Data Detection System for Physically Isolated Network

By setting up storage servers and edge gateways in physically isolated network shooting ranges, using one-way data transmission and encrypted tunneling technology, the problem of high resource costs in the existing technology is solved, and secure and low-cost data detection is achieved.

CN119996089BActive Publication Date: 2025-07-22PENG CHENG LAB
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510466557.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-22
Estimated Expiration
2045-04-15

Smart Images

  • Figure CN119996089B_ABST
    Figure CN119996089B_ABST
Patent Text Reader

Abstract

The data detection system for a physically isolated network proposed in the embodiments of this application includes: multiple network groups, each network group includes multiple network devices and data collectors. The network devices include at least one of servers, security devices, routing, and switching network devices. Data between every two network groups is not interoperable. A corresponding storage server and an edge gateway are provided at the edge of each network group. The data collector is used to collect the network monitoring data of multiple network devices in the corresponding network group in real time, and unidirectionally transmit the network monitoring data to the monitoring service program of the corresponding edge gateway, and then the monitoring service program remotely persists it to the storage server; a central monitoring server, which is used to read the network monitoring data in the associated storage server from the edge gateway of each network group, while improving the security of data collection in a physically isolated network range, and also reducing the resource cost of deploying the data detection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and particularly to a data detection system for physically isolated networks. Background Art

[0002] To improve the security in daily network communication, some virtualization technologies for network space simulation, such as network ranges, have been generated and developed accordingly. In these virtual networks, simulation attacks and defense measures are carried out to improve the defense means and intensity of defense measures in the daily actual communication network. To further improve the antagonism of simulated network attack and defense in the virtual network space and ensure the security of the infrastructure in the network range, usually each network therein is physically isolated, that is, the network is physically divided into parts that are not directly connected to each other to enhance data security and system reliability. However, this deployment method of physically isolated network ranges usually requires a separate set of supervision systems to be maintained for each isolated network, resulting in a relatively large resource cost for deploying the detection system. Summary of the Invention

[0003] The embodiments of this application provide a data detection system for physically isolated networks, which can reduce the resource cost of deploying the data detection system in a physically isolated network range.

[0004] To achieve the above object, a first aspect of the embodiments of this application proposes a data detection system for physically isolated networks, the system includes:

[0005] Multiple network groups, each network group includes multiple network devices and data collectors, the network devices include at least one of servers, security devices, routing and switching network devices, and the data between every two network groups is not interoperable;

[0006] A corresponding storage server and an edge gateway are provided at the edge of each network group;

[0007] The data collector is used to collect the network monitoring data of the multiple network devices in the corresponding network group in real time, and unidirectionally transmit the network monitoring data to the monitoring service program of the corresponding edge gateway, and then remotely persist it to the storage server by the monitoring service program;

[0008] A central monitoring server, the central monitoring server is used to read the network monitoring data in the associated storage server from the edge gateway of each network group.

[0009] In some embodiments, the data detection system further includes a central gateway associated with the central monitoring server;

[0010] Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the central monitoring server is further configured to generate a self-signed certificate between the central gateway and the edge gateway, send the self-signed certificate to the central gateway, and send the self-signed certificate to the edge gateway through an offline medium.

[0011] In some embodiments, before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the edge gateway further include:

[0012] Obtain the self-signed certificate and verify the self-signed certificate to obtain a certificate verification result;

[0013] When the certificate verification result indicates that the self-signed certificate is correct, parse the self-signed certificate to obtain the central gateway identifier and the identity authentication information of the edge gateway;

[0014] Based on the central gateway identifier and the identity authentication information, establish an encrypted tunnel between the edge gateway and the central gateway;

[0015] Based on the central gateway identifier and the identity authentication information, generate an encryption key.

[0016] In some embodiments, when the edge gateway executes the step of generating an encryption key based on the central gateway identifier and the identity authentication information, the execution steps of the edge gateway include:

[0017] Perform a hash process on the central gateway identifier to generate an initial key;

[0018] Perform a normalization splicing process on the edge gateway identifier and the identity authentication information of the edge gateway to generate a dynamic factor;

[0019] Perform a hash process on the dynamic factor to generate a dynamic key;

[0020] Perform an exclusive OR confusion process on the dynamic key and the initial key to generate the encryption key.

[0021] In some embodiments, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the edge gateway include:

[0022] Obtain the network monitoring data acquisition request sent by the central gateway;

[0023] Determine target network monitoring data from the network monitoring data based on the network monitoring data acquisition request, and encrypt the target network monitoring data based on the encryption key to generate encrypted data and corresponding authentication tags;

[0024] Generate combined encrypted network monitoring data based on the combination of the encrypted data and the authentication tags, and transmit the combined encrypted network monitoring data through the encrypted tunnel to the central gateway, so that the central gateway decrypts the combined encrypted network monitoring data and then transmits the target network monitoring data to the central monitoring server.

[0025] In some embodiments, when the edge gateway executes the step of encrypting the target network monitoring data based on the encryption key to generate encrypted data and corresponding authentication tags, the execution steps include:

[0026] Obtain a non-linear mapping table and generate a dislocation processing identifier;

[0027] Based on the non-linear mapping table, perform non-linear substitution on the target network monitoring data to generate non-linear network monitoring data;

[0028] Based on the dislocation processing identifier and the encryption key, perform dislocation encryption processing on the non-linear network monitoring data to obtain the encrypted data;

[0029] Generate the authentication tag based on the mapping table identifier of the non-linear mapping table and the dislocation processing identifier.

[0030] In some embodiments, the dislocation processing identifier includes a row shift identifier and a column mixing identifier. When the edge gateway executes the step of performing dislocation encryption processing on the non-linear network monitoring data based on the dislocation processing identifier and the encryption key to obtain the encrypted data, the execution steps include:

[0031] Select target row data from the non-linear network monitoring data based on the row shift identifier and perform row shift to obtain first shifted data;

[0032] Obtain the mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform matrix operation on the target column data and the mixing matrix to obtain second shifted data;

[0033] Perform exclusive OR processing on the second shifted data and the encryption key to obtain the encrypted data.

[0034] In some embodiments, when the central monitoring server reads network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the central monitoring server include:

[0035] Send a network monitoring data acquisition request to the central gateway;

[0036] Obtain the target network monitoring data sent by the central gateway according to the network monitoring data acquisition request.

[0037] In some embodiments, when the central monitoring server reads network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the central gateway include:

[0038] Receive the network monitoring data acquisition request sent by the central monitoring server;

[0039] Send the central gateway identifier and the network monitoring data acquisition request to the edge gateway through the encrypted tunnel;

[0040] Obtain the combined encrypted network monitoring data sent by the edge gateway according to the network monitoring data acquisition request;

[0041] Perform decoding processing on the encrypted data in the combined encrypted network monitoring data based on the authentication label in the combined encrypted network monitoring data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request;

[0042] Send the target network monitoring data to the central monitoring server.

[0043] In some embodiments, when the data collector collects network monitoring data of the multiple network devices in the corresponding network group in real time, the execution steps include:

[0044] When the current moment reaches the preset acquisition period, determine at least one target data type corresponding to the preset acquisition period;

[0045] Collect real-time type data corresponding to all the target data types from the multiple network devices in the network group;

[0046] Obtain the network monitoring data based on all the real-time type data.

[0047] In some embodiments, after the central monitoring server reads network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps further include:

[0048] Integrate all the network monitoring data to obtain integrated network monitoring data;

[0049] Aggregate and analyze the integrated network monitoring data to obtain analyzed and processed data, and display the analyzed and processed data in the form of charts.

[0050] The data detection system for a physically isolated network provided by an embodiment of the present application includes: a plurality of network groups, each network group includes a plurality of network devices and data collectors, the network devices include at least one of a server, a security device, a routing and switching network device, data between every two network groups is not interoperable, a corresponding storage server and an edge gateway are arranged at the edge of each network group, the data collector is used to collect the network monitoring data of multiple network devices in the corresponding network group in real time, and unidirectionally transmit the network monitoring data to the monitoring service program of the corresponding edge gateway, and then remotely persist it to the storage server by the monitoring service program; a central monitoring server, the central monitoring server is used to read the network monitoring data in the associated storage server from the edge gateway of each network group. In the embodiment of the present application, a storage server and an edge gateway are arranged in each network group corresponding to non-interoperable data, and then a data collector with a single acquisition function is used to collect data from multiple network devices in the network group, and the collected network monitoring data is transmitted unidirectionally through the edge gateway to the storage server in the network group for persistent storage by using the push method, and finally the central monitoring server uniformly reads the data from the edge gateways of each network group through the central gateway, so as to use the same data detection system to detect data for multiple physically isolated network groups together, and use the unidirectional data transmission process to prevent the monitoring service program of the edge gateway from accessing the network devices in the network group, thereby improving the security of data collection in the physically isolated network range while reducing the resource cost of deploying the data detection system.

[0051] Other features and advantages of the present application will be described in the subsequent specification, and, in part, will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the specification, the claims and the drawings. Description of the Drawings

[0052] Figure 1 It is a schematic structural diagram of deploying multiple supervision systems in a network isolated network range provided by an embodiment of the present application.

[0053] Figure 2 It is a schematic structural diagram of a data detection system for a physically isolated network provided by another embodiment of the present application.

[0054] Figure 3 It is a schematic diagram of a three-layer structure in a data detection system provided by another embodiment of the present application.

[0055] Figure 4 It is a flowchart of data collection by a data collector provided in another embodiment of the present application.

[0056] Figure 5 It is a flowchart of a central monitoring server sending a self-signed certificate to a central gateway and an edge gateway provided in another embodiment of the present application.

[0057] Figure 6 It is a flowchart of an edge gateway constructing an encryption tunnel and an encryption key provided in another embodiment of the present application.

[0058] Figure 7 It is a flowchart of an edge gateway generating an encryption key provided in another embodiment of the present application.

[0059] Figure 8 It is a flowchart of an edge gateway performing data encryption processing provided in another embodiment of the present application.

[0060] Figure 9 It is a flowchart of an edge gateway generating encrypted data and an authentication tag provided in another embodiment of the present application.

[0061] Figure 10 It is a flowchart of an edge gateway performing misaligned encryption processing using encrypted data provided in another embodiment of the present application.

[0062] Figure 11 It is a flowchart of a central monitoring server performing data encryption acquisition provided in another embodiment of the present application.

[0063] Figure 12 It is a flowchart of a central gateway performing data encryption acquisition provided in another embodiment of the present application.

[0064] Figure 13 It is a flowchart of a central monitoring server performing data integration and analysis provided in another embodiment of the present application.

[0065] Figure 14 It is a schematic diagram of the hardware structure of an electronic device provided in another embodiment of the present application. Detailed implementation manners

[0066] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.

[0067] It should be noted that although the functional modules are divided in the device schematic diagram and the logical sequence is shown in the flowchart, in some cases, the steps shown or described can be executed in a different module division from that in the device or a different sequence from that in the flowchart.

[0068] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.

[0069] To improve the security in daily network communication, some virtualization technologies such as network ranges for cyber space simulation have been generated and developed accordingly. In these virtual networks, simulation attacks and defense measures are carried out, so as to improve the defense means and intensity of defense measures in the daily actual communication network. To further improve the antagonism of simulation network attack and defense in the virtual cyber space and ensure the security of the infrastructure in the network range, usually each network therein is physically isolated, that is, the network is physically divided into parts that are not directly connected to each other to enhance data security and system reliability. Refer to Figure 1 , which is a schematic structural diagram of deploying multiple supervision systems in a physically isolated network range provided by an embodiment of this application. As Figure 1 shown in, this way of deploying the physically isolated network range usually requires a set of supervision systems to be maintained separately for each isolated network, resulting in a relatively large resource cost for deploying the detection system.

[0070] To reduce the resource cost of deploying the data detection system in the physically isolated network range, in each network group where data is not interoperable, the embodiment of this application is provided with a storage server and an edge gateway. Then, a data collector that realizes the acquisition function alone is used to collect data from multiple network devices in this network group, and the collected network monitoring data is transmitted to the storage server in this network group for persistent storage through the edge gateway by using the push method for one-way transmission. Finally, the central monitoring server uniformly reads data from the edge gateways of each network group through the central gateway, so as to realize the data detection of multiple physically isolated network groups by using the same data detection system, and by using the one-way data transmission process, the monitoring service program of the edge gateway cannot access the network devices in the network group, thereby improving the security of data acquisition in the physically isolated network range while reducing the resource cost of deploying the data detection system.

[0071] Next, the data detection system for the physically isolated network provided by the embodiment of this application will be further described. Refer to Figure 2 , which is a schematic structural diagram of a data detection system for a physically isolated network provided by an embodiment of this application. AsFigure 2 As shown, the physically isolated network consists of multiple network groups with non-interconnected data (such as Network Group 1, Network Group 2... Network Group N) and a central network. Among them, each network group includes multiple network devices and data collectors for data transmission. At the edge of each network group, an edge gateway and a storage server (such as Storage Server 1 in Network Group 1) are set up. The central network includes a central monitoring server and a central gateway, and the central gateway includes functions such as a central firewall and NAT.

[0072] Referring to Figure 3 , it is a schematic diagram of a three-layer structure in a data detection system provided by an embodiment of the present application. As Figure 3 shown, in this data detection system, it is divided into a three-layer structure, including an isolation network layer, an edge layer, and a central network layer. Among them, the isolation network layer is used to collect network monitoring data of internal devices in the isolation network; the edge layer is used to aggregate and store network monitoring data within the current isolation network; the central network layer is used to aggregate, analyze, and display network monitoring data of all isolation networks.

[0073] Among them, the isolation network layer includes multiple mutually isolated (i.e., non-interconnected data) network groups. The network group includes multiple network devices, which are usually servers, security devices, routing, and switching network devices. Data collectors are deployed on the network devices to be monitored within the isolation network of the network group, and the monitoring service addresses on the corresponding edge gateways are equipped. The data collectors unidirectionally parameterize the collected metric data to the edge layer at regular intervals or periodically, and store it on the storage server through the monitoring service program on the edge gateway.

[0074] In the edge layer, an edge gateway and a storage server are set up at the edge of each network group. A security control program and a monitoring service program are deployed on the edge gateway, and multiple repositories are deployed on the storage server in a cluster manner. The security control program on the edge gateway establishes an encrypted tunnel with the central gateway through a virtual interface. The monitoring service program on the edge gateway writes network monitoring data into the repository through the remote read-write interface of the repository. The monitoring service program is used to obtain, cache, and forward network monitoring data of the network group, and the security control program is used to ensure the security of monitoring data transmission between each network group and the central network.

[0075] Among them, the security control program deployed on the edge gateway includes an identity authentication module, an access control module, and a monitoring data encryption module. The identity authentication module is used to ensure that the central gateway corresponding to the authorized central monitoring server can access the monitoring service program on the edge gateway and extract the corresponding central gateway identifier and identity authentication information. The access control module is used to set the unidirectional transmission policy from the network device to the monitoring service program on the edge gateway and authorize the central gateway to access the monitoring service program on the edge gateway. The monitoring data encryption module is used to establish an encrypted tunnel from the edge gateway to the central gateway and encrypt the network monitoring data. The encrypted tunnels from the edge gateway to the central gateway corresponding to each network group are not interconnected and do not affect each other.

[0076] In the central network layer, a security control and monitoring service program is deployed on the central gateway, and a unified monitoring system is deployed on the central server. The central gateway provides a virtual interface to establish an encrypted tunnel with the edge gateway corresponding to each network group. The monitoring service program on the central gateway obtains the network monitoring data of all network groups through remote reading for aggregation analysis and presents it in a visual manner through the unified monitoring system.

[0077] The data collector corresponding to each network group is used to collect the network monitoring data during the data transmission process of multiple network devices in the network group in real time, and unidirectionally transmit the collected network monitoring data to the edge gateway in the network group, and the edge gateway transmits it to the associated storage server for persistent storage, so that the central monitoring server can subsequently read the network monitoring data in the network group from the edge gateway of each network group. Storage servers and edge gateways are set up in each network group where data is not interconnected. Then, a data collector with a single acquisition function is used to collect data from multiple network devices in the network group, and the collected network monitoring data is unidirectionally transmitted through the edge gateway to the associated storage server for persistent storage by using the push method. Finally, the central monitoring server reads the data from the edge gateways of each network group through the central gateway, so as to use the same data detection system to detect the data of multiple physically isolated network groups together, and use the unidirectional data transmission process to prevent the monitoring service program of the edge gateway from accessing the network devices in the network group. Thus, while improving the security of data collection in a physically isolated network range, the resource cost of deploying the data detection system is also reduced.

[0078] Among them, the data collector can be an open-source tool similar to telegraf or a self-developed agent. Then, configure the network monitoring data upload path in each data collector of the network group, that is, the remote write interface of the monitoring service program deployed on the edge gateway corresponding to the network group. The data collector regularly (or in real time) uploads the network monitoring data (such as CPU usage, memory occupancy, performance metrics, etc.) between network devices in the network group collected through this remote write interface of the monitoring service program to the edge gateway and transmits it to the corresponding storage server through the edge gateway for storage.

[0079] A remote repository is deployed on each storage server for storing the network monitoring data sent by the data collector. Configure the remote read-write module in the yaml configuration file of the monitoring service program of the edge gateway, and fill in the read-write interface of the remote repository in the read-write module. In addition, the monitoring service program of the edge gateway receives the collected network monitoring data uploaded from the data collectors in the network group, performs persistent storage, and writes it into the remote repository through the write interface of the remote repository.

[0080] Through the one-way NAT configuration of the monitoring service of the edge gateway, each network device in the network group can access the monitoring service program on the edge gateway and upload the collected network monitoring data to the monitoring service program component of the edge gateway, while the monitoring service program component of the edge gateway cannot access each network device in the network group. Such a setting ensures the security of network devices and reduces the network attack surface.

[0081] In some embodiments, taking Network Group 1 as an example, the monitoring service program deployed on the edge gateway in the network group can be one instance or composed of multiple instances, and each data collector is correspondingly associated with one monitoring service program of the edge gateway. Each data collector in Network Group 1 pushes the network monitoring data unidirectionally to the corresponding monitoring service program of the edge gateway after collecting the network monitoring data, so that the monitoring service program can transmit the network monitoring data to the associated storage server, so that the subsequent central monitoring server can read these network monitoring data from the storage server through the edge gateway.

[0082] Among them, when the data collector collects the network monitoring data of multiple network devices in the corresponding network group in real time, the execution steps include the following steps 401 to 403.

[0083] Step 401: When the current moment reaches the preset acquisition period, determine at least one target data type corresponding to the preset acquisition period.

[0084] Step 402: Collect real-time type data corresponding to all target data types from multiple network devices in the network group.

[0085] Step 403: Obtain network monitoring data based on all real-time type data.

[0086] The following is a detailed description of steps 401 to 403.

[0087] In some embodiments, when the data collector performs data detection, it can also perform periodic data collection according to the network changes in the network group, or perform periodic data acquisition according to the preset acquisition period set by the data period acquisition requirements of the central monitoring server, such as every five minutes, etc. When the clock in the data collector triggers the preset acquisition period at the current moment, the target data types to be collected in this preset acquisition period are determined through a predefined monitoring metric list (such as target_metrics.yaml), such as the CPU usage rate (cpu_usage), memory occupancy (mem_utilization) of each network device, the number of TCP connections (tcp_connections) between network devices, bandwidth utilization (bandwidth_usage), throughput, etc.

[0088] Then the data collector collects the real-time type data corresponding to these target data types at the current moment from all network devices in the network group, and uses these real-time type data as network monitoring data, so as to transmit these network monitoring data to the storage server associated with the edge gateway for persistent storage.

[0089] Through the above steps 401 to 403, by using the preset periodic data acquisition and only collecting key metrics, the transmission of invalid data is reduced, and the reliability of data acquisition is improved. Moreover, by using the preset acquisition period and the corresponding target type data that can be dynamically updated, flexible adaptation to new monitoring requirements can be achieved, thereby improving the data acquisition flexibility of the data detection system.

[0090] In some embodiments, in addition to deploying a monitoring service program on the edge gateway of each network group, in order to further improve the data transmission security of the data detection system for physically isolated networks, and thus improve the data confidentiality in the simulated attack and defense scenarios in the network range, it is also necessary to build an encrypted tunnel between the edge gateway and the central gateway, and generate an encrypted key, so that the encrypted key can be used to encrypt the network monitoring data subsequently, and the encrypted network monitoring data can be securely transmitted through this highly secure encrypted tunnel.

[0091] The following will further describe how to build an encrypted tunnel and generate an encrypted key between the central gateway and the edge gateway.

[0092] Among them, before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateways of each network group, the execution steps of the central monitoring server further include the following step 501.

[0093] Step 501: Generate a self-signed certificate between the central gateway and the edge gateways, send the self-signed certificate to the central gateway, and send the self-signed certificate to the edge gateways through an offline medium.

[0094] The following is a detailed description of step 501.

[0095] In some embodiments, before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateways of each network group, the central monitoring server first generates a self-signed certificate between the central gateway and the edge gateways. The self-signed certificate includes the central gateway identifier, the edge gateway identifier, and the identity authentication information of the monitoring service program of the edge gateway. Then, directly send the self-signed certificate to the intermediate gateway, and send the self-signed certificate to each edge gateway through an offline medium (such as a USB flash drive or other tools), so as to facilitate the subsequent construction of an encrypted tunnel between the central gateway and the edge gateways and generate the corresponding encryption key.

[0096] By setting strict access control policies, it is ensured that only authorized central gateways can obtain data from the storage server through the edge gateways, guaranteeing the security isolation of each isolated area.

[0097] Among them, before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateways of each network group, the execution steps of the edge gateways further include the following steps 601 to 604.

[0098] Step 601: Obtain the self-signed certificate and verify the self-signed certificate to obtain the certificate verification result.

[0099] Step 602: When the certificate verification result indicates that the self-signed certificate is correct, parse the self-signed certificate to obtain the central gateway identifier and the identity authentication information of the edge gateway.

[0100] Step 603: Based on the central gateway identifier and the identity authentication information, establish an encrypted tunnel between the edge gateway and the central gateway.

[0101] Step 604: Based on the central gateway identifier and the identity authentication information, generate an encryption key.

[0102] The following is a detailed description of steps 601 to 604.

[0103] In some embodiments, before the central monitoring server is ready to read the network monitoring data in the storage server from the edge gateways of each physically isolated network group, to ensure communication security, the edge gateway will first perform a series of security preparation steps. Specifically, the edge gateway first obtains a self-signed certificate and verifies the self-signed certificate to obtain a certificate verification result. The edge gateway receives the self-signed certificate passed by the central monitoring server through an offline medium (such as a USB flash drive), and uses a pre-configured trust root certificate or a built-in verification mechanism to verify the validity, integrity, and authenticity of the self-signed certificate to confirm whether the certificate is issued by a trusted source and has not been tampered with, thereby obtaining a certificate verification result.

[0104] When the certificate verification result indicates that the self-signed certificate is correct, that is, it indicates that the self-signed certificate is trustworthy, the edge gateway will further parse the certificate and extract key information, including the central gateway identifier of the central gateway (i.e., the unique identifier, such as the IP address or domain name of the central gateway) and the authentication information for the edge gateway to perform identity authentication (e.g., a pre-shared key or a public key). This information will be used for the subsequent establishment of an encrypted tunnel and encryption keys.

[0105] After obtaining the central gateway identifier and authentication information, the edge gateway will establish an encrypted tunnel between the edge gateway and the central gateway based on the central gateway identifier and authentication information. That is, the edge gateway uses the central gateway identifier as the destination address and combines the authentication information to establish an encrypted tunnel with the central gateway through a preset security protocol (e.g., IPsec, TLS / SSL, or VPN). This encrypted tunnel will be used to protect the transmission of subsequent network monitoring data and prevent the data from being eavesdropped on or tampered with during transmission. This encrypted tunnel is limited to data transmission between the central gateway and the edge gateway, and other devices cannot access or eavesdrop on it.

[0106] Finally, the edge gateway generates an encryption key based on the central gateway identifier and authentication information. The edge gateway uses the central gateway identifier and authentication information to generate an encryption key for encrypting network monitoring data through a specific key derivation function (KDF) or key negotiation algorithm. This encryption key is dynamically generated and can adopt the "one message, one key" strategy, that is, different keys are used for each data transmission to improve security. The key generation process should ensure the randomness and uniqueness of the key and prevent key leakage. The generated encryption key will be used to encrypt the subsequent network monitoring data to protect the confidentiality of the data. How to generate this encryption key will be further described below.

[0107] Among them, when the edge gateway executes to generate an encryption key based on the central gateway identifier and authentication information, the execution steps of the edge gateway include the following steps 701 to step 704.

[0108] Step 701: Generate an initial key through hashing based on the central gateway identifier.

[0109] Step 702: Perform normalization and concatenation processing on the edge gateway identifier and identity authentication information of the edge gateway to generate a dynamic factor.

[0110] Step 703: Generate a dynamic key through hashing based on the dynamic factor.

[0111] Step 704: Perform exclusive-or confusion processing on the dynamic key and the initial key to generate an encryption key.

[0112] The following provides a detailed description of Steps 701 to 704.

[0113] In some embodiments, to ensure the security of data transmission, after establishing an encrypted tunnel with the central gateway, the edge gateway needs to generate an encryption key for encrypting network monitoring data. The edge gateway first generates an initial key through hashing based on the central gateway identifier. Specifically, the edge gateway uses a hashing algorithm (such as SHA-256 or MD5) to perform a hashing operation on the central gateway identifier to generate an initial key of a fixed length.

[0114] Next, the edge gateway concatenates its own edge gateway identifier (i.e., its unique identifier, such as its IP address or unique ID) with the identity authentication information (such as a pre-shared key or public key) previously parsed from the self-signed certificate. To ensure the consistency of the concatenation result, normalization processing can be performed on the edge gateway identifier and the identity authentication information, such as unifying the encoding format, removing spaces or special characters, etc. The concatenated result is used as the dynamic factor for generating the dynamic key, increasing the randomness and security of the encryption key.

[0115] After that, the edge gateway uses a hashing algorithm (such as SHA-256 or MD5) to perform a hashing operation on the generated dynamic factor to generate a dynamic key of a fixed length. Since the dynamic factor contains the edge gateway identifier and the identity authentication information, the generated dynamic key has higher randomness and security, effectively preventing replay attacks and man-in-the-middle attacks.

[0116] Finally, the edge gateway performs an exclusive-or (XOR) operation on the generated initial key and the dynamic key to obtain the final encryption key. The exclusive-or operation is a simple confusion algorithm that can mix the characteristics of the two keys, increasing the complexity and security of the key. The generated encryption key will be used to encrypt the subsequent network monitoring data to protect the confidentiality of the data. This method of combining the initial key and the dynamic key implements a dynamic encryption strategy of "one report, one key". Even if the initial key is leaked, the original data cannot be deduced from the dynamic key, thereby improving the security of the system.

[0117] Through the above steps 701 to 704, a fixed initial key is generated by hashing the central gateway identifier, ensuring the correlation between the encryption key and the central gateway and preventing the forgery of keys. A dynamic factor is generated by combining the edge gateway identifier and the identity authentication information and hashed to generate a dynamic key, making the encryption key dynamic and unique. Even if the central gateway identifier is leaked, an attacker cannot easily obtain a valid key because the key for each edge gateway is unique and changes over time. Finally, the dynamic key and the initial key are XOR - confused to further increase the complexity and randomness of the encryption key, making the encryption key more difficult to be cracked or predicted. This key - generation mechanism that combines static identifiers and dynamic information effectively prevents security threats such as replay attacks and man - in - the - middle attacks, ensuring the confidentiality and integrity of the data transmission process from the edge gateway to the central gateway.

[0118] Through the above step 501 and steps 601 to 604, the central monitoring server generates and distributes a self - signed certificate to the edge gateway offline, avoiding the risk of the self - signed certificate being stolen or tampered with during network transmission. The edge gateway obtains and verifies the certificate, ensuring the legitimacy of the identity of the communication partner. The edge gateway obtains the central gateway identifier and the identity authentication information of the edge gateway by parsing the self - signed certificate, providing the necessary information for subsequent establishment of an encrypted tunnel and generation of an encryption key. An encrypted tunnel is established based on this information, ensuring the confidentiality and integrity of subsequent data transmission. Finally, an encryption key is generated based on the same information, ensuring that only the authorized central gateway can decrypt the data, further enhancing data security. This security mechanism based on self - signed certificates and offline distribution effectively guarantees the data security of the physically isolated network, preventing unauthorized access and data leakage.

[0119] In some embodiments, a monitoring service program is deployed on the central gateway of the central network to read the network monitoring data stored on the storage servers of all network groups through the edge gateways of the network groups. And a remote reading module is configured in the yaml configuration file of the monitoring service program of the central gateway, and the reading interfaces of the monitoring service programs of all edge gateways are filled in under the reading module.

[0120] When the actual central monitoring server reads network monitoring data from the storage server through the edge gateway of each network group, in order to further improve the security and reliability of data transmission and to avoid being eavesdropped by other network eavesdropping devices during data transmission, in this embodiment, the network monitoring data will also be encrypted using the generated encryption key at the edge gateway before data transmission, as described below.

[0121] Among them, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateways of each network group, the execution steps of the edge gateways include the following steps 801 to 803.

[0122] Step 801: Obtain a network monitoring data acquisition request sent by the central gateway.

[0123] Step 802: Determine target network monitoring data from the network monitoring data based on the network monitoring data acquisition request, and perform an encryption process on the target network monitoring data based on the encryption key to generate encrypted data and a corresponding authentication tag.

[0124] The following provides a detailed description of steps 801 to 802.

[0125] In some embodiments, after building an encrypted tunnel between the central gateway and each edge gateway, and after each edge gateway generates an encryption key, when the central monitoring server needs to read the network monitoring data in the storage server from the edge gateways of each network group, the central monitoring server sends a data acquisition request through the central gateway to the edge gateway from the established encrypted tunnel. The request includes the range of the requested data, a timestamp, or other filtering conditions. The edge gateway receives and parses the request to determine the specific data to be transmitted.

[0126] After that, the edge gateway filters out the target network monitoring data that meets the conditions from the locally stored network monitoring data according to the received data acquisition request. Then, the edge gateway performs an encryption process on the target network monitoring data using the previously generated encryption key to generate encrypted data. At the same time, to ensure the integrity of the data, the edge gateway also generates an authentication tag corresponding to the encrypted data while performing the encryption process using the encryption key.

[0127] The following will further describe how the edge gateway performs an encryption process on the target network monitoring data using the encryption key.

[0128] Among them, when the edge gateway performs an encryption process on the target network monitoring data based on the encryption key to generate encrypted data and a corresponding authentication tag, the execution includes the following steps 901 to 904.

[0129] Step 901: Obtain a non-linear mapping table and generate a dislocation processing identifier.

[0130] Step 902: Perform a non-linear substitution on the target network monitoring data based on the non-linear mapping table to generate non-linear network monitoring data.

[0131] Step 903: Perform a dislocation encryption process on the non-linear network monitoring data based on the dislocation processing identifier and the encryption key to obtain encrypted data.

[0132] Step 904: Generate an authentication label based on the mapping table identifier and misalignment processing identifier of the non-linear mapping table.

[0133] The following provides a detailed description of Steps 901 to 904.

[0134] In some embodiments, after obtaining the encryption key, the specific edge gateway determines the non-linear mapping table and misalignment processing identifier corresponding to the current encryption process. The non-linear mapping table is an S-Box (a multi-order lookup table), and its mapping table contains non-linear mapping relationships of multiple character data. The misalignment processing identifier includes a row shift identifier and a column shift identifier. The row shift identifier includes the target rows corresponding to multiple row transformation processes and the corresponding processing methods, and the column shift identifier includes the target columns corresponding to multiple column transformation processes and the corresponding processing methods.

[0135] Next, based on the non-linear mapping table, non-linear substitution is performed on each byte in the target network monitoring data to generate non-linear network monitoring data. When using an FPGA in the edge gateway, the S-Box module can be used in parallel to accelerate this non-linear substitution process.

[0136] After the non-linear substitution process, the edge gateway further performs misalignment encryption processing on the non-linear network monitoring data based on the misalignment processing identifier and the encryption key to obtain encrypted data, which is described in detail as follows.

[0137] Among them, when the edge gateway performs misalignment encryption processing on the non-linear network monitoring data based on the misalignment processing identifier and the encryption key to obtain encrypted data, the following Steps 1001 to 1003 are executed.

[0138] Step 1001: Select target row data from the non-linear network monitoring data based on the row shift identifier and perform row shift to obtain the first shifted data.

[0139] Step 1002: Obtain the mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform matrix operation on the target column data and the mixing matrix to obtain the second shifted data.

[0140] Step 1003: Perform exclusive OR processing on the second shifted data and the encryption key to obtain encrypted data.

[0141] The following provides a detailed description of Steps 1001 to 1003.

[0142] In some embodiments, after obtaining the misalignment processing identifier, encryption key and nonlinear network monitoring data, the edge gateway first selects the target row data from the nonlinear network monitoring data based on the row shift identifier in the misalignment processing identifier to perform row shift to obtain the first shifted data, such as shifting the first row in the nonlinear network monitoring data left by 1 byte, shifting the second row right by 2 bytes, and so on.

[0143] Next, the edge gateway obtains the mixing matrix corresponding to the column shift identifier in the misalignment processing identifier, and then selects the target column data from the first shifted data based on the column shift identifier, and then performs matrix multiplication operation on the target column data and the mixing matrix to obtain the second shifted data. Finally, the obtained second shifted data and the encryption key are subjected to XOR confusion processing (XOR operation) again to obtain encrypted data with strong randomness and confidentiality.

[0144] Finally, the edge gateway uses the mapping table identifier and the dislocation processing identifier (including the row transformation identifier and the column transformation identifier) in the nonlinear mapping table to generate an authentication tag so that the subsequent receiving and conversion device can use the authentication tag to perform corresponding decryption processing on the encrypted data after receiving the encrypted data.

[0145] Through the above steps 901 to 904, and steps 1001 to 1003, the edge gateway significantly improves the security of the target network monitoring data through the synergy of dynamic nonlinear obfuscation and multi-level diffusion mechanism, and destroys the statistical characteristics of the network monitoring data by byte replacement based on the nonlinear mapping table to resist the side channel attack based on pattern analysis. The spatial diffusion effect is introduced by dynamic row shift and mixed matrix operation. The single-byte modification will cause chain changes in multiple columns of data, effectively suppressing differential attacks. Combined with the obfuscation parameters of the dynamic identifier (row shift identifier, column mixed identifier), the central monitoring server implements the "one report and one secret" dynamic encryption strategy in the process of reading the network monitoring data of the storage server associated with the edge gateway. Even if the key is leaked, the network monitoring data cannot be reversely deduced. Then, the authentication tag is used to generate a deep fusion of nonlinear mapping table features and dislocation identifiers, and data integrity protection and encryption process traceability are simultaneously realized to prevent replay attacks and middleman tampering, thereby greatly improving the data security of the data detection system of the physically isolated network.

[0146] Step 803: Generate combined encrypted network monitoring data based on the combination of encrypted data and authentication tag, and transmit the combined encrypted network monitoring data to the central gateway through an encrypted tunnel, so that the central gateway can decrypt the combined encrypted network monitoring data and transmit the target network monitoring data to the central monitoring server.

[0147] Step 803 is described in detail below.

[0148] In some embodiments, to ensure the security and integrity of network monitoring data during transmission, after the edge gateway completes data encryption to obtain encrypted network monitoring data and generates an authentication tag, it will further combine the encrypted data and the authentication tag to combine the encrypted network monitoring data, and transmit the combined encrypted network monitoring data to the central gateway through the previously established encrypted tunnel, so that the central gateway can transmit the combined encrypted network monitoring data to the central monitoring server. This step combines the encrypted data with the authentication tag to form a complete and protected data packet, ensuring that the data cannot be eavesdropped (because it is encrypted) or tampered with (because of the authentication tag) during transmission. Transmission through the encrypted tunnel further guarantees the security of data transmission and prevents threats such as man-in-the-middle attacks. As a relay, after receiving the combined encrypted network monitoring data, the central gateway decrypts it to obtain the target network monitoring data and then securely forwards the target network monitoring data to the central monitoring server for subsequent analysis and processing.

[0149] In contrast, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateways of each network group, the execution of the central monitoring server includes the following steps 1101 to step 1102.

[0150] Step 1101: Send a network monitoring data acquisition request to the central gateway.

[0151] The following is a detailed description of step 1101.

[0152] In some embodiments, when the central monitoring server needs to obtain network monitoring data from the edge gateways of each physically isolated network group, the central monitoring server constructs a network monitoring data acquisition request containing information such as the required data range, timestamp, data type, etc. according to a preset policy or a user's instruction, and sends the network monitoring data acquisition request to the central gateway. The purpose of this request is to instruct the central gateway to obtain specific network monitoring data from the corresponding edge gateway so that the central monitoring server can perform subsequent analysis and processing.

[0153] Similarly, in contrast, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateways of each network group, the execution steps of the central gateway include the following steps 1201 to step 1205.

[0154] Step 1201: Receive the network monitoring data acquisition request sent by the central monitoring server.

[0155] Step 1202: Send the central gateway identifier and the network monitoring data acquisition request to the edge gateway through the encrypted tunnel.

[0156] Step 1203: Obtain the combined encrypted network monitoring data sent by the edge gateway according to the network monitoring data acquisition request.

[0157] Step 1204: Based on the authentication tag in the combined encrypted network monitoring data, perform decoding processing on the encrypted data in the combined encrypted network monitoring data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request.

[0158] Step 1205: Send the target network monitoring data to the central monitoring server.

[0159] The following provides a detailed description of Steps 1201 to 1205.

[0160] In some embodiments, when the central monitoring server needs to obtain network monitoring data from the edge gateways of each physically isolated network group, the central gateway acts as an intermediate bridge, responsible for securely forwarding requests and data. First, the central gateway receives the network monitoring data acquisition request sent by the central monitoring server, and sends the central gateway identifier and the network monitoring data acquisition request to the edge gateway through the established encrypted tunnel, ensuring that the data is not eavesdropped or tampered with during transmission.

[0161] Next, after receiving the request, the edge gateway extracts the corresponding network monitoring data from the local storage according to the request content, performs encryption and authentication tag processing, generates the combined encrypted network monitoring data, and sends it back to the central gateway. The central gateway receives the combined encrypted data from the edge gateway to prepare for subsequent decryption and verification.

[0162] After that, the central gateway uses the authentication tag in the combined encrypted data to generate a highly random encryption key, and then uses the encryption key and the authentication tag in the combined encrypted network monitoring data to decrypt the encrypted data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request.

[0163] Finally, the central gateway sends the decrypted target network monitoring data to the central monitoring server so that the central monitoring server can perform subsequent analysis, processing, and display. Through this series of steps, the central gateway realizes the transfer of the central monitoring server's request to the edge gateway while ensuring data security and integrity, and securely transfers the data returned by the edge gateway to the central monitoring server, thus completing the entire data acquisition process.

[0164] Step 1102: Obtain the target network monitoring data sent by the central gateway according to the network monitoring data acquisition request.

[0165] The following provides a detailed description of Step 1102.

[0166] In some embodiments, after the central monitoring server sends a network monitoring data acquisition request to the central gateway, the central monitoring server continuously listens for the connection with the central gateway. Once the central gateway completes the processing of requesting, receiving, verifying, and decrypting the data of the edge gateway and sends back the final target network monitoring data, the central monitoring server receives this data for subsequent analysis, storage, display, or other related operations.

[0167] Finally, after the central monitoring server reads the network monitoring data in the associated storage server from the edge gateways of each network group, the following steps 1301 to 1302 are also executed.

[0168] Step 1301: Integrate all the network monitoring data to obtain integrated network monitoring data.

[0169] Step 1302: Perform aggregation analysis on the integrated network monitoring data to obtain analysis processing data, and display the analysis processing data in a chart form.

[0170] The following provides a detailed description of steps 1301 to 1302.

[0171] In some embodiments, after the central monitoring server obtains the network monitoring data sent by the monitoring service programs on all the edge gateways through remote reading, it will integrate these network monitoring data to obtain integrated network monitoring data, then perform aggregation analysis on the integrated network monitoring data to obtain analysis processing data, and display the analysis processing data in a chart form to present to the operation and maintenance personnel, so as to improve the observability of data detection, and further improve the data processing efficiency and comprehensibility.

[0172] In some embodiments, the data detection system for physically isolated networks provided by the embodiments of the present application is not only applicable to the facilities of the network range, but also includes multiple specific application scenarios, such as sub-ranges and remote computer rooms, etc. At the same time, the construction and use of this data detection system can also cover other related network environments to ensure safe and effective data processing and information exchange.

[0173] The embodiments of the present application also provide an electronic device, including:

[0174] At least one memory;

[0175] At least one processor;

[0176] At least one program;

[0177] The program is stored in the memory, and the processor executes the at least one program to implement the relevant step processes in the data detection system for physically isolated networks of the present application. The electronic device can be any intelligent terminal including a mobile phone, a tablet computer, a personal digital assistant (PDA for short), an in-vehicle computer, etc.

[0178] Please refer to Figure 14 , Figure 14 which schematically shows the hardware structure of an electronic device according to another embodiment. The electronic device includes:

[0179] A processor 1401, which can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;

[0180] A memory 1402, which can be implemented in forms such as ROM (Read Only Memory), a static storage device, a dynamic storage device, or RAM (Random Access Memory). The memory 1402 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1402 and are called by the processor 1401 to execute the relevant step processes in the data detection system for physically isolated networks of the present application;

[0181] An input / output interface 1403, which is used to implement information input and output;

[0182] A communication interface 1404, which is used to implement communication interaction between this device and other devices, and can achieve communication through wired means (such as USB, network cable, etc.) or through wireless means (such as mobile network, WIFI, Bluetooth, etc.);

[0183] A bus 1405, which transmits information between various components of the device (such as the processor 1401, the memory 1402, the input / output interface 1403, and the communication interface 1404);

[0184] Among them, the processor 1401, the memory 1402, the input / output interface 1403, and the communication interface 1404 achieve communication connections with each other inside the device through the bus 1405.

[0185] The embodiments of the present application also provide a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the relevant step processes in the above-mentioned data detection system for physically isolated networks.

[0186] As a non-transitory computer-readable storage medium, a memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include memories remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0187] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0188] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine some steps, or different steps.

[0189] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0190] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.

[0191] In the description of the present application and the above-mentioned accompanying drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0192] It should be understood that in the present application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expressions refer to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0193] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.

[0194] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0195] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0196] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0197] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of the present application. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall fall within the scope of the rights of the embodiments of the present application.

Claims

1. A data detection system for a physically isolated network, characterized in that, The system includes: Multiple network groups, each network group includes multiple network devices and data collectors, the network devices include at least one of servers, security devices, routing and switching network devices, and data between every two network groups is not interoperable; A corresponding storage server and an edge gateway are provided at the edge of each network group; The data collector is used to collect network monitoring data of the multiple network devices in the corresponding network group in real time, and unidirectionally transmit the network monitoring data to the monitoring service program of the corresponding edge gateway, and then remotely persist it to the storage server by the monitoring service program; A central monitoring server, the central monitoring server is used to read the network monitoring data in the associated storage server from the edge gateway of each network group; The data detection system further includes a central gateway associated with the central monitoring server; Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the central monitoring server is further used to generate a self-signed certificate between the central gateway and the edge gateway, send the self-signed certificate to the central gateway, and send the self-signed certificate to the edge gateway through an offline medium; Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the edge gateway further include: Obtain the self-signed certificate and verify the self-signed certificate to obtain a certificate verification result; When the certificate verification result indicates that the self-signed certificate is correct, parse the self-signed certificate to obtain the central gateway identifier and the identity authentication information of the edge gateway; Based on the central gateway identifier and the identity authentication information, establish an encrypted tunnel between the edge gateway and the central gateway. The encrypted tunnel is limited to data transmission between the central gateway and the edge gateway, and other devices cannot access and eavesdrop; Generate an encryption key based on the central gateway identifier and the identity authentication information.

2. The data detection system for a physically isolated network according to claim 1, wherein When the edge gateway executes generating an encryption key based on the central gateway identifier and the identity authentication information, the execution steps of the edge gateway include: Generate an initial key by performing a hash process on the central gateway identifier; Perform a normalization splicing process on the edge gateway identifier of the edge gateway and the identity authentication information to generate a dynamic factor; Generate a dynamic key by performing a hash process on the dynamic factor; Perform an exclusive OR confusion process on the dynamic key and the initial key to generate the encryption key.

3. The data detection system for a physically isolated network according to claim 1, characterized in that, When the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the edge gateway include: Obtain the network monitoring data acquisition request sent by the central gateway; Determine target network monitoring data from the network monitoring data based on the network monitoring data acquisition request, and encrypt the target network monitoring data based on the encryption key to generate encrypted data and a corresponding authentication tag; Generate combined encrypted network monitoring data based on the combination of the encrypted data and the authentication tag, and transmit the combined encrypted network monitoring data through the encrypted tunnel to the central gateway, so that the central gateway decrypts the combined encrypted network monitoring data and then transmits the target network monitoring data to the central monitoring server.

4. The data detection system for a physically isolated network according to claim 3, characterized in that, When the edge gateway performs the encryption process on the target network monitoring data based on the encryption key to generate encrypted data and a corresponding authentication tag, the execution steps include: Obtain the non-linear mapping table and generate a dislocation processing identifier; Based on the non-linear mapping table, perform non-linear substitution on the target network monitoring data to generate non-linear network monitoring data; Based on the dislocation processing identifier and the encryption key, perform dislocation encryption processing on the non-linear network monitoring data to obtain the encrypted data; Generate the authentication tag based on the mapping table identifier of the non-linear mapping table and the dislocation processing identifier.

5. The data detection system for a physically isolated network according to claim 4, characterized in that, The dislocation processing identifier includes a row shift identifier and a column mixing identifier. When the edge gateway performs the dislocation encryption processing on the non-linear network monitoring data based on the dislocation processing identifier and the encryption key to obtain the encrypted data, the execution steps include: Select target row data from the non-linear network monitoring data based on the row shift identifier for row shifting to obtain the first shifted data; Obtain the mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform matrix operation on the target column data and the mixing matrix to obtain the second shifted data; Perform exclusive OR processing on the second shifted data and the encryption key to obtain the encrypted data.

6. The data detection system for a physically isolated network according to claim 3, wherein When the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the central monitoring server include: Send a network monitoring data acquisition request to the central gateway; Obtain the target network monitoring data sent by the central gateway according to the network monitoring data acquisition request.

7. The data detection system for a physically isolated network according to claim 6, wherein, When the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the central gateway include: Receive the network monitoring data acquisition request sent by the central monitoring server; Send the central gateway identifier and the network monitoring data acquisition request to the edge gateway through the encrypted tunnel; Obtain the combined encrypted network monitoring data sent by the edge gateway according to the network monitoring data acquisition request; Based on the authentication tag in the combined encrypted network monitoring data, perform decoding processing on the encrypted data in the combined encrypted network monitoring data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request; Send the target network monitoring data to the central monitoring server.

8. The data detection system for a physically isolated network according to claim 1, wherein When the data collector collects the network monitoring data of the multiple network devices in the corresponding network group in real time, the execution steps include: When the current time reaches the preset acquisition period, determine at least one target data type corresponding to the preset acquisition period; Collect real-time type data corresponding to all the target data types from the multiple network devices in the network group; Obtain the network monitoring data based on all the real-time type data.

9. The data detection system for a physically isolated network according to claim 1, wherein After the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the steps further executed include: Integrate and process all the network monitoring data to obtain integrated network monitoring data; Perform aggregation analysis on the integrated network monitoring data to obtain analysis and processing data, and display the analysis and processing data in a chart.

Citation Information

Patent Citations

  • Communication method and device, edge gateway and storage medium

    CN118574090A