Communication equipment with safe acquisition function
Through the combination of a secure communication platform and switch, the HIP protocol and multi-core architecture are adopted to solve the problems of existing communication devices in terms of mobility and information security, and efficient network management is achieved and the operation and maintenance costs of enterprise networks are reduced.
Patent Information
- Application Number
- CN202422360186.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2034-09-26
AI Technical Summary
The dedicated line connection method based on fixed physical locations of existing communication equipment is difficult to meet the needs of modern enterprises. It has problems such as multi-hosting, mobility support problems, end-to-end service problems and information security. The traditional network host identification and location are not separated, resulting in high network operation and maintenance costs.
It adopts a secure communication platform, a secure communication terminal and a centralized management platform, supports HIP protocol, adopts a multi-core architecture data plane module and control plane module design, combines the switch to achieve network host identification and location separation, provides a graphical management interface and centralized policy management, supports management access such as Web GUI, SSH, serial port Console, etc., and integrates authentication function modules to monitor users' Internet access.
It solves the multi-host and mobility support problems, improves information security and network stability, reduces network operation and maintenance costs, and realizes convenient configuration management and accurate data resource acquisition.
Smart Images

Figure CN223261544U_ABST
Abstract
Description
Technical Field
[0001] The utility model belongs to the technical field of secure communication platforms, and in particular relates to a communication device with secure collection capabilities. Background Art
[0002] The secure communication platform is an enterprise gateway product tailored for customer business. It is divided into a secure communication platform, a secure communication terminal and a centralized management platform. The secure communication platform series of products are products that closely integrate the current technology trends of security and network.
[0003] Existing communication equipment with secure data collection is a high-performance network security product developed for typical campus networks, wide area networks, and enterprise branches. Currently, communication equipment with secure data collection mainly has the following functions:
[0004] Specific encryption and decryption: Supports encryption and decryption of specific messages in an application-selectable manner. It supports encryption and decryption for specific services and specific message data, which can effectively reduce the total amount of encrypted and decrypted data, increase the encryption and decryption rate, and ensure encryption and decryption performance.
[0005] Support for HIP protocol: Support for HIP protocol can solve the security transmission issues of multi-host and mobility. The HIP layer is added between the network layer and the transport layer to separate the location information and address information, solving the problem of normal communication between devices after IP address switching in different network environments;
[0006] Log Report: Provides powerful log recording and reporting functions to meet auditing, query and other needs. It supports log format settings, log classification, retrieval and storage by system, security, management and traffic. It supports the setting and export storage of log servers, can detect interfaces, traffic, sessions and system status, and can also provide report statistics, graphical display and report export;
[0007] HA hot standby: Provides HA functionality and supports AS (Active Standby) mode. In AS mode, the master and slave machines can synchronize information such as rules, objects, and routes. When the master machine malfunctions, various network services are automatically switched to the slave machine, ensuring business continuity and maximizing network reliability and stability.
[0008] Intelligent broadband access: The product supports multiple broadband access methods such as ADSL and Ethernet, supports PPPOE, IP static routing, and supports multiple ISP broadband access. It also has a dynamic and fully automatic load balancing strategy that can play the role of backup, load balancing, and automatic traffic redistribution in the event of a failure.
[0009] Flexible deployment: supports deployment configuration in routing mode, transparent mode, and hybrid mode.
[0010] The existing communication equipment's dedicated line connection method based on fixed physical locations can no longer meet the needs of modern enterprises, and enterprises need to pay more attention to network operation and maintenance, which increases costs. At the same time, the disadvantages of the traditional network host identification and location of communication equipment are constantly emerging. There are problems with multi-host, mobility support, end-to-end service and information security. Therefore, a communication device with secure collection is needed to solve the above problems. Utility Model Content
[0011] The purpose of the present invention is to provide a communication device with secure data collection function to solve the problems raised in the above background technology.
[0012] To achieve the above-mentioned purpose, the present invention provides the following technical solutions: a communication device with secure collection, including secure communication and users, the secure communication including a secure communication platform, a secure communication terminal and a centralized management platform, the secure communication platform is connected to a CPU, the CPU includes a data plane module and a control plane module, the data plane module and the control plane module communicate with each other, the user is connected to a network access module, the network access module is connected to the secure communication platform, the user can access the secure communication platform through the network access module, the user can directly access the secure communication platform, the secure communication platform is connected to a switch, the switch supports RADIUS server, LDAP server, POP server and TACACS server.
[0013] By setting up the above structure, the secure communication platform supports HIP protocol and deployment, supports network host identification and location separation, and can perfectly solve multi-host, mobility support issues, end-to-end service issues and information security issues. In addition, secure communication supports VPN in terms of security, network optimization and management, and also provides a convenient graphical management interface. The interface supports multiple management access methods such as Web GUI, SSH, and serial console. The centralized management platform has centralized policy management, making configuration management more convenient and easy. At the same time, graphical data reports make it easy for network maintenance personnel to understand the overall operation of the enterprise network, thereby reducing network operation and maintenance costs.
[0014] As a preferred solution, the secure communication is a high-performance network security product developed in accordance with the current technical trend of close integration of security and network, targeting typical campus networks, wide area networks, and enterprise branches.
[0015] As a preferred solution, the secure communication adopts a multi-core architecture, and the original control plane module and data plane module design can efficiently parallelize the scheduling algorithm and memory management mechanism, which can improve the performance of traffic forwarding messages.
[0016] As a preferred solution, the CPU is divided into a data plane module and a control plane module according to its characteristics, abbreviated as DP and CP.
[0017] As an optimal solution, in a multi-core system, some CPUs are dedicated to control plane modules, and most CPUs are dedicated to data plane modules. This can avoid the phenomenon of device forwarding performance degradation or inability to respond to management operations due to system scheduling.
[0018] As a preferred solution, the data plane module mainly handles forwarding work, can parse data packets, and process them by corresponding modules according to the level. In addition, it can save resources consumed by restarting and parsing data packets between different modules and reduce network delays.
[0019] As a preferred solution, the switch can detect the user's Internet access status and support external authentication servers such as RADIUS server, LDAP server, POP server and TACACS server.
[0020] By setting up secure communications and switches, secure communications can implement authentication functions for users through the built-in authentication function module. With the mutual cooperation of secure communication authentication function and switches, users' Internet access status can be monitored, making it easier for users to accurately obtain corresponding data resources according to corresponding permissions, while also improving product security.
[0021] Compared with the prior art, the beneficial effects of the present invention are:
[0022] The utility model sets up a secure communication platform, a secure communication terminal and a centralized management platform. The secure communication platform supports HIP protocol and deployment, supports the separation of network host identification and location, and can perfectly solve the problems of multi-host, mobility support, end-to-end service and information security. In addition, secure communication supports VPN in terms of security, network optimization and management, and also provides a convenient graphical management interface. The interface supports multiple management access methods such as Web GUI, SSH, serial console, etc., and the centralized management platform has centralized policy management, which makes configuration management more convenient and easy. At the same time, the graphical data report makes it easy for network maintenance personnel to understand the overall operation of the enterprise network, thereby reducing the operation and maintenance costs of the network.
[0023] The utility model sets up secure communication and a switch. The secure communication can realize the authentication function for the user through the built-in authentication function module. With the mutual cooperation of the secure communication authentication function and the switch, the user's Internet access situation can be monitored, which is convenient for the user to accurately obtain the corresponding data resources according to the corresponding permissions, and at the same time, the security of the product can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 This is a schematic diagram of the structure of the security communication module of the utility model;
[0025] Figure 2 This is a schematic diagram of the structure of the secure communication platform of the utility model;
[0026] Figure 3 This is a schematic diagram of the structure of the secure communication terminal of the present utility model;
[0027] Figure 4 This is a structural diagram of the networking communication module of the utility model.
[0028] In the figure: 1. Secure communication; 2. Secure communication platform; 3. Secure communication terminal; 4. Centralized management platform; 5. CPU; 6. Data plane module; 7. Control plane module; 8. User; 9. Network access module; 10. Switch; 11. RADIUS server; 12. LDAP server; 13. POP3 server; 14. TACACS server. DETAILED DESCRIPTION
[0029] The present invention will be further described below with reference to the embodiments.
[0030] The following examples are intended to illustrate the present invention and are not intended to limit the scope of protection of the present invention. The conditions in the examples may be further adjusted according to specific conditions. Simple improvements to the method of the present invention based on the concept of the present invention fall within the scope of protection claimed by the present invention.
[0031] See also Figure 1-4The utility model provides a communication device with security collection, including a security communication 1 and a user 8. The security communication 1 includes a security communication platform 2, a security communication terminal 3 and a centralized management platform 4. The security communication platform 2 is connected to a CPU 5. The CPU 5 includes a data plane module 6 and a control plane module 7. The data plane module 6 and the control plane module 7 communicate with each other. The user 8 is connected to a network access module 9. The network access module 9 is connected to the security communication platform 2. The user 8 can access the security communication platform 2 through the network access module 9. The user 8 can directly access the security communication platform 2. The security communication platform 2 is connected to Switch 10, switch 10 supports RADIUS server 11, LDAP server 12, POP3 server 13 and TACACS server 14. By setting up a secure communication platform 2, a secure communication terminal 3 and a centralized management platform 4, the secure communication platform 2 supports HIP protocol and deployment, supports network host identification and location separation, and can perfectly solve multi-host, mobility support problems, end-to-end service problems and information security problems. In addition, secure communication 1 supports VPN in terms of security, network optimization and management, and also provides a convenient graphical management interface. The interface supports multiple management access methods such as Web GUI, SSH, serial port console, etc., and the centralized management platform 4 has centralized policy management, making configuration management more convenient and easy. At the same time, graphical data reports make it easy for network maintenance personnel to understand the overall operation of the enterprise network, thereby reducing the operation and maintenance costs of the network.
[0032] Existing communication equipment with secure data collection has the following characteristics:
[0033] National support for the national secret IPSEC protocol specification: fully support domestic algorithms to ensure independent control and compliance requirements. In tunnel communications such as IPSEC VPN and security proxies, the use of built-in hardware encryption chip encryption can improve encryption and decryption efficiency, and while taking into account efficiency and security, it can also reduce security construction costs;
[0034] Support application encryption transmission: It can encrypt and decrypt specific application data in the transmitted message, and can also cover the network environment topology of Layer 2, Layer 3 and Layer 4. It can selectively encrypt and decrypt transmission according to specific services and specific application keywords;
[0035] Support for HIP protocol and deployment: Support for HIP protocol can meet the current needs of mobile Internet, smart work, and smart manufacturing. Under WiFi or 3G, 4G and 5G mobile networks, it can solve the information transmission stability and security issues caused by address changes caused by the movement of device terminals;
[0036] Support NAT traversal function: NAT technology is the mainstream technology currently used in domestic enterprises for shared Internet access, residential and intelligent building broadband access, and metropolitan area network broadband access. The entire series of IPSEC VPN products support NAT function and have excellent network adaptability;
[0037] Integrated powerful firewall function: Secure communication integrates powerful firewall function, which can provide high-level boundary security protection for user's VPN network;
[0038] Integrated powerful network routing function: Provides powerful network routing function for user networking, enabling it to be configured and used as an independent network device. The main functions are as follows: support static routing, dynamic routing protocols, policy routing, ISP routing, VLAN division, DNS proxy function and DHCP server.
[0039] Secure Communication 1 is a high-performance network security product developed for typical campus networks, wide area networks, and enterprise branches, in line with the current technological trend of close integration of security and networks.
[0040] Secure communication 1 adopts a multi-core architecture, and the original control plane module 7 and data plane module 6 are designed to have efficient parallel scheduling algorithms and memory management mechanisms, which can improve the performance of traffic forwarding messages.
[0041] The CPU 5 is divided into a data plane module 6 and a control plane module 7 according to its characteristics, hereinafter referred to as DP and CP.
[0042] In a multi-core system, a portion of CPUs 5 are dedicated to the control plane module 7, and most CPUs 5 are dedicated to the data plane module 6, which can avoid the phenomenon of device forwarding performance degradation or inability to respond to management operations due to system scheduling.
[0043] The data plane module 6 mainly handles forwarding work, can parse data packets, and process them by corresponding modules according to the level. In addition, it can save resources consumed by restarting the parsing of data packets between different modules and reduce network delay.
[0044] The switch 10 can detect the Internet access status of the user 8, and supports the external authentication servers of the RADIUS server 11, LDAP server 12, POP3 server 13 and TACACS server 14. By setting up the secure communication 1 and the switch 10, the secure communication 1 can realize the authentication function for the user 8 through the built-in authentication function module. With the mutual cooperation of the secure communication 1 authentication function and the switch 10, the Internet access status of the user 8 can be monitored, so that the user 8 can accurately obtain the corresponding data resources according to the corresponding permissions, and the security of the product can also be improved.
[0045] The working principle and usage process of the present invention: The secure communication platform 2 supports HIP protocol and deployment, supports network host identification and location separation, and can perfectly solve multi-host, mobility support problems, end-to-end service problems and information security problems. In addition, the secure communication 1 supports VPN in terms of security, network optimization and management, and also provides a convenient graphical management interface. The interface supports multiple management access methods such as Web GUI, SSH, serial port console, etc., and the centralized management platform 4 has centralized policy management, making configuration management more convenient and easy. At the same time, the graphical data report makes it easy for network maintenance personnel to understand the overall operation of the enterprise network, which can reduce the operation and maintenance costs of the network.
[0046] Although the embodiments of the present invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations may be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A communication device with secure data collection, comprising a secure communication (1) and a user (8), characterized in that: The secure communication (1) includes a secure communication platform (2), a secure communication terminal (3) and a centralized management platform (4); the secure communication platform (2) is connected to a CPU (5); the CPU (5) includes a data plane module (6) and a control plane module (7); the data plane module (6) and the control plane module (7) communicate with each other; the user (8) is connected to a network access module (9); the network access module (9) is connected to the secure communication platform (2); the user (8) can access the secure communication platform (2) through the network access module (9); the user (8) can directly access the secure communication platform (2); the secure communication platform (2) is connected to a switch (10); the switch (10) supports a RADIUS server (11), an LDAP server (12), a POP3 server (13) and a TACACS server (14).
2. The communication device with secure data collection according to claim 1, characterized in that: The secure communication (1) is a high-performance network security product developed for typical campus networks, wide area networks, and enterprise branches in accordance with the current technical trend of close integration of security and network.
3. The communication device with secure data collection according to claim 2, characterized in that: The secure communication (1) adopts a multi-core architecture, and the original control plane module (7) and data plane module (6) are designed to have efficient parallel scheduling algorithms and memory management mechanisms, thereby improving the performance of traffic forwarding messages.
4. The communication device with secure data collection according to claim 1, characterized in that: The CPU (5) is divided into a data plane module (6) and a control plane module (7) according to its characteristics, referred to as DP and CP for short.
5. The communication device with secure data collection according to claim 4, characterized in that: In a multi-core system, a portion of the CPUs (5) are dedicated to the control plane module (7), and the majority of the CPUs (5) are dedicated to the data plane module (6), thereby avoiding the phenomenon that the device forwarding performance is degraded or the device cannot respond to management operations due to system scheduling.
6. The communication device with secure data collection according to claim 5, characterized in that: The data plane module (6) mainly handles forwarding work, can parse data packets, and process them by corresponding modules according to the level. In addition, it can save resources consumed by restarting and parsing data packets between different modules and reduce network delay.
7. The communication device with secure data collection according to claim 1, characterized in that: The switch (10) is capable of detecting the Internet access status of a user (8) and supports external authentication servers such as a RADIUS server (11), an LDAP server (12), a POP3 server (13) and a TACACS server (14).