Method and device for establishing communication link based on virtual network port, and storage medium

By creating a virtual network interface and monitoring the link status in the quantum-safe communication system, the problems of message backlog and key file misalignment within the terminal are solved, thus achieving the continuity and security of data transmission.

CN121644150APending Publication Date: 2026-03-10MATRICTIME DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-24
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

In quantum-safe communication systems, due to the hardware deployment inside the terminal causing message backlog in the communication area and misalignment in the use of symmetric key files, existing technologies cannot perceive the link status in real time, resulting in data backlog and inconsistent use of key files.

Method used

By creating virtual network ports at the terminal, the aggregated security gateway, and the key center, three communication links are established. The link status is monitored through the virtual network ports, and feedback is generated in real time to re-establish the communication links, ensuring the continuity of data transmission and the alignment of key files.

Benefits of technology

It enables real-time awareness of communication links, avoids message backlog and misalignment of key files, and ensures the continuity and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644150A_ABST
    Figure CN121644150A_ABST
Patent Text Reader

Abstract

The invention discloses a method and device for establishing a communication link based on virtual network ports and a storage medium, and the method comprises the steps: a terminal and an aggregation security gateway respectively create two virtual network ports locally, and a key center creates a virtual network port locally; the terminal, the aggregation security gateway and the key center create three communication links based on the virtual network ports; the terminal determines a communication link used by the to-be-transmitted data according to the data type of the to-be-transmitted data; the virtual network ports in the three communication links monitor link connection states, respond to link disconnection, generate feedback of the link states and send the feedback to other virtual network ports; and the virtual network port re-establishes a communication link to perform data communication. The real-time sensing of the communication link condition between communication participants is realized through the monitoring of the virtual network port, the data transmission continuity is improved, and the problems of communication message backlog and secret key use misalignment are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of secure communication technology, and in particular to a method and device for establishing a communication link based on a virtual network interface and a storage medium. BACKGROUND

[0002] In a quantum secure communication system, the normal use of a terminal often requires access authentication by an aggregation security gateway and a process of key issuance by a key center. As shown in FIG. 1, a terminal and an aggregation security gateway are connected in communication through respective first and second physical communication interfaces, and the aggregation security gateway is further connected to the key center through an internal network. In addition, to ensure the security of application data in the terminal, the terminal has a three-zone hardware architecture of a privacy zone, an isolation zone, and a communication zone, an application is deployed in the privacy zone, the isolation zone performs data encryption and decryption and filtering, and the communication zone is the only channel for the terminal to communicate with an external network. Figure 1 The hardware architecture and the communication connection mode of the terminal ensure the security of data transmission out of the terminal and data reception into the terminal, but the following problems may occur. Since the three zones are physically deployed on three different hardware, for example, the privacy zone can be deployed on a chip with business processing functions, the isolation zone can be deployed on an FPGA (Field Programmable Gate Array), and the communication zone can be deployed on a baseband chip with communication functions. Due to such different hardware deployment forms, communication data needs to pass through two communication links of “privacy zone to isolation zone” and “isolation zone to communication zone” to realize data transmission within the terminal.

[0003] Since the location of the physical communication interface is determined at the moment of hardware formation and cannot be changed, the aggregation security gateway directly communicates with the communication zone and cannot realize real-time sensing of the connection state between the isolation zone and the communication zone within the terminal. This results in that the disconnection of the connection within the terminal cannot be transmitted to the aggregation security gateway in real time. During the time interval from the disconnection of the connection within the terminal to the acquisition of the information by the aggregation security gateway, the aggregation security gateway will continue to send data to the communication zone, and the communication zone will also receive the data. However, the data will be accumulated in the communication zone after being received. Similarly, the isolation zone cannot realize real-time sensing of the connection state between the communication zone and the aggregation security gateway. Even if the connection between the communication zone and the server is disconnected, the isolation zone will continue to transmit the to-be-sent data to the communication zone before sensing, resulting in accumulation of the to-be-sent data in the communication zone. The two-way sensing delay will cause message accumulation in the communication zone.

[0004]

[0005] ​In addition, since the communication data in the quantum secure communication network is all ciphertext, it involves encryption operation of the sending end and decryption operation of the receiving end. Taking the case that the terminal sends a message to the aggregation security gateway, the accumulated message in the communication area is the ciphertext to be sent after being encrypted by the isolation area. Since the accumulation is in the communication area, the aggregation security gateway cannot use its own decryption key for decryption operation in time, resulting in that the terminal has recorded the use of the encryption key locally, but as the opposite end of the aggregation security gateway, the decryption key corresponding to the encryption key cannot be recorded for a long time, and stays at the last decryption key usage position, causing the problem of misalignment of the symmetric key file usage between the terminal and the aggregation security gateway.

[0006] Therefore, how to solve the message accumulation problem in the communication area of the terminal without changing the existing hardware deployment, and the misalignment of the symmetric key file usage between the terminal and the aggregation security gateway caused thereby, is a technical problem worth exploring in the field of quantum secure communication. SUMMARY

[0007] The purpose of the present application is to provide a method, device and storage medium for establishing a communication link based on a virtual network port to overcome the message accumulation problem in the communication area of the terminal and the misalignment of the symmetric key file usage between the terminal and the aggregation security gateway caused thereby in the background art.

[0008] Technical solution: The present application provides a method for establishing a communication link based on a virtual network port, comprising:

[0009] The terminal and the aggregation security gateway respectively create two virtual network ports locally, and the key center creates a virtual network port locally;

[0010] The terminal, the aggregation security gateway and the key center create three communication links based on the virtual network ports;

[0011] The terminal determines the communication link used by the to-be-transmitted data according to the data type of the to-be-transmitted data;

[0012] The virtual network ports in the three communication links listen to the link connection state, and in response to listening to the disconnection of the link, generate feedback of the link state and send it to other virtual network ports;

[0013] The virtual network ports re-establish the communication link to perform data communication.

[0014] Further, the terminal and the aggregation security gateway respectively create two virtual network ports locally, comprising:

[0015] The terminal creates a first TAP port and a first TUN port in the isolation area locally;

[0016] The second TAP port and the second TUN port are created locally by the aggregated security gateway;

[0017] The key center locally creates a virtual network port, including:

[0018] The key center locally creates a third TUN port.

[0019] Further, the first TUN port, the second TUN port, and the third TUN port are each assigned an IP address by the command center;

[0020] The first TAP port and the second TAP port each read the IP address of the local physical communication network port as its own IP address;

[0021] The IP address is used for addressing during data transmission.

[0022] Further, the three communication links include:

[0023] The first link from the first TAP port to the second TAP port;

[0024] The second link from the first TUN port to the first TAP port to the second TAP port to the second TUN port;

[0025] And the third link from the first TUN port to the first TAP port to the second TAP port to the third TUN port.

[0026] Further, the terminal determines the communication link used by the data to be transmitted according to the data type of the data to be transmitted, including:

[0027] The data type includes instruction data and message data, the instruction data is one of first instruction data for the terminal to access the aggregated security gateway for the first time, second instruction data for the terminal to access the aggregated security gateway for the second time, and third instruction data for the terminal to download the key, and the message data is application message data or key message data;

[0028] The first instruction data and the application message data are transmitted using the first link;

[0029] The second instruction data and the third instruction data are transmitted using the second link;

[0030] The key message data is transmitted using the third link.

[0031] Further, the virtual network port in the three communication links listens to the link connection state, and in response to listening to the link disconnection, generates a feedback of the link state and sends it to other virtual network ports, including:

[0032] When the link of the first TUN port to the first TAP port segment is disconnected, the first TAP port generates a first feedback of the second link and the third link disconnection to the second TAP port in real time;

[0033] When the link of the second TAP port to the second TUN port segment is disconnected, the second TAP port generates a second feedback of the second link disconnection to the first TAP port;

[0034] When the link of the second TAP port to the third TUN port segment is disconnected, the second TAP port generates a third feedback of the third link disconnection to the first TAP port;

[0035] When the link of the first TAP port to the second TAP port segment is disconnected, the first TAP port generates a fourth feedback of the full link disconnection to the first TUN port, and the second TAP port generates a fifth feedback of the full link disconnection to the second TUN port.

[0036] Further, the virtual network port reestablishes the communication link to perform data communication, which comprises:

[0037] In response to the first TAP port receiving the second feedback or the third feedback, or the second TAP port receiving the first feedback, the communication link between the disconnected virtual network ports is reestablished;

[0038] In response to the first TUN port receiving the fourth feedback and the second TUN port receiving the fifth feedback, the first TUN port sends the fourth feedback to the first physical communication network port of the terminal communication area, the first physical communication network port takes over the transmission data information of the first TAP port based on the fourth feedback; the second TUN port sends the fifth feedback to the second physical communication network port of the aggregation security gateway, the second physical communication network port takes over the transmission data information of the second TAP port based on the fifth feedback, and the communication link between the first physical communication network port and the second physical communication network port replaces the first link between the first TAP port and the second TAP port to perform data transmission.

[0039] Further, the method further comprises:

[0040] When the first TAP port and the second TAP port reestablish a new first link, the first TAP port obtains the transmission data information from the first physical communication network port, and the second TAP port obtains the transmission data information from the second physical communication network port, and continues to perform the data transmission operation using the new first link.

[0041] The application also comprises a computer device, which comprises at least a processor and a memory, and the processor is used to execute the computer program stored in the memory to realize the method for establishing a communication link based on a virtual network port.

[0042] The present invention also includes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described above for establishing a communication link based on a virtual network port.

[0043] The beneficial effects of this invention are:

[0044] (1) Real-time perception of the communication link status between the participants is achieved by monitoring the virtual network port. In the event of a link disconnection, data transmission and reception operations are stopped in time, thus avoiding message backlog in the communication area and the problem of misaligned key usage caused by message backlog.

[0045] (2) By exchanging IP addresses between the TAP network port and the physical communication network port, it is ensured that the IP address used for communication between the terminal and the aggregated security gateway is always the first IP address and the second IP address. This ensures that during the switching between the virtual network port and the physical communication network port, the data packets can be continuously transmitted without changing the target IP address, thus ensuring the continuity of data transmission.

[0046] (3) Different data types are transmitted through different links established by virtual network ports without affecting each other. Each link transmits data according to its own communication rhythm, which is not easy to cause message blocking. Moreover, when a link has a problem, it will not affect the data transmission in other links, which further ensures the continuity of data transmission in the quantum safe communication system. Attached Figure Description

[0047] Figure 1 This is a schematic diagram showing the connection between the terminal, the aggregated security gateway, and the key center in a quantum-secure communication system.

[0048] Figure 2 This is a schematic diagram showing the location of the virtual network port created in this invention;

[0049] Figure 3 This is a schematic diagram of the three communication links created in this invention;

[0050] Figure 4 This is a schematic diagram illustrating the IP acquisition process between the virtual network port and the physical communication network port in this invention.

[0051] Figure 5 This is a schematic diagram of the structure of the computer device of the present invention. Detailed Implementation

[0052] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0053] As described in the background section, the current hardware deployment method of terminals, aggregated security gateways, and key centers in quantum secure communication systems can lead to message backlog within the communication area, and consequently, misalignment of symmetric key files between terminals and aggregated security gateways.

[0054] In view of this, the present invention proposes a method for establishing a communication link based on a virtual network port, comprising the following steps.

[0055] Step 1: The terminal and the aggregated security gateway each create two virtual network ports locally, and the key center creates one virtual network port locally.

[0056] Specifically, such as Figure 2 As shown, the terminal creates a first TAP port and a first TUN port in its local isolation zone; the aggregated security gateway creates a second TAP port and a second TUN port locally; and the key center creates a third TUN port locally. All TAP and TUN ports created here are virtual network ports.

[0057] To ensure data can be successfully addressed by the newly created virtual network ports during transmission, the first, second, and third TUN ports are all assigned IP addresses by the command and control center. The command and control center is the control device for the entire quantum-safe communication system, responsible for recording the routing relationships between communication network elements, assigning unique device numbers to each communication network element, and allocating communication IP addresses to each communication network element within the quantum-safe communication system.

[0058] Since the terminal and the aggregated security gateway are themselves communication network elements, their hardware structures include a first physical communication port (which has a first communication IP address in the quantum-secure communication system) and a second physical communication port (which has a second communication IP address in the quantum-secure communication system). Therefore, to avoid wasting IP addresses, both the first and second TAP ports read the IP address of their local physical communication ports as their own IP addresses. Specifically, the first TAP port reads the first communication IP address as its own IP address, and the second TAP port reads the second communication IP address as its own IP address.

[0059] Whether it's the IP address assigned to the TUN port by the command and control center or the IP address read locally by the TAP port, both of these IP addresses are used for addressing during subsequent data transmission.

[0060] To avoid IP address conflicts between the first physical communication network port and the first TAP port, and between the second physical communication network port and the second TAP port during data transmission, such as Figure 3As shown, while reading the first communication IP address at the first TAP port, the command and control center assigns a mapped address (third communication IP address) to the first physical communication network port to replace the original first communication IP address, ensuring that only one first IP address exists in the quantum-safe communication system. Similarly, while reading the second communication IP address at the second TAP port, the command and control center assigns a mapped address (fourth communication IP address) to the second physical communication network port to replace the original second communication IP address, ensuring that only one second IP address exists in the quantum-safe communication system.

[0061] Step Two: The terminal, the aggregated security gateway, and the key center create three communication links based on the virtual network interface. Specifically, as follows... Figure 4 As shown, the three communication links created include: a first link from the first TAP port to the second TAP port; a second link from the first TUN port to the first TAP port to the second TAP port to the second TUN port; and a third link from the first TUN port to the first TAP port to the second TAP port to the third TUN port.

[0062] Understandable Figure 4 Although the link from the first TAP port to the second TAP port is labeled "First / Second / Third Link," it does not mean that the first TAP port and the second TAP port directly reuse a single communication connection. Depending on actual business needs, these three links can be used as three separate communication connections to perform different types of subsequent data communication processes. Only the logical connection relationship is shown in the diagram; the actual connection links are not shown. Similarly, the link from the first TUN port to the first TAP port can be two separate communication connections to perform different types of subsequent data communication processes.

[0063] During data transmission, in a quantum-secure communication system, all data transmitted over the public network must be in encrypted form to ensure data security. Therefore, the data transmitted between the terminal and the aggregated secure gateway must be encrypted. During data transmission, both the first and second TAP ports will call their local encryption / decryption modules to decrypt the encrypted data and encrypt the plaintext data.

[0064] As mentioned in the background section, for a terminal to enter a quantum-secure communication system, its normal use typically requires access authentication through an aggregated security gateway and the issuance of a key by a key center. Here, access authentication includes the initial access authentication of the terminal to the aggregated security gateway to download the root key; and the secondary access authentication of the terminal to the aggregated security gateway to download the data communication key.

[0065] To ensure the normal use of the terminal, the method proposed in this invention includes step three: the terminal determines the communication link used by the data to be transmitted based on the data type of the data to be transmitted.

[0066] Specifically, based on the process required for normal use of the terminal, the data types here include instruction data and message data. Instruction data is one of the following: the first instruction data for the terminal's first access to the aggregated security gateway, the second instruction data for the terminal's second access to the aggregated security gateway, or the third instruction data for the terminal to download the key. Message data is either application message data or key message data. Application message data is the payload data in the data packet to be transmitted generated by the application, and key message data is the key file data issued to the terminal by the key center.

[0067] The first instruction data and application message data are transmitted using the first link; the second instruction data and the third instruction data are transmitted using the second link; and the key message data is transmitted using the third link.

[0068] Different data types are transmitted through different links established by virtual network ports without affecting each other. Each link transmits data according to its own communication rhythm, which is not prone to message blocking. Furthermore, if a link fails, it will not affect the data transmission in other links, further ensuring the continuity of data transmission in the quantum-safe communication system.

[0069] Step 4: The virtual network ports in the three communication links monitor the link connection status. In response to detecting a link disconnection, they generate link status feedback and send it to the other virtual network ports.

[0070] Specifically, when the link between the first TUN port and the first TAP port is disconnected, the first TAP port generates a first feedback of second and third link interruption in real time and sends it to the second TAP port; when the link between the second TAP port and the second TUN port is disconnected, the second TAP port generates a second feedback of second link interruption and sends it to the first TAP port; when the link between the second TAP port and the third TUN port is disconnected, the second TAP port generates a third feedback of third link interruption and sends it to the first TAP port; when the link between the first TAP port and the second TAP port is disconnected, the first TAP port generates a fourth feedback of full link interruption and sends it to the first TUN port, and the second TAP port generates a fifth feedback of full link interruption and sends it to the second TUN port.

[0071] Step 5: Re-establish the communication link on the virtual network port to enable data communication.

[0072] In response to the first TAP port receiving a second or third feedback, or the second TAP port receiving a first feedback, the disconnected virtual network ports re-establish a communication link. During the link re-establishment window, either the first or second TAP port will refuse to receive or send data. Since the first and second TAP ports are directly connected without any other network ports intermediary, they can obtain each other's current status in real time, thus preventing data transmission during the re-establishment window and resolving message backlog issues.

[0073] In response to the first TUN port receiving the fourth feedback and the second TUN port receiving the fifth feedback, the first TUN port sends the fourth feedback to the first physical communication network port of the terminal's communication area. The first physical communication network port takes over the transmission data information of the first TAP port based on the fourth feedback. The second TUN port sends the fifth feedback to the second physical communication network port of the aggregation security gateway. The second physical communication network port takes over the transmission data information of the second TAP port based on the fifth feedback. The communication link between the first physical communication network port and the second physical communication network port replaces the first link between the first TAP port and the second TAP port for data transmission.

[0074] At this time, to ensure smooth data transmission, when the first physical communication port receives the fourth feedback, it reactivates the first IP address and sends the third IP address to the first TAP port for use. When the second physical communication port receives the fifth feedback, it reactivates the second IP address and sends the fourth IP address to the second TAP port for use.

[0075] After the first TAP port and the second TAP port re-establish the first link, the first TAP port obtains the transmission data information from the first physical communication network port, and the second TAP port obtains the transmission data information from the second physical communication network port. The data transmission is then transferred from the physical communication network port to the virtual network port. The first TAP port re-activates the first IP address, the first physical communication network port re-activates the third IP address, the second TAP port re-activates the second IP address, and the second physical communication network port re-activates the fourth IP address. The data transmission operation continues using the new first link.

[0076] Through the above operations, it is ensured that the IP address used for communication between the terminal and the aggregated security gateway is always the first IP address and the second IP address. This ensures that during the switching between the virtual network port and the physical communication network port, the data packets can be continuously transmitted without changing the target IP address, thus guaranteeing the continuity of data transmission.

[0077] This invention also provides a computer device, such as... Figure 4As shown, the computer device includes at least one processor 501 and a memory 502 communicatively connected to the at least one processor 501; wherein the memory 502 stores instructions that can be executed by the at least one processor 501, and the instructions are executed by the at least one processor 501 to enable the at least one processor 501 to execute the above-described method for establishing a communication link based on a virtual network port.

[0078] The memory 502 and processor 501 are connected via a bus, which can include any number of interconnecting buses and bridges. The bus connects various circuits of one or more processors 501 and memory 502 together. The bus can also connect various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides an interface between the bus and the transceiver. The transceiver can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 501 is transmitted over a wireless medium via an antenna, which further receives data and transmits it to processor 501.

[0079] Processor 501 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory 502 can be used to store data used by processor 501 during operation.

[0080] This invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of a method for establishing a communication link based on a virtual network port according to this invention.

Claims

1. A method for establishing a communication link based on a virtual network port, characterized in that, The method comprises: The terminal and the aggregation security gateway respectively create two virtual network interfaces locally, and the key center creates one virtual network interface locally; The terminal, the aggregation security gateway, and the key center create three communication links based on the virtual network interfaces; The terminal determines the communication link used by the data to be transmitted according to the data type of the data to be transmitted; The virtual network interfaces in the three communication links listen to the link connection state, and in response to listening to the disconnection of the link, generate feedback of the link state and send it to other virtual network interfaces; The virtual network interfaces reestablish the communication links to perform data communication.

2. The method of claim 1, wherein, The terminal and the aggregation security gateway respectively create two virtual network interfaces locally, which comprises: The terminal creates a first TAP interface and a first TUN interface in a local isolation area; The aggregation security gateway creates a second TAP interface and a second TUN interface locally; The key center creates one virtual network interface locally, which comprises: The key center creates a third TUN interface locally.

3. The method of claim 2, wherein: The first TUN interface, the second TUN interface, and the third TUN interface are each assigned an IP address by the command center; The first TAP interface and the second TAP interface each read the IP address of the local physical communication network interface as their own IP address; The IP address is used for addressing during data transmission.

4. The method of claim 2, wherein, The three communication links comprise: A first link from the first TAP interface to the second TAP interface; A second link from the first TUN interface to the first TAP interface to the second TAP interface to the second TUN interface; and A third link from the first TUN interface to the first TAP interface to the second TAP interface to the third TUN interface.

5. The method of claim 4, wherein, The terminal determines the communication link used by the data to be transmitted according to the data type of the data to be transmitted, which comprises: The data type includes instruction data and message data, the instruction data is one of first instruction data for the terminal to access the aggregation security gateway for the first time, second instruction data for the terminal to access the aggregation security gateway for the second time, and third instruction data for the terminal to download the key, and the message data is application message data or key message data; The first instruction data and the application message data are transmitted using the first link; The second instruction data and the third instruction data are transmitted using the second link; The key message data is transmitted using the third link.

6. The method of claim 4, wherein, The virtual network interfaces in the three communication links listen to the link connection state, and in response to listening to the disconnection of the link, generate feedback of the link state and send it to other virtual network interfaces, which comprises: When the link between the first TUN interface and the first TAP interface is disconnected, the first TAP interface generates first feedback of the disconnection of the second link and the third link in real time and sends it to the second TAP interface; When the link between the second TAP interface and the second TUN interface is disconnected, the second TAP interface generates second feedback of the disconnection of the second link and sends it to the first TAP interface; When the link between the second TAP interface and the third TUN interface is disconnected, the second TAP interface generates third feedback of the disconnection of the third link and sends it to the first TAP interface; When the link between the first TAP port and the second TAP port is disconnected, the first TAP port generates a fourth feedback of full link interruption and sends it to the first TUN port, and the second TAP port generates a fifth feedback of full link interruption and sends it to the second TUN port.

7. The method of claim 6, wherein, The virtual network port reestablishes the communication link to perform data communication, including: In response to the first TAP port receiving the second feedback or the third feedback, or the second TAP port receiving the first feedback, the communication link between the disconnected virtual network ports is reestablished; In response to the first TUN port receiving the fourth feedback and the second TUN port receiving the fifth feedback, the first TUN port sends the fourth feedback to the first physical communication network port of the terminal communication area, and the first physical communication network port takes over the transmission data information of the first TAP port based on the fourth feedback; the second TUN port sends the fifth feedback to the second physical communication network port of the aggregation security gateway, and the second physical communication network port takes over the transmission data information of the second TAP port based on the fifth feedback, and the data transmission is performed by the communication link between the first physical communication network port and the second physical communication network port instead of the first link between the first TAP port and the second TAP port.

8. The method of claim 7, wherein, The method further includes: After the first TAP port and the second TAP port reestablish a new first link, the first TAP port obtains transmission data information from the first physical communication network port, and the second TAP port obtains transmission data information from the second physical communication network port, and the data transmission operation is continued using the new first link.

9. A computer device, comprising: The computer device at least includes a processor and a memory, and the processor is configured to execute a computer program stored in the memory to implement the method for establishing a communication link based on a virtual network port according to any one of claims 1-8.

10. A computer-readable storage medium, characterized in that: The computer device has a computer program stored therein, and the computer program is executed by the processor to implement the method for establishing a communication link based on a virtual network port according to any one of claims 1-8.