A data security exchange system based on the Internet of Things

Through the data security exchange system based on the Internet of Things, using multiple encryption and policy control, the problem that traditional switching equipment cannot guarantee the secure transmission of internal and external networks is solved, and the safe, reliable exchange and efficient processing of data between the internal and external networks of the Internet of Things are realized.

CN118740432BActive Publication Date: 2025-09-26ZHONGBEI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410755174.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-12
Publication Date
2025-09-26
Estimated Expiration
2044-06-12

AI Technical Summary

Technical Problem

Traditional cross-domain information exchange equipment cannot guarantee secure transmission between internal and external network devices and isolated devices, and ignores the covert transmission of data, resulting in a high risk of information leakage.

Method used

A data security exchange system based on the Internet of Things is adopted, including a user center, an encrypted transmission module, a write-read module, a secure exchange module, and a management center. Multiple encryption, policy control, and log reporting are used to ensure the secure exchange of data at the boundaries of the internal and external networks. DPDK technology is used to optimize the data packet processing process.

Benefits of technology

It improves the confidentiality and interaction efficiency of data transmission, ensures the safe and reliable exchange of data between the Internet of Things and the internal and external networks, reduces the risk of information leakage, and improves the efficiency of data packet processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118740432B_ABST
    Figure CN118740432B_ABST
Patent Text Reader

Abstract

The present invention discloses a data security exchange system based on the Internet of Things, and relates to the technical field of data exchange systems. The present invention comprises: a user center, wherein the user center is constructed as an encrypted mobile storage medium for secure access of users; and an encryption transmission module, wherein the encryption transmission module is used to perform multiple encryption and decryption processing on encrypted data of the verified mobile storage medium. The present invention ensures the confidentiality of the data transmission process between the internal and external network devices of the Internet of Things and the security exchange module through the user login center and the encryption transmission module, ensures the secure and reliable exchange of data between the internal and external networks of the Internet of Things through the policy control, isolated exchange, and log reporting process of the security exchange module, ensures the efficiency of data interaction between the internal and external networks, optimizes the data packet processing process through the DPDK technology, thereby improving the processing efficiency during the data exchange process, and relieves the storage pressure during the data transmission process through the cloud storage module, thereby improving the overall transmission efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data exchange systems, and in particular to a data security exchange system based on the Internet of Things. Background Art

[0002] The Internet of Things (IoT) connects all objects to the internet through information sensors, exchanging information—meaning everything communicates with everything—to achieve intelligent identification and management. With the rapid development of the internet, online information has become an increasingly important part of people's lives. However, due to the ubiquity and openness of public networks, network information can be easily accessed and tampered with during transmission, leading to the leakage of important information and even serious damage to related networks. Some organizations and institutions with high security requirements are forced to isolate their networks from external public networks. However, with the development of technologies such as big data and the IoT, and their deep integration with the internet, these organizations and institutions inevitably need to exchange data with public networks outside their internal networks to support their internal business needs.

[0003] Traditional cross-domain information exchange typically involves deploying secure isolation switching devices, such as isolation gateways, at the network boundary, physically isolating the internal and external networks. When data exchange is required between the internal and external networks, the data packet is transmitted to the isolation gateway device via the universal TCP / IP protocol. After being processed by the internal and external network processing units of the isolation gateway device, it is delivered to the peer network using data ferrying. However, traditional isolation gateway devices can only ensure secure cross-domain exchange within the device, while ignoring secure transmission between internal and external network devices and the isolation device. Furthermore, traditional secure isolation switching devices focus on detecting attacks and threats while ignoring the covert transmission of data, i.e., information leakage. Therefore, we propose an IoT-based data security exchange system to address the aforementioned issues. Summary of the Invention

[0004] The purpose of the present invention is to provide a data security exchange system based on the Internet of Things to solve the current market problems raised by the above background technology.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a data security exchange system based on the Internet of Things, comprising:

[0006] User center, the user center is constructed as an encrypted mobile storage medium for secure access of users, and the user login module includes a personal information unit and a personal verification unit;

[0007] An encryption transmission module, which is used to perform multiple encryption and decryption processing on the encrypted data of the verified mobile storage medium, and includes an access unit, a data processing optimization unit, an encryption unit, and a decryption unit;

[0008] A write-read module, which is used to write the encrypted data of the encryption transmission module into a mobile storage medium or read the decrypted data of the encryption transmission module;

[0009] A secure exchange module, which is used to assist in the secure exchange of data at the boundary between the internal and external networks. The secure exchange module includes a policy control unit, an isolation exchange unit, and a log reporting unit;

[0010] A management center, which is used to manage the encryption transmission module, the write-read module, the secure exchange module, and the mobile storage medium connected to the encryption transmission module;

[0011] The cloud storage module is used to temporarily store data packets to ensure fast and secure access to data.

[0012] Preferably, the personal information unit is used to access the user to perform registration, login, logout operations and information update, and the personal verification unit is used to access the user to perform access verification.

[0013] Preferably, the encryption transmission module is connected to the mobile storage medium.

[0014] Preferably, the access unit is used to build a secure channel for data transmission, the data processing optimization unit is used to optimize the data packet processing process and improve the data packet throughput, the encryption unit is used to perform multiple encryption processing on the accessed encrypted data, and the decryption unit is used to decrypt and read the accessed encrypted data.

[0015] Preferably, the write-read module is connected to the encryption transmission module.

[0016] Preferably, the policy control unit designs different data matching schemes according to different security policy scenarios, the isolation exchange unit is used to isolate and exchange data from each channel to avoid data crossing, and the log reporting unit is used to generate a log of data exchange information and report it to the management center.

[0017] Preferably, the data processing optimization unit uses DPDK technology to optimize the data packet processing process.

[0018] Preferably, the encryption unit adopts a symmetric encryption algorithm based on DES, and encrypts a data packet three times using three different keys. The decryption unit adopts a symmetric decryption algorithm based on DES, which is the inverse process of the encryption unit, and converts the encoded information into its original data packet.

[0019] Preferably, the cloud storage module is connected to the encryption transmission module, the write-read module and the security exchange module.

[0020] Compared with the prior art, the present invention has the following beneficial effects:

[0021] The present invention ensures the confidentiality of the data transmission process between the IoT intranet and extranet devices and the security exchange module through the user login center and the encryption transmission module. It ensures the safe and reliable exchange of data between the IoT intranet and extranet through the policy control, isolated exchange and log reporting process of the security exchange module, and ensures the efficiency of data interaction between the intranet and extranet. It optimizes the data packet processing process through DPDK technology, thereby improving the processing efficiency during the data exchange process. It relieves the storage pressure during the data transmission process through the cloud storage module, thereby improving the overall transmission efficiency.

[0022] The above summary is for illustrative purposes only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments and features described above, further aspects, embodiments and features of the present invention will be readily apparent by reference to the accompanying drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 This is a flow chart of a data security exchange system based on the Internet of Things according to the present invention;

[0024] Figure 2 This is a flow chart of a user login module of a data security exchange system based on the Internet of Things according to the present invention;

[0025] Figure 3 This is a schematic diagram of the encryption transmission module flow of a data security exchange system based on the Internet of Things of the present invention;

[0026] Figure 4 This is a flow chart of a secure exchange module in a data security exchange system based on the Internet of Things according to the present invention. DETAILED DESCRIPTION

[0027] The following will provide a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0028] See also Figure 1 - Figure 4 , a data security exchange system based on the Internet of Things, comprising:

[0029] User login center, which is constructed as an encrypted mobile storage medium for secure access to users. The user login center includes a personal information unit and a personal verification unit. The personal information unit is used to access users for registration, login, logout operations, and information updates. The personal verification unit is used to access users for access verification. Once the verification is passed, normal access and data exchange can be carried out.

[0030] An encryption transmission module is connected to a mobile storage medium and is used to perform multiple encryption and decryption processing on encrypted data of a verified mobile storage medium. The encryption transmission module includes an access unit, a data processing optimization unit, an encryption unit, and a decryption unit. The access unit is used to establish a secure channel for data transmission. The data processing optimization unit is used to optimize the data packet processing process. The DPDK technology is used to optimize the data packet processing process, improve the data packet throughput, and thus improve the processing efficiency during the data exchange process. The encryption unit is used to perform multiple encryption processing on the accessed encrypted data. A symmetric encryption algorithm based on DES is used to encrypt a data packet three times using three different keys. The decryption unit is used to decrypt and read the accessed encrypted data. A symmetric decryption algorithm based on DES is used. This is the inverse process of the encryption unit and converts the encoded information into its original data packet.

[0031] A write-read module, which is connected to the encryption transmission module and is used to write the encrypted data of the encryption transmission module into a mobile storage medium or read the decrypted data of the encryption transmission module;

[0032] The secure exchange module is used to assist in the secure exchange of data at the boundary between the internal and external networks. The secure exchange module includes a policy control unit, an isolation exchange unit, and a log reporting unit. The policy control unit designs different data matching schemes according to different security policy scenarios. The isolation exchange unit is used to isolate and exchange data from each channel to avoid data cross-talk. The log reporting unit is used to generate logs of data exchange information and report them to the management center.

[0033] The user login center and encrypted transmission module ensure the confidentiality of data transmission between IoT intranet and extranet devices and the secure exchange module. The secure exchange module's policy control, isolated exchange, and log reporting processes ensure secure and reliable data exchange between the IoT intranet and extranet, ensuring efficient data interaction between the intranet and extranet.

[0034] Management center, which is used to manage the encryption transmission module, the write-read module, the security exchange module, and the mobile storage medium connected to the encryption transmission module;

[0035] Cloud storage module, the cloud storage module is connected to the encryption transmission module, the write-read module and the secure exchange module. The cloud storage module is used to temporarily store data packets to ensure fast and secure access to data. The cloud storage module relieves the storage pressure during data transmission, thereby improving the overall transmission efficiency.

[0036] In the present invention, unless otherwise expressly specified or limited, the terms "mounted," "connected," "connect," "fixed," etc. should be understood broadly. For example, they may refer to fixed connection, detachable connection, or integration; mechanical connection or electrical connection; direct connection or indirect connection through an intermediate medium; internal communication between two components or interaction between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0037] In the present invention, unless otherwise expressly specified or limited, when a first feature is "above" or "below" a second feature, it may mean that the first and second features are in direct contact, or that the first and second features are in indirect contact through an intermediary. Furthermore, when a first feature is "above," "above," or "above" a second feature, it may mean that the first feature is directly above or diagonally above the second feature, or simply means that the first feature is at a higher level than the second feature. When a first feature is "below," "below," or "below" a second feature, it may mean that the first feature is directly below or diagonally below the second feature, or simply means that the first feature is at a lower level than the second feature.

[0038] In the description of this specification, the reference terms "one embodiment", "some embodiments", "example", "specific example" or "some examples" mean that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0039] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present invention includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present invention pertain.

[0040] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection having one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.

[0041] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0042] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be accomplished through hardware related to program instructions, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0043] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing module, or each unit may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium.

[0044] Although the embodiments of the present invention have been shown and described above, it will be understood that the above embodiments are illustrative and are not to be construed as limitations on the present invention. A person skilled in the art may change, modify, replace and modify the above embodiments within the scope of the present invention.

Claims

1. A data security exchange system based on the Internet of Things, characterized in that: include: A user login center, which is constructed as an encrypted mobile storage medium for secure access to users, and includes a personal information unit and a personal verification unit; An encryption transmission module, which is used to perform multiple encryption and decryption processing on the encrypted data of the verified mobile storage medium, and includes an access unit, a data processing optimization unit, an encryption unit, and a decryption unit; A write-read module, which is used to write the encrypted data of the encryption transmission module into a mobile storage medium or read the decrypted data of the encryption transmission module; A secure exchange module, which is used to assist in the secure exchange of data at the boundary between the internal and external networks. The secure exchange module includes a policy control unit, an isolation exchange unit, and a log reporting unit; A management center, which is used to manage the encryption transmission module, the write-read module, the secure exchange module, and the mobile storage medium connected to the encryption transmission module; The cloud storage module is used to temporarily store data packets to ensure fast and secure access to data.

2. The data security exchange system based on the Internet of Things according to claim 1, characterized in that: The personal information unit is used to access the user to perform registration, login, logout operations and information update, and the personal verification unit is used to access the user to perform access verification.

3. The data security exchange system based on the Internet of Things according to claim 1, characterized in that: The encryption transmission module is connected to the mobile storage medium.

4. The data security exchange system based on the Internet of Things according to claim 1, characterized in that: The access unit is used to build a secure channel for data transmission, the data processing optimization unit is used to optimize the data packet processing process and improve the data packet throughput, the encryption unit is used to perform multiple encryption processing on the accessed encrypted data, and the decryption unit is used to decrypt and read the accessed encrypted data.

5. The data security exchange system based on the Internet of Things according to claim 1, characterized in that: The write-read module is connected to the encryption transmission module.

6. The data security exchange system based on the Internet of Things according to claim 1, characterized in that: The policy control unit designs different data matching schemes according to different security policy scenarios. The isolation exchange unit is used to isolate and exchange data from each channel to avoid data crossing. The log reporting unit is used to generate a log of data exchange information and report it to the management center.

7. The data security exchange system based on the Internet of Things according to claim 4, characterized in that: The data processing optimization unit adopts DPDK technology to optimize the data packet processing process.

8. The data security exchange system based on the Internet of Things according to claim 4, characterized in that: The encryption unit adopts a symmetric encryption algorithm based on DES, and encrypts a data packet three times using three different keys. The decryption unit adopts a symmetric decryption algorithm based on DES, which is the reverse process of the encryption unit and converts the encoded information into its original data packet.

9. The data security exchange system based on the Internet of Things according to claim 4, characterized in that: The cloud storage module is connected to the encryption transmission module, the write-read module and the security exchange module.