A data interaction system and method based on cross-network interconnection

Through a data interaction system based on cross-network interconnection, an encrypted channel is established using inter-network switching equipment and irreversible optical fiber, which solves the data transmission security and integrity problems in the traditional cross-network isolation method and realizes efficient and secure data transmission.

CN119324797BActive Publication Date: 2025-10-14CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411321622.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2025-10-14
Estimated Expiration
2044-09-23

AI Technical Summary

Technical Problem

Traditional cross-network security isolation methods cannot fully guarantee the security and integrity of intranet data transmission, and are limited in bandwidth and efficiency, making it impossible to achieve highly reliable data quality transmission.

Method used

A data interaction system based on cross-network interconnection is adopted, and network switching equipment and irreversible optical fiber are used to establish an encrypted data transmission channel. Data verification is added to the intranet receiving service module. Cross-network control strategies are managed through network switching equipment and proxy equipment, status is detected, and encrypted channels are actively established. UDP protocol packets are used for data transmission.

Benefits of technology

It improves the bandwidth and link security of cross-network data transmission, ensures the integrity and security of data during transmission, and prevents data from being intercepted and tampered with.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119324797B_ABST
    Figure CN119324797B_ABST
Patent Text Reader

Abstract

The application discloses a data interaction system and method based on cross-network interconnection, which comprises an external network service system, an inter-network exchange device and an internal network service system. The external network service system transmits data to be transmitted to the internal network service system through the inter-network exchange device. The inter-network exchange device is used for managing cross-network control strategies, detecting the state of the inter-network interaction agent device and actively establishing a cross-network data transmission encryption channel. The inter-network exchange device comprises an external network processing unit, an exchange processing unit and an internal network processing unit. The external network processing unit is used for processing data transmitted by the external network service system. The exchange processing unit is used for transmitting the data processed by the external network processing unit to the internal network processing unit. The internal network processing unit is used for processing the received data and transmitting the processed data to the internal network service system. The application can improve data transmission bandwidth and link security and guarantee the integrity of cross-network transmission data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of network communication, and particularly relates to a data interaction system and method based on cross-network interconnection. BACKGROUND

[0002] With the increasing degree of informatization and dataization, cross-network and cross-system data interaction and fusion scenarios are increasing, and the demand for data interaction is becoming more and more urgent. Due to the increasing demand for data cross-network interconnection, if the internal network environment with security requirements is connected with the external network, it will face various cross-network connection threats from the public network.

[0003] The traditional cross-network security isolation method adopts a "physical isolation" method, and uses a whole network isolation scheme of a network gateway or an optical gateway. The two only isolate and block the interface between the internal and external networks in the cross-network data interaction process. However, due to the bandwidth and efficiency limitations of the network gateway and the optical gateway, the speed and quality of cross-network data interaction are affected. In a relatively large and complex internal network environment, the data transmission link is long, and there are many data leakage risk points. The "physical isolation" method of the network gateway or the optical gateway cannot completely guarantee the safety of internal network data transmission. At the same time, when data is interacted through the network gateway or the optical gateway, a high-reliability data quality transmission mechanism cannot be established through the protocol layer, and the integrity of the data in the transmission process cannot be guaranteed. SUMMARY

[0004] In view of the problems in the prior art, the present application provides a data interaction system and method based on cross-network interconnection, which improves the data transmission bandwidth and link security and guarantees the integrity of cross-network transmission data.

[0005] To achieve the above technical purpose, the present application adopts the following technical scheme: a data interaction system based on cross-network interconnection, comprising: an external network service system, an inter-network switching device and an internal network service system, the external network service system transmits data to be transmitted to the internal network service system through the inter-network switching device, the inter-network switching device is used for managing a cross-network control strategy, detecting the state of an inter-network interaction agent device, and actively establishing a cross-network data transmission encryption channel; the inter-network switching device comprises: an external network processing unit, a switching processing unit and an internal network processing unit, the external network processing unit is used for processing data transmitted by the external network service system; the switching processing unit is used for transmitting the data processed by the external network processing unit to the internal network processing unit; and the internal network processing unit is used for processing the received data and transmitting the processed data to the internal network service system.

[0006] Further, the outer network processing unit comprises an outer network interface area, a first processing control area and a first data buffer area; the outer network interface area is used for receiving data sent by an outer network service system and transmitting the data to the first processing control area; the first processing control area receives the data sent by the outer network interface area, and performs security check on the received data, and stores the data passing the security check to the first data buffer area; and the first data buffer area sends the stored data to the inter-network switching device one by one.

[0007] Further, the inner network processing unit comprises an inner network interface area, a second processing control area and a second data buffer area; the second data buffer area receives data from the inter-network switching device and sends the received data to the second processing control area one by one; the second processing control area performs data feature security compliance check on the received data, and sends the data passing the check to the inner network interface area; and the inner network interface area sends the received data to the inner network service system.

[0008] Further, the switching processing unit is composed of a light emitting unit and a light receiving unit, and the light emitting unit and the light receiving unit are connected through an irreversible direction optical fiber.

[0009] Further, the outer network service system comprises an outer network data processing service module, a file service module, a push service module and a first inter-network interactive proxy device; the outer network data processing service module converts the data to be transmitted into a text file through format conversion; the file service module is used for temporarily storing the text file; the push service module is used for reading the text file in the file service module, converting the text file into a UDP protocol data packet, disassembling and marking the UDP protocol data packet, and sending the UDP protocol data packet to the first inter-network interactive proxy device; and the first inter-network interactive proxy device is used for passively establishing a cross-network data transmission encryption channel according to the interactive request between the inner network and the outer network.

[0010] Further, the inner network service system comprises a second inter-network interactive proxy device, a receiving service module and an inner network data processing service module; the second inter-network interactive proxy device is used for passively establishing a cross-network data transmission encryption channel according to the interactive request between the inner network and the outer network; the receiving service module is used for receiving the UDP protocol data packet sent by the second inter-network interactive proxy device, and sequentially assembling the UDP protocol data packet according to the mark on the UDP protocol data packet; and the inner network data processing service module is used for receiving the UDP protocol data packet assembled by the receiving service module and performing a persistent storage operation.

[0011] Further, the data to be transmitted comprises static library table data, dynamic flow data and real-time message data.

[0012] Further, the application further provides a data interaction method of the data interaction system based on cross-network interconnection, and specifically comprises the following steps:

[0013] Step 1, the data to be transmitted is converted into a text file by the external network data processing module, the text file is stored in the file service module, and the text file is encrypted to generate a check value;

[0014] Step 2, the text file and the corresponding check value are converted into a UDP protocol data packet by the push service module, and the UDP protocol data packet is disassembled, labeled, and transmitted to the first Internet interactive agent service device;

[0015] Step 3, the first Internet interactive agent service device checks the network route and the content of the UDP protocol data packet, if the destination address of the UDP protocol data packet is an intranet address, the first Internet interactive agent service device transmits the data in a transparent manner; otherwise, the interworking device checks whether the second Internet interactive agent service device corresponding to the target address is online, if not, the data transmission is ended; otherwise, the interworking device first establishes a data encryption transmission channel with the first Internet interactive agent service device, and then establishes a data encryption transmission channel with the second Internet interactive agent service device;

[0016] Step 4, after the data encryption transmission channel is established, the UDP protocol data packet is sent to the receiving service module at the destination address through the second Internet interactive agent service device;

[0017] Step 5, the receiving service module sequentially assembles according to the label on the UDP protocol data packet, and checks according to the check value, the UDP protocol data packet with failed check is put into the quarantine area for further checking, and the UDP protocol data packet with successful check is forwarded to the intranet data processing service module for persistent storage operation.

[0018] Compared with the prior art, the present application has the following beneficial effects: the data interaction system and method based on cross-network interconnection of the present application can improve the bandwidth of data transmission across networks by optimizing the interworking device and using irreversible direction optical fiber on the interworking device, and can improve the link security of data transmission across networks by establishing a data transmission encryption channel between the interworking agent device and the interworking device. In addition, the present application increases data checking in the receiving service module of the intranet to ensure the integrity of the data transmitted across networks. BRIEF DESCRIPTION OF DRAWINGS

[0019] Figure 1 is a framework diagram of the data interaction system based on cross-network interconnection of the present application;

[0020] Figure 2 is a schematic diagram of the interworking device in the present application;

[0021] Figure 3 is a schematic diagram of the data interaction method based on cross-network interconnection of the present application. DETAILED DESCRIPTION

[0022] The technical solutions of the present application will be further explained in combination with the accompanying drawings.

[0023] As Figure 1 The framework of the data interaction system based on cross-network interconnection of the present application comprises an external network service system, an inter-network switching device and an internal network service system. The external network service system transmits the data to be transmitted to the internal network service system through the inter-network switching device. In the present application, the data to be transmitted comprises static library table data, dynamic flow data and real-time message data. The inter-network switching device is used for managing cross-network control strategies, detecting the state of the inter-network interaction agent device and actively establishing a cross-network data transmission encryption channel. Figure 2 The inter-network switching device comprises an external network processing unit, a switching processing unit and an internal network processing unit. The external network processing unit is used for processing the data transmitted by the external network service system. The switching processing unit is used for transmitting the data processed by the external network processing unit to the internal network processing unit. The internal network processing unit is used for processing the received data and transmitting the processed data to the internal network service system. Through the data interaction system based on cross-network interconnection of the present application, the data to be transmitted can be transmitted from the external network service system to the internal network service system, and the integrity and security of the data transmission process can be ensured.

[0024] In the present application, the external network processing unit comprises an external network interface area, a first processing control area and a first data buffer area. The external network interface area is used for receiving the data transmitted by the external network service system and transmitting the data to the first processing control area. The first processing control area receives the data transmitted by the external network interface area and performs security checks such as virus sample detection and intrusion inspection and protection on the received data to avoid security vulnerabilities in the data to be transmitted and ensure the security of the data transmission. Then, the data passing the security check is stored in the first data buffer area. The first data buffer area transmits the stored data to the inter-network switching device one by one.

[0025] In the present application, the internal network processing unit comprises an internal network interface area, a second processing control area and a second data buffer area. The second data buffer area receives the data from the inter-network switching device and transmits the received data to the second processing control area one by one. The second processing control area performs virus and intrusion detection security checks on the received data according to the data characteristics. The data passing the check is sent to the internal network interface area. The internal network interface area transmits the received data to the internal network service system.

[0026] In the present application, the switching processing unit is composed of a light emitting unit and a light receiving unit. The light emitting unit and the light receiving unit are connected through an irreversible direction optical fiber. This can not only guarantee the bandwidth of the data transmission channel, but also physically realize the one-way transmission of data in the channel, thereby achieving the physical isolation effect of the network gate.

[0027] The extranet service system comprises an extranet data processing service module, a file service module, a push service module and a first inter-network proxy device, the extranet data processing service module converts the data to be transmitted into a text file through format conversion; the file service module is used for temporarily storing the text file; the push service module is used for reading the text file in the file service module, converting the text file into a UDP protocol data packet, disassembling and marking the UDP protocol data packet, and sending the UDP protocol data packet to the first inter-network proxy device; the first inter-network proxy device is used for passively establishing a cross-network data transmission encryption channel according to an interaction request between the intranet and the extranet, the first inter-network proxy device is located between the extranet system and the inter-network switching device, a data transmission encryption channel is established between the first inter-network proxy device and the inter-network switching device, so that in a complex multi-user network, even if network traffic mirroring occurs during data transmission, the service cannot obtain the data content, thereby ensuring that the data is not intercepted, stolen and tampered with during transmission, and the integrity of the transmitted data is ensured.

[0028] The intranet service system comprises a second inter-network proxy device, a receiving service module and an intranet data processing service module, the second inter-network proxy device is used for passively establishing a cross-network data transmission encryption channel according to an interaction request between the intranet and the extranet, the second inter-network proxy device is located between the inter-network switching device and the intranet system, a data transmission encryption channel is established between the second inter-network proxy device and the inter-network switching device; the receiving service module is used for receiving the UDP protocol data packet sent by the second inter-network proxy device and sequentially assembling the UDP protocol data packet according to the mark on the UDP protocol data packet; the intranet data processing service module is used for receiving the UDP protocol data packet assembled by the receiving service module and performing a persistent storage operation.

[0029] As Figure 3 The application further provides a data interaction method based on cross-network interconnection, specifically comprising the following steps:

[0030] Step 1, converting the data to be transmitted into a text file through an extranet data processing module, storing the text file in a file service module, and encrypting the text file through an MD5 encryption algorithm to generate a check value;

[0031] Step 2, converting the text file and the corresponding check value into a UDP protocol data packet through a push service module, and disassembling and marking the UDP protocol data packet, specifically, cutting the UDP protocol data packet into a plurality of UDP protocol data packets not greater than 64K, marking the serial number of the cut UDP protocol data packet, and transmitting the UDP protocol data packet to a first inter-network proxy service device;

[0032] Step 3, the first network interactive proxy service device checks network routing and UDP protocol packet content, if the destination address of the UDP protocol packet is a network address, the first network interactive proxy service device transmits data in a transparent manner; otherwise, the network exchange device checks whether the second network interactive proxy service device corresponding to the target address is online, if not, the data transmission is ended; otherwise, the network exchange device first establishes a data encryption transmission channel with the first network interactive proxy service device, and then establishes a data encryption transmission channel with the second network interactive proxy service device, and the established encryption transmission channel supports 3GE bandwidth;

[0033] Step 4, after the data encryption transmission channel is established, the UDP protocol packet is received by the external network interface area in the external network processing unit of the network exchange device, and then the UDP protocol packet is transferred to the first processing control area for security check, and after the check is passed, it is stored in the first data buffer area for sending, the UDP protocol packets in the first data buffer area are sent to the light emitting unit of the exchange processing unit one by one, and then sent to the light receiving unit through the irreversible direction optical fiber physical line, and then the light receiving unit sends the UDP protocol packet to the second data buffer area in the internal network processing unit, and then forwards it to the second processing control area for data characteristic security compliance check, and after the check is passed, it is given to the internal network interface area, and the data is transmitted to the receiving service module at the destination address through the second network interactive service device;

[0034] Step 5, the receiving service module assembles and restores data according to the mark on the UDP protocol packet, and checks according to the check value to ensure that the received original data is complete, accurate and not tampered with, and the UDP protocol packet that fails the check is put into the isolation area for manual confirmation and subsequent retransmission operation, and the UDP protocol packet that passes the check is forwarded to the internal network data processing service module for persistent storage operation and stored in the local file server and database, which ensures data transmission and data content integrity.

[0035] The data interaction system and method based on cross-network interconnection of the application can improve the bandwidth of data transmission in the cross-network transmission process by optimizing the network exchange device and using irreversible direction optical fiber on the network exchange device, and can improve the link security of data transmission in the cross-network transmission process by establishing a data transmission encryption channel between the network interactive proxy device and the network exchange device. In addition, the application increases data checking in the receiving service module of the internal network to ensure the integrity of the cross-network transmission data.

[0036] The above merely is the preferred embodiment of the present application, the protection scope of the present application is not limited to the above-mentioned embodiment, and the technical scheme belonging to the idea of the present application is all the protection scope of the present application. It should be pointed out that, for the ordinary skilled in the art, some improvements and decorations without departing from the principle of the present application should be regarded as the protection scope of the present application.

Claims

1. A data interaction system based on cross-network interconnection, characterized in that: include: An external network service system, an inter-network switching device, and an internal network service system, wherein the external network service system transmits the data to be transmitted to the internal network service system through the inter-network switching device, and the inter-network switching device is used to manage cross-network control policies, detect the status of inter-network interaction proxy devices, and actively establish an encrypted channel for cross-network data transmission; The inter-network switching device includes: an external network processing unit, an exchange processing unit and an internal network processing unit. The external network processing unit is used to process data transmitted from the external network service system; the exchange processing unit is used to transmit the data processed by the external network processing unit to the internal network processing unit; the internal network processing unit is used to process the received data and transmit the processed data to the internal network service system; The switching processing unit is composed of a light emitting unit and a light receiving unit, and the light emitting unit and the light receiving unit are connected via an irreversible optical fiber; The extranet service system includes an extranet data processing service module, a file service module, a push service module, and a first inter-network interaction proxy device. The extranet data processing service module converts the format of data to be transmitted into a text file. The file service module is used for temporary storage of text files. The push service module is used to read text files from the file service module, convert them into UDP protocol data packets, disassemble and mark the UDP protocol data packets, and send them to the first inter-network interaction proxy device. The first inter-network interaction proxy device is used to passively establish an encrypted cross-network data transmission channel based on interaction requests between the internal and external networks. The intranet service system includes: a second inter-network interaction proxy device, a receiving service module and an intranet data processing service module. The second inter-network interaction proxy device is used to passively establish an encrypted cross-network data transmission channel based on the interaction request between the internal and external networks; the receiving service module is used to receive the UDP protocol data packets sent by the second inter-network interaction proxy device and assemble them in sequence according to the marks on the UDP protocol data packets; the intranet data processing service module is used to receive the UDP protocol data packets assembled by the receiving service module and perform persistent storage operations.

2. A data interaction system based on cross-network interconnection according to claim 1, characterized in that: The external network processing unit includes: an external network interface area, a first processing control area and a first data buffer; the external network interface area is used to receive data sent by the external network service system and transmit it to the first processing control area; the first processing control area receives the data sent by the external network interface area, performs a security check on the received data, and stores the data that passes the security check in the first data buffer; the first data buffer sends the stored data one by one to the inter-network switching device.

3. A data interaction system based on cross-network interconnection according to claim 2, characterized in that: The intranet processing unit includes: an intranet interface area, a second processing control area and a second data buffer area. The second data buffer area receives data from the inter-network switching device and sends the received data to the second processing control area one by one; the second processing control area performs a data feature security and compliance check on the received data, and sends it to the intranet interface area after the check passes; the intranet interface area sends the received data to the intranet service system.

4. The data interaction system based on cross-network interconnection according to claim 1, characterized in that: The data to be transferred includes: static library table data, dynamic stream data and real-time message data.

5. A data interaction method based on a cross-network interconnected data interaction system according to any one of claims 1 to 4, characterized in that: The specific steps include: Step 1: Convert the data to be transmitted into a text file through the external network data processing module, store the text file in the file service module, and encrypt the text file to generate a check value; Step 2: The text file and the corresponding checksum are converted into UDP protocol data packets through the push service module, and the UDP protocol data packets are disassembled and marked, and transmitted to the first inter-network interaction proxy service device; Step 3: The first inter-network interaction proxy service device checks the network route and the content of the UDP protocol data packet. If the destination address of the UDP protocol data packet is an intra-network address, the first inter-network interaction proxy service device transmits the data in a transparent manner. Otherwise, the first inter-network interaction proxy service device checks whether the second inter-network interaction proxy service device corresponding to the destination address is online through the inter-network switching device. If not, the data transmission is terminated. Otherwise, the network switching device first establishes a data encryption transmission channel with the first network interaction proxy service device, and then establishes a data encryption transmission channel with the second network interaction proxy service device; Step 4: After the data encryption transmission channel is established, the UDP protocol data packet is sent to the receiving service module at the destination address through the second inter-network interaction proxy service device; Step 5. The receiving service module assembles the packets in sequence according to the marks on the UDP protocol packets and verifies them according to the check value. The UDP protocol packets that fail the verification are placed in the isolation area for future reference. The UDP protocol packets that pass the verification are forwarded to the intranet data processing service module for persistent storage operations.

Citation Information

Patent Citations

  • Internal and external network isolated one-way secure data transmission structure and method

    CN111901688A

  • File transmission method, device and system based on one-way optical shutter

    CN115801767A