A trusted heterogeneous redundant dual-channel data security boot system and method
By using a trusted heterogeneous redundant dual-channel data security transfer system, which utilizes multi-layer buffers and heterogeneous unidirectional isolators, combined with trusted computing technology, the system achieves end-to-end trusted interconnection authentication and secure data transmission. This solves the network attack risk during the cross-network and cross-domain data transfer process and improves the system's defense capabilities and data transmission reliability.
Patent Information
- Application Number
- CN202411906756.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2044-12-24
AI Technical Summary
In the process of data transfer across networks and domains, how can we effectively reduce the risk of network attacks and ensure the security and reliability of data transmission?
A trusted heterogeneous redundant dual-channel data security connection system is adopted, including trusted computers for the sender and receiver, trusted data exchange gateways, unidirectional isolators, and trusted buffer gateways. Through multi-layer buffers and heterogeneous unidirectional isolators, combined with trusted computing technology, the system achieves end-to-end trusted interconnection authentication and secure data transmission.
By employing multi-layered defense barriers and differentiated protection methods, the system's defense capabilities have been enhanced, the risk of network attacks has been reduced, and the reliability and security of data transmission have been ensured, adapting to data transmission with different performance requirements.
Smart Images

Figure CN119788368B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of network space security, and particularly relates to a trusted heterogeneous redundant double-channel data security lead-in system and method. BACKGROUND
[0002] In the information age, guaranteeing efficient sharing of data is a key link, and the demand for data cross-network and cross-domain safe lead-in has become very urgent, but the data information cross-network and cross-domain lead-in may face phishing attacks, man-in-the-middle attacks, DDOS attacks, virus attacks, social engineering and other network attacks, and once the attacker attacks the high security level network from the low security level network, it will bring immeasurable consequences. In the face of the security risks that may be brought by data cross-network and cross-domain lead-in, how to realize data cross-network and cross-domain safe lead-in is a problem to be solved. SUMMARY
[0003] The purpose of the application is to provide a trusted heterogeneous redundant double-channel data security lead-in system and method, to solve the security risks existing in data cross-network and cross-domain safe lead-in, and to reduce the risk of system being attacked by network.
[0004] The technical scheme of the application is:
[0005] 1. A trusted heterogeneous redundant double-channel data security lead-in system, characterized in that it comprises: a sender external connection access subsystem, an isolation exchange subsystem, an isolation buffer subsystem, and a receiver external connection access subsystem; wherein:
[0006] The sender external connection access subsystem comprises a sender trusted computer.
[0007] The isolation exchange subsystem comprises a first trusted data exchange gateway and a first unidirectional isolator.
[0008] The isolation buffer subsystem comprises a trusted isolation buffer gateway, a second unidirectional isolator, a third unidirectional isolator, and a second trusted data exchange gateway.
[0009] The receiver external connection access subsystem comprises a receiver trusted computer.
[0010] Along the data transmission direction, the data transmission link is in sequence from the sender trusted computer to the first trusted data exchange gateway, to the first unidirectional isolator, to the trusted isolation buffer gateway, to the second unidirectional isolator or the third unidirectional isolator, to the second trusted data exchange gateway, and to the receiver trusted computer.
[0011] The first one-way isolator, the second one-way isolator, and the third one-way isolator are heterogeneous one-way isolators, comprising a sending end, a one-way channel, and a receiving end, wherein the sending end is configured to receive data and perform private protocol encapsulation on the received data, the one-way channel is configured to transmit the private protocol encapsulated data to the receiving end in a single direction, and the receiving end is configured to receive data and send the data.
[0012] The sender trusted computer, the receiver trusted computer, the first trusted data exchange gateway, the trusted isolated buffering gateway, and the second trusted data exchange gateway are all built-in trusted roots; the sender trusted computer and the first trusted data exchange gateway, the first trusted data exchange gateway and the trusted isolated buffering gateway, the trusted isolated buffering gateway and the second trusted data exchange gateway, and the second trusted data exchange gateway and the receiver trusted computer are authenticated by the trusted roots for trusted interconnection, so as to realize the security and trustworthiness of the data security lead system.
[0013] Further, the sender trusted computer, the receiver trusted computer, the first trusted data exchange gateway, the trusted isolated buffering gateway, and the second trusted data exchange gateway are configured with a trusted security management module, which is configured to realize the trusted interconnection authentication and the trustworthiness measurement of the communication parties, wherein the trusted interconnection authentication is configured to authenticate the identities of the communication parties, and the trustworthiness measurement is configured to measure the trustworthiness of the self.
[0014] Further, the sender trusted computer, the first trusted data exchange gateway, the trusted isolated buffering gateway, and the second trusted data exchange gateway are further configured with a data trusted exchange module, which is configured to process the received data according to the trustworthiness measurement results of the trusted security management modules; when the trustworthiness measurement result is trusted, the data is encrypted, protected, and signed, and a trusted identifier, a time delay identifier, and a data size identifier are added to form a special format for sending to the next level; when the result is untrusted, the received data is discarded; the receiver trusted computer is configured with a data trusted exchange module, which is configured to perform integrity verification and digital signature verification on the received data when the trustworthiness measurement result of the self-configured trusted security management module is trusted, and to decrypt the received data and restore it to plaintext data after the verification; when the result is untrusted, the received data is discarded.
[0015] Further, the first one-way isolator, the second one-way isolator, and the third one-way isolator are different types of optical gate isolation, photoelectric isolation, and mechanical isolation.
[0016] Further, the data trusted exchange module, according to the trusted measurement result of the trusted security management module of the subsystem, first performs format checking and trusted identity checking on the received data before processing the received data; if the format checking and trusted identity checking are not passed, the received data is discarded; if the format checking and trusted identity checking are passed, the received data is processed according to the trusted interconnection authentication and the trusted measurement result of the trusted security management module of the subsystem.
[0017] Further, it further comprises an operation and maintenance subsystem for uniformly managing the running state and data transmission of the sender external access subsystem, the boundary protection subsystem, the isolated exchange subsystem, the isolated buffer subsystem, and the receiver external access subsystem, and providing task-level full-process log auditing, and the auditing elements include: task occurrence time, sending subject, receiving subject, path node, data size, and time consumption.
[0018] Further, the first unidirectional isolator selects an optical gate type unidirectional isolator, the second unidirectional isolator selects an optoelectronic type unidirectional isolator, and the third unidirectional isolator selects a mechanical type unidirectional isolator; the trusted isolated buffer gateway is configured with a transmission link distribution module, which selects the data link of the second unidirectional isolator or the third unidirectional isolator according to the time delay identifier and the data size identifier of the received data; data with small transmission data volume and high time delay requirement is sent to the second unidirectional isolator; and data with large transmission data volume and low time delay requirement is sent to the third unidirectional isolator.
[0019] Further, it further comprises a boundary protection subsystem arranged between the sender external access subsystem and the isolated exchange subsystem, for performing network isolation, access control, attack behavior monitoring, and malicious code detection security protection on the boundary between the sender external access subsystem and the isolated exchange subsystem; and the trusted security management module further comprises a trusted reporting function for alarming when an untrusted condition is found.
[0020] A trusted heterogeneous redundant dual-channel data security lead-in method, characterized in that a trusted heterogeneous redundant dual-channel data security lead-in system as described above is used to perform full-link trusted interconnection authentication and lead-in data safe and reliable transmission, and the specific execution steps are as follows:
[0021] A. System initialization
[0022] The operation and maintenance subsystem initializes and configures the sender external access subsystem, the isolation exchange subsystem, the isolation buffer subsystem, and the receiver external access subsystem in an out-of-band manner, monitors the running state and data exchange behavior of each subsystem in real time, and performs task-level full-process log auditing; the sender trusted computer, the receiver trusted computer, the first trusted data exchange gateway, the trusted isolation buffer gateway, and the second trusted data exchange gateway are initialized in a trusted state, and initial measurement values are generated; the sender trusted computer sends its authentication object information as original authentication object information to the first trusted data exchange gateway, and the first trusted data exchange gateway stores the received original authentication object information of the sender trusted computer in a trusted root; the first trusted data exchange gateway sends its authentication object information as original authentication object information to the trusted isolation buffer gateway, and the trusted isolation buffer gateway stores the received original authentication object information of the first trusted data exchange gateway in a trusted root; the trusted isolation buffer gateway sends its authentication object information as original authentication object information to the second trusted data exchange gateway, and the second trusted data exchange gateway stores the received original authentication object information of the trusted isolation buffer gateway in a trusted root; the second trusted data exchange gateway sends its authentication object information as original authentication object information to the receiver trusted computer, and the receiver trusted computer stores the received original authentication object information of the second trusted data exchange gateway in a trusted root;
[0023] B. Full-link trusted interconnection authentication
[0024] The data trusted exchange module of the sender trusted computer detects whether there is data to be connected; when there is data to be connected, the sender trusted computer and the first trusted data exchange gateway, the first trusted data exchange gateway and the trusted isolation buffer gateway, the trusted isolation buffer gateway and the second trusted data exchange gateway, and the second trusted data exchange gateway and the receiver trusted computer start trusted interconnection authentication based on a trusted root, and the process is as follows:
[0025] B1. Trusted interconnection authentication between the sending trusted computer and the first trusted data exchange gateway: the trusted security management module of the sending trusted computer sends authentication object information to the trusted security management module of the first trusted data exchange gateway, which compares the received authentication object information of the sending trusted computer with the original authentication object information of the sending trusted computer stored in its trusted root; if the comparison fails, the trusted interconnection authentication is stopped and step B is returned; if the comparison passes, the sending trusted computer and the first trusted data exchange gateway establish a communication connection and perform B2 to start the trusted interconnection authentication between the first trusted data exchange gateway and the trusted isolation buffer gateway;
[0026] B2. Trusted interconnection authentication between the first trusted data exchange gateway and the trusted isolation buffer gateway: the trusted security management module of the first trusted data exchange gateway sends authentication object information to the trusted security management module of the trusted isolation buffer gateway, which receives the authentication object information of the first trusted data exchange gateway and compares it with the original authentication object information of the first trusted data exchange gateway stored in its trusted root; if the comparison fails, the trusted interconnection authentication is stopped and step B is returned; if the comparison passes, the first trusted data exchange gateway and the trusted isolation buffer gateway establish a communication connection and perform B3 to start the trusted interconnection authentication between the trusted isolation buffer gateway and the second trusted data exchange gateway;
[0027] B3. Trusted interconnection authentication between the trusted isolation buffer gateway and the second trusted data exchange gateway: the trusted security management module of the trusted isolation buffer gateway sends authentication object information to the trusted security management module of the second trusted data exchange gateway; the trusted security management module of the second trusted data exchange gateway receives the authentication object information of the trusted isolation buffer gateway and compares it with the original authentication object information of the trusted isolation buffer gateway stored in its trusted root; if the comparison fails, the trusted interconnection authentication is stopped and step B is returned; if the comparison passes, the trusted isolation buffer gateway and the second trusted data exchange gateway establish a communication connection and perform B4 to start the trusted interconnection authentication between the second trusted data exchange gateway and the receiving trusted computer;
[0028] B4. Trusted interconnection authentication between the second trusted data exchange gateway and the receiving party trusted computer: the trusted security management module of the second trusted data exchange gateway sends authentication object information to the trusted security management module of the receiving party trusted computer; the trusted security management module of the receiving party trusted computer receives the authentication object information of the second trusted data exchange gateway, compares it with the original authentication object information of the second trusted data exchange gateway stored in its trusted root memory; if the comparison fails, the trusted interconnection authentication is stopped and step B is returned; if the comparison passes, the second trusted data exchange gateway and the receiving party trusted computer establish a communication connection;
[0029] C. The trusted security management module in the receiving party trusted computer informs the data trusted exchange module in the sending party trusted computer by an out-of-band manner that the trusted channel is ready; the data trusted exchange module in the sending party trusted computer performs step D to guide data sending;
[0030] D. Guiding data for data communication
[0031] D1. The data trusted exchange module configured in the sending party trusted computer performs format checking and trusted identity checking on the received data; if the format checking and trusted identity checking fail, the received data is discarded and step B is returned; if the format checking and trusted identity checking pass, the received data is processed according to the trusted measurement result of the trusted security management module configured in itself; when the trusted measurement result is trusted, the data is encrypted, integrity protected, digitally signed, and added with trusted identity, time delay identity, and data size identity to form a special format, which is sent to the data trusted exchange module configured in the first trusted data exchange gateway after being protected by the boundary protection subsystem, and step D2 is performed; when the trusted measurement result is untrusted, the received data is discarded and step B is returned;
[0032] D2. When the data trusted exchange module configured in the first trusted data exchange gateway finds that there is data guiding, it performs format checking and trusted identity checking on the received data; if the format checking and trusted identity checking fail, the received data is discarded and step B is returned; if the format checking and trusted identity checking pass, the received data is processed according to the trusted measurement result of the trusted security management module in the subsystem; when the trusted measurement result is trusted, the data is encrypted, integrity protected, digitally signed, and added with trusted identity, time delay identity, and data size identity to form a special format which is sent to the first unidirectional isolator; the first unidirectional isolator encapsulates the received data with a private protocol and sends it to the data trusted exchange module configured in the trusted isolated buffer proxy gateway; when the trusted measurement result is untrusted, the received data is discarded and step B is returned;
[0033] D3. The data trusted exchange module of the trusted isolation buffer agent gateway configuration discovers that there is data connection, and performs format checking and trusted identity checking on the received data; if the format checking and trusted identity checking are not passed, the received data is discarded, and step B is returned; if the format checking and trusted identity checking are passed, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem; when the trusted measurement result is trusted, the data is encrypted, protected, integrity protected, and digitally signed, a trusted identity, a time delay identity, and a data size identity are added, a special format is formed, and is sent to the transmission link allocation module configured by the trusted isolation buffer agent gateway; the transmission link allocation module selects data to be sent to the second unidirectional isolator or the third unidirectional isolator according to the time delay identity and the data size identity of the received data; data with small transmission data volume and high time delay requirement is sent to the second unidirectional isolator; data with large transmission data volume and low time delay requirement is sent to the third unidirectional isolator; the second unidirectional isolator or the third unidirectional isolator sends the received data to the data trusted exchange module of the second trusted data exchange gateway configuration after private protocol encapsulation; when the trusted measurement result is untrusted, the received data is discarded, and step B is returned;
[0034] D4. The data trusted exchange module of the second trusted data exchange gateway configuration discovers that there is data connection, and performs format checking and trusted identity checking on the received data; if the format checking and trusted identity checking are not passed, the received data is discarded, and step B is returned; if the format checking and trusted identity checking are passed, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem; when the trusted measurement result is trusted, the data is encrypted, protected, integrity protected, and digitally signed, a trusted identity, a time delay identity, and a data size identity are added, a special format is formed, and is sent to the data trusted exchange module of the receiving party trusted computer configuration; when the trusted measurement result is untrusted, the received data is discarded, and step B is returned;
[0035] D5. The data trusted exchange module of the receiving party trusted computer configuration discovers that there is data connection, and performs format checking and trusted identity checking on the received data; if the format checking and trusted identity checking are not passed, the received data is discarded, and step B is returned; if the format checking and trusted identity checking are passed, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem; when the trusted measurement result is trusted, the received data is integrity checked and digitally signed verified, and after the verification is passed, the received data is decrypted and restored to plaintext data, and the data communication is completed; when the trusted measurement result is untrusted, the received data is discarded, and step B is returned.
[0036] Advantages of this invention: The trusted heterogeneous redundant dual-channel data secure connection method described in this invention has four advantages:
[0037] First, by setting up multiple buffer zones, the system's defense barriers are increased, the defense depth is expanded, the difficulty of the system being intruded into by the network is increased, and the risk of the system being breached by network attacks is greatly reduced.
[0038] Second, to address the homomorphic failure problem, a heterogeneous buffer is designed. This involves systematically deploying data exchange gateways, buffer proxy gateways, and multiple unidirectional isolators in a differentiated manner to distinguish different types of protection measures, further confusing and deceiving attackers so that they cannot continuously breach the network using the same method.
[0039] Third, based on trusted computing technology, trusted interconnection between cross-network and cross-domain devices is realized. Trust is passed down level by level through trust at each level, and a secure channel is established for the entire link, realizing "building a trusted path first and then transmitting trusted data".
[0040] Fourth, to meet different performance requirements, dual channels are designed around the two core indicators of "latency" and "data size". On the one hand, this improves the reliability of the system, and on the other hand, it better meets the application needs through differentiated design, reducing the situation where large data volume tasks block the opto-isolation channel for a long time, while small data volume tasks blindly use the mechanical isolation channel, increasing unnecessary latency. Attached Figure Description
[0041] Figure 1 This is a schematic diagram of a trusted heterogeneous redundant dual-channel data security connection system; wherein 1-sender external access subsystem, 2-border protection subsystem, 3-isolation switching subsystem, 4-isolation buffer subsystem, 5-receiver external access subsystem, 11-sender trusted computer 1, 31-first trusted data exchange gateway, 32-first unidirectional isolator, 41-trusted isolation buffer gateway, 42-second unidirectional isolator, 43-third unidirectional isolator, 44-second trusted data exchange gateway, 51-receiver trusted computer. In addition, the diagram also includes a trusted security management module, a trusted data exchange module, and a transmission link allocation module. Detailed Implementation
[0042] Example 1:
[0043] like Figure 1 As shown, a trusted heterogeneous redundant dual-channel data security connection system is characterized by comprising: a sender external access subsystem (1), a boundary protection subsystem (2), an isolation switching subsystem (3), an isolation buffer subsystem (4), a receiver external access subsystem (5), and an operation and maintenance management subsystem (6); wherein:
[0044] The external access subsystem (1) of the sender includes a trusted computer of the sender (11);
[0045] The isolated exchange subsystem (3) comprises a first trusted data exchange gateway (31) and a first unidirectional isolator (32);
[0046] The isolated buffer subsystem (4) comprises a trusted isolated buffer gateway (41), a second unidirectional isolator (42), a third unidirectional isolator (43), and a second trusted data exchange gateway (44);
[0047] The receiver external connection access subsystem (5) comprises a receiver trusted computer (51);
[0048] In the data transmission direction, the data transmission link is in sequence from the sender trusted computer (11) to the boundary protection subsystem (2), to the first trusted data exchange gateway (31), to the first unidirectional isolator (32), to the trusted isolated buffer gateway (41), to the second unidirectional isolator (42) or the third unidirectional isolator (43), to the second trusted data exchange gateway (44), and to the receiver trusted computer (51);
[0049] The first unidirectional isolator (32), the second unidirectional isolator (42), and the third unidirectional isolator (43) are heterogeneous unidirectional isolators (the heterogeneous unidirectional isolator means that the three types are different, and the unidirectional means that data is transmitted from a low security level to a high security level), comprising a sending end, a unidirectional channel, and a receiving end. The sending end is used for receiving data and performing private protocol encapsulation on the received data, and then transmitting the data to the receiving end along a single direction through the unidirectional channel. The receiving end forwards the data to the outside of the isolator after receiving the data;
[0050] The sender trusted computer (11), the receiver trusted computer (51), the first trusted data exchange gateway (31), the trusted isolated buffer gateway (41), and the second trusted data exchange gateway (44) are all built-in trusted roots. The sender trusted computer (11) and the first trusted data exchange gateway (31), the first trusted data exchange gateway (31) and the trusted isolated buffer gateway (41), the trusted isolated buffer gateway (41) and the second trusted data exchange gateway (44), and the second trusted data exchange gateway (44) and the receiver trusted computer (51) perform trusted interconnection authentication based on the trusted roots, and build a secure and trusted software and hardware environment for the whole channel. The trusted root is a module for establishing and guaranteeing a trusted source point, and is used for trusted interconnection authentication of received data and trusted measurement of a device (computer, gateway).
[0051] The sender trusted computer (11), the receiver trusted computer (51), the first trusted data exchange gateway (31), the trusted isolated buffering gateway (41), and the second trusted data exchange gateway (44) are configured with a trusted security management module; the trusted security management module is used to realize the trusted interconnection authentication and the trusted measurement of the two parties in communication, and obtain a conclusion of whether the two parties in communication are trusted. The trusted interconnection authentication refers to that the trusted authentication is initiated by the data sender to the data receiver before data transmission; the objects of the trusted authentication include the device IP / MAC layer authentication, the built-in certificate authentication of the device firmware information and serial number, and the device trusted state authentication; the trusted state is a trusted measurement value generated based on the built-in trusted root of the device (computer, gateway); the trusted measurement is a process of calculating the security of the software and hardware environment of the device (computer, gateway) based on the measurement algorithm (such as MD5, SHA1, etc.) provided by the trusted root; and the calculation result of the trusted measurement is the trusted measurement value.
[0052] The sender trusted computer (11), the first trusted data exchange gateway (31), the trusted isolated buffering gateway (41), and the second trusted data exchange gateway (44) are further configured with a data trusted exchange module, which is used to process the received data according to the trusted measurement result of the trusted security management module; when the trusted measurement result is trusted, the data is encrypted, protected in integrity, protected by digital signature, added with a trusted identifier, a time delay identifier, and a data size identifier, formed into a special format, and sent to the next level; when the trusted measurement result is untrusted, the received data is discarded; the receiver trusted computer (51) is configured with a data trusted exchange module, which is used to perform integrity inspection and digital signature verification on the received data when the trusted measurement result of the trusted security management module is trusted, decrypt the received data after the verification, and restore the data to the original data; when the trusted measurement result is untrusted, the received data is discarded. The trusted identifier is generated by combining the data type, the secret level, the forwarding range, and the trusted measurement value generated by the host trusted security management program, and is protected by digital signature.
[0053] The first one-way isolator (32), the second one-way isolator (42), and the third one-way isolator (43) are different types of optical shutter type isolation, photoelectric type isolation, and mechanical type isolation. Alternatively, the first one-way isolator (32) is an optical shutter type one-way isolator, which can be used to complete the first isolation and handover process at a high speed as much as possible due to its large data throughput; the second one-way isolator (42) is a photoelectric type one-way isolator, and the third one-way isolator (43) is a mechanical type one-way isolator; the trusted isolation buffer gateway (41) is provided with a transmission link distribution module, which selects the data link of the second one-way isolator (42) or the third one-way isolator (43) according to the time delay identifier and the data size identifier of the received data, and sends data with small transmission data volume and high time delay requirement to the second one-way isolator (42) and data with large transmission data volume and low time delay requirement to the third one-way isolator (43).
[0054] The data trusted exchange module performs format checking and trusted identifier checking on the received data before processing the received data according to the trusted measurement result of the trusted security management module of the subsystem, discards the received data if the format checking and trusted identifier checking are not passed, and processes the received data according to the trusted measurement result of the trusted security management module of the subsystem if the format checking and trusted identifier checking are passed.
[0055] The operation and maintenance management subsystem (6) is used for unified management of the running state and data transmission of the sender external access subsystem (1), the boundary protection subsystem (2), the isolation exchange subsystem (3), the isolation buffer subsystem (4), and the receiver external access subsystem (5), and provides task-level full-process log auditing, and the auditing elements include occurrence time, sending subject, receiving subject, path node, data size, and time.
[0056] The boundary protection subsystem (2) is used for security protection of the boundary between the sender external access subsystem (1) and the isolation exchange subsystem (3), and can adopt multiple security protection modes such as network isolation, access control, attack behavior monitoring, and malicious code detection.
[0057] The trusted security management module further includes a trusted reporting function which alarms when untrusted data is found.
[0058] Embodiment 2
[0059] A trusted heterogeneous redundant dual-channel data security connection method, characterized in that a trusted heterogeneous redundant dual-channel data security connection system as described in Embodiment 1 is used to perform full-link trusted interconnection authentication and reliable transmission of connected data, and the specific execution steps are as follows:
[0060] A. System initialization
[0061] The sender external access subsystem (1), the isolation exchange subsystem (3), the isolation buffer subsystem (4), and the receiver external access subsystem (5) are initialized and configured by the operation and maintenance subsystem in an out-of-band manner, the running state and data exchange behavior of each subsystem are monitored in real time, and task-level full-process log auditing is performed; the sender trusted computer (11), the receiver trusted computer (51), the first trusted data exchange gateway (31), the trusted isolation buffer gateway (41), and the second trusted data exchange gateway (44) are initialized in a trusted state, and initial measurement values are generated; the sender trusted computer (11) sends its authentication object information as original authentication object information to the first trusted data exchange gateway (31), which stores the received original authentication object information of the sender trusted computer (11) in a trusted root; the first trusted data exchange gateway (31) sends its authentication object information as original authentication object information to the trusted isolation buffer gateway (41), which stores the received original authentication object information of the first trusted data exchange gateway (31) in a trusted root; the trusted isolation buffer gateway (41) sends its authentication object information as original authentication object information to the second trusted data exchange gateway (44), which stores the received original authentication object information of the trusted isolation buffer gateway (41) in a trusted root; the second trusted data exchange gateway (44) sends its authentication object information as original authentication object information to the receiver trusted computer (51), which stores the received original authentication object information of the second trusted data exchange gateway (44) in a trusted root;
[0062] The authentication object information is IP / MAC, device firmware information, and serial number, etc. built-in credential authentication, trusted state.
[0063] B. Full-link trusted interconnection authentication
[0064] The data trusted exchange module of the sender trusted computer (11) detects whether there is data to be connected; when there is data to be connected, the sender trusted computer (11) and the first trusted data exchange gateway (31), the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41), the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44), and the second trusted data exchange gateway (44) and the receiver trusted computer (51) start trusted interconnection authentication based on a trusted root, and the process is as follows:
[0065] B1. Trusted interconnection authentication between the sender trusted computer (11) and the first trusted data exchange gateway (31): the trusted security management module of the sender trusted computer (11) sends authentication object information to the trusted security management module of the first trusted data exchange gateway (31), the trusted security management module of the first trusted data exchange gateway (31) compares the received authentication object information of the sender trusted computer (11) with the original authentication object information of the sender trusted computer (11) stored in its trusted root; if the comparison fails, stop the trusted interconnection authentication and return to step B; if the comparison passes, the sender trusted computer (11) and the first trusted data exchange gateway (31) establish a communication connection, and execute B2 to start the trusted interconnection authentication between the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41);
[0066] B2. Trusted interconnection authentication between the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41): the trusted security management module of the first trusted data exchange gateway (31) sends authentication object information to the trusted security management module of the trusted isolation buffer gateway (41), the trusted security management module of the trusted isolation buffer gateway (41) receives the authentication object information of the first trusted data exchange gateway (31) and compares it with the original authentication object information of the first trusted data exchange gateway (31) stored in its trusted root; if the comparison fails, stop the trusted interconnection authentication and return to step B; if the comparison passes, the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41) establish a communication connection, and execute B3 to start the trusted interconnection authentication between the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44);
[0067] B3. Trusted interconnection authentication between the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44): the trusted security management module of the trusted isolation buffer gateway (41) sends authentication object information to the trusted security management module of the second trusted data exchange gateway (44); the trusted security management module of the second trusted data exchange gateway (44) receives the authentication object information of the trusted isolation buffer gateway (41) and compares it with the original authentication object information of the trusted isolation buffer gateway (41) stored in its trusted root; if the comparison fails, stop the trusted interconnection authentication and return to step B; if the comparison passes, the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44) establish a communication connection, and execute B4 to start the trusted interconnection authentication between the second trusted data exchange gateway (44) and the receiver trusted computer (51);
[0068] B4. Trusted interconnection authentication between the second trusted data exchange gateway (44) and the receiver trusted computer (51): the trusted security management module of the second trusted data exchange gateway (44) sends authentication object information to the trusted security management module of the receiver trusted computer (51); the trusted security management module of the receiver trusted computer (51) receives the authentication object information of the second trusted data exchange gateway (44), and compares it with the original authentication object information of the second trusted data exchange gateway (44) stored in its trusted root; if the comparison fails, stop the trusted interconnection authentication and return to step B; if the comparison passes, the second trusted data exchange gateway (44) and the receiver trusted computer (51) establish a communication connection;
[0069] (The step is a full-link trusted interconnection authentication of multiple trusted devices on the entire link. In order to ensure the continuous trustworthiness of the link between trusted devices, this step is performed to authenticate the full-link trusted interconnection every time a data lead task is initiated.)
[0070] C. The trusted security management module in the receiver trusted computer (51) notifies the data trusted exchange module in the sender trusted computer (11) that the trusted channel is ready through an out-of-band method (out-of-band management refers to transmitting management information through an independent physical channel, which is separate from the data lead channel); the data trusted exchange module in the sender trusted computer (11) performs step D to send lead data;
[0071] D. Lead data for data communication
[0072] D1. The sender external connection access subsystem (1) communicates data to the isolation exchange subsystem (3): the data trusted exchange module configured in the sender trusted computer (11) performs format checking and trusted identity checking on the received data; if the format checking and trusted identity checking do not pass, the received data is discarded and the process returns to step B; if the format checking and trusted identity checking pass, the received data is processed according to the trusted measurement result of the trusted security management module configured in itself; when the trusted measurement result is trusted, the data is encrypted, protected for integrity, digitally signed, and added with trusted identity, time delay identity, and data size identity to form a special format, which is sent to the data trusted exchange module configured in the first trusted data exchange gateway (31) after being protected by the boundary protection subsystem (2), and step D2 is performed; when the trusted measurement result is untrusted, the received data is discarded and the process returns to step B;
[0073] D2. The isolation exchange subsystem (3) communicates data to the isolation buffer subsystem (4):
[0074] The data trusted exchange module configured by the first trusted data exchange gateway (31) discovers data connection, and performs format checking and trusted identification checking on the received data. If the format checking and trusted identification checking are not passed, the received data is discarded, and step B is returned. If the format checking and trusted identification checking are passed, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the data is encrypted, integrity protected, and digitally signed, and trusted identification, time delay identification, and data size identification are added, so that the data is sent to the first unidirectional isolator (32) in a special format. The first unidirectional isolator (32) sends the received data to the data trusted exchange module configured by the trusted isolation buffer agent gateway (41) after private protocol encapsulation. When the trusted measurement result is untrusted, the received data is discarded, and step B is returned.
[0075] D3. The isolation buffer subsystem (4) communicates with the receiving party external access subsystem (5):
[0076] The data trusted exchange module configured by the trusted isolation buffer agent gateway (41) discovers data connection, and performs format checking and trusted identification checking on the received data. If the format checking and trusted identification checking are not passed, the received data is discarded, and step B is returned. If the format checking and trusted identification checking are passed, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the data is encrypted, integrity protected, and digitally signed, and trusted identification, time delay identification, and data size identification are added, so that the data is sent to the transmission link allocation module configured by itself in a special format. The transmission link allocation module selects data to be sent to the second unidirectional isolator (42) or the third unidirectional isolator (43) according to the time delay identification and data size identification of the received data. Data with small transmission data volume and high time delay requirement is sent to the second unidirectional isolator (42), and data with large transmission data volume and low time delay requirement is sent to the third unidirectional isolator (43). The second unidirectional isolator (42) or the third unidirectional isolator (43) sends the received data to the data trusted exchange module configured by the second trusted data exchange gateway (44) after private protocol encapsulation. When the trusted measurement result is untrusted, the received data is discarded, and step B is returned.
[0077] The data trusted exchange module configured by the second trusted data exchange gateway (44) discovers that there is data connection, and performs format checking and trusted identity checking on the received data. If the format checking and trusted identity checking are not passed, the received data is discarded, and the step B is returned. If the format checking and trusted identity checking are passed, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the data is encrypted, protected, integrity protected, digitally signed, and joined with trusted identity, time delay identity and data size identity, and a special format is formed to send the data to the data trusted exchange module configured by the receiving party trusted computer (51). When the trusted measurement result is untrusted, the received data is discarded, and the step B is returned.
[0078] D5. The receiving party external connection access subsystem (5) receives the connection data
[0079] The data trusted exchange module configured by the receiving party trusted computer (51) discovers that there is data connection, and performs format checking and trusted identity checking on the received data. If the format checking and trusted identity checking are not passed, the received data is discarded, and the step B is returned. If the format checking and trusted identity checking are passed, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the received data is integrity checked and digitally signed verified. After the verification is passed, the received data is decrypted and restored to plaintext data, and the connection data communication is completed. When the trusted measurement result is untrusted, the received data is discarded, and the step B is returned.
Claims
1. A trusted heterogeneous redundant dual-channel data security connection system, characterized in that: include: The system comprises: a sender external access subsystem (1), an isolation switching subsystem (3), an isolation buffer subsystem (4), and a receiver external access subsystem (5); among which: The external access subsystem (1) of the sender includes a trusted computer of the sender (11); The isolation and switching subsystem (3) includes a first trusted data exchange gateway (31) and a first unidirectional isolator (32); The isolation buffer subsystem (4) includes a trusted isolation buffer gateway (41), a second one-way isolator (42), a third one-way isolator (43), and a second trusted data exchange gateway (44). The receiver external access subsystem (5) includes the receiver trusted computer (51); Along the data transmission direction, the data transmission link is sequentially from the sender's trusted computer (11) to the first trusted data exchange gateway (31), to the first unidirectional isolator (32), to the trusted isolation buffer gateway (41), to the second unidirectional isolator (42) or the third unidirectional isolator (43), to the second trusted data exchange gateway (44), and to the receiver's trusted computer (51). The first unidirectional isolator (32), the second unidirectional isolator (42), and the third unidirectional isolator (43) are heterogeneous unidirectional isolators, including a transmitting end, a unidirectional channel, and a receiving end. The transmitting end is used to receive data and encapsulate the received data using a private protocol. The unidirectional channel is used to transmit the data encapsulated using the private protocol to the receiving end in a single direction. The receiving end is used to receive data and send the data. The sender trusted computer (11), receiver trusted computer (51), first trusted data exchange gateway (31), trusted isolation buffer gateway (41), and second trusted data exchange gateway (44) all have built-in trusted roots. The trusted computer (11) of the sender and the first trusted data exchange gateway (31), the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41), the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44), and the second trusted data exchange gateway (44) and the trusted computer (51) of the receiver perform trusted interconnection authentication between the two communicating parties based on the trusted root, so as to realize the security and trustworthiness of the data security connection system.
2. The trusted heterogeneous redundant dual-channel data security connection system as described in claim 1, characterized in that: The sender trusted computer (11), receiver trusted computer (51), first trusted data exchange gateway (31), trusted isolation buffer gateway (41), and second trusted data exchange gateway (44) are configured with a trusted security management module. The trusted security management module is used to implement trusted interconnection authentication and trusted measurement between the two communicating parties. The trusted interconnection authentication is used for identity authentication between the two communicating parties, and the trusted measurement measures the trusted state of itself.
3. The trusted heterogeneous redundant dual-channel data security connection system as described in claim 2, characterized in that: The sender trusted computer (11), the first trusted data exchange gateway (31), the trusted isolation buffer gateway (41), and the second trusted data exchange gateway (44) are also configured with a trusted data exchange module, which is used to process the received data according to the trusted measurement result of the trusted security management module configured by each of them. When the trust measurement result is trustworthy, the data is encrypted, protected for integrity, and protected by digital signature. Trust identifiers, delay identifiers, and data size identifiers are added to form a special format for transmission to the next level. When the result is untrustworthy, the received data is discarded. The trusted computer (51) of the receiving party is configured with a trusted data exchange module. When the trust measurement result of its own trusted security management module is trustworthy, it performs integrity verification and digital signature verification on the received data. After the verification is passed, it decrypts the received data and restores it to plaintext data. When the result is untrustworthy, the received data is discarded.
4. The trusted heterogeneous redundant dual-channel data security connection system as described in claim 3, characterized in that: The first unidirectional isolator (32), the second unidirectional isolator (42), and the third unidirectional isolator (43) are different types of optical gate isolation, optoelectronic isolation, and mechanical isolation.
5. The trusted heterogeneous redundant dual-channel data security connection system as described in claim 4, characterized in that: Before processing the received data based on the trust measurement results of the trust security management module of the subsystem, the data trust exchange module first performs format checks and trust identification checks on the received data. If the format checks and trust identification checks fail, the received data is discarded. If the format checks and trust identification checks pass, the received data is then processed based on the trust interconnection authentication and trust measurement results of the trust security management module of the subsystem.
6. The trusted heterogeneous redundant dual-channel data security connection system as described in claim 5, characterized in that: It also includes an operation and maintenance management subsystem (6), which is used to uniformly manage the operation status and data transmission status of the sender external access subsystem (1), boundary protection subsystem (2), isolation switching subsystem (3), isolation buffer subsystem (4), and receiver external access subsystem (5), and provides task-level full-process log auditing. The audit elements include: task occurrence time, sending subject, receiving subject, path nodes, data size, and time taken. The boundary protection subsystem (2) is set between the sender’s external access subsystem (1) and the isolation switching subsystem (3) for network isolation, access control, attack behavior monitoring and malicious code detection security protection of the boundary between the sender’s external access subsystem (1) and the isolation switching subsystem (3); the trusted security management module also includes a trusted reporting function, which will alarm when an untrusted situation is found.
7. The trusted heterogeneous redundant dual-channel data security connection system as described in claim 6, characterized in that: The first unidirectional isolator (32) is a light gate type unidirectional isolator; the second unidirectional isolator (42) is an optoelectronic type unidirectional isolator; and the third unidirectional isolator (43) is a mechanical type unidirectional isolator. The trusted isolation buffer gateway (41) is equipped with a transmission link allocation module, which selects the data link of the second unidirectional isolator (42) or the third unidirectional isolator (43) according to the delay identifier and data size identifier of the received data. Data with small transmission volume and high delay requirement is sent to the second unidirectional isolator (42); data with large transmission volume and low delay requirement is sent to the third unidirectional isolator (43).
8. A reliable heterogeneous redundant dual-channel data secure connection method, characterized in that: The trusted heterogeneous redundant dual-channel data security connection system described in claim 7 is used to perform end-to-end trusted interconnection authentication and secure and reliable transmission of connection data. The specific steps are as follows: A. System Initialization Based on the operation and maintenance management subsystem, the sender external access subsystem (1), isolation switching subsystem (3), isolation buffer subsystem (4), and receiver external access subsystem (5) are initialized and configured in out-of-band mode, and the running status and data exchange behavior of each subsystem are monitored in real time, and task-level full-process log auditing is performed; the sender trusted computer (11), receiver trusted computer (51), first trusted data exchange gateway (31), trusted isolation buffer gateway (41), and second trusted data exchange gateway (44) are initialized with trusted status and generate their respective initial metric values; the sender trusted computer (11) sends its own authentication object information as the original authentication object information to the first trusted data exchange gateway (31), and the first trusted data exchange gateway (31) stores the received original authentication object information of the sender trusted computer (11) in the trusted root; the first trusted data exchange gateway (31) The first trusted data exchange gateway (31) sends its own authentication object information as the original authentication object information to the trusted isolation buffer gateway (41), and the trusted isolation buffer gateway (41) stores the received original authentication object information of the first trusted data exchange gateway (31) in the trusted root; the trusted isolation buffer gateway (41) sends its own authentication object information as the original authentication object information to the second trusted data exchange gateway (44), and the second trusted data exchange gateway (44) stores the received original authentication object information of the trusted isolation buffer gateway (41) in the trusted root; the second trusted data exchange gateway (44) sends its own authentication object information as the original authentication object information to the receiving trusted computer (51), and the receiving trusted computer (51) stores the received original authentication object information of the second trusted data exchange gateway (44) in the trusted root; B. End-to-End Trusted Interconnection Authentication The trusted data exchange module of the sending trusted computer (11) detects whether there is incoming data; when there is data to be incoming, the trusted computer (11) and the first trusted data exchange gateway (31), the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41), the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44), and the second trusted data exchange gateway (44) and the receiving trusted computer (51) initiate trusted interconnection authentication based on the trusted root, the process being as follows: B1. Trusted interconnection authentication between the sender trusted computer (11) and the first trusted data exchange gateway (31): The trusted security management module of the sender trusted computer (11) sends authentication object information to the trusted security management module of the first trusted data exchange gateway (31). The trusted security management module of the first trusted data exchange gateway (31) compares the received authentication object information of the sender trusted computer (11) with the original authentication object information of the sender trusted computer (11) stored in its trusted root. If the comparison fails, the trusted interconnection authentication stops and returns to step B. If the comparison passes, the sender trusted computer (11) establishes a communication connection with the first trusted data exchange gateway (31) and executes B2 to enable trusted interconnection authentication between the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41). B2. Trusted interconnection authentication between the first trusted data exchange gateway (31) and the trusted isolation buffer gateway (41): The trusted security management module of the first trusted data exchange gateway (31) sends authentication object information to the trusted security management module of the trusted isolation buffer gateway (41). The trusted security management module of the trusted isolation buffer gateway (41) receives the authentication object information of the first trusted data exchange gateway (31) and compares it with the original authentication object information of the first trusted data exchange gateway (31) stored in its trusted root. If the comparison fails, the trusted interconnection authentication is stopped and the process returns to step B; if the comparison passes, the first trusted data exchange gateway (31) establishes a communication connection with the trusted isolation buffer gateway (41) and executes step B3 to enable trusted interconnection authentication between the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44). B3. Trusted interconnection authentication between the trusted isolation buffer gateway (41) and the second trusted data exchange gateway (44): The trusted security management module of the trusted isolation buffer gateway (41) sends authentication object information to the trusted security management module of the second trusted data exchange gateway (44); The trusted security management module of the second trusted data exchange gateway (44) receives the authentication object information of the trusted isolation buffer gateway (41) and compares it with the original authentication object information of the trusted isolation buffer gateway (41) stored in its trusted root. If the comparison fails, the trusted interconnection authentication is stopped and the process returns to step B. If the comparison passes, the trusted isolation buffer gateway (41) establishes a communication connection with the second trusted data exchange gateway (44) and executes step B4 to enable trusted interconnection authentication between the second trusted data exchange gateway (44) and the trusted computer (51) of the receiving party. B4. Trusted interconnection authentication between the second trusted data exchange gateway (44) and the recipient trusted computer (51): The trusted security management module of the second trusted data exchange gateway (44) sends authentication object information to the trusted security management module of the recipient trusted computer (51); The trusted security management module of the receiving trusted computer (51) receives the authentication object information of the second trusted data exchange gateway (44) and compares it with the original authentication object information of the second trusted data exchange gateway (44) stored in its trusted root. If the comparison fails, the trusted interconnection authentication is stopped and the process returns to step B. If the comparison passes, the second trusted data exchange gateway (44) establishes a communication connection with the receiving trusted computer (51). C. The trusted security management module in the receiver's trusted computer (51) notifies the trusted data exchange module in the sender's trusted computer (11) via out-of-band that "trusted channel ready"; the trusted data exchange module in the sender's trusted computer (11) executes step D to send the incoming data; where out-of-band management refers to transmitting management information through an independent physical channel, separate from the data incoming channel; D. Receiving data for data communication D1. The trusted data exchange module configured in the sender's trusted computer (11) performs format checks and trusted identifier checks on the received data. If the format checks and trusted identifier checks fail, the received data is discarded and the process returns to step B. If the format checks and trusted identifier checks pass, the received data is processed according to the trusted measurement result of the trusted security management module configured in the sender's computer. When the trusted measurement result is trusted, the data is encrypted, protected for integrity, and protected with a digital signature. A trusted identifier, a delay identifier, and a data size identifier are added to form a special format. After passing through the security protection of the boundary protection subsystem (2), the data is sent to the trusted data exchange module configured in the first trusted data exchange gateway (31) and step D2 is executed. When the trusted measurement result is untrustworthy, the received data is discarded and the process returns to step B. D2. When the trusted data exchange module configured in the first trusted data exchange gateway (31) detects a data connection, it performs format checks and trusted identifier checks on the received data. If the format checks and trusted identifier checks fail, the received data is discarded and the process returns to step B. If the format checks and trusted identifier checks pass, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the data is encrypted, protected for integrity, and protected with digital signature. A trusted identifier, a delay identifier, and a data size identifier are added to form a special format and sent to the first unidirectional isolator (32). The first unidirectional isolator (32) encapsulates the received data with a private protocol and sends it to the trusted data exchange module configured in the trusted isolation buffer gateway (41). When the trusted measurement result is untrustworthy, the received data is discarded and the process returns to step B. D3. When the trusted data exchange module configured in the trusted isolation buffer gateway (41) detects a data connection, it performs format checks and trusted identifier checks on the received data. If the format checks and trusted identifier checks fail, the received data is discarded, and the process returns to step B. If the format checks and trusted identifier checks pass, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the data is encrypted, protected for integrity, and protected with a digital signature. A trusted identifier, a delay identifier, and a data size identifier are added to form a dedicated format, which is then sent to the transmission link allocation module configured in the subsystem. The allocation module selects data to send to the second unidirectional isolator (42) or the third unidirectional isolator (43) according to the delay identifier and data size identifier of the received data; data with small transmission volume and high delay requirements are sent to the second unidirectional isolator (42); data with large transmission volume and low delay requirements are sent to the third unidirectional isolator (43); the second unidirectional isolator (42) or the third unidirectional isolator (43) encapsulates the received data with a private protocol and sends it to the data trust exchange module configured in the second trusted data exchange gateway (44); when the trust measurement result is untrustworthy, the received data is discarded and the process returns to step B; D4. When the trusted data exchange module configured in the second trusted data exchange gateway (44) detects a data connection, it performs format checks and trusted identifier checks on the received data. If the format checks and trusted identifier checks fail, the received data is discarded and the process returns to step B. If the format checks and trusted identifier checks pass, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the data is encrypted, protected for integrity, and protected with a digital signature. A trusted identifier, a delay identifier, and a data size identifier are added to form a special format and sent to the trusted data exchange module configured in the trusted computer (51) of the receiving party. When the trusted measurement result is untrustworthy, the received data is discarded and the process returns to step B. D5. When the trusted data exchange module configured in the trusted computer (51) of the receiving party detects a data connection, it performs format checks and trusted identifier checks on the received data. If the format checks and trusted identifier checks fail, the received data is discarded and the process returns to step B. If the format checks and trusted identifier checks pass, the received data is processed according to the trusted measurement result of the trusted security management module of the subsystem. When the trusted measurement result is trusted, the received data undergoes integrity checks and digital signature verification. After the verification is successful, the received data is decrypted and restored to plaintext data, and the data connection communication is completed. When the trusted measurement result is untrustworthy, the received data is discarded and the process returns to step B.
Citation Information
Patent Citations
Domestic network security isolation and one-way import system and method
CN108449310A
An internal and external network isolation and data exchange device and method based on a unidirectional transmission physical medium
CN109698837A