A communication system and device applied in network security
By integrating optical cable data protection units in the network security communication system, using armored and fiber attenuation detection modules, combined with dynamic IP and hardware encryption, the problem of lack of security protection in optical cable data transmission is solved, real-time monitoring and protection of optical cable data is achieved, and network security is improved.
Patent Information
- Application Number
- CN202510407067.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-04-02
AI Technical Summary
In the current network communication system, optical cables lack effective security protection during data transmission, resulting in data theft behavior being more secretive and difficult to detect.
A communication system applied in network security is designed. By integrating optical cable data protection unit on the server side, the optical cable is remotely monitored by using armored protection detection module and optical fiber attenuation detection module, and combining dynamic IP simulation module and hardware encryption engine to achieve real-time protection of optical cable data.
Effectively monitor and protect optical cable data, improve network security, be able to detect data theft in a timely manner, and prevent data leakage by encrypting or cutting off communications.
Smart Images

Figure CN119906592B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of communication systems, and particularly to a communication system and device applied to network security. Background Art
[0002] With the progress and maturity of network technology, people's production and life increasingly rely on the network. However, this means that people increasingly rely on the network to store and transmit important data, which poses higher requirements for network security.
[0003] Network data transmission mainly relies on communication systems. Therefore, in modern network security services, it is required that communication systems have high network security protection performance. The current network communication system architecture is mainly composed of terminal devices, routers, switches, optical cables, and servers, which are built step by step.
[0004] Regarding the architecture of the network communication system, it can be found that the current network data protection is more based on communication encryption protection of the upper-level server and terminal data protection of users. The protection of the upper-level server is mainly based on physical protection means such as firewalls, intrusion prevention systems, and cabinets, while terminal data protection can rely on firewalls and anti-intrusion software. At the same time, the interaction time with users is relatively long, and it can be better protected and monitored, so the security is relatively good.
[0005] Although the data protection of communication servers and terminals has good protection performance, the optical cables used as intermediate transmission for data exchange often have no security defense measures. This makes it a new and more concealed data theft means to steal data through optical cables during the transmission of communication data. Specifically, there are reports that 'SubCom company has deployed monitoring devices on global submarine optical cables'. Therefore, how to protect optical cables from being stolen of data is an important development trend in future network security.
[0006] Based on the above, protecting network data security not only requires protecting network servers and personal terminals, but also protecting optical cables used for transmission. The current optical cable data theft means are mainly divided into accessing the optical cable to split optical signals through external leads, and peeling the optical cable to expose the optical fiber to collect leaked optical signals. At present, the monitoring and protection of optical cable data transmission mainly use the attenuation of optical cable signals as the detection means, and the means are relatively single. The deformation and bending of optical cables are also likely to cause attenuation of optical cable signals, so the detection is prone to errors, and usually does not have subsequent disposal functions, which is likely to cause data theft. In view of this, in-depth research on the above problems has led to the generation of this case. Summary of the Invention
[0007] In view of the deficiencies of the prior art, the present invention provides a communication system and device applied in network security, which solves the problems of the existing background technology.
[0008] To achieve the above objectives, the present invention is realized through the following technical solutions: A communication system applied in network security includes terminal devices, network relay devices, communication optical cables, and servers;
[0009] The terminal device is a host computer, and a firewall and an intrusion prevention system are provided on the terminal device;
[0010] The network relay device includes a switch and a router, and the switch and the router are used for electrical (optical) signal forwarding;
[0011] The communication optical cable connects the network relay device and the server for optical signal transmission;
[0012] The server plays the roles of data protocol conversion, data storage, and network management;
[0013] On one side of the server, an encrypted communication tunnel is established based on the VPN access control module, and a data encryption module and an access control module are set;
[0014] On one side of the server, an optical cable data protection unit is also provided. The optical cable data protection unit is connected to the communication optical cable. The optical cable data protection unit performs data protection detection on the communication optical cable. The optical cable data protection unit is composed of an armored protection detection module, an optical fiber attenuation detection module, and a data protection module;
[0015] The armored protection detection module performs on-off detection by transmitting ultrasonic signals through the armored layer of the communication optical cable, and transmits the detection data to the data protection module;
[0016] The optical fiber attenuation detection module performs optical cable communication data protection by detecting the signal attenuation data of the communication optical cable, and transmits the detection data to the data protection module;
[0017] The data protection module is equipped with a dynamic IP simulation module and a hardware encryption engine. The data protection module analyzes the armored layer on-off data and the optical fiber attenuation data, and starts the dynamic IP simulation module and the hardware encryption engine according to the analysis results.
[0018] The verification method of the VPN access control module is one or more of the following methods: mobile phone verification code login, username and password login, fingerprint authentication, and face recognition authentication.
[0019] The server is equipped with a firewall, an intrusion prevention system, and a security information and event management system.
[0020] A communication device applied in network security, including a server cabinet, on one side of the server cabinet there is a connection port for installing a communication optical cable, and an optical cable data protection unit is arranged on the connection port for monitoring the communication optical cable;
[0021] The optical cable data protection unit includes an integrated box body, which is a cavity shell with a rectangular structure. The two sides of the integrated box body are connected to the server cabinet by bolts, and a detection and protection mechanism is arranged at the bottom of the integrated box body and connected to the communication optical cable;
[0022] The detection and protection mechanism is composed of an optical fiber attenuation detection module and an armored protection detection module;
[0023] A data protection module is arranged in the integrated box body and connected to the server in the server cabinet;
[0024] An accompanying detection optical fiber is arranged in the communication optical cable and an armored layer is wrapped outside the optical fiber; the optical fiber attenuation detection module is based on the accompanying detection optical fiber for the optical signal attenuation of the optical fiber; the armored protection detection module is installed based on the armored layer of the communication optical cable;
[0025] The armored protection detection module is composed of a positioning and installation component wrapped outside the communication optical cable, a signal transceiver installed on the positioning and installation component, and a detection and control component connecting the signal transceiver and the positioning and installation component. The positioning and installation component is installed outside the communication optical cable to provide an installation space for the detection and control component, and the detection and control component connects the signal transceiver to the armored layer of the communication optical cable;
[0026] The signal transceiver is powered by the integrated box body, the signal transceiver is based on a relay, and the detection end of the signal transceiver is connected to the detection and control component and connected to the armored layer of the communication optical cable;
[0027] The optical fiber attenuation detection module includes an optical power meter, a positioning and clamping groove, and a data transmitter;
[0028] The data protection module includes a data conversion interface, which is respectively connected to the signal transceiver and the data transmitter. A protection controller is connected to the data conversion interface. A dynamic IP simulation module and a hardware encryption engine are carried on the protection controller. The data conversion interface receives the detection signals transmitted by the signal transceiver and the data transmitter. The protection controller controls the dynamic IP simulation module and the hardware encryption engine to work according to the detection signals, and the dynamic IP simulation module and the hardware encryption engine are connected to the server.
[0029] The positioning and installation component includes a wrapping ring sleeve, which is composed of a pair of semi-circular positioning ring pipes. One side of the pair of positioning ring pipes is connected by a hinge, and a connector is arranged on the corresponding side of the pair of positioning ring pipes. The connector connects and fixes the pair of positioning ring pipes;
[0030] The connector includes a pressing rod, which is movably installed on one positioning ring pipe. An anti-pulling sleeve is arranged on the corresponding other positioning ring pipe. A locking sleeve is sleeved outside the pressing rod. A through groove is formed on the anti-pulling sleeve. The through groove matches the diameter of the pressing rod. A limiting groove is arranged on the through groove, and the limiting groove cooperates with the anti-pulling sleeve;
[0031] Two pairs of sealing rubber rings are arranged at both ends of the pair of positioning ring pipes. The two pairs of sealing rubber rings adopt an inflatable structure to wrap the outer skin of the communication cable.
[0032] The detection and control component includes a fixed seat. One side of one positioning ring pipe extends out of the fixed seat. A telescopic channel is arranged on the fixed seat. The fixed seat is connected to the integrated box body. A telescopic controller is arranged inside the integrated box body. The bottom of the telescopic controller is connected with a telescopic control rod. The telescopic control rod penetrates through the fixed seat and contacts the armored layer. The telescopic control rod is connected to the detection end;
[0033] The telescopic controller includes a control motor. A driving gear is arranged at the driving end of the control motor. A driving rack is meshed on one side of the driving gear. The driving rack is connected with the telescopic control rod. A reverse pushing spring is sleeved outside the telescopic control rod. A one-way ratchet is arranged on the inner shaft of the driving gear. A driving roller is sleeved on the driving end of the control motor. A one-way ratchet tooth is arranged on one side of the driving roller. The one-way ratchet tooth is meshed with the one-way ratchet.
[0034] The accompanying detection optical fiber is coaxially arranged with the optical fiber in the communication optical cable. The armored layer is a GYTA type or GYTS type armored layer.
[0035] One end of the accompanying detection optical fiber is connected with a light source. The optical power meter calculates the optical power and the optical signal wavelength after the transmission of the accompanying detection optical fiber, calculates the optical power attenuation efficiency according to the wavelength, and then compares it with the actual detected optical power.
[0036] One end of the data protection module penetrates out of the integrated box body. A plurality of data interfaces are arranged outside the data protection module. The plurality of data interfaces are connected with the server through network cables;
[0037] The integrated box body is a cavity shell with a rectangular structure. A power adapter is arranged on one side of the integrated box body. The power adapter is connected with the server. A control cover plate is arranged on one side of the integrated box body. The control cover plate is detachably connected with the integrated box body.
[0038] Beneficial effects
[0039] The present invention provides a communication system and device applied in network security. It has the following beneficial effects: adopting a highly integrated structure, in addition to setting up firewalls and intrusion prevention systems on terminal devices and servers, an optical cable data protection unit is integrated on the server side. The optical cable data protection unit is used to remotely monitor the optical cable to avoid data theft. In response to the current means of stealing optical cable data, relying on the on-off status of the optical cable and the attenuation of the optical fiber signal to detect whether the optical cable data has been stolen, and then protecting the optical cable data through a protection structure, thereby improving network security. Specifically, it also includes the following advantages;
[0040] 1. By connecting the optical cable data protection unit to the server, the detection data of the optical cable data protection unit can be monitored on the server side, which is convenient for quantifying and controlling the protection effect of the optical cable data;
[0041] 2. The detection means of the optical cable data protection unit are divided into long-distance on-off detection relying on the armored layer as a conductor and attenuation data monitoring based on the attenuation of the optical cable signal, which can effectively monitor the common means of stealing optical cable data and timely detect data theft behavior;
[0042] 3. A data protection module is set in the optical cable data protection unit. According to the firewall and other protection means carried by itself, after the optical cable is stolen, the data protection module encrypts or cuts off the communication data through dynamic IP and encryption operations, effectively protecting the communication data;
[0043] 4. The optical cable data protection unit adopts an independently set installation structure, with an integrated box body as the main body close to the communication optical cable for installation. While having a simple structure and high integration, the requirement for modifying the existing server structure is low, which is more convenient for deployment, disassembly and assembly. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a system block diagram of a communication system applied in network security according to the present invention.
[0045] Figure 2 It is a first three-dimensional structure schematic diagram of a communication device applied in network security according to the present invention.
[0046] Figure 3 It is a second three-dimensional structure schematic diagram of a communication device applied in network security according to the present invention.
[0047] Figure 4 It is a front view structure schematic diagram of a communication device applied in network security according to the present invention.
[0048] Figure 5The third three-dimensional structure diagram of a communication device applied in network security according to the present invention.
[0049] Figure 6 The sectional three-dimensional structure diagram of a communication device applied in network security according to the present invention.
[0050] Figure 7 The fourth three-dimensional structure diagram of a communication device applied in network security according to the present invention.
[0051] Figure 8 The front sectional structure diagram of a communication device applied in network security according to the present invention.
[0052] Figure 9 The partial sectional structure diagram of a communication device applied in network security according to the present invention.
[0053] Figure 10 The three-dimensional structure diagram of the positioning and installation component of a communication device applied in network security according to the present invention.
[0054] Figure 11 The side sectional structure diagram of a communication device applied in network security according to the present invention.
[0055] Figure 12 A communication device applied in network security according to the present invention Figure 8 The partial enlarged diagram at position A in.
[0056] Figure 13 The schematic diagram of the optical cable data protection unit system of a communication system and device applied in network security according to the present invention.
[0057] In the figure: 1, server cabinet; 2, communication optical cable; 3, integrated box body; 4, optical fiber attenuation detection module; 5, armored protection detection module; 6, data protection module; 21, armored layer; 22, accompanying detection optical fiber; 31, power adapter; 32, control cover plate; 33, electrical controller; 41, optical power meter; 42, positioning card slot; 43, data transmitter; 51, positioning and installation component; 52, signal transceiver; 53, detection control component; 54, horizontal adjustment component; 61, data conversion interface; 62, protection controller; 63, data interface; 511, positioning ring tube; 512, hinge; 513, connector; 514, sealing rubber ring; 531, fixed seat; 532, telescopic channel; 533, telescopic controller; 534, telescopic control rod; 541, rotating ring groove; 542, rotating plate; 543, horizontal track; 544, sliding seat; 545, guiding lead screw; 546, rotating ring; 5131, pressing rod; 5132, anti-pulling sleeve; 5133, locking sleeve; 5134, through slot; 5135, limiting slot; 5331, control motor; 5332, driving gear; 5333, driving rack; 5334, anti-pushing spring; 5335, one-way ratchet; 5336, driving roller; 5337, one-way ratchet tooth. Detailed implementation manner
[0058] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0059] Please refer to Figure 1-13 , the present invention provides an implementation solution: In modern communication systems, firewalls and intrusion prevention systems based on clients can effectively protect the security of network data. Firewalls and intrusion prevention systems can also be installed on the server side. Therefore, it is relatively easy for network data to be intercepted and cracked only during the transmission process. At present, the transmission of network data mainly relies on optical cable devices. Therefore, many measures for stealing data from optical cables have emerged at present. How to protect the transmission of network security data is an urgent problem to be solved.
[0060] Example 1: To solve the above problems, according to the attached drawings of the specification Figure 1It can be seen that the present application discloses a communication system applied in network security, including a terminal device, a network relay device, a communication optical cable, and a server; in the specific implementation process, the terminal device is responsible for human-computer interaction work, and the data generated during the use of the terminal device is converted by the network relay device, and then the data is sent to the server through the communication optical cable. The server stores and processes the data uploaded by the terminal device, and then sends it back to the network relay device through the communication optical cable, and then the network relay device distributes the data to the terminal device. In this process, in order to protect the network security of the data, network protection measures need to be set on each level of network device, specifically as follows;
[0061] The terminal device is a host computer, and the host computer is a device such as a mobile phone or a computer, which is mainly responsible for human-computer interaction and the sending and receiving of client data. A firewall and an intrusion prevention system are set on the terminal device;
[0062] The network relay device includes a switch and a router. The network relay device is set in a large computer room or at home, and is used to integrate and collect data, and the switch and the router are used for the forwarding of electrical (optical) signals;
[0063] The communication optical cable connects the network relay device and the server for optical signal transmission. The switch converts electronic data into optical signals and uses the high-speed characteristics of the optical fiber to complete data interaction with the server;
[0064] The server is the data processing center and storage center of the communication system. Specifically, the server plays the role of data protocol conversion, data storage, and network management. The data uploaded by the terminal device is processed and stored by the server, and then the processed data is sent back to the terminal device in the form of optical signals to complete the network service. Furthermore, in order to protect the security of the server, a firewall, an intrusion prevention system, and a security information and event management system are installed on the server. On one side of the server, an encrypted communication tunnel is established based on the VPN access control module, and a data encryption module and an access control module are set. The verification method of the VPN access control module is one or more of the following methods: mobile phone verification code login, username and password login, fingerprint authentication, and face recognition authentication.
[0065] In view of the problem that there is no protection means during the data transmission process of the optical cable in the current network security, in order to protect the data security, a fiber optic cable data protection unit is also set on one side of the server. The fiber optic cable data protection unit is connected to the communication optical cable, and the fiber optic cable data protection unit separately performs fiber optic signal attenuation detection and on-off detection on the communication optical cable, and encrypts the server data;
[0066] The fiber optic cable data protection unit is composed of an armored protection detection module, a fiber optic attenuation detection module, and a data protection module;
[0067] The armored protection detection module uses the armored layer of the communication optical cable to transmit ultrasonic signals for on-off detection and transmits the detection data to the data protection module;
[0068] The optical fiber attenuation detection module protects the optical cable communication data by detecting the signal attenuation data of the communication optical cable and transmits the detection data to the data protection module;
[0069] The data protection module is equipped with a dynamic IP simulation module and a hardware encryption engine. The data protection module analyzes the on-off data of the armored layer and the optical fiber attenuation data, and starts the dynamic IP simulation module and the hardware encryption engine according to the analysis results.
[0070] Embodiment 2: To solve the above problems, according to the appended Figure 2 - appended Figure 13 As can be seen, in order to cooperate with the application of the above system, the present application also discloses a communication device applied in network security, including a server cabinet 1. The communication device is installed based on the server cabinet 1. The server cabinet 1 integrates a server and various necessary security devices for the server. A connection port is provided on one side of the server cabinet 1. The connection port is used to install a communication optical cable 2. The communication optical cable 2 is connected to the server and plays a role in transmitting optical signals. Furthermore, an optical cable data protection unit is provided on the connection port to monitor and protect the communication optical cable 2;
[0071] According to the appended Figure 2 - appended Figure 5 As can be seen, the above optical cable data protection unit includes an integrated box body 3. The integrated box body 3 is a hollow shell with a rectangular structure. The integrated box body 3 serves as the main airborne box body for installing the optical cable data protection unit. The integrated box body 3 itself is made of plastic lined with aluminum alloy. Both sides of the integrated box body 3 are connected to the server cabinet 1 by bolts, which is convenient for disassembly, installation and maintenance;
[0072] Furthermore, the integrated box body 3 is a hollow shell with a rectangular structure. A power adapter 31 is provided on one side of the integrated box body 3. The power adapter 31 is connected to the server. A control cover plate 32 is provided on one side of the integrated box body 3. The control cover plate 32 is detachably connected to the integrated box body 3. The electrical controller 33 inside the integrated box body 3 can be controlled through the control cover plate 32. A detection and protection mechanism is provided at the bottom of the integrated box body 3 and is connected to the communication optical cable 2. The detection and protection mechanism is composed of an optical fiber attenuation detection module 4 and an armored protection detection module 5. The main function of the detection and protection mechanism is to detect the attenuation of the optical fiber signal of the communication optical cable 2 and the on-off of the armored protection layer, which is specifically implemented by the above optical fiber attenuation detection module 4 and armored protection detection module 5;
[0073] A data protection module 6 is arranged in the integrated box body 3 and is connected to the server in the server cabinet 1. When the above-mentioned optical fiber attenuation detection module 4 and the armored protection detection module 5 detect that the optical cable data is stolen, the data protection module 6 is used to implement temporary protection for the server, further enriching the server data protection means, making the data transmitted by the optical cable difficult to be deciphered, achieving the purpose of protecting the data. At the same time, an alarm is issued and the server is shut down, which can further improve the security of data protection;
[0074] According to the attached instructions Figure 5 As can be seen, the above-mentioned communication optical cable 2 is provided with an accompanying detection optical fiber 22 and an armored layer 21 is wrapped outside the optical fiber. The accompanying detection optical fiber 22 is coaxially arranged with the optical fiber in the communication optical cable 2. The armored layer 21 is a GYTA type or GYTS type armored layer 21. The accompanying detection optical fiber 22 is a single-mode optical fiber (SMF), the detection wavelength is 1550 nm, and the bandwidth is 10 GHz / km. The optical fiber attenuation detection module 4 can perform the optical signal attenuation of the optical fiber based on the accompanying detection optical fiber 22. Under normal circumstances, the attenuation range of the accompanying detection optical fiber 22 is 0.2 - 0.3 dB / km. If the detected value is higher than this range, it can be determined that the data has been stolen; The armored protection detection module 5 monitors based on the armored layer 21 of the communication optical cable 2. In fact, the armored layer 21 is a conductor. Then, the armored protection detection module 5 is used to construct a continuity detection system based on the armored layer 21. And the armored layer 21 is arranged around the optical fiber of the cable. When there is an attempt to steal data by damaging the outer skin of the optical cable, the armored protection detection module 5 can determine whether the optical cable is damaged and whether the data security is threatened according to the continuity of the armored layer 21, and then determine the disconnection position of the optical cable data;
[0075] According to the attached instructions Figure 6 - Attachment Figure 8 As can be seen, the above-mentioned armored protection detection module 5 is composed of a positioning and installation component 51 wrapped outside the communication optical cable 2, a signal transceiver 52 installed on the positioning and installation component 51, and a detection and control component 53 connecting the signal transceiver 52 and the positioning and installation component 51. The positioning component is installed based on the integrated box body 3. The positioning and installation component 51 is installed outside the communication optical cable 2 to provide an installation space for the detection and control component 53. The detection and control component 53 can move and is installed based on the positioning and installation component 51. The detection and control component 53 connects the signal transceiver 52 to the armored layer 21 of the communication optical cable 2, and a continuity detection system is formed by connecting the armored layer 21 through the signal transceiver 52;
[0076] According to the attached instructions Figure 8It can be known that the signal transceiver 52 is powered by the integrated box body 3. The signal transceiver 52 is based on a relay. The detection end of the signal transceiver 52 is connected to the detection control component 53 and is also connected to the armor layer 21 of the communication optical cable 2. The signal transceiver 52 uses ultrasonic waves as the detection signal. Through the transmission of the armor layer 21, the ultrasonic detection signal is detected at the signal transceiver 52 on the server side through the detection end. After receiving the ultrasonic signal, the amplifier and filter carried by the signal transceiver 52 are used for signal processing. When it is detected that the signal transmission of the armor layer 21 is blocked, the relay will turn on the alarm circuit, thereby realizing the operation of the alarm and the data protection module 6;
[0077] According to the attached instructions Figure 9 - Attachment Figure 11 It can be known that the above-mentioned optical fiber attenuation detection module 4 includes an optical power meter 41, a positioning and mounting groove 42, and a data transmitter 43. A light source is connected to the end of the accompanying detection optical fiber 22. The optical power meter 41 is installed and fixed through the positioning and mounting groove 42. The optical fiber attenuation is detected by the optical power meter 41 to analyze the optical fiber wavelength and detect the output power of the optical cable optical fiber. If there is an act of stealing data, the optical fiber signal will be intercepted, resulting in a decrease in the output optical fiber power. It is judged whether the optical fiber attenuation is within the normal attenuation range according to the decrease in the optical fiber power, and then the detection result is transmitted by the data transmitter 43;
[0078] According to the attached instructions Figure 13 It can be known that the above-mentioned data protection module 6 includes a data conversion interface 61. The data conversion interface 61 is respectively connected to the signal transceiver 52 and the data transmitter 43. A protection controller 62 is connected to the data conversion interface 61. A dynamic IP simulation module and a hardware encryption engine are carried on the protection controller 62. The data conversion interface 61 receives the detection signals transmitted by the signal transceiver 52 and the data transmitter 43. The protection controller 62 controls the operation of the dynamic IP simulation module and the hardware encryption engine according to the detection signals. The dynamic IP simulation module and the hardware encryption engine are connected to the server;
[0079] In the specific implementation process, the data protection module 6 takes the protection controller 62 as the main control. The protection controller 62 is built with a security chip of the ATECC series. The data conversion interface 61 is used to connect the signal transceiver 52 and the data transmitter 43. When the signal transceiver 52 and the data transmitter 43 transmit the control signals for security protection, the data of the server is encrypted by the dynamic IP simulation module and the hardware encryption engine connected to the protection controller 62, thereby increasing the difficulty of data theft. Furthermore, an alarm module is also installed on the protection controller 62. In addition to remote alarm, the alarm module can also perform audible and visual alarms through the audible and visual alarm on the integrated box body 3. One end of the data protection module 6 passes through the integrated box body 3, and a number of data interfaces 63 are arranged outside the data protection module 6. The number of data interfaces 63 is connected to the server through a network cable.
[0080] According to the attached instructions Figure 6 As can be seen, the above-mentioned positioning and installation component 51 includes a wrapping ring sleeve. The wrapping ring sleeve is fixed to the bottom of the integrated box body 3 through the horizontal adjustment component 54. The position of the wrapping ring sleeve can be adjusted through the horizontal adjustment component 54 to correspond to the communication optical cable 2. Furthermore, the wrapping ring sleeve is composed of a pair of semi-circular positioning ring pipes 511. One side of the pair of positioning ring pipes 511 is connected through a hinge 512. In this way, the pair of positioning ring pipes 511 can rotate around the hinge 512. A connector 513 is arranged on the corresponding side of the pair of positioning ring pipes 511. The connector 513 connects and fixes the pair of positioning ring pipes 511. Through the connector 513, the pair of positioning ring pipes 511 can be buckled and fixed, so that the pair of positioning ring pipes 511 wrap the opening position of the outer skin of the communication optical cable 2. Two pairs of sealing rubber rings 514 are arranged at both ends of the pair of positioning ring pipes 511. The two pairs of sealing rubber rings 514 adopt an inflatable structure to wrap the outer skin of the communication cable. After the pair of positioning ring pipes 511 wrap the outside of the communication optical cable 2, by injecting gas into the two pairs of sealing rubber rings 514, the two pairs of sealing rubber rings 514 expand to wrap the outer skin of the optical cable, playing a role in isolating external influences;
[0081] According to the attached instructions Figure 6 As can be seen, the above-mentioned horizontal adjustment component 54 includes a rotating ring groove 541. The rotating ring groove 541 is opened at the bottom of the integrated box body 3. A rotating plate 542 is assembled on the rotating ring groove 541. A horizontal track 543 is opened on the rotating plate 542. A sliding seat 544 is assembled on the horizontal track 543. A guiding lead screw 545 is arranged in parallel on one side of the horizontal track 543. The sliding seat 544 is threadedly engaged with the guiding lead screw 545. The bottom of the sliding seat 544 is provided with a rotating ring 546 which is connected to one of the positioning ring pipes 511 of the wrapping ring sleeve;
[0082] According to the attached instructions Figure 6It can be seen that the above connector 513 includes a pressing rod 5131. The pressing rod 5131 is movably installed on a positioning ring tube 511. A pulling-back sleeve 5132 is provided on the corresponding other positioning ring tube 511. A locking sleeve 5133 is sleeved outside the pressing rod 5131. A through groove 5134 is formed on the pulling-back sleeve 5132. The through groove 5134 matches the diameter of the pressing rod 5131. A limiting groove 5135 is provided on the through groove 5134. The limiting groove 5135 cooperates with the pulling-back sleeve 5132;
[0083] In the specific implementation process, after a pair of positioning ring tubes 511 are symmetrically buckled, by rotating the pressing rod 5131, the pressing rod 5131 is inserted into the through groove 5134. During the process, the locking sleeve 5133 is always located outside the pressing rod 5131. When the pressing rod 5131 moves in place, the locking sleeve 5133 is loosened. By using the spring counter-pushing effect between the locking sleeve 5133 and the pressing rod 5131, the locking sleeve 5133 retreats, and then the locking sleeve 5133 is inserted into the limiting groove 5135 of the pulling-back sleeve 5132. By using the pushing effect of the spring, the pushing-out effect on the pressing rod 5131 is realized, so that the pressing rod 5131 pulls one side of the positioning ring tube 511 to complete the buckling with the positioning ring tube 511 on the other side, and the sealing performance of the buckling of a pair of positioning ring tubes 511 is maintained.
[0084] According to the instruction manual appendix Figure 7 - appendix Figure 8 And appendix Figure 12 It can be seen that the above detection and control component 53 includes a fixed seat 531. One side of a positioning ring tube 511 extends out of the fixed seat 531. A telescopic channel 532 is provided on the fixed seat 531. A telescopic controller 533 is arranged in the integrated box body 3. The bottom of the telescopic controller 533 is connected with a telescopic control rod 534. The telescopic control rod 534 penetrates through the fixed seat 531 and contacts the armored layer 21. The telescopic control rod 534 is connected with the detection end;
[0085] In the specific implementation process, taking the fixed seat 531 as the installation space of the detection and control component 53, the fixed seat 531 is connected with the horizontal adjustment component 54. The position of the fixed seat 531 is controlled by the horizontal adjustment component 54 to move synchronously with the wrapping ring sleeve. The telescopic control rod 534 is controlled by the telescopic controller 533 to move linearly in the telescopic channel 532. Then the telescopic control rod 534 drives the detection end to move, so that the detection end contacts the armored layer 21. Furthermore, by using the contact between the detection end and the armored layer 21, the sending and receiving of ultrasonic signals are realized;
[0086] Furthermore, according to the instruction manual appendix Figure 7 - appendix Figure 8 And appendix Figure 12It can be seen that the above-mentioned telescopic controller 533 includes a control motor 5331. A driving gear 5332 is provided at the driving end of the control motor 5331. A driving rack 5333 is meshed on one side of the driving gear 5332. The driving rack 5333 is connected to a telescopic control rod 534. A counter-thrust spring 5334 is sleeved outside the telescopic control rod 534. A one-way ratchet 5335 is provided on the inner shaft of the driving gear 5332. A driving roller 5336 is sleeved on the driving end of the control motor 5331. A one-way ratchet tooth 5337 is provided on one side of the driving roller 5336. The one-way ratchet tooth 5337 is meshed with the one-way ratchet 5335.
[0087] In the specific implementation process, when detecting contact, the control motor 5331 does not output power. Under the action of the counter-thrust spring 5334, the counter-thrust spring 5334 pushes the telescopic control rod 534 downward, so that the telescopic control rod 534 drives the detection end to contact the armor layer 21. Furthermore, during disassembly and maintenance, by starting the control motor 5331, the control motor 5331 drives the one-way ratchet tooth 5337 to rotate. Then, by using the meshing of the one-way ratchet tooth 5337 and the one-way ratchet 5335, under the action of the one-way ratchet 5335, the driving gear 5332 rotates, so that the driving gear 5332 is meshed with the driving rack 5333. Since the driving rack 5333 is connected to the telescopic control rod 534, the driving rack 5333 can pull the telescopic control rod 534 to move, so that the detection end is separated from the contact with the armor layer 21, which is convenient for maintenance and repair.
[0088] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A communication system for network security, characterized in that: Including terminal equipment, network relay equipment, communication optical cables and servers; The terminal device is a host computer, and a firewall and an intrusion prevention system are arranged on the terminal device; The network relay equipment includes a switch and a router, and the switch and the router are used for forwarding photoelectric signals; The communication optical cable connects the network relay device and the server for optical signal transmission; The server plays the role of data protocol conversion, data storage and network management; The server side establishes an encrypted communication tunnel based on the VPN access control module, and sets a data encryption module and an access control module; The server side is also provided with an optical cable data protection unit, which is connected to the communication optical cable and is composed of an armor protection detection module, an optical fiber attenuation detection module and a data protection module; The armor protection detection module transmits ultrasonic signals through the armor layer of the communication optical cable to perform continuity detection, and transmits the detection data to the data protection module; The optical fiber attenuation detection module protects the optical cable communication data by detecting the signal attenuation data of the communication optical cable, and transmits the detection data to the data protection module; The data protection module is equipped with a dynamic IP simulation module and a hardware encryption engine. The data protection module analyzes the armor layer on-off data and the optical fiber attenuation data, and starts the dynamic IP simulation module and the hardware encryption engine according to the analysis results.
2. A communication system for network security according to claim 1, characterized in that: The authentication method of the VPN access control module is one or more of the following methods: mobile phone verification code login, username and password login, fingerprint authentication and face recognition authentication.
3. A communication system for network security according to claim 2, characterized in that: The server is equipped with a firewall, an intrusion prevention system, and a security information and event management system.
4. A communication device used in network security, applied to a communication system used in network security as claimed in any one of claims 1 to 3, characterized in that: Comprising a server cabinet (1), wherein a connection port is provided on one side of the server cabinet (1), the connection port is used to install a communication optical cable (2), and an optical cable data protection unit is provided on the connection port for monitoring the communication optical cable (2); The optical cable data protection unit comprises an integrated box body (3), the integrated box body (3) being a hollow shell with a rectangular structure, the two sides of the integrated box body (3) being connected to the server cabinet (1) by bolts, and the bottom of the integrated box body (3) being provided with a detection and protection mechanism connected to the communication optical cable (2); The detection and protection mechanism is composed of an optical fiber attenuation detection module (4) and an armor protection detection module (5); The integrated box body (3) is provided with a data protection module (6) which is connected to the server in the server cabinet (1); The communication optical cable (2) is provided with a companion detection optical fiber (22) and an armor layer (21) is wrapped around the optical fiber; the optical fiber attenuation detection module (4) performs optical fiber optical signal attenuation based on the companion detection optical fiber (22); the armor protection detection module (5) is installed based on the armor layer (21) of the communication optical cable (2); The armor protection detection module (5) is composed of a positioning installation component (51) wrapped outside the communication optical cable (2), a signal transceiver (52) installed on the positioning installation component (51), and a detection control component (53) connected to the signal transceiver (52) and the positioning installation component (51), wherein the positioning installation component (51) is installed outside the communication optical cable (2) to provide an installation space for the detection control component (53), and the detection control component (53) connects the signal transceiver (52) to the armor layer (21) of the communication optical cable (2); The signal transceiver (52) is powered by the integrated box (3), the signal transceiver (52) is arranged based on a relay, and the detection end of the signal transceiver (52) is connected to the detection control component (53) and to the armor layer (21) of the communication optical cable (2); The optical fiber attenuation detection module (4) comprises an optical power meter (41), a positioning card mounting slot (42) and a data transmission device (43); The data protection module (6) comprises a data conversion interface (61), the data conversion interface (61) being connected to the signal transceiver (52) and the data transmitter (43) respectively, the data conversion interface (61) being connected to a protection controller (62), the protection controller (62) being equipped with a dynamic IP simulation module and a hardware encryption engine, the data conversion interface (61) receiving detection signals transmitted by the signal transceiver (52) and the data transmitter (43), the protection controller (62) controlling the dynamic IP simulation module and the hardware encryption engine to operate according to the detection signals, and the dynamic IP simulation module and the hardware encryption engine being connected to a server.
5. A communication device for use in network security according to claim 4, characterized in that: The positioning and installation assembly (51) comprises a wrapping ring sleeve, which is composed of a pair of semi-annular positioning ring tubes (511), one side of the pair of positioning ring tubes (511) is connected via a hinge (512), and the corresponding sides of the pair of positioning ring tubes (511) are provided with a connector (513), and the connector (513) connects and fixes the pair of positioning ring tubes (511).
6. A communication device for use in network security according to claim 5, characterized in that: The detection control component (53) comprises a fixing seat (531), one side of the positioning ring tube (511) extends out from the fixing seat (531), a telescopic channel (532) is provided on the fixing seat (531), the fixing seat (531) is connected to the integrated box body (3), a telescopic controller (533) is provided in the integrated box body (3), a telescopic control rod (534) is connected to the bottom of the telescopic controller (533), the telescopic control rod (534) passes through the fixing seat (531) and contacts the armor layer (21), and the telescopic control rod (534) is connected to the detection end.
7. A communication device for use in network security according to claim 6, characterized in that: The accompanying detection optical fiber (22) is coaxially arranged with the optical fiber in the communication optical cable (2), and the armor layer (21) is a GYTA type or a GYTS type armor layer (21).
8. A communication device for use in network security according to claim 7, characterized in that: The end of the accompanying detection optical fiber (22) is connected to a light source, and the optical power meter (41) calculates the optical power and the wavelength of the optical signal after transmission of the accompanying detection optical fiber (22), calculates the optical power attenuation efficiency according to the wavelength, and compares it with the actual detection optical power.
9. A communication device for use in network security according to claim 8, characterized in that: One end of the data protection module (6) passes through the integrated box body (3), and a plurality of data interfaces (63) are arranged outside the data protection module (6), and the plurality of data interfaces (63) are connected to the server via a network cable.
10. A communication device for use in network security according to claim 9, characterized in that: The integrated box body (3) is a hollow shell with a rectangular structure. A power adapter (31) is provided on one side of the integrated box body (3). The power adapter (31) is connected to a server. A control cover plate (32) is provided on one side of the integrated box body (3). The control cover plate (32) is connected to the integrated box body (3) in a separate body.
Citation Information
Patent Citations
Teaching demonstration apparatus combining quantum cryptography communication with fiber eavesdropping
CN106340222A
Power transmission line network safety protection method based on optical fiber ring network communication
CN111131330A