A Cross-Domain Secure Data Flow Detection System, Method, Device and Storage Medium

By using data identification and verification code mechanisms in the data cross-domain identification tunnel system, the cross-domain data compliance identification and verification problems are solved, efficient cross-domain data identification and secure transmission are achieved, and data compliance and traceability are ensured.

CN118659933BActive Publication Date: 2025-06-13中孚安全技术有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411140823.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-20
Publication Date
2025-06-13
Estimated Expiration
2044-08-20

AI Technical Summary

Technical Problem

It is difficult for the prior art to effectively identify and verify the compliance of cross-domain data, especially in massive data, which data can be accurately identified. Moreover, due to data encryption, it is impossible to distinguish sensitive data, and the lack of effective monitoring and auditing measures, resulting in the inability to block illegal cross-domain transmission behavior in a timely manner.

Method used

Using specific encapsulated data identification technology, a verification code mechanism is implemented in the data identification, and non-invasive verification and detection of cross-domain data is achieved through the data cross-domain identification tunnel system and verification system.

Benefits of technology

It improves the identification efficiency of cross-domain data, realizes the ability of "ununboxing detection", ensures the integrity and immutability of data identification, and provides traceability and security compliance for cross-domain data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118659933B_ABST
    Figure CN118659933B_ABST
Patent Text Reader

Abstract

A data cross - domain secure transfer detection system, method, device and storage medium proposed by the present invention belong to the technical field of data processing. The method includes: generating service data and sending it to a data verification end through an intra - domain network; identifying the destination IP of the service data through a data cross - domain identification tunnel system, and identifying the service data sent to an extra - domain network; identifying the data content of the service data and generating a data identifier; encapsulating the data identifier and the service data into a tunnel carrier; receiving the tunnel carrier through a data cross - domain identification tunnel verification system, stripping the tunnel header of the tunnel carrier, and extracting the data identifier; verifying the data identifier; and performing transfer processing on the service data sent to the extra - domain network according to the verification result. The present invention utilizes a specific encapsulated data identifier technology and implements a check code mechanism in the data identifier, improving the identification efficiency of cross - domain data and realizing non - intrusive data verification and detection of cross - domain data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and more specifically, to a data cross-domain secure transfer detection system, method, device, and storage medium. Background Art

[0002] Data cross-domain flow refers to a data processor providing service data to an external network. This generally includes cross-domain transmission and transfer of data, as well as situations where, although the data has not crossed domains, it can be accessed and processed by entities in the external network. With the acceleration of the digitalization process, data cross-domain flow has become increasingly frequent, and data problems have become increasingly prominent.

[0003] Currently, in order to ensure the security of data transmission, the Internet in each region conducts data cross-domain detection according to its own requirements, but there are many difficulties in the specific implementation. Due to factors such as the diversity of data types, the complexity of formats, and the uncertainty of transmission methods, it is a very difficult task to ensure the compliance of each cross-domain data item.

[0004] Specifically, first, due to the huge amount of cross-domain transferred data, it is impossible to accurately identify which data can be cross-domain transmitted in the vast amount of data. Second, since cross-domain data is encrypted, it is impossible to effectively distinguish sensitive data or protected information therein, such as personal information, important geographical information, important meteorological data, etc. In addition, due to the lack of effective monitoring and auditing measures for data cross-domain flow, it is impossible to timely and effectively block the illegal cross-domain transmission behavior of data. Summary of the Invention

[0005] In view of the above problems, the purpose of the present invention is to provide a data cross-domain secure transfer detection system, method, device, and storage medium, which utilize a specific encapsulated data identification technology and implement a check code mechanism in the data identification, improving the identification efficiency of cross-domain data and realizing non-intrusive data verification and detection of cross-domain data.

[0006] To achieve the above object, the present invention is realized through the following technical solutions: A data cross-domain secure transfer detection system, comprising:

[0007] A data sending end and a data verification end, the data sending end and the data verification end are connected through intradomain network data, and the data verification end is also connected to the external network;

[0008] A plurality of business systems and a data cross-domain identification tunnel system are provided in the data sending end; a data cross-domain identification tunnel verification system is provided in the data verification end;

[0009] The data cross-domain identification tunnel system is respectively connected to the business system and the data cross-domain identification tunnel verification system through data;

[0010] The business system is used to generate business data to be sent to the in-domain network or the out-of-domain network, and send it to the data cross-domain identification tunnel system;

[0011] The data cross-domain identification tunnel system is used to identify the business data sent to the out-of-domain network, encapsulate the business data into a tunnel carrier through tunnel encapsulation processing, add a data identifier to the tunnel carrier, and send the tunnel carrier to the data cross-domain identification tunnel verification system;

[0012] The data cross-domain identification tunnel verification system is used to perform decapsulation processing on the tunnel carrier, extract the data identifier therein, and verify the data identifier; if the verification passes, forward the business data in the tunnel carrier to the out-of-domain network.

[0013] Furthermore, the business system includes: a commodity shelf system, a commodity logistics system, and an employee information system;

[0014] The commodity shelf system is used to generate business data to be sent to the out-of-domain network;

[0015] The commodity logistics system is used to generate business data to be sent to the out-of-domain network;

[0016] The employee information system is used to generate business data to be sent to the in-domain network.

[0017] Furthermore, the tunnel carrier includes: a tunnel header and a tunnel payload;

[0018] The tunnel header is used to store the IPv4 tunnel header;

[0019] The tunnel payload is used to store the data identifier and the business data.

[0020] Furthermore, the data identifier sequentially records the identifier length, the identifier ID, the business additional information, the extended field, and the identifier check code;

[0021] The identifier length is stored at the starting position of the tunnel payload, and is used to record the length of the data identifier;

[0022] The identifier ID is used to record the description information related to the business data, including but not limited to: the data provider, the business type, and the business data level;

[0023] The business additional information is used to record the data scale of the business data;

[0024] The extended field is used to record the algorithm type of the identifier check code;

[0025] The identifier check code is used to perform data verification on the data identifier in cooperation with the algorithm type recorded in the extended field.

[0026] Correspondingly, the present invention also discloses a method for detecting cross - domain secure data transfer, including the following steps:

[0027] S1: The business system in the data sending end generates business data and sends it to the cross - domain identification tunnel system through the intradomain network;

[0028] S2: The cross - domain identification tunnel system identifies the destination IP of the business data and identifies the business data sent to the extradomain network;

[0029] S3: Identify the data content of the business data sent to the extradomain network and generate a data identifier;

[0030] S4: Package the data identifier and the business data sent to the extradomain network into a tunnel carrier and send it to the cross - domain identification tunnel verification system;

[0031] S5: The cross - domain identification tunnel verification system receives the tunnel carrier, strips the tunnel header of the tunnel carrier, and extracts the data identifier;

[0032] S6: Verify the data identifier;

[0033] S7: Perform transfer processing on the business data sent to the extradomain network according to the verification result.

[0034] Further, step S2 includes:

[0035] The cross - domain identification tunnel system identifies the destination IP of the business data;

[0036] Judge whether the destination IP is an extradomain network IP;

[0037] If so, the business data is the business data sent to the extradomain network;

[0038] If not, the business data is the business data sent to the intradomain network, and the business data is directly forwarded according to the destination IP.

[0039] Further, step S3 includes:

[0040] Identify the content of the business data, determine the data provider, business type, and business data level according to the content of the business, and record the identification length, identification ID, business additional information, extended field, and identification check code according to the format of the data identifier to generate a data identifier.

[0041] Further, step S7 includes:

[0042] If the verification result is successful verification, then strip the data identifier in the tunnel carrier, generate a traffic packet for the business data sent to the extradomain network, send it to the extradomain network according to the destination IP, and record the audit log;

[0043] If the verification result is a verification failure, data flow blocking processing is performed on the tunnel carrier.

[0044] Correspondingly, the present invention discloses a data cross-domain security transfer detection device, including:

[0045] A memory for storing a data cross-domain security transfer detection program;

[0046] A processor for implementing the steps of the data cross-domain security transfer detection method as described in any one of the above when executing the data cross-domain security transfer detection program.

[0047] Correspondingly, the present invention discloses a readable storage medium, on which a data cross-domain security transfer detection program is stored, and when the data cross-domain security transfer detection program is executed by a processor, the steps of the data cross-domain security transfer detection method as described in any one of the above are implemented.

[0048] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0049] 1. The present invention guarantees the security of cross-domain service data through the IPv4 tunnel mechanism, avoiding the potential risk of cross-domain data being snooped.

[0050] 2. The present invention quickly identifies attribute information such as the type, importance level, and transmission size of cross-domain data through data identifiers, greatly improving the identification efficiency of cross-domain data and realizing the "unopened box detection" ability.

[0051] 3. The present invention guarantees the integrity and non-tamperability of data identifiers through the check code mechanism of data identifiers, ensuring the traceability of cross-domain data transmission.

[0052] 4. The present invention provides the "digital transmission audit" ability for the secure transmission of cross-domain data by establishing a data cross-domain identifier tunnel verification system, ensuring the security and compliance of cross-domain data transmission.

[0053] It can be seen that compared with the prior art, the present invention has prominent substantive features and significant progress, and the beneficial effects of its implementation are also obvious. Description of the Drawings

[0054] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0055] Figure 1It is the system structure diagram of the specific implementation manner of the present invention.

[0056] Figure 2 It is the structure schematic diagram of the tunnel carrier of the specific implementation manner of the present invention.

[0057] Figure 3 It is the method flowchart of the specific implementation manner of the present invention.

[0058] In the figure, 1 is the data sending end; 2 is the data verification end; 3 is the service system; 4 is the data cross-domain identification tunnel system; 5 is the data cross-domain identification tunnel verification system. Specific implementation manner

[0059] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0060] See Figure 1 As shown, this embodiment provides a data cross-domain secure transfer detection system, including: a data sending end 1 and a data verification end 2. The data sending end 1 and the data verification end 2 are connected by intradomain network data. The data verification end 2 is also connected to the extradomain network.

[0061] A plurality of service systems 3 and a data cross-domain identification tunnel system 4 are provided in the data sending end 1; a data cross-domain identification tunnel verification system 5 is provided in the data verification end 2. The data cross-domain identification tunnel system 4 is respectively connected to the service system 3 and the data cross-domain identification tunnel verification system 5 by data.

[0062] The service system 3 is used to generate service data to be sent to the intradomain network or the extradomain network and send it to the data cross-domain identification tunnel system 4. Among them, the service system 3 includes, but is not limited to: a commodity shelf system, a commodity logistics system, and an employee information system. Among them, the commodity shelf system and the commodity logistics system provide data services to the outside of the domain, while the business traffic of the employee information system only circulates within the domain.

[0063] The data cross-domain identification tunnel system 4 is used to identify the service data sent to the extradomain network, encapsulate the service data into a tunnel carrier through tunnel encapsulation processing, add a data identifier to the tunnel carrier, and send the tunnel carrier to the data cross-domain identification tunnel verification system 5.

[0064] The data cross-domain identification tunnel verification system 5 is used to unpack the tunnel carrier, extract the data identification therein, and verify the data identification; if the verification is passed, the business data in the tunnel carrier is forwarded to the external network.

[0065] In a specific embodiment, Figure 2 As shown, the tunnel carrier includes: a tunnel header and a tunnel payload; wherein the tunnel header is used to store the IPv4 tunnel header, and the tunnel payload is used to store the data identifier and service data.

[0066] The data identifier is encapsulated in the IPv4 tunnel carrier, including: identifier length, identifier ID, service additional information, extension field and identifier check code, as detailed below:

[0067] Identifier length: It is set at the beginning of the tunnel payload, occupies 2 bytes, and indicates the overall length of the data identifier.

[0068] Identification ID: It is a set of character string feature codes that represent common descriptive information in multiple dimensions, such as data provider, business type, and business data level.

[0069] Business additional information: used to describe the specific size of business data transmission, such as the size of unstructured files, or the number of entries returned by the database.

[0070] Extension field: As supplementary information, it implements customized extension functions according to requirements, such as specifying the algorithm type of the identification verification code.

[0071] Identification check code: A certain algorithm is used to calculate the data identification field to ensure that the identification content cannot be tampered with and the integrity of the identification content.

[0072] It should be noted that the data cross-domain identification tunnel system 4 can adopt mainstream IPv4 tunnel technology, including but not limited to ipsec, L2TP, PPTP, GRE and other tunnel technologies. In addition, the data cross-domain identification tunnel system 4 can also adopt the encrypted tunnel technology based on the SSL transport layer, encapsulate the data identification and the original cross-domain traffic message in the transport layer, and unpack and identify them uniformly at the data verification end 2.

[0073] Based on the system structure and functions disclosed by the above data cross-domain security flow detection system, see Figure 3 As shown, the present invention also discloses a method for detecting cross-domain secure data transfer, comprising the following steps:

[0074] S1: The business system in the data sending end generates business data and sends it to the data cross-domain identification tunnel system through the intra-domain network.

[0075] In a specific implementation manner, the business data that needs to cross domains is generated within the data sender. Externally, the cross-domain data is obtained through a request for download and transmitted to the data cross-domain identification tunnel system through a network protocol.

[0076] S2: Identify the destination IP of the business data through the data cross-domain identification tunnel system, and identify the business data sent to the external network.

[0077] In a specific implementation manner, the business data passes through the data cross-domain identification tunnel system. This system analyzes the destination IP to determine whether it is cross-domain traffic. If it is not cross-domain traffic, it is directly forwarded without encapsulating the tunnel. If it is cross-domain traffic, it enters the tunnel module for processing.

[0078] Specifically, first identify the destination IP of the business data through the data cross-domain identification tunnel system. Then, determine whether the destination IP is an external network IP. If so, the business data is the business data sent to the external network; if not, the business data is the business data sent to the internal network, and the business data is directly forwarded according to the destination IP.

[0079] S3: Identify the data content of the business data sent to the external network and generate a data identifier.

[0080] In a specific implementation manner, first identify the business type of the traffic, and generate a cross-domain data identifier according to attribute information such as the business type. The specific content of the identifier refers to Figure 2 the specific format definition shown. Specifically, first identify the content of the business data, and determine the data provider, business type, and business data level according to the content of the business. Then, based on the identification results, record the identifier length, identifier ID, business additional information, extended field, and identifier check code according to the format of the data identifier to generate a data identifier.

[0081] S4: Package the data identifier and the business data sent to the external network into a tunnel carrier and send it to the data cross-domain identification tunnel verification system.

[0082] In a specific implementation manner, the generated data identifier and the original traffic packet are used as the tunnel carrier, encapsulated inside the IPv4 tunnel, and sent to the data cross-domain identification tunnel verification system.

[0083] S5: Receive the tunnel carrier through the data cross-domain identification tunnel verification system, strip the tunnel header of the tunnel carrier, and extract the data identifier.

[0084] S6: Verify the data identifier.

[0085] In a specific embodiment, the cross-domain data identification tunnel verification system parses according to the specific format of the data identification. First, it determines the legality of the data identification through the identification verification code, and then determines whether there are any violations in the cross-domain data according to the identification content. If the data identification is legal and there are no violations in the cross-domain data, the verification is successful; otherwise, the verification fails.

[0086] S7: Perform flow processing on the service data sent to the external network according to the verification result.

[0087] In a specific embodiment, if the verification result is successful, the data identification in the tunnel carrier is stripped, the service data sent to the external network is generated into a traffic packet, and is sent to the external network according to the destination IP, and the audit log is recorded. If the verification result is a failure, the data flow in the tunnel carrier is blocked. Through this step, secure and compliant cross-domain data transfer can be achieved.

[0088] The present invention also discloses a cross-domain data security transfer detection device, including a processor and a memory; wherein, when the processor executes the cross-domain data security transfer detection program saved in the memory, it realizes the steps of the cross-domain data security transfer detection method described in any one of the above.

[0089] Further, the cross-domain data security transfer detection device in this embodiment may further include:

[0090] An input interface, which is used to obtain the cross-domain data security transfer detection program imported from the outside and save the obtained cross-domain data security transfer detection program to the memory, and can also be used to obtain various instructions and parameters transmitted by external terminal devices and transmit them to the processor, so that the processor can perform corresponding processing using the above various instructions and parameters. In this embodiment, the input interface may specifically include, but is not limited to, a USB interface, a serial interface, a voice input interface, a fingerprint input interface, a hard disk reading interface, etc.

[0091] An output interface, which is used to output various data generated by the processor to the terminal device connected thereto, so that other terminal devices connected to the output interface can obtain various data generated by the processor. In this embodiment, the output interface may specifically include, but is not limited to, a USB interface, a serial interface, etc.

[0092] A communication unit, which is used to establish a remote communication connection between the cross-domain data security transfer detection device and an external server, so that the cross-domain data security transfer detection device can mount the mirror file to the external server. In this embodiment, the communication unit may specifically include, but is not limited to, a remote communication unit based on wireless communication technology or wired communication technology.

[0093] A keyboard for obtaining various parameter data or instructions input by a user by tapping the key caps in real time.

[0094] A display for displaying in real time the relevant information of the data cross-domain secure transfer detection process.

[0095] A mouse that can be used to assist the user in inputting data and simplify the user's operations.

[0096] The present invention also discloses a readable storage medium. The readable storage medium mentioned here includes random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable hard disks, CD-ROMs, or any other form of storage medium well-known in the technical field. A data cross-domain secure transfer detection program is stored in the readable storage medium. When the data cross-domain secure transfer detection program is executed by a processor, the steps of the data cross-domain secure transfer detection method described in any one of the above are implemented.

[0097] In summary, the present invention utilizes a specific encapsulated data identification technology to implement an efficient method for "unopened detection" of cross-domain data, ensuring the legality and compliance of cross-domain data. At the same time, the present invention utilizes the check code mechanism in the data identification to quickly identify the behavior of forging cross-domain data, which not only ensures the security of cross-domain data transmission but also realizes the traceability of cross-domain data transmission, facilitating post-event audit and accountability.

[0098] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other. For the methods disclosed in the embodiments, since they correspond to the systems disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.

[0099] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0100] In several embodiments provided by the present invention, it should be understood that the disclosed systems, systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of systems or units can be electrical, mechanical or other forms.

[0101] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0102] In addition, in each embodiment of the present invention, the various functional modules can be integrated in a processing unit, or each module can exist physically alone, or two or more modules can be integrated in one unit.

[0103] Similarly, in each embodiment of the present invention, the various processing units can be integrated in a functional module, or each processing unit can exist physically, or two or more processing units can be integrated in a functional module.

[0104] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software module can be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0105] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0106] The above has introduced in detail the data cross-domain secure transfer detection system, method, device and readable storage medium provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.

Claims

1. A data cross-domain security flow detection system, characterized in that: include: The data sending end and the data verification end are connected via the intra-domain network data, and the data verification end is also connected to the extra-domain network; The data sending end is provided with a plurality of business systems and a data cross-domain identification tunnel system; the data verification end is provided with a data cross-domain identification tunnel verification system; The data cross-domain identification tunnel system is respectively connected with the business system and the data cross-domain identification tunnel verification system; The business system is used to generate business data to be sent to the intra-domain network or the extra-domain network, and send it to the data cross-domain identification tunnel system; The data cross-domain identification tunnel system is used to identify the business data sent to the extra-domain network, encapsulate the business data into a tunnel carrier by performing tunnel encapsulation processing on the business data, add a data identifier to the tunnel carrier, and send the tunnel carrier to the data cross-domain identification tunnel verification system; The data cross-domain identification tunnel verification system is used to unblock the tunnel carrier, extract the data identification therein, and verify the data identification; If the verification is successful, the service data in the tunnel carrier will be forwarded to the external network; The business system includes: commodity shelf system, commodity logistics system and employee information system; The commodity shelf system is used to generate business data that is sent to the external network; Commodity logistics system, used to generate business data sent to the external network; Employee information system, used to generate business data sent to the intra-domain network; The tunnel carrier includes: a tunnel head and a tunnel load; Tunnel header, used to store IPv4 tunnel header; Tunnel payload, used to store data identifiers and business data; The data identifier sequentially records the identifier length, identifier ID, service additional information, extension field and identifier check code; The identification length is stored at the starting position of the tunnel load and is used to record the length of the data identification; Identification ID, used to record descriptive information related to business data, including but not limited to: data provider, business type, and business data level; Business additional information, used to record the data size of business data; An extended field is used to record the algorithm type of the identification check code; The identification verification code is used to verify the data identification in conjunction with the algorithm type recorded in the extension field.

2. A method for detecting cross-domain secure data transfer, characterized in that: The method adopts the data cross-domain security flow detection system as claimed in claim 1; The method comprises the following steps: S1: The business system in the data sending end generates business data and sends it to the data cross-domain identification tunnel system through the intra-domain network; S2: Identify the destination IP address of the service data through the data cross-domain identification tunnel system, and identify the service data sent to the extra-domain network; S3: Identify the data content of the business data sent to the external network and generate a data identifier; S4: Encapsulate the data identifier and the service data sent to the extra-domain network into a tunnel carrier, and send it to the data cross-domain identifier tunnel verification system; S5: receiving the tunnel carrier through the data cross-domain identification tunnel verification system, stripping the tunnel header of the tunnel carrier, and extracting the data identification; S6: Verify the data identification; S7: Process the business data sent to the external network based on the verification results.

3. The data cross-domain secure flow detection method according to claim 2 is characterized in that: The step S2 comprises: Identify the destination IP address of business data through the data cross-domain identification tunnel system; Determine whether the destination IP is an external network IP; If yes, the business data is business data sent to an external network; If not, the business data is business data sent to the intra-domain network, and the business data is directly forwarded according to the destination IP.

4. The data cross-domain secure flow detection method according to claim 2 is characterized in that: The step S3 comprises: Identify the content of business data, determine the data provider, business type, and business data level based on the content of the business, and record the identification length, identification ID, business additional information, extension field, and identification check code according to the format of the data identification to generate a data identification.

5. The data cross-domain secure flow detection method according to claim 2 is characterized in that: The step S7 comprises: If the verification result is successful, the data identifier in the tunnel carrier is stripped, the business data sent to the external network is generated into a traffic message, sent to the external network according to the destination IP, and the audit log is recorded; If the verification result is a verification failure, the data flow of the tunnel carrier is blocked.

6. A data cross-domain secure flow detection device, characterized in that: include: A memory device for storing a data cross-domain security flow detection program; A processor is used to implement the steps of the data cross-domain security flow detection method as described in any one of claims 2 to 5 when executing the data cross-domain security flow detection program.

7. A readable storage medium, characterized in that: The readable storage medium stores a data cross-domain security flow detection program, and when the data cross-domain security flow detection program is executed by the processor, the steps of the data cross-domain security flow detection method as described in any one of claims 2 to 5 are implemented.

Citation Information

Patent Citations

  • Method and device for data verification

    CN107172081A

  • Judicial public internal and external network data consistency verification method

    CN113422671A