A method and system for unidirectional data transfer
By configuring unidirectional data transmission strategies and routes in a multi-domain network environment, the transmission problem of manual participation in traditional methods is solved, and the convenience and security of multi-domain unidirectional data transmission are achieved.
Patent Information
- Application Number
- CN202211663382.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2042-12-23
AI Technical Summary
When there are three or more security-level network domains, the networking deployment method of traditional one-way data transmission equipment cannot meet the convenience requirements and requires manual participation in data transmission.
A one-way data transmission method and system is adopted. By setting up network modules, service modules and management modules in each network domain, configuring one-way transmission strategies, business strategies and one-way transmission routes, multi-domain one-way data transmission is realized, and data transmission based on applications, IP addresses, client parameters and mixed modes is supported.
It supports unidirectional data transmission in multiple domains, provides flexible policy forwarding forms to ensure transmission security, and supports multicast unidirectional data transmission to multiple domains.
Smart Images

Figure CN116032589B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of one-way data transmission, in particular to a one-way data transmission method and system. BACKGROUND
[0002] One-way data transmission devices are widely used in scenarios of transmitting data from a low-security level network domain to a high-security level network domain. Since information is strictly limited to one-way transmission, there is no reverse data transmission, which ensures the reliable and secure isolation of the high-security level network domain while completing data transmission. One-way data transmission devices are widely used in scenarios such as industrial control, finance, and critical infrastructure protection.
[0003] Generally, the transmission source and destination of one-way transmission are each one, i.e., the low-security level network domain and the high-security level network domain.
[0004] When there are three or more security level network domains, transmitting data from a low-security level network domain to a high-security level network domain based on the traditional networking deployment method of one-way data transmission devices cannot meet the convenience of transmission, two one-way transmission devices need to be cascaded, and manual intervention is required for data transmission. SUMMARY
[0005] The technical problem to be solved by the present application is to overcome the defects of the background art. The present application provides a one-way data transmission method and system, which can meet the ability of one-way data transmission based on application, IP address, client parameters, mixed mode, and specified mode.
[0006] To solve the above technical problems, the present application adopts the following technical solutions:
[0007] A one-way data transmission method and system, comprising a first network domain, referred to as L domain, a second network domain, referred to as M domain, and a third network domain, referred to as H domain. In the one-way data transmission system, each of L, M, and H domains corresponds to a module unit, referred to as domain unit. The domain unit is internally provided with a network module, a service module, an analysis module, and a management module. The network module realizes the delivery processing of transmission data to the next hop, supports the data network access protocol, and checks the data source for receiving and selects forwarding or discarding. The service module realizes application-level service proxy. The analysis module realizes compliance and security checking of received data. The management module realizes the configuration and management functions of network access, content analysis strategy, and data forwarding rules. The method further comprises the following steps:
[0008] Step S1, configuring one-way transmission strategy and establishing a specified requirement one-way transmission channel.
[0009] Step S2: Configure business policies to establish supported application services, access network configuration, and compliance and security inspection policies;
[0010] Step S3, configuring a one-way transmission route to specify a destination where specific data can be transmitted one-way;
[0011] Step S4: When the access data enters the domain unit and completes the application service and compliance security check processing, the data that meets the business legitimacy will be matched with the unidirectional transmission policy according to the established business forwarding domain to implement data unidirectional transmission.
[0012] Preferably, the specific steps of step S1 are as follows:
[0013] Configuration of unidirectional transmission policy from L domain to M domain and H domain
[0014] 1) Enter the L domain management module
[0015] a. Configure the domain label, domain label L;
[0016] b. Configure the sendable domain destination and forward label M,H;
[0017] 2) Enter the M domain management module
[0018] a. Configure the domain label, domain label M;
[0019] b. Configure acceptable domain sources, accept label L
[0020] c. Configure the sendable domain destination, forward label H;
[0021] 3) Enter the H domain management module
[0022] a. Configure the domain label, domain label H;
[0023] b. Configure acceptable domain sources, accept label L,M
[0024] At this point, the data transmission path from the L domain to the M domain is reachable, the data transmission path from the M domain to the H domain is reachable, and the data transmission path from the L domain to the H domain is reachable;
[0025] Configuration of unidirectional transmission policy between L domain and M domain, and between M domain and H domain
[0026] The L domain is used to transmit unidirectional data to the M domain. The unidirectional data transmission from the L domain to the H domain and the unidirectional data transmission from the M domain to the H domain are prohibited.
[0027] The configuration is based on the unidirectional data transmission from the L domain to the M domain, which prohibits the unidirectional data transmission from the L domain to the H domain, and the unidirectional data transmission from the M domain to the H domain:
[0028] 4) Enter the L domain management module
[0029] a. Configure the domain label, domain label L;
[0030] b. Configure the domain destination, forward label M;
[0031] 5) Enter the M domain management module
[0032] a. Configure the domain label, domain label M;
[0033] b. Configure acceptable domain sources, accept label L
[0034] c. Configure the sendable domain destination, forward label H;
[0035] 6) Enter the H domain management module
[0036] c. Configure the domain label, domain label H;
[0037] d. Configure acceptable domain sources, accept label M
[0038] At this point, the data transmission path from domain L to domain M is reachable, the data transmission path from domain M to domain H is reachable, but the data transmission path from domain L to domain H is unreachable. The configuration of domain L restricts data transmission to domain H, and the configuration of domain H restricts data reception from domain L.
[0039] Preferably, the method further comprises the following steps:
[0040] After the unidirectional transmission policy between the L, M, and H domains is configured, the corresponding unidirectional transmission channel is established. Before formal unidirectional data transmission, the association between the service destination and the domain label needs to be set according to business requirements, as shown below:
[0041] 7) Set the service destination associated with the destination domain tag according to the client user service parameters
[0042] Configure the association between the service destination and the destination domain label in L domain, configure in the client user parameter mode, and enter the L domain management module;
[0043] b. Configure the business destination and the destination domain association, forward model agent;
[0044] After the client carries the domain parameter information to the domain unit, it is forwarded and transmitted according to the carried domain parameters;
[0045] 8) Set the associated destination domain label based on the IP address
[0046] Configure the association between the service destination and the destination domain label in L domain, and configure it in unit IP address mode.
[0047] Enter the L domain management module
[0048] e. Configure the business destination and the destination domain association, and the forward model IP address;
[0049] f. Configure the association between the destination IP and the destination domain, forward dstip 10.0.0.1M
[0050] g. Configure the association between the destination IP and the destination domain, forward dstip 20.0.0.1H
[0051] h. Configure the relationship between the source IP and the destination domain, forward srcip 30.0.0.1M
[0052] According to the association between the configured IP and the destination domain, data is transmitted in one direction according to the configured IP address;
[0053] 9) Set the associated destination domain tag according to the access application service type
[0054] Configure the relationship between the service destination and the destination domain label in L domain, access the application service type mode for configuration, and enter the L domain management module
[0055] i. Configure the business destination and the target domain association, forward model app;
[0056] j. Configure the association between the application and the destination domain, forward http M
[0057] k. Configure the association between the application and the destination domain, forward https M
[0058] l. Configure the association between the application and the destination domain, forward smtp H
[0059] m. Configure the association between the application and the destination domain, forward pop H
[0060] n. Configure the association between the application and the destination domain, forward imap H
[0061] o. Configure the association between the application and the destination domain, forward sip M
[0062] p. Configure the association between the application and the destination domain, forward h265 M
[0063] According to the association between the access application and the destination domain, data is transmitted in one direction according to the configured application.
[0064] 10) Composite association destination domain tag strategy can be performed
[0065] Enter the L domain management module
[0066] b. Configure the business destination and the destination domain association, forward model hybird;
[0067] So far, the data can be transmitted in one direction by mixing the association modes 1), 2), and 3.
[0068] 11) Configurable multi-destination domain label strategy
[0069] Configure the association between the service destination and the destination domain label in the L domain, and configure the access application service type.
[0070] Enter the L domain management module
[0071] c. Configure the business destination and the target domain association, forward model app;
[0072] d. Configure the association between the application and the destination domain, forward http M,H
[0073] At this point, according to the association between the access application and the destination domain, the specified http data can be transmitted unidirectionally to the M domain and the H domain at the same time;
[0074] 12) Specify the destination domain tag strategy
[0075] Enter the L domain management module
[0076] d. Configure the business destination and the destination domain association, forward model assign;
[0077] e. Configure the specified destination domain association, forward assign M
[0078] At this point, all data, regardless of type, is specified to be transmitted unidirectionally to the M domain;
[0079] f. Configure the specified destination domain association, forward assign M,H
[0080] At this point, all data, regardless of type, is designated for unidirectional transmission to the M domain and the H domain.
[0081] Preferably, it also includes the following:
[0082] After completing the configuration of one-way transmission strategy, business strategy, and one-way transmission routing strategy, the system can be used for one-way data transmission business;
[0083] A unidirectionally transmitted data packet carries a sending domain label and a receiving domain label.
[0084] The sending end of unidirectional transmission, that is, the outbound interface of the sending domain unit, fills the domain label of the current domain unit into the sending domain label field of the transmitted data packet, and fills the receiving domain label of the receiving domain unit into the receiving domain unit label field of the data packet;
[0085] The receiving end of unidirectional transmission, that is, the inbound interface of the receiving domain unit, checks the value of the sending domain label in the received data packet and matches it with the receivable domain label of the current domain unit. If it does not match, it is discarded. If it matches the sending domain, it then determines whether to receive it in the local domain unit or forward it to the next hop (that is, the unidirectional transmission outbound interface of the local domain unit) based on the value of the receiving domain label in the received data packet, or whether to receive it in the local domain unit and forward it to the next hop at the same time.
[0086] The receiving end of unidirectional transmission removes the sending domain label and receiving domain label from the data packet received and processed by the local domain unit, obtains the received data payload, and transfers it to the service module to continue the next business processing;
[0087] The receiving end of a unidirectional transmission does not process packets that are not intended to be received by the local unit, but forwards them to the next hop, that is, directly to the unidirectional data transmission outbound interface of the local unit. The unidirectional transmission outbound interface of the local unit compares the receiving domain label field in the packet with the transmit domain label of the local unit. If the packet does not match, it is immediately discarded. If the packet matches, it is sent directly from the outbound interface without modification.
[0088] The receiving end of unidirectional transmission makes two copies of the data packets received by the local unit and forwarded to the next hop at the same time, and executes the receiving execution process of the local unit and the execution process of sending to the next hop respectively.
[0089] Compared with the prior art, the present invention has the following beneficial effects:
[0090] 1. The present invention provides a unidirectional data transmission method and system that supports unidirectional data transmission in multiple domains.
[0091] 2. The present invention provides a one-way data transmission method and system that supports the limitation of the receivable domain and the sendable domain of the domain unit, further providing the security of the one-way transmission.
[0092] 3. The application provides a one-way data transmission method and system, which supports flexible policy-based forwarding transmission mode and can meet the ability of one-way data transmission based on application, IP address, client parameter, mixed mode and specified mode.
[0093] 4. The application provides a one-way data transmission method and system, which supports one-way data transmission to multiple domain groups simultaneously. BRIEF DESCRIPTION OF DRAWINGS
[0094] In order to more clearly illustrate the specific embodiments of the application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or prior art description. Obviously, the drawings described below are some embodiments of the application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.
[0095] Figure 1 The flowchart of the application;
[0096] Figure 2 The structure diagram of a multi-domain one-way transmission system;
[0097] Figure 3 L-domain name to M-domain and H-domain one-way data transmission;
[0098] Figure 4 L-domain name to M-domain and M-domain to H-domain one-way data transmission;
[0099] Figure 5 According to the client parameter to associate the destination domain label;
[0100] Figure 6 According to the IP address to set the associated destination domain label;
[0101] Figure 7 According to the access application service type to associate the destination domain label;
[0102] Figure 8 One-way data transmission source and destination label;
[0103] Figure 9 Single-domain single-hop one-way forwarding example;
[0104] Figure 10 Single-domain one-way multi-hop forwarding example;
[0105] Figure 11 Multi-domain one-way multicast forwarding example. DETAILED DESCRIPTION
[0106] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0107] A multi-domain unidirectional data transmission method and system can realize unidirectional data transmission in three or more network isolation domains, namely the first network domain (hereinafter referred to as the L domain), the second network domain (hereinafter referred to as the M domain), and the third network domain (hereinafter referred to as the H domain). In scenarios with more than three isolated network domains, this technology can be expanded to support unidirectional data transmission in more than three domains. This patent uses a three-domain unidirectional data transmission system as an example to illustrate.
[0108] like Figure 2 As shown, within the one-way data transmission system implemented by this technology, each domain of L, M, and H corresponds to a module unit, referred to as the domain unit. Each domain unit is equipped with a network module, a service module, an analysis module, and a management module. The network module implements the delivery processing of transmitted data to the next hop, supports the data network access protocol, and checks the data source for permission to receive and chooses to forward or discard it. The service module implements application-level service agents (such as HTTP, FTP, email, audio and video, etc. application agents). The analysis module implements compliance and security checks on received data. The management module implements the configuration and management functions of network access, content analysis strategies, and data forwarding rules.
[0109] A unidirectional transmission channel is set between the L domain unit and the M domain unit, and the L domain data is unidirectionally transmitted to the M domain unit through the L domain unit.
[0110] A unidirectional transmission channel is set between the M domain unit and the H domain unit, and the M domain data is unidirectionally transmitted to the H domain unit through the M domain unit.
[0111] The L domain unit and the H domain unit can be connected through two unidirectional transmission channels, that is, the L domain data is unidirectionally transmitted through the L domain unit to the M domain unit, and then continues to be unidirectionally transmitted to the H domain unit.
[0112] The L domain unit can simultaneously transmit unidirectional multicast data to the M domain unit and the H domain unit.
[0113] Each domain unit can be configured to receive data from a specified domain source, which can be one or more.
[0114] Each domain unit can be configured to send data to a specific domain destination, which can be one or more.
[0115] Before using this one-way data transmission system for the first time, you must first configure the forwarding policy through the management module of each domain unit. Each domain unit is configured with a domain label (for data forwarding and delivery); each domain unit is configured with a sendable domain destination; and each domain unit is configured with a receiveable domain source. The L domain unit, as the first domain unit with the lowest security level, does not require a receiveable domain source configuration. The H domain unit, as the last domain unit with the highest security level, does not require a sendable domain destination configuration.
[0116] 1. One-way transmission policy configuration
[0117] Configuration of unidirectional transmission policy from L domain to M domain and H domain
[0118] Take the example of unidirectional data transmission from L domain to M domain and H domain, and unidirectional data transmission from M domain to H domain, as shown in the following example: Figure 3 As shown,
[0119] 1) Enter the L domain management module
[0120] a. Configure the domain label, domain label L;
[0121] B. Configure the sendable domain destination, forward label M,H;
[0122] 2) Enter the M domain management module
[0123] d. Configure the domain label, domain label M;
[0124] e. Configure acceptable domain sources, accept label L
[0125] f. Configure the sendable domain destination, forward label H;
[0126] 3) Enter the H domain management module
[0127] c. Configure the domain label, domain label H;
[0128] d. Configure acceptable domain sources, accept label L,M
[0129] So far, if Figure 2 As shown, the data transmission path from the L domain to the M domain is reachable, the data transmission path from the M domain to the H domain is reachable, and the data transmission path from the L domain to the H domain is reachable.
[0130] Configuration of unidirectional transmission policy between L domain and M domain, and between M domain and H domain
[0131] Take the example of unidirectional data transmission from L domain to M domain (unidirectional data transmission from L domain to H domain is prohibited), and unidirectional data transmission from M domain to H domain, as follows: Figure 4 shown
[0132] 1) Enter the L domain management module
[0133] a. Configure the domain label, domain label L;
[0134] b. Configure the domain destination, forward label M;
[0135] 2) Enter the M domain management module
[0136] a. Configure the domain label, domain label M;
[0137] b. Configure acceptable domain sources, accept label L
[0138] c. Configure the sendable domain destination, forward label H;
[0139] 3) Enter the H domain management module
[0140] a. Configure the domain label, domain label H;
[0141] b. Configure acceptable domain sources, accept label M
[0142] So far, if Figure 4 As shown in Figure 1, the data transmission path from domain L to domain M is reachable, the data transmission path from domain M to domain H is reachable, and the data transmission path from domain L to domain H is unreachable. The L domain is configured to restrict data transmission to domain H, and domain H is also configured to restrict data reception from domain L.
[0143] 2. Business policy configuration
[0144] After configuring the relevant business policies of the network module, service module, and analysis module, one-way data transmission can begin. After processing the received data, the domain unit can process and send the data that meets the requirements (based on certain specific compliance and security policies, which are not included in this technical claim).
[0145] 3. One-way transmission routing policy configuration
[0146] After the unidirectional transmission policy between the L, M, and H domains is configured, the corresponding unidirectional transmission channel is established. Before the unidirectional data transmission is officially carried out, the association between the service destination and the domain label needs to be set according to the business requirements.
[0147] The correspondence between business destinations and destination domain labels can be divided into six modes:
[0148] 1) Set the service destination and associated destination domain tag according to the client user service parameters
[0149] Take the association relationship between the L domain configuration service destination and the destination domain label (client user parameter mode) as an example for configuration. Figure 5 shown
[0150] Enter the L domain management module
[0151] a. Configure the business destination and the destination domain association, forward model agent;
[0152] At this point, after the client carries the domain parameter information to the domain unit, it can be forwarded and transmitted in a designated manner according to the carried domain parameters.
[0153] 2) Set the associated destination domain label based on the IP address
[0154] Take the association relationship between the L domain configuration service destination and the destination domain label (unit IP address mode) as an example for configuration. Figure 6 shown
[0155] Enter the L domain management module
[0156] a. Configure the service destination and the destination domain association, and the forward model IP address.
[0157] b. Configure the association between the destination IP and the destination domain, forward dstip 10.0.0.1M
[0158] c. Configure the association between the destination IP and the destination domain, forward dstip 20.0.0.1H
[0159] d. Configure the relationship between the source IP and the destination domain, forward srcip 30.0.0.1M
[0160] At this point, according to the configured association between the IP and the destination domain, data can be transmitted in a designated one-way manner according to the configured IP address.
[0161] 3) Set the associated destination domain tag according to the access application service type
[0162] Take the association relationship between the L domain configuration service destination and the destination domain label (access application service type mode) as an example for configuration. Figure 7 shown
[0163] Enter the L domain management module
[0164] a. Configure the business destination and the target domain association, forward model app;
[0165] b. Configure the association between the application and the destination domain, forward http M
[0166] c. Configure the association between the application and the destination domain, forward https M
[0167] d. Configure the association between the application and the destination domain, forward smtp H
[0168] e. Configure the association between the application and the destination domain, forward pop H
[0169] f. Configure the association between the application and the destination domain, forward imap H
[0170] g. Configure the association between the application and the destination domain, forward sip M
[0171] h. Configure the association between the application and the destination domain, forward h265 M
[0172] At this point, according to the association between the access application and the destination domain, data can be transmitted in a designated one-way manner according to the configured application.
[0173] 4) Composite association destination domain tag strategy can be performed
[0174] Enter the L domain management module
[0175] a. Configure the business destination and the destination domain association, forward model hybird;
[0176] At this point, the above three association modes can be mixed to carry out data-specified unidirectional transmission.
[0177] 5) Configurable multi-destination domain labeling strategy
[0178] Take the association relationship between the L domain configuration service destination and the destination domain label (access application service type) as an example to configure and enter the L domain management module
[0179] a. Configure the business destination and the target domain association, forward model app;
[0180] b. Configure the association between the application and the destination domain, forward http M,H
[0181] At this point, according to the association between the access application and the destination domain, the specified http data can be transmitted unidirectionally to the M domain and the H domain at the same time.
[0182] 6) Specify the destination domain tag strategy
[0183] Enter the L domain management module
[0184] a. Configure the business destination and the destination domain association, forward model assign;
[0185] b. Configure the specified destination domain association, forward assign M
[0186] At this point, all data, regardless of type, is specified to be transmitted unidirectionally to the M domain.
[0187] c. Configure the specified destination domain association, forward assign M,H
[0188] At this point, all data, regardless of type, is designated for unidirectional transmission to the M domain and the H domain.
[0189] 4. One-way transmission of business data
[0190] After completing the configuration of one-way transmission strategy, service strategy, and one-way transmission routing strategy, the system can be used for one-way data transmission services.
[0191] A unidirectionally transmitted data packet carries a sending domain label and a receiving domain label, such as Figure 8 shown.
[0192] The sending end of unidirectional transmission, that is, the outbound interface of the sending domain unit, fills the domain label of the current domain unit into the sending domain label field of the transmitted data packet, and fills the receiving domain label of the receiving domain unit into the receiving domain unit label field of the data packet.
[0193] The receiving end of unidirectional transmission, that is, the inbound interface of the receiving domain unit, checks the value of the sending domain label in the received data packet and matches it with the receivable domain label of the current domain unit. If it does not match, it is discarded. If it matches the sending domain, it then determines whether the local domain unit receives it or forwards it to the next hop (that is, the unidirectional transmission outbound interface of the local domain unit) based on the value of the receiving domain label in the received data packet, or whether the local domain unit receives it and forwards it to the next hop at the same time.
[0194] The receiving end of the unidirectional transmission removes the sending domain label and receiving domain label from the data packet received and processed by the domain unit, obtains the received data payload, and transfers it to the service module to continue the next business processing (business processing is not within the scope of this technical claim).
[0195] The receiving end of unidirectional transmission does not process data packets that are not intended to be received by the local domain unit, but forwards them to the next hop, that is, directly to the unidirectional data transmission outbound interface of the local domain unit. The unidirectional transmission outbound interface of the local domain unit compares the receiving domain label field in the data packet with the sendable domain label of the local domain unit. If the data packet does not match, it will be discarded immediately. If the data packet matches, it will be sent directly from the outbound interface without modification.
[0196] The receiving end of unidirectional transmission makes two copies of the data packets received by the local unit and forwarded to the next hop at the same time, and executes the receiving execution process of the local unit and the execution process of sending to the next hop respectively.
[0197] This example uses the following configuration examples to set the forwarding mode of the target domain for unidirectional transmission between the L domain and the M domain and the H domain by accessing the application service type, and the unidirectional transmission policy between the L domain and the M domain and the H domain.
[0198] 1) Single-domain, unidirectional, single-hop forwarding
[0199] refer to Figure 9 ,According to the L-domain sending domain destination, the M-domain receiving domain source configuration, and the L-domain forwarding association configuration, when the L-domain unit receives the transmission data and is processed by the service module and the analysis module, it is ready to be sent from the L-domain unidirectional transmission output interface. The unidirectional transmission output interface shows the single-domain unidirectional single-hop data transmission process based on the original data source and the establishment of the unidirectional channel.
[0200] L domain:
[0201] domain label L;
[0202] forward label M;
[0203] forward model app;
[0204] forward http M;
[0205] M domain:
[0206] domain label M;
[0207] accept label L;
[0208] The L-domain outbound interface, based on the forwarding relationship between the HTTP application and the M-domain, prepares to forward the data to the next-hop M-domain. It also checks that the M-domain is a sendable destination for the L-domain. Therefore, the transmitted data carries the L-domain label as the send-domain label field and the M-domain label as the receive-domain label field before forwarding. The M-domain inbound interface checks that the data received by the M-domain contains the L-domain label, confirming that it is a receiveable source. The data is received, the send-domain label and the receive-domain label are removed from the data packet, and the application data is passed to the service module for processing.
[0209] 2) Single-domain unidirectional multi-hop forwarding
[0210] refer to Figure 7,According to the sending domain destination of L domain and M domain, the receiving domain source configuration of M domain and H domain, and the forwarding association configuration of L and M domain, when the L domain unit receives the transmission data and is processed by the service module and the analysis module, it is ready to be sent from the unidirectional transmission output interface of L domain. The unidirectional transmission output interface shows the single-domain unidirectional multi-hop data transmission process according to the original data source of the data and the unidirectional transmission strategy between L domain and H domain.
[0211] L domain:
[0212] domain label L;
[0213] forward label M,H;
[0214] forward model app;
[0215] forward http H;
[0216] M domain:
[0217] domain label M;
[0218] accept label L
[0219] forward label H;
[0220] H domain:
[0221] domain label H;
[0222] accept label L,M
[0223] refer to Figure 10 This shows the process of unidirectional multi-hop forwarding of HTTP data in the L domain to the H domain.
[0224] 3) Multi-domain unidirectional multicast forwarding
[0225] Based on the single-domain unidirectional multi-hop forwarding example, the L domain is configured with the following additional features:
[0226] forward http M, H;
[0227] refer to Figure 11 This diagram shows the process of forwarding HTTP data from domain L to domains M and H simultaneously.
[0228] 4) One-way transmission outbound interface discards
[0229] When the sendable domain label configured by the sending domain unit does not include the destination domain label of the data to be sent, the unidirectional transmission output interface performs a discard process.
[0230] Configuration examples include:
[0231] L domain:
[0232] domain label L;
[0233] forward label M;
[0234] forward model app;
[0235] forward http H;
[0236] The L domain receives HTTP data and prepares to send it to the unidirectional transmission output interface, but the sendable domain label does not support the H domain, so it is discarded on this output interface.
[0237] Configuration examples include:
[0238] L domain:
[0239] domain label L;
[0240] forward label M,H;
[0241] forward model app;
[0242] forward http H;
[0243] M domain:
[0244] domain label M;
[0245] accept label L;
[0246] The M domain receives data transmitted by the L domain unit, but the destination domain is not the local domain unit. The data packet is forwarded to the next hop, that is, the unidirectional transmission outbound interface of the local domain unit. However, the sendable field of the unidirectional transmission outbound interface of the domain unit does not contain H. Therefore, the unidirectional transmission outbound interface of the M domain unit discards the data packet.
[0247] 5) One-way transmission input interface discards
[0248] When the receivable domain tag configured by the receiving domain unit does not include the sending domain tag of the data to be received, the unidirectional transmission input interface performs a discarding process.
[0249] Configuration examples include:
[0250] L domain:
[0251] domain label L;
[0252] forward label M, H;
[0253] forward model app;
[0254] forward http M;
[0255] H domain:
[0256] domain label H;
[0257] accept label M;
[0258] The H domain receives data transmitted by the L domain unit, but the destination domain is the local domain unit. However, the local domain unit does not support the L domain, so the data is discarded on the inbound interface.
[0259] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A one-way data transmission method and system, characterized in that: It includes a first network domain, referred to as L domain, a second network domain, referred to as M domain, and a third network domain, referred to as H domain. Within the unidirectional data transmission system, each of the L, M, and H domains corresponds to a module unit, referred to as a domain unit; the domain unit is internally provided with a network module, a service module, an analysis module, and a management module; The network module implements the delivery processing of transmitted data to the next hop, supports the data network access protocol, and checks the data source for permission to receive and chooses to forward or discard; the service module implements application-level service proxy; the analysis module implements compliance and security checks on received data; the management module implements the configuration and management functions of network access, content analysis strategy, and data forwarding rules; The following steps are also included: Step S1, configure a one-way transmission policy and establish a specified one-way transmission channel; Step S2: Configure business policies to establish supported application services, access network configuration, and compliance and security inspection policies; Step S3, configuring a one-way transmission route to specify a destination where specific data can be transmitted one-way; Step S4: When the access data enters the domain unit and completes the application service and compliance security check processing, the data that meets the business legitimacy is matched with the established business forwarding domain and the unidirectional transmission policy, and the data is transmitted in one direction; The specific steps of step S1 are as follows: Configuration of unidirectional transmission policy from L domain to M domain and H domain 1) Enter the L domain management module a. Configure domain label L; b. Configure the sendable domain destination and forward label M,H; 2) Enter the M domain management module a. Configure the domain label, domain label M; b. Configure the acceptable domain source, accept label L c. Configure the sendable domain destination, forward label H; 3) Enter the H domain management module a. Configure the domain label, domain label H; b. Configure acceptable domain sources, accept label L,M At this point, the data transmission path from the L domain to the M domain is reachable, the data transmission path from the M domain to the H domain is reachable, and the data transmission path from the L domain to the H domain is reachable; Configuration of unidirectional transmission policy between L domain and M domain, and between M domain and H domain The L domain is used to transmit unidirectional data to the M domain. The unidirectional data transmission from the L domain to the H domain and the unidirectional data transmission from the M domain to the H domain are prohibited. The configuration is based on the unidirectional data transmission from the L domain to the M domain, which prohibits the unidirectional data transmission from the L domain to the H domain, and the unidirectional data transmission from the M domain to the H domain: 1) Enter the L domain management module a. Configure the domain label, domain label L; b. Configure the domain destination, forward label M; 2) Enter the M domain management module a. Configure the domain label, domain label M; b. Configure the acceptable domain source, accept label L c. Configure the sendable domain destination, forward label H; 3) Enter the H domain management module a. Configure the domain label, domain label H; b. Configure the acceptable domain source, accept label M; At this point, the data transmission path from domain L to domain M is reachable, the data transmission path from domain M to domain H is reachable, but the data transmission path from domain L to domain H is unreachable. The configuration of domain L restricts data transmission to domain H, and domain H also restricts data reception from domain L. After the unidirectional transmission policy between the L, M, and H domains is configured, the corresponding unidirectional transmission channel is established. Before formal unidirectional data transmission, the association between the service destination and the domain label needs to be set according to business requirements, as shown below: 1) Set the service destination and associated destination domain tag according to the client user service parameters Configure the association between the service destination and the destination domain label in L domain, configure in the client user parameter mode, and enter the L domain management module; a. Configure the service destination and the destination domain association, forward model agent; after the client carries the domain parameter information to the domain unit, it forwards the transmission according to the carried domain parameters; 2) Set the associated destination domain label based on the IP address Configure the association between the service destination and the destination domain label in L domain, and configure it in unit IP address mode. Enter the L domain management module a. Configure the service destination and the destination domain association, and the forward model IP address. b. Configure the association between the destination IP and the destination domain, forward dstip 10.0.0.1M c. Configure the association between the destination IP and the destination domain, forward dstip 20.0.0.1H d. Configure the relationship between the source IP and the destination domain, forward srcip 30.0.0.1M According to the association between the configured IP and the destination domain, data is transmitted in one direction according to the configured IP address; 3) Set the associated destination domain tag according to the access application service type Configure the relationship between the service destination and the destination domain label in L domain, access the application service type mode for configuration, and enter the L domain management module a. Configure the business destination and the target domain association, forward model app; b. Configure the association between the application and the destination domain, forward http M c. Configure the association between the application and the destination domain, forward https M d. Configure the association between the application and the destination domain, forward smtp H e. Configure the association between the application and the destination domain, forward pop H f. Configure the association between the application and the destination domain, forward imap H g. Configure the association between the application and the destination domain, forward sip M h. Configure the association between the application and the destination domain, forward h265 M According to the association between the access application and the destination domain, data is transmitted in one direction according to the configured application. 4) Composite association destination domain tag strategy can be performed Enter the L domain management module a. Configure the business destination and the destination domain association, forward model hybird; So far, the data can be transmitted in one direction by mixing the association modes 1), 2), and 3. 5) Configurable multi-destination domain labeling strategy Configure the association between the service destination and the destination domain label in the L domain, access the application service type to configure and enter the L domain management module a. Configure the business destination and the target domain association, forward model app; b. Configure the association between the application and the destination domain, forward http M,H At this point, according to the association between the access application and the destination domain, the specified http data can be transmitted unidirectionally to the M domain and the H domain at the same time; 6) Specify the destination domain tag strategy Enter the L domain management module a. Configure the business destination and the destination domain association, forward model assign; b. Configure the specified destination domain association, "forward assign M." This specifies that all data, regardless of type, is transmitted unidirectionally to domain M. c. Configure the specified destination domain association, forward assign M,H At this point, all data, regardless of type, is designated for unidirectional transmission to the M domain and the H domain.
2. A one-way data transmission method and system according to claim 1, characterized in that: Also includes the following: After completing the configuration of one-way transmission strategy, business strategy, and one-way transmission routing strategy, the system can be used for one-way data transmission business; A unidirectionally transmitted data packet carries a sending domain label and a receiving domain label. The sending end of unidirectional transmission, that is, the outbound interface of the sending domain unit, fills the domain label of the current domain unit into the sending domain label field of the transmitted data packet, and fills the receiving domain label of the receiving domain unit into the receiving domain unit label field of the data packet; The receiving end of unidirectional transmission, that is, the inbound interface of the receiving domain unit, checks the value of the sending domain label in the received data packet and matches it with the receivable domain label of the current domain unit. If it does not match, it is discarded. If it matches the sending domain, it then determines whether to receive it in the local domain unit or forward it to the next hop, that is, the unidirectional transmission outbound interface of the local domain unit, or both receive it in the local domain unit and forward it to the next hop based on the value of the receiving domain label in the received data packet. The receiving end of unidirectional transmission removes the sending domain label and receiving domain label from the data packet received and processed by the local domain unit, obtains the received data payload, and transfers it to the service module to continue the next business processing; The receiving end of a unidirectional transmission does not process packets that are not intended to be received by the local unit, but forwards them to the next hop, that is, directly to the unidirectional data transmission outbound interface of the local unit. The unidirectional transmission outbound interface of the local unit compares the receiving domain label field in the packet with the transmit domain label of the local unit. If the packet does not match, it is immediately discarded. If the packet matches, it is sent directly from the outbound interface without modification. The receiving end of unidirectional transmission makes two copies of the data packets received by the local unit and forwarded to the next hop at the same time, and executes the receiving execution process of the local unit and the execution process of sending to the next hop respectively.
Citation Information
Patent Citations
Hierarchical sub-domain control method and system based on network label communication
CN103944884A