KR101429877B1 - L2/L3 switch system having a function of security module updating - Google Patents
L2/L3 switch system having a function of security module updating Download PDFInfo
- Publication number
- KR101429877B1 KR101429877B1 KR1020130126746A KR20130126746A KR101429877B1 KR 101429877 B1 KR101429877 B1 KR 101429877B1 KR 1020130126746 A KR1020130126746 A KR 1020130126746A KR 20130126746 A KR20130126746 A KR 20130126746A KR 101429877 B1 KR101429877 B1 KR 101429877B1
- Authority
- KR
- South Korea
- Prior art keywords
- security module
- update
- security
- module
- switch system
- Prior art date
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/572—Secure firmware programming, e.g. of basic input output system [BIOS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Stored Programmes (AREA)
Abstract
Description
The present invention relates to an L2 / L3 switch, and more particularly to an L2 / L3 switch system having a security module update function.
Korean Patent Laid-Open No. 10-2011-0117947 (Oct. 28, 2011) discloses that the conventional L2 / L3 switch system does not have an update function for the security module, so that the user must manually update the security module manually There was.
Accordingly, the present inventors have developed a security module update function that can improve user convenience by automatically updating a security module when update information is detected from a security server without the inconvenience of a user manually updating the security module, L3 switch system.
It is an object of the present invention to provide a security module update function which is implemented to automatically update a security module when update information is detected from a security server without the inconvenience of a user manually updating the security module, / L3 switch system.
According to an aspect of the present invention, there is provided an L2 / L3 switch system having a security module update function, including: a security module for detecting an abnormality of traffic data transmitted and received using sampling data; A traffic sampling engine for extracting sampling data for detecting an anomaly from traffic data to be transmitted and received, and a system on a chip (SoC) module including a packet forwarding engine for relaying traffic data transmitted and received and; Controlling the operation of the security module and the traffic sampling engine to be off when update information is detected from the security server, controlling the packet forwarding engine operation to keep on, An O / S kernel module for controlling the update of the security module using updated update data; And the like.
According to a further aspect of the present invention, there is provided an update engine, wherein the switch SoC module receives update data from a security server and updates the security module by reflecting the update data to the security module under the control of the O / S kernel module; And further comprising:
According to a further aspect of the present invention, when the O / S kernel module detects update information from the security server, it releases the memory allocation of the security module and reassigns the security module to the memory after the security module update is completed .
According to a further aspect of the present invention, after the security module update of the O / S kernel module is completed, the security module operation and the traffic sampling engine operation are controlled to be on.
According to a further aspect of the present invention, the update engine detects update information by monitoring an update notification from a security server or a security module version of a security server, and reports the update information to the O / S kernel module.
The present invention has the effect of improving user convenience by automatically updating the security module when update information is detected from the security server without the inconvenience of the user manually updating the security module of the L2 / L3 switch system.
1 is a block diagram illustrating a configuration of an L2 / L3 switch system having a security module update function according to an embodiment of the present invention.
2 is a flowchart illustrating an example of a security module update operation of an L2 / L3 switch system having a security module update function according to the present invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Reference will now be made in detail to embodiments of the present invention, examples of which are illustrated in the accompanying drawings, wherein like reference numerals refer to the like elements throughout.
In the following description of the present invention, a detailed description of known functions and configurations incorporated herein will be omitted when it may make the subject matter of the present invention rather unclear.
The terms used throughout the specification of the present invention have been defined in consideration of the functions of the embodiments of the present invention and can be sufficiently modified according to the intentions and customs of the user or operator. It should be based on the contents of.
1 is a block diagram illustrating a configuration of an L2 / L3 switch system having a security module update function according to an embodiment of the present invention. 1, an L2 /
The
The
The
The
The O /
When the O /
The O /
Therefore, according to the present invention, when the update information is detected from the security server, the security module is updated automatically. However, according to the present invention, a sampling data extraction function for detecting abnormalities of traffic data during updating of the security module, And the packet forwarding function for relaying the transmission / reception traffic data is maintained, so that the security module can be automatically updated without any problem.
According to a further aspect of the invention, the
Meanwhile, the
Therefore, according to the present invention, when the update information is detected from the security server without the inconvenience of the user manually updating the security module of the L2 / L3 switch system, the security module is automatically updated through the
The security module update operation of the L2 / L3 switch system having the security module update function according to the present invention as described above will be described with reference to FIG. 2 is a flowchart illustrating an example of a security module update operation of an L2 / L3 switch system having a security module update function according to the present invention.
First, in
If the security module update information is detected by the
Then, in step 330, the L2 / L3 switch system controls the security module operation and the traffic sampling engine operation to be off and the packet forwarding engine operation to continue to be on.
Then, in
When the security module update is completed, in
Therefore, according to the present invention, when the update information is detected from the security server without the inconvenience of the user manually updating the security module of the L2 / L3 switch system, the security module is automatically updated to improve user convenience Therefore, the object of the present invention can be achieved.
While the present invention has been particularly shown and described with reference to exemplary embodiments thereof, it will be understood by those of ordinary skill in the art that various changes in form and details may be made therein without departing from the spirit and scope of the invention as defined by the appended claims. .
The present invention is industrially applicable in the L2 / L3 switch technology field and its application field.
100: L2 / L3 switch system
110: Security module
111: Blacklist
112: Security Application
120: Switch SoC module
121: Traffic sampling engine
122: Packet Forwarding Engine
123: Update Engine
130: O / S kernel module
200: Security server
Claims (5)
A traffic sampling engine for extracting sampling data for detecting abnormality from traffic data to be transmitted and received, and a system on a chip (SoC) module including a packet forwarding engine for relaying traffic data transmitted and received and;
Controlling the operation of the security module and the traffic sampling engine to be off when update information is detected from the security server, controlling the packet forwarding engine operation to keep on, An O / S kernel module for controlling the update of the security module using updated update data;
L3 switch system having a security module update function.
The switch SoC module comprises:
An update engine for receiving update data from the security server and updating the security module by reflecting the update data to the security module under the control of the O / S kernel module;
L2 / L3 switch system having a security module update function.
The O / S kernel module comprises:
And when the security information is detected from the security server, releasing the memory allocation of the security module, and reassigning the security module to the memory after the security module update is completed, the L2 / L3 switch system having the security module update function.
The O / S kernel module comprises:
L3 switch system having a security module update function, after the security module update is completed, the security module operation and the traffic sampling engine operation are turned on.
The update engine comprising:
And reports the update information to the O / S kernel module by notifying the update information from the security server or monitoring the security module version of the security server.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020130126746A KR101429877B1 (en) | 2013-10-23 | 2013-10-23 | L2/L3 switch system having a function of security module updating |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020130126746A KR101429877B1 (en) | 2013-10-23 | 2013-10-23 | L2/L3 switch system having a function of security module updating |
Publications (1)
Publication Number | Publication Date |
---|---|
KR101429877B1 true KR101429877B1 (en) | 2014-08-13 |
Family
ID=51750360
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020130126746A KR101429877B1 (en) | 2013-10-23 | 2013-10-23 | L2/L3 switch system having a function of security module updating |
Country Status (1)
Country | Link |
---|---|
KR (1) | KR101429877B1 (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR102370848B1 (en) * | 2020-11-17 | 2022-03-07 | 주식회사 시큐브 | Computer device including divided security module and method for updating security module |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR100604604B1 (en) * | 2004-06-21 | 2006-07-24 | 엘지엔시스(주) | Method for securing system using server security solution and network security solution, and security system implementing the same |
KR100750377B1 (en) * | 2006-05-09 | 2007-08-17 | 한정보통신 주식회사 | Network security system based system on chip and method thereof |
KR100998284B1 (en) * | 2009-12-31 | 2010-12-03 | 신영전자통신 주식회사 | Protection switch system integrated network and security and the method thereof |
-
2013
- 2013-10-23 KR KR1020130126746A patent/KR101429877B1/en active IP Right Grant
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR100604604B1 (en) * | 2004-06-21 | 2006-07-24 | 엘지엔시스(주) | Method for securing system using server security solution and network security solution, and security system implementing the same |
KR100750377B1 (en) * | 2006-05-09 | 2007-08-17 | 한정보통신 주식회사 | Network security system based system on chip and method thereof |
KR100998284B1 (en) * | 2009-12-31 | 2010-12-03 | 신영전자통신 주식회사 | Protection switch system integrated network and security and the method thereof |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR102370848B1 (en) * | 2020-11-17 | 2022-03-07 | 주식회사 시큐브 | Computer device including divided security module and method for updating security module |
WO2022107991A1 (en) * | 2020-11-17 | 2022-05-27 | 주식회사 시큐브 | Computer device including separated security module, and method for updating security module |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US9338862B2 (en) | Techniques for remote communication with a photocontrol device | |
EP3301856A1 (en) | Router management method, router and mobile terminal | |
US9715604B2 (en) | RFID tag reading device, RFID tag reading program, and RFID tag reading method | |
EP3200074A1 (en) | Switching method, switching system and terminal for system and/or application program | |
US10959143B2 (en) | Communication connection control method, and device | |
US20180098286A1 (en) | Power consumption control method for wearable device, and wearable device | |
CN105392187A (en) | Instant messaging application program management method, device and mobile terminal | |
CN105471648A (en) | Zigbee network system and standby assistance method therefor | |
US20160050567A1 (en) | Wireless Network System, Terminal Management Device, Wireless Relay Device, and Communications Method | |
KR101429877B1 (en) | L2/L3 switch system having a function of security module updating | |
CN111344755A (en) | Radio control of sensors | |
US20160274955A1 (en) | Method and Device for Activating and Controlling Application in Multi-Screen System, and Mobile Terminal | |
WO2017051312A1 (en) | A method of enabling a lock button of a mobile device with an ios operating system to be used by a user to effect an action | |
CN105992188A (en) | Application updating method and device | |
JP2009267851A5 (en) | ||
CN108134678B (en) | VoWIFI configuration method based on SMS and terminal equipment | |
JP2014123791A (en) | Radio telemeter system | |
EP3147787A1 (en) | Method, device and terminal for setting system data | |
CN104462958A (en) | Intersystem switching method and device of terminal | |
CN109495119B (en) | Radio frequency switch control method, device, mobile terminal and storage medium | |
CN109996100B (en) | Control method of intelligent remote controller, storage medium and remote controller | |
US20170150297A1 (en) | Display device, which is equipped with a wireless interface, for the operating state of a switch device | |
KR102284194B1 (en) | Driver contact device using NFC, and the method of thereof | |
Song et al. | Elements of successful management of an imported Middle East respiratory syndrome case in Guangdong, China | |
US10004129B2 (en) | Extending coverage in an outdoor lighting system by using a mobile device and short-range wireless communications |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
E701 | Decision to grant or registration of patent right | ||
GRNT | Written decision to grant | ||
FPAY | Annual fee payment |
Payment date: 20170727 Year of fee payment: 4 |
|
FPAY | Annual fee payment |
Payment date: 20180731 Year of fee payment: 5 |
|
FPAY | Annual fee payment |
Payment date: 20190715 Year of fee payment: 6 |