File one-way safe import and export method under red-black isolation system

By combining hardware switches under the red-black isolation system with FPGA encryption and decryption boards, the security and bidirectional transmission problems of traditional isolation gateways and one-way optical gateways in file transfer are solved, realizing secure one-way file import and export and improving the confidentiality of cross-network file transfer.

CN120849359APending Publication Date: 2025-10-28JIANGSU SHENWANG TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510948116.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

In existing technologies, traditional isolation gateways have insufficient security in file transmission, and one-way optical gateways cannot meet the needs of bidirectional file transfer, and the confidentiality of cross-network remote file transfer cannot be guaranteed.

Method used

The system employs a red-black isolation mechanism, controlling the switching between one-way export and one-way import via a hardware switch. It utilizes FPGA encryption and decryption boards for file encryption and decryption, ensuring that the system can only operate in one-way mode at any given time, thus achieving secure one-way file import and export.

Benefits of technology

It enables communication in only one direction at a time, improving the confidentiality of cross-network file transfers and ensuring the security and reliability of file transfers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120849359A_ABST
    Figure CN120849359A_ABST
Patent Text Reader

Abstract

The invention discloses a one-way safe file import and export method under a red-black isolation system. Switching between one-way export processing and one-way import processing is achieved through a hardware switch. During one-way export, one-way conduction from the encryption board FPGA to the outer end machine is controlled through the hardware switch, and only the export direction is in a conduction state; and during one-way import, the hardware switch is used for controlling one-way conduction between the external end machine and the FPGA encryption board B ', so that only the import direction is in a conduction state. A hardware switch is adopted for switching control over export and import, it is ensured that the system can only work in a one-way export mode or a one-way import mode at any time, that is, it is ensured that communication can only be conducted in one direction at the same time, the requirement for bidirectional file ferrying is met, an FPGA-based hardware encryption algorithm is adopted for encryption, and the encryption efficiency is improved. And the encrypted file is transmitted to an external end machine through a one-way channel, so that the confidentiality of cross-network file transmission can be remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of digital information transmission technology, and relates to confidential or secure communication technology, specifically to a secure one-way import and export method for files under a red-black isolation system. Background Technology

[0002] With the widespread use of computer networks and the increasing awareness of network security, more and more organizations are dividing their internal departments into different network security domains based on different security levels. This necessitates secure file import and export between networks with different security levels. Currently, using traditional isolation gateways for file transfer offers high efficiency but carries the risk of network breaches and infiltration, thus compromising security. Traditional one-way optical gateways provide high security through one-way physical isolation but cannot handle bidirectional file transfers. Furthermore, the confidentiality of cross-network remote file transfers cannot be guaranteed. Summary of the Invention

[0003] To address the aforementioned issues, this invention proposes a file encryption one-way export and file decryption import method based on a red-black isolation system. This method ensures that the file can only operate in one-way export mode or one-way import mode at any given time, guaranteeing that only one direction can communicate at any given moment.

[0004] The technical solution of this invention is a one-way secure import and export method for files under a red-black isolation system. The switching between one-way export processing and one-way import processing is implemented through a hardware switch. Specifically: The one-way export process includes the following steps: S1 _ex User uploads and sends files: Through the web interface of the intranet machine, the user first clicks the "Upload" button to upload the specified file on the intranet file client. After the upload is complete, the user selects the receiving device and then clicks the "Export" button to send the file. S2 _ex The internal terminal sends files to the FPGA (Field-Programmable Gate Array) encryption board. The messages sent by the internal terminal to the FPGA encryption board are divided into file information packets and file data packets. The file information packet is the first packet, which contains file information and key generation information. The file data packets carry file fragment data. The internal terminal fragments the file into several file data packets and sends the file data packets to the FPGA encryption board in sequence through the network port. S3 _exThe FPGA encryption board performs encryption on the received file information packets and file data packets in sequence, and performs integrity protection on them. Specifically, the FPGA board extracts the source device identifier src_id, destination device identifier dst_id, key base offset offset, and random number Nonce from the file information packets. It then uses a key expansion algorithm to generate encryption MYkey_encode and integrity protection MYkey_integrity to encrypt and protect the file information packets and file data packets. Finally, it sends the encrypted and integrity-protected file information packets and file data packets to the external machine in sequence. S4 _ex External processing: If the data packet sequence numbers are consecutive and there is no packet loss, the encrypted file information and encrypted fragments are combined into an encrypted file in sequence. After receiving the last file data packet, the encrypted file is closed and displayed on the interface; if the data packet sequence numbers are not consecutive, packet loss has occurred. The interface of the external network processing board will display a packet loss error and prompt the user to restart sending on the internal network. S5 _ex The user sends the encrypted file to the shuttle: The user selects the encrypted file on the web interface of the external terminal and sends it to the communication terminal through the external terminal.

[0005] The one-way import process includes the following steps: S1 _in User uploads files: Users access the file upload interface on the external machine to import files. The files are imported to the external machine by the transfer machine, and then the user clicks the "Import" button to start the import process. S2 _in The external terminal sends files to the FPGA encryption board: The external terminal first extracts the file information packet and several file data packets from the encrypted file according to a predetermined format, and then sends the file information packet and file data packets to the FPGA encryption board B' via the network port in sequence; S3 _in B' decrypts: B' decrypts and verifies the integrity of the received file information packet and file data packet in sequence; B' then sends the decrypted file information packet and file data packet to internal machine A in sequence. S4 _in Internal processing: Extract the decrypted file information packets to form file information, extract the file payload from the decrypted file data packets, and combine them sequentially into plaintext files. After receiving the last file data packet, close the plaintext file. S5 _in User accesses the file import interface on the internal terminal to obtain plaintext files: The user logs into the file import interface on the internal terminal and sends the file to the internal network processing machine through the internal terminal.

[0006] Preferably, the S2 of the unidirectional export process _exThe file is divided into several file data packets, each containing a fragment and an identifier indicating whether it is the last fragment.

[0007] Preferably, the switching between the one-way export processing and the one-way import processing is implemented by a hardware switch. Specifically, during one-way export, the hardware switch controls the one-way conduction of the encryption board FPGA → external terminal, so that only the export direction is in the conduction state; during one-way import, the hardware switch controls the one-way conduction of the external terminal → FPGA encryption board B', so that only the import direction is in the conduction state.

[0008] This invention also discloses a red-black isolated single-port device that implements the above-mentioned red-black isolation system for secure one-way file import and export. It consists of an internal terminal, an FPGA encryption board, an FPGA decryption board, and an external terminal. The FPGA encryption board is responsible for encryption forwarding during file export, and the FPGA decryption board is responsible for decryption forwarding during file import. Both the internal terminal and the external terminal have a Web interface for users to perform export and import operations.

[0009] Preferably, the aforementioned external terminal connects to the web interface via a shuttle.

[0010] Compared with the prior art, the advantages of the present invention are: First, by using a hardware switch to control the switching between export and import, the system can only work in one-way export mode or one-way import mode at any time, that is, it can only communicate in one direction at a time, thus meeting the need for bidirectional file transfer.

[0011] Second, the confidentiality of cross-network file transfer is improved. Ordinary cross-network file transfers are generally transmitted in plaintext; if hackers monitor the process online, sensitive information can easily be leaked, compromising confidentiality. This invention employs an FPGA-based hardware encryption algorithm. The encrypted file is transmitted to the external machine via a one-way channel, significantly improving the confidentiality of cross-network file transfers. Attached Figure Description

[0012] Figure 1 This is a schematic diagram illustrating the one-way import and export process of file encryption based on the red-black isolation system of the present invention. Detailed Implementation

[0013] The invention will now be described in further detail with reference to the accompanying drawings.

[0014] Red-black isolation technology is a security protection mode based on network architecture, which divides the network into red and black zones to achieve different levels of security isolation.

[0015] like Figure 1As shown, the intranet file client uses a red-black isolated single-port device and a remote network file client to perform secure one-way file export and import.

[0016] Both the internal terminal A and the external terminal C of the single-channel device have web interfaces for users to perform export and import operations. FPGA encryption board B is responsible for encryption forwarding during file export, and FPGA decryption board B' is responsible for decryption forwarding during file import.

[0017]

One-way export processing flow

[0018] S1: User uploads and sends file: The user first clicks the "Upload" button to upload the specified file on the intranet file client through the web interface of the intranet terminal A. After the upload is complete, the user selects the receiving device and then clicks the "Export" button to send the file. S2: Internal terminal A sends a file to FPGA encryption board B: The message sent by A to B is divided into file information packets and file data packets. The file information packet is the first packet, containing file information and key generation information; the file data packets carry file fragment data. A fragments the file, forming several file data packets (each file data packet contains one fragment and has an identifier indicating whether it is the last fragment), and sends the file data packets sequentially to FPGA encryption board B via the network port; S3: Encryption by FPGA encryption board B: B encrypts and protects the received file information packets and file data packets in sequence; Specifically, the FPGA board extracts the source device identifier src_id, destination device identifier dst_id, key base offset offset, and random number Nonce from the file information packets, and generates encryption MYkey_encode and integrity protection MYkey_integrity through a key expansion algorithm, encrypting and protecting the file information packets and file data packets, and then sends the encrypted and integrity-protected file information packets and file data packets to C in sequence; S4: External terminal (C-end) processing: If the data packet sequence numbers are consecutive and there is no packet loss, the encrypted file information and encrypted fragments are sequentially combined into an encrypted file. After receiving the last file data packet, the encrypted file is closed and displayed on the interface; if the data packet sequence numbers are not consecutive, packet loss has occurred, and a packet loss error is displayed on the interface of the external network processing board, prompting the user to restart sending on the internal network.

[0019] S5: The user sends the encrypted file to the shuttle: The user selects the encrypted file on the web interface of the external terminal C, and the file is sent to the communication terminal through the external terminal C.

[0020]

One-way import processing flow

[0021] S1: User uploads file: The user accesses the file upload interface of the external terminal C to import the file. The file is imported into the external terminal C by the transfer machine, and then the user clicks the "Import" button to start the import. S2: C sends a file to B': C first extracts the file information packet and several file data packets from the encrypted file according to a predetermined format, and then sends the file information packet and file data packets to the FPGA decryption board B' via the network port in sequence; S3: B' decrypts: B' decrypts and verifies the integrity of the received file information packet and file data packet in sequence; B' then sends the decrypted file information packet and file data packet to internal machine A in sequence; S4: Processing at end A: Extract the decrypted file information packets to form file information, extract the file payload from the decrypted file data packets, and combine them sequentially to form a plaintext file. After receiving the last file data packet, close the plaintext file.

[0022] S5: User accesses file import interface on A to obtain plaintext file: User logs in to file import interface on A and sends it to internal network processor through internal terminal A.

[0023] In the above technical solution of the present invention, it can only work in one-way export mode or one-way import mode at any time, which can ensure that only one direction can communicate at the same time.

[0024] The above description, in conjunction with specific preferred technical solutions, provides a further detailed explanation of the present invention and should not be construed as limiting the specific implementation of the invention to these descriptions. It should be noted that those skilled in the art can make various modifications without departing from the principles of the invention, and these modifications should also be considered to fall within the scope of protection of the present invention.

Claims

1. A method for secure one-way import and export of files under a red-black isolation system, characterized in that, Switching between one-way export and one-way import processing is achieved via a hardware switch. The one-way export process includes the following steps: S1 _ex User uploads and sends files: Through the web interface of internal terminal A, the user first clicks the "Upload" button to upload the specified file on the intranet file client. After the upload is complete, the user selects the receiving device and then clicks the "Export" button to send the file. S2 _ex Internal terminal A sends a file to FPGA encryption board B: The message sent by internal terminal A to FPGA encryption board B is divided into file information packets and file data packets. The file information packet is the first packet, which contains file information and key generation information. The file data packets carry file fragment data. Internal terminal A fragments the file into several file data packets and sends the file data packets to FPGA encryption board B in sequence through the network port. S3 _ex FPGA encryption board B performs encryption: FPGA encryption board B encrypts and protects the integrity of the received file information packets and file data packets in sequence; Specifically, the FPGA board extracts the source device identifier src_id, destination device identifier dst_id, key base offset offset, and random number Nonce from the file information packets, and generates encryption MYkey_encode and integrity protection MYkey_integrity through a key expansion algorithm, encrypting and protecting the file information packets and file data packets in sequence, and then sends the encrypted and integrity-protected file information packets and file data packets to the external machine C in sequence; S4 _ex External terminal (C-end) processing: If the data packet sequence numbers are consecutive and there is no packet loss, the encrypted file information and encrypted fragments are sequentially combined into an encrypted file. After receiving the last file data packet, the encrypted file is closed and displayed on the interface; if the data packet sequence numbers are not consecutive, packet loss has occurred. The interface of the external network processing board will display a packet loss error and prompt the user to restart sending on the internal network. S5 _ex The user sends the encrypted file to the shuttle: The user selects the encrypted file on the web interface of the external terminal C, and the file is sent to the communication terminal through the external terminal C; The one-way import process includes the following steps: S1 _in User uploads files: The user accesses the file upload interface of the external terminal C to import the file. The file is imported into the external terminal C by the transfer machine, and then the user clicks the "Import" button to start the import. S2 _in C sends a file to B': C first extracts the file information packet and several file data packets from the encrypted file according to a predetermined format, and then sends the file information packet and file data packets to the FPGA decryption board B' via the network port in sequence; S3 _in B' decrypts: B' decrypts and verifies the integrity of the received file information packet and file data packet in sequence; B' then sends the decrypted file information packet and file data packet to internal machine A in sequence. S4 _in A-end processing: Extract the decrypted file information packet to form file information, extract the file payload from the decrypted file data packet, and combine them sequentially into a plaintext file. After receiving the last file data packet, close the plaintext file. S5 _in User accesses file import interface on A to obtain plaintext file: User logs in to file import interface on A and sends it to internal network processor through internal terminal A.

2. The method for one-way secure import and export of files under the red-black isolation system according to claim 1, characterized in that, S2 of the one-way export process _ex The file is divided into several file data packets, each containing a fragment and an identifier indicating whether it is the last fragment.

3. The method for one-way secure import and export of files under a red-black isolation system according to claim 1, characterized in that, The switching between unidirectional export processing and unidirectional import processing is implemented through a hardware switch. Specifically, during unidirectional export, the hardware switch controls the unidirectional conduction of encryption board B → external terminal C, so that only the export direction is in the conduction state; during unidirectional import, the hardware switch controls the unidirectional conduction of external terminal C → FPGA decryption board B', so that only the import direction is in the conduction state.

4. A red-black isolated single-export device for implementing the one-way secure import / export method for files under the red-black isolation system as described in claim 1, characterized in that... It consists of an internal terminal A, an FPGA encryption board B, an FPGA decryption board B', and an external terminal C. The FPGA encryption board B is responsible for encryption forwarding during file export, and the FPGA decryption board B' is responsible for decryption forwarding during file import. Both the internal terminal A and the external terminal C have a web interface for users to perform export and import operations.

5. The red-black isolation single-conductor device according to claim 4, characterized in that... External terminal C connects to the web interface via a shuttle.