Service transparent secure network channel establishment mechanism and system

By using the terminal-invisible security module and the business-invisible security gateway for identity authentication and data encryption encapsulation, the problems of terminal modification and network topology modification in existing technologies are solved, realizing seamless access and fine-grained security protection, and improving the security protection capabilities of the terminal.

WO2026051465A1PCT designated stage Publication Date: 2026-03-12XINLIAN TECH (NANJING) CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

The construction of existing network security channels requires modifications to terminals and network topology, which cannot achieve fine-grained, multi-service security protection, and traditional security modules cannot support application layer communication protocols for specific services.

Method used

Design a business-invisible network security channel construction mechanism. Through a terminal-invisible security module and a business-invisible security gateway, a secure channel is established using authentication data frames with the same Ethernet header and IP address, and the data is encrypted and encapsulated to achieve seamless access.

Benefits of technology

While reducing the number of terminal modification steps, it enhances security protection capabilities, enables on-demand protection, and does not affect the operating logic and configuration of intermediate network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025099198_12032026_PF_FP_ABST
    Figure CN2025099198_12032026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a service transparent secure network channel establishment mechanism. On the basis of a terminal transparent security module and a service transparent security gateway, and on the basis of a service request data frame sent by a terminal, a secure channel is established by designing an identity authentication data frame that has the same Ethernet header and the same source IP and destination IP. By means of a secure service data communication mechanism, it is ensured that service data with different security requirements can be protected on demand. Transparent access of the terminal to a service system is realized by means of an encrypted and encapsulated service request data frame that has the same Ethernet header and the same source IP and destination IP and undergoes encryption and encapsulation processing. In a corresponding design system, by means of the modular decomposition design of the terminal transparent security module and the service transparent security gateway, functions such as a secure communication protocol, service communication packet parsing, and secure data packet processing and forwarding are specifically implemented, thereby implementing transparent service access and improving the security protection capability of applications.
Need to check novelty before this filing date? Find Prior Art

Description

A service-unaware network security channel construction mechanism and system TECHNICAL FIELD

[0001] The present application relates to a service-unaware network security channel construction mechanism and system, belonging to the technical field of network service access control. BACKGROUND

[0002] To realize the data security transmission of service terminals, the current mainstream means is to construct a network security channel based on VPN between the terminal and the service system, for realizing the security protection of service terminals and systems, but this protection method needs to modify the terminal, system and network topology, for example, adding a security module to the terminal or performing identity authentication according to a specific security protocol format, and only after the authentication is passed, the security communication is allowed, at the same time, due to the addition of new security devices, the configuration of the service system, network topology and related network devices also needs to be changed to adapt to the new security requirements, so this security scheme cannot be applied to in-use terminals and network systems that have been constructed.

[0003] The existing network security channel construction process involves four types of entities, including service terminals, terminal agents, security gateways and service systems, and the channel construction process is shown in FIG. 1, and the construction of a security channel between the terminal and the service system includes four stages: ① the security module and the security gateway perform identity authentication and establish a security channel based on a specific security protocol, such as the national secret SSL / IPSec protocol; ② the business module of the terminal is modified, and the communication configuration of the business module is modified, and the business request is forwarded to the security module; ③ the security module encrypts the business data according to the channel security requirements to realize the secure transmission; and ④ the security gateway performs security processing on the data and forwards it to the service system.

[0004] The existing technology provides authentication and encryption mechanisms through a terminal agent, which improves the security of terminal access and data transmission to a certain extent, but still has the following deficiencies:

[0005] (1) The business terminal needs to be modified: the business terminal needs to set the business destination IP and port to the IP and port of the security module;

[0006] (2) The network topology needs to be modified: network devices such as firewalls and routers need to set access control rules and strategies according to the IP of the security gateway and the security module;

[0007] (3) Unable to realize fine-grained and multi-service security protection: the network security channel cannot set specific protection strategies for specific services, and cannot realize on-demand or selective protection;

[0008] (4) The traditional terminal security module cannot realize the security protection support of multiple service protocols: the traditional security module generally supports TCP and UDP protocols, and the application layer communication protocol of specific services cannot be parsed and forwarded, resulting in that part of the services cannot use the network security channel to realize security protection. SUMMARY

[0009] The technical problem to be solved by the present application is to provide a service-unaware network security channel construction mechanism based on security channel and data encryption, which introduces an unaware access method to reduce the terminal security modification steps and improve the security protection capability of the terminal.

[0010] The present application adopts the following technical solutions to solve the above technical problems: the present application designs a service-unaware network security channel construction mechanism, which is executed by each terminal as follows: steps A to G, and the target type service system is accessed through the terminal unaware security module and the service-unaware security gateway in turn;

[0011] Step A. The terminal sends the service request data frame of the target type service system, and enters step B;

[0012] Step B. The terminal unaware security module captures the service request data frame for analysis, judges whether there is a security channel between the terminal and the service-unaware security gateway for the target type service system, and if yes, enters step D; otherwise, enters step C;

[0013] Step C. The terminal unaware security module constructs an identity authentication data frame with the same Ethernet header and the same source IP and destination IP according to the service request data frame, and sends it to the service-unaware security gateway for authentication. If the authentication is successful, a security channel between the terminal corresponding terminal unaware security module and the service-unaware security gateway for the target type service system is created, and then step D is entered. If the authentication fails, the processing of the service request data frame fails and ends;

[0014] Step D. The terminal unaware security module constructs a service request encryption encapsulation data frame with the same Ethernet header and the same source IP and destination IP, and which is processed by encryption and encapsulation, according to the service request data frame, and sends it to the service-unaware security gateway through the security channel between the terminal corresponding terminal unaware security module and the service-unaware security gateway for the target type service system, and then enters step E;

[0015] Step E. The service-unaware security gateway captures the service request encryption encapsulation data frame for analysis, and performs decryption and decryption processing to obtain the corresponding service request data frame, and forwards it to the target type service system, and the target type service system creates a corresponding service feedback data frame and returns it to the service-unaware security gateway, and then enters step F;

[0016] Step F. The service non-sensing security gateway captures the service feedback data frame for analysis, constructs a service feedback encryption encapsulation data frame with the same Ethernet header and the same source IP and destination IP, and after the encryption encapsulation processing, sends it to the terminal non-sensing security module through the security channel about the target type service system between the terminal non-sensing security module and the service non-sensing security gateway, and then enters step G;

[0017] Step G. The terminal non-sensing security module captures the service feedback encryption encapsulation data frame for analysis, and performs decryption processing to obtain the corresponding service feedback data frame, and forwards the terminal, completing the non-sensing access of the terminal to the target type service system.

[0018] As a preferred technical solution of the present application: in step C, the terminal non-sensing security module extracts the corresponding identity characteristic data in the service request data frame according to the identity authentication rules and security channel protocols corresponding to the target type service system to form an identity authentication message, and then sends the identity authentication data frame to the service non-sensing security gateway, which is composed of the same Ethernet header, the same source IP and destination IP in the service request data frame, the identity authentication message, and the corresponding frame check sum in sequence.

[0019] In step D, the terminal non-sensing security module extracts the TCP / UDP header and application data in the service request data frame, and calls the preset data encryption mode corresponding to the target type service system to encrypt the application data to obtain application encryption data, and then constructs the service request encryption encapsulation data frame by sequentially following the same Ethernet header, the same source IP and destination IP in the service request data frame, the TCP / UDP header, the application encryption data, and the corresponding frame check sum.

[0020] In step F, the service non-sensing security gateway extracts the IP header, TCP / UDP header, and application data in the service feedback data frame, and calls the preset data encryption mode corresponding to the target type service system to encrypt the application data to obtain application encryption data, and then constructs the service feedback encryption encapsulation data frame by sequentially following the same Ethernet header, the same source IP and destination IP in the service feedback data frame, the TCP / UDP header, the application encryption data, and the corresponding frame check sum.

[0021] As a preferred technical scheme of the present application: in step B, the terminal non-perception security module first filters the captured service request data frame based on the filtering rules corresponding to the target type service system according to the source IP and source MAC formed by the terminal IP and terminal MAC obtained by analysis, and then judges whether there is a security channel between the terminal and the service non-perception security gateway with respect to the target type service system.

[0022] In step E, the service non-perception security gateway first filters the captured service request encryption encapsulation data frame based on the filtering rules corresponding to the target type service system according to the source IP formed by the terminal IP, the destination IP formed by the service system IP, the destination port formed by the service system port, and the secure transmission protocol, and then performs decryption and decryption processing on the service request encryption encapsulation data frame.

[0023] As a preferred technical scheme of the present application: the terminal non-perception security module is based on the first network card for communication with each terminal and the second network card for communication with the service non-perception security gateway built-in;

[0024] Data uplink direction: first, the terminal non-perception security module corresponding to step B executes the packet capture thread to capture the service request data frame from the terminal by the RX cache queue of the first network card, and stores it in the receiving queue corresponding to the terminal; then the terminal non-perception security module corresponding to step D executes the work thread to build the service request encryption encapsulation data frame, and stores it in the sending queue corresponding to the terminal; finally, the terminal non-perception security module corresponding to step D executes the packet sending thread to obtain the service request encryption encapsulation data frame from the sending queue corresponding to the terminal, and sends it to the TX sending buffer queue of the second network card, realizing sending to the service non-perception security gateway;

[0025] Data downlink direction: first, the terminal non-perception security module corresponding to step G executes the packet capture thread to capture the service feedback encryption encapsulation data frame from the service non-perception security gateway by the RX cache queue of the second network card, and stores it in the receiving queue corresponding to the terminal; then the terminal non-perception security module corresponding to step G executes the work thread to obtain the corresponding service feedback data frame, and stores it in the sending queue corresponding to the terminal; finally, the terminal non-perception security module corresponding to step G executes the packet sending thread to obtain the service feedback data frame from the sending queue corresponding to the terminal, and sends it to the TX sending buffer queue of the first network card, realizing sending to the terminal;

[0026] The service non-perception security gateway is based on the third network card for communication with the terminal non-perception security module and the fourth network card for communication with each target type service system built-in;

[0027] Data uplink direction: firstly, the business non-sensing security gateway executes the packet capturing thread corresponding to step E to capture the business request encryption encapsulation data frame from the terminal non-sensing security module by the RX buffer queue of the third network card, and store it in the receiving queue corresponding to the terminal; then the business non-sensing security gateway executes the working thread corresponding to step E to obtain the corresponding business request data frame, and store it in the sending queue corresponding to the terminal; finally, the business non-sensing security gateway executes the packet sending thread corresponding to step E to obtain the business request data frame from the sending queue, and send it to the TX sending buffer queue of the fourth network card, so as to realize sending to the target type business system;

[0028] Data downlink direction: firstly, the business non-sensing security gateway executes the packet capturing thread corresponding to step F to capture the business feedback data frame from the target type business system by the RX buffer queue of the fourth network card, and store it in the receiving queue corresponding to the terminal; then the business non-sensing security gateway executes the working thread corresponding to step F to construct the business feedback encryption encapsulation data frame, and store it in the sending queue corresponding to the terminal; finally, the business non-sensing security gateway executes the packet sending thread corresponding to step F to obtain the business feedback encryption encapsulation data frame from the sending queue, and send it to the TX sending buffer queue of the third network card, so as to realize sending to the terminal non-sensing security module;

[0029] Based on the judgment of the terminal non-sensing security module corresponding to step B that there is no security channel, the terminal non-sensing security module and the business non-sensing security gateway realize the construction of the identity authentication data frame based on the communication between the second network card and the third network card, the authentication of the identity authentication data frame by the business non-sensing security gateway, and the creation of the security channel between the terminal non-sensing security module and the business non-sensing security gateway based on the successful authentication.

[0030] Corresponding to the above, the technical problem to be solved by the present application is to provide a system of a business non-sensing network security channel construction mechanism, which is specific to the terminal non-sensing security module and the business non-sensing security gateway, and is used for executing the designed business non-sensing network security channel construction mechanism, so as to reduce the terminal security modification steps and improve the security protection capability of the terminal.

[0031] In order to solve the above technical problems, the present application adopts the following technical scheme: the present application designs a system of a business non-sensing network security channel construction mechanism, the terminal non-sensing security module comprises a first data receiving module, a first data processing module, a first security protocol processing module and a first data forwarding module, wherein the first data processing module comprises a first message analysis module, a first message filtering module and a first message processing module, and the first security protocol processing module comprises a first security protocol rule library, a first protocol processing module and a first channel management module.

[0032] The terminal non-inductive security module executes step B, first applies the first data receiving module to listen to the captured service request data frame sent to the first message analysis module, the first message analysis module analyzes the service request data frame, then the first message filtering module calls the filtering rule corresponding to the target type business system in the first security protocol rule library, and filters the service request data frame according to the analysis result; Then judge whether there is a security channel between the terminal non-inductive security module and the service non-inductive security gateway about the target type business system, yes, the first message processing module executes step D, according to the preset data encryption mode corresponding to the target type business system in the first security protocol rule library, constructs the service request encryption encapsulation data frame for the service request data frame, and combines the one-to-one correspondence between each business system and each security channel in the first channel management module, and forwards to the first data forwarding module, and the first data forwarding module sends the service request encryption encapsulation data frame to the service non-inductive security gateway based on the corresponding security channel;

[0033] Otherwise, the first protocol processing module executes step C, according to the identity authentication rule and the security channel protocol corresponding to the target type business system in the first security protocol rule library, constructs the identity authentication data frame based on the service request data frame, and forwards to the service non-inductive security gateway through the first data forwarding module, and the service non-inductive security gateway authenticates according to the identity authentication rule corresponding to the target type business system, and based on the authentication success, the first protocol processing module creates the security channel between the terminal non-inductive security module corresponding to the terminal and the service non-inductive security gateway about the target type business system, and the first channel management module stores the one-to-one correspondence between each business system and each security channel in each terminal; Then the first message processing module executes step D, constructs the service request encryption encapsulation data frame for the service request data frame, and sends it to the service non-inductive security gateway through the corresponding security channel by the first data forwarding module;

[0034] The terminal non-inductive security module also executes step G, applies the first data receiving module to listen to the captured service feedback encryption encapsulation data frame sent to the first message analysis module, the first message processing module, the first message analysis module analyzes the captured service feedback encryption encapsulation data frame, and the first message processing module continues to execute step G, according to the preset data encryption mode corresponding to the target type business system in the first security protocol rule library and the analysis result, decrypts and processes the service feedback encryption encapsulation data frame, obtains the corresponding service feedback data frame, and forwards the terminal through the first data forwarding module.

[0035] As a preferred technical scheme of the present application: the service non-aware security gateway comprises a second data receiving module, a second data processing module, a second security protocol processing module and a second data forwarding module, wherein the second data processing module comprises a second packet analysis module, a second packet filtering module and a second packet processing module, and the second security protocol processing module comprises a second security protocol rule library, a second protocol processing module and a second channel management module.

[0036] In step C, the service non-aware security gateway first receives the identity authentication data frame from the second data receiving module, and then sends the identity authentication data frame to the second packet analysis module. The second packet analysis module analyzes the identity authentication data frame. The second packet filtering module calls the filtering rule corresponding to the target type business system in the second security protocol rule library, and filters the identity authentication data frame according to the analysis result. The second protocol processing module authenticates the identity authentication data frame according to the identity authentication rule corresponding to the target type business system in the second security protocol rule library. If the authentication is successful, the second protocol processing module communicates with the first protocol processing module to create a security channel between the terminal non-aware security module corresponding to the terminal and the service non-aware security gateway for the target type business system. The second channel management module stores the one-to-one correspondence between each business system in each terminal and each security channel.

[0037] In step E, the service non-aware security gateway first receives the business request encryption encapsulation data frame from the second data receiving module, and then sends the business request encryption encapsulation data frame to the second packet analysis module. The second packet analysis module analyzes the business request encryption encapsulation data frame. The second packet filtering module calls the filtering rule corresponding to the target type business system in the second security protocol rule library, and filters the business request encryption encapsulation data frame according to the analysis result. The second packet processing module continues to execute step E, decrypts and processes the business request encryption encapsulation data frame according to the preset data encryption mode corresponding to the target type business system in the second security protocol rule library, obtains the corresponding business request data frame, and forwards the business request data frame to the target type business system through the second data forwarding module.

[0038] The service non-sensing security gateway also performs step F, first, the second data receiving module listens to the captured service feedback data frame and sends it to the second message analysis module and the second message processing module, the second message analysis module analyzes the captured service feedback data frame, and the second message processing module continues to perform step F, according to the preset data encryption mode corresponding to the target type service system in the second security protocol rule library and the analysis result, constructs a service feedback encrypted encapsulation data frame for the service feedback data frame, and combines the one-to-one correspondence relationship between each service system and each security channel in each terminal in the second channel management module, and forwards it to the second data forwarding module, which sends the service feedback encrypted encapsulation data frame to the terminal non-sensing security module based on the corresponding security channel.

[0039] As a preferred technical solution of the present application: the second security protocol processing module in the service non-sensing security gateway further comprises a session management module, which manages the data and data processing related to different terminals respectively.

[0040] The service non-sensing network security channel construction mechanism and system of the present application have the following technical effects compared with the prior art by adopting the above technical solution:

[0041] The present application designs a service non-sensing network security channel construction mechanism based on the terminal non-sensing security module and the service non-sensing security gateway, and establishes a security channel based on the service request data frame sent by the terminal through identity authentication data frame design with the same Ethernet header and the same source IP and destination IP, and cooperates with the service data security communication mechanism to ensure that different security requirements of service data can be protected on demand, and realizes non-sensing access of the terminal to the service system through the service request encrypted encapsulation data frame with the same Ethernet header and the same source IP and destination IP and encrypted encapsulation processing; the corresponding system is designed through the modular decomposition design of the terminal non-sensing security module and the service non-sensing security gateway, and the functions of security communication protocol, service communication message analysis, data message security processing and forwarding are realized, which realizes non-sensing service access and improves the security protection capability in application under the condition of reducing or canceling the modification of the terminal, the service system and the network topology;

[0042] In the service non-sensing network security channel construction mechanism and system of the present application, no new MAC and IP are introduced, but the original communication address and network information of the terminal and the system are continued to be used, so that the operation of the intermediate network such as switch, firewall and router is not affected, in addition, the source MAC and source IP analyzed by the operating system protocol stack of the service system after receiving the original service data forwarded by the security gateway are consistent with those in the case without adding security module and security gateway topology, so that the operation logic of the service system also does not need to be changed. BRIEF DESCRIPTION OF DRAWINGS

[0043] Figure 1 is a prior art schematic diagram about security channel establishment;

[0044] Figure 2 is a schematic diagram of the system of the application designed network security channel construction mechanism of service non-sense;

[0045] Figure 3 is a schematic diagram of the module of the terminal non-sense security module in the design of the application;

[0046] Figure 4 is a schematic diagram of the module of the service non-sense security gateway in the design of the application;

[0047] Figure 5 is a schematic diagram of the data processing process of the terminal non-sense security module in the design of the application;

[0048] Figure 6 is a schematic diagram of the data processing process of the service non-sense security gateway in the design of the application;

[0049] Figure 7 is a schematic diagram of the communication framework of the terminal non-sense security module in the design of the application;

[0050] Figure 8 is a schematic diagram of the communication framework of the service non-sense security gateway in the design of the application. DETAILED DESCRIPTION

[0051] The specific embodiments of the application will be further described in detail below with reference to the accompanying drawings.

[0052] The application designs a network security channel construction mechanism and system of service non-sense, which is realized by terminals respectively and sequentially accessing target type service system through terminal non-sense security module and service non-sense security gateway. In the actual application of the designed system, as shown in Figure 3, the terminal non-sense security module includes a first data receiving module, a first data processing module, a first security protocol processing module and a first data forwarding module. The first data processing module includes a first message analysis module, a first message filtering module and a first message processing module. The first security protocol processing module includes a first security protocol rule library, a first protocol processing module and a first channel management module. As shown in Figure 4, the service non-sense security gateway includes a second data receiving module, a second data processing module, a second security protocol processing module and a second data forwarding module. The second data processing module includes a second message analysis module, a second message filtering module and a second message processing module. The second security protocol processing module includes a second security protocol rule library, a second protocol processing module and a second channel management module.

[0053] Based on the above designed system, the network security channel construction mechanism of service non-sense is designed to be applied in the actual application, as shown in Figure 2, which is realized by terminals respectively and sequentially accessing target type service system through terminal non-sense security module and service non-sense security gateway.

[0054] Step A. The terminal sends a service request data frame about the target type service system, and goes to Step B.

[0055] Step B. The terminal unconscious security module first applies the first data receiving module to listen to and capture the service request data frame sent to the first message parsing module, and the first message parsing module parses the service request data frame. Then the first message filtering module calls the filtering rules corresponding to the target type service system in the first security protocol rule library, filters the captured service request data frame according to the source IP and source MAC composed of the terminal IP and terminal MAC obtained by parsing, and then judges whether there is a security channel between the terminal unconscious security module and the service unconscious security gateway about the target type service system. If yes, go to Step D by the first message processing module; otherwise, go to Step C by the first protocol processing module.

[0056] Step C. The first message processing module in the terminal unconscious security module extracts the corresponding identity characteristic data in the service request data frame to form an identity authentication message according to the identity authentication rules and security channel protocols corresponding to the target type service system, as shown in FIG. 5. The identity authentication data frame is composed of the same Ethernet header, the same source IP and destination IP, followed by the identity authentication message, and the corresponding frame check sum in the service request data frame, and is forwarded to the service unconscious security gateway through the first data forwarding module. The service unconscious security gateway authenticates according to the identity authentication rules corresponding to the target type service system. If the authentication is successful, the first protocol processing module creates a security channel between the terminal unconscious security module and the service unconscious security gateway about the target type service system corresponding to the terminal, and the first channel management module stores the one-to-one correspondence between each service system and each security channel in each terminal. Then the first message processing module executes Step D. If the authentication fails, the processing of the service request data frame fails.

[0057] According to the identity authentication rule corresponding to the target type business system, the authentication of the identity authentication data frame is first captured by the second data receiving module and sent to the second packet analysis module, the identity authentication data frame is analyzed by the second packet analysis module, then the filtering rule corresponding to the target type business system in the second security protocol rule library is called by the second packet filtering module, and the identity authentication data frame is filtered according to the analysis result; then the second protocol processing module authenticates the identity authentication data frame according to the identity authentication rule corresponding to the target type business system in the second security protocol rule library, and based on the authentication success, the second protocol processing module and the first protocol processing module communicate to create a security channel between the terminal corresponding terminal invisible security module and the business invisible security gateway for the target type business system, and the one-to-one correspondence between each business system and each security channel in each terminal is stored in the second channel management module.

[0058] Step D. The first packet processing module in the terminal invisible security module analyzes and extracts the TCP / UDP header and application data in the business request data frame, and calls the preset data encryption mode corresponding to the target type business system in the first security protocol rule library to encrypt the application data, as shown in FIG. 3, then constructs a business request encryption encapsulation data frame with the same Ethernet header, the same source IP and destination IP in the business request data frame, followed by the TCP / UDP header, the application encryption data, and the corresponding frame checksum, and combines the one-to-one correspondence between each business system and each security channel in each terminal in the first channel management module, and forwards to the first data forwarding module, which sends the business request encryption encapsulation data frame to the business invisible security gateway based on the corresponding security channel, and then enters Step E.

[0059] Step E. The second data receiving module in the business invisible security gateway listens to the business request encryption encapsulation data frame and sends it to the second packet analysis module, the second packet analysis module analyzes the business request encryption encapsulation data frame, then the second packet filtering module calls the filtering rule corresponding to the target type business system in the second security protocol rule library, and filters the captured business request encryption encapsulation data frame according to the source IP composed of the terminal IP, the destination IP composed of the business system IP, the destination port composed of the business system port, and the secure transmission protocol; then the second packet processing module decrypts the business request encryption encapsulation data frame according to the preset data encryption mode corresponding to the target type business system in the second security protocol rule library, obtains the corresponding business request data frame, and forwards it to the target type business system through the second data forwarding module, and the target type business system creates a corresponding business feedback data frame and returns it to the business invisible security gateway, and then enters Step F.

[0060] Step F. The second data receiving module in the service non-sensing security gateway listens to the captured service feedback data frame and sends it to the second packet analysis module and the second packet processing module. The second packet analysis module analyzes the captured service feedback data frame, extracts the IP header, TCP / UDP header, and application data in the service feedback data frame, and the second packet processing module encrypts the application data according to the preset data encryption method corresponding to the target type business system in the second security protocol rule library and the analysis result, obtains application encrypted data, and then constructs a service feedback encrypted encapsulation data frame with the same Ethernet header, the same source IP and destination IP, followed by the TCP / UDP header, application encrypted data, and the corresponding frame checksum in the service feedback data frame, as shown in FIG. 6. In combination with the one-to-one correspondence between each business system and each security channel in each terminal in the second channel management module, it is forwarded to the second data forwarding module, which sends the service feedback encrypted encapsulation data frame to the terminal non-sensing security module based on the corresponding security channel, and then enters Step G.

[0061] Step G. The first data receiving module in the terminal non-sensing security module listens to the captured service feedback encrypted encapsulation data frame and sends it to the first packet analysis module and the first packet processing module. The first packet analysis module analyzes the captured service feedback encrypted encapsulation data frame, as shown in FIG. 6, and the first packet processing module decrypts and decrypts the service feedback encrypted encapsulation data frame according to the preset data encryption method corresponding to the target type business system in the first security protocol rule library and the analysis result, obtains the corresponding service feedback data frame, and transmits it to the terminal through the first data forwarding module, completing the terminal's non-sensing access to the target type business system.

[0062] In practical application, the above design steps A to G involve data uplink and data downlink, as shown in FIG. 7. Specifically, the terminal non-sensing security module is based on a first network card for communication with each terminal and a second network card for communication with the service non-sensing security gateway. In the data uplink direction: first, the terminal non-sensing security module executes the packet capturing thread corresponding to step B to capture the service request data frame from the terminal by the RX buffer queue of the first network card and store it in the receiving queue corresponding to the terminal; then, the terminal non-sensing security module executes the working thread corresponding to step D to build the service request encrypted encapsulation data frame and store it in the sending queue corresponding to the terminal; finally, the terminal non-sensing security module executes the packet sending thread corresponding to step D to obtain the service request encrypted encapsulation data frame from the sending queue corresponding to the terminal and send it to the TX sending buffer queue of the second network card, thereby achieving sending to the service non-sensing security gateway. In the data downlink direction: first, the terminal non-sensing security module executes the packet capturing thread corresponding to step G to capture the service feedback encrypted encapsulation data frame from the service non-sensing security gateway by the RX buffer queue of the second network card and store it in the receiving queue corresponding to the terminal; then, the terminal non-sensing security module executes the working thread corresponding to step G to obtain the corresponding service feedback data frame and store it in the sending queue corresponding to the terminal; finally, the terminal non-sensing security module executes the packet sending thread corresponding to step G to obtain the service feedback data frame from the sending queue corresponding to the terminal and send it to the TX sending buffer queue of the first network card, thereby achieving sending to the terminal.

[0063] Correspondingly, as shown in FIG. 8, the service non-sensing security gateway is based on a third network card for communication with the terminal non-sensing security module and a fourth network card for communication with each target type service system. In the data uplink direction: first, the service non-sensing security gateway executes the packet capturing thread corresponding to step E to capture the service request encrypted encapsulation data frame from the terminal non-sensing security module by the RX buffer queue of the third network card and store it in the receiving queue corresponding to the terminal; then, the service non-sensing security gateway executes the working thread corresponding to step E to obtain the corresponding service request data frame and store it in the sending queue corresponding to the terminal; finally, the service non-sensing security gateway executes the packet sending thread corresponding to step E to obtain the service request data frame from the sending queue and send it to the TX sending buffer queue of the fourth network card, thereby achieving sending to the target type service system. In the data downlink direction: first, the service non-sensing security gateway executes the packet capturing thread corresponding to step F to capture the service feedback data frame from the target type service system by the RX buffer queue of the fourth network card and store it in the receiving queue corresponding to the terminal; then, the service non-sensing security gateway executes the working thread corresponding to step F to build the service feedback encrypted encapsulation data frame and store it in the sending queue corresponding to the terminal; finally, the service non-sensing security gateway executes the packet sending thread corresponding to step F to obtain the service feedback encrypted encapsulation data frame from the sending queue and send it to the TX sending buffer queue of the third network card, thereby achieving sending to the terminal non-sensing security module.

[0064] In the actual communication of the above-mentioned service non-sensing security gateway, a thread pool is set and the hash value of the current data frame to be processed is calculated based on the four-tuple of <source IP address, destination IP address, source port, destination port> to realize the binding of the terminal and the working thread, thereby reducing the performance impact caused by CPU switching; meanwhile, after the working thread reads the queue information, it judges the current data frame type and IP datagram type, directly forwards the ARP protocol data meeting the requirements, calls the second security protocol processing module to process the identity authentication data frame to complete the establishment and management of the security channel, and stores the data transmitted in the security channel to the cyclic sending queue after security processing.

[0065] In the identity authentication process of the security channel, based on the step B of the terminal non-sensing security module, it is judged that there is no security channel, and the terminal non-sensing security module and the service non-sensing security gateway realize the construction of the identity authentication data frame by the terminal non-sensing security module, the authentication of the identity authentication data frame by the service non-sensing security gateway, and the creation of the security channel between the terminal non-sensing security module and the service non-sensing security gateway based on the successful authentication according to the communication between the second network card and the third network card.

[0066] In practical application, the second security protocol processing module in the service non-sensing security gateway further includes a session management module, which manages the data and data processing respectively involved by different terminals.

[0067] In the above design, in the process of establishing the network security channel and forwarding the service data, the terminal non-sensing security module and the service non-sensing security gateway do not introduce new MAC and IP, but continue to use the original communication address and network information of the terminal and the system, so as not to affect the operation of the intermediate network such as switch, firewall and router.

[0068] In the application, the software and hardware inside the terminal do not need to be reformed, the original communication configuration does not need to be modified, the communication destination IP and port are still the business system, and the business terminal is not sensitive to the security protection process; the terminal-insensitive security module selects a specific security communication protocol based on the business security protection requirement of the business terminal to construct a network security channel, and realizes the security transmission of the original business request data, wherein the terminal-insensitive security module uses the related information in the business terminal communication data when constructing the link layer data frame header and the network layer IP header, so as to ensure that the configuration of the intermediate network equipment does not need to be changed, and realizes the insensitive forwarding and processing; the business-insensitive security gateway first realizes the establishment of the security network channel based on the security protocol selected by the terminal-insensitive security module, and realizes the security protection of the interactive data of the business terminal and the business system on this basis, wherein the business-insensitive security gateway performs security processing on the data transmitted by the terminal-insensitive security module, restores the original business request message, and forwards it to the business system for business processing; the business system does not need to be reformed or modified in network configuration, and only needs to receive the original business data forwarded by the security gateway according to the original business logic for processing.

[0069] The embodiments of the present application are described in detail above in combination with the drawings, but the present application is not limited to the above-described embodiments, and various changes can be made within the knowledge of those skilled in the art without departing from the purpose of the present application.

Claims

1. A business-insensitive network security channel construction mechanism, characterized in that: The following steps A to G are performed by each terminal to realize non-sensing access to the target type service system through the terminal non-sensing security module and the service non-sensing security gateway in turn. Step A. The terminal sends a service request data frame about the target type service system, and enters step B. Step B. The terminal non-sensing security module captures the service request data frame for analysis, and judges whether there is a security channel between the terminal non-sensing security module and the service non-sensing security gateway about the target type service system, and if yes, enters step D. Otherwise, enter step C. Step C. The terminal non-sensing security module constructs an identity authentication data frame with the same Ethernet header and the same source IP and destination IP according to the service request data frame, and sends it to the service non-sensing security gateway for authentication. If the authentication is successful, a security channel between the terminal non-sensing security module and the service non-sensing security gateway about the target type service system is created, and then enters step D. If the authentication fails, the processing of the service request data frame fails and ends. Step D. The terminal non-sensing security module constructs a service request encryption encapsulation data frame with the same Ethernet header and the same source IP and destination IP, and after encryption and encapsulation processing, and sends it to the service non-sensing security gateway through the security channel between the terminal non-sensing security module and the service non-sensing security gateway about the target type service system, and then enters step E. Step E. The service non-sensing security gateway captures the service request encryption encapsulation data frame for analysis, and performs decryption and decryption processing to obtain the corresponding service request data frame, and forwards it to the target type service system, and the target type service system creates a corresponding service feedback data frame and returns it to the service non-sensing security gateway, and then enters step F. Step F. The service non-sensing security gateway captures the service feedback data frame for analysis, constructs a service feedback encryption encapsulation data frame with the same Ethernet header and the same source IP and destination IP, and after encryption and encapsulation processing, and sends it to the terminal non-sensing security module through the security channel between the terminal non-sensing security module and the service non-sensing security gateway about the target type service system, and then enters step G. Step G. The terminal non-sensing security module captures the service feedback encryption encapsulation data frame for analysis, and performs decryption and decryption processing to obtain the corresponding service feedback data frame, and forwards it to the terminal, and completes the non-sensing access of the terminal to the target type service system.

2. The service transparent network security channel construction mechanism according to claim 1, characterized in that: In the step C, the terminal non-sensing security module extracts identity authentication messages from the respective identity characteristic data in the business request data frame according to the identity authentication rules and the security channel protocol corresponding to the target type business system, and then sends the identity authentication data frame to the business non-sensing security gateway, wherein the identity authentication data frame is composed of the same Ethernet header, the same source IP and destination IP in the business request data frame, the identity authentication message, and the corresponding frame check sum in sequence. In the step F, the business non-sensing security gateway extracts the IP header, the TCP / UDP header, and the application data from the business feedback data frame, and then encrypts the application data by calling the preset data encryption mode corresponding to the target type business system to obtain the application encrypted data, and then composes the business feedback encrypted encapsulation data frame by taking the same Ethernet header, the same source IP and destination IP in the business feedback data frame, the TCP / UDP header, the application encrypted data, and the corresponding frame check sum in sequence.

3. The service transparent network security channel construction mechanism according to claim 1, characterized in that: In the step B, the terminal non-sensing security module first filters the captured business request data frame based on the source IP and the source MAC composed of the terminal IP and the terminal MAC obtained by analysis according to the filtering rules corresponding to the target type business system, and then determines whether there is a security channel between the terminal and the business non-sensing security gateway with respect to the target type business system. In the step E, the business non-sensing security gateway first filters the captured business request encrypted encapsulation data frame based on the source IP composed of the terminal IP, the destination IP composed of the business system IP, the destination port composed of the business system port, and the security transmission protocol according to the filtering rules corresponding to the target type business system, and then performs decryption and encapsulation processing on the business request encrypted encapsulation data frame.

4. The service transparent network security channel construction mechanism according to claim 1, characterized in that: The terminal non-sensing security module is based on the first network card for communication with each terminal and the second network card for communication with the business non-sensing security gateway built-in; In the data uplink direction, the terminal non-sensing security module corresponding to the step B executes the packet capture thread to capture the business request data frame from the terminal by the RX cache queue of the first network card and store it in the receiving queue corresponding to the terminal. Then the terminal non-inductive security module corresponding to step D performs a work thread to build a service request encryption encapsulation data frame, which is stored in the terminal corresponding sending queue; finally, the terminal non-inductive security module corresponding to step D performs a packet sending thread to obtain the service request encryption encapsulation data frame from the terminal corresponding sending queue, send it to the TX sending buffer queue of the second network card, and realize sending to the service non-inductive security gateway; Data downward direction: first, the terminal non-inductive security module corresponding to step G performs a packet capturing thread to capture the service feedback encryption encapsulation data frame from the service non-inductive security gateway from the RX cache queue of the second network card, and store it in the terminal corresponding receiving queue; Then the terminal non-inductive security module corresponding to step G performs a work thread to obtain the corresponding service feedback data frame, which is stored in the terminal corresponding sending queue; finally, the terminal non-inductive security module corresponding to step G performs a packet sending thread to obtain the service feedback data frame from the terminal corresponding sending queue, send it to the TX sending buffer queue of the first network card, and realize sending to the terminal; The service non-inductive security gateway is based on the third network card built-in and the terminal non-inductive security module communication, and the fourth network card respectively communicating with each target type business system; Data upward direction: first, the terminal non-inductive security module corresponding to step G performs a packet capturing thread to capture the service feedback encryption encapsulation data frame from the service non-inductive security gateway from the RX cache queue of the second network card, and store it in the terminal corresponding receiving queue; Then the terminal non-inductive security module corresponding to step G performs a work thread to obtain the corresponding service feedback data frame, which is stored in the terminal corresponding sending queue; finally, the terminal non-inductive security module corresponding to step G performs a packet sending thread to obtain the service feedback data frame from the terminal corresponding sending queue, send it to the TX sending buffer queue of the first network card, and realize sending to the terminal; Data downward direction: first, the terminal non-inductive security module corresponding to step G performs a packet capturing thread to capture the service feedback encryption encapsulation data frame from the service non-inductive security gateway from the RX cache queue of the second network card, and store it in the terminal corresponding receiving queue; Then the terminal non-inductive security module corresponding to step G performs a work thread to obtain the corresponding service feedback data frame, which is stored in the terminal corresponding sending queue; finally, the terminal non-inductive security module corresponding to step G performs a packet sending thread to obtain the service feedback data frame from the terminal corresponding sending queue, send it to the TX sending buffer queue of the first network card, and realize sending to the terminal; Based on the terminal non-inductive security module corresponding to step B judging that there is no security channel, the terminal non-inductive security module and the service non-inductive security gateway realize the construction of the identity authentication data frame, the authentication of the identity authentication data frame by the service non-inductive security gateway, and the creation of the security channel between the terminal non-inductive security module and the service non-inductive security gateway based on the successful authentication according to the communication between the second network card and the third network card.

5. The system for implementing the mechanism for constructing a network security channel with no awareness of a service according to any one of claims 1 to 4, characterized by: The terminal non-sensing security module comprises a first data receiving module, a first data processing module, a first security protocol processing module and a first data forwarding module, wherein the first data processing module comprises a first message analysis module, a first message filtering module and a first message processing module, and the first security protocol processing module comprises a first security protocol rule library, a first protocol processing module and a first channel management module. In step B, the terminal non-sensing security module first applies the first data receiving module to listen to and capture the business request data frame and sends it to the first message analysis module, and then the first message analysis module analyzes the business request data frame. Next, the first message filtering module calls the filtering rules corresponding to the target type business system in the first security protocol rule library, and filters the business request data frame according to the analysis result. Then, it is judged whether there is a security channel between the terminal non-sensing security module and the business non-sensing security gateway with respect to the target type business system. If yes, the first message processing module executes step D, constructs a business request encryption encapsulation data frame according to the preset data encryption mode corresponding to the target type business system in the first security protocol rule library, and forwards it to the first data forwarding module according to the one-to-one correspondence between each business system and each security channel in the first channel management module. The first data forwarding module sends the business request encryption encapsulation data frame to the business non-sensing security gateway based on the corresponding security channel. If not, the first protocol processing module executes step C, constructs an identity authentication data frame based on the business request data frame according to the identity authentication rules and the security channel protocol corresponding to the target type business system in the first security protocol rule library, and forwards it to the business non-sensing security gateway through the first data forwarding module. The business non-sensing security gateway authenticates according to the identity authentication rules corresponding to the target type business system, and creates a security channel between the terminal non-sensing security module and the business non-sensing security gateway with respect to the target type business system based on the authentication success. The first protocol processing module stores the one-to-one correspondence between each business system and each security channel in the first channel management module. Then, the first message processing module executes step D to construct a business request encryption encapsulation data frame according to the business request data frame, and sends it to the business non-sensing security gateway through the corresponding security channel. The terminal non-sensing security module further executes step G, applies the first data receiving module to listen to and capture the business feedback encryption encapsulation data frame and sends it to the first message analysis module and the first message processing module. The first message analysis module analyzes the captured business feedback encryption encapsulation data frame, and the first message processing module continues to execute step G to decrypt and process the business feedback encryption encapsulation data frame according to the preset data encryption mode corresponding to the target type business system in the first security protocol rule library and the analysis result, obtains the corresponding business feedback data frame, and forwards it to the terminal through the first data forwarding module.

6. The system of claim 5, wherein the system is characterized by: The service non-sensing security gateway comprises a second data receiving module, a second data processing module, a second security protocol processing module and a second data forwarding module, wherein the second data processing module comprises a second message analysis module, a second message filtering module and a second message processing module, and the second security protocol processing module comprises a second security protocol rule library, a second protocol processing module and a second channel management module; In step C, the service non-sensing security gateway first captures the identity authentication data frame sent by the second data receiving module to the second message analysis module, analyzes the identity authentication data frame by the second message analysis module, then calls the filtering rule corresponding to the target type business system in the second security protocol rule library by the second message filtering module, and filters the identity authentication data frame according to the analysis result; then, the second protocol processing module authenticates the identity authentication data frame according to the identity authentication rule corresponding to the target type business system in the second security protocol rule library, and creates the security channel between the terminal non-sensing security module and the service non-sensing security gateway with respect to the target type business system based on the successful authentication by the second protocol processing module communicating with the first protocol processing module, and the one-to-one correspondence between each business system and each security channel in each terminal is stored in the second channel management module; In step E, the service non-sensing security gateway first captures the business request encryption encapsulation data frame sent by the second data receiving module to the second message analysis module, analyzes the business request encryption encapsulation data frame by the second message analysis module, then calls the filtering rule corresponding to the target type business system in the second security protocol rule library by the second message filtering module, and filters the business request encryption encapsulation data frame according to the analysis result; then, the second message processing module continues to execute step E, decrypts and processes the business request encryption encapsulation data frame according to the preset data encryption mode corresponding to the target type business system in the second security protocol rule library, obtains the corresponding business request data frame, and forwards the business request data frame to the target type business system through the second data forwarding module; In step F, the service non-sensing security gateway first captures the business feedback data frame sent by the second data receiving module to the second message analysis module and the second message processing module, analyzes the captured business feedback data frame by the second message analysis module, then the second message processing module continues to execute step F, constructs the business feedback encryption encapsulation data frame according to the preset data encryption mode corresponding to the target type business system in the second security protocol rule library and the analysis result, and forwards the business feedback encryption encapsulation data frame to the second data forwarding module based on the one-to-one correspondence between each business system and each security channel in each terminal in the second channel management module, and sends the business feedback encryption encapsulation data frame to the terminal non-sensing security module based on the corresponding security channel by the second data forwarding module.

7. The system of claim 6, wherein the system is characterized by: The second security protocol processing module of the service non-perception security gateway further comprises a session management module, and the session management module manages data and data processing respectively involved by different terminals.

Citation Information

Patent Citations

  • User non-inductive VPN access method based on container technology

    CN110113243A

  • Secure communication method and system based on secure communication module

    CN111918284A

  • NB-IOT (Narrow Band Internet of Things) terminal security access system and access method

    CN115835194A

  • Business-noninductive network security channel construction mechanism and system

    CN118764322A

  • Apparatus, system, and method for monitoring network security and performance

    US20230180005A1