High-stability terminal national secret processing unit equipment
By introducing a secure communication platform, load balancing module and network main site security protection equipment into the terminal national secret processing unit equipment, and using national secret algorithm hard encryption and IPSEC tunnel, the problems of unstable network communication and low data security are solved, and stability and security are improved.
Patent Information
- Application Number
- CN202422360296.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2034-09-26
AI Technical Summary
The existing terminal national secret processing unit equipment has poor network communication stability, low data security, and cannot effectively prevent malicious intrusion when it is connected to multiple devices at the same time.
It adopts a secure communication platform, load balancing module and security protection equipment for distribution main websites, and through hard encryption of the national secret algorithm, IPSEC security tunnels and security barriers are established, combined with network isolation and access control technology to ensure network communication stability and data security.
It realizes the stability and data security of network communication, prevents malicious intrusion, and ensures the high utilization rate of network bandwidth and the security of data transmission.
Smart Images

Figure CN223093785U_ABST
Abstract
Description
Technical Field
[0001] The utility model belongs to the technical field of terminal national cryptography processing unit equipment, and particularly relates to a terminal national cryptography processing unit equipment with high stability. Background Technique
[0002] Existing terminal national cryptography processing unit equipment meets the IPSEC VPN technical specifications of the State Cryptography Administration, conforms to the regulations of relevant industries, and adopts IPSEC VPN based on national cryptography SM1 / 2 / 3 / 4 algorithms to implement two-way authentication and transmission encryption measures with the master station equipment. It also uses a dedicated hard encryption chip approved by the State Cryptography Administration, and the hard encryption chip and the communication chip are integrated in an integrated design. The hard encryption chip adopts a unique data stream encryption and decryption mechanism, and can realize the function of synchronously encrypting high-speed data streams.
[0003] At present, the terminal national cryptography processing unit equipment has the following functions:
[0004] Flexible configuration function: supports flexible configuration functions of multiple protocols, and can communicate with multiple master stations and slave stations at the same time;
[0005] Built-in secure communication software: the built-in secure communication software supports automatic switching of dual-card dual-mode networks, binding authentication of static IP addresses, user names, passwords, SIM card numbers, device serial numbers, and MAC addresses;
[0006] The secure communication software supports multiple functions: supports functions such as software automatic initialization, remote security management, abnormal alarm, automatic restart, status rollback, link detection, intelligent recovery, and device self-check;
[0007] Supports multiple function modes: supports ESP encapsulation, NAT traversal function, transparent working mode, supports both encrypted communication and plain communication modes, and supports interoperability between devices of different manufacturers;
[0008] Fully supports multiple authentications: adopts a dedicated hard encryption chip approved by the State Cryptography Administration, establishes an IPSCE tunnel meeting national cryptography standards, realizes IP layer encryption and two-way authentication of data, supports the KPI authentication system, and supports certificates in x.509 format;
[0009] Self-reliability guarantee: adopts the same EMC and IP protection levels as the secure communication terminal, meets the requirements of the distribution network, and can ensure the reliability of the security equipment itself.
[0010] When the existing terminal national cryptography processing unit devices access multiple devices simultaneously, the overall trend of network communication shows volatility, resulting in poor stability of network communication. Moreover, when the terminal national cryptography processing unit devices transport data through an automated system, there is no relevant data security transmission service, leading to low data security and easy leakage. At the same time, there is no security barrier established between the internal network and the public network of the distribution network master station system, and thus it is impossible to effectively prevent malicious intrusion. Therefore, a terminal national cryptography processing unit device with high stability is needed to solve the above problems. Summary of the Invention
[0011] The purpose of the present invention is to provide a terminal national cryptography processing unit device with high stability to solve the problems mentioned in the above background technology.
[0012] To achieve the above purpose, the present invention provides the following technical solution: A terminal national cryptography processing unit device with high stability includes a secure communication terminal, a secure communication platform, a power distribution terminal, and a user. The user is connected to a terminal device, the terminal device is connected to a network communication module, the network communication module is connected to a backbone router, the backbone router is connected to a secure access switch, the secure access switch is connected to a load balancing module, the load balancing module is connected to the secure communication platform, the secure communication platform is connected to a secure core switch, data between the secure core switches can interact with each other, the secure core switch is connected to a server, the power distribution terminal is connected to a dedicated communication module and a public communication module, the dedicated communication module is connected to a power distribution network master station security protection device, the public communication module is connected to a power distribution network master station security protection device, the power distribution network master station security protection device is connected to a security module and a secure access module, and the security module and the secure access module are connected to a power distribution network master station system.
[0013] By setting the above structure, the secure communication terminal transmits and obtains data through the network communication module and by applying the IPSEC VPN of the secure communication platform to access the server. During this process of transmitting and obtaining data, national cryptography algorithm hard encryption is adopted to ensure the security of communication. Among them, the secure communication platform can perform HA dual-machine warm-up to ensure the stability of network communication and make the network communication tend to be stable. The load balancing module can forward the access traffic to the secure communication platform, so that when multiple terminal devices are accessed, the high utilization rate of network bandwidth can be guaranteed. The power distribution network master station security protection device is established at the boundary of the power supply bureau's power distribution network master station system, can establish an IPSEC security tunnel with the power distribution terminal, and can provide a secure transmission service for the data of the power distribution automation system.
[0014] As a preferred solution, the secure communication platform can ensure the stability of network communication, making the overall trend of network communication tend to be stable.
[0015] As a preferred solution, the backbone router can access the server through the IPSEC VPN of the secure communication platform. The entire process of connecting the backbone router to the server is encrypted using a national secret algorithm, which can ensure the security of communication.
[0016] As a preferred solution, the secure access switch can distribute the traffic from the backbone router to the secure communication platform through the load balancing module, so that when multiple devices access the backbone router, high utilization of the network bandwidth can be guaranteed.
[0017] As a preferred solution, the dedicated communication module can access the security module through the security protection equipment of the distribution network master station, and the public communication module connection can access the security access module through the security protection equipment of the distribution network master station.
[0018] As a preferred solution, the distribution network master station security protection equipment is deployed at the network boundary of the power supply bureau's distribution network master station system, and an IPSEC security tunnel is established between the equipment and the distribution terminal.
[0019] As a preferred solution, a security barrier is established between the internal network of the distribution network master station system and the public network, and by using network isolation and access control technology, the combination of the three can prevent malicious intrusion.
[0020] By setting up distribution network master station security protection equipment, security modules, security access modules and distribution network master station systems, and by using network isolation and access control technologies, a security barrier can be established between the internal network of the distribution network master station system and the public network and malicious access intrusions can be effectively prevented, thereby avoiding malicious intrusions into the distribution network master station system as much as possible.
[0021] Compared with the prior art, the beneficial effects of the utility model are:
[0022] The utility model, by setting up a secure communication platform, a load balancing module, a distribution network master station security protection device and a distribution network master station system, a secure communication terminal transmits and obtains data through a network communication module and applies an IPSEC VPN access server of the secure communication platform. In the process of transmitting and obtaining data, a national secret algorithm hard encryption is adopted to ensure the security of communication, wherein the secure communication platform can perform HA dual-machine preheating to ensure the stability of network communication and make the network communication tend to be stable, the load balancing module can forward the access traffic to the secure communication platform, so that when multiple terminal devices are connected, the high utilization rate of the network bandwidth can be guaranteed, the distribution network master station security protection device is established at the boundary of the distribution network master station system of the power supply bureau, can establish an IPSEC security tunnel with the distribution terminal, and can provide secure transmission services for the distribution network automation system data.
[0023] In this utility model, by setting up a power distribution master station security protection device, a security module, a security access module and a power distribution master station system, and by applying network isolation and access control technologies, a security barrier can be established between the internal network and the public network of the power distribution master station system, and malicious access intrusion can be effectively prevented. Furthermore, the situation where the power distribution master station system is maliciously invaded can be avoided as much as possible. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is a schematic structural diagram of the stable communication module of this utility model;
[0025] Figure 2 It is a schematic structural diagram of the security communication module of this utility model;
[0026] Figure 3 It is a schematic structural diagram of the security communication terminal of this utility model;
[0027] Figure 4 It is a schematic structural diagram of the security communication platform of this utility model.
[0028] In the figure: 1. Security communication terminal; 2. Security communication platform; 3. User; 4. Terminal device; 5. Network communication module; 6. Main router; 7. Security access switch; 8. Load balancing module; 9. Security core switch; 10. Server; 11. Power distribution terminal; 12. Dedicated communication module; 13. Public communication module; 14. Power distribution master station security protection device; 15. Security module; 16. Security access module; 17. Power distribution master station system. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] The following describes this utility model in further detail with reference to the embodiments.
[0030] The following embodiments are used to illustrate this utility model, but cannot be used to limit the protection scope of this utility model. The conditions in the embodiments can be further adjusted according to specific conditions. Any simple improvement of the method of this utility model under the premise of the concept of this utility model belongs to the protection scope required by this utility model.
[0031] Please refer to Figures 1-4, the present utility model provides a high-stability terminal national cryptography processing unit device, including a secure communication terminal 1, a secure communication platform 2, a power distribution terminal 11 and a user 3. The user 3 is connected to a terminal device 4, the terminal device 4 is connected to a network communication module 5, the network communication module 5 is connected to a backbone router 6, the backbone router 6 is connected to a secure access switch 7, the secure access switch 7 is connected to a load balancing module 8, the load balancing module 8 is connected to the secure communication platform 2, the secure communication platform 2 is connected to a secure core switch 9, data between the secure core switches 9 can interact with each other, the secure core switch 9 is connected to a server 10, the power distribution terminal 11 is connected to a dedicated communication module 12 and a public communication module 13, the dedicated communication module 12 is connected to a power distribution main station security protection device 14, the public communication module 13 is connected to a power distribution main station security protection device 14, the power distribution main station security protection device 14 is connected to a security module 15 and a secure access module 16, the security module 15 and the secure access module 16 are connected to a power distribution main station system 17. By setting up the secure communication platform 2, the load balancing module 8, the power distribution main station security protection device 14 and the power distribution main station system 17, the secure communication terminal 1 accesses the server 10 through the network communication module 5 and applies the IPSEC VPN of the secure communication platform 2 to transmit and obtain data. During this process of transmitting and obtaining data, national cryptography algorithm hard encryption is adopted, which can ensure the security of communication. Among them, the secure communication platform 2 can perform HA dual-machine warm-up to ensure the stability of network communication and make the network communication tend to be stable. The load balancing module 8 can forward the access traffic to the secure communication platform 2, so that when multiple terminal devices 4 are connected, the high utilization rate of network bandwidth can be guaranteed. The power distribution main station security protection device 14 is established at the boundary of the power distribution main station system 17 of the power supply bureau, can establish an IPSEC security tunnel with the power distribution terminal 11, and can provide secure transmission services for the data of the distribution automation system.
[0032] The secure communication platform 2 can ensure the stability of network communication, making the overall trend of network communication tend to be stable.
[0033] The backbone router 6 can access the server 10 through the IPSEC VPN of the secure communication platform 2, and the entire process from the backbone router 6 to the connection of the server 10 uses national cryptography algorithm encryption, which can ensure the security of communication.
[0034] The secure access switch 7 can distribute the traffic from the backbone router 6 to the secure communication platform 2 through the load balancing module 8, so that when multiple devices are connected to the backbone router 6, the high utilization rate of network bandwidth can be guaranteed.
[0035] The dedicated communication module 12 can access the security module 15 through the power distribution main station security protection device 14, and the public communication module 13 connection can access the secure access module 16 through the power distribution main station security protection device 14.
[0036] The distribution network master station security protection device 14 is deployed at the network boundary of the power supply bureau's distribution network master station system 17, and an IPSEC security tunnel is established between it and the distribution terminal 11.
[0037] A security barrier is established between the internal network of the distribution network master station system 17 and the public network, and by using network isolation and access control technology, the combination of the three can prevent malicious intrusion. By setting up the distribution network master station security protection equipment 14, the security module 15, the security access module 16 and the distribution network master station system 17, and by using network isolation and access control technology, a security barrier can be established between the internal network of the distribution network master station system 17 and the public network and malicious access intrusion can be effectively prevented, thereby avoiding malicious intrusion into the distribution network master station system 17 as much as possible.
[0038] The working principle and use process of the utility model are as follows: the secure communication terminal 1 transmits and obtains data through the network communication module 5 and the IPSEC VPN access server 10 of the secure communication platform 2. In the process of transmitting and obtaining data, the national secret algorithm hard encryption is adopted to ensure the security of communication. The secure communication platform 2 can perform HA dual-machine preheating to ensure the stability of network communication and make the network communication tend to be stable. The load balancing module 8 can forward the access traffic to the secure communication platform 2, so that when multiple terminal devices 4 are connected, the high utilization rate of the network bandwidth can be guaranteed. The distribution network master station security protection equipment 14 is established at the boundary of the power supply bureau's distribution network master station system 17, and can establish an IPSEC security tunnel with the distribution terminal 11, and can provide secure transmission services for distribution network automation system data.
[0039] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A high-stability terminal national cryptography processing unit device, comprising a secure communication terminal (1), a secure communication platform (2), a power distribution terminal (11), and a user (3), characterized in that: The user (3) is connected to a terminal device (4), the terminal device (4) is connected to a network communication module (5), the network communication module (5) is connected to a backbone router (6), the backbone router (6) is connected to a secure access switch (7), the secure access switch (7) is connected to a load balancing module (8), the load balancing module (8) is connected to a secure communication platform (2), the secure communication platform (2) is connected to a secure core switch (9), data between the secure core switches (9) can interact with each other, the secure core switch (9) is connected to a server (10), the power distribution terminal (11) is connected to a dedicated communication module (12) and a public communication module (13), the dedicated communication module (12) is connected to a power distribution main station security protection device (14), the public communication module (13) is connected to a power distribution main station security protection device (14), the power distribution main station security protection device (14) is connected to a security module (15) and a secure access module (16), and the security module (15) and the secure access module (16) are connected to a power distribution main station system (17).
2. The high-stability terminal national cryptography processing unit device according to claim 1, characterized in that: The secure communication platform (2) can ensure the stability of network communication, making the overall trend of network communication tend to be stable.
3. The high-stability terminal national cryptography processing unit device according to claim 1, characterized in that: The backbone router (6) can access the server (10) through the IPSEC VPN of the secure communication platform (2). The entire process of the connection from the backbone router (6) to the server (10) uses the national cryptography algorithm for encryption, which can ensure the security of communication.
4. A high-stability terminal national cipher processing unit device according to claim 1, characterized in that: The secure access switch (7) can distribute the traffic from the backbone router (6) to the secure communication platform (2) through the load balancing module (8), so that when multiple devices access the backbone router (6), it can ensure a high utilization rate of network bandwidth.
5. A high-stability terminal national cipher processing unit device according to claim 1, characterized in that: The dedicated communication module (12) can access the security module (15) through the power distribution main station security protection device (14), and the public communication module (13) can access the secure access module (16) through the power distribution main station security protection device (14).
6. The high-stability terminal national cryptography processing unit device according to claim 5, characterized in that: The power distribution main station security protection device (14) is deployed at the network boundary of the power supply bureau's power distribution main station system (17), and an IPSEC security tunnel is established with the power distribution terminal (11).
7. The high-stability terminal national cipher processing unit device according to claim 6, characterized in that: A security barrier is established between the internal network of the power distribution main station system (17) and the public network. By applying network isolation and access control technologies, the combination of the three can prevent malicious intrusion.