An industrial control broadcast suppression method, system and switching device

By using an industrial control broadcast suppression system, which incorporates data acquisition, processing, and encapsulation modules in conjunction with IPSec VPN, the interface limitations and security issues of traditional industrial control broadcast protocols are resolved. This enables precise control and secure, reliable data transmission, thereby improving the security and efficiency of the network environment.

CN122226337APending Publication Date: 2026-06-16BEIJING SECURITY UNION IT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING SECURITY UNION IT CO LTD
Filing Date
2026-02-27
Publication Date
2026-06-16

AI Technical Summary

Technical Problem

Traditional industrial control broadcast protocols are limited by interface type and transmission distance in industrial control systems, resulting in high deployment costs and a lack of security protection. They are also vulnerable to attacks and intrusions, leading to system crashes and data leaks.

Method used

An industrial control broadcast suppression system is adopted, including a main control unit, an external network unit, an internal network unit, an IP protocol stack, a bridge unit, and an IPSec VPN unit. Through data acquisition, processing, marking, and encapsulation modules, broadcast data transmission is precisely controlled, and encrypted transmission is performed using IPSec VPN, realizing functional control from the link layer to the network layer.

Benefits of technology

It enables precise control of industrial control protocols and secure and reliable data transmission, saving resources and improving the security and efficiency of the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122226337A_ABST
    Figure CN122226337A_ABST
Patent Text Reader

Abstract

The application discloses an industrial control broadcast inhibition method and system and a switching device. The system comprises a master control unit, an external network unit, an internal network unit, an IP protocol stack, a network bridge unit and an IPSec VPN unit. The master control unit is in communication connection with the external network unit, the internal network unit, the IP protocol stack, the network bridge unit and the IPSec VPN unit. The external network unit and the internal network unit are in communication connection through the IP protocol stack and the network bridge unit. The IP protocol stack is in communication connection with the IPSec VPN. The application can accurately control broadcast data transmission, improve product competitiveness and reduce user use cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, specifically to an industrial control broadcast suppression method, system, and switching equipment. Background Technology

[0002] Industrial control broadcast protocol (ICBB) is a protocol used in industrial control systems based on TCP / IP to broadcast messages between multiple devices. ICBB can be used for scenarios such as real-time data transmission, event notification, remote control operation, and data synchronization. The advantages of ICBB include:

[0003] High reliability: Accurate message transmission is ensured through multiple broadcasts and acknowledgments.

[0004] Fast response: It can quickly deliver messages and reduce latency.

[0005] Real-time control: Allows for real-time control and adjustment of equipment and systems.

[0006] Flexibility and scalability: The functionality and features of the protocol can be expanded and adjusted as needed.

[0007] Industrial control broadcast protocols can be applied to industrial control systems in industries such as power, chemical, and transportation to enable remote monitoring and control of equipment.

[0008] Traditional industrial control broadcast protocols in industrial control environments rely on hardware interfaces such as RS485 and RS232. These are limited by interface type and transmission distance, have high deployment costs, lack security protection measures during transmission, and are vulnerable to attacks and intrusions, leading to security problems such as system crashes and data leaks. Summary of the Invention

[0009] Therefore, the technical problem to be solved by the present invention is to provide an industrial control broadcast suppression method, system and switching equipment that can accurately control broadcast data transmission, improve product competitiveness and reduce user costs.

[0010] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0011] An industrial control broadcast suppression system includes a main control unit, an external network unit, an internal network unit, an IP protocol stack, a bridge unit, and an IPSec VPN unit. The main control unit is communicatively connected to the external network unit, the internal network unit, the IP protocol stack, the bridge unit, and the IPSec VPN unit. The external network unit and the internal network unit are communicatively connected through the IP protocol stack and the bridge unit. The IP protocol stack is communicatively connected to the IPSec VPN unit. The IPSec VPN unit includes a data acquisition module, a data processing module, a packet marking module, a packet encapsulation / decapsulation module, a data transmission module, and a policy management module with a pre-configured list of controlled protocols. The data acquisition module registers a hook point in the PreRouting chain of the netfilter module of the IP protocol stack and is communicatively connected to the data processing module. The data processing module is communicatively connected to the packet marking module, the packet encapsulation / decapsulation module, and the data transmission module. The packet marking module is communicatively connected to the packet encapsulation / decapsulation module and the data transmission module. The packet encapsulation / decapsulation module is communicatively connected to the data transmission module. The data transmission module is communicatively connected to the IP protocol stack.

[0012] In the aforementioned industrial control broadcast suppression system, the HOOK points registered by the data acquisition module in the PreRouting chain of the netfilter module in the IP protocol stack have the highest priority attributes.

[0013] In the aforementioned industrial control broadcast suppression system, after the external network unit and external network equipment establish an IPSec tunnel, the main control unit constructs a virtual network card for internal network access. The virtual network card communicates and binds with the bridge unit.

[0014] The aforementioned industrial control broadcast suppression system uses a message encapsulation / decapsulation unit to encapsulate data that needs to be encapsulated according to a point-to-point tunneling strategy.

[0015] A method for suppressing industrial control broadcasts using the aforementioned industrial control broadcast suppression system, wherein when an intranet device sends link-layer broadcast frame data outward through the industrial control broadcast suppression system, the industrial control broadcast suppression system processes the link-layer broadcast frame data before forwarding it outward by performing the following steps:

[0016] S101) The data acquisition module acquires the link layer broadcast frame data sent to the IP protocol stack through the intranet unit and the bridge unit, and sends the acquired link layer broadcast frame data to the data processing module;

[0017] S102) The data processing module analyzes the received link layer broadcast frame data and determines the protocol type of the link layer broadcast frame data. If the protocol type of the link layer broadcast frame data does not belong to the protocol type recorded in the controlled protocol list, the data processing module sends the link layer broadcast frame data to the IP protocol stack through the data sending module and the IP protocol stack propagates it outward through the external network unit. Otherwise, the link layer broadcast frame data is sent to the message marking module.

[0018] S103) The message marking module detects whether there is marking information in the cb object in the sub_buf structure of the received link layer broadcast frame data. If there is marking information, the link layer broadcast frame data is discarded; otherwise, it is determined that the link layer broadcast frame data is broadcast data generated by the intranet device, and then the link layer broadcast frame data is sent to the message encapsulation / decapsulation module.

[0019] S104) The message encapsulation / decapsulation module encapsulates the received link layer broadcast frame data according to the point-to-point tunnel strategy and sends the encapsulated link layer broadcast frame data to the data transmission module;

[0020] S105) The data sending module sends the received and encapsulated link layer broadcast frame data to the IP protocol stack;

[0021] S106) The IP protocol stack propagates encapsulated link layer broadcast frame data to the outside world through the external network unit.

[0022] In the above method, the controlled protocol types in the controlled protocol list are protocol types that are preset by the user.

[0023] In the above method (S106), when the IP protocol stack propagates the encapsulated link layer broadcast frame data to the outside through the external network unit, the external network unit communicates with the device receiving the encapsulated link layer broadcast frame data through an IPSec tunnel.

[0024] A method for suppressing industrial control broadcasts using the aforementioned industrial control broadcast suppression system involves the following steps when an external network device transmits link-layer broadcast frame data to the internal network via an external network unit: The industrial control broadcast suppression system processes the link-layer broadcast frame data before forwarding it to the internal network:

[0025] S201) The data acquisition module acquires the link layer broadcast frame data sent by the external network device to the IP protocol stack through the external network unit and sends the acquired link layer broadcast frame data to the message encapsulation / decapsulation module;

[0026] S202) The message encapsulation / decapsulation module decapsulates the received link layer broadcast frame data and sends the decapsulated link layer broadcast frame data to the data processing module;

[0027] (S203) The data processing module analyzes the received decrypted link layer broadcast frame data and determines the protocol type of the link layer broadcast frame data. If the protocol type of the link layer broadcast frame data does not belong to the protocol type recorded in the controlled protocol list, the data processing module sends the link layer broadcast frame data to the IP protocol stack through the data sending module and then the IP protocol stack propagates to the intranet through the bridge unit and the intranet unit. Otherwise, the link layer broadcast frame data is sent to the message marking module.

[0028] (S204) The message marking module modifies the value of the cb object in the skb_buf structure of the received decapsulated link layer broadcast frame data and marks the link layer broadcast frame data. Then, the marked link layer broadcast frame data is sent to the IP protocol stack and propagated to the intranet by the IP protocol stack through the bridge unit and the intranet unit.

[0029] In the above method, when the bridge unit is connected to and bound to a virtual network card, in step S204), the IP protocol stack writes the identified link layer broadcast frame data into the virtual network card.

[0030] A switching device, wherein the communication input terminal and the communication output terminal are connected via the aforementioned industrial control broadcast suppression system.

[0031] The technical solution of the present invention achieves the following beneficial technical effects:

[0032] 1. This invention allows users to freely control the industrial control protocols that are allowed to be transmitted at the link layer, and enables encrypted transmission through IPSec VPN, thereby achieving precise control and security.

[0033] 2. This invention allows users to freely control the broadcasting of industrial control protocols according to actual scenarios, thereby achieving the goals of saving resources and improving efficiency.

[0034] 3. This invention mainly implements all functions from the link layer to the network layer based on the IPSec VPN module, making data processing more efficient and controllable. Attached Figure Description

[0035] Figure 1 This is a schematic diagram illustrating the working principle of the industrial control broadcast suppression system in this invention.

[0036] Figure 2 This is a schematic diagram illustrating the working principle of the IPSec VPN unit in this invention.

[0037] Figure 3 This is a flowchart illustrating the industrial control broadcast suppression process during data transmission from the intranet to the extranet in this invention.

[0038] Figure 4This is a flowchart illustrating the process of suppressing industrial control broadcasts when transmitting data from the external network to the internal network in this invention.

[0039] Figure 5 This is a schematic diagram illustrating the working principle of the switching device in this invention. Detailed Implementation

[0040] The present invention will be further explained below with reference to examples.

[0041] like Figure 1 and Figure 2 As shown, the industrial control broadcast suppression system of this invention includes a main control unit, an external network unit, an internal network unit, an IP protocol stack, a bridge unit, and an IPSec VPN unit. The main control unit is communicatively connected to the external network unit, the internal network unit, the IP protocol stack, the bridge unit, and the IPSec VPN unit. The external network unit and the internal network unit are communicatively connected through the IP protocol stack and the bridge unit. The IP protocol stack is communicatively connected to the IPSec VPN unit. The IPSec VPN unit is equipped with a data acquisition module, a data processing module, a packet marking module, a packet encapsulation / decapsulation module, a data transmission module, and a policy management module with a pre-set list of controlled protocols. The data acquisition module registers a hook point in the PreRouting chain of the netfilter module of the IP protocol stack and is communicatively connected to the data processing module. The data processing module is communicatively connected to the packet marking module, the packet encapsulation / decapsulation module, and the data transmission module. The packet marking module is communicatively connected to the packet encapsulation / decapsulation module and the data transmission module. The packet encapsulation / decapsulation module is communicatively connected to the data transmission module. The data transmission module is communicatively connected to the IP protocol stack. The message encapsulation / decapsulation unit encapsulates the data that needs to be encapsulated according to the point-to-point tunnel strategy.

[0042] The hook point is the core of the netfilter module. Its existence allows the Linux kernel to insert custom processing logic at different stages of a data packet's journey through the network stack. The preRouting chain is a crucial hook point in the netfilter module, located before the data packet enters the routing decision process. For example, the following code defines `struct nf_hook_ops`:

[0043] 1 static struct nf_hook_ops nfho = {

[0044] 2. hook-hook_func, / / Specifies the hook function

[0045] 3. `hooknum-NF_INET_PRE_ROUTING`, / / The network traffic phase in which the hook function is located.

[0046] 4. .pf-PF_INET, / / IP protocol suite

[0047] 5. priority - NF_IP_PRI_FIRST / / Priority

[0048] 6};

[0049] The existing techniques in the field used in this invention for data collection by registering HOOK points in the PreRouting chain of the netfilter module in the IP protocol stack will not be described in detail in this specification.

[0050] To increase the number of interfaces that can be connected to, and to ensure security, after the IPSec tunnel is established between the external network unit and the external network device, the main control unit builds a virtual network card for internal network access. The virtual network card communicates and is bound to the bridge unit.

[0051] In an APN network, when information is transmitted based on the industrial control broadcast protocol, there are two scenarios: one is information transmission from the intranet to the extranet, and the other is information transmission from the extranet to the intranet. In these two scenarios, the processing flow of the information to be transmitted using the industrial control broadcast suppression system is different, and this embodiment will describe them separately.

[0052] When internal network devices send link-layer broadcast frame data to the outside world through the industrial control broadcast suppression system, such as Figure 3 As shown, the industrial control broadcast suppression system processes the link layer broadcast frame data through the following steps before forwarding it outwards:

[0053] S101) The data acquisition module acquires the link layer broadcast frame data sent to the IP protocol stack through the intranet unit and the bridge unit, and sends the acquired link layer broadcast frame data to the data processing module;

[0054] S102) The data processing module analyzes the received link layer broadcast frame data and determines the protocol type of the link layer broadcast frame data. If the protocol type of the link layer broadcast frame data does not belong to the protocol type recorded in the controlled protocol list, the data processing module sends the link layer broadcast frame data to the IP protocol stack via the data sending module and the IP protocol stack propagates it outward through the external network unit. Otherwise, the link layer broadcast frame data is sent to the message marking module. The protocol type recorded in the controlled protocol list is set by the user according to the specific application scenario. It can be Modbus / TCP, PROFINET, PROFIBUS, or PCWorx.

[0055] S103) The message marking module detects whether there is marking information in the cb object in the sub_buf structure of the received link layer broadcast frame data. If there is marking information, the link layer broadcast frame data is discarded; otherwise, it is determined that the link layer broadcast frame data is broadcast data generated by the intranet device, and then the link layer broadcast frame data is sent to the message encapsulation / decapsulation module.

[0056] S104) The message encapsulation / decapsulation module encapsulates the received link layer broadcast frame data according to the point-to-point tunnel strategy and sends the encapsulated link layer broadcast frame data to the data transmission module;

[0057] S105) The data sending module sends the received and encapsulated link layer broadcast frame data to the IP protocol stack;

[0058] S106) The IP protocol stack propagates encapsulated link layer broadcast frame data to the outside world through the external network unit.

[0059] In this invention, the controlled protocol types stored in the controlled protocol list can be set, added, or deleted by the user according to their own network security needs, which increases the applicability of the industrial control broadcast suppression system.

[0060] Furthermore, the industrial control broadcast suppression system can propagate information in different ways depending on the type of information being transmitted. For example, when point-to-point transmission is required, the message encapsulation / decapsulation module encapsulates the data to be encapsulated, and then forwards it to the external network unit via the IP protocol stack. In this case, the external network unit needs to establish an IPSec tunnel with the receiving device. If point-to-point transmission is not required, the message encapsulation / decapsulation module does not need to encapsulate the relevant messages; the IP protocol stack can directly forward the messages to the external network device through the external network unit. That is, in S106), when the IP protocol stack propagates the encapsulated link layer broadcast frame data outward through the external network unit, the external network unit communicates with the device receiving the encapsulated link layer broadcast frame data through an IPSec tunnel.

[0061] When external network devices propagate link-layer broadcast frame data to the internal network through the external network unit, such as Figure 4 As shown, the industrial control broadcast suppression system processes the link layer broadcast frame data through the following steps before forwarding it to the internal network:

[0062] S201) The data acquisition module acquires the link layer broadcast frame data sent by the external network device to the IP protocol stack through the external network unit and sends the acquired link layer broadcast frame data to the message encapsulation / decapsulation module;

[0063] S202) The message encapsulation / decapsulation module decapsulates the received link layer broadcast frame data and sends the decapsulated link layer broadcast frame data to the data processing module;

[0064] (S203) The data processing module analyzes the received decrypted link layer broadcast frame data and determines the protocol type of the link layer broadcast frame data. If the protocol type of the link layer broadcast frame data does not belong to the protocol type recorded in the controlled protocol list, the data processing module sends the link layer broadcast frame data to the IP protocol stack through the data sending module and then the IP protocol stack propagates to the intranet through the bridge unit and the intranet unit. Otherwise, the link layer broadcast frame data is sent to the message marking module.

[0065] (S204) The message marking module modifies the value of the cb object in the skb_buf structure of the received decapsulated link-layer broadcast frame data and marks the link-layer broadcast frame data. Then, it sends the marked link-layer broadcast frame data to the IP protocol stack, which then propagates it to the intranet via the bridge unit and the intranet unit. The mark is used to mark the link-layer broadcast frame data as restricted broadcast data, serving as the basis for intranet devices to determine whether the link-layer broadcast frame data can be forwarded or broadcast. This mark can be calculated using a hash algorithm or set by the user.

[0066] When the bridge unit is connected and bound to a virtual network card, in step S204), the IP protocol stack writes the identified link layer broadcast frame data into the virtual network card. At this time, when some devices access the network through the virtual network card, the identified link layer broadcast frame data can be propagated to these devices through the virtual network card.

[0067] When transmitting data from the external network to the internal network via broadcast, if the protocol type in the message formed based on the data from the external network is a controlled protocol type, the IPSec VPN unit adds an identifier to the message. Then, the IPSec VPN unit in the virtual network card that receives the message with the added identifier determines whether to continue transmitting the message based on the identifier, thereby achieving the effect of suppressing industrial control broadcasts. This can limit the transmission of industrial control broadcast protocols in specific industrial control environments, thereby purifying the network environment, saving bandwidth, and improving performance.

[0068] Based on the aforementioned industrial control broadcast suppression system and method, this invention also provides a switching device for forwarding information data between intranet devices and extranet devices, such as... Figure 5 As shown, the communication input terminal and the communication output terminal of the switching device are connected via the aforementioned industrial control broadcast suppression system.

[0069] Obviously, the above embodiments are merely illustrative examples for clear explanation and are not intended to limit the implementation. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations here. However, obvious variations or modifications derived therefrom are still within the scope of protection of the claims of this patent application.

Claims

1. An industrial control broadcast suppression system, characterized in that, It includes a main control unit, an external network unit, an internal network unit, an IP protocol stack, a bridge unit, and an IPSec VPN unit. The main control unit communicates with the external network unit, the internal network unit, the IP protocol stack, the bridge unit, and the IPSec VPN unit. The external network unit communicates with the internal network unit through the IP protocol stack and the bridge unit. The IP protocol stack communicates with the IPSec VPN unit. The IPSec VPN unit contains a data acquisition module, a data processing module, a packet marking module, a packet encapsulation / decapsulation module, a data sending module, and a policy management module with a pre-configured list of controlled protocols. The data acquisition module registers a hook point in the PreRouting chain of the netfilter module in the IP protocol stack and communicates with the data processing module. The data processing module communicates with the packet marking module, the packet encapsulation / decapsulation module, and the data sending module. The packet marking module communicates with the packet encapsulation / decapsulation module and the data sending module. The packet encapsulation / decapsulation module communicates with the data sending module. The data sending module communicates with the IP protocol stack.

2. The industrial control broadcast suppression system according to claim 1, characterized in that, The attributes of the hook points registered by the data acquisition module in the PreRouting chain of the netfilter module in the IP protocol stack have the highest priority.

3. The industrial control broadcast suppression system according to claim 1, characterized in that, After the external network unit and external network devices establish an IPSec tunnel, the main control unit builds a virtual network card for internal network access. The virtual network card communicates and binds with the bridge unit.

4. The industrial control broadcast suppression system according to claim 1, characterized in that, The message encapsulation / decapsulation unit encapsulates the data that needs to be encapsulated according to the point-to-point tunnel strategy.

5. A method for suppressing industrial broadcasts using the industrial broadcast suppression system according to claim 1, characterized in that, When intranet devices send link-layer broadcast frame data to the outside through the industrial control broadcast suppression system, the industrial control broadcast suppression system processes the link-layer broadcast frame data before forwarding it outwards using the following steps: S101) The data acquisition module acquires the link layer broadcast frame data sent to the IP protocol stack through the intranet unit and the bridge unit, and sends the acquired link layer broadcast frame data to the data processing module; S102) The data processing module analyzes the received link layer broadcast frame data and determines the protocol type of the link layer broadcast frame data. If the protocol type of the link layer broadcast frame data does not belong to the protocol type recorded in the controlled protocol list, the data processing module sends the link layer broadcast frame data to the IP protocol stack through the data sending module and the IP protocol stack propagates it outward through the external network unit. Otherwise, the link layer broadcast frame data is sent to the message marking module. S103) The message marking module detects whether there is marking information in the cb object in the sub_buf structure of the received link layer broadcast frame data. If there is marking information, the link layer broadcast frame data is discarded; otherwise, it is determined that the link layer broadcast frame data is broadcast data generated by the intranet device, and then the link layer broadcast frame data is sent to the message encapsulation / decapsulation module. S104) The message encapsulation / decapsulation module encapsulates the received link layer broadcast frame data according to the point-to-point tunnel strategy and sends the encapsulated link layer broadcast frame data to the data transmission module; S105) The data sending module sends the received and encapsulated link layer broadcast frame data to the IP protocol stack; S106) The IP protocol stack propagates encapsulated link layer broadcast frame data to the outside world through the external network unit.

6. The method according to claim 5, characterized in that, The controlled protocol types in the controlled protocol list are those that have been pre-defined by the user.

7. The method according to claim 5, characterized in that, In S106), when the IP protocol stack propagates the encapsulated link layer broadcast frame data to the outside through the external network unit, the external network unit communicates with the device receiving the encapsulated link layer broadcast frame data through the IPSec tunnel.

8. A method for suppressing industrial broadcasts using the industrial broadcast suppression system according to claim 1, characterized in that, When external network devices transmit link-layer broadcast frame data to the internal network through the external network unit, the industrial control broadcast suppression system processes the link-layer broadcast frame data through the following steps before forwarding it to the internal network: S201) The data acquisition module acquires the link layer broadcast frame data sent by the external network device to the IP protocol stack through the external network unit and sends the acquired link layer broadcast frame data to the message encapsulation / decapsulation module; S202) The message encapsulation / decapsulation module decapsulates the received link layer broadcast frame data and sends the decapsulated link layer broadcast frame data to the data processing module; (S203) The data processing module analyzes the received decrypted link layer broadcast frame data and determines the protocol type of the link layer broadcast frame data. If the protocol type of the link layer broadcast frame data does not belong to the protocol type recorded in the controlled protocol list, the data processing module sends the link layer broadcast frame data to the IP protocol stack via the data sending module, and the IP protocol stack propagates to the intranet through the bridge unit and the intranet unit. Otherwise, the link layer broadcast frame data is sent to the message marking module. (S204) The message marking module modifies the value of the cb object in the skb_buf structure of the received decapsulated link layer broadcast frame data and marks the link layer broadcast frame data. Then, the marked link layer broadcast frame data is sent to the IP protocol stack and propagated to the intranet by the IP protocol stack through the bridge unit and the intranet unit.

9. The method according to claim 8, characterized in that, When a bridge unit is connected to and bound to a virtual network interface card (NIC), in step S204), the IP protocol stack writes the identified link layer broadcast frame data into the virtual NIC.

10. A switching device, characterized in that, The communication input terminal and the communication output terminal are connected via the industrial control broadcast suppression system described in claim 1.