Office network switching method and equipment adaptive to extranet and intranet
By monitoring and comparing the network feature information of office equipment connections, security detection and network protocol switching are performed, and the problem of automatic security switching between intranet and external networks cannot be achieved in the existing technology, automatic security switching of office networks is realized, and information security is improved.
Patent Information
- Application Number
- CN202510164712.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-13
AI Technical Summary
The existing technology cannot achieve secure automatic switching between the intranet and the outside network, resulting in enterprises facing the risk of data leakage and system paralysis.
By monitoring the network feature information connected to the office equipment, comparing it with the preset network feature library, security detection and network protocol switching are performed. The specific steps include: performing security detection when the external network switches to the intranet, and loading the driver and network protocol dedicated to the intranet; when the intranet switches to the external network, clearing the intranet access records and connecting to the external network.
It realizes automatic secure switching between the adaptive external and intranet office networks, avoids information leakage and improves the security index of intranet information.
Smart Images

Figure CN119996008A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer office technology, and in particular to an office network switching method and equipment for adaptive external network and internal network. Background Art
[0002] In modern office scenarios, companies usually have both external network (such as the Internet, used to obtain public information, communicate with the outside world, etc.) and intranet (internal private network, used to store the company's core confidential data, key business systems, etc.) office needs.
[0003] When employees use computer equipment to work in different office environments, they may face many security risks. For example, on the one hand, after the computer equipment is switched from the external network to the internal network, if the equipment carries viruses or malware from the external network, it is very easy to invade the internal network, causing internal data leakage and even causing serious consequences such as paralysis of the internal system of the enterprise; on the other hand, during the use of the internal network, if sensitive files on the internal network are accidentally transmitted to the external network, it will also cause security problems. The existing office system lacks a secure internal and external network switching mechanism, which is difficult to meet the growing office security needs. Summary of the invention
[0004] The present invention provides an office network switching method and equipment for adaptively switching between an external network and an internal network, so as to solve the technical problem that safe and automatic switching between an internal network and an external network cannot be realized in the prior art.
[0005] On the one hand, the present invention provides an office network switching method for adaptively switching between an external network and an internal network, comprising: Monitor the characteristic information of the network to which the office equipment is connected, and compare the characteristic information with a preset network characteristic library to obtain a comparison result; wherein the network characteristic library includes the IP segment of the Internet service provider, the public DNS, and the pre-entered intranet network identifier; When the comparison result indicates that the network to which the office equipment is connected is switched from an external network to an internal network, a security check is performed on the office equipment; When the security check is passed, the office equipment is controlled to load a driver and network protocol dedicated to the intranet to access the intranet; When the comparison result indicates that the network to which the office device is connected is switched from the intranet to the extranet, clearing the intranet access record of the office device; When the cleaning of the intranet access records is completed, the office equipment is controlled to access the external network.
[0006] According to an adaptive external network and internal network office network switching method provided by the present invention, the security detection of the office equipment includes: Suspending the network data interaction process of the office equipment, wherein the network data interaction process includes: network upload and download process, file sharing process, synchronization service process, and remote desktop connection process; Multi-engine scanning is used, combined with a real-time updated virus signature library and behavior analysis algorithm, to perform virus detection and malware detection on the storage space of the office equipment; wherein the storage space includes memory, cache and hard disk, and the malware includes: viruses, Trojans, worms and spyware.
[0007] According to an adaptive external network and internal network office network switching method provided by the present invention, the cleaning of the internal network access record of the office device includes: Delete the temporary authorization file on the intranet; Clear cached intranet pages; Shut down intranet-related applications and services; Cryptographically erase temporary information in the relevant storage area.
[0008] According to an office network switching method for adaptively switching between an external network and an internal network provided by the present invention, when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, the method further includes: Automatically start a pre-established virtual desktop environment dedicated to the intranet; wherein the virtual desktop environment is isolated from the extranet environment and supports simultaneous access by multiple users; Monitor and record the operation records of each user; When the comparison result indicates that the network to which the office equipment is connected is switched from an intranet to an extranet, the method further includes: The virtual desktop environment is closed, and each recorded operation record is encrypted and stored.
[0009] According to an office network switching method for adaptively switching between an external network and an internal network provided by the present invention, when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, the method further includes: Verify the identity of the user who accesses the intranet dedicated hard disk space, and when the user identity meets the preset identity rules, allow the user identity to access the preset storage space in the intranet dedicated hard disk; wherein the preset storage space uses an encryption algorithm to encrypt and store the stored files; Access to the hard disk space dedicated to the external network is prohibited; When the comparison result indicates that the network to which the office equipment is connected is switched from an intranet to an extranet, the method further includes: Prohibiting access to the preset storage space; When receiving a download instruction to download a file from the external network to the preset storage space, storing the file in the preset isolation area; Perform virus scan and malware detection on the files in the quarantine area; The files detected after virus removal and malware detection are stored in the preset storage space.
[0010] According to an office network switching method for adaptively switching between an external network and an internal network provided by the present invention, when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, the method further includes: Detecting the external network usage behavior of the office equipment before switching; wherein the external network usage behavior includes the type of website visited, the frequency of data transmission, and the source of file downloads; Conducting a risk assessment on the external network usage behavior and obtaining an assessment result; Dynamically adjust the security detection after intranet access based on the evaluation results; After controlling the office equipment to load the intranet-specific driver and network protocol, the method further includes: Automatically optimize network configuration parameters according to the role and business requirements of the office equipment in the intranet; wherein the network configuration parameters include network bandwidth, firewall rules and network paths.
[0011] According to an office network switching method for adaptively switching between an external network and an internal network provided by the present invention, the security detection after the internal network access is dynamically adjusted based on the evaluation result, including: When the assessment result indicates that the risk is at a first risk level, increasing the frequency of virus scanning and malware detection on the storage space of the office device; Modifying the preset identity rule to improve the access rights to the intranet dedicated hard disk space; When the assessment result indicates that the risk is at a second risk level, the frequency of virus scanning and malware detection on the storage space of the office equipment is reduced; wherein the second risk level is lower than the first risk level.
[0012] According to the present invention, a method for adaptively switching between an external network and an internal network for office network also includes: Based on the feature information and the network feature library, a machine learning algorithm is used to learn historical network switching behaviors and sample data to predict the possibility of network switching in advance; Based on the predicted possibility of network switching, security detection is performed in advance or the intranet access record of the office equipment is cleared.
[0013] According to the present invention, a method for adaptively switching between an external network and an internal network for office network also includes: Obtaining environmental information of the location of the office equipment; wherein the environmental information includes geographical location, network signal strength, device information within a preset range, and network congestion; Based on the environmental information, determine whether there is a potential risk in the current network environment; If there is a potential risk, dynamically adjust the network switching strategy; Record the environmental information and potential risks of each network switch and generate a log.
[0014] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it implements any of the above-mentioned methods for adaptively switching between external and internal networks.
[0015] The present invention provides an office network switching method and device for adaptive external network and internal network. When the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, a security check is performed on the office equipment. When the security check passes, the office equipment is controlled to load a driver and network protocol dedicated to the internal network to access the internal network. When the comparison result indicates that the network connected to the office equipment is switched from the internal network to the external network, the internal network access record of the office equipment is cleared. When the clearing of the internal network access record is completed, the office equipment is controlled to access the external network, thereby realizing automatic and secure switching of the office network for adaptive external network and internal network, avoiding information leakage, and improving the security index of information in the internal network. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0017] Figure 1 It is a flowchart of an office network switching method for adaptive external network and internal network provided by an embodiment of the present invention; Figure 2 It is a schematic diagram of the structure of an office network switching device for adaptively switching between an external network and an internal network provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0018] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0019] Figure 1 The present invention provides a flow chart of an adaptive external network and internal network office network switching method provided in an embodiment of the present invention. The execution subject of the method can be a computer, a tablet computer, a smart wearable device, etc.
[0020] See also Figure 1 The office network switching method of adaptive external network and internal network may include the following steps.
[0021] Step 101: monitor the characteristic information of the network to which the office equipment is connected, and compare the characteristic information with a preset network characteristic library to obtain a comparison result; wherein the network characteristic library includes the IP segment of the Internet service provider, the public DNS, and the pre-entered intranet network identifier.
[0022] In this step, the characteristic information may refer to certain identifiable attributes of the network to which the office equipment is connected, for example, it may include the IP segment of the Internet service provider, the Public Domain Name System (Public DNS), and the network identifier, etc. The network characteristic library is a preset database that stores various characteristic information used to distinguish between the external network and the internal network, which may include the IP segment of the Internet service provider, the public DNS, and the network identifier of the internal network, etc. When the office equipment is connected to the network, its characteristic information will be monitored and extracted, and then compared with the data in the network characteristic library, and the comparison result will be used to determine whether the currently connected network is an external network or an internal network. The network identifier of the internal network may include the IP address segment, gateway, DNS server, subnet mask, and the identifier of the preset network device (such as the device name or MAC address of the router or switch), etc.
[0023] Step 102: When the comparison result indicates that the network to which the office equipment is connected is switched from the external network to the internal network, a security check is performed on the office equipment.
[0024] For example, assuming that the IP address of the external network is 203.0.113.45 and the IP address of the internal network is 192.168.1.100, if it is detected that the IP address of the office equipment changes from 203.0.113.45 (external network) to 192.168.1.100 (intranet), it can be determined that the office equipment has switched from the external network to the intranet.
[0025] For another example, when connected to the external network, office equipment usually uses a public DNS server, such as 8.8.8.8; when connected to the intranet, office equipment uses the intranet's dedicated DNS server, such as 192.168.1.1. If it is detected that the DNS server of the office equipment changes from 8.8.8.8 (external network) to 192.168.1.1 (intranet), it can be determined that the office equipment has switched from the external network to the intranet.
[0026] Step 103: After the security check is passed, the office equipment is controlled to load the intranet-specific driver and network protocol to access the intranet.
[0027] In this step, intranet-specific drivers refer to hardware drivers that are customized for the intranet environment to ensure that the device can run efficiently and securely in the intranet. These drivers are usually optimized for specific network hardware (such as network cards) to support special needs of the intranet, such as higher security and specific network configurations. For example, Intel Network Adapter Driver: This is a driver designed for Intel network cards to ensure high performance and stability of network cards in the intranet. For example, Intel Network Adapter Driver can support specific intranet features such as VLAN (Virtual Local Area Network) and QoS (Quality of Service) settings. For example, Custom Network Adapter Driver: Enterprises may develop customized network adapter drivers based on their own intranet security needs. These drivers can include additional security features such as data encryption and access control.
[0028] Intranet-specific network protocols refer to specific network communication protocols used in the intranet environment, which can provide higher security, optimized performance, and specific functional support. For example, IPSec (Internet Protocol Security): IPSec is a protocol used to protect IP communications, ensuring the secure transmission of data in the intranet through encryption and authentication technology. IPSec is often used in VPN (virtual private network) connections in the intranet to ensure the confidentiality and integrity of data. For example, L2TP (Layer 2 Tunneling Protocol): L2TP is another protocol used to create VPN tunnels, which is often used in conjunction with IPSec to provide a higher level of security. For example, custom protocols: Enterprises may develop custom network protocols to meet specific intranet needs. For example, an enterprise may design a protocol for internal communications to optimize data transmission efficiency and security.
[0029] Step 104: When the comparison result indicates that the network to which the office equipment is connected is switched from the intranet to the extranet, clear the intranet access record of the office equipment.
[0030] The situation of switching the network from the intranet to the extranet can refer to the situation of switching the network from the extranet to the intranet in the aforementioned steps, which will not be repeated here.
[0031] Step 105: When the cleaning of the intranet access records is completed, control the office equipment to access the external network.
[0032] In this embodiment, when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, a security check is performed on the office equipment. When the security check passes, the office equipment is controlled to load the driver and network protocol dedicated to the internal network to access the internal network. When the comparison result indicates that the network connected to the office equipment is switched from the internal network to the external network, the internal network access record of the office equipment is cleared. When the clearing of the internal network access record is completed, the office equipment is controlled to access the external network, thereby realizing automatic and secure switching of the office network that is adaptive to the external network and the internal network, which can avoid information leakage and improve the security index of information in the internal network.
[0033] In one embodiment of this specification, performing security detection on office equipment includes: Suspending the network data interaction process of the office equipment, wherein the network data interaction process may include at least one of the following: network upload and download process, file sharing process, synchronization service process, and remote desktop connection process; Multi-engine scanning is used, combined with a real-time updated virus signature library and behavior analysis algorithm, to perform virus detection and malware detection on the storage space of office equipment; the storage space may include at least one of the following: memory, cache and hard disk, and the malware may include at least one of the following: viruses, Trojans, worms and spyware.
[0034] In this embodiment, for example, assume that a company employee carries a laptop computer back to the company's intranet environment from an external network (such as a coffee shop's Wi-Fi). In order to ensure that the device does not introduce security risks when it is connected to the intranet, it is necessary to perform security detection on the device. The network data interaction processes of office equipment include network upload and download processes, file sharing processes, synchronization service processes, and remote desktop connection processes. When the security detection starts, these processes are automatically suspended to prevent potential malicious data transmission or the spread of malware.
[0035] Use a multi-engine scanning tool (such as integrating different antivirus engines such as Avast and Kaspersky) to perform a comprehensive scan of the device. Combined with the real-time updated virus signature library, scan the device's storage space (including memory, cache, and hard disk). For example, if a Trojan program is detected in the device's memory, the signature library records the Trojan's feature information, and the scanning tool identifies and reports the Trojan. Use behavioral analysis algorithms to detect whether there are abnormal behaviors in programs running on the device, for example, a program attempts to frequently access suspicious addresses on the external network, or attempts to modify critical system files. Generally, an access frequency threshold can be set, and if the access frequency threshold is exceeded, it can be defined as frequent access. Critical files can be defined based on actual conditions.
[0036] This embodiment avoids potential malicious data transmission or malware propagation during security detection by suspending the network data interaction process. It uses multi-engine scanning combined with a real-time updated virus signature library and behavior analysis algorithm to comprehensively detect viruses, Trojans, worms and spyware in the device storage space, thereby effectively preventing malware from entering the intranet.
[0037] In one embodiment of the present specification, clearing the intranet access records of office equipment includes at least one of the following: Delete the temporary authorization file on the intranet; Clear cached intranet pages; Shut down intranet-related applications and services; Cryptographically erase temporary information in the relevant storage area.
[0038] In this embodiment, temporary means that it is valid within a preset time range, and it becomes invalid after exceeding the set time range. Those skilled in the art can understand the specific meaning of temporary. Intranet temporary authorization files refer to temporary authorization credentials generated in an intranet environment to allow users or devices to access restricted resources (such as files, services or network areas) within a specific time. These files usually contain the user's access rights, validity period and related security information to ensure the legality and security of access. For example, a project team may need to temporarily access the company's internal financial data. By generating a temporary authorization file, it can be ensured that the data is securely accessed and used during the project. Temporary authorization files can be generated through a secure authentication system (such as STS, Security Token Service).
[0039] Intranet-related applications and services can be set up according to actual conditions, for example, intranet file sharing services, intranet mail clients, intranet printing services, intranet database clients, etc.
[0040] This embodiment protects the privacy and security of the intranet by cleaning up the intranet access records to prevent the intranet information from being leaked in the external network. Deleting temporary authorization files and closing intranet-related applications can reduce the risk of the device being attacked in the external network. Clearing cached intranet pages and encrypting and erasing temporary information ensures that the device complies with the company's security policy when switching to the external network.
[0041] In an embodiment of the present specification, when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, the method further includes: Automatically start a pre-established virtual desktop environment dedicated to the intranet; the virtual desktop environment is isolated from the external network environment and supports simultaneous access by multiple users; Monitor and record the operation records of each user; When the comparison result indicates that the network to which the office equipment is connected is switched from the intranet to the extranet, it also includes: Close the virtual desktop environment and encrypt and store the recorded operation records.
[0042] In this embodiment, the virtual desktop environment can be created in a variety of ways. For example, first, select a suitable virtualization platform such as VMware, Citrix or Microsoft Hyper-V according to the needs, install the corresponding virtualization software on the server, and configure the necessary hardware resources. Next, create a virtual machine template, install the operating system and perform basic configuration to ensure that it meets the needs of intranet use. Then, configure network connections and security policies to ensure that the virtual desktop environment is isolated from the external network while ensuring the security of the intranet. Finally, perform functional testing and performance optimization to ensure stable operation of the system.
[0043] When the user switches the device to the intranet, he can log in to the virtual desktop environment to securely access intranet resources and carry out work. The virtual desktop environment ensures that intranet resources are completely isolated from the external network environment to prevent potential threats to the intranet from the external network. After the virtual desktop environment is closed, intranet resources cannot be accessed by the external network, further enhancing the security of the intranet. Encrypted storage operation records ensure the security and confidentiality of sensitive data and prevent data leakage.
[0044] In some other embodiments of this specification, monitoring and recording the operation records of each user may also include: Behavior analysis and risk warning: Intelligent analysis of recorded user operations to identify abnormal operations or potential risk behaviors. For example, by analyzing the frequency of user access to sensitive data, abnormal data transmission patterns, or unauthorized software installation, it can be determined whether there are illegal operations or security threats.
[0045] Generate behavior analysis reports: Based on the above analysis, user behavior analysis reports are generated regularly for administrators to review and evaluate intranet usage. The report content includes the core data types accessed by users, operation frequency, violation records, etc., to help administrators discover potential security risks in a timely manner.
[0046] Dynamically adjust monitoring strategies: Based on the above analysis results, dynamically adjust monitoring strategies and security detection strength. For example, for users who frequently access sensitive data, increase the frequency and depth of monitoring; for low-risk users, appropriately reduce the intensity of monitoring to optimize resource allocation.
[0047] In this embodiment, through functions such as behavioral analysis and risk warning, dynamic adjustment of monitoring strategies, and visual reporting, the security, monitoring efficiency, and management decision-making capabilities of the intranet are significantly improved, while the user experience is optimized and real-time response and compliance management are supported.
[0048] In an embodiment of the present specification, when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, the method further includes: Verify the identity of the user who accesses the dedicated hard disk space of the intranet. When the user identity meets the preset identity rules, the user identity is allowed to access the preset storage space in the dedicated hard disk of the intranet; wherein the preset storage space uses an encryption algorithm to encrypt and store the stored files; Access to the hard disk space dedicated to the external network is prohibited; When the comparison result indicates that the network to which the office equipment is connected is switched from the intranet to the extranet, it also includes: Prohibit access to preset storage space; When receiving a download instruction to download a file from the external network to a preset storage space, the file is stored in a preset isolation area; Perform virus and malware scans on files in quarantine; Store files detected by viruses and malware into the preset storage space.
[0049] In this embodiment, the preset identity rules can be set as needed, for example, they can include job level, years of service, performance level, authority level, etc. Through user identity authentication and encrypted storage technology, the security of intranet access is enhanced, and data leakage is effectively prevented. At the same time, it improves data management efficiency and device performance through dynamic permission adjustment and automatic optimization of network configuration. In addition, by monitoring and recording operations and encrypting and storing operation records, the audit and monitoring capabilities are improved, and the security and compliance of the intranet are further guaranteed. These measures not only optimize the user experience, but also ensure the stability and efficiency of the intranet environment, and meet the company's needs for data security and management.
[0050] Verify the identity of the user who accesses the dedicated hard disk space on the intranet, for example, by requiring the user to enter a username and password, or by using biometric technology (such as fingerprint or facial recognition) for identity authentication. The system will compare the entered identity information with the preset identity rules (such as employee permission lists, role assignments, etc.), and only users who meet the rules can access the preset storage space in the dedicated hard disk on the intranet.
[0051] Prohibit access to the external network dedicated hard disk space. For example, set the access permission of the external network dedicated hard disk space to "Prohibit", or limit access to specific hard disk partitions through network firewalls and access control policies.
[0052] When a download instruction is received to download a file from the external network to the preset storage space, the file is stored in a preset isolation area. For example, an isolation area (such as a special folder or storage partition) is set up. When an instruction to download a file from the external network to the internal network storage space is detected, the system will automatically store the file in the isolation area.
[0053] Perform virus and malware detection on files in quarantine, for example, use security scanning tools (such as antivirus software and malware detection tools) to scan files in quarantine. These tools can detect whether files contain viruses, Trojans, worms, or spyware based on real-time updated virus signature libraries and behavior analysis algorithms.
[0054] In an embodiment of the present specification, when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network, the method further includes: Detecting the external network usage behavior of the office equipment before switching; wherein the external network usage behavior includes at least one of the following: the type of website visited, the frequency of data transmission, and the source of file downloads; Conduct risk assessment on external network usage and obtain assessment results; Dynamically adjust security checks after intranet access based on assessment results; After controlling the office equipment to load the intranet-specific driver and network protocol, it also includes: Automatically optimize network configuration parameters based on the role of office equipment in the intranet and business requirements; network configuration parameters include network bandwidth, firewall rules and network paths.
[0055] In this embodiment, by detecting the use of office equipment in the extranet and conducting risk assessment, dynamic adjustment of intranet access security detection is achieved, thereby improving the security and flexibility of the intranet. It optimizes security policies based on the evaluation results, such as adjusting the virus detection frequency and access rights, and automatically optimizes network configuration parameters based on the role of the device in the intranet and business needs, further improving network performance and resource utilization efficiency. These measures not only enhance the protection capabilities of the intranet, but also ensure the security and efficiency of the device when switching between the intranet and the extranet, while reducing management costs and improving user experience.
[0056] Detecting extranet usage behavior: By installing behavior monitoring software on office equipment, the network activities of the equipment in the extranet environment are recorded, including the domain names of the websites visited, the frequency and amount of data transmission, the source of file downloads, and other information.
[0057] Risk assessment: Use the preset risk assessment model and analyze the behavior data. For example, behaviors such as visiting suspicious websites and frequently downloading files will be assigned higher risk values. The system evaluates the overall risk level based on these risk values. The risk assessment model can be a neural network-based model (such as BP neural network, RBF neural network); it can also be a machine learning-based model (such as random forest, support vector machine).
[0058] Dynamically adjust security detection: adjust security detection strategies based on risk assessment results. For example, for high-risk devices, increase virus scanning frequency and enable the first security check rule; for low-risk devices, enable the second security check rule or reduce the virus scanning frequency. The second security check rule has a lower detection intensity than the first security check rule.
[0059] Automatically optimize network configuration parameters: Adjust network configuration parameters based on the role of the device in the intranet (such as ordinary employees, administrators, etc.) and business needs. For example, more bandwidth can be allocated to business applications that require high bandwidth or employees with higher job levels, and firewall rules and network paths can also be adjusted based on security needs.
[0060] In one embodiment of the present specification, dynamically adjusting the security detection after intranet access based on the evaluation result includes: When the assessment result indicates that the risk is at the first risk level, increase the frequency of virus and malware detection on the storage space of office equipment; Modify the preset identity rules to increase access rights to the intranet dedicated hard disk space; When the assessment result indicates that the risk is at a second risk level, the frequency of virus scanning and malware detection on the storage space of the office equipment is reduced; wherein the second risk level is lower than the first risk level.
[0061] In this embodiment, the security and flexibility of the intranet are further improved through risk assessment and dynamic adjustment of security policies. Specifically, it dynamically adjusts the security detection strategy after intranet access based on the risk assessment results of the external network usage behavior, such as increasing or decreasing the frequency of virus detection and killing, adjusting access rights, etc. This not only enhances the protection capabilities of the intranet, but also enables the flexible adjustment of security measures according to the actual risk situation to avoid excessive or insufficient security detection, thereby optimizing resource utilization and user experience. When the risk assessment results show the first risk level, the preset identity rules may be temporarily modified to increase access rights to the dedicated hard disk space of the intranet. This dynamic adjustment can ensure that only users who have been more strictly verified can access sensitive data, thereby reducing potential risks.
[0062] In an embodiment of the present specification, the method for adaptively switching between an external network and an internal network also includes: Based on feature information and network feature library, machine learning algorithm is used to learn historical network switching behavior and sample data to predict the possibility of network switching in advance; Based on the predicted possibility of network switching, perform security checks in advance or clean up the intranet access records of office equipment.
[0063] In this embodiment, by learning historical data through machine learning algorithms, the system can predict the possibility of network switching in advance, so as to take proactive security measures, such as conducting security detection in advance or cleaning up intranet access records, to reduce potential security risks. Conducting security detection in advance can avoid delays caused by the detection process during the actual switching, and improve the overall efficiency of the device when switching between the intranet and the intranet.
[0064] In an embodiment of the present specification, the method for adaptively switching between an external network and an internal network for office network further includes: Obtaining environmental information about the location of office equipment; the environmental information includes geographic location, network signal strength, device information within a preset range, and network congestion; Based on the environmental information, determine whether there are potential risks in the current network environment; If there is a potential risk, dynamically adjust the network switching strategy; Record the environmental information and potential risks of each network switch and generate a log.
[0065] In this embodiment, by obtaining detailed environmental information, the security and stability of the current network environment can be evaluated in real time, and potential risks, such as network congestion or abnormal device access, can be discovered in a timely manner. Based on the environmental information and risk assessment results, the network switching strategy can be dynamically adjusted, such as delaying switching or strengthening security detection, to ensure the security and stability of the device during the switching process. The environmental information and potential risks of each network switching are recorded and logs are generated to facilitate subsequent audits and analysis, helping administrators better understand network switching behaviors and optimize security policies.
[0066] The present embodiment is described below by means of specific examples.
[0067] Scenario 1: Office equipment is inside the company. Environmental information includes the following: Geographical location: The office equipment is located in the office area within the company.
[0068] Network signal strength: The signal strength is good (for example, the Wi-Fi signal strength is -30dBm).
[0069] Device information within the preset range: There are other company internal devices (such as printers, servers, etc.) nearby.
[0070] Network congestion: Network traffic is normal and there is no congestion.
[0071] Judgment: Based on this information, the system determines that the current network environment is safe and reliable and there are no potential risks.
[0072] Policy adjustment: Due to the security of the environment, the system allows office equipment to switch to the intranet normally and load drivers and network protocols dedicated to the intranet.
[0073] Record log: The system records the environmental information and judgment results of this network switch, for example: Geographic location: within the company; Network signal strength: -30dBm; Peripheral equipment: printer, server; Network congestion: normal; Judgment result: safe; Network switching strategy: Switch to the intranet normally.
[0074] Scenario 2: Office equipment is in a public area (such as an airport). Environmental information includes the following: Geographical location: The office facilities are located in the airport terminal.
[0075] Network signal strength: The signal strength is medium (for example, the Wi-Fi signal strength is -50dBm).
[0076] Device information within preset range: There are many unfamiliar devices around (such as other passengers' mobile phones, tablets, etc.).
[0077] Network congestion: Network traffic is extremely high and there may be congestion.
[0078] Judgment: Based on this information, the system determines that the current network environment has a high risk. For example, the public network is vulnerable to attacks and the surrounding devices may contain malware.
[0079] Strategy Adjustment: The system dynamically adjusts the network switching strategy: Temporarily prohibit office devices from switching to the intranet until users switch to a more secure network (such as a company VPN).
[0080] Remind users that the current network environment is not secure and it is recommended to use an encrypted connection.
[0081] Conduct emergency security checks on office equipment to ensure that they are not infected.
[0082] Record log: The system records the environmental information and judgment results of this network switch, for example: Geographical location: Airport terminal; Network signal strength: -50dBm; Surrounding equipment: A large number of unfamiliar equipment; Network congestion: extremely high traffic; Judgment result: high risk; Network switching policy: prohibit switching to the intranet and remind users to use encrypted connections.
[0083] In some other embodiments of the present specification, the hardware layer of the office equipment may include: High-performance multi-core processors, such as the Kunpeng series and Feiteng series processors; these processors are based on independently developed architectures and have powerful data processing capabilities. They can quickly respond to various complex computing requirements when the system switches between internal and external networks, such as security scanning, encryption and decryption operations, and multi-tasking. Its advanced architecture design ensures that when running multiple office software and performing network switching operations at the same time, the system remains smooth and stable without any lag. Compared with imported CPUs, domestically produced processors have significantly improved security performance, avoiding known foreign chip security vulnerabilities from the hardware bottom layer, and have built-in autonomous and controllable security protection mechanisms, such as Trusted Execution Environment (TEE) technology, which can effectively prevent malware attacks and data theft, providing a more reliable hardware foundation for internal and external network office work.
[0084] Large capacity and high-speed memory, such as 16GB or 32GB DDR4 memory; during the switching process between the internal and external networks, a large number of temporary files, process data, etc. need to be temporarily stored. Sufficient memory capacity can avoid data loss or system crashes caused by insufficient memory. High-speed memory read and write speed can speed up the operation efficiency of security scanning programs and encryption and decryption processes, and reduce switching waiting time.
[0085] Graphics card chips, such as Jingjiawei series graphics card chips; The network interface controller integrates a Gigabit Ethernet interface and a wireless network card of the latest Wi-Fi standard. The Gigabit Ethernet interface is used to stably connect to the enterprise intranet to meet the needs of large data transmission in the intranet, such as accessing the internal servers and databases of the enterprise to obtain confidential information, etc., with high-speed and stable transmission. The wireless network card allows employees to flexibly access the Internet in an extranet environment, obtain public information at any time, and communicate and collaborate online. The network interface controller has an intelligent switching function. According to the instructions of the network monitoring module, it automatically switches between different network interfaces to ensure the timeliness and accuracy of the internal and external network connections, and automatically adjusts the network configuration parameters during the switching process to ensure network connectivity.
[0086] Trusted Platform Module (TPM) is used to securely store sensitive information such as system encryption keys and digital certificates. Compared with pure software encryption, the hardware encryption feature based on TPM greatly improves the security of keys, preventing hackers from stealing keys through software vulnerabilities, thereby ensuring the confidentiality of files stored in the secure space. When users perform intranet identity authentication, TPM works together to verify the legitimacy of authentication devices such as digital certificate USB flash drives, laying a solid security foundation for the entire office system.
[0087] Hybrid storage architecture, including hard disk dedicated to external network and hard disk dedicated to internal network; among them, hard disk dedicated to external network: use high-speed and large-capacity solid-state hard disk to store various applications, temporary files, cached data and ordinary data downloaded from external network used by employees in external network environment, etc. This hard disk is completely isolated from the internal network, eliminating any interference of potential risks of external network to internal network data. Even if the external network is attacked maliciously, infected with viruses or malware, it cannot affect the data in the hard disk dedicated to internal network, ensuring the security of internal network data. Hard disk dedicated to internal network: use enterprise-level solid-state hard disk with high reliability and high security, specially used to store mobile files, core confidential data of enterprises and various types of internal network security files. Its hardware design has multiple protection mechanisms, such as anti-electromagnetic interference, data encryption chip, etc., to further enhance the security of internal network data storage. When the hard disk dedicated to internal network is connected to the system, it needs to go through a strict identity authentication process. Only through the authentication key or digital certificate authorization pre-set by the enterprise network administrator can the hard disk work normally, effectively preventing illegal access and data theft.
[0088] The above-mentioned domestically produced graphics card chips may have the following characteristics: High-resolution dual-channel output support: The graphics card must have at least two DisplayPort interfaces or HDMI interfaces, and be able to simultaneously output 4K and above high-resolution image signals to ensure clear and delicate split-screen display effects on the same monitor. This allows employees to open the external network desktop window and the internal network desktop window on the same screen at the same time, and the image quality of both windows can meet professional office needs, making it easy to quickly compare information, collaborate, and improve office efficiency. For example, when dealing with work scenarios involving comparative analysis of external network market research data and internal network product development materials, employees do not need to frequently switch screens or devices, and can intuitively operate in the high-resolution split-screen interface.
[0089] Multi-tasking graphics processing capability: It can smoothly run multiple graphics-intensive office applications, whether it is high-definition video conferencing software in the extranet environment, 3D model display web pages, or professional design software and geographic information systems (GIS) in the intranet environment, there will be no screen freezes or tearing. The graphics card has built-in large-capacity high-speed video memory, such as 8GB or higher GDDR6 video memory, and with the advanced GPU architecture, it ensures that sufficient graphics rendering resources are provided for different desktop windows during multi-tasking, ensuring the smooth operation of intranet and extranet office applications.
[0090] Security enhancement features: Compared with imported graphics chips, domestic graphics chips are designed with greater emphasis on security. An encryption module is built into the hardware to encrypt the transmission and storage of graphics data to prevent data from being stolen or tampered with during processing. At the same time, it has an access control mechanism so that only authorized applications can call graphics resources, further improving the overall security of the system and effectively resisting external malicious attacks that target graphics card vulnerabilities.
[0091] In this embodiment, all hardware can be domestically produced hardware to improve security.
[0092] In some other embodiments of this specification, the method further includes: Real-time monitoring and analysis of user operation habits: Build a personalized user behavior model by collecting and analyzing user operation data on office devices (such as application usage frequency, file access patterns, etc.).
[0093] Dynamically adjust network policies based on user behavior models: Based on the above user behavior models, the system can predict changes in user network needs and make network switching decisions in advance. For example, when a user is about to start a task that requires high security, the system automatically switches the network from the external network to the internal network.
[0094] Personalized configuration recommendations: Provide customized network configuration recommendations for different users to improve work efficiency and security. For example, for users who often handle sensitive information, the system will recommend higher network security settings.
[0095] In some other embodiments of this specification, the method further includes: Monitor and analyze user behavior of office equipment in real time and extract user behavior characteristics, including but not limited to user login time, login location, operation frequency, file access mode, etc.; Based on user behavior characteristics and the preset user behavior model, determine whether the user behavior is abnormal; If user behavior is judged to be abnormal, dynamically adjust security policies, including but not limited to: Suspend or limit a user's network access rights; Conduct more stringent security checks on users’ devices; Require users to perform a second authentication step; Record abnormal behaviors and their handling results, and generate security reports.
[0096] In some other embodiments of this specification, the method further includes: Use blockchain technology to build a decentralized trusted network switching platform, which records detailed information of each network switch through a distributed ledger, including device authentication, network environment characteristics, security detection results, and data access records; Utilize the immutability and transparency of blockchain to ensure the security and traceability of the network switching process; Smart contracts can automatically execute preset security policies and data access rules, such as automatically triggering security checks or restricting access rights when potential risks are detected, thereby improving the automation and credibility of the system while ensuring the security of network switching.
[0097] The present solution is described below through a specific example.
[0098] System initialization: When the enterprise network administrator deploys the personal all-in-one machine for the first time, he / she configures the intranet feature library according to the enterprise intranet architecture, makes adaptability adjustments according to the performance requirements of the domestic graphics card chip, determines the relevant parameter configuration of the domestic CPU processor, sets basic security information such as security scanning parameters and encryption key derivation rules, and creates an intranet identity authentication account password for employees or issues a digital certificate USB flash drive. At the same time, the internal and external network independent physical isolation hard disks are initialized and configured, and key parameters such as their respective access rights and authentication methods are set. When an employee logs in to the external network environment for the first time, the system automatically completes the hardware device feature code collection and initializes each module of the security middleware layer.
[0099] Daily office use: When employees work on the extranet, they can run all kinds of extranet applications normally, and the data is stored on the extranet dedicated hard disk. When it is necessary to switch to the intranet to process work, such as accessing the company's internal business system or obtaining intranet files, the network monitoring module responds quickly and triggers the switching process. After the switch is completed, employees can access files in the secure space through identity authentication in the intranet environment to perform office operations. At this time, both read and write operations are for the intranet dedicated hard disk. After completing the intranet work and returning to the extranet, the system automatically cleans up the traces to ensure that the internal and external network environments do not interfere with each other.
[0100] Security maintenance and updates: The system automatically updates the external network signature database regularly (e.g., weekly) to cope with the ever-changing network environment of the Internet. Enterprise network administrators can update the key security configurations such as the internal network signature database and encryption algorithm strength from time to time according to security needs, and upgrade and maintain the firmware of the independent physical isolation hard disks of the internal and external networks to ensure that the office system continues to maintain a high level of security.
[0101] The personal all-in-one computer office system invented above can effectively solve the security problem of employees in the process of switching between internal and external networks, and provide reliable protection for corporate office.
[0102] Based on the same general inventive concept, the present invention also protects an office network switching device that is adaptive to external networks and internal networks, such as Figure 2 Show, Figure 2 The present invention provides an adaptive external network and internal network office network switching device. The adaptive external network and internal network office network switching device provided by the present invention is described below. The adaptive external network and internal network office network switching device described below and the adaptive external network and internal network office network switching method described above can be referred to each other.
[0103] The office network switching device capable of adaptively switching between external network and internal network comprises a monitoring and comparison module 201 , a first detection module 202 , an internal network switching module 203 , a second detection module 204 and an external network switching module 205 .
[0104] The monitoring and comparison module 201 is used to monitor the characteristic information of the network to which the office equipment is connected, and compare the characteristic information with a preset network characteristic library to obtain a comparison result; wherein the network characteristic library includes the IP segment of the Internet service provider, the public DNS, and the pre-entered intranet network identifier; The first detection module 202 is used to perform security detection on the office equipment when the comparison result indicates that the network connected to the office equipment is switched from the external network to the internal network; The intranet switching module 203 is used to control the office equipment to load the intranet-specific driver and network protocol to access the intranet after the security check passes; The second detection module 204 is used to clear the intranet access record of the office equipment when the comparison result indicates that the network connected to the office equipment is switched from the intranet to the extranet; The external network switching module 205 is used to control the office equipment to access the external network when the internal network access record clearing is completed.
[0105] Figure 3 Schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. Figure 3 As shown, the electronic device may include: a processor 310, a communication interface 320, a memory 330 and a communication bus 330, wherein the processor 310, the communication interface 320 and the memory 330 communicate with each other through the communication bus 330. The processor 310 may call the logic instructions in the memory 330 to execute the office network switching method of the adaptive external network and the internal network.
[0106] In addition, the logic instructions in the above-mentioned memory 330 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0107] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the adaptive external network and internal network office network switching method provided by the above methods.
[0108] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the office network switching method for adaptive external network and internal network provided by the above methods.
[0109] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0110] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0111] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for adaptively switching between external and internal office networks, characterized in that: include: Monitor the characteristic information of the network to which the office equipment is connected, and compare the characteristic information with a preset network characteristic library to obtain a comparison result; wherein the network characteristic library includes the IP segment of the Internet service provider, the public DNS, and the pre-entered intranet network identifier; When the comparison result indicates that the network to which the office equipment is connected is switched from an external network to an internal network, a security check is performed on the office equipment; When the security check is passed, the office equipment is controlled to load a driver and network protocol dedicated to the intranet to access the intranet; When the comparison result indicates that the network to which the office device is connected is switched from the intranet to the extranet, clearing the intranet access record of the office device; When the cleaning of the intranet access records is completed, the office equipment is controlled to access the external network.
2. The method for adaptively switching between external and internal office networks according to claim 1, characterized in that: The security detection of the office equipment includes: Suspending the network data interaction process of the office equipment, wherein the network data interaction process includes: network upload and download process, file sharing process, synchronization service process, and remote desktop connection process; Multi-engine scanning is used, combined with a real-time updated virus signature library and behavior analysis algorithm, to perform virus detection and malware detection on the storage space of the office equipment; wherein the storage space includes memory, cache and hard disk, and the malware includes: viruses, Trojans, worms and spyware.
3. The method for adaptively switching between external and internal office networks according to claim 1, characterized in that: The cleaning of the intranet access records of the office equipment includes: Delete the temporary authorization file on the intranet; Clear cached intranet pages; Shut down intranet-related applications and services; Cryptographically erase temporary information in the relevant storage area.
4. The method for adaptively switching between external and internal office networks according to claim 1, characterized in that: When the comparison result indicates that the network connected to the office equipment is switched from an external network to an internal network, the method further includes: Automatically start a pre-established virtual desktop environment dedicated to the intranet; wherein the virtual desktop environment is isolated from the extranet environment and supports simultaneous access by multiple users; Monitor and record the operation records of each user; When the comparison result indicates that the network to which the office equipment is connected is switched from an intranet to an extranet, the method further includes: The virtual desktop environment is closed, and each recorded operation record is encrypted and stored.
5. The method for adaptively switching between external and internal office networks according to claim 1, characterized in that: When the comparison result indicates that the network connected to the office equipment is switched from an external network to an internal network, the method further includes: Verify the identity of the user who accesses the intranet dedicated hard disk space, and when the user identity meets the preset identity rules, allow the user identity to access the preset storage space in the intranet dedicated hard disk; wherein the preset storage space uses an encryption algorithm to encrypt and store the stored files; Prohibit access to external network dedicated hard disk space; When the comparison result indicates that the network to which the office equipment is connected is switched from an intranet to an extranet, the method further includes: Prohibiting access to the preset storage space; When receiving a download instruction to download a file from the external network to the preset storage space, storing the file in the preset isolation area; Perform virus scan and malware detection on the files in the quarantine area; The files detected after virus removal and malware detection are stored in the preset storage space.
6. The method for adaptively switching between external and internal office networks according to claim 5, characterized in that: When the comparison result indicates that the network connected to the office equipment is switched from an external network to an internal network, the method further includes: Detecting the external network usage behavior of the office equipment before switching; wherein the external network usage behavior includes the type of website visited, the frequency of data transmission, and the source of file downloads; Conducting a risk assessment on the external network usage behavior and obtaining an assessment result; Dynamically adjust the security detection after intranet access based on the evaluation results; After controlling the office equipment to load the intranet-specific driver and network protocol, the method further includes: Automatically optimize network configuration parameters according to the role and business requirements of the office equipment in the intranet; wherein the network configuration parameters include network bandwidth, firewall rules and network paths.
7. The method for adaptively switching between external and internal office networks according to claim 6, characterized in that: Dynamically adjust the security detection after intranet access based on the evaluation results, including: When the assessment result indicates that the risk is at a first risk level, increasing the frequency of virus scanning and malware detection on the storage space of the office device; Modifying the preset identity rule to improve the access rights to the intranet dedicated hard disk space; When the assessment result indicates that the risk is at a second risk level, the frequency of virus scanning and malware detection on the storage space of the office equipment is reduced; wherein the second risk level is lower than the first risk level.
8. The method for adaptively switching between external and internal office networks according to claim 1, characterized in that: Also includes: Based on the feature information and the network feature library, a machine learning algorithm is used to learn historical network switching behaviors and sample data to predict the possibility of network switching in advance; Based on the predicted possibility of network switching, security detection is performed in advance or the intranet access record of the office equipment is cleared.
9. The method for adaptively switching between external and internal office networks according to claim 1, characterized in that: Also includes: Obtaining environmental information of the location of the office equipment; wherein the environmental information includes geographical location, network signal strength, device information within a preset range, and network congestion; Based on the environmental information, determine whether there is a potential risk in the current network environment; If there is a potential risk, dynamically adjust the network switching strategy; Record the environmental information and potential risks of each network switch and generate a log.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method for adaptively switching between an external network and an internal network as described in any one of claims 1 to 9 is implemented.