A multi-system terminal cross-domain communication control system and method

By introducing Root namespace, NAT read and write agents and authentication components into multi-system terminals, security control of cross-domain communications of multi-system terminals is achieved, and the problems of private network data leakage and malicious code intrusion are solved, ensuring the security and auditability of cross-domain communications.

CN119052092BActive Publication Date: 2025-09-02THE FIRST RES INST OF MIN OF PUBLIC SECURITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411011817.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-26
Publication Date
2025-09-02
Estimated Expiration
2044-07-26

AI Technical Summary

Technical Problem

Multi-system terminals lack control over cross-domain communication, and there is a risk that sensitive data on the private network will be leaked to the Internet. The lack of a unified data format will lead to malicious code or attacks on the Internet that may enter the private network.

Method used

Multi-system terminal cross-domain communication control system is adopted, including Root namespace, NAT read and write agent, VP authentication client and authentication component, password module, Internet and private network service platform, and the security control of cross-domain communication is realized through authentication, encryption and unified message formats.

Benefits of technology

Ensure that sensitive information on the private network is not leaked to the Internet, prevent malicious code from entering the workspace, and realize security auditing and cross-domain message management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119052092B_ABST
    Figure CN119052092B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-system terminal cross-domain communication control system and method. The system includes a multi-system terminal, an Internet service platform, and a private network service platform. The multi-system terminal has multiple VPs, including at least one VP1 for daily life and one VP2 for work. The multi-system terminal also has a root namespace and a device namespace. The root namespace is deployed with a NAT read / write proxy. The VP1 is deployed with a VP1 authentication client and a VP1 authentication component. The VP2 is deployed with a VP2 authentication client, a VP2 authentication component, a NAT control module, and a message management module. The device namespace is deployed with a password module. The Internet service platform is deployed with an authentication service. The private network service platform is deployed with an authentication service, a cross-domain message management module, and a NAT management module. The present invention can prevent sensitive private network information from being leaked to the Internet, prevent malicious Internet code from entering a workspace VP, and prevent the creation of illegal communication links between different VPs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of multi-system terminal cross-domain communication, and in particular to a multi-system terminal cross-domain communication management and control system and method. Background Art

[0002] A multi-system terminal refers to building multiple virtual terminals on a single terminal hardware, one of which is used for daily life and internet access, while the remaining virtual terminals are used for work and private network access. In a multi-system terminal, the NAT module in the root namespace provides a bridge function, enabling routing between virtual terminals in the daily life domain and virtual terminals in the work domain. Once cross-domain communication links between different virtual terminals are established, any information can be forwarded and exchanged via these virtual links. Therefore, cross-domain interactions in multi-system terminals present the following risks:

[0003] 1. Lack of control over cross-domain communications between multiple system terminals creates the risk of leaking sensitive private network data to the internet.

[0004] 2. The cross-domain communication interface of multiple system terminals is controlled by the terminal equipment manufacturer. There is no unified data format and lacks auditing, which poses the risk of introducing malicious Internet code or attacks into the private network. Summary of the Invention

[0005] In view of the deficiencies in the prior art, the present invention aims to provide a multi-system terminal cross-domain communication management and control system and method.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] A multi-system terminal cross-domain communication management and control system, including multi-system terminals, an Internet service platform and a private network service platform;

[0008] The multi-system terminal has multiple virtual terminals VP, including at least one virtual terminal VP1 for daily life and one virtual terminal VP2 for work; VP1 can access the Internet service platform, while VP2 can only access the private network service platform using a dedicated link or a dedicated network;

[0009] A multi-system terminal also has a root namespace and a device namespace. After the multi-system terminal is started, the root namespace will establish a virtual link for each VP. One end of each virtual link is in the root namespace, and the other end is in the corresponding VP.

[0010] A NAT read / write proxy is deployed in the Root namespace. The NAT read / write proxy is used to read the configuration of the NAT module in the Root namespace or send configuration to the NAT module, and add or delete routes.

[0011] VP1 is deployed with a VP1 authentication client and a VP1 authentication component. The VP1 authentication client is used to make authentication requests before cross-domain communication. The VP1 authentication component is used to receive authentication requests initiated by the VP2 authentication client, interact with it, and complete authentication.

[0012] VP2 is deployed with a VP2 authentication client, a VP2 authentication component, a NAT control module, and a message management module; the VP2 authentication client is used to perform authentication requests before cross-domain communication; the VP2 authentication component is used to receive authentication requests initiated by the VP1 authentication client, interact with it, and complete authentication; the NAT control module is used to read or write the configuration of the NAT module in the root namespace through the NAT read-write agent of the root namespace; the message management module is used to log and manage cross-domain messages of all apps on multiple system terminals;

[0013] A cryptographic module is deployed in the device namespace. The cryptographic module is used to provide a certificate interface for the VP1 authentication client and VP1 authentication component in VP1, and the VP2 authentication client and VP2 authentication component in VP2, completing digital certificate-based authentication and authorization.

[0014] An authentication service is deployed in the Internet service platform. The authentication service is used to receive authentication requests initiated by the VP1 authentication component, interact with it, and help it complete cross-domain communication authentication of the APP in VP2;

[0015] The private network service platform is deployed with authentication services, cross-domain message management modules and NAT management modules; the authentication service of the private network service platform is used to receive authentication requests initiated by the VP2 authentication and authorization component, interact with it, and help it complete the cross-domain communication authentication of the APP in VP1; the cross-domain message management module is used to complete the logging and management of cross-domain messages of multiple system terminals through the VP2 message management module; the NAT management module is used to complete the reading and writing of the configuration of the NAT module of the Root namespace through the VP2 NAT control module.

[0016] The present invention also provides a method for cross-domain communication control of multi-system terminals using the above-mentioned system, and the specific process is as follows: when the user of the multi-system terminal resides in VP2, the APP of VP1 receives a new message; the APP of VP1 initiates an authentication request to the VP1 authentication client; the VP1 authentication client reads the certificate information in the password module, carries the authentication information and sends an authentication request to the VP2 authentication and authorization component through a virtual link; the VP2 authentication and authorization component sends the authentication request to the authentication service of the private network service platform, completes the authentication of the APP of VP1, and then returns an authentication token to the APP of VP1; the APP of VP1 carries the authentication token information and sends a cross-domain message to the VP2 authentication and authorization component, the VP2 authentication and authorization component passes the authentication, decrypts the cross-domain message and displays it in the notification bar of VP2; the message management module of VP2 sends the cross-domain message to the cross-domain message management module of the private network service platform in a specified format; the NAT control module of VP2 can control the virtual link between VP1 and VP2 through the NAT read and write agent of the Root namespace.

[0017] Furthermore, the cross-domain message format is defined using the sys log format.

[0018] Furthermore, cross-domain messages are encrypted via TLS, and the encryption key is the key negotiated during the authentication phase.

[0019] The present invention also provides another method for controlling cross-domain communication of multiple system terminals using the above system, the specific process of which is as follows:

[0020] When a user of a multi-system terminal resides in VP1, the VP2 APP receives a new message; the VP2 APP initiates an authentication request to the VP2 authentication client; the VP2 authentication client reads the certificate information in the password module, carries the authentication information, and sends an authentication request to the VP1 authentication component through the virtual link; the VP1 authentication component sends the authentication request to the authentication service of the Internet service platform, completes the authentication of the VP2 APP, and then returns the authentication token to the VP2 APP; the VP2 APP carries the authentication token information and sends a cross-domain message to the VP1 authentication component. The VP1 authentication component passes the authentication, decrypts the cross-domain message, and displays it in the notification bar of VP1; the VP2 message management module sends the cross-domain message to the cross-domain message management module of the private network service platform in the specified format; the VP2 NAT control module can control the virtual link between VP1 and VP2 through the NAT read and write agent of the Root namespace.

[0021] The beneficial effects of the present invention are:

[0022] 1. The method of the present invention can realize cross-domain communication authentication, authorization and encryption of multiple system terminals, ensure the security of cross-domain communication, and prevent sensitive information of private networks from being leaked to the Internet.

[0023] 2. The method of the present invention can prevent Internet malicious codes from entering the workspace VP by unifying the cross-domain communication data interface, and deploy a cross-domain message management function in the workspace VP to facilitate security auditing.

[0024] 3. The method of the present invention can prevent the creation of illegal communication links between different VPs by controlling the NAT module of the Root namespace. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 Schematic diagram of the system architecture in Example 1 of the present invention;

[0026] Figure 2 This is a flow chart of the method of embodiment 2 of the present invention;

[0027] Figure 3 This is a flow chart of the method of Example 3 of the present invention. DETAILED DESCRIPTION

[0028] The present invention will be further described below in conjunction with the accompanying drawings. It should be noted that this embodiment is based on the technical solution and provides a detailed implementation method and specific operation process, but the protection scope of the present invention is not limited to this embodiment.

[0029] Example 1

[0030] This embodiment provides a multi-system terminal cross-domain communication management and control system, such as Figure 1 As shown, it includes multi-system terminals, Internet service platform and private network service platform;

[0031] The multi-system terminal may be a smart phone, a tablet computer, etc., which is an industry-specific mobile terminal and has multiple virtual terminals VP (Virtual Phone), including at least one virtual terminal VP1 for life and one virtual terminal VP2 for work;

[0032] The multi-system terminal also has a root namespace and a device namespace. After the multi-system terminal is started, the root namespace will establish a virtual link for each VP. One end of each virtual link is in the root namespace, and the other end is in the corresponding VP.

[0033] A NAT read / write proxy is deployed in the Root namespace. The NAT read / write proxy is used to read the configuration of the NAT module in the Root namespace or send configuration to the NAT module, and add or delete routes.

[0034] VP1 is deployed with a VP1 authentication client and a VP1 authentication component. The VP1 authentication client is used to make authentication requests before cross-domain communication. The VP1 authentication component is used to receive authentication requests initiated by the VP2 authentication client, interact with it, and complete authentication.

[0035] VP2 is deployed with a VP2 authentication client, a VP2 authentication and authorization component, a NAT control module, and a message management module; the VP2 authentication client is used to make authentication requests before cross-domain communication; the VP2 authentication and authorization component is used to receive authentication requests initiated by the VP1 authentication client, interact with it, and complete authentication; the NAT control module is used to read or write the configuration of the NAT module in the Root namespace through the NAT read-write agent of the Root namespace; the message management module is used to log and manage cross-domain messages of all APPs on multi-system terminals.

[0036] A cryptographic module is deployed in the device namespace. The cryptographic module is used to provide a certificate interface for the VP1 authentication client and VP1 authentication component in VP1 and the VP2 authentication client and VP2 authentication component in VP2, completing authentication and authorization based on digital certificates.

[0037] An authentication service is deployed in the Internet service platform, which is used to receive the authentication request initiated by the VP1 authentication component, interact with it, and help it complete the cross-domain communication authentication of the APP in VP2.

[0038] The private network service platform is deployed with authentication services, cross-domain message management modules and NAT management modules; the authentication service of the private network service platform is used to receive authentication requests initiated by the VP2 authentication and authorization component, interact with it, and help it complete the cross-domain communication authentication of the APP in VP1; the cross-domain message management module is used to complete the logging and management of cross-domain messages of multiple system terminals through the VP2 message management module; the NAT management module is used to complete the reading and writing of the configuration of the NAT module of the Root namespace through the VP2 NAT control module.

[0039] VP1 can access the Internet service platform, while VP2 can only access the private network service platform using the dedicated APN / VPDN link provided by the operator. In addition to dedicated APN / VPDN links, some special areas may also have dedicated WLAN networks.

[0040] Example 2

[0041] This embodiment provides a method for controlling cross-domain communication of multiple system terminals using the system described in Example 1. When a user of a multi-system terminal resides in VP2, it is necessary to promptly remind the user when there is a new message from an Internet application such as WeChat in VP1 to avoid affecting the user's personal life.

[0042] like Figure 2 As shown, when the user of the multi-system terminal resides in VP2, the APP of VP1 receives a new message. The APP of VP1 initiates an authentication request to the VP1 authentication client. The VP1 authentication client reads the certificate information in the password module, carries the authentication information, and sends an authentication request to the VP2 authentication and authorization component through the virtual link. The VP2 authentication and authorization component sends the authentication request to the authentication service of the private network service platform, completes the authentication of the APP of VP1, and then returns the authentication token to the APP of VP1. The APP of VP1 carries the authentication token information and sends a cross-domain message to the VP2 authentication and authorization component. The VP2 authentication and authorization component passes the authentication, decrypts the cross-domain message, and displays it in the notification bar of VP2. The message management module of VP2 sends the cross-domain message to the cross-domain message management module of the private network service platform in the specified format. The NAT control module of VP2 can control the virtual link between VP1 and VP2 through the NAT read and write agent of the Root namespace.

[0043] Specifically, the cross-domain message format can be defined with reference to the syslog format (e.g., timestamp, host name, device manufacturer identifier, version number, application name, message digest, and message body), facilitating unified log storage and auditing. Furthermore, cross-domain messages can be encrypted via TLS, using the encryption key negotiated during the authentication phase.

[0044] In summary, the method flow of this embodiment is as follows:

[0045] Step 1: Start the multi-system terminal;

[0046] Step 2: Root namespace and its application start;

[0047] Step 3: VP1, VP2 and their applications are started;

[0048] Step 4: VP1's app is started. When the app receives a new message, it needs to send an instant message to VP2's notification bar.

[0049] Step 5: VP1's APPAPP calls the authentication interface of the VP1 authentication client;

[0050] Step 6: The VP1 authentication client calls the authentication interface of the VP2 authentication component through the virtual link;

[0051] Step 7: The VP2 authentication component calls the authentication service of the private network service platform to complete the authentication, where the authentication service can be an existing facility of the private network service platform;

[0052] Step 8: If the authentication succeeds, go to step 9. If the authentication fails, the program terminates.

[0053] Step 9: The VP1 app carries the authentication token, calls the cross-domain message interface provided by the authentication client, and sends a cross-domain message.

[0054] Step 10: VP2 authentication component performs authentication;

[0055] Step 11: If the authentication succeeds, go to step 12; if the authentication fails, go back to step 5.

[0056] Step 12: The VP2 authentication component receives the cross-domain message, displays it in the VP2 notification bar, and sends it to the cross-domain message management module of the private network service platform through the VP2 message management module for storage in preparation for later security audits.

[0057] Step 13: The program ends.

[0058] Example 3

[0059] This embodiment provides another method for controlling cross-domain communication of multiple system terminals using the system described in Example 1.

[0060] When users of multi-system terminals reside in VP1, when there are new messages in APPs such as private network instant messaging in VP2, users need to be reminded in time to avoid affecting their work.

[0061] like Figure 3 As shown, when a user of a multi-system terminal resides in VP1, the VP2 APP receives a new message. The VP2 APP initiates an authentication request to the VP2 authentication client. The VP2 authentication client reads the certificate information in the cryptographic module, and carries the authentication information to send an authentication request to the VP1 authentication and authorization component through a virtual link. The VP1 authentication and authorization component sends the authentication request to the authentication service of the Internet service platform, completes the authentication of the VP2 APP, and then returns the authentication token to the VP2 APP. The VP2 APP carries the authentication token information and sends a cross-domain message to the VP1 authentication and authorization component. The VP1 authentication and authorization component passes the authentication, decrypts the cross-domain message, and displays it in the notification bar of VP1. The message management module of VP2 sends the cross-domain message to the cross-domain message management module of the private network service platform in the specified format. The NAT control module of VP2 can control the virtual link between VP1 and VP2 through the NAT read and write agent of the Root namespace.

[0062] Specifically, the cross-domain message format complies with the prescribed format (such as: timestamp, host name, device manufacturer identification, version number, application name, message digest, message body), and can be transmitted encrypted through TLS, and the encryption key is the key negotiated during the authentication phase.

[0063] In summary, the method flow of this embodiment is as follows:

[0064] Step 1: Start the multi-system terminal;

[0065] Step 2: Root namespace and its application start;

[0066] Step 3: VP1, VP2 and their applications are started;

[0067] Step 4: VP2's app is started. When the app receives a new message, it needs to send an instant message to VP1's notification bar.

[0068] Step 5: The APP calls the authentication interface of the authentication client in VP2;

[0069] Step 6: The VP2 authentication client calls the authentication interface of the VP1 authentication component through the virtual link;

[0070] Step 7: The VP1 authentication component calls the authentication service of the Internet service platform to complete the authentication, where the authentication service can be an existing facility of the Internet service platform;

[0071] Step 8: If the authentication succeeds, go to step 9. If the authentication fails, the program terminates.

[0072] Step 9: The VP2 app carries the authentication token, calls the cross-domain message interface provided by the VP2 authentication client, and sends a cross-domain message;

[0073] Step 10: VP1 authentication component performs authentication;

[0074] Step 11: If the authentication succeeds, go to step 12; if the authentication fails, go back to step 5.

[0075] Step 12: The VP1 authentication component receives the cross-domain message and displays it in the VP1 notification bar;

[0076] Step 13: The message management group module of VP2 sends the cross-domain message in the specified format to the cross-domain message management module of the private network service platform for storage in preparation for a later security audit;

[0077] Step 14: The program ends.

[0078] Those skilled in the art can make various corresponding changes and modifications based on the above technical solutions and concepts, and all of these changes and modifications should be included in the scope of protection of the claims of the present invention.

Claims

1. A multi-system terminal cross-domain communication management and control system, characterized in that: Including multi-system terminals, Internet service platform and private network service platform; The multi-system terminal has multiple virtual terminals VP, including at least one virtual terminal VP1 for daily life and one virtual terminal VP2 for work; VP1 can access the Internet service platform, while VP2 can only access the private network service platform using a dedicated link or a dedicated network; A multi-system terminal also has a root namespace and a device namespace. After the multi-system terminal is started, the root namespace will establish a virtual link for each VP. One end of each virtual link is in the root namespace, and the other end is in the corresponding VP. A NAT read / write proxy is deployed in the Root namespace. The NAT read / write proxy is used to read the configuration of the NAT module in the Root namespace or send configuration to the NAT module, and add or delete routes. VP1 is deployed with a VP1 authentication client and a VP1 authentication component. The VP1 authentication client is used to make authentication requests before cross-domain communication. The VP1 authentication component is used to receive authentication requests initiated by the VP2 authentication client, interact with it, and complete authentication. VP2 is deployed with a VP2 authentication client, a VP2 authentication component, a NAT control module, and a message management module; the VP2 authentication client is used to perform authentication requests before cross-domain communication; the VP2 authentication component is used to receive authentication requests initiated by the VP1 authentication client, interact with it, and complete authentication; the NAT control module is used to read or write the configuration of the NAT module in the root namespace through the NAT read-write agent of the root namespace; the message management module is used to log and manage cross-domain messages of all apps on multiple system terminals; A cryptographic module is deployed in the device namespace. The cryptographic module is used to provide a certificate interface for the VP1 authentication client and VP1 authentication component in VP1, and the VP2 authentication client and VP2 authentication component in VP2, completing digital certificate-based authentication and authorization. An authentication service is deployed in the Internet service platform. The authentication service is used to receive authentication requests initiated by the VP1 authentication component, interact with it, and help it complete cross-domain communication authentication of the APP in VP2; The private network service platform is deployed with authentication services, cross-domain message management modules and NAT management modules; the authentication service of the private network service platform is used to receive authentication requests initiated by the VP2 authentication and authorization component, interact with it, and help it complete the cross-domain communication authentication of the APP in VP1; the cross-domain message management module is used to complete the logging and management of cross-domain messages of multiple system terminals through the VP2 message management module; the NAT management module is used to complete the reading and writing of the configuration of the NAT module of the Root namespace through the VP2 NAT control module.

2. A method for controlling cross-domain communication of multiple system terminals using the system of claim 1, characterized in that: The specific process is as follows: when a user of a multi-system terminal resides in VP2, the VP1 APP receives a new message; the VP1 APP initiates an authentication request to the VP1 authentication client; the VP1 authentication client reads the certificate information in the password module, and carries the authentication information to send an authentication request to the VP2 authentication and authorization component through a virtual link; the VP2 authentication and authorization component sends the authentication request to the authentication service of the private network service platform, completes the authentication of the VP1 APP, and then returns the authentication token to the VP1 APP; the VP1 APP carries the authentication token information and sends a cross-domain message to the VP2 authentication and authorization component. The VP2 authentication and authorization component passes the authentication, decrypts the cross-domain message, and displays it in the notification bar of VP2; the VP2 message management module sends the cross-domain message to the cross-domain message management module of the private network service platform in the specified format; the VP2 NAT control module can control the virtual link between VP1 and VP2 through the NAT read and write agent of the Root namespace.

3. The method according to claim 2, characterized in that The cross-domain message format is defined using the syslog log format.

4. The method according to claim 2, characterized in that Cross-domain messages are encrypted via TLS, and the encryption key is the key negotiated during the authentication phase.

5. A method for controlling cross-domain communication of multiple system terminals using the system of claim 1, characterized in that: The specific process is: When a user of a multi-system terminal resides in VP1, the VP2 APP receives a new message; the VP2 APP initiates an authentication request to the VP2 authentication client; the VP2 authentication client reads the certificate information in the password module, carries the authentication information, and sends an authentication request to the VP1 authentication component through the virtual link; the VP1 authentication component sends the authentication request to the authentication service of the Internet service platform, completes the authentication of the VP2 APP, and then returns the authentication token to the VP2 APP; the VP2 APP carries the authentication token information and sends a cross-domain message to the VP1 authentication component. The VP1 authentication component passes the authentication, decrypts the cross-domain message, and displays it in the notification bar of VP1; the VP2 message management module sends the cross-domain message to the cross-domain message management module of the private network service platform in the specified format; the VP2 NAT control module can control the virtual link between VP1 and VP2 through the NAT read and write agent of the Root namespace.

Citation Information

Patent Citations

  • Method and device for system switching under multi-system terminal and multi-system terminal

    CN106156555A

  • Power distribution terminal information-physics bidirectional cross-domain attack analysis method

    CN116566658A