信息网络安全 ›› 2016, Vol. 16 ›› Issue (9): 196-201.doi: 10.3969/j.issn.1671-1122.2016.09.039

• • 上一篇    下一篇

一种基于龙芯平台的安全防护网关设计与实现

马书磊1(), 田洪娟2, 刘丰2   

  1. 1.中国航天科工集团二院七〇六所,北京100854
    2.解放军某部驻北京地区军代室,北京100083
  • 收稿日期:2016-07-25 出版日期:2016-09-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 马书磊(1980—),男,黑龙江,高级工程师,硕士,主要研究方向为信息安全;田洪娟(1969—),女,河南,高级工程师,硕士,主要研究方向为信息安全;刘丰(1984—),男,河北,工程师,硕士,主要研究方向为信息安全。

Design and Implementation of a Security Protect Gateway Based on Loongson Platform

Shulei MA1(), Hongjuan TIAN2, Feng LIU2   

  1. 1. Institute 706,The Second Academy of China Aerospace Science and Industry Corporation, Beijing 100854, China
    2. P.L.A, Beijing 100083, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

摘要:

目前的网络设备大部分基于国外的基础软硬件研制开发,存在核心技术受制于人带来的安全隐患。针对国产龙芯处理器性能和可靠性不能满足网络安全设备使用要求的情况,文章设计了一种多龙芯处理器并行处理技术架构,并基于此架构设计实现了一种多功能安全防护网关,硬件兼容ATCA标准,同时选用国产交换芯片和自主操作系统,整机设计采用开放式架构,遵循通用化、系列化、模块化设计原则,实现了基于多重检测的网络攻击防御、网络报文并行处理、基于连接和包分类的网络快速转发等关键技术。安全防护网关可部署于网络边界处,具备防火墙、应用安全防护和安全接入控制等多个功能,同时预留可信计算接口。在提升自主可控水平的同时,弥补了国产处理器性能和可靠性的不足,能够满足大中型信息中心及用户网络环境的日常使用要求。

关键词: 龙芯, 安全防护, 防火墙, 入侵防御, 安全接入控制

Abstract:

Currently, most network devices are developed base on foreign software and hardware. The core technology is controlled by others. After the Snowden leaks, some backdoors were publicly announced, which brought much latent dangers to our country. Because of the background, designed an architecture which is parallel processing by several Loongson CPU, due to the lack of performance for single Loongson CPU, and base on the architecture, developed a security protection gateway, which can be deployed in the entrance of the information center in network, and it has many functions such as firewall, IPS, and security access control. It improved the level of independence and controllable, and covered the shortage of performance and reliability for domestic Loongson CPU, also it guaranteed the security and controllable for the information center and user network.

Key words: Loongson, security protect, firewall, IPS, security access control

中图分类号: