Novel network isolation and information exchange equipment and method
By designing a new type of network isolation and information exchange device, using dedicated secure channels and proprietary protocols to process data, the existing technology's performance limitations, compatibility challenges, encryption technology difficulties, configuration complexity and high hardware cost are solved, and efficient and secure network isolation and data exchange are achieved.
Patent Information
- Application Number
- CN202510120397.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-25
- Publication Date
- 2025-05-13
AI Technical Summary
Existing network isolation technology has performance limitations when dealing with high concurrency and large data volumes of secure isolation and data exchange, compatibility challenges, encryption technology faces the threat of quantum computing, and is complex in configuration and maintenance, difficult in security policy management, and high hardware costs.
A new type of network isolation and information exchange equipment is designed, including a 3U chassis, an external network processing unit, an intranet processing unit, an isolation unit module, a power supply module and a CPEX bus bottom plate module. Data scrambling and descrambling processing are realized through dedicated security channels and proprietary protocols to ensure the secure exchange of data.
It realizes the isolation and control of data exchange of networks of different security levels, improves processing speed and efficiency, reduces latency and packet loss rates, simplifies configuration and maintenance, enhances resistance to quantum computing threats, and reduces hardware costs.
Smart Images

Figure CN119995970A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data interaction, and in particular to a novel network isolation and information exchange device and method. Background Art
[0002] In the face of the emergence of new network attack methods and the special security needs of high-security networks, a new network security technology with a new security protection concept, "network isolation technology", came into being. The goal of network isolation technology is to ensure the isolation of harmful attacks and complete the secure exchange of data between networks outside the trusted network and on the premise of ensuring that information within the trusted network is not leaked.
[0003] Network isolation technology has gone through the first generation of physical isolation technology, the second generation of hardware card isolation technology, the third generation of data relay isolation technology, the fourth generation of air switch isolation technology, and now the fifth generation of safe channel isolation technology. This technology uses security mechanisms such as dedicated communication hardware and proprietary security protocols to achieve isolation and data exchange between internal and external networks. It not only solves the security and performance problems of previous isolation technologies, and effectively isolates internal and external networks, but also efficiently achieves secure exchange of internal and external network data, transparently supports a variety of network applications, and has become the current development direction of isolation technology.
[0004] Technical aspects
[0005] -Performance limitations: With the explosive growth of data volume and the diversification of business scenarios, when dealing with high-concurrency, large-volume security isolation and data exchange, problems such as slow processing speed, high latency, and packet loss may occur, affecting business continuity and efficiency.
[0006] - Compatibility challenges: It needs to be compatible with existing network architecture, operating systems, applications and other software and hardware environments. However, new technologies may have adaptation issues with old systems. For example, it may be difficult to deploy and run smoothly in some old industrial control systems or specific professional software environments.
[0007] -Difficulties in encryption technology: Although encryption is an important means of secure channel isolation, the development of quantum computing poses a threat to traditional encryption algorithms and may make existing encryption technologies unsafe in the future. New technologies such as quantum-safe encryption algorithms face challenges in performance and cost in their applications.
[0008] Management Level
[0009] - Complex configuration and maintenance: The complexity of the technology makes it difficult to configure and maintain, requiring professional technicians to operate and manage. The formulation, update and adjustment of security policies also require a deep understanding of the technology, otherwise it may lead to security vulnerabilities or affect normal business operations.
[0010] -Security policy management: It is necessary to formulate reasonable security policies according to different business needs and security levels, and ensure that the policies are effectively implemented and work together in different network areas and user groups. This requires the establishment of a complete security policy management system, otherwise policy conflicts, loopholes and other problems are likely to occur.
[0011] Cost aspect
[0012] -Hardware cost: Deploying fifth-generation secure channel isolation technology usually requires the purchase of new hardware equipment, such as high-performance secure isolation gateways, encryption equipment, etc. These hardware devices are relatively expensive, which may pose cost pressure for some small and medium-sized enterprises. Summary of the invention
[0013] The purpose of the present invention is to overcome the shortcomings of the prior art and propose a new type of network isolation and information exchange equipment and method, which can maintain the stable operation of the power grid, can quickly and accurately provide the optimal load transfer plan, greatly improve the work efficiency of dispatchers, and ensure the safe and stable operation of the power grid.
[0014] The present invention solves the technical problem by adopting the following technical solutions:
[0015] A novel network isolation and information exchange device and method, comprising a 3U chassis, an external network processing unit, an internal network processing unit, an isolation unit module, a power module and a CPEX bus backplane module, wherein the external network processing unit, the internal network processing unit, the isolation unit module, the power module and the CPEX bus backplane module are installed inside the 3U chassis, the external network processing unit, the internal network processing unit, the isolation unit module and the power module are connected to the CPEX bus backplane module, wherein the CPEX bus backplane module is used for output transmission, and the power module is used for providing power.
[0016] Moreover, the internal network processing unit is connected to one end of the isolation unit module through the CPEX bus baseboard module, and the other end of the isolation unit module is connected to the external network processing unit through the CPEX bus baseboard module, and the CPEX bus baseboard module is connected to the power supply module.
[0017] Moreover, the external network processing unit includes an external network processing channel, an external network Ethernet, an external network serial port and an external network display / mouse / keyboard / USB2.0 interface. The external network processing channel is connected to the external network dedicated security channel of the isolation unit module through the PCIEx4 bus of the CPEX bus baseboard module.
[0018] Moreover, the intranet processing unit includes an intranet processing channel, an intranet Ethernet, an intranet serial port and an intranet display / mouse / keyboard / USB2.0 interface. The intranet processing channel is connected to the intranet dedicated security channel of the isolation unit module through the PCIEx4 bus of the CPEX bus baseboard module.
[0019] Moreover, the isolation unit module includes a processor, an algorithm FPGA, a security protection module and a dedicated security channel. The processor and the algorithm FPGA are connected to the dedicated security channel through the EMIF bus. The dedicated security channel includes an external network dedicated security channel and an internal and external network dedicated security channel.
[0020] Moreover, the external network dedicated security channel includes an independent noise sampling circuit, a PCI / PCIE local bus, a scrambling circuit, a first FIFO circuit, a second FIFO circuit and an embedded processor external bus, wherein the processor and the algorithm FPGA of the isolation unit module are respectively connected to the independent noise sampling circuit and the embedded processor external bus, the embedded processor external bus is connected to the scrambling circuit through the first FIFO circuit and the second FIFO circuit, the scrambling circuit is respectively connected to the independent noise sampling circuit and the PCI / PCIE local bus, and the PCI / PCIE local bus is connected to the intranet processing unit or the external network processing unit.
[0021] A novel information exchange method for network isolation and information exchange equipment includes an intranet data sending method and an extranet data receiving method.
[0022] Moreover, the specific implementation method of the intranet data sending method is as follows: the data sent from the intranet reaches the intranet processing unit through the network port, the data is processed by a proprietary protocol, and then sent to the secure channel. The secure channel scrambles the data and sends it to the isolation unit. The isolation unit then descrambles the data and performs algorithm processing on the data. The isolation unit then performs scrambling and other processing, and after scrambling, it is sent to the secure channel on the other side, descrambled by the secure channel, and then sent to the external network processing unit. The external network processing unit performs security protocol processing, and after processing, it is sent out by the network port of the external network processing unit.
[0023] Moreover, the specific implementation method of the intranet data sending method is: after the data filtered from the external network reaches the external network processing unit, the data is first checked and filtered, the network protocol header part is stripped off, leaving only the pure data and the security protocol part, and scrambling is performed when passing through the security channel. After reaching the isolation unit, it is first descrambled, and then algorithm processing is performed to verify whether the data can pass. If it is allowed to pass, it is sent to the intranet processing unit through the security channel, and the intranet processing unit performs corresponding processing, otherwise it cannot pass.
[0024] The advantages and positive effects of the present invention are:
[0025] The present invention includes a 3U chassis, an external network processing unit, an internal network processing unit, an isolation unit module, a power module and a CPEX bus backplane module, wherein the external network processing unit, the internal network processing unit, the isolation unit module, the power module and the CPEX bus backplane module are installed inside the 3U chassis, and the external network processing unit, the internal network processing unit, the isolation unit module and the power module are connected to the CPEX bus backplane module, wherein the CPEX bus backplane module is used for output transmission, and the power module is used to provide power. The present invention can be used to isolate the internal LAN from the external transmission network, solve the problem of information security exchange between networks, and realize the isolation and data exchange of networks with different security levels. The system adopts technical means such as network isolation exchange, network attack detection, network access control, and network protocol format inspection to prevent network attacks, block illegal access behavior, and provide security protection for information exchange. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 This is a diagram of the hardware composition of the system of the present invention;
[0027] Figure 2 This is a block diagram of the hardware architecture of the system of the present invention;
[0028] Figure 3 It is a principle block diagram of the internal and external network processing unit of the system of the present invention;
[0029] Figure 4 It is a principle block diagram of the isolation unit of the system of the present invention;
[0030] Figure 5 It is a schematic diagram of the principle of the dedicated safety channel of the system of the present invention. DETAILED DESCRIPTION
[0031] The present invention is further described in detail below with reference to the accompanying drawings.
[0032] The construction idea of the present invention is: the reinforced network isolation and information exchange equipment mainly completes the data security exchange function between networks with different security levels. The security of the exchanged data is the first thing that the equipment needs to ensure, which is mainly achieved through security isolation technology. Since the system is implemented based on the TCP / IP and UDP / IP models, attacks may come from attacks on one or more layers of the data communication model. The security isolation technology disconnects all levels of the data communication model during the data interaction process, including the physical layer, data link layer, network layer, transport layer and application layer. The isolation of the physical layer is achieved by building a dedicated two-way secure channel, and the isolation of the data link layer, network layer, transport layer and application layer is achieved by stripping off the protocols of each layer, using proprietary protocol encapsulation during data exchange, eliminating attacks from protocols of each layer, thereby achieving security isolation.
[0033] A novel network isolation and information exchange device and method, such as Figure 1As shown, it includes a 3U chassis, an external network processing unit, an internal network processing unit, an isolation unit module, a power module and a CPEX bus baseboard module, wherein the external network processing unit, the internal network processing unit, the isolation unit module, the power module and the CPEX bus baseboard module are installed inside the 3U chassis, and the external network processing unit, the internal network processing unit, the isolation unit module and the power module are connected to the CPEX bus baseboard module, wherein the CPEX bus baseboard module is used for output transmission, and the power module is used to provide power.
[0034] like Figure 2 As shown, the internal network processing unit is connected to one end of the isolation unit module through the CPEX bus baseboard module, and the other end of the isolation unit module is connected to the external network processing unit through the CPEX bus baseboard module, and the CPEX bus baseboard module is connected to the power module.
[0035] The external network processing unit includes an external network processing channel, an external network Ethernet, an external network serial port and an external network display / mouse / keyboard / USB2.0 interface. The external network processing channel is connected to the external network dedicated security channel of the isolation unit module through the PCIEx4 bus of the CPEX bus baseboard module.
[0036] The intranet processing unit includes an intranet processing channel, an intranet Ethernet, an intranet serial port and an intranet display / mouse / keyboard / USB2.0 interface. The intranet processing channel is connected to the intranet dedicated security channel of the isolation unit module through the PCIEx4 bus of the CPEX bus baseboard module.
[0037] like Figure 3 As shown, the internal and external network processing unit can provide an efficient and real-time operation platform for the security isolation software. The internal and external network processing unit is connected to the isolation unit through the baseboard, completes the system's command scheduling and process processing, receives and parses the command information sent from the network interface module, and sends it to the corresponding interface processing circuit for processing, realizes the reception and transmission of communication data, and also provides user transmission service type permissions, transmission content format inspection and filtering control functions.
[0038] like Figure 4 As shown, the isolation unit module includes a processor, an algorithm FPGA, a security protection module and a dedicated security channel. The processor and the algorithm FPGA are connected to the dedicated security channel through the EMIF bus. The dedicated security channel includes an external network dedicated security channel and an internal and external network dedicated security channel. The isolation unit mainly provides an operating platform for the algorithm, provides document-level data interaction authentication functions, realizes data transmission between the module and the dual-side host through a dedicated security channel, and provides information ferrying between the internal and external network processing units.
[0039] like Figure 5As shown, the function of the dedicated security channel is to realize data transmission between the isolation unit and the internal and external network processing units. The connection between the dedicated security channel and the internal and external network processing units is realized through the PCIE bus. The external network dedicated security channel includes an independent noise sampling circuit, a PCI / PCIE local bus, a scrambling circuit, a first FIFO circuit, a second FIFO circuit and an embedded processor external bus, wherein the processor and the algorithm FPGA of the isolation unit module are respectively connected to the independent noise sampling circuit and the embedded processor external bus, the embedded processor external bus is connected to the scrambling circuit through the first FIFO circuit and the second FIFO circuit, the scrambling circuit is respectively connected to the independent noise sampling circuit and the PCI / PCIE local bus, and the PCI / PCIE local bus is connected to the internal network processing unit or the external network processing unit.
[0040] The working process of the dedicated safety channel is as follows: the data passed from one side processing unit to the FIFO must be disturbed, that is, the noise data sampled by the noise sampling circuit is used to perform an XOR operation on the data, and the disturbed data is passed to the embedded processor for subsequent processing
[0041] A novel information exchange method for network isolation and information exchange equipment includes an intranet data sending method and an extranet data receiving method.
[0042] The specific implementation method of the intranet data sending method is as follows: the data sent from the intranet reaches the intranet processing unit through the network port, the data is processed by the proprietary protocol, and then sent to the security channel. The security channel scrambles the data and sends it to the isolation unit. The isolation unit then descrambles the data and performs algorithm processing on the data. The isolation unit then scrambles the data and performs other processing. After scrambling, it is sent to the security channel on the other side, descrambled by the security channel, and then sent to the external network processing unit. The external network processing unit performs security protocol processing and sends it out through the network port of the external network processing unit after processing.
[0043] The specific implementation method of the intranet data sending method is as follows: after the data filtered from the external network reaches the external network processing unit, the data is first checked and filtered, and the network protocol header part is stripped off, leaving only the pure data and the security protocol part. When passing through the secure channel, it is scrambled. After reaching the isolation unit, it is first descrambled, and then algorithm processing is performed to verify whether the data can pass. If it is allowed to pass, it is sent to the intranet processing unit through the secure channel, and the intranet processing unit performs corresponding processing, otherwise it cannot pass.
[0044] It should be emphasized that the embodiments described in the present invention are illustrative rather than restrictive. Therefore, the present invention includes but is not limited to the embodiments described in the specific implementation manner. Any other implementation manners derived by those skilled in the art based on the technical solution of the present invention also fall within the scope of protection of the present invention.
Claims
1. A novel network isolation and information exchange device and method, characterized in that: It includes a 3U chassis, an external network processing unit, an internal network processing unit, an isolation unit module, a power module and a CPEX bus baseboard module, wherein the external network processing unit, the internal network processing unit, the isolation unit module, the power module and the CPEX bus baseboard module are installed inside the 3U chassis, and the external network processing unit, the internal network processing unit, the isolation unit module and the power module are connected to the CPEX bus baseboard module, wherein the CPEX bus baseboard module is used for output transmission, and the power module is used to provide power.
2. A novel network isolation and information exchange device according to claim 1, characterized in that: The internal network processing unit is connected to one end of the isolation unit module through the CPEX bus baseboard module, and the other end of the isolation unit module is connected to the external network processing unit through the CPEX bus baseboard module, and the CPEX bus baseboard module is connected to the power supply module.
3. A novel network isolation and information exchange device according to claim 1, characterized in that: The external network processing unit includes an external network processing channel, an external network Ethernet, an external network serial port and an external network display / mouse / keyboard / USB2.0 interface. The external network processing channel is connected to the external network dedicated security channel of the isolation unit module through the PCIEx4 bus of the CPEX bus baseboard module.
4. A novel network isolation and information exchange device according to claim 1, characterized in that: The intranet processing unit includes an intranet processing channel, an intranet Ethernet, an intranet serial port and an intranet display / mouse / keyboard / USB2.0 interface. The intranet processing channel is connected to the intranet dedicated security channel of the isolation unit module through the PCIEx4 bus of the CPEX bus baseboard module.
5. A novel network isolation and information exchange device according to claim 1, characterized in that: The isolation unit module includes a processor, an algorithm FPGA, a security protection module and a dedicated security channel. The processor and the algorithm FPGA are connected to the dedicated security channel through an EMIF bus. The dedicated security channel includes an external network dedicated security channel and an internal and external network dedicated security channel.
6. A novel network isolation and information exchange device according to claim 5, characterized in that: The external network dedicated security channel includes an independent noise sampling circuit, a PCI / PCIE local bus, a scrambling circuit, a first FIFO circuit, a second FIFO circuit and an embedded processor external bus, wherein the processor and the algorithm FPGA of the isolation unit module are respectively connected to the independent noise sampling circuit and the embedded processor external bus, the embedded processor external bus is connected to the scrambling circuit through the first FIFO circuit and the second FIFO circuit, the scrambling circuit is respectively connected to the independent noise sampling circuit and the PCI / PCIE local bus, and the PCI / PCIE local bus is connected to the internal network processing unit or the external network processing unit.
7. An information exchange method for the novel network isolation and information exchange device according to any one of claims 1 to 6, characterized in that: It includes methods for sending data via the intranet and receiving data via the extranet.
8. The information exchange method of the novel network isolation and information exchange device according to claim 7 is characterized in that: The specific implementation method of the intranet data sending method is as follows: the data sent from the intranet reaches the intranet processing unit through the network port, the data is processed by a proprietary protocol, and then sent to the secure channel. The secure channel scrambles the data and sends it to the isolation unit. The isolation unit then descrambles the data and performs algorithm processing on the data. The isolation unit then performs scrambling and other processing, and then sends it to the secure channel on the other side after scrambling. The secure channel performs descrambling processing and then sends it to the external network processing unit. The external network processing unit performs security protocol processing and after processing, it is sent out by the network port of the external network processing unit.
9. The information exchange method of a novel network isolation and information exchange device according to claim 7 is characterized in that: The specific implementation method of the intranet data sending method is as follows: after the data filtered from the external network arrives at the external network processing unit, the data is first checked and filtered, the network protocol header part is stripped off, leaving only the pure data and the security protocol part, and scrambling processing is performed when passing through the security channel. After arriving at the isolation unit, the data is first descrambled and then algorithm processing is performed to verify whether the data can pass. If it is allowed to pass, it is sent to the intranet processing unit through the security channel, and the intranet processing unit performs corresponding processing, otherwise it cannot pass.