A unidirectional secure data transmission structure and method for internal and external network isolation
By using UDP multicast and TS streaming card distribution methods in the one-way secure data transmission structure isolated by internal and external networks, the secure one-way transmission of intranet data is realized, solving the problem of data leakage and mismatch in transmission protocols, and supporting data transmission and remote operation and maintenance in broadcasting and television systems.
Patent Information
- Application Number
- CN202010913124.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-03
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2040-09-03
AI Technical Summary
When the prior art realizes the secure one-way transmission of intranet data, there is a problem of data leakage and mismatch between transmission protocols, especially in broadcasting and television systems, it is difficult to transmit data through digital TV multiplexers and modulators.
The one-way secure data transmission structure is isolated from the internal and external networks, including the intranet operation and maintenance data signal processing system, a one-way fiber multicast code streaming transmission unit and a one-way ASI code streaming transmission device. The one-way data transmission is realized through UDP multicast and TS code streaming issuance cards, and the operation and maintenance data is transmitted on the public network through the streaming media protocol.
It realizes secure one-way transmission of intranet data, avoids data leakage, solves the problem of mismatch in transmission protocols, can transmit data through digital TV devices in the radio and television system, and supports remote operation and maintenance and mobile operation and maintenance.
Smart Images

Figure CN111901688B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of unidirectional data transmission, and particularly to a unidirectional secure data transmission structure and method with internal and external isolation. Background Art
[0002] The unidirectional data transmission technology realizes point-to-point data transmission in a simplex manner. For example, the infrared data transmission of an infrared remote control, the TV reception of an analog TV system, and the received FM radio station are all unidirectional data transmission methods. The data sending end can only send data and cannot receive data, while the data receiving end can only receive data and cannot send data.
[0003] Such a data transmission method seems to return to the era when one can only listen to or watch data, such as TV and radio, and cannot actively order programs, which seems to run counter to the progress of current technology and violates the law of technological development. However, everything has two sides. Unidirectional data communication seems very backward, but such data is very secure. The receiver only listens to the data and cannot send data to the sender, which can ensure the security of the internal data of the sender and prevent it from being hacked and causing the system crash of the sending end. If the sending end is a TV station or a power plant, the consequences will be unimaginable.
[0004] In recent years, with the increasing attention to network security, the unidirectional data transmission method has been used in different scenarios, basically adopting physical methods of unidirectional data transmission, including infrared data, optical fiber data, etc. At the same time, various methods are also used to switch the backhaul data channels, using physical or firewall methods. The purpose is that data can be obtained, but there must be no feedback data interference. Therefore, unidirectional data transmission is gradually applied to secure data transmission.
[0005] A firewall is a system composed of computer hardware and software, deployed at the network boundary, which is a connection bridge between the internal network and the external network. At the same time, it protects the data passing through the network boundary, preventing malicious intrusion, the spread of malicious code, etc., and ensuring the security of the internal network data. Firewall technology is an applied security technology based on network technology and information security technology. Almost all enterprise internal networks are connected to the external network (such as the Internet) with firewalls placed at the boundaries. The firewall can play a role in security filtering and isolating harmful network security information and behaviors such as external network attacks and intrusions.
[0006] Gatediode:
[0007] A network isolation device is an information security device that uses a solid-state switch reading and writing medium with multiple control functions to connect two independent host systems. Since the two independent host systems are isolated by the network isolation device, there is no physical connection, logical connection, or information transmission protocol for communication between the systems, and there is no information exchange based on the protocol. Instead, there is only protocol-free ferry in the form of data files. Therefore, the network isolation device logically isolates and blocks all network connections that may potentially attack the internal network, preventing external attackers from directly invading, attacking, or damaging the internal network and ensuring the security of internal hosts.
[0008] Unidirectional network isolation device:
[0009] To ensure that data in a high-security-level network cannot flow to a low-security-level network, but data in the low-security-level network can flow to the high-security-level network (data confidentiality requirement) and completely solve the problem of information leakage in the high-security-level network, only unidirectional transmission technology without feedback can be adopted. The developed security isolation and information unidirectional import system adopts the unique "unidirectional non-feedback transmission" technology to ensure the absolute unidirectional flow of data from the physical link layer and the transport layer. At the same time, the system adopts original and advanced error correction coding technology, ASIC parallel processing technology, and MRP (multiple redundancy technology) to ensure the high reliability, high fault tolerance, high security, and high stability of the system.
[0010] Based on unidirectional optical transmission network cards with different hardware, there are many unidirectional transmission fiber network cards on the market that can achieve unidirectional data transmission, that is, data can only be transmitted in one direction and there cannot be a reverse link or channel. For example: data can only go out and not come in, and can only be sent from a high-security network to a low-security network, and there cannot be a reverse connection.
[0011] Optical code unidirectional transmission. The optical code machine displays the data in the high-security domain on the display device in the form of two-dimensional codes. The device at the other end reads the two-dimensional codes on the display device, parses and restores them to the original data, and sends them to the low-security domain. There is no electrical connection between the display device and the reading device, which is complete physical isolation.
[0012] UDP multicast. UDP is a connectionless protocol. Before transmitting data, no connection is established between the source end and the terminal. When it wants to transmit, it simply grabs the data from the application program and throws it onto the network as quickly as possible. At the sending end, the speed of UDP transmitting data is only limited by the speed of the application program generating data, the capabilities of the computer, and the transmission bandwidth; at the receiving end, UDP places each message segment in a queue, and the application program reads one message segment from the queue each time.
[0013] TS stream, in the MPEG2 format in DVD programs. The full name of TS is Transport Stream. MPEG-TS is mainly applied to programs for real-time transmission, such as live broadcast TV programs. TS is the abbreviation of "Transport Stream". It is sent in packets, and each packet is 188 bytes long. Many types of data can be filled in the TS stream, such as video, audio, custom information, etc. The structure of its packet is that the packet header is 4 bytes and the payload is 184 bytes.
[0014] The multiplexer of digital TV programs mainly completes the re-multiplexing function of the MPEG-2 transport stream (TS) to form a multi-program transport stream (MPTS) for the transmission task of digital TV programs. The so-called statistical multiplexing means that the bitrates of the multiplexed programs are not constant, and the principle of allocating bitrates according to the image complexity is implemented among the programs. Since each channel (standard or supplementary) can transmit multiple programs and the image complexities of the programs at the same moment are different (the probability of being the same is very small), we can allocate bitrates among the programs in the same channel according to the image complexity to achieve statistical multiplexing. The key factors for implementing statistical multiplexing are: one is how to evaluate the image complexity at any time for the image sequence, and there are two methods, subjective evaluation and objective evaluation; the other is how to dynamically allocate the bandwidth of the video service in a timely manner. Using statistical multiplexing technology can improve the compression efficiency, improve the image quality, facilitate the transmission of multiple sets of programs in one channel, and save the transmission cost.
[0015] The digital TV modulator functions to modulate the video signal (VIDEO) and audio signal (AUDIO) provided by the signal source (which can be an AV signal source such as a digital TV set-top box, satellite TV receiver, telecom IPTV set-top box, DVD or VCD player, computer, surveillance camera, TV demodulator, etc.) into a stable high-frequency radio frequency oscillation signal. The video is in amplitude modulation mode and the audio is in frequency modulation mode. The digital TV modulator is widely used in the transformation of the front end of digital cable TV to modulate the audio and video signals into radio frequency signals. The input audio and video signals can be continuously adjusted through external adjustment knobs, allowing the input of a video signal source signal of 0.7 - 1.4V and an audio signal of 0.775V ± 10dB. Under normal frequency deviation conditions, the modulator can also be continuously adjusted externally to make the output image normal. The product uses frequency synthesis technology with high frequency stability.
[0016] TS over IP technology. TS over IP technology is to transmit the TS stream of digital TV through IP. In real time, the UDP transport protocol is generally selected, which is applicable to the stream transmission protocol of multicast mode. At the same time, the multicast transmission mode of TS over IP is applicable to the IP-based devices of digital TV, including multiplexers and modulators, for data multiplexing and modulation, thus saving the data transmission bandwidth and anti-interference ability.
[0017] As Figure 1 shown, the existing firewall can play the role of security filtering and security isolation of harmful network security information and behaviors such as external network attacks and intrusions. Such a technology is to set up a firewall at the boundary where the internal network is connected to the external network, and at the same time set the access rights of the external network in software to shield external network attacks. Such a method does not adopt the physical isolation method. If a malicious attacker breaks through the firewall, the security of the internal network data cannot be guaranteed. As can be seen from the above figure, the internal and external network data are isolated by the firewall. Because it is a two-way network, if the firewall is invaded, it may cause the internal network to be paralyzed. Secondly, in this way, data that is not in the digital TV protocol cannot be transmitted by the lower-level digital TV multiplexer and modulator.
[0018] As Figure 2 shown, the existing network isolation technology is an information security device that uses a solid-state switch reading and writing medium with multiple control functions to connect two independent host systems. Since the two independent host systems are isolated by the network isolation device, there is no physical connection, logical connection and information transmission protocol for communication between the systems, and there is no information exchange based on the protocol, but only protocol-free ferry in the form of data files. The network isolation device only logically isolates and blocks all network connections that may potentially attack the internal network, so that external attackers cannot directly invade, attack or damage the internal network, ensuring the security of internal hosts. In fact, the network isolation device is also a soft isolation, and there is still a link connected. At present, the main mode is to wire the internal and external networks separately. However, in order to meet the needs of some special internal services to connect to the external network, the internal network interacts with the external network through the network isolation device, which is still a two-way communication, so there is also a risk of internal network data leakage. At the same time, in this way, due to the problem of the transport protocol, the data output from the internal network cannot be transmitted by the digital TV multiplexer and modulator and finally provided to the digital TV receiving terminal.
[0019] As Figure 3As shown in the figure, existing unidirectional network gates ensure that data in high-security-level networks cannot flow to low-security-level networks, but data in low-security-level networks can flow to high-security-level networks (data confidentiality requirements). To completely solve the problem of information leakage in high-security-level networks, only unidirectional transmission technology without feedback can be adopted. The developed security isolation and information unidirectional import system adopts a unique "unidirectional non-feedback transmission" technology to ensure the absolute unidirectional flow of data from the physical link layer and the transport layer. The unidirectional network gate physically blocks the feedback link signal to achieve high security. However, there are still two problems. One problem is that although the internal network will not be attacked, the data may be leaked. Another problem is that in the radio and television system, due to data transmission protocol issues, unidirectional data sending cannot pass through digital TV multiplexers and modulators, and at the same time, data cannot be transmitted through streaming media protocols.
[0020] As Figure 4 shown, there are many unidirectional transmission fiber optic network cards on the market now, which can achieve unidirectional data transmission, that is, data can only be transmitted in one direction and there cannot be a reverse link or channel. This is mainly achieved by only connecting the single-transmission fiber to the fiber optic network card without connecting the receiving fiber, so as to realize the unidirectional output of data. The problems existing in this method are the same as those of the unidirectional network gate. There are two problems. One problem is that although the internal network will not be attacked, the data may be leaked. Another problem is that in the radio and television system, due to data transmission protocol issues, unidirectional data sending cannot pass through digital TV multiplexers and modulators, and at the same time, data cannot be transmitted through streaming media protocols.
[0021] As Figure 5 shown, the optical code machine displays the data in the high-security domain on the display device in the form of a two-dimensional code. The device at the other end reads the two-dimensional code on the display device, parses and restores it to the original data, and then sends it to the low-security domain. There is no electrical connection between the display device and the reading device, which is completely physically isolated. There are three problems. One problem is that the operation is complex and additional hardware devices and daily personnel operation and maintenance are required. Another problem is that although the internal network will not be attacked, the data may be leaked. The last problem is that in the radio and television system, due to the digital TV data transmission format problem, unidirectional data sending cannot pass through digital TV multiplexers and modulators, and at the same time, data cannot be transmitted through streaming media protocols.
[0022] Disadvantages of existing firewall technologies: They do not adopt physical isolation. If a malicious attacker breaks through the firewall, it will also lead to attacks and intrusions. At the same time, using such a method, due to data transmission protocol issues, the data output from the internal network cannot pass through digital TV multiplexers and modulators for data transmission and finally be provided to the digital TV receiving terminal.
[0023] Disadvantages of existing network isolation gate technologies: In fact, a network isolation gate is also a soft isolation, and there is still a two-way link connection. Currently, the main mode is to lay separate cables for the internal and external networks. However, to meet the needs of certain special internal services to connect to the external network, the internal network interacts with the external network through the network isolation gate, and it is still a two-way communication. In this way, there is also a risk of internal network data leakage. At the same time, with this method, due to problems with the transmission protocol, the data output from the internal network cannot be transmitted through a digital TV multiplexer or modulator and finally provided to the digital TV receiving terminal.
[0024] Disadvantages of one-way network isolation gates: There are two problems. One problem is that although the internal network will not be attacked, the data may still be leaked. Another problem is that in a broadcast television system, one-way data transmission cannot pass through a digital TV multiplexer and modulator, and at the same time, data cannot be transmitted through a streaming media protocol.
[0025] Disadvantages of one-way optical transmission network cards: There are two problems. One problem is that although the internal network will not be attacked, the data may be leaked. Another problem is that in a broadcast television system, one-way data transmission cannot pass through a digital TV multiplexer and modulator, and at the same time, data cannot be transmitted through a streaming media protocol.
[0026] Disadvantages of optical code one-way transmission: There are three problems. One problem is that the operation is complex and requires additional hardware devices and daily personnel operation and maintenance. Another problem is that although the internal network will not be attacked, the data may be leaked. The last problem is that in a broadcast television system, one-way data transmission cannot pass through a digital TV multiplexer and modulator, and at the same time, data cannot be transmitted through a streaming media protocol. Summary of the Invention
[0027] To solve the above technical problems, the object of the present invention is to provide a one-way secure data transmission structure and method for internal and external network isolation. This structure and method solve the problem of transmitting internal network data to the external network in a secure manner, realize the application of internal network data on the external network, and at the same time prevent the external network from accessing the internal network in the reverse direction, thus avoiding the possibility of attacking the internal network; solve the problem of data format by using a transmission protocol suitable for broadcast television to send data files, enabling data to be transmitted in digital TV devices; solve the problem of public network data transmission by using a streaming media protocol, enabling data to be transmitted on the public network; solve the problem of one-way data transmission by using one-way optical data transmission and an ASI (TS) stream broadcast card to achieve one-way data output.
[0028] The object of the present invention is achieved through the following technical solutions:
[0029] A one-way secure data transmission structure with internal and external network isolation, comprising: an internal network operation and maintenance data signal processing system, a one-way optical fiber multicast stream transmission unit, and a one-way ASI stream transmission device; the internal network operation and maintenance data signal processing system is interconnected with the one-way optical fiber multicast stream transmission unit and the one-way ASI stream transmission unit.
[0030] A UDP multicast device and a TS stream broadcast card are provided in the internal network operation and maintenance data signal processing system;
[0031] The UDP multicast device includes a data acquisition module, an internal network database server, a local file generation module, a TS file generation module, and a UDP multicast stream generation module; the data acquisition module is respectively connected to the internal network database server and the local file generation module, and sends a message file to the local file generation module; the local file generation module is connected to the TS file generation module, and sends a message data file and a configuration data file to the TS file generation module; the TS file generation module is connected to the UDP multicast stream generation module, and sends a TS file to the UDP multicast stream generation module; the UDP multicast stream generation module is connected to the TS stream broadcast card, and sends a UDP multicast stream to the TS stream broadcast card.
[0032] The TS stream broadcast card includes an internal network data acquisition module, a network database server, a local file generation module, a TS file generation module, and a TS / ASI stream broadcast module; the internal network data acquisition module is respectively connected to the database server and the local file generation module, and sends a message file to the local file generation module; the local file generation module is connected to the TS file generation module, and sends a message data file and a configuration data file to the TS file generation module; the TS file generation module is connected to the TS / ASI stream broadcast module, and sends a TS file to the TS / ASI stream broadcast module.
[0033] A one-way secure data transmission method with internal and external network isolation, comprising:
[0034] Step 10: Collect data of all devices in the radio and television broadcast system, generate a TS file from the collected data, and send the TS file in the form of a UDP multicast stream or output it through a TS stream broadcast card;
[0035] Step 20: Transmit the received multicast stream in a one-way optical fiber multicast transmission manner;
[0036] Step 30: The ASI signal output by using the TS stream broadcast card is encapsulated into a UDP multicast and provided to the external network data receiving gateway and the database server through one path; and the ASI signal is directly provided to the television multiplexing device through another path.
[0037] Compared with the prior art, one or more embodiments of the present invention may have the following advantages:
[0038] By encapsulating the operation and maintenance data of radio and television in the TS format, it is applicable to the mechanism of digital television broadcasting to transmit operation and maintenance data, and the broadcast method is adopted to achieve unidirectional data transmission.
[0039] Adopting the TS OVER IP method, through the multicast protocol of digital television standards, the unidirectional transmission of UDP data is realized. Such a method is applicable to optical network cards, and can physically realize the data transmission of single optical fiber. At the same time, the UDP protocol is also applicable to data discovery without a handshake protocol. The advantage of this is that only unidirectional data transmission is performed, without backhaul data, and it will not threaten the internal network security.
[0040] Adopting an ASI stream broadcast card to achieve the transmission of TS files. Through the TS encapsulation protocol of digital television standards, a unidirectional ASI stream broadcast card is used to achieve the unidirectional transmission of TS file data. The advantage of this is that only unidirectional data transmission is performed, without backhaul data, and it will not threaten the internal network security.
[0041] Whether it is the method of ASI broadcast card or the method of UDP multicast transmission, ultimately, the operation and maintenance data can be transmitted using the streaming media protocol on the public network. In this way, the operation and maintenance data can be transmitted using the public network, expanding the scope of system operation and maintenance, and realizing remote operation and maintenance and mobile operation and maintenance.
[0042] Before the operation and maintenance data to be transmitted is encapsulated into a TS file, the MD5 method is adopted to encrypt the file. By adopting this method, on the one hand, the integrity verification of the transmitted file can be achieved through MD5, and on the other hand, a similar MD5 encryption method can be used to achieve the security of the transmitted data content.
[0043] Adopting the digital television standard protocol and the streaming media protocol for the unidirectional transmission of operation and maintenance data is a first. On the one hand, it meets the needs of its own radio and television security and operation and maintenance. More importantly, the entire data transmission mechanism is completely based on radio and television communication, which can realize the sharing of transmission equipment resources, reduce the system input cost, and can combine with digital television services to achieve the safe and unidirectional transmission of data.
[0044] An internal and external network database is established. At the same time, the TS file transmission method is adopted, and a timer is used to realize the internal and external network inventory data. At the same time, the mechanism of internal network data secure forwarding is adopted, and the method of incremental data internal and external network synchronization is also realized. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1It is a schematic diagram of the structure of existing firewall technology;
[0046] Figure 2 It is a schematic diagram of the structure of existing network isolation gateway technology;
[0047] Figure 3 It is a schematic diagram of the structure of existing unidirectional network isolation gateway technology;
[0048] Figure 4 It is a schematic diagram of the structure of existing unidirectional optical transmission network card technology based on different hardware;
[0049] Figure 5 It is a schematic diagram of the structure of existing optical code unidirectional transmission technology;
[0050] Figure 6 It is a schematic diagram of the structure of unidirectional secure data transmission for internal and external network isolation;
[0051] Figure 7 It is a flowchart of the method for unidirectional secure data transmission for internal and external network isolation;
[0052] Figure 8 It is a structure diagram of a UDP multicast device;
[0053] Figure 9 It is a structure diagram of the output data of a TS file using a stream playback card;
[0054] Figure 10 It is a structure diagram of unidirectional optical fiber multicast stream transmission;
[0055] Figure 11 It is a structure diagram of a multicast data gateway;
[0056] Figure 12 It is a flowchart of the forwarding structure of multicast and streaming media data;
[0057] Figure 13 It is a structure diagram of the signal processing of a digital TV receiving terminal;
[0058] Figure 14 It is a structure diagram of data reception between a mobile terminal and a fixed terminal;
[0059] Figure 15 Structure diagram of the unidirectional ASI stream transmission method;
[0060] Figure 16 It is a structure diagram of ASI signal loop-through output and IP multicast output. Detailed implementation manner
[0061] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with embodiments and the accompanying drawings.
[0062] Such as Figure 6As shown, the one-way secure data transmission structure with internal and external network isolation includes: an internal network operation and maintenance data signal processing system, a one-way optical fiber multicast code stream transmission unit and a one-way ASI code stream transmission device; the internal network operation and maintenance data signal processing system is interconnected with the one-way optical fiber multicast code stream transmission unit and the one-way ASI code stream transmission unit.
[0063] Figure 7 The one-way secure data transmission method for isolating the internal and external networks includes the following steps:
[0064] Step 10 collects data from all devices in the radio and television broadcasting system, generates TS files from the collected data, and sends the TS files through UDP multicast stream mode or outputs them through TS stream broadcasting card mode;
[0065] Step 20 transmits the received multicast code stream in a unidirectional optical fiber multicast transmission mode;
[0066] Step 30 uses a TS code stream broadcast card to output the ASI signal, and encapsulates the ASI signal into UDP multicast through one path to provide it to the external network data receiving gateway and database server; and directly provides the ASI signal to the TV multiplexing device through another path.
[0067] The above-mentioned intranet operation and maintenance data signal processing system: The radio and television system is composed of a variety of radio and television professional equipment, basic IT equipment, power environment system and other different equipment and subsystems, covering every link from program production, processing and distribution. The operation and maintenance management of the radio and television system is an important guarantee for safe broadcasting. Figure 6 Point A is the intranet data collection server, which can collect data from all devices in the radio and television broadcasting system. The collected data is stored in the database server through the internal switch, and the upper-level application platform loads different business applications through the database data.
[0068] However, with the development of technology, local operation and maintenance can no longer meet the needs of operation and maintenance. This requires the collected data to be applied on the external network. Once the internal network and the external network are connected, it will bring risks to the security of the internal network system. This method and structure is to solve the problem of how to safely transmit data from a high-security, high-security internal network to a low-level external network.
[0069] The above-mentioned intranet operation and maintenance data signal processing system is provided with a UDP multicast device and a TS code stream broadcast card; Figure 8As shown in the figure, the UDP multicast device includes a data acquisition module, an intranet database server, a local file generation module, a TS file generation module, and a UDP multicast stream generation module. The data acquisition module is respectively connected to the intranet database server and the local file generation module, and sends a message file to the local file generation module. The local file generation module is connected to the TS file generation module, and sends a message data file and a configuration data file to the TS file generation module. The TS file generation module is connected to the UDP multicast stream generation module, and sends a TS file to the UDP multicast stream generation module. The UDP multicast stream generation module is connected to the TS stream broadcast card, and sends a UDP multicast stream to the TS stream broadcast card.
[0070] The above intranet operation and maintenance data is output by means of UDP multicast:
[0071] In the first step, the data collected is first generated into a TS file. The entire software structure is shown in Figure 8 , the intranet data acquisition module collects data, stores the data in the intranet database server through the intranet switch, and at the same time forwards a copy of the data to the local file generation module. The local file generation module generates two different file types from the collected data, including a configuration data file and a message data file. The configuration data file is a file in which the configuration data of the devices and systems of the entire radio and television system is encapsulated into one type of file, and the message data file includes data such as alarm data and device status encapsulated into another type of file. Among them, the configuration data file needs to be saved separately on the local server, which is for the future synchronization service of the configuration data files of the internal and external networks. The real-time generated incremental configuration data file and message data file enter the TS file generation module, and the two different types of files are generated into a TS file in real time. The TS file is finally provided to the IP multicast stream generation module and output through the UDP stream optical network card. The function of the timer is to periodically convert the configuration data file stored in the intranet into a TS file, or provide it to the external network database through the ASI interface or multicast for configuration data synchronization.
[0072] In the second step, the TS file is sent by means of UDP multicast. Each 1316-byte TS packet can be encapsulated into a UDP packet according to 2-7 TS packets, and a multicast stream is generated by using the TS OVER UDP method. The multicast stream is pushed and output through the optical network card.
[0073] The output multicast stream is output through the optical network card. The multicast output by the optical network card only outputs the stream through the TX port to the downstream device, and does not receive the data of the downstream device, realizing the unidirectional transmission of UDP multicast data.
[0074] Implement the MD5 encryption of the transmitted file. After encryption, it is encapsulated into a TS file for transmission. In this way, the integrity and security of the transmitted file at the receiving end are ensured.
[0075] As Figure 9 shown, the TS stream broadcast card includes an intranet data acquisition module, a network database server, a local file generation module, a TS file generation module, and a TS / ASI stream broadcast module; the intranet data acquisition module is respectively connected to the database server and the local file generation module, and sends a message file to the local file generation module; the local file generation module is connected to the TS file generation module, and sends a message data file and a configuration data file to the TS file generation module; the TS file generation module is connected to the TS / ASI stream broadcast module, and sends a TS file to the TS / ASI stream broadcast module.
[0076] The intranet operation and maintenance data is output in the form of a TS stream broadcast card:
[0077] In the first step, first complete the generation of a TS file from the collected data. The entire software structure is shown in Figure 8 , the intranet data acquisition module collects data, stores the data in the intranet database server through the intranet switch, and at the same time forwards a copy of the data to the local file generation module. The local file generation module generates two different file types from the collected data, including a configuration data file and a message data file. The configuration data file is a file in which the configuration data of the devices and systems of the entire radio and television system is encapsulated into one type of file, and the message data file includes data such as alarm data and device status encapsulated into another type of file. Among them, the configuration data file needs to be saved separately on the local server, which is for the future synchronization service of the inventory configuration data files of the internal and external networks. The real-time generated incremental configuration data file and message data file enter the TS file generation module, and the two different types of files are generated into a TS file in real time. The TS file is finally provided to the ASI (TS) stream broadcast card for hardware output. The function of the timer is to periodically convert the stored configuration data file into a TS file and provide it to the external network database for configuration data synchronization through the ASI interface or multicast.
[0078] In the second step, the TS file is output through the TS stream broadcast card. The TS stream broadcast card is a hardware device used in the digital television system to realize the output of the TS stream in the form of an ASI port. This hardware can only output unidirectionally and does not have bidirectional functions.
[0079] Implement the MD5 encryption of the transmitted file. After encryption, it is encapsulated into a TS file for transmission. In this way, the integrity of the transmitted file at the receiving end is determined and security is ensured.
[0080] As Figure 10 shown, the above-mentioned unidirectional optical fiber multicast stream transmission unit includes an intranet data acquisition server, an extranet data receiving gateway, a database server, a digital TV multiplexing device, a digital TV modulation device, a digital TV receiving terminal, a switch, a mobile terminal and a fixed terminal;
[0081] The intranet data acquisition server is connected to the extranet data receiving gateway and the database server; the extranet data receiving gateway and the database server are respectively connected to the digital TV multiplexing device and the switch; the digital TV multiplexing device is connected to the digital TV modulation device; the digital TV modulation device is connected to the digital TV receiving terminal; the switch is connected to the mobile terminal and the fixed terminal through the network respectively.
[0082] Unidirectional optical fiber multicast stream transmission mode: Adopt the transmission mode of unidirectional optical fiber multicast stream (such as Figure 11 ), where Mode A receives the unidirectional multicast stream data from point A on the intranet side, and the following is described in separate links:
[0083] Point B1, the extranet side data receiving gateway and the database server:
[0084] The software of the gateway is deployed on the server at Point B1 to restore the received multicast stream into a data file, as shown in Figure Ten . The multicast stream from point A on the intranet side is received through an optical board card, the multicast stream is parsed through software to restore the configuration file data and the message file data, and at the same time the integrity and security of the data are verified through MD5. The complete and secure data (configuration file data, message file data) is stored in the database of this server, and at the same time the data (configuration file data, message file data) is also sent downward to the lower level in the original multicast mode. At this point, it is actually the extranet side link, and the data on this side can all adopt the two-way communication mode in the transmission mode.
[0085] In this link, for the processing of the database, it includes the timing synchronization of the stock data and the real-time synchronization mechanism of the incremental data. Only in this way can the upper-layer application software obtain the data in real time and synchronize the application content in real time.
[0086] As Figure 12 shown, an optical fiber receiving network card, a multicast data parsing gateway module, a multicast data forwarding module and a streaming media data protocol gateway module are deployed on the extranet data receiving gateway and the database server; the optical fiber receiving network card is connected to the multicast data gateway module and sends the multicast stream to the multicast data gateway module; the multicast data parsing gateway module is connected to the multicast data forwarding module; the multicast data forwarding module is connected to the streaming media data protocol gateway module.
[0087] The software of the data parsing gateway is deployed on the B1 point server, which restores the received multicast stream into a data file. At the same time, it can also forward the received multicast to provide it to the next-level digital TV system. See Figure 12 , receive the multicast stream from A through the optical board card, parse the multicast stream through the software in the multicast data gateway module, and restore the configuration file data and message file data. Store the configuration file data and message file data in the database of this server. At the same time, forward the multicast through the multicast data forwarding module. During the forwarding process, the multicast address and port number can be modified and sent to the next-level digital TV system device. At this point, it is actually the external network link. In the transmission of the signal data of the digital TV system, it is still a one-way data transmission.
[0088] The streaming media protocol gateway module is deployed on the B1 point server. This module can perform protocol conversion on the received multicast, convert it into streaming media protocols such as RTSP, HLS, and SRT for forwarding, and provide it to the next-level non-digital TV system. See Figure 12 , receive the multicast stream from A through the optical board card, parse the multicast stream through the software, and restore the configuration file data and message file data. Store the configuration file data and message file data in the database of this server. At the same time, the UDP data can be converted into streaming media protocols such as RTSP, HLS, and SRT through the streaming media data gateway module and sent to the next-level network system. At this point, it is actually the external network link. The subsequent devices include but are not limited to switches, routers, servers, etc.
[0089] C1 point, digital TV multiplexing equipment
[0090] This system serves the radio and television platform, and it is also hoped that the maintenance information of the system can be published through the digital TV system. This requires that the multicast stream received from the B1 point is a standard TS OVER IP stream. The reason for adopting such a method and structure is also for this point. The stream from the B1 point to the multiplexer can be multiplexed with other radio and television streams to achieve the output of the multiplexed stream.
[0091] E1 point, digital TV modulation equipment
[0092] Similarly, for the digital TV debugging equipment, the input also needs to be a standard TS OVER IP stream. The E1 point receives the standard stream from the C1 point of the multiplexer, modulates the stream and outputs it, and outputs it to the set-top box or other terminals through the HFC network.
[0093] Such as Figure 13As shown in the figure, the digital TV receiving terminal includes a QAM signal receiving device, an optical fiber receiving network card, a multicast data gateway, and a multicast data forwarding unit; the QAM signal receiving device is connected to the optical fiber receiving network card; the optical fiber receiving network card is connected to the multicast data gateway; the multicast data gateway is connected to the multicast data forwarding unit.
[0094] Point F1, Digital TV Receiving Terminal
[0095] Through the digital TV receiving terminal, the QAM signal output after digital TV debugging at point E1 is received, and the QAM signal is demodulated and demultiplexed to output a multicast stream (see Figure 13 ). The multicast stream is parsed by software to restore the configuration file data and message file data, and the integrity and security of data transmission are verified through MD5. The secure and complete data stores the configuration file data and message file data in the database of the local server, and at the same time, the configuration file data and message file data are protocol-converted into a streaming media protocol through UDP and sent to the next-level switch or service application terminal. At this point, it is actually the external network link, and two-way communication can be carried out for the subsequent data. The upper-layer application software can receive incremental data in real time, and at the same time, it can also access the database server to obtain historical data and publish the data to the application terminal.
[0096] Point G1, Switch Data Distribution
[0097] The switch at point G1 receives the streaming media protocol data from point B1. These streaming media data are the data after the operation and maintenance data are protocol-converted through UDP. Since the possibility of UDP data transmission in the public network is very small, the streaming media protocol conversion mainly ensures that the operation and maintenance data can be transmitted in the public network, so the streaming media protocol method is adopted, which is also an important part of the solution method and structure in this scheme.
[0098] Point H2, Network
[0099] The streaming media data output through the switch at point G1 is transmitted through the public network, including the transmission of 4G and 5G networks, to achieve the secure transmission of operation and maintenance data in the public network.
[0100] As Figure 14 shown in the figure, the mobile terminal and the fixed terminal are connected to the web application module and the multicast data gateway through the public network or the local area network, and the web application module and the multicast data gateway transmit data files to each other; the multicast data gateway is interconnected with the streaming media data gateway, and the streaming media data gateway converts the streaming media data into UDP multicast data and transmits it to the multicast data gateway; the streaming media data gateway is connected to the local switch, and the switch transports the streaming media data to the streaming media data gateway.
[0101] Points I1 and J1 obtain streaming media information through the public network and input it into the local switch. First, the streaming media data gateway converts the streaming media data (RTSP, HLS, SRT) into UDP multicast data (see Figure 14 ). Then, through the multicast data gateway, the software parses the multicast bitstream to restore the configuration file data and message file data, and checks the integrity and security of the data transmission through MD5. The secure and complete data stores the configuration file data and message file data in the database of this server, and at the same time provides the configuration file data and message file data to the web application software in the form of files, and publishes the web application data to the public network through the local area network. In this way, real-time information data and historical data queries can be obtained through mobile terminals and computer terminals.
[0102] As Figure 15 shown, the unidirectional ASI bitstream transmission device includes an intranet data acquisition server, an ASI to IP gateway device, an extranet data receiving gateway, a database server, a digital TV multiplexing device, a digital TV modulation device, a digital TV receiving terminal, a switch, a mobile terminal and a fixed terminal; the intranet data acquisition server is connected to the ASI to IP gateway device and sends an ASI signal to the ASI to IP gateway device; the ASI to IP gateway device is connected to the extranet data receiving gateway and the database server; the extranet data receiving gateway and the database server are respectively connected to the digital TV multiplexing device and the switch; the digital TV multiplexing device is connected to the digital TV modulation device and is connected to the digital TV receiving terminal through the digital TV modulation device; the switch is connected to the mobile terminal and the fixed terminal through the network.
[0103] Unidirectional ASI bitstream transmission method:
[0104] See Figure 15 Method B in. The TS bitstream broadcast card is used to implement the transmission method of operation and maintenance data, and method B receives the ASI signal from point A on the intranet side.
[0105] In the overall system structure, different from method A, a link of point B2 and the ASI to IP gateway is added. This link has two types of signal outputs. One is to loop out an ASI signal directly to the multiplexer at point C2, and the other is to encapsulate the ASI signal into UDP multicast through this link and provide it to point B3. After passing through point B3, the signal processing method is exactly the same as that of point B1, and will not be elaborated further.
[0106] As Figure 16As shown in the figure, the ASI-to-IP gateway device includes sending an ASI signal from the ASI signal output end to the connected ASI signal receiving end. The ASI signal receiving end is connected to the ASI signal gateway module, and the ASI signal gateway module repackages the multicast of UDP into a streaming media protocol and outputs data through the connected multicast data output end.
[0107] Receive the ASI signal from point A. The ASI signal is a unidirectional transmission signal in digital TV, which can only receive data and cannot send data back. The transmission medium used is coaxial cable. After the ASI signal receiving module receives the ASI signal, it simultaneously loops through an ASI signal and outputs it to the multiplexer of the digital TV multiplexing device at point C2. The ASI signal is transmitted in the radio and television network through the multiplexer. In the final signal processing, the operation and maintenance data can also be parsed in the form of UDP multicast and provided to the application software for processing and publishing of operation and maintenance data. At the same time, the data received by the ASI signal receiving module is input to the gateway of the ASI signal. The ASI gateway can encapsulate the ASI signal into a UDP multicast and transmit it to point C1 and point B3. After receiving the data at point C1, it is transmitted in the digital TV system, and after receiving the data at point B3, the UDP multicast can be repackaged into a streaming media protocol and data can be published through the public network.
[0108] In the data signal processing method of this embodiment, the method adopted is to encapsulate the operation and maintenance data into a TS file. In addition to this file encapsulation method, there may also be methods such as IP OVER DVB or DVB data broadcast in data encapsulation.
[0109] In the encryption of transmitted data, the scheme adopts the MD5 encryption method, and other different encryption methods can also be adopted to ensure the integrity of the transmitted data and the security of the content.
[0110] Although the disclosed embodiments of the present invention are as above, the above content is only an embodiment adopted for the convenience of understanding the present invention and is not used to limit the present invention. Any person skilled in the art within the technical field to which the present invention pertains can make any modifications and changes in the form of implementation and details without departing from the spirit and scope disclosed by the present invention. However, the patent protection scope of the present invention shall still be subject to the scope defined by the appended claims.
Claims
1. A unidirectional secure data transmission method for internal and external network isolation, characterized in that, the method comprises the following steps: Step 10: Collect data of all devices in the radio and television broadcast system, generate a TS file from the collected data, and send the TS file in the form of a UDP multicast stream or output it through a TS stream broadcast card; Step 20: Transmit the received multicast stream in a unidirectional optical fiber multicast transmission mode; Step 30: Output the ASI signal by means of a TS stream broadcast card. One way is to encapsulate the ASI signal into a UDP multicast and provide it to the external network data receiving gateway and the database server; the other way is to directly provide the ASI signal to the television multiplexing device; Step 10 further includes: The UDP multicast stream is output through an optical network card, and unidirectional transmission of UDP multicast data is achieved; The TS stream outputs the stream in the form of an ASI port, and unidirectional transmission of stream data is achieved; Encrypt the unidirectional transmission file of UDP multicast data and the stream file with unidirectional output through the ASI port of the TS stream by MD5, and after encryption, encapsulate it into a TS file for transmission.
2. The unidirectional secure data transmission method for internal and external network isolation according to claim 1, characterized in that, Steps 20 and 30 specifically include: Restore the received multicast stream into a data file, parse the multicast stream to restore the configuration file data and the message file data, store the configuration file data and the message file data, and at the same time forward the multicast through the multicast data forwarding module; Convert the received multicast through the streaming media protocol gateway module, convert it into RTSP, HLS, SRT streaming media protocols, and send it to the digital television multiplexing device.
3. The unidirectional secure data transmission method for internal and external network isolation according to claim 1 or 2, characterized in that, the The multiplexer in the digital television multiplexing device multiplexes the received stream and other radio and television streams together to achieve the output of the multiplexed stream; The digital television debugging device receives the multiplexed standard stream, modulates and outputs the stream, and outputs it to the set-top box or other terminals through the HFC network; Through the digital television receiving terminal, receive the QAM signal output after digital television debugging, demodulate and demultiplex the QAM signal to output a multicast stream, parse the multicast stream, restore the configuration file data and the message file data, and verify the integrity and security of data transmission through MD5.
4. The unidirectional secure data transmission method for internal and external network isolation according to claim 1 or 2, characterized in that, Convert the received multicast through the streaming media protocol gateway module, convert it into RTSP, HLS, SRT streaming media protocols, and send it to the switch; The switch receives the streaming media protocol data, converts the streaming media protocol data into UDP multicast data, then transmits the streaming media data protocol through the network, and parses the multicast stream, restores the configuration file data and the message file data, and verifies the integrity and security of data transmission through MD5; Store the configuration file data and message file data in the database of this server. At the same time, provide the configuration file data and message file data to the web application software in the form of files, and publish the web application data to the public network or local area network; Obtain real-time information data and query historical data through mobile terminals and computer terminals.
5. A one-way secure data transmission device with internal and external network isolation for implementing the method of claims 1-4, characterized in that, the device includes: an internal network operation and maintenance data signal processing system, a one-way optical fiber multicast stream transmission unit, and a one-way ASI stream transmission device; the internal network operation and maintenance data signal processing system is connected to the one-way optical fiber multicast stream transmission unit and the one-way ASI stream transmission unit; a UDP multicast device and a TS stream broadcast card are provided in the internal network operation and maintenance data signal processing system; the UDP multicast device includes a data acquisition module, an internal network database server, a local file generation module, a TS file generation module, and a UDP multicast stream generation module; the data acquisition module is respectively connected to the internal network database server and the local file generation module, and sends a message file to the local file generation module; the local file generation module is connected to the TS file generation module, and sends a message data file and a configuration data file to the TS file generation module; the TS file generation module is connected to the UDP multicast stream generation module, and sends a TS file to the UDP multicast stream generation module; the UDP multicast stream generation module is connected to the TS stream broadcast card, and sends a UDP multicast stream to the TS stream broadcast card; the TS stream broadcast card includes an internal network data acquisition module, a network database server, a local file generation module, a TS file generation module, and a TS / ASI stream broadcast module; the internal network data acquisition module is respectively connected to the database server and the local file generation module, and sends a message file to the local file generation module; the local file generation module is connected to the TS file generation module, and sends a message data file and a configuration data file to the TS file generation module; the TS file generation module is connected to the TS / ASI stream broadcast module, and sends a TS file to the TS / ASI stream broadcast module; The unidirectional ASI code stream transmission device includes an intranet data acquisition server, an ASI to IP gateway device, an extranet data receiving gateway, a database server, a digital TV multiplexing device, a digital TV modulation device, a digital TV receiving terminal, a switch, a mobile terminal, and a fixed terminal; the intranet data acquisition server is connected to the ASI to IP gateway device and sends an ASI signal to the ASI to IP gateway device; the ASI to IP gateway device is connected to the extranet data receiving gateway and the database server; the extranet data receiving gateway and the database server are respectively connected to the digital TV multiplexing device and the switch; the digital TV multiplexing device is connected to the digital TV modulation device and is connected to the digital TV receiving terminal through the digital TV modulation device; the switch is connected to the mobile terminal and the fixed terminal through the network; The ASI to IP gateway device includes sending an ASI signal from the ASI signal output end to the connected ASI signal receiving end, the ASI signal receiving end is connected to the ASI signal gateway module, and the ASI signal gateway module repackages the multicast of UDP into a streaming media protocol and outputs the data through the connected multicast data output end.
6. The unidirectional secure data transmission device with internal and external network isolation as described in claim 5, characterized in that, The unidirectional optical fiber multicast code stream transmission unit includes an intranet data acquisition server, an extranet data receiving gateway, a database server, a digital TV multiplexing device, a digital TV modulation device, a digital TV receiving terminal, a switch, a mobile terminal, and a fixed terminal; The intranet data acquisition server is connected to the extranet data receiving gateway and the database server; the extranet data receiving gateway and the database server are respectively connected to the digital TV multiplexing device and the switch; the digital TV multiplexing device is connected to the digital TV modulation device; the digital TV modulation device is connected to the digital TV receiving terminal; the switch is connected to the mobile terminal and the fixed terminal through the network.
7. The unidirectional secure data transmission device with internal and external network isolation as described in claim 5, characterized in that, An optical fiber receiving network card, a multicast data parsing gateway module, a multicast data forwarding module, and a streaming media data protocol gateway module are deployed on the extranet data receiving gateway and the database server; the optical fiber receiving network card is connected to the multicast data parsing gateway module and sends a multicast code stream to the multicast data parsing gateway module; the multicast data parsing gateway module is connected to the multicast data forwarding module; the multicast data forwarding module is connected to the streaming media data protocol gateway module.
8. The unidirectional secure data transmission device with internal and external network isolation as described in claim 5, characterized in that, The digital TV receiving terminal includes a QAM signal receiving device, an optical fiber receiving network card, a multicast data gateway, and a multicast data forwarding unit; the QAM signal receiving device is connected to the optical fiber receiving network card; the optical fiber receiving network card is connected to the multicast data gateway; The multicast data gateway is connected to the multicast data forwarding unit.
9. The unidirectional secure data transmission device with internal and external network isolation as described in claim 5, It is characterized in that the mobile terminal and the fixed terminal are connected to the web application module and the multicast data gateway through a public network or a local area network, and data files are transmitted between the web application module and the multicast data gateway; the multicast data gateway is interconnected with the streaming media data gateway, and the streaming media data gateway converts the streaming media data into UDP multicast data and transmits it to the multicast data gateway; the streaming media data gateway is connected to the local switch, and the switch delivers the streaming media data to the streaming media data gateway.
Citation Information
Patent Citations
Multimedia network data processing system
CN107579996A
Industrial data security isolation acquisition system and intranet and extranet data one-way transmission method
CN110557251A
Method for realizing all-IP digital television conditional access technology through CMTS
CN111372106A
Satellite broadcasting-based mobile wireless video service system
CN202334795U