A method and system for integrity checking of transport layer encrypted data

CN122845307APending Publication Date: 2026-09-29BEIJING ZHONGYU WANTONG TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611348967.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-09-02
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0003]当前主流传输层完整性校验方案均以单个传输层数据包为最小处理单元独立生成校验标识,不存在针对同一数据流批量数据包统一拼接载荷后生成全局校验标识的处理逻辑,逐包生成校验信息会持续产生大量附属校验报文挤占通信链路有效带宽,同时数据解密流程与完整性校验流程分步独立执行,缺少数据流窗口标识绑定关联机制,当接收端校验发现数据异常时无法精准定位发送端对应缓存窗口,只能对整条数据流全部发起重传请求,无效重传数据量大幅增加,校验处理链路步骤繁琐,整体数据校验处理时延较长,大批量并发数据流传输场景下校验稳定性与传输效率均存在明显短板

Benefits of technology

1.本发明通过五元组识别同一数据流的全部待发送传输层数据包并统一归集至窗口缓存区形成待校验数据包窗口,整合窗口内所有数据包载荷拼接生成完整待校验载荷序列后统一开展杂凑运算得到唯一校验摘要值,单独构建完整性校验信令包承载校验摘要值与对应数据流专属窗口标识信息,整套校验信息仅随批量加密数据包统一发送,能够集中完成整组窗口数据包的完整性校验逻辑,大幅缩减链路内校验附属报文的传输总量,依靠全局唯一窗口标识完成发送端缓存窗口与接收端解密数据包组的定向绑定,精准建立整组载荷数据与对应校验摘要值的一一对应关联关系。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845307A_ABST
    Figure CN122845307A_ABST
Patent Text Reader

Abstract

This invention relates to the field of communication encryption technology and proposes a method and system for verifying the integrity of transport layer encrypted data. The method includes: firstly, storing transport layer data packets to be sent in the same data stream into a window buffer to form a window of data packets to be verified; extracting the window payload and concatenating it into a sequence of payloads to be verified; obtaining a verification digest value through hash operation; and encapsulating an integrity verification signaling packet in combination with a window identifier; then sending the encrypted data packets and the two types of messages to the data communication gateway; the receiving end distinguishes between the encrypted data packets and the verification signaling packet, decrypts them to obtain decrypted payload data, and binds the verification digest value to the corresponding decrypted data packet group based on the window identifier; generating a sequence of payloads to be verified by concatenating the payloads in the group and calculating the digest value to be compared; judging the integrity of the data packet group by comparing the results of the two digests; triggering retransmission of the corresponding window when there is an anomaly, and releasing the buffer and forwarding the data when it is normal; this invention can improve the efficiency of transport layer encrypted data integrity verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication encryption technology, and in particular to a method and system for verifying the integrity of encrypted data at the transport layer. Background Technology

[0002] In cross-gateway transmission scenarios, business data is segmented into multiple independent transport layer data packets to be sent according to the transport layer protocol rules. The complete data stream corresponding to the same business interaction is stored separately in the payloads of different data packets. Downstream business applications can only rely on the complete and untampered payload data to complete instruction parsing, business calculation and result output. Therefore, a complete integrity verification process must be matched between the data sending end and the receiving end to identify abnormal situations such as data packet loss, payload tampering and message out of order that occur during the link transmission process, so as to ensure the reliable operation of business data interaction.

[0003] Current mainstream transport layer integrity verification schemes generate verification identifiers independently for each individual transport layer data packet as the smallest processing unit. There is no processing logic for generating a global verification identifier by uniformly splicing the payloads of batch data packets of the same data stream. Generating verification information packet by packet will continuously generate a large number of auxiliary verification messages, which will occupy the effective bandwidth of the communication link. At the same time, the data decryption process and the integrity verification process are executed independently step by step, and there is no data stream window identifier binding and association mechanism. When the receiving end detects data anomalies, it cannot accurately locate the corresponding buffer window of the sending end, and can only initiate a retransmission request for the entire data stream. The amount of invalid retransmission data increases significantly. The verification processing link steps are cumbersome, and the overall data verification processing latency is long. In the scenario of large-scale concurrent data stream transmission, there are obvious shortcomings in verification stability and transmission efficiency. Summary of the Invention

[0004] This invention provides a method and system for verifying the integrity of transport layer encrypted data, in order to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides a transport layer encrypted data integrity verification method, comprising: Pt.1. Buffer the transport layer data packets to be sent that belong to the same data stream in the window buffer area to form a window of data packets to be verified; Pt.2. Extract the payload data from the data packet window to be verified and concatenate them to generate a payload sequence to be verified. Perform a hash operation on the payload sequence to be verified to generate a verification digest value. Encapsulate the verification digest value and the window identification information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet. Pt.3. Perform encryption operation on the payload of the data packet in the data packet window to be verified to generate an encrypted data packet, and send the integrity verification signaling packet and the encrypted data packet to the data communication gateway; Pt.4. Distinguish the encrypted data packet and the integrity verification signaling packet from the received incoming data packet, decrypt the encrypted data packet to obtain decrypted payload data, and establish an association between the verification digest value in the integrity verification signaling packet and the decrypted data packet group belonging to the same data stream in the decrypted payload data according to the window identification information in the integrity verification signaling packet. Pt.5. Concatenate the payload data in the decrypted data packet group to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a comparison digest value, compare the comparison digest value with the verification digest value, and determine whether the decrypted data packet group is complete based on the comparison result.

[0006] In a preferred embodiment, the step of caching transport layer data packets belonging to the same data stream in a window buffer to form a window of data packets to be verified includes: Obtain the transport layer data packet to be sent, and read the five-tuple information from the header of the transport layer data packet to be sent. The five-tuple information includes the source address, source port, destination address, destination port, and transport layer protocol type. If the five-tuple information of the transport layer data packet to be sent is consistent with that of a cached data packet, then it is determined that the transport layer data packet to be sent and the cached data packet belong to the same data stream. The transport layer data packets to be sent are written into the window buffer, and the transport layer data packets to be sent are kept in the window buffer in the order of arrival to form the window of data packets to be verified.

[0007] In a preferred embodiment, the step of extracting payload data from the data packet window to be verified, concatenating it to generate a payload sequence to be verified, and performing a hash operation on the payload sequence to be verified to generate a verification digest value includes: The payload data of the data packet is extracted from the data packet window to be verified, and the payload length corresponding to the payload data is read from the packet header to obtain the payload data and the payload length corresponding to the payload data. The load length is appended before the load data, and the load data with the load length is appended sequentially according to the order of the data packets in the data packet window to be verified, to generate a load sequence to be verified with length markers. The session key negotiated between the encryption module and the data communication gateway is obtained. The session key and the length-marked payload sequence to be verified are input into the hash operation unit inside the encryption module. The hash operation unit performs a hash operation on the input session key and the length-marked payload sequence to be verified to generate the verification digest value.

[0008] In a preferred embodiment, encapsulating the verification digest value and the window identifier information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet includes: Write the window identification information into the header field of the signaling packet payload, write the verification digest value into the data field of the signaling packet payload, and generate the payload part of the integrity verification signaling packet; A type flag is added to the header of the integrity verification signaling packet. The type flag is used to indicate that the current data packet is an integrity verification signaling packet. The type flag has a different value than the type flag in the header of the encrypted data packet. The integrity verification signaling packet is generated by assembling the payload portion of the integrity verification signaling packet with the header of the integrity verification signaling packet that has the type mark added.

[0009] In a preferred embodiment, the step of performing an encryption operation on the payload of the data packets in the data packet window to be verified to generate an encrypted data packet, and sending the integrity verification signaling packet and the encrypted data packet to the data communication gateway, includes: The encrypted data packets are sent sequentially to the data communication gateway, and the encrypted data packets that have been sent are recorded during the sending process. After all the encrypted data packets have been sent, the integrity verification signaling packet is sent to the data communication gateway. The integrity verification signaling packet is sent after the encrypted data packets in the timing sequence. After sending the integrity verification signaling packet, listen for the acknowledgment response from the data communication gateway. If no acknowledgment response is received, resend the integrity verification signaling packet.

[0010] In a preferred embodiment, distinguishing the encrypted data packet and the integrity verification signaling packet from the received incoming data packet includes: Receive incoming data packets from the communication link connected to the data communication gateway, read the type flag field in the header of the incoming data packets, and obtain the type flag of the incoming data packets; The type marker of the incoming data packet is compared with the preset type marker corresponding to the encrypted data packet. If the type marker of the incoming data packet is consistent with the preset type marker corresponding to the encrypted data packet, the incoming data packet is identified as the encrypted data packet. The type marker of the incoming data packet is compared with the preset type marker corresponding to the integrity verification signaling packet. If the type marker of the incoming data packet is consistent with the preset type marker corresponding to the integrity verification signaling packet, the incoming data packet is identified as the integrity verification signaling packet. The identified encrypted data packet is passed to the decryption process, and the identified integrity verification signaling packet is passed to the verification information extraction process.

[0011] In a preferred embodiment, the step of associating the verification digest value in the integrity verification signaling packet with the decrypted data packet group belonging to the same data stream in the decryption payload data based on the window identification information in the integrity verification signaling packet includes: Extract the window identifier information and the verification digest value from the integrity verification signaling packet to obtain the window identifier to be associated and the verification digest value to be associated. Search for each stored decrypted data packet group in the cache area to be verified, read the cache window identifier corresponding to each decrypted data packet group, and compare the window identifier to be associated with each cache window identifier one by one. When the identifier of the window to be associated is consistent with the cache window identifier of a certain decrypted data packet group, the verification digest value to be associated is written into the association field corresponding to the certain decrypted data packet group to establish the correspondence between the verification digest value and the certain decrypted data packet group; After establishing the correspondence, the number of decrypted payload data stored in a certain decrypted data packet group is read to obtain the number of received data packets.

[0012] In a preferred embodiment, the step of concatenating payload data from the decrypted data packet group to generate a payload sequence to be verified, performing a hash operation on the payload sequence to be verified to generate a comparison digest value, comparing the comparison digest value with the verification digest value, and determining whether the decrypted data packet group is complete based on the comparison result includes: When the comparison result shows that the digest value to be compared is inconsistent with the verification digest value, it is determined that there is a tampered transport layer data packet in the decrypted data packet group, and the decrypted payload data in the decrypted data packet group is discarded; Based on the window identifier information corresponding to the decrypted data packet group, a window retransmission request is generated, and the window retransmission request includes the window identifier information. The window retransmission request is sent to the encryption module. Based on the window identification information in the window retransmission request, the window of the data packet to be verified is located in the window buffer and the data transmission operation corresponding to the window of the data packet to be verified is re-executed.

[0013] In a preferred embodiment, the step of caching in a window buffer to form a window of data packets to be verified and determining whether the decrypted data packet group is complete based on the comparison result further includes: When the buffer space occupied by the transport layer data packet to be sent in the window buffer reaches the preset storage limit of the window buffer, the window buffer is locked and the writing of newly arrived transport layer data packets to be sent to the window buffer is stopped. After locking the window buffer, the step of extracting the payload data from the data packet window to be verified and splicing it to generate the payload sequence to be verified is performed. When the comparison result is that the comparison digest value and the verification digest value are consistent, the data communication gateway forwards the decrypted payload data in the decrypted data packet group to the target application system in the order of each data packet in the decrypted data packet group, and after the forwarding is completed, returns a window confirmation response to the encryption module, the window confirmation response containing the window identification information; The encryption module receives the window confirmation response, locates the corresponding data packet window to be verified in the window cache based on the window identifier information in the window confirmation response, unlocks the window cache and releases the cache space occupied by the data packet window to be verified.

[0014] To address the above problems, the present invention also provides a transport layer encrypted data integrity verification system, the system comprising: The stream window buffer module is used to buffer transport layer data packets to be sent that belong to the same data stream in the window buffer area, forming a window of data packets to be verified; The digest group signaling module is used to extract the payload data in the data packet window to be verified, splice it to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a verification digest value, and encapsulate the verification digest value and the window identification information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet. The encrypted packet delivery module is used to perform encryption operations on the payload of the data packets in the data packet window to be verified to generate encrypted data packets, and send the integrity verification signaling packet and the encrypted data packets to the data communication gateway; The unpacking and binding module is used to distinguish the encrypted data packet and the integrity verification signaling packet from the received incoming data packet, decrypt the encrypted data packet to obtain decrypted payload data, and establish an association between the verification digest value in the integrity verification signaling packet and the decrypted data packet group belonging to the same data stream in the decrypted payload data according to the window identification information in the integrity verification signaling packet. The digest verification module is used to concatenate the payload data in the decrypted data packet group to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a digest value to be compared, compare the digest value to be compared with the verification digest value, and determine whether the decrypted data packet group is complete based on the comparison result.

[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention identifies all transport layer data packets to be sent from the same data stream using a 5-tuple and uniformly aggregates them into a window buffer to form a window of data packets to be verified. After concatenating the payloads of all data packets within the window to generate a complete sequence of payloads to be verified, a hash operation is uniformly performed to obtain a unique verification digest value. A separate integrity verification signaling packet is constructed to carry the verification digest value and the corresponding data stream-specific window identifier information. The entire set of verification information is sent only with the batch of encrypted data packets, which can centrally complete the integrity verification logic of the entire group of window data packets, significantly reducing the total amount of verification auxiliary messages transmitted within the link. Relying on the globally unique window identifier, the sending end buffer window and the receiving end decrypted data packet group are directly bound, accurately establishing a one-to-one correspondence between the entire group of payload data and the corresponding verification digest value.

[0016] 2. This invention synchronously encrypts the payload of all data packets within a window at the sending end to obtain encrypted data packets. The encrypted data packets and integrity verification signaling packets are then sequentially sent to the data communication gateway. At the receiving end, the two types of packets are distinguished by the message type marker, and batch data packets are decrypted to obtain the decrypted payload data. The corresponding decrypted data packet group is matched with the window identifier to splice the payload and generate a payload sequence to be verified. A unified hash comparison is performed. When the payload verification is abnormal, only the corresponding window identifier is carried to generate a directed retransmission request, which only triggers the retransmission of the corresponding window data packets. At the same time, a window buffer capacity limit control mechanism and a window confirmation response buffer release logic are added to constrain the peak value of buffer resource usage in real time, simplify the execution steps of the verification processing link at both the sending and receiving ends, continuously reduce the processing time of the entire integrity verification process in the scenario of batch data stream cross-gateway transmission, and steadily improve the data verification processing efficiency and the reliability of the entire data interaction process when transmitting large-scale concurrent data streams. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a flowchart illustrating a transport layer encrypted data integrity verification method according to an embodiment of the present invention. Figure 2 This is a functional block diagram of a transport layer encrypted data integrity verification system provided in an embodiment of the present invention.

[0019] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0020] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0021] This application provides a method for verifying the integrity of transport layer encrypted data. The executing entity of this method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. In other words, the method for verifying the integrity of transport layer encrypted data can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0022] Reference Figure 1 The diagram shown is a flowchart illustrating a transport layer encrypted data integrity verification method according to an embodiment of the present invention. In this embodiment, the transport layer encrypted data integrity verification method includes: Pt.1. Buffer the transport layer data packets to be sent that belong to the same data stream in the window buffer area to form a window of data packets to be verified; In this embodiment of the invention, the step of caching transport layer data packets belonging to the same data stream in a window buffer to form a window of data packets to be verified includes: Obtain the transport layer data packet to be sent, and read the five-tuple information from the header of the transport layer data packet to be sent. The five-tuple information includes the source address, source port, destination address, destination port, and transport layer protocol type. If the five-tuple information of the transport layer data packet to be sent is consistent with that of a cached data packet, then it is determined that the transport layer data packet to be sent and the cached data packet belong to the same data stream. The transport layer data packets to be sent are written into the window buffer, and the transport layer data packets to be sent are kept in the window buffer in the order of arrival to form the window of data packets to be verified.

[0023] The hardware message receiving channel continuously captures the transport layer data packets to be sent pushed by the link. The message parsing hardware locates the header storage area of ​​the transport layer data packets to be sent, and reads out the source address, source port, destination address, destination port and transport layer protocol type of the five-tuple information in sequence according to the fixed field offset position of the header, and stores them completely in the temporary storage unit.

[0024] The complete set of five-tuple information corresponding to the current transport layer data packet to be sent in the temporary storage unit will be compared byte by byte with the complete set of five-tuple information of each data packet already stored in the window buffer. When all bytes of the complete set of five-tuple information match completely, the data stream attribution determination operation is performed to determine that the current transport layer data packet to be sent and the corresponding cached data packet in the window buffer belong to the same data stream.

[0025] The message writing control unit retrieves the storage location at the end of the window buffer and writes the complete data packet to be sent into the storage location. The message writing control unit maintains the storage arrangement order of the data packets in the window buffer according to the order in which the data packets arrive at the hardware message receiving path. After all the data packets to be sent belonging to the same data stream are arranged in an orderly manner in the window buffer, a window of data packets to be verified with a fixed storage structure is generated.

[0026] The window buffer is configured with a hardware storage capacity threshold as the basis for determining whether to stop writing. When the storage capacity occupied by all data packets written to the transport layer to be sent in the window buffer reaches the preset hardware storage capacity threshold, the buffer locking hardware performs a locking operation to block the path of new data packets to be written to the window buffer. The locking state is maintained until the current data packet window to be verified completes all the sending and processing procedures and releases the storage space.

[0027] Pt.2. Extract the payload data from the data packet window to be verified and concatenate them to generate a payload sequence to be verified. Perform a hash operation on the payload sequence to be verified to generate a verification digest value. Encapsulate the verification digest value and the window identification information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet. In this embodiment of the invention, the step of extracting payload data from the data packet window to be verified, concatenating it to generate a payload sequence to be verified, and performing a hash operation on the payload sequence to be verified to generate a verification digest value includes: The payload data of the data packet is extracted from the data packet window to be verified, and the payload length corresponding to the payload data is read from the packet header to obtain the payload data and the payload length corresponding to the payload data. The load length is appended before the load data, and the load data with the load length is appended sequentially according to the order of the data packets in the data packet window to be verified, to generate a load sequence to be verified with length markers. The session key negotiated between the encryption module and the data communication gateway is obtained. The session key and the length-marked payload sequence to be verified are input into the hash operation unit inside the encryption module. The hash operation unit performs a hash operation on the input session key and the length-marked payload sequence to be verified to generate the verification digest value.

[0028] The step of encapsulating the verification digest value and the window identifier information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet includes: Write the window identification information into the header field of the signaling packet payload, write the verification digest value into the data field of the signaling packet payload, and generate the payload part of the integrity verification signaling packet; A type flag is added to the header of the integrity verification signaling packet. The type flag is used to indicate that the current data packet is an integrity verification signaling packet. The type flag has a different value than the type flag in the header of the encrypted data packet. The integrity verification signaling packet is generated by assembling the payload portion of the integrity verification signaling packet with the header of the integrity verification signaling packet that has the type mark added.

[0029] The window data reading hardware retrieves complete data packets one by one according to the fixed storage order of the data packets inside the window to be verified. The message parsing hardware locates the offset address of the preset length field in the header of a single data packet, reads the binary data of the payload length, and then locates the payload storage segment of the data packet to read the payload data completely. The hardware temporary storage unit simultaneously retains the two types of data content obtained from a single read: payload data and payload length.

[0030] The sequence splicing hardware retrieves a single set of payload length data from the temporary storage unit, places the binary data of the payload length at the front of the same set of payload data storage segment to complete the construction of a single payload unit with length marking. The sequence splicing hardware strictly follows the predetermined order of the data packets inside the data packet window to be verified, and splices all the constructed payload units with length marking continuously from beginning to end to the dedicated sequence storage area. The complete and continuous data content in this storage area is the payload sequence to be verified with length marking.

[0031] The key interaction hardware reads the complete binary content of the session key, which has been negotiated and fixedly stored in the key storage partition inside the encryption module through a handshake interaction process with the data communication gateway. The data transmission path synchronously and in parallel pushes the complete binary content of the session key and the complete binary content of the payload sequence to be verified with length markers to the dedicated input buffer area of ​​the hash operation unit deployed independently inside the encryption module. After reading the two types of complete data content in the input buffer area, the hash operation unit performs fixed logic data promiscuous compression processing segment by segment. After the entire promiscuous compression processing process is completed, a binary data block of fixed byte length is output. This binary data block is fixedly defined as the verification digest value.

[0032] The payload encapsulation hardware locates the signaling packet. The header field is stored in a fixed storage area within the payload's dedicated storage partition. The complete binary data of the window identifier bound to the corresponding data packet window is written into this header field storage area. The data field is stored in a fixed storage area within the payload's dedicated storage partition. The complete binary data of the verification digest value output by the hash operation unit is written into this data field storage area. After the header field and data field are filled, the data content formed in the storage partition is fixed as the payload part of the integrity verification signaling packet.

[0033] The header editing hardware retrieves the dedicated blank storage block of the integrity verification signaling packet header, and writes a fixed type flag into the preset message type storage field inside the header. This type flag is set with a fixed binary value as the judgment criterion. This binary value and the preset binary value of the type flag field in the encrypted data packet header are set to two different fixed values. After writing, the header of the integrity verification signaling packet with the dedicated type flag is obtained.

[0034] The message assembly hardware retrieves the complete binary data of the payload portion of the integrity verification signaling packet that has been filled, and simultaneously retrieves the complete binary data of the header of the integrity verification signaling packet that has completed the type tag writing operation. The message assembly hardware places the header storage content at the front of the payload storage content according to the transport layer message standard layout rules. The two data segments are continuously merged and stored in the dedicated buffer area of ​​the signaling message. The complete message entity merged in the buffer area is fixedly defined as the integrity verification signaling packet.

[0035] Pt.3. Perform encryption operation on the payload of the data packet in the data packet window to be verified to generate an encrypted data packet, and send the integrity verification signaling packet and the encrypted data packet to the data communication gateway; In this embodiment of the invention, the step of performing an encryption operation on the payload of the data packet in the data packet window to be verified to generate an encrypted data packet, and sending the integrity verification signaling packet and the encrypted data packet to the data communication gateway, includes: The encrypted data packets are sent sequentially to the data communication gateway, and the encrypted data packets that have been sent are recorded during the sending process. After all the encrypted data packets have been sent, the integrity verification signaling packet is sent to the data communication gateway. The integrity verification signaling packet is sent after the encrypted data packets in the timing sequence. After sending the integrity verification signaling packet, listen for the acknowledgment response from the data communication gateway. If no acknowledgment response is received, resend the integrity verification signaling packet.

[0036] The message sending hardware retrieves the encrypted data packets one by one according to the original arrangement order of the data packets inside the data packet window to be verified. The message sending hardware transmits the single encrypted data packet completely to the built-in message receiving buffer of the data communication gateway through a fixed transmission link interface. After the message recording hardware completes the complete transmission operation of each encrypted data packet, it writes the unique message number of the corresponding encrypted data packet into the sending record storage partition. All the message numbers written together constitute the set of records of the sent encrypted data packets.

[0037] The message sending hardware reads the unique message number of all encrypted data packets written in the transmission record storage partition, and performs a complete match verification with the total number of original data packets in the data packet window to be verified. When the two sets of values ​​are completely consistent, it is determined that the transmission process of all encrypted data packets has been completed. The message sending hardware retrieves the complete message data of the integrity verification signaling packet that was previously encapsulated, and pushes the integrity verification signaling packet to the data communication gateway through the same fixed transmission link interface. The execution timing of this push operation is fixed after the push operation of all encrypted data packets is completed.

[0038] The link monitoring hardware continuously reads the message data returned by the data communication gateway from the transmission link interface. The link monitoring hardware identifies the preset response identifier field in the message header. When the field content matches the preset fixed binary value of the acknowledgment response, it is determined that the acknowledgment response has been received normally. The link monitoring hardware sets a fixed message waiting time threshold. If no message matching the acknowledgment response identifier field is identified after the time threshold expires, the message sending hardware retrieves the integrity verification signaling packet again and pushes the complete message data to the data communication gateway repeatedly.

[0039] Pt.4. Distinguish the encrypted data packet and the integrity verification signaling packet from the received incoming data packet, decrypt the encrypted data packet to obtain decrypted payload data, and establish an association between the verification digest value in the integrity verification signaling packet and the decrypted data packet group belonging to the same data stream in the decrypted payload data according to the window identification information in the integrity verification signaling packet. In this embodiment of the invention, distinguishing the encrypted data packet and the integrity verification signaling packet from the received incoming data packet includes: Receive incoming data packets from the communication link connected to the data communication gateway, read the type flag field in the header of the incoming data packets, and obtain the type flag of the incoming data packets; The type marker of the incoming data packet is compared with the preset type marker corresponding to the encrypted data packet. If the type marker of the incoming data packet is consistent with the preset type marker corresponding to the encrypted data packet, the incoming data packet is identified as the encrypted data packet. The type marker of the incoming data packet is compared with the preset type marker corresponding to the integrity verification signaling packet. If the type marker of the incoming data packet is consistent with the preset type marker corresponding to the integrity verification signaling packet, the incoming data packet is identified as the integrity verification signaling packet. The identified encrypted data packet is passed to the decryption process, and the identified integrity verification signaling packet is passed to the verification information extraction process.

[0040] The step of associating the verification digest value in the integrity verification signaling packet with the decrypted data packet group belonging to the same data stream in the decryption payload data based on the window identification information in the integrity verification signaling packet includes: Extract the window identifier information and the verification digest value from the integrity verification signaling packet to obtain the window identifier to be associated and the verification digest value to be associated. Search for each stored decrypted data packet group in the cache area to be verified, read the cache window identifier corresponding to each decrypted data packet group, and compare the window identifier to be associated with each cache window identifier one by one. When the identifier of the window to be associated is consistent with the cache window identifier of a certain decrypted data packet group, the verification digest value to be associated is written into the association field corresponding to the certain decrypted data packet group to establish the correspondence between the verification digest value and the certain decrypted data packet group; After establishing the correspondence, the number of decrypted payload data stored in a certain decrypted data packet group is read to obtain the number of received data packets.

[0041] The link receiving hardware continuously reads the binary message data transmitted in real time from the external communication link of the data communication gateway, completely extracts a single complete message and stores it in the receiving temporary buffer as the incoming data packet. The packet header parsing hardware locates the type mark field storage range at a fixed offset position inside the packet header of the incoming data packet, completely reads the binary data stored in this range and transfers it to the mark temporary storage unit as the type mark of the incoming data packet.

[0042] The tagging hardware retrieves the complete binary data of the preset type tag corresponding to the encrypted data packet from the hardware storage partition, and performs a complete matching operation byte by byte with the type tag of the incoming data packet stored in the tagging temporary storage unit. When the condition that all bytes of the two sets of binary data are completely identical is met, the message classification hardware classifies the incoming data packet stored in the currently received temporary buffer as an encrypted data packet.

[0043] The tagging and comparison hardware retrieves the complete binary data of the preset type tag corresponding to the integrity verification signaling packet pre-fixed in the hardware storage partition, and performs a complete matching operation byte by byte with the type tag of the incoming data packet stored in the tag temporary storage unit. When the condition that all bytes of the two sets of binary data are completely identical is met, the message classification hardware classifies the incoming data packet stored in the currently received temporary buffer as an integrity verification signaling packet.

[0044] The complete encrypted data packet, after being classified and determined by the message splitting hardware, is pushed to the hardware cache partition corresponding to the decryption process through a dedicated hardware data transmission channel, awaiting the execution of the decryption operation. The complete integrity verification signaling packet, after being classified and determined by the message splitting hardware, is pushed to the hardware cache partition corresponding to the verification information extraction process through another independent dedicated hardware data transmission channel, awaiting the execution of the identification and digest data reading operation.

[0045] The signaling parsing hardware positioning integrity verification signaling packet payload header field storage area reads complete window identifier information binary data, and the synchronous positioning integrity verification signaling packet payload data field storage area reads complete verification digest value binary data. The two types of data are stored in independent temporary storage units. The temporary unit storing window identifier information is defined as the window identifier to be associated, and the temporary unit storing verification digest value is defined as the verification digest value to be associated.

[0046] The cache retrieval hardware retrieves each decrypted data packet group sequentially according to the fixed storage arrangement of the data packet groups within the cache area to be verified. After each group is retrieved, the cache window identifier storage field bound in the corresponding storage block is located and the binary content is read completely. The tag comparison hardware compares all the binary bytes of the cache window identifier obtained in a single read with all the binary bytes of the window identifier to be associated in the temporary storage unit bit by bit. The comparison is repeated until all the decrypted data packet groups in the cache area to be verified are completed.

[0047] Once the marking and comparison hardware identifies that the binary byte of the cache window identifier corresponding to a single decrypted data packet group completely matches the binary byte of the window identifier to be associated, the data writing hardware locates the preset associated field storage space within the dedicated storage block of the decrypted data packet group that has been matched, and writes the complete binary data of the verification digest value to be associated in the temporary storage unit into the associated field storage space. After the writing operation is completed, the verification digest value to be associated stored in the associated field forms a fixed binding correspondence with the decrypted data packet group.

[0048] The hardware locates the complete storage block of the decrypted data packet group that has completed the corresponding relationship binding operation. It enumerates each decrypted payload data storage unit that is independently stored within the block. After the enumeration is completed, the total number of storage units is fixedly defined as the number of received data packets. The hardware statistics register stores the number of received data packets as the basis for the preliminary judgment of the subsequent payload splicing operation.

[0049] Pt.5. Concatenate the payload data in the decrypted data packet group to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a comparison digest value, compare the comparison digest value with the verification digest value, and determine whether the decrypted data packet group is complete based on the comparison result.

[0050] In this embodiment of the invention, the step of splicing payload data in the decrypted data packet group to generate a payload sequence to be verified, performing a hash operation on the payload sequence to be verified to generate a comparison digest value, comparing the comparison digest value with the verification digest value, and determining whether the decrypted data packet group is complete based on the comparison result includes: When the comparison result shows that the digest value to be compared is inconsistent with the verification digest value, it is determined that there is a tampered transport layer data packet in the decrypted data packet group, and the decrypted payload data in the decrypted data packet group is discarded; Based on the window identifier information corresponding to the decrypted data packet group, a window retransmission request is generated, and the window retransmission request includes the window identifier information. The window retransmission request is sent to the encryption module. Based on the window identification information in the window retransmission request, the window of the data packet to be verified is located in the window buffer and the data transmission operation corresponding to the window of the data packet to be verified is re-executed.

[0051] The process of caching in the window buffer, forming a window of data packets to be verified, and determining whether the decrypted data packet group is complete based on the comparison result also includes: When the buffer space occupied by the transport layer data packet to be sent in the window buffer reaches the preset storage limit of the window buffer, the window buffer is locked and the writing of newly arrived transport layer data packets to be sent to the window buffer is stopped. After locking the window buffer, the step of extracting the payload data from the data packet window to be verified and splicing it to generate the payload sequence to be verified is performed. When the comparison result is that the comparison digest value and the verification digest value are consistent, the data communication gateway forwards the decrypted payload data in the decrypted data packet group to the target application system in the order of each data packet in the decrypted data packet group, and after the forwarding is completed, returns a window confirmation response to the encryption module, the window confirmation response containing the window identification information; The encryption module receives the window confirmation response, locates the corresponding data packet window to be verified in the window cache based on the window identifier information in the window confirmation response, unlocks the window cache and releases the cache space occupied by the data packet window to be verified.

[0052] The digest comparison hardware performs a byte-by-byte comparison between the complete binary content of the digest value to be compared and the complete binary content of the verification digest value stored internally in the associated field. When the condition that any byte content of the two sets of binary data does not match is met, the integrity judgment hardware marks that there are tampered transport layer data packets in the current decrypted data packet group. The cache clearing hardware locates the storage partition corresponding to all decrypted payload data of the decrypted data packet group, clears all binary data in the partition and releases the hardware storage space occupied by the partition, and completes the operation of discarding the decrypted payload data in the decrypted data packet group.

[0053] The request encapsulates the hardware to retrieve the complete binary data of the window identifier information bound to the decrypted data packet group where a data mismatch occurred. It locates the preset identifier storage field in the exclusive storage area of ​​the window retransmission request message, writes the complete binary data of the window identifier information into the identifier storage field, and defines the complete message entity formed in the storage area as the window retransmission request after the field is filled.

[0054] The message forwarding hardware pushes the encapsulated window retransmission request to the built-in message receiving buffer of the encryption module through an independent hardware transmission channel. The window retrieval hardware reads the window identifier information stored inside the window retransmission request and matches the window identifier bound to each block of data packets to be verified in the window buffer byte by byte. When the binary contents of the two sets of identifiers match completely, the storage block of the corresponding data packet window to be verified is locked. The message sending hardware retrieves all the transport layer data packets to be sent in the locked block and repeats the entire data sending operation process of payload encryption, signaling encapsulation, and message delivery.

[0055] The spatial metering hardware continuously monitors the total number of storage bytes occupied by all transport layer data packets to be sent in the window buffer. The hardware storage partition has a fixed number of bytes pre-fixed as the preset storage limit of the window buffer. When the condition that the total number of storage bytes obtained in real time is completely equal to the preset storage limit is triggered, the buffer locking hardware writes a locking status flag to the window buffer. At the same time, the message writing path cuts off the writing channel of newly arrived transport layer data packets to be sent to the window buffer, blocking the writing of all new data packets.

[0056] The process scheduling hardware reads the lock status marker inside the window buffer to complete the lock status identification. The process scheduling hardware directly calls the load reading hardware to start the operation of retrieving the data packet load data inside the data packet window to be verified. After the load reading hardware completes the data reading, the sequence splicing hardware performs the load splicing operation. The entire hardware processing flow corresponding to the load sequence to be verified is completely run by extracting the load data in the data packet window to be verified and splicing it to generate the load sequence to be verified.

[0057] The digest comparison hardware matches the binary content of the digest value to be compared with the check digest value byte by byte. When the condition that every byte of the two sets of binary data is exactly the same is triggered, the data communication gateway’s built-in message forwarding hardware reads all the decrypted payload data inside the decrypted data packet group and pushes it to the target application system’s dedicated data receiving interface in strict accordance with the original storage order of the data packets inside the decrypted data packet group. After all the decrypted payload data push actions are completed, the response encapsulation hardware reads the window identification information bound to the decrypted data packet group and writes it into the built-in identification field of the window confirmation response message. The complete window confirmation response message is transmitted to the encryption module through the communication link.

[0058] The encryption module's built-in message receiving hardware receives the window acknowledgment response message transmitted through the link. The identifier parsing hardware reads the binary data of the window identifier information stored inside the message. The window retrieval hardware compares the window identifier with the window identifier bound to each data packet window to be verified in the window buffer byte by byte. When the two sets of identifier binary data match completely, the buffer unlocking hardware clears the lock status flag associated with the corresponding data packet window to be verified. The space reclamation hardware reclaims all the buffer storage blocks occupied by the data packet window to be verified segment by segment. After all storage blocks are reclaimed, the window buffer is restored to the state of receiving new transport layer data packets to be sent.

[0059] like Figure 2 The diagram shown is a functional block diagram of a transport layer encrypted data integrity verification system provided in an embodiment of the present invention.

[0060] The transport layer encrypted data integrity verification system 100 described in this invention can be installed in an electronic device. Depending on the functions implemented, the transport layer encrypted data integrity verification system 100 may include a stream window buffer module, a digest group command module, a encrypted packet distribution module, an unpacking and binding module, and a digest verification module. The module described in this invention can also be referred to as a unit, which refers to a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, and are stored in the memory of the electronic device.

[0061] In this embodiment, the functions of each module / unit are as follows: The stream window caching module is used to cache transport layer data packets to be sent that belong to the same data stream in the window buffer area to form a data packet window to be verified. The digest group signaling module is used to extract the payload data in the data packet window to be verified, splice it to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a verification digest value, and encapsulate the verification digest value and the window identification information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet. The encrypted packet delivery module is used to perform encryption operations on the payload of the data packets in the data packet window to be verified to generate encrypted data packets, and send the integrity verification signaling packet and the encrypted data packets to the data communication gateway. The unpacking and binding module is used to distinguish the encrypted data packet and the integrity verification signaling packet from the received incoming data packet, decrypt the encrypted data packet to obtain decrypted payload data, and establish an association between the verification digest value in the integrity verification signaling packet and the decrypted data packet group belonging to the same data stream in the decrypted payload data according to the window identification information in the integrity verification signaling packet. The digest verification module is used to concatenate the payload data in the decrypted data packet group to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a digest value to be compared, compare the digest value to be compared with the verification digest value, and determine whether the decrypted data packet group is complete based on the comparison result.

[0062] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0063] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0064] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0065] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for verifying the integrity of transport layer encrypted data, characterized in that, The method includes: Pt.

1. Buffer the transport layer data packets to be sent that belong to the same data stream in the window buffer area to form a window of data packets to be verified; Pt.

2. Extract the payload data from the data packet window to be verified and concatenate them to generate a payload sequence to be verified. Perform a hash operation on the payload sequence to be verified to generate a verification digest value. Encapsulate the verification digest value and the window identification information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet. Pt.

3. Perform encryption operation on the payload of the data packet in the data packet window to be verified to generate an encrypted data packet, and send the integrity verification signaling packet and the encrypted data packet to the data communication gateway; Pt.

4. Distinguish the encrypted data packet and the integrity verification signaling packet from the received incoming data packet, decrypt the encrypted data packet to obtain decrypted payload data, and establish an association between the verification digest value in the integrity verification signaling packet and the decrypted data packet group belonging to the same data stream in the decrypted payload data according to the window identification information in the integrity verification signaling packet. Pt.

5. Concatenate the payload data in the decrypted data packet group to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a comparison digest value, compare the comparison digest value with the verification digest value, and determine whether the decrypted data packet group is complete based on the comparison result.

2. The method for verifying the integrity of transport layer encrypted data as described in claim 1, characterized in that, The step of caching transport layer data packets belonging to the same data stream into a window buffer to form a window of data packets to be verified includes: Obtain the transport layer data packet to be sent, and read the five-tuple information from the header of the transport layer data packet to be sent. The five-tuple information includes the source address, source port, destination address, destination port, and transport layer protocol type. If the five-tuple information of the transport layer data packet to be sent is consistent with that of a cached data packet, then it is determined that the transport layer data packet to be sent and the cached data packet belong to the same data stream. The transport layer data packets to be sent are written into the window buffer, and the transport layer data packets to be sent are kept in the window buffer in the order of arrival to form the window of data packets to be verified.

3. The method for verifying the integrity of transport layer encrypted data as described in claim 1, characterized in that, The process of extracting payload data from the data packet window to be verified, concatenating it to generate a payload sequence to be verified, and performing a hash operation on the payload sequence to generate a verification digest value includes: The payload data of the data packet is extracted from the data packet window to be verified, and the payload length corresponding to the payload data is read from the packet header to obtain the payload data and the payload length corresponding to the payload data. The load length is appended before the load data, and the load data with the load length is appended sequentially according to the order of the data packets in the data packet window to be verified, to generate a load sequence to be verified with length markers. The session key negotiated between the encryption module and the data communication gateway is obtained. The session key and the length-marked payload sequence to be verified are input into the hash operation unit inside the encryption module. The hash operation unit performs a hash operation on the input session key and the length-marked payload sequence to be verified to generate the verification digest value.

4. The method for verifying the integrity of transport layer encrypted data as described in claim 3, characterized in that, The step of encapsulating the verification digest value and the window identifier information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet includes: Write the window identification information into the header field of the signaling packet payload, write the verification digest value into the data field of the signaling packet payload, and generate the payload part of the integrity verification signaling packet; A type flag is added to the header of the integrity verification signaling packet. The type flag is used to indicate that the current data packet is an integrity verification signaling packet. The type flag has a different value than the type flag in the header of the encrypted data packet. The integrity verification signaling packet is generated by assembling the payload portion of the integrity verification signaling packet with the header of the integrity verification signaling packet that has the type mark added.

5. The method for verifying the integrity of transport layer encrypted data as described in claim 1, characterized in that, The step of performing encryption operations on the payload of the data packets in the data packet window to be verified to generate encrypted data packets, and sending the integrity verification signaling packet and the encrypted data packets to the data communication gateway, includes: The encrypted data packets are sent sequentially to the data communication gateway, and the encrypted data packets that have been sent are recorded during the sending process. After all the encrypted data packets have been sent, the integrity verification signaling packet is sent to the data communication gateway. The integrity verification signaling packet is sent after the encrypted data packets in the timing sequence. After sending the integrity verification signaling packet, listen for the acknowledgment response from the data communication gateway. If no acknowledgment response is received, resend the integrity verification signaling packet.

6. The method for verifying the integrity of transport layer encrypted data as described in claim 1, characterized in that, The step of distinguishing the encrypted data packet and the integrity verification signaling packet from the received incoming data packet includes: Receive incoming data packets from the communication link connected to the data communication gateway, read the type flag field in the header of the incoming data packets, and obtain the type flag of the incoming data packets; The type marker of the incoming data packet is compared with the preset type marker corresponding to the encrypted data packet. If the type marker of the incoming data packet is consistent with the preset type marker corresponding to the encrypted data packet, the incoming data packet is identified as the encrypted data packet. The type marker of the incoming data packet is compared with the preset type marker corresponding to the integrity verification signaling packet. If the type marker of the incoming data packet is consistent with the preset type marker corresponding to the integrity verification signaling packet, the incoming data packet is identified as the integrity verification signaling packet. The identified encrypted data packet is passed to the decryption process, and the identified integrity verification signaling packet is passed to the verification information extraction process.

7. The method for verifying the integrity of transport layer encrypted data as described in claim 1, characterized in that, The step of associating the verification digest value in the integrity verification signaling packet with the decrypted data packet group belonging to the same data stream in the decryption payload data based on the window identification information in the integrity verification signaling packet includes: Extract the window identifier information and the verification digest value from the integrity verification signaling packet to obtain the window identifier to be associated and the verification digest value to be associated. Search for each stored decrypted data packet group in the cache area to be verified, read the cache window identifier corresponding to each decrypted data packet group, and compare the window identifier to be associated with each cache window identifier one by one. When the identifier of the window to be associated is consistent with the cache window identifier of a certain decrypted data packet group, the verification digest value to be associated is written into the association field corresponding to the certain decrypted data packet group to establish the correspondence between the verification digest value and the certain decrypted data packet group; After establishing the correspondence, the number of decrypted payload data stored in a certain decrypted data packet group is read to obtain the number of received data packets.

8. The method for verifying the integrity of transport layer encrypted data as described in claim 1, characterized in that, The steps include: concatenating payload data from the decrypted data packet group to generate a payload sequence to be verified; performing a hash operation on the payload sequence to be verified to generate a comparison digest value; comparing the comparison digest value with the verification digest value; and determining whether the decrypted data packet group is complete based on the comparison result. When the comparison result shows that the digest value to be compared is inconsistent with the verification digest value, it is determined that there is a tampered transport layer data packet in the decrypted data packet group, and the decrypted payload data in the decrypted data packet group is discarded; Based on the window identifier information corresponding to the decrypted data packet group, a window retransmission request is generated, and the window retransmission request includes the window identifier information. The window retransmission request is sent to the encryption module. Based on the window identification information in the window retransmission request, the window of the data packet to be verified is located in the window buffer and the data transmission operation corresponding to the window of the data packet to be verified is re-executed.

9. The method for verifying the integrity of transport layer encrypted data as described in claim 1, characterized in that, The process of caching in the window buffer, forming a window of data packets to be verified, and determining whether the decrypted data packet group is complete based on the comparison result also includes: When the buffer space occupied by the transport layer data packet to be sent in the window buffer reaches the preset storage limit of the window buffer, the window buffer is locked and the writing of newly arrived transport layer data packets to be sent to the window buffer is stopped. After locking the window buffer, the step of extracting the payload data from the data packet window to be verified and splicing it to generate the payload sequence to be verified is performed. When the comparison result is that the comparison digest value and the verification digest value are consistent, the data communication gateway forwards the decrypted payload data in the decrypted data packet group to the target application system in the order of each data packet in the decrypted data packet group, and after the forwarding is completed, returns a window confirmation response to the encryption module, the window confirmation response containing the window identification information; The encryption module receives the window confirmation response, locates the corresponding data packet window to be verified in the window cache based on the window identifier information in the window confirmation response, unlocks the window cache and releases the cache space occupied by the data packet window to be verified.

10. A transport layer encrypted data integrity verification system, characterized in that, The system for implementing the transport layer encrypted data integrity verification method according to claim 1 includes: The stream window buffer module is used to buffer transport layer data packets belonging to the same data stream into the window buffer area to form a window of data packets to be verified. The digest group signaling module is used to extract the payload data in the data packet window to be verified, splice it to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a verification digest value, and encapsulate the verification digest value and the window identification information of the data stream corresponding to the data packet window to be verified into an integrity verification signaling packet. The encrypted packet delivery module is used to perform encryption operations on the payload of the data packets in the data packet window to be verified to generate encrypted data packets, and send the integrity verification signaling packet and the encrypted data packets to the data communication gateway; The unpacking and binding module is used to distinguish the encrypted data packet and the integrity verification signaling packet from the received incoming data packet, decrypt the encrypted data packet to obtain decrypted payload data, and establish an association between the verification digest value in the integrity verification signaling packet and the decrypted data packet group belonging to the same data stream in the decrypted payload data according to the window identification information in the integrity verification signaling packet. The digest verification module is used to concatenate the payload data in the decrypted data packet group to generate a payload sequence to be verified, perform a hash operation on the payload sequence to be verified to generate a digest value to be compared, compare the digest value to be compared with the verification digest value, and determine whether the decrypted data packet group is complete based on the comparison result.