A secure transmission method for isolated file data inside and outside the cloud desktop based on network disk
By deploying internal and external network disks in a cloud desktop environment and setting up permission folders, and utilizing information encryption and network protection modules, efficient and secure transmission of internal and external network data is achieved, solving the problems of large network bandwidth usage, impact on approval processes, and high network gateway failure rates in existing technologies, reducing costs and improving data transmission efficiency and security.
Patent Information
- Application Number
- CN202211356739.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-01
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2042-11-01
AI Technical Summary
In the existing technology, the transmission of data between internal and external networks has the problems of large network bandwidth usage, approval process affecting work efficiency, high network gateway failure rate and high cost.
A network disk-based internal and external isolated file data transmission method is adopted. By deploying internal and external network disks in the cloud desktop environment, setting folders with multiple permissions, and using information encryption and network protection modules, user mapping authorization of the network gate function is realized, reducing the impact of network traffic and approval processes.
It reduces the impact of network traffic, saves costs, reduces the frequency of approval processes, improves data transmission efficiency and security, and simplifies information management.
Smart Images

Figure CN115914206B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise information transmission, and in particular to a method for securely transmitting file data isolated inside and outside a cloud desktop based on a network disk. Background Art
[0002] With the continuous development of enterprise informatization, the interaction between internal and external network business systems is accelerating, and the information security issues brought about by the openness of the Internet are becoming increasingly prominent. The network boundary defense system with firewalls and gateways as the core can no longer meet the security needs of information system construction.
[0003] For example, a data security transmission method based on a message queue, with an authorization announcement number of CN107454186A and an authorization announcement date of 20171208, involves the data security application field in the field of information and communication technology. In order to ensure the security of data, the power company deploys a strong isolation device of the State Grid between the internal and external networks. The device is mainly suitable for the transmission of small data, and the efficiency of large file transmission is low, and the real-time communication response time is long. The present invention includes a method for transmitting data from the external network to the internal network and a method for transmitting data from the internal network to the external network; this technical solution replaces the original strong isolation device network gate with a forward and reverse network gate device, and implements message management of the forward and reverse network gate devices through ToprowMQ, so that the external network service can access the internal network application, and the internal network application accesses the external network service, which facilitates data sharing, and adds an MQ front-end message service and an MQ message management service to the internal and external networks respectively, which are used to communicate messages with the MQ network gate, improve efficiency, ensure the normal operation of the original various application system services, improve the efficiency and quality of internal and external network penetration, and improve data transmission efficiency and response speed.
[0004] For example, a method for secure data transmission, with authorization announcement number CN100428665C and authorization announcement date 2008-10-22, sets a weakly trusted server in the network to which both communicating parties currently belong. The method also includes: a) when both communicating parties need to transmit data, each party sends a request to the weakly trusted server; upon receiving the request, the weakly trusted server randomly generates a pair of random vectors and a pair of random numbers; b) the weakly trusted server divides the generated random vectors and random numbers into two groups and sends them to the communicating parties respectively; c) the communicating parties interact using the obtained random vectors and random numbers, and the data demander securely obtains the required data from the data provider. This method ensures the security and reliability of data transmitted by both communicating parties during use and upgrades, and improves the trust of both communicating parties in the data used.
[0005] The existing technology basically adopts the method of intranet and extranet process authorization + network gate + data synchronization, which has the following main disadvantages:
[0006] 1. Data synchronization will occupy network bandwidth, especially the large amount of internal and external interactions during the design process, which has a greater impact on network traffic.
[0007] 2. A large number of internal and external network interactions require the use of internal and external network approval processes, which affects the daily work of approvers.
[0008] The performance of the network gateway will also affect data synchronization. The failure rate is fatal to internal and external interactions, and it also has certain costs.
[0009] Therefore, it is urgent to design a method for securely transmitting isolated file data inside and outside the cloud desktop based on the network disk to solve the above problems. Summary of the Invention
[0010] The purpose of the present invention is to provide a method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk, so as to solve the above-mentioned deficiencies in the prior art.
[0011] In order to achieve the above object, the present invention provides the following technical solutions:
[0012] A method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk includes the following steps:
[0013] S1. Network disk deployment: First, deploy a network disk in the cloud desktop environment, referred to as the internal network disk, and then deploy a network disk outside the cloud desktop environment, referred to as the external network disk;
[0014] S2. Network disk interconnection: connect the internal network disk and the external disk through the network to achieve interconnection between the internal network disk and the external network disk;
[0015] S3.Network disk settings:
[0016] S3.1. Intranet disk setup: Set up the intranet work area, external network data receiving area, and protection unit in the intranet disk;
[0017] S3.2. External network disk settings: Set up the external network work area, internal network data exchange area, internal network product distribution area and protection unit in the external network disk;
[0018] S4. File transfer: Transfer the data to the external network disk through the network transmission method, then log in to the internal network disk in the computer cloud desktop environment, and then select the required files to download.
[0019] Furthermore, when the intranet disk in S1 is deployed, the intranet disk requires an approval process, is bound to the cloud desktop environment, has an IP address that is an intranet address and cannot access the external network, has an independent database, and when a C / S architecture is adopted, the intranet disk can only be used in the cloud desktop environment.
[0020] Furthermore, when the S1 network disk is deployed in an external network, an approval process is required, the IP address is an intranet address and can access the external network, a B / S architecture is adopted, and there is an independent database.
[0021] Furthermore, when the network disks are interconnected in S2, the external network disk user organization structure is first mapped to the internal network disk external user organization structure, and then the internal network disk user organization structure is mapped to the external network disk external user organization structure, thereby realizing the interconnection between the internal and external network disks.
[0022] Furthermore, in the S3.1 intranet disk setting, folders are set up in the intranet workspace according to the company's organizational structure, and the permissions are the intranet disk user permissions, which are set as needed.
[0023] Furthermore, the S3.2 Chinese and foreign network disk settings set up multiple folders in the Chinese and foreign network data receiving area as needed, and the permissions are: internal network disk users display / browse / download permissions; external network disk users; display / browse / upload permissions.
[0024] Furthermore, the protection unit in S3.1 and S3.2 includes a network protection module, a log recording module, and an information encryption module, and the network protection module adopts one of various network protection software such as Huorong, 360 Security Guard, Kingsoft Antivirus, etc.
[0025] Furthermore, the log recording module will record all operations performed by the user from the time he logs in to the time he logs out of the network disk, and the content recorded in the log includes the IP address of the machine performed by the user who performed a certain operation, the operation type, the operation object and the operation execution time, etc. The information encryption module encrypts the data through encryption algorithms such as EDS, 3EDS, AES, RSA, Elgamal, backpack algorithm, Rabin, HD.ECC, etc.
[0026] Furthermore, there are three methods for file transfer in S4, and the methods are as follows:
[0027] (1) Importing data from the external network: Upload the file to the "Intranet Data Interaction Area" through the external network disk, then log in to the intranet disk in the cloud desktop environment, select the external network disk server, and select the file download in the "Intranet Data Interaction Area";
[0028] (2) Importing external network data: Log in to the external network disk, select the internal network disk server, select the "External Network Data Acceptance Area", upload the file, and then log in to the internal network disk in the cloud desktop environment and directly select the file in the "External Network Data Acceptance Area" to download;
[0029] (3) Sending intranet data externally: Log in to the intranet disk in the cloud desktop environment, select the external disk server, and upload the file to the "Intranet Product Sending Area". Only users with download / external link permissions or who have applied for permissions can download / external link files for external sending.
[0030] Furthermore, the network disk and the cloud desktop are integrated during deployment in S1, and the integration is performed in a mixed manner of virtual data disk and fixed network data disk.
[0031] In the above technical solution, the present invention provides a secure transmission method for isolated file data inside and outside the cloud desktop based on a network disk. (1) The present invention adopts an internal and external network disk server user mapping authorization mechanism to realize the function achieved by the network gate, so no network gate is set. Since there is no network gate and no file data synchronization is required, costs are saved, file data is not redundant, and network traffic is not greatly affected; (2) The present invention sets a variety of exchange folders according to needs, sets permissions for the exchange folders, allows designated users to have specific permissions, reduces the frequency of approval processes, reduces the pressure on approvers, and improves the efficiency of internal and external file data interaction; (3) The protection unit designed by the present invention can encrypt the network disk data through the information encryption module, and can also record the operation steps between the user logging into the network disk and exiting the network disk through the log recording module, and can also protect the network disk through the network protection module, thereby improving the network disk's data protection capability and improving the security of the network disk; (4) By integrating the network disk with the cloud desktop, the cost of enterprise information storage can be reduced, making information data management more convenient. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments described in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0033] Figure 1 This is a method flow chart provided for an embodiment of the present invention, which implements a method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk.
[0034] Figure 2 This is a schematic diagram of the integrated structure provided by an embodiment of the present invention for a method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk.
[0035] Figure 3 This is a method schematic diagram provided for an embodiment of the present invention, which implements a method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk. DETAILED DESCRIPTION
[0036] In order to enable those skilled in the art to better understand the technical solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings.
[0037] like Figure 1-3As shown, an embodiment of the present invention provides a method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk, including the following steps:
[0038] S1. Network disk deployment: First, deploy a network disk in the cloud desktop environment, referred to as the internal network disk, and then deploy a network disk outside the cloud desktop environment, referred to as the external network disk;
[0039] S2. Network disk interconnection: connect the internal network disk and the external disk through the network to achieve interconnection between the internal network disk and the external network disk;
[0040] S3.Network disk settings:
[0041] S3.1. Intranet disk setup: Set up the intranet work area, external network data receiving area, and protection unit in the intranet disk;
[0042] S3.2. External network disk settings: Set up the external network work area, internal network data exchange area, internal network product distribution area and protection unit in the external network disk;
[0043] S4. File transfer: Transfer the data to the external network disk through the network transmission method, then log in to the internal network disk in the computer cloud desktop environment, and then select the required files to download.
[0044] Specifically, in this embodiment, the following steps are included:
[0045] S1. Network disk deployment: First, deploy a network disk in the cloud desktop environment, referred to as the internal network disk. This network disk requires an approval process, is bound to the cloud desktop environment, has an intranet IP address and cannot access the Internet, has an independent database, and can only be used in the cloud desktop environment when using a client-server architecture. Then, deploy a network disk outside the cloud desktop environment, referred to as the external network disk. This network disk requires an approval process, has an intranet IP address and can access the Internet, uses a client-server architecture, and has an independent database.
[0046] S2. Network disk interconnection: The internal network disk and the external network disk are connected through the network to achieve interconnection between the internal and external network disks. At this time, the user organization structure of the external network disk is mapped to the external user organization structure of the internal network disk. Similarly, the user organization structure of the internal network disk is mapped to the external user organization structure of the external network disk to achieve interconnection between the internal and external network disks.
[0047] S3.Network disk settings:
[0048] S3.1. Intranet disk settings: Set up the intranet work area, external network data receiving area and protection unit in the intranet disk. Set up the following in the intranet disk:
[0049] 1) Intranet workspace (folders are set up according to the company's organizational structure). The permissions are the same as those of intranet disk users and are set as needed.
[0050] 2) External network data receiving area (multiple folders can be set as needed), with permissions mainly including display / browse / download permissions for internal network disk users and display / browse / upload permissions for external network disk users;
[0051] S3.2. External network disk settings: Set up the external network work area, internal network data exchange area, internal network product distribution area and protection unit in the external network disk. Set up the following in the external network disk:
[0052] 1) External network workspace (folders are set up according to the company's organizational structure). The permissions are mainly the user permissions of the external network disk and are set as needed.
[0053] 2) Intranet data interaction area (multiple folders can be set as needed), the permissions are mainly display / browse / authority / upload for external network disk users, and display / browse / download permissions for internal network disk users.
[0054] 3) Intranet product distribution area (multiple folders can be set as needed), permissions are mainly for intranet disk users (specified users): display / browse / upload / download / external link permissions. Other intranet disk users: display / browse / upload / (authorization can be applied for);
[0055] S4. File transfer: Transfer the data to the external network disk through the network transmission method, then log in to the internal network disk in the computer cloud desktop environment, and then select the required files to download.
[0056] The present invention provides a secure transmission method for isolated file data inside and outside a cloud desktop based on a network disk. The present invention adopts an internal and external network disk server user mapping authorization mechanism to achieve the functions achieved by a network gate, so no network gate is set. Since there is no network gate and no file data synchronization is required, costs are saved, file data has no redundancy, and network traffic is not greatly affected.
[0057] In another embodiment provided by the present invention, when the intranet disk in S1 is deployed, the intranet disk requires an approval process, is bound to the cloud desktop environment, has an IP address that is an intranet address and cannot access the external network, has an independent database, and when a C / S architecture is adopted, the intranet disk can only be used in the cloud desktop environment.
[0058] In another embodiment provided by the present invention, when S1 is deployed in an external network disk, an approval process is required for the network disk, the IP address is an intranet address and can access the external network, a B / S architecture is adopted, and there is an independent database.
[0059] In another embodiment provided by the present invention, when the network disks in S2 are interconnected, the external network disk user organization structure is first mapped to the internal network disk external user organization structure, and then the internal network disk user organization structure is mapped to the external network disk external user organization structure to realize the interconnection between the internal and external network disks.
[0060] In another embodiment provided by the present invention, in S3.1 intranet disk setting, folders are set up in the intranet workspace according to the company's organizational structure, and the permissions are intranet disk user permissions, which are set as needed.
[0061] In another embodiment provided by the present invention, S3.2 sets up multiple folders in the domestic and foreign network disk receiving area as needed, and the permissions are: display / browse / download permissions for internal network disk users; display / browse / upload permissions for external network disk users.
[0062] In another embodiment provided by the present invention, the protection unit in S3.1 and S3.2 includes a network protection module, a log recording module, and an information encryption module, and the network protection module adopts one of various network protection software such as Huorong, 360 Security Guard, Kingsoft Antivirus, etc.
[0063] In another embodiment provided by the present invention, the log recording module will record all operations performed by the user from the time he logs into the network disk to the time he logs out of the network disk, and the content recorded in the log includes the IP address of the machine performed by the user who performs a certain operation, the operation type, the operation object and the operation execution time, etc. The information encryption module encrypts the data using encryption algorithms such as EDS, 3EDS, AES, RSA, Elgamal, backpack algorithm, Rabin, HD.ECC, etc.
[0064] In another embodiment provided by the present invention, there are three methods for file transmission in S4, and the methods are as follows:
[0065] (1) Importing data from the external network: Upload the file to the "Intranet Data Interaction Area" through the external network disk, then log in to the intranet disk in the cloud desktop environment, select the external network disk server, and select the file download in the "Intranet Data Interaction Area";
[0066] (2) Importing external network data: Log in to the external network disk, select the internal network disk server, select the "External Network Data Acceptance Area", upload the file, and then log in to the internal network disk in the cloud desktop environment and directly select the file in the "External Network Data Acceptance Area" to download;
[0067] (3) Sending intranet data externally: Log in to the intranet disk in the cloud desktop environment, select the external disk server, and upload the file to the "Intranet Product Sending Area". Only users with download / external link permissions or who have applied for permissions can download / external link files for external sending.
[0068] In another embodiment provided by the present invention, the network disk and the cloud desktop are integrated during deployment in S1, and the integration is performed in a mixed manner of a virtual data disk and a fixed network data disk.
[0069] Example 1
[0070] A method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk includes the following steps:
[0071] S1. Network disk deployment: First, deploy a network disk in the cloud desktop environment, referred to as the internal network disk. This network disk requires an approval process, is bound to the cloud desktop environment, has an intranet IP address and cannot access the Internet, has an independent database, and can only be used in the cloud desktop environment when using a client-server architecture. Then, deploy a network disk outside the cloud desktop environment, referred to as the external network disk. This network disk requires an approval process, has an intranet IP address and can access the Internet, uses a client-server architecture, and has an independent database.
[0072] S2. Network disk interconnection: The internal network disk and the external network disk are connected through the network to achieve interconnection between the internal and external network disks. At this time, the user organization structure of the external network disk is mapped to the external user organization structure of the internal network disk. Similarly, the user organization structure of the internal network disk is mapped to the external user organization structure of the external network disk to achieve interconnection between the internal and external network disks.
[0073] S3.Network disk settings:
[0074] S3.1. Intranet disk settings: Set up the intranet work area, external network data receiving area and protection unit in the intranet disk. Set up the following in the intranet disk:
[0075] 1) Intranet workspace (folders are set up according to the company's organizational structure). The permissions are the same as those of intranet disk users and are set as needed.
[0076] 2) External network data receiving area (multiple folders can be set as needed), with permissions mainly including display / browse / download permissions for internal network disk users and display / browse / upload permissions for external network disk users;
[0077] S3.2. External network disk settings: Set up the external network work area, internal network data exchange area, internal network product distribution area and protection unit in the external network disk. Set up the following in the external network disk:
[0078] 1) External network workspace (folders are set up according to the company's organizational structure). The permissions are mainly the user permissions of the external network disk and are set as needed.
[0079] 2) Intranet data interaction area (multiple folders can be set as needed), the permissions are mainly display / browse / authority / upload for external network disk users, and display / browse / download permissions for internal network disk users.
[0080] 3) Intranet product distribution area (multiple folders can be set as needed), permissions are mainly for intranet disk users (specified users): display / browse / upload / download / external link permissions. Other intranet disk users: display / browse / upload / (authorization can be applied for);
[0081] S4. File transfer: Transfer the data to the external network disk through the network transmission method, then log in to the internal network disk in the computer cloud desktop environment, and then select the required files to download. The transfer method is as follows:
[0082] 1) Importing data from the external network: Upload the file to the "Intranet Data Interaction Area" through the external network disk, then log in to the intranet disk in the cloud desktop environment, select the external network disk server, and select the file download in the "Intranet Data Interaction Area";
[0083] 2) Sending Intranet Data: Log in to the Intranet Disk in the cloud desktop environment, select the external disk server, and upload the file to the "Intranet Product Sending Area". Only users with download / external link permissions or who have applied for permissions can download / external link files and send them externally.
[0084] Example 2
[0085] S1. Network disk deployment: First, deploy a network disk in the cloud desktop environment, referred to as the internal network disk. This network disk requires an approval process, is bound to the cloud desktop environment, has an intranet IP address and cannot access the Internet, has an independent database, and can only be used in the cloud desktop environment when using a client-server architecture. Then, deploy a network disk outside the cloud desktop environment, referred to as the external network disk. This network disk requires an approval process, has an intranet IP address and can access the Internet, uses a client-server architecture, and has an independent database.
[0086] S2. Network disk interconnection: The internal network disk and the external network disk are connected through the network to achieve interconnection between the internal and external network disks. At this time, the user organization structure of the external network disk is mapped to the external user organization structure of the internal network disk. Similarly, the user organization structure of the internal network disk is mapped to the external user organization structure of the external network disk to achieve interconnection between the internal and external network disks.
[0087] S3.Network disk settings:
[0088] S3.1. Intranet disk settings: Set up the intranet work area, external network data receiving area and protection unit in the intranet disk. Set up the following in the intranet disk:
[0089] 1) Intranet workspace (folders are set up according to the company's organizational structure). The permissions are the same as those of intranet disk users and are set as needed.
[0090] 2) External network data receiving area (multiple folders can be set as needed), with permissions mainly including display / browse / download permissions for internal network disk users and display / browse / upload permissions for external network disk users;
[0091] S3.2. External network disk settings: Set up the external network work area, internal network data exchange area, internal network product distribution area and protection unit in the external network disk. Set up the following in the external network disk:
[0092] 1) External network workspace (folders are set up according to the company's organizational structure). The permissions are mainly the user permissions of the external network disk and are set as needed.
[0093] 2) Intranet data interaction area (multiple folders can be set as needed), the permissions are mainly display / browse / authority / upload for external network disk users, and display / browse / download permissions for internal network disk users.
[0094] 3) Intranet product distribution area (multiple folders can be set as needed), permissions are mainly for intranet disk users (specified users): display / browse / upload / download / external link permissions. Other intranet disk users: display / browse / upload / (authorization can be applied for);
[0095] S4. File transfer: Transfer the data to the external network disk through the network transmission method, then log in to the internal network disk in the computer cloud desktop environment, and then select the required files to download. The transfer method is as follows:
[0096] 1) Importing external network data: Log in to the external network disk, select the internal network disk server, select the "External Network Data Accepting Area", upload the file, and then log in to the internal network disk in the cloud desktop environment and directly select the "External Network Data Accepting Area" to download the file;
[0097] 2) Sending Intranet Data: Log in to the Intranet Disk in the cloud desktop environment, select the external disk server, and upload the file to the "Intranet Product Sending Area". Only users with download / external link permissions or who have applied for permissions can download / external link files and send them externally.
[0098] Working principle: Deploy a network disk (referred to as intranet disk) in the cloud desktop environment. The network disk requires an approval process, is bound to the cloud desktop environment, has an IP address that is an intranet address and cannot access the external network, has an independent database, and when using C / S architecture, the intranet disk can only be used in the cloud desktop environment; deploy a network disk outside the cloud desktop environment (referred to as external network disk). The network disk requires an approval process, has an IP address that is an intranet address and can access the external network, uses B / S architecture, and has an independent database; map the external network disk user organization structure to the internal network disk external user organization structure, and similarly, map the internal network disk user organization structure to the external network disk external user organization structure to achieve interconnection between internal and external network disks; set up in the intranet disk: 1) Intranet workspace (folders are set up according to the company's organizational structure), permissions are intranet disk user permissions, set as needed, 2) External network data receiving area (multiple folders can be set up as needed), permissions mainly include intranet disk user display / browse / download permissions; external network disk users: display / browse / upload permissions, 1) External network workspace (folders are set up according to the company's organizational structure), permissions are mainly external network disk user permissions, set as needed, 2) Intranet data interaction area (multiple folders can be set up as needed), permissions are mainly external network disk users display / browse / permissions / upload, internal network disk users: display / browse / download permissions, 3) Intranet product external distribution area (multiple folders can be set up as needed), permissions are mainly internal network disk users (specified users): display / browse / upload / download / external link permissions. Other intranet disk users: display / browse / upload / (authorization can be applied for), and then the following file transfer methods are used for data transmission: 1) External network data transmission: upload files to the "Intranet Data Interaction Area" through the external network disk, then log in to the intranet disk in the cloud desktop environment, select the external network disk server, and select the file download in the "Intranet Data Interaction Area"; 2) External network data transmission: log in to the external network disk, select the intranet disk server, select the "External Network Data Receiving Area", upload the file, and then log in to the intranet disk in the cloud desktop environment and directly select the file download in the "External Network Data Receiving Area"; 3) Internal network data outbound: log in to the intranet disk in the cloud desktop environment, select the external network disk server, and upload the file to the "Intranet Product Outbound Area". Only users with download / external link permissions or who have applied for permissions can download / external link files outbound.
[0099] The above description is merely illustrative of certain exemplary embodiments of the present invention. It goes without saying that those skilled in the art will be able to modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the scope of protection of the claims.
Claims
1. A method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk, characterized in that: The following steps are involved: S1. Network disk deployment: Deploy an internal network disk within the cloud desktop environment and an external network disk outside the cloud desktop environment. S2. Network disk interconnection: Map the external network disk user organization structure to the internal network disk external user organization structure, and map the internal network disk user organization structure to the external network disk external user organization structure; S3. Network disk settings: S3.1 The intranet disk is configured with an intranet work area, an extranet data receiving area, and a protection unit. The permissions for the extranet data receiving area are set as follows: Internal network disk users can download, and external network disk users can upload; S3.2 The external network disk shall be equipped with an external network work area, an internal network data interaction area, an internal network product distribution area, and a protection unit; S4. File transfer is performed via any of the following paths: (1) Importing data from the external network: Upload the file to the "Intranet Data Interaction Area" through the external network disk, then log in to the intranet disk in the cloud desktop environment, select the external network disk server, and select the file download in the "Intranet Data Interaction Area"; (2) Importing external network data: Log in to the external network disk, select the internal network disk server, select the "External Network Data Accepting Area", upload the file, and then log in to the internal network disk in the cloud desktop environment and directly select the file in the "External Network Data Accepting Area" to download; (3) Sending files from the intranet: Log in to the intranet disk in the cloud desktop environment, select the external disk server, and upload the file to the "Intranet Product Sending Area". Only users with download / external link permissions or who have applied for permissions can download / external link files for sending; The protection unit includes a log recording module for recording the machine IP address, operation type and operation time during user operation; In S1, when deploying the intranet disk, the network disk requires an approval process, is bound to the cloud desktop environment, has an intranet IP address that cannot access the external network, has an independent database, and can only be used in the cloud desktop environment when using a C / S architecture; When deploying the S1 network disk, an approval process is required. The IP address is an intranet address and can access the external network. It adopts a B / S architecture and has an independent database.
2. A method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk according to claim 1, characterized in that: In the S3.1 intranet disk setting, folders are set up in the intranet workspace according to the company's organizational structure, and the permissions are the intranet disk user permissions, which are set as needed.
3. According to claim 1, a method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk is characterized in that: In the S3.1, the internal network disk setting sets multiple folders in the external network data receiving area as needed, and the permissions are: external network disk user display / browse / upload permissions.
4. According to claim 1, a method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk is characterized in that: The protection unit in S3.1 and S3.2 includes a network protection module, a log recording module and an information encryption module, and the network protection module adopts one of the network protection softwares of Huorong, 360 Security Guard and Kingsoft Antivirus.
5. A method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk according to claim 4, characterized in that: The log recording module will record all operations performed by the user from the time he logs in to the time he logs out of the network disk, and the content recorded in the log includes the IP address of the machine performed by the user who performed a certain operation, the operation type, the operation object and the operation execution time. The information encryption module encrypts the data using EDS, 3EDS, AES, RSA, Elgammal, backpack algorithm, Rabin or HD.ECC encryption algorithm.
6. A method for securely transmitting isolated file data inside and outside a cloud desktop based on a network disk according to claim 1, characterized in that: When deployed in S1, the network disk and the cloud desktop are integrated, and the integration is performed in a mixed manner of virtual data disk and fixed network data disk.
Citation Information
Patent Citations
A safety data transmission method
CN100428665C
Data security transmission method based on message queue
CN107454186A
Internetwork data access method and system based on safety isolation
CN109639652A