Internal and external network security interaction method based on asymmetric encryption
Through the combination of asymmetric encryption based on the method and the combination of a dynamic QR code display screen and 4K macro camera, the problems of data transmission security and efficiency between the internal and external networks are solved, and the secure isolation and efficient data transmission of the internal and external networks are achieved.
Patent Information
- Application Number
- CN202510249726.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to achieve secure isolation between internal and external networks, while ensuring the security and efficiency of data transmission.
Asymmetric encryption is used to generate public-private key pairs using the RSA algorithm, and data transmission is carried out through a scanning module composed of a dynamic QR code display and a 4K macro camera to ensure safe isolation of the internal and external networks.
It improves the security and efficiency of data transmission, simplifies the key management process, realizes secure isolation of internal and external networks, and improves the simplicity and applicability of the system.
Smart Images

Figure CN120017399A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field where information network security and power communication intersect, and in particular, relates to a method for secure interaction between an intranet and an extranet based on asymmetric encryption, and relates to a security technology for data interaction between an intranet and an extranet. Background Art
[0002] The interaction between the internal and external networks usually involves the transmission of sensitive data, and security is of paramount importance: on the one hand, considering the security isolation requirements between the internal and external networks, the existing technology cannot overcome the problem of connecting the internal and external networks to the same device while ensuring the security and confidentiality of information transmission; on the other hand, the existing technology needs to avoid the use of encrypted USB flash drives and other cumbersome operations that require manual execution for data interaction, and the security and efficiency of data transmission need to be improved.
[0003] CN117675346A discloses a secure access method based on zero trust between internal and external networks to solve the potential security risks faced when internal and external networks interact in the existing network environment. This method implements strict verification, access, monitoring and other processing on all connections and data traffic passing through this gateway to achieve zero-trust secure access between internal and external networks. The security gateway is equipped with identity and device verification, dynamic encrypted communication, policy-based fine-grained access control, security audit logs and defense mechanisms against threats. When internal and external network communication entities attempt to interact, the security gateway enforces two-way identity authentication to confirm the correspondence between the subject and the identifier.
[0004] CN117081852A discloses a method and device for safely publishing public information based on the isolation of internal and external networks. The method includes: generating data to be queried; backing up and verifying the data to be queried; verifying in the data storage area to be released; external network release; recording the external network data query log; and log audit. The data to be queried is transmitted one-way in sequence between the internal network reference library, the reverse proxy, the data storage area to be released, and the external interactive website. The log delivery storage area is physically isolated from the internal network reference library, the reverse proxy, and the data storage area to be released, and the log delivery storage area cannot be sent to the internal network reference library, the reverse proxy, and the data storage area to be released.
[0005] After repeated experiments, the applicant believes that the security of data transmission can be improved, the key management process can be simplified, the efficiency and convenience of data transmission can be further improved, and the internal and external network security isolation can be achieved, making the system easier to operate and more widely applicable. Summary of the invention
[0006] To solve the above problems, the purpose of the present invention is to disclose a method for secure interaction between internal and external networks based on asymmetric encryption, which is implemented by adopting the following technical solutions.
[0007] A method for secure interaction between an intranet and an extranet based on asymmetric encryption, characterized in that it comprises the following steps: Step 1: Key generation and management steps; Step 2: Data encryption step; Step 3: Data transmission steps: Step 4: Data decryption step.
[0008] The above-mentioned method for secure interaction between internal and external networks based on asymmetric encryption is characterized in that the first step includes the following sub-steps: S1: Generate a pair of public and private keys using the RSA algorithm: use 65537 as the public key exponent value, specify the key length as 1024 bits, the public key is used for data encryption, and the private key is used for data decryption; S2: Serialize and save the public key and private key: The private key is encoded using PEM and saved in PKCS8 format. The private key is encrypted with a password to ensure the security of the private key. The public key is saved in PEM encoding format. S3: Local password storage: The private key is distributed to the external client through a secure channel for storage, and the public key is stored locally on the intranet server.
[0009] The above-mentioned method for secure interaction between internal and external networks based on asymmetric encryption is characterized in that: in the second step, the internal network server uses the locally stored public key to encrypt the data before data transmission, converts the transmitted data string into a byte string, and then uses the RSA encryption filling method PKCS#1 v1.5 standard to complete the encryption.
[0010] The above-mentioned method for secure interaction between internal and external networks based on asymmetric encryption is characterized in that: in the third step, a dynamic QR code display screen and a 4K macro camera are used to form a scanning module to transmit data and ensure the secure isolation of the internal and external networks; the QR code display screen is a thin-film field effect transistor color display module with a USB A interface simulating a serial port, and is connected to the intranet server when in use.
[0011] The above-mentioned method for secure interaction between internal and external networks based on asymmetric encryption is characterized by: a hexadecimal control instruction protocol for a two-dimensional code display screen: when there is data in the internal network that needs to be transmitted to the external network, a data packet is created based on the encrypted data, and commands and data are sent to the LCDs module through the USB interface. The data packet format consists of a command header, data length, command, data and checksum; the data length is the length of the entire data packet after removing the command header; the command is a control command for the two-dimensional code display screen module, using a clear screen command and a two-dimensional code display command; the data is the data sent to the module, with a maximum length of 192 bytes; the check is the command header, data length, and the numerical sum of the command and data; the return data instruction contains a command and status part: the command is consistent with the request command; if the status is 0, the command execution is abnormal, and if it is 1, the command execution is successful.
[0012] The above-mentioned method for secure interaction between internal and external networks based on asymmetric encryption is characterized in that: the 4K macro camera connects the macro camera to the external network device using a USB A interface. When there is data transmission, the camera is awakened on the external network client to take pictures and save them, and the QR code image of the transmitted data is updated and stored; to ensure that the camera can clearly capture the QR code pixels on the display screen, the feasible shooting distance range between the display screen and the camera is 10cm-70cm.
[0013] The above-mentioned method for secure interaction between internal and external networks based on asymmetric encryption is characterized in that: in the fourth step, when the external network device receives the encrypted data, it identifies the stored encrypted data QR code content and uses the locally stored private key to decrypt it and restore the original data.
[0014] The present application has the following main beneficial technical effects: improving data transmission security, simplifying the key management process, improving data transmission efficiency and convenience, achieving secure isolation of internal and external networks, making system operation easier, and improving wide applicability. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 This is a schematic diagram of the hardware structure of this application.
[0016] Figure 2 It is a schematic diagram of the performance parameters of the QR code display screen.
[0017] Figure 3 This is a schematic diagram of the electrical performance parameters of the QR code display screen.
[0018] Figure 4 This is a schematic diagram of the working parameters of the QR code display screen.
[0019] Figure 5 This is a diagram illustrating the QR code display interface.
[0020] Figure 6This is a data chart of the QR code display screen size. DETAILED DESCRIPTION
[0021] In order to enable those skilled in the art to better understand and implement this patent, the specific implementation methods of this application are now described in detail in conjunction with the drawings in the specification.
[0022] Please see Figures 1 to 6 , Figure 1 In the embodiment, there is a sealed box between the intranet server and the external network device, and the intranet server and the sealed box are connected through a USB A interface. In addition, one end of the USB A interface is connected to the intranet server, and the other end of the USB A interface is connected to a QR code display screen. The QR code on the QR code display screen can be photographed by a camera device in the sealed box; the external network device and the sealed box are connected through a USB A interface. Here, one end of the USB A interface is connected to the external network device, and the other end of the USB A interface is connected to the camera device. The camera device is installed on an inner wall of the sealed box to photograph the QR code.
[0023] A method for secure interaction between an intranet and an extranet based on asymmetric encryption, characterized by comprising the following steps: Step 1: Key generation and management steps: S1: Generate a pair of public and private keys using the RSA algorithm: use 65537 as the public key exponent value, specify the key length as 1024 bits, the public key is used for data encryption, and the private key is used for data decryption; S2: Serialize and save the public key and private key: The private key is encoded using PEM and saved in PKCS8 format. The private key is encrypted with a password to ensure the security of the private key. The public key is saved in PEM encoding format. S3: Local password storage: The private key is distributed to the external client through a secure channel for storage, and the public key is stored locally on the intranet server; Step 2: Data encryption step: Before data transmission, the intranet server uses the locally stored public key to encrypt the data, converts the transmitted data string into a byte string, and then uses the RSA encryption filling method PKCS#1 v1.5 standard to complete the encryption, increasing the randomness and security of the data; Step 3: Data transmission step: In order to ensure the security isolation of the internal and external networks, a dynamic QR code display screen and a 4K macro camera are used to form a scanning module to transmit data; The QR code display is a thin-film field effect transistor (TFT) color display module with a USB A interface simulating a serial port. It is connected to the intranet server when in use. Its display performance parameters are as follows: Figure 2 As shown, the electrical performance parameters are as follows Figure 3 As shown, the working parameters are as follows Figure 4 As shown, the interface description is as follows Figure 5 As shown, the size data is as follows Figure 6 shown.
[0024] Description of the hexadecimal control command protocol of the QR code display screen: When there is data in the intranet that needs to be transmitted to the external network, a data packet is created based on the encrypted data, and commands and data are sent to the LCDs module through the USB interface. The data packet format consists of a command header (0xAA), data length (Length), command (Command), data (Data) and checksum (CheckSum); Length is the length of the entire data packet after removing the command header; Command is the control command of the QR code display module, mainly using the clear screen command (0x80) and the QR code display command (0x82); Data is the data sent to the module, with a maximum length of 192 bytes; CheckSum is the command header, data length, command and data value sum; The return data instruction contains the command (Command) and status (Status) parts: Command is consistent with the request command; Status is 0 if the command is executed abnormally, and 1 if the command is executed successfully; Among them, the 4K macro camera description: connect the macro camera to the external network device using the USB A interface. When there is data transmission, wake up the camera on the external network client to take pictures and save them, and update and store the QR code image of the transmitted data; to ensure that the camera can clearly capture the QR code pixels on the display screen, the feasible shooting distance between the display screen and the camera is 10cm~70cm; Step 4: Data decryption step: When the external network device receives the encrypted data, it identifies the stored encrypted data QR code content and uses the locally stored private key to decrypt and restore the original data.
[0025] The key technical points of the present invention are as follows: 1. Application of asymmetric encryption technology The RSA algorithm is used to generate a key pair, with the public key used for data encryption and the private key used for data decryption. This method overcomes the complexity and difficulty of key management in symmetric encryption and improves the security of data transmission.
[0026] At the same time, the key is saved in PEM encoding format, and the private key is saved in PKCS8 format and encrypted to further ensure its security.
[0027] 2. Data transmission based on dynamic QR code technology The dynamic QR code display screen and the 4K macro camera realize physical isolation and transmission of data. The QR code display screen uses the USB A interface to connect to the intranet server and display the encrypted data; the 4K macro camera connects to the external network client through the USB A interface to scan and transmit the QR code data, ensuring the security isolation between the internal and external networks.
[0028] 3. QR code display screen control protocol The hexadecimal control command protocol is used to control the display content and screen parameters of the QR code display. The data packet consists of a command header, data length, command code, transmission data and checksum to ensure the accuracy and reliability of data transmission.
[0029] The main beneficial effects of the present invention are: 1. Improved data transmission security: Asymmetric encryption technology ensures the security of data during transmission, preventing data leakage and tampering. Through the encryption and decryption process, the integrity and confidentiality of the transmitted data are ensured.
[0030] 2. Simplified the key management process: public keys and private keys are managed separately, and private keys are encrypted and stored, avoiding the complexity of key management in symmetric encryption and improving the security and ease of use of the system.
[0031] 3. Improved data transmission efficiency and convenience: Automatic data transmission through dynamic QR codes and 4K macro cameras improves transmission efficiency and convenience, and overcomes the problem of manually using encrypted storage devices to transfer data.
[0032] 4. Realized the security isolation of internal and external networks: The use of dynamic QR code display screen and 4K macro camera realizes the physical isolation of internal and external networks, avoids network attacks and data theft, and ensures the security of data transmission.
[0033] 5. Easier system operation: The QR code display screen and macro camera are easy to operate and suitable for various operating systems, which reduces the system deployment and maintenance costs and improves the user experience.
[0034] 6. Improved wide applicability: The technical solution in this application is applicable to the data security transmission needs of multiple fields such as enterprises, governments, and medical care. It has strong adaptability and scalability, meets the data security needs of different users, and is applicable to various internal and external network interaction scenarios.
[0035] The present application has the following main beneficial technical effects: improving data transmission security, simplifying the key management process, improving data transmission efficiency and convenience, achieving secure isolation of internal and external networks, making system operation easier, and improving wide applicability.
[0036] The above embodiments are only preferred technical solutions of the present invention and should not be regarded as limiting the present invention. The protection scope of the present invention shall be the technical solutions recorded in the claims, including the equivalent replacement solutions of the technical features in the technical solutions recorded in the claims. That is, equivalent replacement improvements within this scope are also within the protection scope of the present invention.
Claims
1. A method for secure interaction between internal and external networks based on asymmetric encryption, characterized in that: The following steps are involved: Step 1: Key generation and management steps; Step 2: Data encryption step; Step 3: Data transmission steps: Step 4: Data decryption step.
2. According to claim 1, a method for secure interaction between internal and external networks based on asymmetric encryption, characterized in that: The first step includes the following sub-steps: S1: Generate a pair of public and private keys using the RSA algorithm: use 65537 as the public key exponent value, specify the key length as 1024 bits, the public key is used for data encryption, and the private key is used for data decryption; S2: Serialize and save the public key and private key: The private key is encoded using PEM and saved in PKCS8 format. The private key is encrypted with a password to ensure the security of the private key. The public key is saved in PEM encoding format. S3: Local password storage: The private key is distributed to the external client through a secure channel for storage, and the public key is stored locally on the intranet server.
3. The method for secure interaction between internal and external networks based on asymmetric encryption according to claim 2, characterized in that: In the second step, the intranet server encrypts the data using the locally stored public key before data transmission, converts the transmitted data string into a byte string, and then uses the RSA encryption padding method PKCS#1 v1.5 standard to complete the encryption.
4. The method for secure interaction between internal and external networks based on asymmetric encryption according to claim 3, characterized in that: In the third step, a dynamic QR code display screen and a 4K macro camera are used to form a scanning module to transmit data and ensure the security isolation of the internal and external networks. The QR code display screen is a thin-film field-effect transistor color display module with a USB A interface simulating a serial port, and is connected to the intranet server when in use.
5. The method for secure interaction between internal and external networks based on asymmetric encryption according to claim 4, characterized in that: Hexadecimal control command protocol of the QR code display screen: When there is data in the intranet that needs to be transmitted to the external network, a data packet is created based on the encrypted data, and commands and data are sent to the LCDs module through the USB interface. The data packet format consists of a command header, data length, command, data, and checksum; the data length is the length of the entire data packet after removing the command header; the command is the control command of the QR code display screen module, using the clear screen command and the QR code display command; the data is the data sent to the module, with a maximum length of 192 bytes; the checksum is the command header, data length, and the numerical sum of the command and data; the return data instruction contains the command and status part: the command is consistent with the request command; if the status is 0, the command execution is abnormal, and if it is 1, the command execution is successful.
6. The method for secure interaction between internal and external networks based on asymmetric encryption according to claim 5, characterized in that: The 4K macro camera connects the macro camera to the external network device using the USB A interface. When there is data transmission, the camera is awakened on the external network client to take pictures and save them, and the QR code image of the transmitted data is updated and stored. To ensure that the camera can clearly capture the QR code pixels on the display screen, the feasible shooting distance between the display screen and the camera is 10cm-70cm.
7. The method for secure interaction between internal and external networks based on asymmetric encryption according to claim 6, characterized in that: In the fourth step, when the external network device receives the encrypted data, it identifies the stored encrypted data QR code content and uses the locally stored private key to decrypt it and restore the original data.
Citation Information
Patent Citations
Public information security publishing method and device based on internal and external network isolation
CN117081852A
System and method for transmitting data using barcode
CN106101662A
Data transmission method and device, server and computer storage medium
CN109451006A
Data exchange method and device
CN109525599A
Test system and method for earphone production
CN112235708A
Cited By
Physical isolation information interaction method and device, computer and storage medium
CN120498896A