Private network access system, information transmission method, storage medium and program product
By introducing Cato and private network security gateway into the information management system, using the DNN signing information and certificate verification of the national encryption card, and establishing a dedicated network transmission channel, the security risks in the information transmission process are resolved and the security and reliability of information are improved.
Patent Information
- Application Number
- CN202411945530.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-12-26
AI Technical Summary
The existing information management system has security risks during information transmission. Information may be leaked or tampered with, affecting the integrity and confidentiality of the information.
Cato and private network security gateway are introduced, and the DNN signing information of the national encryption card built into Cato is used to interact with the private network security gateway to establish a dedicated network transmission channel. The identity authentication information and certificate of the national encryption card are verified, and information transmission is allowed only when the verification result passes.
By building a triple protection system, we ensure that information is logically isolated from the external network during transmission, thereby improving the security and reliability of information transmission and reducing the risk of information leakage and tampering.
Smart Images

Figure CN119854057B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and particularly relates to a private network access system, an information transmission method, a storage medium and a program product. BACKGROUND
[0002] With the rapid development of communication technology, the demand for informatization management of relevant departments is increasing, especially in personnel management and material management. Among them, the information management system as an important government affair application is widely used in the management and maintenance of information of in-service personnel.
[0003] In the related art, the information management system usually adopts a client / server (C / S) architecture. Specifically, the client is deployed on the office computer of each grassroots organization, and the server is deployed in a centralized management place such as a provincial data center. When the personnel relationship of a source grassroots organization changes, the corresponding grassroots client, for example, client A, needs to synchronize the change information to the government intranet and extranet area and other related grassroots organizations. However, in the process of information transmission, there may be security risks, for example, the information may be at risk of being leaked or tampered with during transmission, which threatens the integrity and confidentiality of the information.
[0004] Therefore, it is urgent to provide a private network access scheme to improve the security of information transmission. SUMMARY
[0005] The present application provides a private network access system, an information transmission method, a storage medium and a program product to improve the security of information transmission.
[0006] In a first aspect, the present application provides a private network access system, comprising: a card holder and a private network security gateway, wherein:
[0007] The card holder is connected with a grassroots terminal where a grassroots client is located, and is configured to, when receiving an information transmission instruction of the grassroots client connected with the card holder, interact with the private network security gateway to establish a private network transmission channel based on the dedicated data network name (DNN) subscription information of the national secret card built-in in the card holder.
[0008] The private network security gateway is deployed in the government extranet area and is configured to check the national secret card based on a private network transmission channel to obtain a check result, wherein the check includes checking identity authentication information of the national secret card and checking a certificate of the national secret card; when the check result is passed, the private network security gateway forwards the target information to a front-end machine deployed in the government extranet area via the private network transmission channel, and the front-end machine is configured to manufacture an optical disc according to the target information, and migrate the target information to a server in the government intranet area via the optical disc, wherein the target information is sent by the basic client.
[0009] In a possible implementation, the private network access system further includes a user plane function (UPF) network element, and the private network security gateway is further configured to: when the check result is passed, determine a target Internet Protocol (IP) address included in the target information; if the target IP address is an IP address of the front-end machine, forward the target information to the front-end machine; and if the target IP address is an IP address of another basic terminal, forward the target information to the other basic client via the UPF network element.
[0010] In a possible implementation, the private network security gateway is further configured to store a routing table including network configurations of each basic terminal, and when the target IP address is the IP address of the other basic terminal, the private network security gateway forwards the target information to the other basic client via the UPF network element, including: when the target IP address is the IP address of the other basic terminal, determining routing information in the routing table that matches the IP address; and based on the routing information, forwarding the target information to the other basic client via the UPF network element.
[0011] In a possible implementation, the card tray is connected to the basic terminal where the basic client is located via a target interface, and the target interface includes a serial bus USB interface and a Type-C interface.
[0012] In a possible implementation, the card tray is further configured to: collect physical information of the basic terminal and physical information of the card tray, wherein the physical information includes a serial number and a media access control address; and compare the physical information of the basic terminal with the physical information of the card tray to determine whether the physical information of the basic terminal and the physical information of the card tray match.
[0013] In a possible implementation, before forwarding the target information to the front-end machine deployed in the government extranet area via the dedicated network transmission channel, the special network security gateway is further configured to: obtain the physical information of the target base-level terminal and the physical information of the target card holder corresponding to the target base-level terminal stored locally; if the physical information of the base-level terminal does not match the physical information of the target base-level terminal, and / or if the physical information of the card holder does not match the physical information of the target card holder, the information transmission via the target interface is restricted; if the physical information of the base-level terminal matches the physical information of the target base-level terminal, and the physical information of the card holder matches the physical information of the target card holder, the information transmission via the target interface is allowed.
[0014] In a second aspect, the embodiments of the present application provide an information transmission method, applied to the special network access system in any of the first aspect, the special network access system comprising a card holder and a special network security gateway, the information transmission method comprising:
[0015] The card holder responds to the information transmission instruction of the base-level client connected to the card holder, and interacts with the special network security gateway to establish a dedicated network transmission channel based on the DNN subscription information of the national secret card built-in in the card holder, and the card holder is connected to the base-level terminal where the base-level client is located.
[0016] The special network security gateway verifies the national secret card based on the dedicated network transmission channel to obtain a verification result, wherein the verification includes verifying the identity authentication information of the national secret card and verifying the certificate of the national secret card; when the verification result is passed, the special network security gateway forwards the target information to the front-end machine deployed in the government extranet area via the dedicated network transmission channel, and the front-end machine is configured to manufacture an optical disc according to the target information, and migrate the target information into the server in the government intranet area via the optical disc, wherein the target information is sent by the base-level client, and the special network security gateway is deployed in the government extranet area.
[0017] In a possible implementation, the special network access system further comprises a UPF network element, and the information transmission method further comprises: when the verification result is passed, the special network security gateway determines a target IP address contained in the target information; if the target IP address is the IP address of the front-end machine, the special network security gateway forwards the target information to the front-end machine; if the target IP address is the IP address of another base-level client, the special network security gateway forwards the target information to the other base-level client via the UPF network element.
[0018] In a third aspect, the present application provides a computer readable storage medium, the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed to implement the method in any of the second aspect.
[0019] In a fourth aspect, the present application provides a computer program product comprising a computer program, and the computer program is executed to implement the method in any of the second aspect.
[0020] The application provides a private network access system, an information transmission method, a storage medium and a program product. The system comprises a card tray and a private network security gateway. The card tray is connected with a basic terminal where a basic client is located. When an information transmission instruction of the basic client connected with the card tray is received, the card tray interacts with the private network security gateway to establish a private network transmission channel based on DNN subscription information of a national secret card built in the card tray. The private network security gateway is deployed in a government extranet area. The private network security gateway verifies the national secret card based on the private network transmission channel to obtain a verification result. The verification comprises verifying identity authentication information of the national secret card and verifying a certificate of the national secret card. When the verification result is passed, the private network security gateway forwards target information to a front-end machine deployed in the government extranet area through the private network transmission channel. The front-end machine is used to manufacture an optical disc according to the target information, and the target information is migrated into a server in a government intranet area through the optical disc. The target information is sent by the basic client. The application introduces the card tray and the private network security gateway, interacts with the private network security gateway to establish a private network transmission channel based on DNN subscription information of a national secret card built in the card tray, and verifies the identity authentication information and the certificate of the national secret card. Only when the verification result is passed, the target information is allowed to be transmitted through the private network transmission channel. The construction of the multiple protection system ensures that the target information is logically isolated from external networks during transmission and is always kept in the private network, thereby significantly improving the security and reliability of information transmission. BRIEF DESCRIPTION OF DRAWINGS
[0021] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.
[0022] Figure 1 An information transmission schematic diagram of an information management system in the related art;
[0023] Figure 2 A structure schematic diagram of the private network access system provided by the exemplary embodiments of the application;
[0024] Figure 3 An information transmission schematic diagram of the private network access system provided by the exemplary embodiments of the application;
[0025] Figure 4 A system architecture schematic diagram of the private network access system provided by the exemplary embodiments of the application;
[0026] Figure 5 A flowchart of the information transmission method provided by the exemplary embodiments of the application.
[0027] The present application has been shown and described with reference to the preferred embodiments. Equivalent mechanisms and methods can be used as substitutes for those described and illustrated. The application is not limited to the examples described herein, but can vary and modify these examples in many ways. The scope of the application is defined by the appended claims. DETAILED DESCRIPTION
[0028] The exemplary embodiments will be described in detail herein with reference to the accompanying drawings. The following description is presented with reference to the accompanying drawings, in which the same or similar elements are referred to with the same or similar reference numerals. The embodiments described in the following exemplary embodiments are not meant to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with some aspects of the present application as detailed in the appended claims.
[0029] The terms "first", "second", and the like, in the description and in the claims of this application, are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order. It is to be understood that the terms so used are interchangeable under appropriate circumstances such that the embodiments of the application described herein are capable of operation in other sequences than described or illustrated herein. Moreover, the terms "include", and "have", and any variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, system, product, or apparatus that comprises a list of elements is not necessarily limited to those elements but can include other elements not expressly listed or inherent to such process, method, system, product, or apparatus.
[0030] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards, and provide corresponding operation portal for user to choose authorization or refusal.
[0031] At present, 5G as a new generation of mobile communication technology has the characteristics of large bandwidth, low delay and wide connection, which has a wide range of uses in network coverage, mobile access and improving the governance ability of related departments. For example, based on the 5G network infrastructure of the operator, a 5G special network is built for the external network of the electronic government affairs of the related department, which can significantly improve the ubiquitous access capability and mobile access capability of the external network of the government affairs, and extend the coverage range of the external network of the government affairs, so as to meet the network access in the scenarios of mobile office, mobile law enforcement, emergency communication, remote access, Internet of Things sensing and special network integration.
[0032] In the related art, a certain information management system is a typical C / S architecture, in which the client (i.e., Client side) is deployed in the office computers of each grassroots organization, and the server (i.e., Server side) is deployed in, for example, a provincial data center. The system is mainly used to manage the information of in-service staff within the province. When the personnel relationship of the source grassroots organization changes, such as basic information update, transfer of organizational relationship within the province, transfer out of the province, or transfer in of organizational relationship outside the province, it is necessary to synchronize the change information to the server corresponding to the provincial organization (such as the provincial scheduling server) through its corresponding grassroots client, such as client A. At the same time, the change information also needs to be synchronized to the grassroots clients corresponding to other target grassroots organizations, such as client B. For example, Figure 1 Figure 1 is a schematic diagram of information transmission in an information management system in related technology. Figure 1 As shown, client A and client B are located in the Internet area, and the server is located in the government intranet area. Data transfer and exchange are all achieved through the government extranet area, where the government extranet area and the government intranet area are physically isolated by a one-way optical gate. Correspondingly, when the personnel relationship of the source grassroots organization changes, client A transmits the change information in plain text via the Internet to the data exchange area in the government extranet, and the account and password are signed and verified by the front-end machine, and then transmitted to the one-way optical gate to burn the change information; the burned CD is manually transported to the government intranet area, and the change information is migrated to the server in the government intranet area via the CD; when the server in the government intranet area completes the data update, the change information is burned again, and the burned CD is manually transported to the target grassroots organization, such as client B, to complete the information update of the target grassroots organization. However, since client A uses an account and password to log in and transmits the change information in plain text via the Internet, there is a great security risk. The information may be at risk of being leaked or tampered with during transmission, which poses a threat to the integrity and confidentiality of the information.
[0033] In order to solve the above problems, the embodiment of the present application provides a private network access solution. In order to reduce the security risks of plain text transmission on the Internet, in terms of private network security management, security authentication and data encryption technologies at the network transmission level and the data transmission level are introduced. By introducing customized card holders and private network security gateways, it is ensured that the target information is transmitted through a dedicated network transmission channel and is logically isolated from the external network during the transmission process, so that the authenticity, integrity and confidentiality of the target information are not affected, thereby significantly improving the security and reliability of information transmission.
[0034] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0035] Figure 2 A structural diagram of a private network access system provided by an exemplary embodiment of this application. Figure 2 As shown, the private network access system 20 includes: a card holder 21 and a private network security gateway 22; wherein:
[0036] Cato 21 is connected to the grassroots terminal where the grassroots client is located. It is used to interact with the private network security gateway to establish a dedicated network transmission channel based on the DNN signing information of the national encryption card built into Cato when receiving the information transmission instruction from the grassroots client connected to Cato.
[0037] For example, Figure 3 This is a schematic diagram of information transmission of a private network access system provided by an exemplary embodiment of this application. Figure 3 As shown, each grassroots terminal, such as the source grassroots computer and the target grassroots computer, is equipped with a card tray, which includes a communication module and a data transmission module. A national security card is inserted into the communication module, and this national security card is only used to sign up for the Organization Department's dedicated DNN. A private network security gateway is deployed in the government extranet area. Card trays include, but are not limited to, 5G card trays; national security cards include, but are not limited to, 5G national security subscriber identity modules (SIMs); and private network security gateways include, but are not limited to, 5G private network security gateways.
[0038] Accordingly, refer to Figure 3 When the personnel relationship of the source grassroots organization changes, its corresponding source grassroots client, such as client A, generates an information transmission instruction and sends the information transmission instruction to the communication module of Cato through the interface; after receiving the information transmission instruction, the communication module of Cato automatically reads the DNN signing information of the built-in national secret card, and communicates with the private network security gateway based on the read DNN signing information, and initiates a request to establish a dedicated network transmission channel to ensure the security and exclusivity of information transmission.
[0039] The private network security gateway 22 is deployed in the government extranet area and is used to verify the national secret card based on the private network transmission channel to obtain the verification result. The verification includes verifying the identity authentication information of the national secret card and verifying the certificate of the national secret card. When the verification result is passed, the target information is forwarded to the front-end machine deployed in the government extranet area via the private network transmission channel. The front-end machine is used to make a CD based on the target information, and migrate the target information to the server in the government intranet area via the CD. The target information is sent by the grassroots client.
[0040] For example, still refer to Figure 3The special network security gateway is deployed in the government extranet area and is responsible for ensuring the security and integrity of information transmission. The special network security gateway includes an authentication and authorization module (i.e., a DN-AAA module), a national secret encryption module, and a forwarding policy module. The DN-AAA module checks the identity authentication information of the national secret card, specifically including checking information such as MSISDN and IMSI. MSISDN is the telephone number of a mobile user, and IMSI is the international mobile subscriber identity, which are used to uniquely identify and verify the identity of a user. It is determined that only the national secret card that passes the secondary authentication is allowed to access network resources, thereby enhancing the security of the network. Secondly, the national secret encryption module checks the certificate pre-stored in the national secret card, and it is determined that only the national secret card that passes the two-way authentication is allowed to establish a national secret transport layer security (TLS) tunnel. When the check result is passed, the data transmission module of the card reader sends the change information in the source base computer through the communication module, and the forwarding policy module of the special network security gateway forwards the target information to the front-end machine deployed in the government extranet area. The front-end machine makes an optical disc according to the target information, and then migrates the target information into the server in the government intranet area through the optical disc by means of manual ferry.
[0041] The special network access system provided by the embodiments of the present application introduces a card reader and a special network security gateway, uses the DNN subscription information of the national secret card built-in the card reader to interact with the special network security gateway to establish a special network transmission channel, and checks the identity authentication information and certificate of the national secret card. Only when the check result is passed, the target information is allowed to be transmitted through the special network transmission channel. By constructing a triple protection system of "special network + secondary authentication + national secret encryption", it is ensured that the target information is logically isolated from the external network during transmission and always remains in the special network, thereby significantly improving the security and reliability of information transmission.
[0042] Considering that in the related art, due to the physical isolation of the government intranet and extranet, when the change information is transmitted from the client A to the server in the government intranet area, the last mile can only be completed by using the optical disc manual ferry method. However, when the change information is transmitted from the server to the client B, the method of using the optical disc manual ferry to transmit the change information to the target base organization has the problems of long period and high cost, which seriously affects the work efficiency. Therefore, in some embodiments, the special network access system further includes a UPF network element, and the special network security gateway is further configured to: when the check result is passed, determine that the target IP address contained in the target information; if the target IP address is the IP address of the front-end machine, forward the target information to the front-end machine; and if the target IP address is the IP address of the other base terminal, forward the target information to the other base client through the UPF network element.
[0043] For example, still referring to Figure 3In the government extranet data exchange area, a sinking and exclusive UPF network element is deployed. Correspondingly, when the check result is passed, the forwarding strategy module of the special network security gateway is activated, which judges according to the target IP address contained in the target information which route the personnel change information corresponding to the source grassroots client such as client A should be transmitted to: if the target IP address is the front-end machine in the government extranet area, the forwarding strategy module is directly passed, and the target information is directly forwarded to the front-end machine, and the front-end machine processes the target information according to the target information, such as making a CD for further transmission; if the target IP address is the IP address of other grassroots terminals, the forwarding strategy module does not store data, and the target information is forwarded to other grassroots clients such as client B through the UPF network element, and the UPF network element is responsible for efficiently routing and forwarding data packets in the special network transmission channel, and ensuring that the target information is accurately sent to the target grassroots client.
[0044] In the embodiments of the present application, when the change information is transmitted from the server to other grassroots clients, it is not necessary to pass through the manual ferry mode of the CD, but is directly forwarded to the target grassroots client corresponding to the target grassroots organization through the special network, which greatly improves the work efficiency and improves the problems of long information transmission period and high cost. In addition, by using the "special network + card" to access the government extranet area, the way that the grassroots terminal can only be fixedly accessed to the government extranet area through a network cable is improved, so that the demand of mobile office of the government industry can be better met.
[0045] On the basis of the above-mentioned embodiments, in some embodiments, the special network security gateway is also used to store a routing table containing network configurations of each grassroots terminal, and if the target IP address is the IP address of other grassroots terminals, the target information is forwarded to other grassroots clients through the UPF network element, including: if the target IP address is the IP address of other grassroots terminals, the routing information matched with the IP address in the routing table is determined; based on the routing information, the target information is forwarded to other grassroots clients through the UPF network element.
[0046] Exemplarily, the forwarding policy module of the private network security gateway further stores a routing table containing configurations of all base terminal networks, in which the intranet IP addresses of all base terminals and their corresponding routing information are recorded; when the private network security gateway receives target information, the forwarding policy module analyzes the target IP address contained in the target information; if the target IP address is the IP address of another base terminal, the forwarding policy module finds the routing information matching the target IP address in the routing table, and obtains the corresponding forwarding path based on the matching routing information, and further, based on the forwarding path addressing, forwards the target information to the other base client through the UPF network element. In addition, a suitable forwarding policy can also be preset in the forwarding policy module to support cross-provincial terminal intercommunication; correspondingly, after obtaining the corresponding forwarding path, the preset forwarding policy is applied to ensure that the information can be transmitted across provinces; the UPF network element is responsible for efficiently routing and forwarding data packets in the private network according to the routing information and the policy, ensuring that the information reaches the target client accurately regardless of its geographical location.
[0047] The embodiments of the present application ensure the security and efficiency of information transmission through the private network security gateway, and also realize cross-provincial terminal intercommunication through a suitable forwarding policy, thereby breaking the limitation of traditional UPF terminal intercommunication within the province and significantly improving the flexibility and practicality of the network.
[0048] In some embodiments, the card holder is connected to the base terminal where the base client is located through a target interface, and the target interface includes a serial bus USB interface and a Type-C interface.
[0049] The USB interface is a widely used interface standard that supports plug-and-play functionality, provides power and data transmission capabilities, and is suitable for most computing devices; the Type-C interface is a modern interface standard that supports higher data transmission rates, bidirectional power supply capabilities, and reversible insertion design.
[0050] Exemplarily, in one implementation, the connection between the card holder and the base terminal where the base client is located is realized through the USB interface, that is, the USB cable is inserted into the USB port of the card holder and the terminal.
[0051] In another implementation, the connection between the card holder and the base terminal where the base client is located is realized through the Type-C interface, that is, the Type-C cable is inserted into the Type-C port of the card holder and the terminal.
[0052] Correspondingly, after the card adapter is connected with the base terminal where the base client is located through the target interface, the operating system of the base terminal automatically recognizes the card adapter and loads necessary drivers to initialize the card adapter. After the card adapter is initialized, data transmission and identity authentication are performed to verify the legality of the base terminal device and the user, so as to ensure that only authorized devices and users can access network resources. Once the authentication is passed, the card adapter provides secure network access for the base terminal, and the base terminal can access network resources through the card adapter and perform data communication and business operations.
[0053] In the embodiments of the present application, the card adapter and the base terminal are connected through the USB and Type-C interfaces, which not only improves the compatibility and performance of the system, but also simplifies user operations and enhances the flexibility and adaptability of the device.
[0054] In some embodiments, the card adapter is also used to: collect physical information of the base terminal and physical information of the card adapter, the physical information including a serial number and a media access control address; and compare the physical information of the base terminal with the physical information of the card adapter to confirm whether the physical information of the base terminal matches the physical information of the card adapter.
[0055] For example, the card adapter also includes an interface management module (i.e., an APP module) that automatically collects information such as a serial number (S / N) and a media access control (MAC) address of the base terminal, and information such as an S / N and a MAC address of the card adapter; and compares the S / N and the MAC address of the base terminal with the S / N and the MAC address of the card adapter to check whether the S / N of the base terminal is consistent with the S / N of the card adapter and whether the MAC address of the base terminal is consistent with the MAC address of the card adapter. Correspondingly, if the S / N of the base terminal is consistent with the S / N of the card adapter and the MAC address of the base terminal is consistent with the MAC address of the card adapter, it is confirmed that the physical information of the base terminal matches the physical information of the card adapter, and the system can continue subsequent configuration or operation; if the S / N of the base terminal is inconsistent with the S / N of the card adapter and / or the MAC address of the base terminal is inconsistent with the MAC address of the card adapter, it is confirmed that the physical information of the base terminal does not match the physical information of the card adapter, and the system generates relevant alarm or prompt information to notify the user to further check and verify.
[0056] In the embodiments of the present application, by verifying the consistency of the physical information of the base terminal and the card adapter, the possibility of the card adapter being mixed with other terminals can be effectively reduced, which is particularly important for systems that require strict configuration management, and can prevent security risks, configuration errors or communication problems caused by information mismatch, thereby improving the security of the overall network.
[0057] In some embodiments, before forwarding the target information to the front-end machine deployed in the government extranet area through the special network transmission channel, the special network security gateway is further configured to: obtain the physical information of the target basic terminal and the physical information of the target card reader corresponding to the target basic terminal stored locally; if the physical information of the basic terminal does not match the physical information of the target basic terminal, and / or if the physical information of the card reader does not match the physical information of the target card reader, the information transmission through the target interface is restricted; if the physical information of the basic terminal matches the physical information of the target basic terminal, and the physical information of the card reader matches the physical information of the target card reader, the information transmission through the target interface is allowed.
[0058] For example, the special network security gateway further includes a binding verification module. Accordingly, before forwarding the target information to the front-end machine deployed in the government extranet area through the special network transmission channel, the binding verification module is further configured to obtain the physical information of the target basic terminal and the physical information of the target card reader corresponding to the target basic terminal stored locally; the binding verification module compares the physical information of the basic terminal uploaded by the interface management module of the card reader with the pre-stored physical information of the target basic terminal in the system, and compares the physical information of the card reader with the pre-stored physical information of the target card reader in the system. Accordingly, if the physical information of the basic terminal does not match the physical information of the target basic terminal, and / or if the physical information of the card reader does not match the physical information of the target card reader, the information transmission through the target interface is restricted, i.e. the information transmission through the U / C port such as the USB interface or the Type-C interface is restricted; if the physical information of the basic terminal matches the physical information of the target basic terminal, and the physical information of the card reader matches the physical information of the target card reader, the information transmission through the target interface is allowed, i.e. the information transmission through the U / C port such as the USB interface or the Type-C interface is allowed, so that the target information can be transmitted to the front-end machine through the target interface.
[0059] In the embodiments of the present application, by verifying the physical information of the basic terminal and the card reader, if it is detected that the physical information does not match, the information transmission is restricted, which helps to prevent sensitive information from being leaked through unauthorized devices, and ensures that only authorized devices can perform information transmission. Through this multi-level security verification mechanism combining the network transmission level, the data transmission level and the device management level, unauthorized devices can be effectively prevented from accessing the network, and the security and reliability in the information transmission process are significantly improved. In addition, through the automatic physical information verification process, the need for manual intervention is reduced, the operation efficiency is improved, and the risk of human error is reduced.
[0060] For example, Figure 4 The system architecture schematic diagram of the special network access system provided by the exemplary embodiments of the present application is shown in FIG. 1. Figure 4As shown, the source basic layer terminal such as the source basic layer computer is connected with the card holder A through the USB interface or the Type-C interface, and the target basic layer terminal such as the target basic layer computer is connected with the card holder B through the USB interface or the Type-C interface; the card holder A and the card holder B both include an interface management module (i.e., an APP module), a 5G module module, and a data transmission module, wherein the 5G module module is an example of a communication module module; the private network security gateway such as the 5G private network security gateway includes a forwarding policy module, an authentication and authorization module (i.e., a DN-AAA module), a national secret encryption module, and a binding verification module.
[0061] Correspondingly, when the personnel relationship of the source basic layer organization changes, the source basic layer computer corresponding source basic layer client such as client A generates information transmission instructions, and sends the information transmission instructions to the 5G module module of the card holder through the USB interface or the Type-C interface; after receiving the information transmission instructions, the 5G module module of the card holder automatically reads the DNN subscription information of the built-in national secret card, and communicates with the private network security gateway based on the read DNN subscription information to initiate a request to establish a private network transmission channel, to ensure the security and privacy of information transmission. Further, the DN-AAA module verifies the identity authentication information of the national secret card, specifically including the verification of MSISDN and IMSI information, and determines that only the national secret card that passes the secondary authentication is allowed to access network resources; the national secret encryption module verifies the certificate preloaded in the national secret card, and determines that only the national secret card that passes the two-way authentication is allowed to establish an encrypted tunnel such as a national secret TLS tunnel; and when the verification result is passed, the data transmission module of the card holder A sends the target information (such as the changed personnel information) in the source basic layer computer through the 5G communication module module, and the forwarding policy module of the private network security gateway is activated, which determines which route the personnel change information of the source basic layer client such as client A should be transmitted to according to the target IP address contained in the target information; if the target IP address is the front-end machine in the government external network area, the forwarding policy module directly passes through, and directly forwards the target information to the front-end machine, which processes the target information accordingly, such as making a CD for further transmission; if the target IP address is the IP address of the other basic layer computer, the forwarding policy module does not store data, and forwards the target information to the other basic layer client such as client B through the UPF network element, which is responsible for efficiently routing and forwarding data packets in the private network transmission channel, to ensure that the target information is accurately sent to the target basic layer client.
[0062] It should be noted that, Figure 4 The source basic layer computer and the target basic layer computer in the above are only an example of the basic layer terminal, and the number of source basic layer computers and the number of target basic layer computers can both be multiple, which is not limited here.
[0063] The above embodiments introduce the implementation mode of the private network access system, and next, the application in information transmission is introduced through specific embodiments.
[0064] Figure 5 A flowchart of an information transmission method provided by an example embodiment of the present application. The information transmission method provided by the embodiment of the present application is applied to the private network access system in the above embodiments, and the private network access system includes a card holder and a private network security gateway. As shown in the figure, Figure 5 The information transmission method includes the following steps.
[0065] S501, the card holder responds to the information transmission instruction of the basic level client connected to the card holder, interacts with the private network security gateway based on the DNN subscription information of the national secret card built-in in the card holder to establish a private network transmission channel, and the card holder is connected to the basic level terminal where the basic level client is located.
[0066] For example, the card holder and the basic level terminal where the basic level client is located are connected through a target interface, and the target interface includes a serial bus USB interface and a Type-C interface. Correspondingly, when the personnel relationship of the source basic level organization changes, the corresponding source basic level client, for example, client A, generates an information transmission instruction and sends the information transmission instruction to the communication module of the card holder through the interface; after receiving the information transmission instruction, the communication module of the card holder automatically reads the DNN subscription information of the built-in national secret card, and communicates with the private network security gateway based on the read DNN subscription information, initiates a request to establish a private network transmission channel, to ensure the security and privacy of information transmission.
[0067] S501, the private network security gateway verifies the national secret card based on the private network transmission channel to obtain a verification result, and the verification includes verifying the identity authentication information of the national secret card and verifying the certificate of the national secret card; when the verification result is passed, the target information is forwarded to the front-end machine deployed in the government external network area through the private network transmission channel, and the front-end machine is used to make an optical disc according to the target information, and the target information is migrated into the server in the government internal network area through the optical disc, the target information is sent by the basic level client, and the private network security gateway is deployed in the government external network area.
[0068] The special network security gateway comprises an authentication and authorization module (i.e., a DN-AAA module), a national secret encryption module, and a forwarding strategy module. The DN-AAA module checks the identity authentication information of the national secret card, specifically including the checking of MSISDN and IMSI information, and determines that only the national secret card that passes the secondary authentication is allowed to access network resources, thereby enhancing the security of the network. Secondly, the national secret encryption module checks the pre-stored certificate in the national secret card, and determines that only the national secret card that passes the two-way authentication is allowed to establish a national secret TLS tunnel. When the checking result is passed, the data transmission module of the card sends the change information in the source base computer through the communication module, and the forwarding strategy module of the special network security gateway forwards the target information to the front-end machine deployed in the government external network area. The front-end machine produces an optical disc according to the target information, and then migrates the target information into the server in the government internal network area through the optical disc by means of manual ferry.
[0069] On the basis of the above-mentioned embodiments, in some embodiments, the special network access system further comprises a UPF network element, and the information transmission method further comprises: when the checking result is passed, the special network security gateway determines that the target IP address contained in the target information; if the target IP address is the IP address of the front-end machine, the special network security gateway forwards the target information to the front-end machine; if the target IP address is the IP address of another base client, the special network security gateway forwards the target information to the other base client through the UPF network element.
[0070] For example, the special network security gateway further comprises a forwarding strategy module, which stores a routing table containing the network configurations of all base terminals. The routing table records the internal network IP addresses of all base terminals and the corresponding routing information. When the checking result is passed, the forwarding strategy module of the special network security gateway is activated. The forwarding strategy module analyzes the target IP address contained in the target information. If the target IP address is the IP address of another base terminal, the forwarding strategy module finds the matching routing information in the routing table, and obtains the corresponding forwarding path based on the matching routing information. Further, based on the forwarding path, the target information is forwarded to the other base client through the UPF network element. If the target IP address is the front-end machine in the government external network area, the forwarding strategy module directly passes through and forwards the target information to the front-end machine. The front-end machine processes the target information accordingly, such as producing an optical disc for further transmission. In addition, appropriate forwarding strategies can be pre-stored in the forwarding strategy module to support cross-provincial terminal visits. Correspondingly, after obtaining the corresponding forwarding path, the forwarding strategy module can also forward the target information to other cross-provincial base terminals through the UPF network element according to the pre-stored forwarding strategies.
[0071] In summary, the present application has at least the following advantages:
[0072] I. By introducing the card holder and the special network security gateway, the DNN subscription information of the built-in national secret card in the card holder is used to interact with the special network security gateway to establish a special network transmission channel, and the identity authentication information and certificate of the national secret card are checked. Only when the checking result is passed, the target information is allowed to be transmitted through the special network transmission channel. By constructing a three-protection system of "special network + secondary authentication + national secret encryption", the target information is logically isolated from the external network during transmission and always remains in the special network, thereby significantly improving the security and reliability of information transmission.
[0073] II. When the change information is transmitted from the server to other grassroots clients, it is not necessary to pass through the optical disc manual ferry way, but is directly forwarded to the target grassroots client corresponding to the target grassroots organization through the special network, which greatly improves the work efficiency and solves the problems of long information transmission period and high cost. In addition, by using "special network + card holder" to access the government external network area, the way of fixed access to the government external network area through network cable for grassroots terminals is improved, so that the demand for mobile office of the government industry can be better met.
[0074] III. By introducing the card holder and the special network security gateway, the secondary authentication, national secret authentication encryption and card machine binding verification and other multiple authentication processes are integrated, and appropriate forwarding strategies are preset, so as to realize the mutual visit between grassroots terminals. This scheme breaks through the limitation of UPF terminal mutual visit function within the province, and realizes the cross-provincial mutual visit capability.
[0075] The embodiment of the application also provides a computer readable storage medium, and the computer readable storage medium stores computer execution instructions. When the computer execution instructions are executed, the computer execution instructions are used to implement the method steps in the method embodiment described above. The specific implementation manner and technical effects are similar, and will not be described here.
[0076] The computer readable storage medium described above can be realized by any type of volatile or nonvolatile storage devices or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read only memory (EEPROM), erasable programmable read only memory (EPROM), programmable read only memory (PROM), read only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special purpose computer.
[0077] An exemplary readable storage medium is coupled to the processor, thereby enabling the processor to read information from the readable storage medium and to write information to the readable storage medium. Of course, the readable storage medium can also be part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit. Of course, the processor and the readable storage medium can also exist as discrete components in the special network access system.
[0078] The embodiments of the present application also provide a computer program product, comprising a computer program, when the computer program is executed, realizing the method steps in the above method embodiments, the specific implementation manners and technical effects are similar, and thus will not be described here.
[0079] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The foregoing program can be stored in a computer readable storage medium. The program, when executed, executes the steps of the above-mentioned method embodiments; and the foregoing storage medium includes: ROM, RAM, magnetic or optical disk and various other media capable of storing program codes.
[0080] Finally, it should be noted that: those skilled in the art will easily conceive other embodiments of the present application after considering the specification and practicing the application disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application that follow the general principles of the present application and include known or customary technical means in the art that are not disclosed in the present application, and is not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the present application is only limited by the appended claims.
Claims
1. A private network access system, characterized in that: include: Cato and private network security gateway, including: The card holder is connected to the grassroots terminal where the grassroots client is located, and is used to interact with the private network security gateway to establish a dedicated network transmission channel based on the dedicated data network name DNN contract information of the national secret card built into the card holder when receiving the information transmission instruction of the grassroots client connected to the card holder; The private network security gateway is deployed in the government extranet area and is used to verify the national security card based on the private network transmission channel to obtain a verification result. The verification includes verifying the identity authentication information of the national security card and verifying the certificate of the national security card. When the verification result is passed, the target information is forwarded to the front-end machine deployed in the government extranet area via the private network transmission channel. The front-end machine is used to produce a CD based on the target information, and migrate the target information to the server in the government intranet area via the CD. The target information is sent by the grassroots client.
2. The private network access system according to claim 1, characterized in that: The private network access system further includes a user plane function UPF network element, and the private network security gateway is further configured to: When the verification result is passed, determining a target Internet Protocol (IP) address included in the target information; If the target IP address is the IP address of the front-end processor, the target information is forwarded to the front-end processor; If the target IP address is the IP address of another grassroots terminal, the target information is forwarded to the other grassroots client via the UPF network element.
3. The private network access system according to claim 2, characterized in that: The private network security gateway is further configured to store a routing table containing network configurations of each grassroots terminal, and if the target IP address is the IP address of another grassroots terminal, forwarding the target information to the other grassroots client via the UPF network element includes: If the target IP address is the IP address of another grassroots terminal, determining routing information matching the IP address in the routing table; Based on the routing information, the target information is forwarded to other grassroots clients via the UPF network element.
4. The private network access system according to claim 1 or 2, characterized in that: The card tray is connected to the grassroots terminal where the grassroots client is located through a target interface, and the target interface includes a serial bus USB interface and a Type-C interface.
5. The private network access system according to claim 4, characterized in that: The card holder is also used for: Collecting physical information of the grassroots terminal and the physical information of the card tray, wherein the physical information includes a serial number and a media access control address; The physical information of the base terminal and the physical information of the card tray are compared to confirm whether the physical information of the base terminal and the physical information of the card tray match.
6. The private network access system according to claim 5, characterized in that: Before forwarding the target information to the front-end processor deployed in the government extranet area via the dedicated network transmission channel, the dedicated network security gateway is further used to: Obtaining locally stored physical information of the target grassroots terminal and physical information of the target card tray corresponding to the target grassroots terminal; If the physical information of the base terminal does not match the physical information of the target base terminal, and / or if the physical information of the card tray does not match the physical information of the target card tray, restricting information transmission through the target interface; If the physical information of the base terminal matches the physical information of the target base terminal, and the physical information of the card tray matches the physical information of the target card tray, information transmission through the target interface is allowed.
7. An information transmission method, characterized in that: The private network access system applied to any one of claims 1 to 6, the private network access system comprising a card holder and a private network security gateway, the information transmission method comprising: The Cato responds to the information transmission instruction of the grassroots client connected to the Cato, and based on the dedicated data network name contract information of the national encryption card built into the Cato, interacts with the private network security gateway to establish a dedicated network transmission channel, and the Cato is connected to the grassroots terminal where the grassroots client is located; The private network security gateway verifies the national secret card based on the private network transmission channel and obtains a verification result. The verification includes verifying the identity authentication information of the national secret card and verifying the certificate of the national secret card. When the verification result is passed, the target information is forwarded to the front-end processor deployed in the government extranet area via the private network transmission channel. The front-end processor is used to produce a CD based on the target information, and migrate the target information to the server in the government intranet area via the CD. The target information is sent by the grassroots client, and the private network security gateway is deployed in the government extranet area.
8. The information transmission method according to claim 7, characterized in that: The private network access system further includes a user plane function UPF network element, and the information transmission method further includes: The private network security gateway determines the target Internet Protocol IP address included in the target information when the verification result is passed; If the target IP address is the IP address of the front-end processor, the private network security gateway forwards the target information to the front-end processor; If the target IP address is the IP address of another grassroots client, the private network security gateway forwards the target information to the other grassroots client via the UPF network element.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to claim 7 or 8 when executed.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed, the method according to claim 7 or 8 is implemented.
Citation Information
Patent Citations
Communication method, communication device, electronic equipment and readable storage medium
CN116234057A
Security authentication method, device, equipment, medium and product
CN118828495A