A dual-link redundant secure network building connection device

CN224804960UActive Publication Date: 2026-09-25LINZHOU TENGKUN CHUANBO INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202522399911.2
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2025-11-11
Publication Date
2026-09-25
Estimated Expiration
2035-11-11

AI Technical Summary

Technical Problem

当前主流网络连接装置多采用单链路设计,该设计在实际应用中存在显著局限:当链路因硬件故障、信号干扰或外部攻击出现中断时,会直接导致数据传输停滞,造成业务中断或关键数据丢失,难以满足高可靠性场景需求

Benefits of technology

[0015](1)本实用新型通过双链路冗余技术,保障网络的稳定性和数据传输的安全性,满足各类对网络可靠性要求极高的应用场景需求。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN224804960U_ABST
    Figure CN224804960U_ABST
Patent Text Reader

Abstract

The utility model discloses a kind of safety network construction connection devices of dual-link redundancy, including dual-link module, intelligent switching module, safety protection module, main controller and external device interface, dual-link module includes main link unit and spare link unit, the signal input end of main link unit and the signal input end of spare link unit are all electrically connected with the signal output end of main controller through data bus, the signal output end of main link unit and the signal output end of spare link unit are all electrically connected with the signal input end of intelligent switching module through data bus, the signal output end of intelligent switching module is electrically connected with the signal input end of the safety protection module through data bus, the signal output end of safety protection module is connected with the signal input end of external device interface through data bus.The utility model guarantees the stability of network and the security of data transmission, satisfies various application scene needs of network reliability requirement extremely high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This utility model relates to the field of network connectivity and communication technology, specifically to a dual-link redundant secure network construction and connection device. Background Technology

[0002] In the field of network connectivity and communication technology, the demands for network reliability and data security in various critical scenarios (such as financial transactions, industrial control, and medical data transmission) are becoming increasingly stringent. Currently, most mainstream network connectivity devices adopt a single-link design, which has significant limitations in practical applications: when the link is interrupted due to hardware failure, signal interference, or external attacks, data transmission will directly stop, causing service interruption or loss of critical data, making it difficult to meet the requirements of high-reliability scenarios.

[0003] Meanwhile, existing network connectivity devices generally have weak security capabilities, with most only possessing basic data filtering functions and lacking real-time encryption protection and proactive intrusion detection mechanisms for transmitted data. This makes data vulnerable to theft and tampering during transmission, and hinders timely identification and response to network attacks, further exacerbating the risks of data leakage and system intrusion. Furthermore, some devices with redundancy rely on manual link switching, resulting in high switching latency and an inability to achieve automatic and rapid recovery after failures. This makes them unsuitable for automated, high-real-time application scenarios. Therefore, it is necessary to design a dual-link redundant secure network construction and connection device. Utility Model Content

[0004] The purpose of this invention is to provide a dual-link redundant secure network construction and connection device to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, this utility model provides the following technical solution: a dual-link redundant security network construction and connection device, comprising a dual-link module, an intelligent switching module, a security protection module, a main controller, and an external device interface;

[0006] The dual-link module includes a main link unit and a backup link unit. The signal input terminals of the main link unit and the backup link unit are electrically connected to the signal output terminal of the main controller through a data bus. The signal output terminals of the main link unit and the backup link unit are electrically connected to the signal input terminal of the intelligent switching module through a data bus.

[0007] The signal output terminal of the intelligent switching module is electrically connected to the signal input terminal of the safety protection module via a data bus.

[0008] The signal output terminal of the safety protection module is connected to the signal input terminal of the external device interface via a data bus, and the signal output terminal of the main controller is electrically connected to the control input terminal of the intelligent switching module via a control bus.

[0009] Preferably, the main link unit includes a main network interface card (NIC) and a main link status detector. The main NIC is electrically connected to the signal input terminal of the main link status detector via a data bus, and the main link status detector is electrically connected to the status input terminal of the main controller via a feedback bus.

[0010] Preferably, the backup link unit includes a backup network card and a backup link status detector. The backup network card is electrically connected to the signal input terminal of the backup link status detector via a data bus, and the status feedback terminal of the backup link status detector is electrically connected to the status input terminal of the main controller via a feedback bus.

[0011] Preferably, the intelligent switching module includes a switching controller and a link selection switch. The switching controller is electrically connected to the control input terminal of the link selection switch via a data bus, and the switching status feedback terminal of the link selection switch is electrically connected to the status input terminal of the main controller via a feedback bus.

[0012] Preferably, the security protection module includes a data encryption unit and an intrusion detection unit. The data encryption unit is electrically connected to the signal input terminal of the intrusion detection unit via a data bus. The data encryption unit is electrically connected to the configuration output terminal of the main controller via a configuration bus. The detection rule configuration terminal of the intrusion detection unit is electrically connected to the configuration output terminal of the main controller via a configuration bus. The abnormal alarm terminal of the intrusion detection unit is electrically connected to the alarm input terminal of the main controller via an alarm bus.

[0013] Preferably, the external device interface includes an RJ45 Ethernet interface and an optical fiber interface, and the signal input terminals of the RJ45 Ethernet interface and the optical fiber interface are electrically connected to the signal output terminal of the security protection module through a data bus.

[0014] Beneficial effects:

[0015] (1) This utility model uses dual-link redundancy technology to ensure network stability and data transmission security, meeting the needs of various application scenarios with extremely high network reliability requirements.

[0016] (2) This utility model sets up a main link unit and a backup link unit. With the main and backup link status detectors, the link status can be fed back to the main controller in real time. When the main link fails, the main controller can quickly trigger the link switching through the intelligent switching module to avoid delays caused by manual intervention, ensure that the network connection is not interrupted, and meet the continuous operation requirements of key scenarios such as finance and industry.

[0017] (3) The security protection module set up in this utility model improves the security of data transmission. The data encryption unit can encrypt the transmitted data in real time to prevent the data from being stolen or tampered with; the intrusion detection unit can actively identify abnormal network behavior and trigger alarms according to the rules configured by the main controller, forming a triple security protection system, which significantly reduces the risk of data leakage and system attack.

[0018] The above description is merely an overview of the technical solutions of the embodiments of this application. In order to better understand the technical means of the embodiments of this application and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of this application more apparent and understandable, specific implementation methods of this application are described below. Attached Figure Description

[0019] Figure 1 This is a schematic diagram of the structure of this utility model;

[0020] Figure 2 This is a block diagram of the main link unit of this utility model;

[0021] Figure 3 This is a block diagram of the backup link unit of this utility model;

[0022] Figure 4 This is a block diagram illustrating the principle of the intelligent switching module of this utility model;

[0023] Figure 5 This is a schematic diagram of the safety protection module of this utility model. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0025] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0026] Please see Figures 1-5This utility model discloses a dual-link redundant security network construction and connection device, including a dual-link module 1, an intelligent switching module 2, a security protection module 3, a main controller 4, and an external device interface 5. The external device interface 5 includes an RJ45 Ethernet interface and an optical fiber interface. The signal input end of the RJ45 Ethernet interface and the signal input end of the optical fiber interface are electrically connected to the signal output end of the security protection module through a data bus.

[0027] The dual-link module 1 includes a main link unit 6 and a backup link unit 7. The signal input terminals of the main link unit 6 and the backup link unit 7 are electrically connected to the signal output terminal of the main controller 4 through a data bus. The signal output terminals of the main link unit 6 and the backup link unit 7 are electrically connected to the signal input terminal of the intelligent switching module 2 through a data bus.

[0028] The signal output terminal of the intelligent switching module 2 is electrically connected to the signal input terminal of the safety protection module 3 via a data bus.

[0029] The signal output terminal of the safety protection module 3 is connected to the signal input terminal of the external device interface 5 via a data bus, and the signal output terminal of the main controller 4 is electrically connected to the control input terminal of the intelligent switching module 2 via a control bus.

[0030] In this invention, the main link unit 6 includes a main network interface card (NIC) 8 and a main link status detector 9. The NIC 8 is electrically connected to the signal input terminal of the main link status detector 9 via a data bus, and the main link status detector 9 is electrically connected to the status input terminal of the main controller 4 via a feedback bus. The backup link unit 7 includes a backup NIC 10 and a backup link status detector 11. The backup NIC 10 is electrically connected to the signal input terminal of the backup link status detector 11 via a data bus, and the status feedback terminal of the backup link status detector 11 is electrically connected to the status input terminal of the main controller 4 via a feedback bus. Under normal operating conditions, the main link continuously and stably transmits data, ensuring smooth network communication. The backup link is not idle; it constantly monitors the working status of the main link in real time. If the main link fails, such as due to physical line damage, network equipment failure causing link interruption, or abnormal situations such as severe packet loss or excessively high latency exceeding normal thresholds, the backup link will respond quickly and automatically take over the data transmission task within a very short time, ensuring uninterrupted network communication.

[0031] In this invention, the intelligent switching module 2 includes a switching controller 12 and a link selection switch 13. The switching controller 12 is electrically connected to the control input terminal of the link selection switch 13 via a data bus, and the switching status feedback terminal of the link selection switch 13 is electrically connected to the status input terminal of the main controller 4 via a feedback bus. If the main link fails, and the intelligent switching module does not receive a heartbeat signal from the main link within several consecutive heartbeat detection cycles, or if the received heartbeat signal shows significant abnormalities, such as a sharp drop in signal strength or incorrect signal content, the intelligent switching module will quickly initiate a switching process to rapidly switch data transmission to the backup link.

[0032] In this invention, the security protection module 3 includes a data encryption unit 14 and an intrusion detection unit 15. The data encryption unit 14 is electrically connected to the signal input terminal of the intrusion detection unit 15 via a data bus. The data encryption unit 14 is also electrically connected to the configuration output terminal of the main controller 4 via a configuration bus. The detection rule configuration terminal of the intrusion detection unit 15 is electrically connected to the configuration output terminal of the main controller 4 via a configuration bus. Furthermore, the abnormal alarm terminal of the intrusion detection unit 15 is electrically connected to the alarm input terminal of the main controller 4 via an alarm bus. For data encryption, an advanced encryption algorithm is used to encrypt the transmitted data. At the data sending end, the data to be transmitted is sent to the encryption module. The encryption module uses the AES algorithm to encrypt the data according to a preset key, converting plaintext into ciphertext. Even if the ciphertext is illegally intercepted during network transmission, attackers cannot decipher the data content due to the lack of the correct key, thus effectively protecting the confidentiality of the data. Intrusion detection systems monitor network traffic in real time and perform in-depth analysis of incoming data packets. When a data packet in the network traffic matches a feature in the attack signature database, the IDS will immediately issue an alert and take corresponding defensive measures, such as blocking the connection of the attack source and restricting abnormal traffic, to promptly resist external attacks and protect network security.

[0033] Working Principle: The main controller coordinates the operation of the dual-link module, intelligent switching module, security protection module, and external device interfaces. The dual-link module includes primary and backup link units, both connected to the main controller and the intelligent switching module. The primary link transmits data, while the backup link uses a status detector to monitor the primary link's status in real time and feeds the data back to the main controller. Based on the feedback, the main controller operates the intelligent switching module via the control bus. When the primary link fails, the main controller instructs the switching controller of the intelligent switching module to drive the link selection switch, quickly switching data transmission to the backup link to ensure uninterrupted network operation. After passing through the intelligent switching module, the data enters the security protection module. The data encryption unit encrypts the data in real time, and the intrusion detection unit monitors for anomalies according to the main controller's configuration rules. If a problem is detected, it notifies the main controller via the alarm bus. Finally, the processed secure data is output through the RJ45 Ethernet interface or fiber optic interface of the external device interface.

[0034] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A dual-link redundant secure network construction and connection device, characterized in that: It includes a dual-link module (1), an intelligent switching module (2), a security protection module (3), a main controller (4), and an external device interface (5); The dual-link module (1) includes a main link unit (6) and a backup link unit (7). The signal input terminals of the main link unit (6) and the backup link unit (7) are electrically connected to the signal output terminal of the main controller (4) through a data bus. The signal output terminals of the main link unit (6) and the backup link unit (7) are electrically connected to the signal input terminal of the intelligent switching module (2) through a data bus. The signal output terminal of the intelligent switching module (2) is electrically connected to the signal input terminal of the safety protection module (3) via a data bus; The signal output terminal of the safety protection module (3) is connected to the signal input terminal of the external device interface (5) via a data bus, and the signal output terminal of the main controller (4) is electrically connected to the control input terminal of the intelligent switching module (2) via a control bus.

2. The dual-link redundant secure network construction and connection device according to claim 1, characterized in that: The main link unit (6) includes a main network card (8) and a main link status detector (9). The main network card (8) is electrically connected to the signal input terminal of the main link status detector (9) through a data bus. The main link status detector (9) is electrically connected to the status input terminal of the main controller (4) through a feedback bus.

3. The dual-link redundant secure network construction and connection device according to claim 1, characterized in that: The backup link unit (7) includes a backup network card (10) and a backup link status detector (11). The backup network card (10) is electrically connected to the signal input terminal of the backup link status detector (11) via a data bus. The status feedback terminal of the backup link status detector (11) is electrically connected to the status input terminal of the main controller (4) via a feedback bus.

4. The dual-link redundant secure network construction and connection device according to claim 1, characterized in that: The intelligent switching module (2) includes a switching controller (12) and a link selection switch (13). The switching controller (12) is electrically connected to the control input terminal of the link selection switch (13) via a data bus. The switching status feedback terminal of the link selection switch (13) is electrically connected to the status input terminal of the main controller (4) via a feedback bus.

5. The dual-link redundant secure network construction and connection device according to claim 1, characterized in that: The security protection module (3) includes a data encryption unit (14) and an intrusion detection unit (15). The data encryption unit (14) is electrically connected to the signal input terminal of the intrusion detection unit (15) via a data bus. The data encryption unit (14) is electrically connected to the configuration output terminal of the main controller (4) via a configuration bus. The detection rule configuration terminal of the intrusion detection unit (15) is electrically connected to the configuration output terminal of the main controller (4) via a configuration bus. The abnormal alarm terminal of the intrusion detection unit (15) is electrically connected to the alarm input terminal of the main controller (4) via an alarm bus.

6. The dual-link redundant secure network construction and connection device according to claim 1, characterized in that: The external device interface (5) includes an RJ45 Ethernet interface and an optical fiber interface. The signal input terminals of the RJ45 Ethernet interface and the optical fiber interface are electrically connected to the signal output terminal of the security protection module through a data bus.