passive sensing with the timeliness of active detection in the calibration procedure. The constraint of this calibration procedure is that the transmission quality data on which the critical instruction service flow relies when performing optimal link mapping, and the time interval from the generation of this data to its use, are defined as data timeliness. This data timeliness must not exceed the maximum tolerable delay. In specific examples of this procedure, The timeout period is set to 120 seconds, a value determined by the timeliness requirements of the access service on the link status. The procedure is executed on a controllable test platform, including a packet generator and a network simulator. The packet generator simulates batch data flow and critical command flow, while the network simulator controls the packet loss rate and latency of the link. The calibration process uses a gradient scanning method. The time intervals were set to 30 seconds, 60 seconds, 90 seconds, 120 seconds, and 180 seconds, respectively, as the variables to be measured. Under the set values, repeat the following test steps: Step 1, start the batch data service flow, putting the perception policy arbitrator into passive perception mode; Step 2, in All batch data service flows are stopped immediately to simulate the start of a quiet period; Step 3, in At any given moment, the transmission quality of a link is changed from excellent (0% packet loss) to poor (5% packet loss) using a network simulator; step four, the system status is continuously monitored until... At any given moment, the perception strategy arbitrator determines that the transmission activity is below the silent threshold, switches to active detection mode, and obtains the poor transmission quality; step five, in After a certain time, as At that time, the key instruction service flow is sent, and the transmission quality data on which the static access multiplexing unit is based is recorded. The previous outdated data, or Real-time, fresh data.
[0045] when When set to 120 seconds and 180 seconds, the system... Constantly acquire fresh data; the timeliness of this data, i.e., its elapsed since... The time intervals have reached 120 seconds and 180 seconds respectively; both of these values are equal to or greater than 120 seconds. The constraint limit causes critical instruction service flows to use transmission quality data that does not meet timeliness requirements. When set to 30 seconds, 60 seconds, and 90 seconds, The data timeouts for acquiring fresh data at all times are 30 seconds, 60 seconds, and 90 seconds, all of which meet the requirement of being less than 120 seconds. Constraints: To maximize the zero-overhead advantage of passive sensing while satisfying constraints and avoiding premature switching to active detection, 90 seconds is chosen as the timeframe. The calibration value is embedded in the gateway system configuration to ensure the timeliness of access decision data while minimizing the network resource consumption of active probing.
[0046] Example 5: Standardized engineering calibration procedures for static access multiplexing units. During system deployment, the capacity of static multiplexing resources is precisely matched with the rated throughput of the hardware-based national cryptographic processing module. Through offline benchmark testing, a full-load stress test is performed on the FPGA encryption card, which serves as the national cryptographic processing module, to determine the maximum sustainable rated throughput when processing 1KB standard critical instruction packets. Maximum processing latency The test results are and Simultaneously, the system queries the frame structure parameters of a satellite link serving as a TDM link through a multi-mode communication interface to obtain its TDM frame period. and the data payload of a single TDM time slot. Based on the above calibration parameters, the static access multiplexing unit performs capacity configuration, which calculates the minimum number of static time slots that need to be reserved in each TDM frame period. The calculation method is as follows ,in, The minimum number of static time slots to be reserved. This is the rated throughput of the national cryptographic processing module. For TDM frame period, For the data payload of a single TDM time slot; according to , and The input value is used to calculate the result. ,Sure The static access multiplexing unit then binds the seven fixed time slots in each frame of the TDM link as static multiplexing resources for the critical command channel; the unit will The constant processing latency is configured as a fixed processing overhead baseline parameter for its internal access service scheduler. This parameter is used to always include this hardware processing time when planning the end-to-end access latency budget for critical instruction service flows.
[0047] Example 6: This example discloses a recovery management procedure for a fault-switching arbitrator, which is initiated after the hardware status self-test unit detects a failure in the national cryptographic processing module and redirects the critical instruction business flow to the shared national cryptographic processing module. In this fault state, the fault-switching arbitrator continuously polls the hardware status self-test unit to obtain the recovery status of the failed national cryptographic processing module. After the monitored national cryptographic processing module fails, the hardware status self-test unit periodically executes self-test logic, such as encryption-decryption loopback testing. When external maintenance actions, such as hardware hot-plugging or system restart, restore the functionality of the national cryptographic processing module, the hardware status self-test unit will be able to continuously pass the self-test logic. This self-test unit is configured to continuously pass... (set value) After self-testing, the module's status is updated from failed to normal, and this normal status is reported to the fault switching arbitrator. Secondary verification is used to prevent frequent fluctuations in module status near critical points. After receiving a normal status report, the fault-switching arbitrator executes a switchback procedure: First, the arbitrator instructs the dynamic access multiplexing unit to stop the absolute priority mode after processing all redirected critical instruction service flows in the current queue. Second, after confirming that the queue has been emptied, the instruction service priority identification unit redirects all newly arriving critical instruction service flows to the restored hardware-based national cryptographic processing module. This ensures that after a fault switch occurs in the access service, the system has the ability to automatically recover to its designed dual-channel isolated operating state and re-establish constant latency access protection for critical instruction service flows.
[0048] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0049] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A national cryptographic security edge gateway system with multi-mode redundant communication, characterized in that the system... include: Multimode communication interfaces are used to access multiple communication links; The service priority identification unit is used to distinguish data packets into critical instruction service flows and batch data service flows; The multimode link quality detection unit is used to acquire the transmission quality of multiple communication links in real time; Key instruction channels, including: Hardware-based national cryptographic processing modules are used to encrypt critical instruction business flows with constant processing latency and rated throughput; The static access multiplexing unit, coupled with the national cryptographic processing module and the multimode communication interface, is used to: configure the capacity and time window of static multiplexing resources on multiple communication links to match the constant processing delay and rated throughput of the national cryptographic processing module; dynamically select a target communication link from multiple communication links based on the real-time transmission quality obtained by the multimode link quality detection unit when a critical instruction service flow needs to be sent; and allocate static multiplexing resources for the critical instruction service flow on the target communication link. Batch data channels, which include: The software-based shared national cryptographic processing module is used to dynamically process latency-encrypted batch data business flows; The dynamic access multiplexing unit, which is coupled with a shared national cryptographic processing module and a multi-mode communication interface, is used to transmit batch data service streams by utilizing the remaining available resources on multiple communication links.
2. The national cryptographic security edge gateway system for multi-mode redundant communication according to claim 1, characterized in that, The multi-mode link quality detection unit is replaced by the transmission acknowledgment timestamp matching logic module integrated in the dynamic access multiplexing unit of the batch data channel. The transmission acknowledgment timestamp matching logic module is used to calculate and generate the round-trip delay, jitter, and packet loss rate of a certain link based on the sending timestamp of the batch data service flow through a certain link and the receiving timestamp of the acknowledgment packet corresponding to the batch data service flow returned from that link, as the transmission quality.
3. The national cryptographic security edge gateway system for multi-mode redundant communication according to claim 2, characterized in that, The system further includes a perception policy arbitrator, which is used to monitor the transmission activity of batch data service flows, wherein the perception policy arbitrator is used to... When the transmission activity of a batch data service stream is determined to be below a quiet threshold, the threshold is then set. The current system time. The logic module for matching transmission acknowledgment timestamps records the receive timestamp of the last received acknowledgment packet. The silent threshold is set as follows: when the transmission activity is determined to be lower than the silent threshold, the active probing function is activated to obtain the transmission quality of multiple communication links; otherwise, the active probing function is disabled and the transmission quality is used.
4. The national cryptographic security edge gateway system for multi-mode redundant communication according to claim 1, characterized in that, The static access multiplexing unit is used to allocate fixed time slots of Time Division Multiplexing (TDM) as static multiplexing resources; the dynamic access multiplexing unit is used to allocate the remaining available resources using a statistical multiplexing strategy.
5. The national cryptographic security edge gateway system for multi-mode redundant communication according to claim 1, characterized in that, The system includes a preemptive multiplexing arbitration unit, which is used to detect the output queue status of the national cryptographic processing module; when the output queue is empty, it authorizes the dynamic access multiplexing unit to use the static multiplexing resources allocated by the static access multiplexing unit.
6. The national cryptographic security edge gateway system for multi-mode redundant communication according to claim 5, characterized in that, The preemptive multiplexing arbitration unit revokes the authorization for the dynamic access multiplexing unit when the output queue of the national cryptographic processing module is no longer empty; the static access multiplexing unit restores its attribute of serving only the critical instruction channel after the authorization is revoked.
7. The national cryptographic security edge gateway system for multi-mode redundant communication according to claim 1, characterized in that, The system further includes a hardware status self-test unit and a fault switching arbitrator; the hardware status self-test unit is used to detect the failure status of the national cryptographic processing module; the fault switching arbitrator is used to: a command service priority identification unit to redirect the key command service flow to the shared national cryptographic processing module when the national cryptographic processing module fails; and a command dynamic access multiplexing unit to process and allocate the remaining available resources to the redirected key command service flow.
8. The national cryptographic security edge gateway system for multi-mode redundant communication according to claim 1, characterized in that, The system further includes a source authentication logic unit, which is located upstream of the service priority identification unit. The source authentication logic unit performs cryptographic source authentication verification on data packets that are claimed to be critical instruction service flows. If the verification fails, the data packet is redirected to the batch data channel.
9. A national cryptographic security edge gateway system for multi-mode redundant communication according to claim 1, characterized in that, The hardware-based national cryptographic processing module includes a national cryptographic encryption engine implemented by FPGA.
10. A national cryptographic security edge gateway system for multi-mode redundant communication according to claim 1, characterized in that, The hardware-based national cryptographic processing module includes a national cryptographic encryption engine implemented by ASIC.
Citation Information
Patent Citations
Communication method and device, equipment and storage medium
CN114553548A