Road traffic management information transceiving and safety protection equipment in public network environment
By integrating national secret algorithm security chips and edge computing cards into VPN security gateway devices, two-way identity authentication of traffic control information and monitoring of information transmission and reception cycles are achieved, solving the security risk issues of VPN security gateway devices in public network environments and improving the active prevention and control capabilities of the equipment.
Patent Information
- Application Number
- CN202422090468.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-27
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2034-08-27
AI Technical Summary
In the existing technology, VPN security gateway devices are at risk of identity theft or misuse in public network environments, and lack the terminal security detection capability for the entire information transmission and reception cycle, resulting in delayed security measures.
A security chip based on the national secret algorithm is used for two-way identity authentication, and the information sending and receiving cycle is monitored through the edge computing card. The integrated edge computing card realizes abnormal warning and active prevention and control.
It improves the two-way identity authentication security of the equipment, reduces the risk of information leakage, improves the proactive prevention capability of the information sending and receiving cycle, and reduces the risk of viruses infecting the internal business systems of traffic management.
Smart Images

Figure CN223451988U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model relates to the field of safety protection equipment, concretely relates to a kind of receiving and transmitting of road traffic management information under public network environment and safety protection equipment. BACKGROUND
[0002] At present, gradually construct full-coverage full-networking road monitoring system, traffic management business handling and service system, gather the data resources of traffic management related motor vehicle, driving license, traffic violation, traffic accident and vehicle trajectory etc..Due to the characteristics of scale, wide range, high value of information system and collected data, traffic management department needs and external unit to carry out information receiving and transmitting in public network environment.
[0003] In prior art, usually install VPN security gateway equipment in the network communication node of traffic management department and external unit, to ensure the security of information receiving and transmitting.The existing VPN security gateway equipment usually adopts "soft encryption" to carry out identity authentication, however, this "soft encryption" encryption method is stored in equipment, and there is the risk of being stolen or misused, and once relevant communication configuration information is leaked, illegal person can directly replace the original VPN security device of communication node using equipment without security detection or without authorized authentication, to cause information security risk. UTILITY MODEL CONTENT
[0004] Therefore, the technical problem to be solved by the utility model is to overcome the high security risk in prior art, to provide a kind of receiving and transmitting of road traffic management information under public network environment and safety protection equipment.
[0005] The utility model provides a kind of receiving and transmitting of road traffic management information under public network environment and safety protection equipment, including host case, the host case is provided with hard disk installation area, security chip installation area, edge computing card installation area, wherein,
[0006] The hard disk installation area is used to install solid state disk;
[0007] The security chip installation area is used to install security chip, and the security chip carries out two-way identity authentication to the communication node of traffic management department and other communication nodes through national secret algorithm;
[0008] The edge computing card installation area is used to install edge computing card, and the edge computing card is used to carry out safety monitoring to the information receiving and transmitting period of the communication node of traffic management department and other communication nodes.
[0009] The utility model discloses a based on the security chip of national secret algorithm is added, realizes the " hard encryption " of equipment identity information, promotes the security of equipment two -way identity authentication, through increasing edge computing card, realizes the safety monitoring of the communication node of the traffic control department and other communication node information receiving cycle, has improved active prevention ability greatly.
[0010] In an alternative embodiment, the security chip supports national secret SM2, national secret SM3 and national secret SM4 algorithm.
[0011] The utility model discloses a based on the security chip of national secret algorithm is integrated, and national secret algorithm is used to the encryption and decryption of VPN security gateway communication parameter, solves the problem of VPN security gateway port information exposure to the outside, reduces the risk of being sniffed and attacked by lawbreaker or tool.
[0012] In an alternative embodiment, the edge computing card is provided with a compatible Raspberry Pi 40PIN Header interface.
[0013] The utility model discloses a based on the security chip of national secret algorithm is integrated, and national secret algorithm is used to the encryption and decryption of VPN security gateway communication parameter, solves the problem of VPN security gateway port information exposure to the outside, reduces the risk of being sniffed and attacked by lawbreaker or tool.
[0014] In an alternative embodiment, the host box is further provided with a network card control port for realizing network connection of the device.
[0015] The utility model discloses a based on the security chip of national secret algorithm is integrated, and national secret algorithm is used to the encryption and decryption of VPN security gateway communication parameter, solves the problem of VPN security gateway port information exposure to the outside, reduces the risk of being sniffed and attacked by lawbreaker or tool.
[0016] In an alternative embodiment, the host box is further provided with a VGA interface and a USB interface for realizing connection of the device and display device.
[0017] The utility model discloses a based on the security chip of national secret algorithm is integrated, and national secret algorithm is used to the encryption and decryption of VPN security gateway communication parameter, solves the problem of VPN security gateway port information exposure to the outside, reduces the risk of being sniffed and attacked by lawbreaker or tool.
[0018] In an alternative embodiment, the USB interface includes two USB2.0 interfaces and three USB3.0 interfaces.
[0019] The utility model discloses a based on the security chip of national secret algorithm is integrated, and national secret algorithm is used to the encryption and decryption of VPN security gateway communication parameter, solves the problem of VPN security gateway port information exposure to the outside, reduces the risk of being sniffed and attacked by lawbreaker or tool.
[0020] In an alternative embodiment, the host box is further provided with an indicator light for displaying the running state of the device.
[0021] The utility model discloses a setting indicating lamp, timely feedback state, auxiliary staff carries out fault diagnosis, improves user experience feeling. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to more clearly illustrate the specific embodiment of the utility model or the technical scheme in prior art, the following will be briefly introduced the drawing needed to be used in the specific embodiment or prior art description, obviously, the drawing in the following description is some implementation of the utility model, for ordinary skilled person in the art, can know the detailed technical scheme of the embodiment according to these drawings without paying creative labor.
[0023] Figure 1 It is the front view of the receiving and dispatching and security protection equipment of road traffic management information under the public network environment provided by the utility model embodiment;
[0024] Figure 2 It is the structural schematic diagram of the security chip provided by the utility model embodiment;
[0025] Figure 3 It is the structural schematic diagram of the edge computing card provided by the utility model embodiment;
[0026] Figure 4 It is the back view of the receiving and dispatching and security protection equipment of road traffic management information under the public network environment provided by the utility model embodiment;
[0027] EXPLANATION OF REFERENCE NUMERALS
[0028] 1, mainframe box;11, hard disk installation area;12, security chip installation area;13, edge computing card installation area;14, network card control port;15, VGA interface;16, USB interface;17, indicating lamp. DETAILED DESCRIPTION
[0029] The technical scheme of the utility model will be described clearly and completely in the following by combining with the drawings, obviously, the described embodiment is a part of the embodiment of the utility model, not all the embodiment. Based on the embodiment in the utility model, all other embodiments obtained by ordinary skilled person in the art without making creative labor belong to the scope of protection of the utility model.
[0030] In the description of the utility model, it is necessary to explain that the terms "first", "second", "third" are only used for the purpose of description, and can not be understood as indicating or implying relative importance.
[0031] In the related art, the mode of adding VPN security gateway equipment in the traffic management department and external unit network communication node mainly has the following problems:
[0032] 1. The device without security detection or unauthorized authentication is easy to access the communication node. The VPN security gateway device installed in the communication node of the traffic management department and external units establishes the information receiving and transmitting link by setting the identity information of the opposite device on the device respectively, and performs bidirectional identity authentication. However, the related device identity information is stored in the device by the method of "soft encryption", and there is a risk of being stolen or stolen. In addition, once the related communication configuration information is leaked, the illegal person can directly replace the original VPN security device of the communication node with the device without security detection or unauthorized authentication, and cause the related information security risk.
[0033] 2. The existing VPN security gateway device only authenticates the identity of the communication device, lacks the terminal security detection capability of the whole cycle of information receiving and transmitting, and causes passive security disposal. At present, the VPN security gateway device installed in the communication node of the traffic management department and the communication node of external units is in a "completely trusted" state after the communication link is established, and if the illegal person implements abnormal behaviors such as unauthorized access and virus attack after the communication link is established, only other security devices (such as firewalls) on the communication node can be used for identification, prevention and disposal, which has great hysteresis.
[0034] The utility model embodiment provides a kind of receiving and transmitting and security protection equipment of road traffic management information under public network environment, as shown in Figure 1 The device includes host case 1, and the host case 1 is provided with hard disk installation area 11, security chip installation area 12 and edge computing card installation area 13.
[0035] The hard disk installation area 11 is used to install solid state disk, and specifically, the specific configuration of the host case 1 is as follows:
[0036] (1) standard 1U rack type device is adopted, and is provided with mounting guide rail, so that the device can be installed in standard 1U rack space, and the stability and portability of installation are improved.
[0037] (2) at least one Intel Xeon Scalable processor is configured, and the CPU is not less than Silver 4208, the basic frequency of the processor is 2.10GHz, 11MB cache, 8 cores, provides powerful computing performance, and supports processing complex computing tasks and high concurrency application scenarios.
[0038] (3) the maximum support 8DIMM slot is configured for memory, the memory type is DDR4, the running frequency supports 2933MHz, supports RDIMM memory, and the maximum memory capacity can reach 1TB in theory, and the basic memory configuration is not less than 32GB, so that there is enough resource to process a large amount of data and multitask operation.
[0039] (4) Support installation of 2 2.5-inch SSD hard drives and one PCI-EM interface SSD hard drive, ensuring high-speed storage and flexible expansion. The standard configuration includes at least one 250GB SSD hard drive to meet basic data storage needs.
[0040] (5) Scalability: by default, provide one half-height PCI-E 3.0x8 expansion slot, reserve space for future possible hardware upgrades.
[0041] (6) Network card controller: integrate 2 Intel x772 Gigabit GE (Gigabit Ethernet) network interfaces to provide stable network connection foundation. In addition, optional external Gigabit and 10 Gigabit network cards can be selected, with a minimum of 2 Gigabit Ethernet ports to ensure basic network access capabilities.
[0042] (7) Power supply: standard 600W gold medal server single power supply, high efficiency and energy saving, while providing optional 450W 1+1 gold medal hot plug redundant power supply, enhancing reliability and maintenance convenience, supporting 240V high-voltage direct current power supply, adapting to different power supply environments.
[0043] (8) Support display integrated VGA interface, USB interface.
[0044] (9) Remote management function: standard remote management function, which can realize complete remote control of the server regardless of the operating system, functions include: virtual power can be remotely started, restarted, and shut down; update Firmware; support remote fault phenomenon reproduction; virtual console can remotely monitor the graphical interface, remotely start installation from local floppy disk and CD or its image, operate Windows, Linux, etc. (virtual floppy drive, virtual CD drive, virtual directory, and virtual U disk). Through the integration of the intelligent platform management interface iBMC, realize remote iKVM.
[0045] (10) Gateway underlying hardware devices can support operating systems: Windows Server 2012R2 and later versions, RedHat*Enterprise Advanced Server 7.5 and later versions, openEuler V2.0SP5 and later versions.
[0046] The security chip installation area 12 is used to install a security chip, and the structure of the installed chip is as shown in Figure 2 The security chip performs bidirectional identity authentication on the communication nodes of the traffic management department and other communication nodes through a national secret algorithm.
[0047] Specifically, the specific configuration of the security chip is as follows:
[0048] (1) CPU: use enhanced 51-core
[0049] (2) Main frequency: up to 32MHz
[0050] (3) Communication: communicate through I2C bus
[0051] (4) Storage: integrated 32K secure EEROM
[0052] (5) RAM: 8K general-purpose RAM + 3K algorithm-specific RAM
[0053] (6) International algorithm: support DES / 3DES / RSA / ECC / SHA-1 / SHA-256
[0054] (7) National secret algorithm: support SM2 / SM3 / SM4
[0055] By integrating a security chip based on a national secret algorithm, and using the national secret algorithm to encrypt and decrypt the communication parameters of the VPN security gateway, the problem of external exposure of the port information of the VPN security gateway is solved, and the risk of being sniffed and attacked by illegal persons or tools is reduced.
[0056] The edge computing card installation area 13 is used for installing an edge computing card, the structure of the edge computing card is as shown in Figure 3 The edge computing card is used for safe monitoring of the communication node and other communication node information receiving and transmitting period of the traffic management department.
[0057] Specifically, the specific configuration of the edge computing card is as follows:
[0058] (1) Processor: equipped with RZ / G2L, integrated with 2 Cortex-A55 cores with a running frequency of 1.2GHz, and 1 Cortex-M33H core with a running frequency of 200MHz.
[0059] (2) Memory: 1GB DDR4
[0060] (3) Storage: 8GB eMMC
[0061] (4) Power supply: PMIC model RAA215300
[0062] (5) Power supply: USB Type-C power supply interface
[0063] (6) Wireless connection: WIFI / BT 2.4GHz WIFI+BT4.2 module
[0064] (7) Wired connection: Ethernet 2-way gigabit Ethernet interface
[0065] (8) USB interface: 1-way USB 2.0 OTG Type-C interface, 2-way USB HOST Type-A interface
[0066] (9) Multimedia support: 1 HDMI display interface, 1 LVDS display interface, 1 MIPI CSI camera interface, 1 audio input / output interface.
[0067] (10) Debugging and control: 2 UART debugging interfaces (Cortex-A55, Cortex-M33), and ON / OFF, RESET, USER buttons.
[0068] (11) Status indicator lights: Power and system status indicator lights.
[0069] (12) Expansion interface: 1 compatible Raspberry 40PIN Header, supporting multiple interfaces such as GPIO, I2C, UART, SPI, and CAN.
[0070] By integrating the edge computing card, the monitoring of the information transmission cycle and the abnormal early warning are realized. Once an abnormality is found, the communication link between the two parties can be directly cut off, greatly improving the active security and prevention and control capability of the VPN security gateway device, and reducing the risk of virus infection of internal business systems.
[0071] In an embodiment, as shown in Figure 4 The host box 1 is also provided with a network card control port 14 for accessing a local area network or the Internet to realize network connection of the device and effectively ensure network transmission of data packets.
[0072] In an embodiment, as shown in Figure 4 The host box 1 is also provided with a VGA interface 15 and a USB interface 16 for realizing connection between the device and a display device.
[0073] Specifically, the VGA interface 15 can be used to connect a display device such as a display or a projector, the VGA interface has wide compatibility, is simple to use, and is easy to install. The USB interface 16 can be used to connect peripheral devices such as a printer and a storage device, the USB interface has multifunctionality and supports efficient transmission.
[0074] Specifically, the USB interface 16 includes 2 USB2.0 interfaces and 3 USB3.0 interfaces, the USB2.0 interface improves wide compatibility, meets basic data transmission requirements, and the USB3.0 interface realizes efficient transmission of data.
[0075] In an embodiment, as shown in Figure 1As shown, the host box 1 is further provided with an indicator light 17, which is used to display the running state of the device.
[0076] The utility model provides a kind of receiving and transmitting and security protection equipment of road traffic control information under public network environment, by increasing the security chip based on national secret algorithm, the security of equipment two-way identity authentication is improved, by increasing edge computing card, the safety monitoring of communication node and other communication node information receiving and transmitting cycle of traffic control department is realized, and active prevention ability is greatly improved.
[0077] Obviously, the above embodiments are only examples for clearly illustrating, and not limit the embodiments. For ordinary skilled in the art, other different forms of changes or variations can be made on the basis of the above description. Here, all embodiments need not and cannot be exhausted. The obvious changes or variations derived therefrom are still within the protection scope of the utility model creation.
Claims
1. A road traffic information receiving and sending and safety protection device in a public network environment, characterized by: It includes a main chassis, which is provided with a hard disk installation area, a security chip installation area, and an edge computing card installation area, wherein: The hard disk installation area is used to install a solid state hard disk; The security chip installation area is used to install a security chip, which performs two-way identity authentication on the communication node of the traffic management department and other communication nodes through a national secret algorithm; The edge computing card installation area is used to install edge computing cards, and the edge computing cards are used to perform security monitoring of the information sending and receiving cycles of the communication nodes of the traffic management department and other communication nodes.
2. The device according to claim 1, characterized in that The security chip supports the national encryption SM2, national encryption SM3 and national encryption SM4 algorithms.
3. The device according to claim 1, characterized in that The edge computing card is provided with a 40-pin header interface compatible with the Raspberry Pi.
4. The device according to claim 1, characterized in that The host box is also provided with a network card control port, which is used to realize the network connection of the device.
5. The device according to claim 1, characterized in that The host box is also provided with a VGA interface and a USB interface, and the VGA interface and the USB interface are used to realize the connection between the device and the display device.
6. The device according to claim 5, characterized in that The USB interface includes two USB 2.0 interfaces and three USB 3.0 interfaces.
7. The device according to claim 1, characterized in that The main chassis is also provided with an indicator light, which is used to display the operating status of the device.