Intranet and extranet data sharing method, device, system and computer-readable storage medium
By using data communication rooms and blockchain technology in intranet and extranet data sharing, a directory chain is formed and the address information of intranet data is displayed instead of sharing the original data. This solves the problem of data sharing in existing technologies that increases the difficulty of security protection and the risk of leakage, and realizes safe and efficient data sharing.
Patent Information
- Application Number
- CN202110426784.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-20
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2041-04-20
AI Technical Summary
In the process of sharing data between internal and external networks, existing technologies require that data be transmitted to shared nodes, which increases the difficulty of protecting internal network security and poses a risk of data leakage.
Through the data communication room node, the relevant information of intranet users is uploaded to the blockchain to form a directory chain. The directory chain includes the mapping relationship between the directory information and address information corresponding to the intranet user's original intranet data. After the external network user undergoes identity authentication and access rights determination, the address information of the original intranet data is displayed instead of directly sharing the original data.
It enables data sharing without hardware migration, reduces the difficulty of intranet security protection and the risk of data leakage. The solution is simple to implement and has good market application scenarios.
Smart Images

Figure CN115242394B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of mobile communication technology, and in particular to a method, device, system and computer-readable storage medium for sharing intranet and extranet data. Background Art
[0002] With the rapid development of computer network and communication technologies, data sharing, flow, and data applications are becoming increasingly prevalent. For example, data sharing in areas such as public services, government data disclosure, and government data governance is becoming increasingly common. However, in this data sharing process, some sensitive data, especially government data from various departments, involves data interaction between internal and external networks. This requires strengthening the manageability and control of data sharing, while also preventing unauthorized leakage of intranet data to reduce the risk of data leaks.
[0003] In related technologies, data sharing between intranets and external networks typically involves transferring data to a shared node and then encrypting or desensitizing it before transferring it to other applications. This approach, which requires transferring data to a shared node, increases the difficulty of protecting intranet security during the data migration process and poses the risk of data leakage. Summary of the Invention
[0004] In view of this, embodiments of the present invention are intended to provide a method, device, system, and computer-readable storage medium for sharing data between an intranet and an extranet.
[0005] To achieve the above-mentioned purpose, the technical solution of the embodiment of the present invention is implemented as follows:
[0006] An embodiment of the present invention provides a method for sharing intranet and intranet data. The method is applied to a data communication room node corresponding to an intranet. The data communication room node uploads relevant information of an intranet user to a blockchain to form a directory chain. The directory chain includes at least directory information corresponding to the intranet original data of the intranet user and an intranet mapping relationship between address information of the intranet original data and the directory information. The method includes:
[0007] Perform identity authentication and access rights determination on extranet users who access intranet data;
[0008] When the identity authentication result of the external network user is that the user is a legitimate user and has access rights, the data communication room node displays the address information of the internal network original data in text form through the internal network mapping relationship.
[0009] The directory chain also includes a smart contract, which includes a strategy for each data communication room node to use the blockchain. The strategy includes but is not limited to: user identity authentication, access permission control, and key exchange mechanism.
[0010] The identity authentication of the external network user who is about to access the intranet data includes:
[0011] The judgment is made based on whether the entered username and password are correct, and whether the entered verification code matches the verification code randomly generated at the time. If the username and password are correct and the verification code matches, the user is determined to be a legitimate user, otherwise it is an illegal user.
[0012] The access rights of extranet users who are accessing intranet data are determined, including:
[0013] The access authority is judged based on the access control matrix of the legal user. For the items whose permission values in the access control matrix are expressed as passed, the user has permission to access; for the items whose permission values in the access control matrix are expressed as failed, the user has no permission to access.
[0014] Each item in the access control matrix represents a value of the right to access the corresponding intranet data, and the value of the right is expressed as pass or fail.
[0015] Optionally, the method further includes:
[0016] The directory information corresponding to the original intranet data and the address information of the original intranet data are obtained from the intranet device to form the directory chain.
[0017] Optionally, before performing identity authentication and access rights determination on the external network user who is to access the intranet data, the method further includes:
[0018] Receive the intranet data information or directory information of the intranet data that the user clicks or fills in and submits in the directory chain system.
[0019] The displaying of the address information of the original intranet data in text form through the intranet mapping relationship includes:
[0020] Determine the directory information corresponding to the original intranet data to be accessed by extranet users;
[0021] Determining the address information of the Intranet original data based on an Intranet mapping relationship between the address information of the Intranet original data and the directory information;
[0022] The address information of the original data of the intranet is displayed in text form.
[0023] Optionally, after displaying the address information of the intranet original data in text form, the method further includes:
[0024] Receiving digitally signed access data input by an external network user, wherein the access data includes address information of the original data on the internal network;
[0025] Perform digital signature verification on the access data, and after verification, encrypt the access data and transmit it to the intranet device, which decrypts it to obtain the plain text address information of the intranet data to be accessed;
[0026] The encrypted intranet data output by the intranet device is received and decrypted to obtain the plain text of the intranet data and then transmitted to the user; wherein the intranet data output by the intranet device is the intranet data corresponding to the address information.
[0027] Optionally, the method further includes:
[0028] The various operations of the data communication room node are recorded in a log, and the audit results are obtained through subsequent analysis.
[0029] An embodiment of the present invention further provides a device for sharing intranet and intranet data. The device is applied to a data communication room node corresponding to an intranet. The data communication room node uploads relevant information of an intranet user to a blockchain to form a directory chain. The directory chain includes at least directory information corresponding to the intranet original data of the intranet user and an intranet mapping relationship between the address information of the intranet original data and the directory information. The device includes:
[0030] The authentication and permission module is used to authenticate the identity and access rights of external network users who are accessing intranet data;
[0031] The display processing module is used to display the address information of the original data in the intranet in text form through the intranet mapping relationship when the authentication authority module determines that the identity authentication result of the external network user is a legal user and has access rights.
[0032] An embodiment of the present invention further provides a system for sharing intranet and intranet data, the system comprising: a data communication room node corresponding one-to-one to an intranet, the data communication room node linking relevant information of an intranet user to a blockchain to form a directory chain, the directory chain comprising at least directory information corresponding to the intranet original data of the intranet user and an intranet mapping relationship between address information of the intranet original data and the directory information; wherein,
[0033] The data communication room node is used to authenticate the identity of the external network user who is accessing the intranet data and determine the access rights; when it is determined that the external network user's identity authentication result is a legitimate user and has access rights, the address information of the original intranet data is displayed in text form through the intranet mapping relationship.
[0034] The embodiment of the present invention further provides a device for sharing data between an intranet and an intranet, the device comprising: a processor and a memory for storing a computer program that can be run on the processor,
[0035] Wherein, the processor is used to execute the steps of the above method when running the computer program.
[0036] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.
[0037] Embodiments of the present invention provide a method, device, system, and computer-readable storage medium for sharing intranet and intranet data. The method is applied to a data communication room node corresponding to an intranet. The data communication room node uploads relevant information of an intranet user to a blockchain to form a directory chain. The directory chain includes at least directory information corresponding to the intranet user's original intranet data and an intranet mapping relationship between the address information of the original intranet data and the directory information. The method includes: performing identity authentication and access rights determination on an external network user who wishes to access the intranet data; if the external network user's identity authentication result indicates that the user is a legitimate user and has access rights, the data communication room node displays the address information of the original intranet data in text form using the intranet mapping relationship. It can be seen that in embodiments of the present invention, when sharing intranet and intranet data, sharing is achieved through the data communication room. Moreover, the content shared by the data communication room is the directory information and the directory mapping relationship corresponding to the directory, rather than the original data itself. The directory chain of these data communication rooms is constructed through the blockchain. Thus, data sharing is achieved without hardware migration, or data sharing is not possible, thereby reducing the difficulty of intranet security protection, the exposure, and the risk of data leakage. Moreover, the solution is simple to implement, has good market application scenarios, and can be promoted and applied on a large scale after the product is realized. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 This is a flow chart of the method for sharing data between internal and external networks according to an embodiment of the present invention;
[0039] Figure 2 Schematic diagram of the structure of the intranet data sharing device according to the embodiment of the present invention Figure 1 ;
[0040] Figure 3 Schematic diagram of the structure of the intranet data sharing device according to the embodiment of the present invention Figure 2 ;
[0041] Figure 4 This is a schematic diagram of the structure of the intranet and extranet data sharing system based on blockchain and data communication room according to an embodiment of the present invention;
[0042] Figure 5 This is a schematic diagram of the overall topology of the data communication room according to an embodiment of the present invention;
[0043] Figure 6This is a schematic diagram of the functional layer structure of the data communication room described in an embodiment of the present invention. DETAILED DESCRIPTION
[0044] The present invention will be described below with reference to the accompanying drawings and embodiments.
[0045] An embodiment of the present invention provides a method for sharing intranet and intranet data. The method is applied to a data communication room node corresponding to an intranet. The data communication room node uploads relevant information of an intranet user to a blockchain to form a directory chain. The directory chain includes at least directory information corresponding to the intranet original data of the intranet user and an intranet mapping relationship between the address information of the intranet original data and the directory information; Figure 1 As shown, the method includes:
[0046] Step 101: Perform identity authentication and access rights determination on the external network user who is accessing the intranet data;
[0047] Step 102: When the identity authentication result of the external network user is that the user is a legitimate user and has access rights, the data communication room node displays the address information of the internal network original data in text form through the internal network mapping relationship.
[0048] In this embodiment of the present invention, data sharing between intranets and external networks is achieved through a data communication room. The content shared by the data communication room is directory information and the directory mapping relationships corresponding to the directories, rather than the original data itself. These directories in these data communication rooms are used to construct a directory chain through blockchain. This enables data sharing without hardware migration, or even when migration is not possible, thereby reducing the difficulty of intranet security protection, exposure, and the risk of data leakage.
[0049] In the embodiment of the present invention, the relevant information of the intranet user may include: the real business system name of the intranet user, business type, address information of business data, etc.
[0050] In one embodiment of the present invention, the directory chain also includes a smart contract, which includes a strategy for each data communication room node to use the blockchain, and the strategy includes but is not limited to: user identity authentication, access permission control and key exchange mechanism.
[0051] In the embodiment of the present invention, the identity authentication of the external network user who is about to access the intranet data includes:
[0052] The judgment is made based on whether the entered username and password are correct, and whether the entered verification code matches the verification code randomly generated at the time. If the username and password are correct and the verification code matches, the user is determined to be a legitimate user, otherwise it is an illegal user.
[0053] In an embodiment of the present invention, determining access rights of an external network user who is to access intranet data includes:
[0054] The access authority is judged based on the access control matrix of the legal user. For the items whose permission values in the access control matrix are expressed as passed, the user has permission to access; for the items whose permission values in the access control matrix are expressed as failed, the user has no permission to access.
[0055] Each item in the access control matrix represents a value of the right to access the corresponding intranet data, and the value of the right is expressed as pass or fail.
[0056] In one embodiment of the present invention, the method further includes:
[0057] The directory information corresponding to the original intranet data and the address information of the original intranet data are obtained from the intranet device to form the directory chain.
[0058] In the embodiment of the present invention, the intranet device may be a device such as an intranet service database, which stores the intranet original data of the intranet users and the corresponding related information of the intranet users.
[0059] In one embodiment of the present invention, before performing identity authentication and access rights determination on an external network user who is to access intranet data, the method further includes:
[0060] Receive the intranet data information or directory information of the intranet data that the user clicks or fills in and submits in the directory chain system.
[0061] In one embodiment of the present invention, displaying the address information of the intranet original data in text form through the intranet mapping relationship includes:
[0062] Determine the directory information corresponding to the original intranet data to be accessed by extranet users;
[0063] Determining the address information of the Intranet original data based on an Intranet mapping relationship between the address information of the Intranet original data and the directory information;
[0064] The address information of the original data of the intranet is displayed in text form.
[0065] In one embodiment of the present invention, after displaying the address information of the intranet original data in text form, the method further includes:
[0066] Receiving digitally signed access data input by an external network user, wherein the access data includes address information of the original data on the internal network;
[0067] Perform digital signature verification on the access data, and after verification, encrypt the access data and transmit it to the intranet device, which decrypts it to obtain the plain text address information of the intranet data to be accessed;
[0068] The encrypted intranet data output by the intranet device is received and decrypted to obtain the plain text of the intranet data and then transmitted to the user; wherein the intranet data output by the intranet device is the intranet data corresponding to the address information.
[0069] It should be noted that the encrypted intranet data can be obtained by encrypting the intranet data by the intranet device, or by encrypting the intranet data by the data communication room.
[0070] In one embodiment of the present invention, the method further includes:
[0071] The various operations of the data communication room node are recorded in a log, and the audit results are obtained through subsequent analysis.
[0072] In order to implement the above method embodiment, the embodiment of the present invention further provides a device for sharing intranet and intranet data, which is applied to a data communication room node corresponding to the intranet. The data communication room node uploads the relevant information of the intranet user to the blockchain to form a directory chain. The directory chain at least includes the directory information corresponding to the intranet original data of the intranet user and the intranet mapping relationship between the address information of the intranet original data and the directory information; Figure 2 As shown, the device includes:
[0073] Authentication and permission module 201, used to authenticate the identity and access rights of external network users who want to access intranet data;
[0074] The display processing module 202 is used to display the address information of the original data of the intranet in text form through the intranet mapping relationship when the authentication authority module determines that the identity authentication result of the external network user is a legal user and has access rights.
[0075] In one embodiment of the present invention, the directory chain also includes a smart contract, which includes a strategy for each data communication room node to use the blockchain, and the strategy includes but is not limited to: user identity authentication, access permission control and key exchange mechanism.
[0076] In the embodiment of the present invention, the authentication authority module 201 performs identity authentication on an external network user who is about to access the intranet data, including:
[0077] The judgment is made based on whether the entered username and password are correct, and whether the entered verification code matches the verification code randomly generated at the time. If the username and password are correct and the verification code matches, the user is determined to be a legitimate user, otherwise it is an illegal user.
[0078] In the embodiment of the present invention, the authentication authority module 201 determines the access authority of an external network user who is to access the intranet data, including:
[0079] The access authority is judged based on the access control matrix of the legal user. For the items whose permission values in the access control matrix are expressed as passed, the user has permission to access; for the items whose permission values in the access control matrix are expressed as failed, the user has no permission to access.
[0080] Each item in the access control matrix represents a value of the right to access the corresponding intranet data, and the value of the right is expressed as pass or fail.
[0081] In one embodiment of the present invention, the display processing module 202 is further configured to
[0082] The directory information corresponding to the original intranet data and the address information of the original intranet data are obtained from the intranet device to form the directory chain.
[0083] In one embodiment of the present invention, the authentication authority module 201 is further used to authenticate the identity of the external network user who is to access the intranet data and to determine the access authority.
[0084] Receive the intranet data information or directory information of the intranet data that the user clicks or fills in and submits in the directory chain system.
[0085] In one embodiment of the present invention, the display processing module 202 displays the address information of the intranet original data in text form according to the intranet mapping relationship, including:
[0086] Determine the directory information corresponding to the original intranet data to be accessed by extranet users;
[0087] Determining the address information of the Intranet original data based on an Intranet mapping relationship between the address information of the Intranet original data and the directory information;
[0088] The address information of the original data of the intranet is displayed in text form.
[0089] In one embodiment of the present invention, Figure 3 As shown, the device further includes: an encryption and decryption module 203, after the display processing module 202 displays the address information of the original data of the intranet in text form, the encryption and decryption module 203 is used to
[0090] Receiving digitally signed access data input by an external network user, wherein the access data includes address information of the original data on the internal network;
[0091] Perform digital signature verification on the access data, and after verification, encrypt the access data and transmit it to the intranet device, which decrypts it to obtain the plain text address information of the intranet data to be accessed;
[0092] The encrypted intranet data output by the intranet device is received and decrypted to obtain the plain text of the intranet data and then transmitted to the user; wherein the intranet data output by the intranet device is the intranet data corresponding to the address information.
[0093] In one embodiment of the present invention, Figure 3 As shown, the device also includes: a log recording module 204, which is used to log various operations of the data communication room node and obtain audit results through subsequent analysis.
[0094] The embodiment of the present invention also provides a system for sharing data between internal and external networks. Figure 4 As shown, the system includes: a data communication room node corresponding to the intranet one-to-one, the data communication room node uploads the relevant information of the intranet user to the blockchain to form a directory chain, the directory chain at least includes the directory information corresponding to the intranet original data of the intranet user and the intranet mapping relationship between the address information of the intranet original data and the directory information; wherein,
[0095] The data communication room node is used to perform identity authentication and access permission judgment for external network users who are accessing internal network data; when it is determined that the identity authentication result of the external network user is a legitimate user and has access permission, the address information of the original internal network data is displayed in text form through the internal network mapping relationship.
[0096] An embodiment of the present invention further provides a device for sharing intranet and intranet data. The device is applied to a data communication room node corresponding to an intranet. The data communication room node uploads relevant information of an intranet user to a blockchain to form a directory chain. The directory chain includes at least directory information corresponding to the intranet original data of the intranet user and an intranet mapping relationship between the address information of the intranet original data and the directory information. The device includes: a processor and a memory for storing a computer program that can be run on the processor.
[0097] Wherein, when the processor is used to run the computer program, it executes:
[0098] Perform identity authentication and access rights determination on extranet users who access intranet data;
[0099] When the identity authentication result of the external network user is that the user is a legitimate user and has access rights, the data communication room node displays the address information of the internal network original data in text form through the internal network mapping relationship.
[0100] The directory chain also includes a smart contract, which includes a strategy for each data communication room node to use the blockchain. The strategy includes but is not limited to: user identity authentication, access permission control, and key exchange mechanism.
[0101] When performing identity authentication on an external network user who is to pre-access the intranet data, the processor is further configured to execute, when running the computer program:
[0102] The judgment is made based on whether the entered username and password are correct, and whether the entered verification code matches the verification code randomly generated at the time. If the username and password are correct and the verification code matches, the user is determined to be a legitimate user, otherwise it is an illegal user.
[0103] When determining access rights for an external network user who is to access intranet data, the processor is further configured to execute, when running the computer program:
[0104] The access authority is judged based on the access control matrix of the legal user. For the items whose permission values in the access control matrix are expressed as passed, the user has permission to access; for the items whose permission values in the access control matrix are expressed as failed, the user has no permission to access.
[0105] Each item in the access control matrix represents a value of the right to access the corresponding intranet data, and the value of the right is expressed as pass or fail.
[0106] The processor is further configured to, when running the computer program, execute:
[0107] The directory information corresponding to the original intranet data and the address information of the original intranet data are obtained from the intranet device to form the directory chain.
[0108] Before performing identity authentication and access rights determination on an external network user who is to access the intranet data, the processor is further configured to execute, when running the computer program:
[0109] Receive the intranet data information or directory information of the intranet data that the user clicks or fills in and submits in the directory chain system.
[0110] When the address information of the original intranet data is displayed in text form through the intranet mapping relationship, the processor is further configured to execute, when running the computer program:
[0111] Determine the directory information corresponding to the original intranet data to be accessed by extranet users;
[0112] Determining the address information of the Intranet original data based on an Intranet mapping relationship between the address information of the Intranet original data and the directory information;
[0113] The address information of the original data of the intranet is displayed in text form.
[0114] After displaying the address information of the intranet original data in text form, the processor is further configured to execute, when running the computer program:
[0115] Receiving digitally signed access data input by an external network user, wherein the access data includes address information of the original data on the internal network;
[0116] Perform digital signature verification on the access data, and after verification, encrypt the access data and transmit it to the intranet device, which decrypts it to obtain the plain text address information of the intranet data to be accessed;
[0117] The encrypted intranet data output by the intranet device is received and decrypted to obtain the plain text of the intranet data and then transmitted to the user; wherein the intranet data output by the intranet device is the intranet data corresponding to the address information.
[0118] The processor is further configured to, when running the computer program, execute:
[0119] The various operations of the data communication room node are recorded in a log, and the audit results are obtained through subsequent analysis.
[0120] It should be noted that the above embodiments provide an example of the division of the aforementioned program modules when sharing data between internal and external networks. In actual applications, the aforementioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the aforementioned processing. In addition, the apparatus provided in the above embodiments and the corresponding method embodiments are based on the same concept. The specific implementation process is detailed in the method embodiments and will not be repeated here.
[0121] In an exemplary embodiment, an embodiment of the present invention further provides a computer-readable storage medium, which can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM; or it can be various devices including one or any combination of the above memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0122] An embodiment of the present invention further provides a computer-readable storage medium, which is applied to a data communication room node corresponding one-to-one to an intranet. The data communication room node uploads relevant information of an intranet user to a blockchain to form a directory chain. The directory chain includes at least directory information corresponding to the intranet original data of the intranet user and an intranet mapping relationship between the address information of the intranet original data and the directory information. A computer program is stored on the medium. When the computer program is executed by a processor, the computer program performs:
[0123] Perform identity authentication and access rights determination on extranet users who access intranet data;
[0124] When the identity authentication result of the external network user is that the user is a legitimate user and has access rights, the data communication room node displays the address information of the internal network original data in text form through the internal network mapping relationship.
[0125] The directory chain also includes a smart contract, which includes a strategy for each data communication room node to use the blockchain. The strategy includes but is not limited to: user identity authentication, access permission control, and key exchange mechanism.
[0126] When performing identity authentication on an external network user who is to access the intranet data, the computer program, when executed by the processor, further executes:
[0127] The judgment is made based on whether the entered username and password are correct, and whether the entered verification code matches the verification code randomly generated at the time. If the username and password are correct and the verification code matches, the user is determined to be a legitimate user, otherwise it is an illegal user.
[0128] When determining access rights for an external network user who is to access intranet data, the computer program, when executed by the processor, further executes:
[0129] The access authority is judged based on the access control matrix of the legal user. For the items whose permission values in the access control matrix are expressed as passed, the user has permission to access; for the items whose permission values in the access control matrix are expressed as failed, the user has no permission to access.
[0130] Each item in the access control matrix represents a value of the right to access the corresponding intranet data, and the value of the right is expressed as pass or fail.
[0131] When the computer program is executed by a processor, it further performs:
[0132] The directory information corresponding to the original intranet data and the address information of the original intranet data are obtained from the intranet device to form the directory chain.
[0133] Before performing identity authentication and access rights determination on the external network user who is to access the internal network data, when the computer program is executed by the processor, the computer program further executes:
[0134] Receive the intranet data information or directory information of the intranet data that the user clicks or fills in and submits in the directory chain system.
[0135] When the address information of the original intranet data is displayed in text form through the intranet mapping relationship, the computer program, when executed by the processor, further executes:
[0136] Determine the directory information corresponding to the original intranet data to be accessed by extranet users;
[0137] Determining the address information of the Intranet original data based on an Intranet mapping relationship between the address information of the Intranet original data and the directory information;
[0138] The address information of the original data of the intranet is displayed in text form.
[0139] After the address information of the intranet original data is displayed in text form, when the computer program is executed by the processor, the following steps are further performed:
[0140] Receiving digitally signed access data input by an external network user, wherein the access data includes address information of the original data on the internal network;
[0141] Perform digital signature verification on the access data, and after verification, encrypt the access data and transmit it to the intranet device, which decrypts it to obtain the plain text address information of the intranet data to be accessed;
[0142] The encrypted intranet data output by the intranet device is received and decrypted to obtain the plain text of the intranet data and then transmitted to the user; wherein the intranet data output by the intranet device is the intranet data corresponding to the address information.
[0143] When the computer program is executed by a processor, it further performs:
[0144] The various operations of the data communication room node are recorded in a log, and the audit results are obtained through subsequent analysis.
[0145] The present invention is described below with reference to scenario embodiments.
[0146] In the relevant technical solutions, data needs to be transferred to shared nodes for sharing, and data migration is performed, which increases the difficulty and exposure of intranet security protection; in addition, even if the data transmission process adopts encryption or desensitization methods, the full amount of data will still exist in the data sharing node, and there is a risk of data leakage.
[0147] Based on this, this embodiment proposes a method and system for sharing intranet and intranet data based on blockchain and a data communication room. When sharing intranet and intranet data, this sharing is achieved through the data communication room. The content shared by the data communication room is directory information, not the original data itself and the directory mapping relationships corresponding to the directory. These data communication room directories are constructed into a directory chain using blockchain. This enables data sharing without hardware migration, or even when migration is not possible, thereby reducing the difficulty of intranet security protection, exposure, and the risk of data leakage.
[0148] This embodiment uses blockchain and data communication room as the basis to share intranet and extranet data.
[0149] First, we introduce the intranet and extranet data sharing system based on blockchain and data communication room. The system is composed as follows: Figure 4 As shown in the figure, the structure of the intranet and extranet data sharing system based on blockchain and data communication room is as follows:
[0150] Intranet 1 corresponds to Data Communication Room 1, Intranet 2 corresponds to Data Communication Room 2, and so on. Intranet n corresponds to Data Communication Room n. These n Data Communication Rooms, acting as nodes on a directory chain, form a directory chain, essentially an intranet and intranet data sharing system. The specific contents of each Data Communication Room and the sharing methods are described below.
[0151] The corresponding functions and structure of the data communication room are introduced in detail below.
[0152] The overall topology of the data communication room is as follows Figure 5 As shown, the topology diagram depicts the main modules, including the "Data Communication Room" portal, the authentication and security management server, the audit server (Syslog server), the security management console, the system management console, the user application console / operation proxy server, and the corresponding security gateway. The backend cache service, business systems, and business approval console within the dashed box in the diagram belong to the intranet. External users can request required data from the intranet through the user application console / operation proxy server. The authentication and security management server authenticates the user's identity and permissions, confirming that the user is legitimate and has the appropriate permissions before allowing access to intranet data through the directory information displayed in the portal.
[0153] The "Data Communication Room" portal serves as the core and hub of the entire intranet and extranet data sharing system, responsible for invoking and connecting various other components to achieve overall functional objectives. The portal itself is exposed in the DMZ and is not responsible for actual business content or user authentication. This way, even if the portal is compromised, it would be difficult for attackers to obtain further user information and business data. Furthermore, all portal interfaces and operations are recorded to a log (audit) server, enabling rapid detection of anomalies and emergency response.
[0154] The "Data Communication Room" portal and related management modules and interfaces are mainly divided into three levels: user function layer, entity function layer and interface function layer. In addition, there are separate management (security management, system management) interfaces and modules. Its architecture and modules are as follows: Figure 6 shown.
[0155] The user function layer implements functions such as user login, user information, form filling, application submission, approval review, and data download;
[0156] The entity function layer processes form information and transaction management;
[0157] The interface function layer corresponds to the secure communication interface, log interface, service submission interface, user verification interface and security / management interface, etc.;
[0158] System management corresponds to system configuration, daily operation and maintenance, and form management;
[0159] Security management corresponds to corresponding algorithm and key management, user identity and authority management, user verification, etc.
[0160] The following introduces the intranet and extranet data sharing method based on blockchain and data communication room.
[0161] The overall process of this method is described as follows:
[0162] Step 1: When users A, B, C (intranet users, such as different organizations) need to share data resources, by default, as nodes of the alliance chain, they are all trusted, and the information of users A, B, C, etc. can be uploaded to the chain. Then, each of them will upload the directory information corresponding to their own data information to the chain through the data communication room to form a directory chain.
[0163] The directory chain contains at least directory information and the corresponding intranet mapping relationship. The directory information includes, but is not limited to, simplified information translated from the original intranet data address information. The intranet mapping relationship is the correspondence between the original data address information and the directory information.
[0164] In addition to the two pieces of information mentioned above, the directory chain can also include smart contracts. The smart contracts include the strategies for each data communication room node to use the blockchain, including but not limited to: user identity authentication, access rights control, and key exchange mechanisms.
[0165] Step 2: The data communication room is used for secure data interaction in the case of intranet and extranet data sharing. Specifically, it mainly includes two sub-modules: access control module and data ferry center module. The corresponding functions of these two modules are described as follows:
[0166] 1) Access control module, used to authenticate and control access to users accessing intranet business system data.
[0167] For identity authentication, the user name and password are matched (correct) or not, and the verification code entered is verified to be matched with the randomly generated verification code at that time. If both match, the identity is authenticated as a legitimate user, otherwise it is an illegal user.
[0168] Regarding access control, the access control module here performs an intranet-internet conversion, converting the access control of the intranet business system data into the access control of the directory information presented by the business system in the data ferry center. Its specific implementation is as follows:
[0169] The access control judgment process is as follows: for users who have passed identity authentication, their access control matrix is retrieved and the value of each permission item in the access control matrix is judged one by one. If the permission value indicates an item is passed, the user has permission to access; if the permission value indicates an item is not passed, the user does not have permission to access. The specific implementation is achieved through smart contracts on the blockchain.
[0170] If access control determines that the operation is authorized, the original data address information is displayed through the directory mapping relationship. If access control determines that the operation is not authorized, the original data address information is not displayed. Here, the actual business system name of the intranet is displayed to the user as a directory entry in the directory information. This content is only constructed and presented in the form of text and does not have command operation functions.
[0171] Based on the results of access control, it is determined whether to allow the user to enter the data ferry center module and which authorized part of the data ferry center module to enter.
[0172] 2) Data ferry center module
[0173] This module implements multiple functions, and it is combined with the access control module to realize the function of the data communication room.
[0174] a. Collect, submit and present intranet data to complete the display function of user operations.
[0175] Data collection, including directory information of the intranet itself provided by the intranet;
[0176] Data submission means that the directory information that the user clicks or fills in the directory chain system will be submitted through the submit button;
[0177] Presentation means that the directory information of the original data of the business system is displayed.
[0178] b. Carrying the function of isolating and exchanging data between the internal and external networks, it adopts an operation mode similar to a "single-pole double-throw switch" to set up a control unit between the external network and the internal network to realize data ferrying. The internal network control unit adds a data encryption and decryption unit and a digital signature unit to protect the confidentiality and non-repudiation of the external network data. Among them,
[0179] The encryption process is to encrypt the output data through a traditional encryption algorithm to obtain ciphertext, and then transmit it; the decryption process is to decrypt the received data through a key to obtain the original plaintext.
[0180] The digital signature process is implemented by performing operations on data using a private key to obtain the signed information. Digital signature verification is implemented by performing operations on received information using a public key to obtain the original information, thereby verifying the source of the information and preventing denial of authenticity.
[0181] c. Implement intranet data mapping and conversion, security audit, key and signature management, user data access control, user identification and authentication, intranet business system interface management, etc.
[0182] Mapping and conversion is to map the obtained directory information with the original data address information, and then map it into the original data address information;
[0183] Security auditing is to log all operations and obtain audit results through subsequent analysis to facilitate the detection of abnormal situations and emergency response.
[0184] Key and signature management is the application of general technology in modern cryptography.
[0185] Access control, user identification and authentication, namely user name, password, verification code, and access control permission matrix implementation.
[0186] Interface management is achieved through general system interface management.
[0187] The Data Ferry Center module, when implemented, consists of directory information and mapping relationships within the directory chain, as well as various smart contracts. First, it acquires the aforementioned information; second, it primarily converts the mapping relationships within the directory information to obtain the address of the original data, converting access to the directory within the Data Ferry Center into access to the intranet system.
[0188] In this embodiment of the present invention, data sharing between intranets and external networks is achieved through a data communication room. The content shared by the data communication room is directory information and the directory mapping relationships corresponding to the directory, rather than the original data itself. These directories in these data communication rooms form a directory chain using blockchain. This enables data sharing without hardware migration, or even when migration is not possible, thereby reducing the difficulty of intranet security protection, exposure, and the risk of data leakage. Furthermore, this solution is simple to implement and has promising market application scenarios, allowing for large-scale promotion and application after product implementation.
[0189] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.
Claims
1. A method for sharing data between an intranet and an extranet, characterized in that: The method is applied to a data communication room node corresponding to an intranet. The data communication room node uploads relevant information of an intranet user to a blockchain to form a directory chain. The directory chain includes at least directory information corresponding to the intranet original data of the intranet user and an intranet mapping relationship between the address information of the intranet original data and the directory information. The method includes: Perform identity authentication and access rights determination on extranet users who access intranet data; When the identity authentication result of the external network user is that the user is legal and has access rights, the data communication room node displays the address information of the original data of the internal network in text form through the internal network mapping relationship; The displaying of the address information of the original intranet data in text form through the intranet mapping relationship includes: Determine the directory information corresponding to the original intranet data to be accessed by extranet users; Determining the address information of the Intranet original data based on an Intranet mapping relationship between the address information of the Intranet original data and the directory information; The address information of the original data of the intranet is displayed in text form.
2. The method according to claim 1, characterized in that The directory chain also includes a smart contract, which includes a strategy for each data communication room node to use the blockchain. The strategy includes but is not limited to: user identity authentication, access permission control and key exchange mechanism.
3. The method according to claim 1, characterized in that The identity authentication of the external network user who is to access the internal network data includes: The judgment is made based on whether the entered username and password are correct, and whether the entered verification code matches the verification code randomly generated at the time. If the username and password are correct and the verification code matches, the user is determined to be a legitimate user, otherwise it is an illegal user.
4. The method according to claim 1, wherein Determine the access rights of extranet users who are accessing intranet data, including: The access authority is judged based on the access control matrix of the legal user. For the items whose permission values in the access control matrix are expressed as passed, the user has permission to access; for the items whose permission values in the access control matrix are expressed as failed, the user has no permission to access. Each item in the access control matrix represents a value of the right to access the corresponding intranet data, and the value of the right is expressed as pass or fail.
5. The method according to claim 1, wherein The method further includes: The directory information corresponding to the original intranet data and the address information of the original intranet data are obtained from the intranet device to form the directory chain.
6. The method according to claim 1, characterized in that Before performing identity authentication and access rights determination on the external network user who is to access the intranet data, the method further includes: Receive the intranet data information or directory information of the intranet data that the user clicks or fills in and submits in the directory chain system.
7. The method according to claim 1, characterized in that After displaying the address information of the intranet original data in text form, the method further includes: Receiving digitally signed access data input by an external network user, wherein the access data includes address information of the original data on the internal network; Perform digital signature verification on the access data, and after verification, encrypt the access data and transmit it to the intranet device, which decrypts it to obtain the plain text address information of the intranet data to be accessed; The encrypted intranet data output by the intranet device is received and decrypted to obtain the plain text of the intranet data and then transmitted to the user; wherein the intranet data output by the intranet device is the intranet data corresponding to the address information.
8. The method according to claim 1, characterized in that The method further includes: The various operations of the data communication room node are recorded in a log, and the audit results are obtained through subsequent analysis.
9. A device for sharing data between an intranet and an extranet, characterized in that: The device is applied to a data communication room node corresponding to an intranet. The data communication room node uploads the relevant information of the intranet user to the blockchain to form a directory chain. The directory chain includes at least the directory information corresponding to the intranet original data of the intranet user and the intranet mapping relationship between the address information of the intranet original data and the directory information. The device includes: The authentication and permission module is used to authenticate the identity and access rights of external network users who are accessing intranet data; A display processing module, configured to display the address information of the original intranet data in text form through the intranet mapping relationship when the authentication authority module determines that the identity authentication result of the external network user is a legitimate user and has access rights; The display processing module is further used to determine the directory information corresponding to the original data of the intranet to be accessed by the external network user; Determining the address information of the Intranet original data based on an Intranet mapping relationship between the address information of the Intranet original data and the directory information; The address information of the original data of the intranet is displayed in text form.
10. A system for sharing data between internal and external networks, characterized in that: The system includes: a data communication room node corresponding to an intranet, wherein the data communication room node links the relevant information of the intranet user to the blockchain to form a directory chain, wherein the directory chain at least includes the directory information corresponding to the intranet original data of the intranet user and the intranet mapping relationship between the address information of the intranet original data and the directory information; wherein, The data communication room node is used to perform identity authentication and access permission judgment for external network users who are accessing internal network data; when it is determined that the identity authentication result of the external network user is a legitimate user and has access permission, the address information of the original internal network data is displayed in text form through the internal network mapping relationship.
11. A device for sharing data between internal and external networks, characterized in that: The device comprises: a processor and a memory for storing a computer program capable of running on the processor, Wherein, when the processor is used to run the computer program, it executes the steps of the method according to any one of claims 1 to 8.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Government affair data sharing system based on block chain
CN110457303A