Cross-network security streaming media data transmission system and method
By building a multimedia proxy server in the two-way industrial isolation gate module, the security and accessibility problems when displaying security video streaming media data across networks are solved, safe and effective access to security system data by the business system is achieved, and the deployment process is simplified.
Patent Information
- Application Number
- CN202411937209.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-05-13
AI Technical Summary
When the prior art displays security video streaming media data across networks, it is difficult to achieve effective access to multimedia data in the security system by the service system while ensuring network security.
By incorporating a multimedia proxy server unit in the bidirectional industrial isolation gate module, the configuration subunit and the proxy service subunit convert the multimedia data in the security video system into a format suitable for access to the business network module, and ensure network isolation and security through the security management unit.
It realizes cross-network access by the service system to multimedia data in the security system without affecting the existing network structure and security, simplifying the deployment process and saving construction costs.
Smart Images

Figure CN119995929A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial communication technology, and in particular to a cross-network security streaming media data transmission system, method, device and storage medium. Background Art
[0002] Many automation and information systems have been built in the process of factory production and management. With the establishment of different systems, the corresponding system communication networks of different systems are also established. Because different systems have security requirements for their respective networks, and at the same time, two networks with different security requirements are required to communicate when the system communicates across businesses. Taking the common security video network and business management network in the factory information system upgrade as an example, the access location of the pictures, streaming audio, and streaming video generated by the original security video system is dynamically generated by the security management system. The business system needs to dynamically obtain multimedia data in the security system. At this time, it is necessary to open up the existing security video network and business management network, and require security between the two networks. Using a combination of a two-way industrial isolation network gate with a built-in multimedia proxy server, the problem of cross-network display of multimedia data is solved under the premise of ensuring network security.
[0003] Usually, in factories, the business system network and the security video network are physically isolated networks, and the business system and security system are deployed in their own network systems. Due to network isolation, the security system can only be accessed by the terminal devices of the security network terminal. The business system can also only be accessed by the device terminals in the business network. If it is necessary to access the security video system in the business system, the existing technology usually provides solutions such as directly physically connecting the security video network and the business network, adding a two-way industrial isolation network gate between the security video network and the business network, and adding a one-way network gate and a streaming proxy server in each network in the security video network and the business network.
[0004] The disadvantage of directly accessing the video terminals in the security video network through the device terminals in the business system network is that the devices in the two networks can be directly accessed, and the security between the networks and the systems cannot be guaranteed; the disadvantage of adding a two-way industrial isolation network gate between the security video network and the business network is that although the two-way industrial isolation network gate protects the security between the networks, the multimedia data provided in the security video system cannot be accessed by the business system through the two-way industrial isolation network gate; the disadvantage of adding unidirectional network gates and streaming media proxy servers to each network in the security video network and the business network is that the deployment combination of dual unidirectional network gates and dual streaming media proxy servers is complex, requiring additional equipment costs and deployment costs. Summary of the invention
[0005] The purpose of the present invention is to solve the shortcomings of the prior art and provide a cross-network security streaming media data transmission system, including: The business system network module is used to send network requests to access the security network module; A bidirectional industrial isolation network gateway module, comprising a physical network access unit, a security management unit, a multimedia proxy server unit and a network service unit, for receiving and processing the network request to obtain a first streaming media access request or a second service request, wherein the uplink network port of the physical network access unit is used to connect to the access network cable of the business system network module, the downlink network port of the physical network access unit is connected to the incoming network cable of the security network module, the multimedia proxy server unit comprises a configuration subunit and a proxy service subunit, the configuration subunit is used to set the network configuration of the business system network module and the security network module; The security network module is used to encapsulate the first streaming media request or the second business request, and return it to the business system network module after being processed by the bidirectional industrial isolation network gateway module.
[0006] Preferably, the configuration subunit is used to set the network configuration of the business system network module and the security network module, and further includes: The configuration subunit includes configuration functions including connection configuration, security management configuration, multimedia server configuration and routing management configuration; The connection configuration is used to configure the basic information including the IP, subnet mask, and gateway of the uplink network port and the downlink network port in different networks; The security management configuration is used to configure the configuration data including the network protocol allowed to pass and the port request information allowed to pass. After the configuration, in the business system network module and the security network module, only the network protocol allowed to pass and the port request allowed to pass can access the other module through the two-way industrial isolation network gate module; The multimedia server configuration is used to configure the IP, port and basic path mapping information of the security video subunit in the security network module. After the configuration is completed, the business system network module is allowed to obtain security multimedia data by accessing the resource URI provided by the multimedia proxy server; The routing management configuration is used to configure the routing jump information of the business system network module and the security network module.
[0007] Preferably, the security management unit intercepts the network request, further comprising: The security management unit obtains the network request and parses it according to the security filtering mechanism to obtain the request data including the request initiating IP, the request access port and the request protocol type. The security filtering mechanism determines whether the request data is legal according to the parsing result and processes it according to the judgment result.
[0008] Preferably, the security filtering mechanism determines whether the request data is legal, further comprising: The request initiating IP, the request access port and the request protocol type are matched with the allowed request IP address list, allowed request port list and request protocol list respectively. If all the matching results meet the requirements, it is a legal request. If not all the matching results meet the requirements, it is judged as an illegal request.
[0009] Preferably, the security filtering mechanism performs processing according to the judgment result, including: If the request data is a streaming media request in a legitimate request, the first streaming media request is forwarded to the multimedia proxy service subunit, the multimedia proxy service subunit obtains a streaming media access request according to the first streaming media request, and sends the first streaming media access request to the security video subunit for processing; If the request data is a service request in a legitimate request, forwarding the first service request to the network service unit, and the network service unit processes the first service request; If the request data is illegal request data, the security management unit intercepts the illegal request data, directly returns a request failure to the request initiator, and records it in the access log.
[0010] Preferably, sending the first streaming media access request to the security video subunit for processing further comprises: After receiving the first streaming media access request, the security video subunit responds to the multimedia resource URI data or the multimedia data according to the request type, and encapsulates the multimedia resource URI data or the multimedia data in the request response body and returns it to the multimedia proxy service subunit; The multimedia proxy service subunit parses the request response body to obtain response body data, and performs processing according to the response body data; Among them, processing is performed according to the response body data, including: if the response body data is the multimedia data, re-packaging the multimedia data as the second streaming media request and returning it to the business system network module; if the response body data is the multimedia resource URI data, modifying the IP address, port, and resource address in the multimedia resource URI data according to the multimedia server configuration, and then re-packaging it as the second streaming media request and returning it to the business system network module.
[0011] Preferably, the network service unit processes the first service request, further comprising: The network service unit obtains the service request information including the initiating IP and MAC address of the first service request, the connection configuration changes the service request information into the security designated request information designated by the security network module, and encapsulates the security designated request information into a second service request and sends it to the security service system module. After the security service system module processes the second service request, it returns the second service request to the network service unit; After obtaining the second service request, the network service unit parses to obtain the security specified request information, and the connection configuration changes the security specified request information into the service specified request information specified by the service network module, and then repackages the service specified request information into a third service request and returns it to the service network module.
[0012] Based on the same concept, the present invention also provides a cross-network security streaming media data transmission method, comprising the following steps: S1: The business system network module sends a network request to access the security network module; S2: The bidirectional industrial isolation network gateway module receives and processes the network request to obtain a first streaming media access request or a second service request; S3: The security network module encapsulates the first streaming media request or the second service request, and returns it to the business system network module after processing by the bidirectional industrial isolation network gateway module.
[0013] Based on the same concept, the present invention also provides a computer device, characterized in that it includes a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes a method of a cross-network security streaming media data transmission system in an embodiment of the present invention.
[0014] Based on the same concept, the present invention also provides a storage medium storing computer-readable instructions, characterized in that when the computer-readable instructions are executed by one or more processors, the one or more processors execute a method of a cross-network security streaming media data transmission system in an embodiment of the present invention.
[0015] Compared with the prior art, the present invention has the following beneficial effects: The present invention has a built-in multimedia proxy server unit through a two-way industrial isolation network gateway module, which does not need to occupy separate server resources in a business network or a security network, thus saving construction costs. The deployment process is simplified by integrating the two-way industrial isolation network gateway with the multimedia proxy server configuration function.
[0016] The present invention converts multimedia data in the security video system module into a format suitable for access in the business network module through the configuration subunit and the proxy service subunit in the multimedia proxy server unit, thereby ensuring that the video data can be safely and effectively accessed and played in the business system.
[0017] The present invention ensures network isolation by configuring sub-units, security management units and network service units to prevent unauthorized access and data leakage. While ensuring security, it enables the business system module to access multimedia data in the security system across the network without affecting the existing network structure and security, thereby achieving expansion and upgrading of system functions. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the following detailed description of the preferred embodiment.The drawings are only for the purpose of illustrating the preferred embodiments and are not to be construed as limiting the invention.
[0019] Figure 1 It is a structural diagram of the multimedia proxy server module of the present invention; Figure 2 It is a structural diagram of the cross-network security streaming media data transmission system of the present invention. DETAILED DESCRIPTION
[0020] In order to make the purpose, technical scheme and advantages of the present invention clearer, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of this application.
[0021] Those skilled in the art will appreciate that, unless otherwise stated, the singular forms "a", "an", and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present invention refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0022] The technical terms involved in the embodiments of the present invention are defined as follows: 1. Two-way Industrial Isolation Gateway: An industrial isolation gateway is a network security device designed specifically for industrial environments. It can provide physical and logical isolation between two different networks.
[0023] 2. Multimedia Proxy Server: A multimedia proxy server is a server specially designed to handle multimedia data transmission. It is located somewhere in the network and is responsible for receiving, caching, converting and forwarding media content, such as pictures, video streams, audio streams, etc.
[0024] Example 1 See also Figure 1 and Figure 2 As shown, the security streaming media data transmission system provided in this embodiment includes: The business system network module is used to send network requests to access the security network module; A bidirectional industrial isolation network firewall module, comprising a physical network access unit, a security management unit, a multimedia proxy server unit and a network service unit, for receiving and processing the network request to obtain a first streaming media access request or a second service request, wherein the uplink network port of the physical network access unit is used to connect to the access network cable of the business system network module, and the downlink network port of the physical network access unit is connected to the incoming network cable of the security network module, and the multimedia proxy server unit comprises a configuration subunit and a proxy service subunit, and the configuration subunit is used to set the network configuration of the business system network module and the security network module. Specifically, in this embodiment, the multimedia proxy service subunit is used to provide a reverse proxy for the security video subunit in the security network module to provide multimedia data such as camera streaming media video, microphone streaming media audio data, and camera captured pictures, so as to allow the device terminal of the business system module to access the multimedia proxy service subunit without directly accessing the security video subunit in the security network module; The security network module is used to encapsulate the first streaming media request or the second business request, and return it to the business system network module after being processed by the two-way industrial isolation network gateway module.
[0025] The two-way industrial isolation network gate module provides physical and logical network isolation through the physical network access unit, configuration subunit and network service unit, and prevents unauthorized access and data leakage through the security management unit, while the configuration subunit and multimedia proxy service subunit in the multimedia proxy server unit are responsible for converting multimedia data into the format transmitted by the business network module, thereby ensuring the integrity and security of multimedia data when transmitted across networks. This system architecture design not only ensures the security of the network, but also solves the need to access multimedia data across networks.
[0026] This system is not only suitable for factory security monitoring and production process monitoring, but can also be used in scenarios such as remote maintenance and technical support, helping to improve the transparency and efficiency of production management.
[0027] Preferably, the configuration subunit is used to set the network configuration of the business system network module and the security network module, further comprising: The configuration subunit includes configuration functions including connection configuration, security management configuration, multimedia server configuration and routing management configuration; Among them, the connection configuration is used to configure the basic information including the IP, subnet mask, and gateway of the upstream network port and the downstream network port in different networks. Specifically, in this embodiment, the basic information such as the IP, subnet mask, and gateway of the upstream network port and the downstream network port of the bidirectional industrial isolation network gateway module in the unconnected network is configured to complete the physical connection between the business system network module and the security network module. Security management configuration is used to configure configuration data including network protocols allowed to pass and request port information allowed to pass. In the configured business system network module and security network module, only the network protocols allowed by the service and the port requests allowed to pass the port can access another module through the two-way industrial isolation network gate module. Specifically, in this embodiment, when the factory is upgraded and renovated for informatization, after the two business networks are connected using the two-way industrial isolation network gate, in the system configuration page of the two-way industrial isolation network gate module-security management configuration sub-page, the communication protocol control tab selects the request protocol allowed to pass the two-way industrial isolation network gate module, such as HTTP, MQTT, SNMP, TCP, UDP, etc. On the same sub-page, the access port control tab can select the request port that needs to be allowed to pass the two-way industrial isolation network gate module. This tab will provide a quick selection of commonly used protocol ports, such as 80, 43, 22, 23, etc., and supports releasing ports by range, such as 40 to 80, and multiple ranges are separated by ';'. On the same sub-page, the access address control tab can fill in the request IP address that needs to be allowed to pass the network gate, and multiple IP addresses can be separated by ';'. The multimedia server configuration is used to configure the IP, port and basic path mapping information of the security video subunit in the security network module. After the configuration is completed, the business system network module is allowed to obtain security multimedia data by accessing the resource URI provided by the multimedia proxy server; Routing management configuration is used to configure the routing jump information of the business system network module and the security network module.
[0028] Preferably, the security management unit intercepts the network request, further comprising: The security management unit obtains the network request and parses it according to the security filtering mechanism to obtain the request data including the request initiating IP, the request access port and the request protocol type. The security filtering mechanism determines whether the request data is legal based on the parsing result and processes it based on the judgment result. Specifically, in this embodiment, after the multimedia request reaches the bidirectional industrial isolation network gateway module, it is intercepted by the security management module in the bidirectional industrial isolation network gateway module.
[0029] Preferably, the security filtering mechanism determines whether the request data is legal, further comprising: The request initiating IP, request access port and request protocol type are matched with the allowed request IP address list, allowed request port list and request protocol list respectively. If all the matching results meet the requirements, it is a legal request. If not all the matching results meet the requirements, it is judged as an illegal request.
[0030] See also Figure 2 As shown, the security filtering mechanism processes according to the judgment results, including: If the request data is a streaming media request in a legitimate request, the first streaming media request is forwarded to the multimedia proxy service subunit, the multimedia proxy service subunit obtains a streaming media access request according to the first streaming media request, and sends the first streaming media access request to the security video subunit for processing; If the request data is a business request in a legitimate request, forwarding the first business request to the network service unit, and the network service unit processes the first business request; If the request data is illegal request data, the security management unit intercepts the illegal request data, directly returns the request failure to the request initiator, and records it in the access log. Specifically, in this embodiment, illegal requests cannot pass the security filtering mechanism of the bidirectional industrial isolation network gateway module.
[0031] Preferably, sending the first streaming media access request to the security video sub-unit for processing further includes: After receiving the first streaming media access request, the security video subunit responds to the multimedia resource URI data or multimedia data according to the request type, and at the same time encapsulates the multimedia resource URI data or multimedia data in the request response body and returns it to the multimedia proxy service subunit; The multimedia proxy service subunit parses the request response body to obtain the response body data, and processes according to the response body data; Among them, processing is performed according to the response body data, including: if the response body data is multimedia data, re-packaging the multimedia data into a second streaming media request and returning it to the business system network module; if the response body data is multimedia resource URI data, modifying the IP address, port, and resource address in the multimedia resource URI data according to the multimedia server configuration, and then re-packaging it into a second streaming media request and returning it to the business system network module.
[0032] Preferably, the network service unit processes the first service request, further comprising: The network service unit obtains the service request information including the initiating IP and MAC address of the first service request, and the connection configuration changes the service request information to the security designated request information specified by the security network module, and encapsulates the security designated request information as a second service request and sends it to the security service system module. After the security service system module processes the second service request, it returns the second service request to the network service unit. Specifically, in this embodiment, by querying the connection data configuration in the system configuration page-connection configuration subpage, the initiating IP, MAC address and other information are changed to the initiating IP, MAC address and other information specified by the security network module in the connection configuration; After obtaining the second service request, the network service unit parses and obtains the security specified request information, and the connection configuration changes the security specified request information into the service specified request information specified by the service network module, and then repackages the service specified request information into the third service request and returns it to the service network module.
[0033] Example 2 This embodiment provides a method for transmitting security streaming media data across networks, comprising the following steps: S1: The business system network module sends a network request to access the security network module; S2: The bidirectional industrial isolation network gateway module receives and processes the network request to obtain a first streaming media access request or a second service request; S3: The security network module encapsulates the first streaming media request or the second service request, and returns it to the business system network module after processing by the bidirectional industrial isolation network gateway module.
[0034] Example 3 In some embodiments of the present application, a computer device is also provided, including a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes a method of a cross-network security streaming media data transmission system in an embodiment of the present invention.
[0035] The present invention also provides a storage medium storing computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of a cross-network security streaming media data transmission system in an embodiment of the present invention.
[0036] It is understandable that, for the aforementioned cross-network security streaming media data transmission system, if it is implemented in the form of software function modules and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer server, or a network device, etc.) to perform all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program codes.
[0037] Computer readable storage media may include data signals propagated in baseband or as part of a carrier wave, wherein readable program codes are carried. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program codes contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.
[0038] The above is only a preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technicians in this technical field, some improvements and modifications without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.
Claims
1. A cross-network security streaming media data transmission system, characterized in that: include: The business system network module is used to send network requests to access the security network module; A bidirectional industrial isolation network gateway module, comprising a physical network access unit, a security management unit, a multimedia proxy server unit and a network service unit, for receiving and processing the network request to obtain a first streaming media access request or a second service request, wherein the uplink network port of the physical network access unit is used to connect to the access network cable of the business system network module, the downlink network port of the physical network access unit is connected to the incoming network cable of the security network module, the multimedia proxy server unit comprises a configuration subunit and a proxy service subunit, the configuration subunit is used to set the network configuration of the business system network module and the security network module; The security network module is used to encapsulate the first streaming media request or the second business request, and return it to the business system network module after being processed by the bidirectional industrial isolation network gateway module.
2. The cross-network security streaming media data transmission system according to claim 1 is characterized in that: The configuration subunit is used to set the network configuration of the business system network module and the security network module, and further includes: The configuration subunit includes configuration functions including connection configuration, security management configuration, multimedia server configuration and routing management configuration; The connection configuration is used to configure the basic information including the IP, subnet mask, and gateway of the uplink network port and the downlink network port in different networks; The security management configuration is used to configure the configuration data including the network protocol allowed to pass and the port request information allowed to pass. After the configuration, in the business system network module and the security network module, only the network protocol allowed to pass and the port request allowed to pass can access the other module through the two-way industrial isolation network gate module; The multimedia server configuration is used to configure the IP, port and basic path mapping information of the security video subunit in the security network module. After the configuration is completed, the business system network module is allowed to obtain security multimedia data by accessing the resource URI provided by the multimedia proxy server; The routing management configuration is used to configure the routing jump information of the business system network module and the security network module.
3. The cross-network security streaming media data transmission system according to claim 2 is characterized in that: The security management unit intercepts the network request, further comprising: The security management unit obtains the network request and parses it according to the security filtering mechanism to obtain the request data including the request initiating IP, the request access port and the request protocol type. The security filtering mechanism determines whether the request data is legal according to the parsing result and processes it according to the judgment result.
4. The cross-network security streaming media data transmission system according to claim 3 is characterized in that: The security filtering mechanism determines whether the request data is legal, further comprising: The request initiating IP, the request access port and the request protocol type are matched with the allowed request IP address list, allowed request port list and request protocol list respectively. If all the matching results meet the requirements, it is a legal request. If not all the matching results meet the requirements, it is judged as an illegal request.
5. The cross-network security streaming media data transmission system according to claim 4 is characterized in that: The security filtering mechanism processes the information based on the judgment results, including: If the request data is a streaming media request in a legitimate request, the first streaming media request is forwarded to the multimedia proxy service subunit, the multimedia proxy service subunit obtains a streaming media access request according to the first streaming media request, and sends the first streaming media access request to the security video subunit for processing; If the request data is a service request in a legitimate request, forwarding the first service request to the network service unit, and the network service unit processes the first service request; If the request data is illegal request data, the security management unit intercepts the illegal request data, directly returns a request failure to the request initiator, and records it in the access log.
6. The cross-network security streaming media data transmission system according to claim 5 is characterized in that: Sending the first streaming media access request to the security video sub-unit for processing further includes: After receiving the first streaming media access request, the security video subunit responds to the multimedia resource URI data or the multimedia data according to the request type, and encapsulates the multimedia resource URI data or the multimedia data in the request response body and returns it to the multimedia proxy service subunit; The multimedia proxy service subunit parses the request response body to obtain response body data, and performs processing according to the response body data; Among them, processing is performed according to the response body data, including: if the response body data is the multimedia data, re-packaging the multimedia data as the second streaming media request and returning it to the business system network module; if the response body data is the multimedia resource URI data, modifying the IP address, port, and resource address in the multimedia resource URI data according to the multimedia server configuration, and then re-packaging it as the second streaming media request and returning it to the business system network module.
7. The cross-network security streaming media data transmission system according to claim 6, characterized in that: The network service unit processes the first service request, further comprising: The network service unit obtains the service request information including the initiating IP and MAC address of the first service request, the connection configuration changes the service request information into the security designated request information designated by the security network module, and encapsulates the security designated request information into a second service request and sends it to the security service system module. After the security service system module processes the second service request, it returns the second service request to the network service unit; After obtaining the second service request, the network service unit parses to obtain the security specified request information, and the connection configuration changes the security specified request information into the service specified request information specified by the service network module, and then repackages the service specified request information into a third service request and returns it to the service network module.
8. A method for transmitting security streaming media data across networks, characterized in that: The following steps are involved: S1: The business system network module sends a network request to access the security network module; S2: The bidirectional industrial isolation network gateway module receives and processes the network request to obtain a first streaming media access request or a second service request; S3: The security network module encapsulates the first streaming media request or the second service request, and returns it to the business system network module after processing by the bidirectional industrial isolation network gateway module.
9. A computer device, characterized in that: It comprises a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes the method of the cross-network security streaming media data transmission system as described in any one of claims 1 to 7.
10. A storage medium storing computer-readable instructions, characterized in that: When the computer-readable instructions are executed by one or more processors, the one or more processors execute the method of the cross-network secure streaming media data transmission system as described in any one of claims 1 to 7.