Network isolation method and device, electronic equipment and storage medium

By using the first gateway and the second gateway in the network isolation system for packet conversion and encapsulation, the problems of high cost, low data throughput and time delay in the prior art are solved, and efficient and secure network isolation effect is achieved.

CN120075187AInactive Publication Date: 2025-05-30DIGITAL GUANGDONG NETWORK CONSTR CO LTD

Patent Information

Application Number
CN202510282144.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, network isolation methods have problems such as high cost, low data throughput and time delay.

Method used

By using the first gateway and the second gateway in the network isolation system, the first gateway receives the public network request packet sent by the client in the application network, converts and encapsulates the address, forms a private network data packet, and sends it to the second gateway; the second gateway further converts and encapsulates the private network data packets, forms a public network request packet, and sends it to the server in the core network.

Benefits of technology

It realizes the logical isolation function between the application network and the core network, reduces costs, improves data throughput and transmission efficiency, shortens latency, and enhances the security of the core network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075187A_ABST
    Figure CN120075187A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network isolation method and device, electronic equipment and a storage medium, and relates to the technical field of communication. The network isolation system comprises a first gateway and a second gateway which are connected with each other, the first gateway is accessed to an application network, the second gateway is accessed to a core network, and the method comprises the following steps: receiving a first public network request data packet sent by a client in the application network through the first gateway; performing address conversion on the first public network packet header through the first gateway to obtain a private network packet header, packaging the private network packet header and a packet body to obtain a private network data packet, and sending the private network data packet to a second gateway; and performing address conversion on a private network packet header of the private network data packet through the second gateway to obtain a second public network packet header, packaging the second public network packet header and a packet body to obtain a second public network request data packet, and sending the second public network request data packet to the server in the core network, thereby realizing a logic isolation function between the application network and the core network. And the cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communication technologies, and in particular, to a network isolation method, apparatus, electronic device, and storage medium. Background Art

[0002] Network isolation refers to building a relatively independent and direct-connection-blocking security mechanism between different network areas through various technical means, so as to ensure the safe operation of devices within each network area.

[0003] In the prior art, when a server in the core network communicates with a client in the application network, a network isolation device is mainly used for physical isolation to isolate the core network and the application network and ensure the safe operation of the server in the core network. However, the cost of hardware devices such as network isolation devices is relatively high, and there are also problems of low data throughput rate and long latency. Summary of the Invention

[0004] Embodiments of the present application provide a network isolation method, apparatus, electronic device, and storage medium, which implement the network isolation function to solve the problems of high cost, low data throughput rate, and long latency existing in the network isolation method in the prior art.

[0005] In a first aspect, an embodiment of the present application provides a network isolation method, which is applied to a network isolation system. The network isolation system includes a first gateway and a second gateway connected to each other. The first gateway accesses the application network, and the second gateway accesses the core network. The method includes:

[0006] Receiving, by the first gateway, a first public network request data packet sent by a client in the application network; the first public network request data packet includes a first public network header and a packet body;

[0007] Performing, by the first gateway, address conversion on the first public network header to obtain a private network header, encapsulating the private network header and the packet body to obtain a private network data packet, and sending the private network data packet to the second gateway;

[0008] Performing, by the second gateway, address conversion on the private network header of the private network data packet to obtain a second public network header, encapsulating the second public network header and the packet body to obtain a second public network request data packet, and sending the second public network request data packet to a server in the core network.

[0009] In the technical solution of the embodiment of the present application, the first gateway receives the first public network request data packet sent by the client in the application network; the first gateway performs address conversion on the first public network packet header to obtain a private network packet header, encapsulates the private network packet header and the packet body to obtain a private network data packet, and sends the private network data packet to the second gateway; the second gateway performs address conversion on the private network packet header of the private network data packet to obtain a second public network packet header, encapsulates the second public network packet header and the packet body to obtain a second public network request data packet, and sends the second public network request data packet to the server in the core network. In the above technical solution, the first gateway converts the first public network request data packet sent by the client in the application network into a private network data packet, and then the second gateway converts the private network data packet into a second public network request data packet and sends the second public network request data packet to the server in the core network. Through the first gateway and the second gateway of the network isolation system, the logical isolation function between the application network and the core network is realized, and there is no need to deploy hardware devices such as network gates for physical isolation, which reduces the cost. Moreover, the installation, deployment and maintenance of the network isolation system are relatively simple. At the same time, the first gateway and the second gateway can perform dynamic resource allocation according to the actual situation (such as dynamically allocating port numbers, etc.), which improves the data throughput rate, and improves the data transmission efficiency, shortens the transmission delay, and solves the problems of high cost, low data throughput rate and long delay existing in the network isolation method in the prior art; in addition, the first gateway and the second gateway communicate through a private network protocol stack instead of a public network protocol stack including an IP communication protocol, which can realize non-IP communication between the first gateway and the second gateway, thereby reducing the risk of the core network being attacked due to forged IP data packets, and thus ensuring the operation safety of the core network.

[0010] In a second aspect, an embodiment of the present application provides a network isolation device, which is applied to a network isolation system. The network isolation system includes a first gateway and a second gateway connected to each other. The first gateway accesses the application network, and the second gateway accesses the core network. The device includes:

[0011] A receiving module, configured to receive, through the first gateway, a first public network request data packet sent by a client in the application network; the first public network request data packet includes a first public network packet header and a packet body;

[0012] A first conversion module, configured to perform address conversion on the first public network packet header through the first gateway to obtain a private network packet header, encapsulate the private network packet header and the packet body to obtain a private network data packet, and send the private network data packet to the second gateway;

[0013] A second conversion module, configured to perform address conversion on the private network packet header of the private network data packet through the second gateway to obtain a second public network packet header, encapsulate the second public network packet header and the packet body to obtain a second public network request data packet, and send the second public network request data packet to the server in the core network.

[0014] In a third aspect, an embodiment of the present application provides an electronic device, which includes:

[0015] at least one processor; and a memory communicatively connected to the at least one processor;

[0016] wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the network isolation method according to any embodiment of the present application.

[0017] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the network isolation method according to any embodiment of the present application.

[0018] For the descriptions of the second, third, and fourth aspects in the present application, reference may be made to the detailed description of the first aspect; and for the beneficial effects described in the second, third, and fourth aspects, reference may be made to the analysis of the beneficial effects of the first aspect, which will not be elaborated here.

[0019] In the present application, the names of the above-mentioned network isolation devices do not constitute a limitation to the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those of the present application and fall within the scope of the claims of the present application and their equivalent technologies.

[0020] These aspects or other aspects of the present application will be made more concise and understandable in the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0022] Figure 1 is a flowchart of the network isolation method provided by an embodiment of the present application;

[0023] Figure 2 is a schematic structural diagram of the network isolation system provided by an embodiment of the present application;

[0024] Figure 3 is another schematic structural diagram of the network isolation system provided by an embodiment of the present application;

[0025] Figure 4 is a schematic structural diagram of the network isolation device provided by an embodiment of the present application;

[0026] Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only a part rather than all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0028] It should be noted that the terms "first", "second", "target", and "original" in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such used data may be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include", "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0029] Figure 1 It is a schematic flowchart of a network isolation method provided by an embodiment of the present application. This embodiment can be applied to a scenario where network isolation needs to be performed on a client in an application network and a server in a core network when they communicate. A network isolation method provided in this embodiment can be executed by a network isolation device provided by an embodiment of the present application, and this device can be implemented in a software and / or hardware manner. In a specific embodiment, this network isolation device can be integrated in an electronic device, and this electronic device is an overall controller in a network isolation system. For example, this electronic device can be a computer or a server, etc.

[0030] In a specific embodiment, the structure of the network isolation system can be as Figure 2 shown Figure 2 The shown network isolation system can include an electronic device, a first gateway and a second gateway that are interconnected; the electronic device is used to control the first gateway and the second gateway; the first gateway accesses the application network and can communicate with m clients in the application network; the second gateway accesses the core network and can communicate with n servers in the core network.

[0031] The following combines Figure 2 with the network isolation system shown in the figure to illustrate a network isolation method provided by an embodiment of the present application. The execution subject of this method can be an electronic device. Continuing to refer to Figure 1 , the network isolation method of this embodiment includes but is not limited to the following steps:

[0032] S110: Receive a first public network request data packet sent by a client in the application network through a first gateway.

[0033] Among them, the first public network request data packet is a request data packet generated by the client according to the public network protocol stack, aiming to inform a specific server in the core network of relevant information such as operations to be performed or resources to be feedback. In the embodiment of the present application, the client in the application network sends a first public network request data packet to a specific server in the core network so that the specific server performs a specific operation or feedbacks specific resources.

[0034] Optionally, the first public network request data packet may include a first public network packet header and a packet body; the first public network packet header is the header data encapsulated by the client according to the public network protocol stack; the packet body is used to carry the specific data content passed by the client to the server.

[0035] Specifically, in order to protect the running security of each server in the core network, the client in the application network can send data to the server in the core network through the network isolation system. Therefore, the client in the application network can generate a first public network request data packet according to the public network protocol stack, send the first public network request data packet to the network isolation system, and then the electronic device can receive the first public network request data packet sent by the client through the first gateway.

[0036] Optionally, the first gateway may include a first network card and a second network card connected to each other. The first network card accesses the application network; the public network protocol stack may include an application layer, a transport layer, a network layer, a data link layer, and a physical layer, which is an existing standard network protocol stack.

[0037] Furthermore, the client internally stores the logical address (i.e., Internet Protocol Address (IP address)) and physical address (i.e., Media Access Control Address (MAC address)) of the first network card; the process of the client generating the first public network request data packet according to the public network protocol stack is as follows: (1) Perform application layer encapsulation. Specifically, generate request data such as acquisition instructions (e.g., Structured Query Language (SQL) statements), then determine the header information of the application layer, such as protocol version number, protocol type identifier, and uniform resource locator, etc., and perform application layer encapsulation on this header information to obtain the application layer packet header, and then add the application layer packet header to the front of the request data to obtain the application layer data packet, that is, the packet body; (2) Perform transport layer encapsulation. Specifically, select an unused port number from the available port number range as the source port number of the transport layer, that is, use the port number of the client as the source port number of the transport layer. Then, based on the first preset relationship table, determine the destination port number of the transport layer, where the first preset relationship table is used to save the mapping relationship between the default port number corresponding to the service and the port number of the first network card. Thus, the destination port number of the transport layer is the port number of the first network card. Then, perform transport layer encapsulation to obtain the transport layer packet header, and add the transport layer packet header to the front of the packet body to obtain the transport layer data packet; (3) Perform network layer encapsulation. Specifically, use the logical address of the client as the source address of the network layer, and use the logical address of the first network card as the destination address of the network layer to perform network layer encapsulation to obtain the network layer packet header, and add the network layer packet header to the front of the transport layer data packet to obtain the network layer data packet; (4) Perform data link layer encapsulation. Specifically, use the physical address of the client as the source address of the data link layer, and use the physical address of the first network card as the destination address of the data link layer to perform data link layer encapsulation to obtain the data link layer packet header, and add the data link layer packet header to the front of the network layer data packet to obtain the data link layer data packet, that is, the first public network request data packet; (5) Send the first public network request data packet to the first gateway of the network isolation system through the physical layer, that is, send the first public network request data packet to the first network card.

[0038] After that, the electronic device can receive the first public network request data packet sent by the client in the application network through the first network card of the first gateway.

[0039] S120. Perform address conversion on the first public network packet header through the first gateway to obtain a private network packet header, encapsulate the private network packet header and the packet body to obtain a private network data packet, and send the private network data packet to the second gateway.

[0040] Among them, the private network packet header is the packet header obtained after the first gateway performs address conversion on the first public network packet header. The private network data packet is the data packet obtained by encapsulating the private network packet header and the packet body.

[0041] Specifically, after receiving the first public network request data packet sent by the client through the first gateway, the first gateway can parse the first public network request data packet to obtain the first public network packet header and the packet body. At this time, the packet body is the data packet encapsulated by the application layer. The first public network packet header includes the packet header of the transport layer, the packet header of the network layer, and the packet header of the data link layer, that is, the port number, logical address, and physical address of the client, as well as the port number, logical address, and physical address of the first network card, etc.

[0042] Then, the first gateway performs address conversion on the first public network packet header to obtain the private network packet header. For example, based on the information in the first public network packet header, the source address and destination address in the private network packet header are determined; then, the private network packet header and the packet body are encapsulated according to the private network protocol stack to obtain the private network data packet, and the private network data packet is sent to the second gateway. Among them, the private network protocol stack is a custom network protocol stack used to transmit data between the first gateway and the second gateway.

[0043] Optionally, the second gateway may include a third network card. The second network card is connected to the third network card, and the second network card and the third network card are set to disable the IP communication protocol, that is, the second network card and the third network card cannot communicate using the public network protocol stack, but need to communicate using the private network protocol stack; the private network protocol stack may include an application layer, a first private layer, a second private layer, and a physical layer. Thus, the private network packet header may include a first private packet header and a second private packet header; among them, the first private layer is a custom communication protocol layer that can support the "micro-tunnel" ability with controllable traffic to support the allocation and control function of end-to-end bandwidth resources; the first private packet header is the packet header encapsulated by the first private layer; the second private layer is a custom communication protocol layer, that is, based on the public network protocol stack, the frame type corresponding to the private network protocol stack is defined to distinguish the IP communication protocol of the public network protocol stack and the non-IP communication protocol of the private network protocol stack; the second private packet header is the packet header encapsulated by the second private layer.

[0044] Furthermore, the source address information in the first public network packet header includes the logical address information of the client, and the destination address information in the first public network packet header includes the logical address information of the first network card; the logical address information may include a logical address and a port number; the first gateway performs address conversion on the first public network packet header to obtain the private network packet header, encapsulates the private network packet header and the packet body to obtain the private network data packet, including Sa1-Sa3:

[0045] Sa1. Based on the logical address information of the first network card, determine the server in the core network accessed by the client.

[0046] Specifically, in one implementation, the first gateway can search for a matching socket record in the existing network socket list based on the logical address and port number of the first network card. The network socket list includes detailed information such as the source logical address, source port number, destination logical address, destination port number, and associated server process. Thus, relevant information about the associated server process, such as the logical address and port number of the server, can be obtained from the matching socket record, and based on this, the server accessed by the client can be determined from the core network.

[0047] In another implementation, the first gateway can query a preset static mapping relationship based on the logical address information of the first network card to determine the server in the core network accessed by the client. The preset static mapping relationship is a pre-configured mapping relationship that is pre-stored in the first gateway. The preset static mapping relationship can include the relationship between the logical address information of the first network card and the logical address information of the server. Specifically, based on the logical address and port number of the first network card, the preset static mapping relationship is queried to obtain the logical address and port number of the corresponding server, and based on this, the server accessed by the client is determined from the core network. Through the preset static mapping relationship, the implementation complexity can be reduced, the calculation efficiency can be improved, and further the determination efficiency and determination accuracy of the server can be improved, providing an accurate data basis for subsequent determination of the private network packet header.

[0048] Sa2. Use the logical address information of the client as the source address of the first private layer, use the logical address information of the server as the destination address of the first private layer, perform encapsulation of the first private layer to obtain the first private packet header, and add the first private packet header in front of the packet body to obtain the first private layer data packet.

[0049] Among them, the first private layer data packet is a data packet obtained by encapsulating the first private packet header and the packet body according to the private network protocol stack.

[0050] Specifically, after determining the server in the core network accessed by the client, encapsulation of the first private layer can be performed, that is, use the logical address and port number of the client in the first public network packet header as the source address of the first private layer, use the logical address and port number of the server as the destination address of the first private layer, perform encapsulation of the first private layer to obtain the first private packet header, and add the first private packet header in front of the packet body to obtain the first private layer data packet.

[0051] Sa3. Use the physical address of the second network card as the source address of the second private layer, use the physical address of the third network card as the destination address of the second private layer, perform encapsulation of the second private layer to obtain the second private packet header, and add the second private packet header in front of the first private layer data packet to obtain the private network data packet.

[0052] Specifically, since the second network card is connected to the third network card of the second gateway, and the second gateway accesses the core network, data transmission is carried out between the second network card of the first gateway and the third network card of the second gateway inside the network isolation system, thereby realizing communication between the first gateway and the second gateway; thus, after obtaining the first private layer data packet, encapsulation of the second private layer can be performed, that is, the physical address of the second network card is used as the source address of the second private layer, the physical address of the third network card is used as the destination address of the second private layer, and the frame type corresponding to the private network protocol stack is used as the frame type of the second private layer to perform encapsulation of the second private layer, obtaining a second private packet header, and adding the second private packet header to the front of the first private layer data packet to obtain a private network data packet.

[0053] In the embodiment of the present application, through the logical address information of the first network card, the server accessed by the client can be accurately and quickly determined, and then, based on the logical address information of the client, the logical address information of the server, the physical address of the second network card, and the physical address of the third network card, encapsulation of the first private layer and the second private layer is performed in sequence, and the first public network data packet can be accurately converted into a private network data packet, thereby realizing the function of non-IP communication between the first gateway and the second gateway; since there may be a router between the first gateway and the second gateway when the first gateway and the second gateway are in a wide area network, if IP communication is used between the first gateway and the second gateway at this time, forged IP data packets can also be transmitted between the first gateway and the second gateway, resulting in attacks on the servers in the core network. Therefore, non-IP communication between the first gateway and the second gateway can reduce the risk of the core network being attacked due to forged IP data packets and ensure the operation security of the core network.

[0054] After obtaining the private network data packet, the private network data packet can be sent to the second gateway through the first gateway, that is, the second network card of the first gateway sends the private network data packet to the third network card of the second gateway through the physical layer.

[0055] S130. Perform address conversion on the private packet header of the private network data packet through the second gateway to obtain a second public packet header, encapsulate the second public packet header and the packet body to obtain a second public network request data packet, and send the second public network request data packet to the server in the core network.

[0056] Among them, the second public packet header is the packet header obtained after the second gateway performs address conversion on the private packet header; the second public packet header may include a transport layer packet header, a network layer packet header, and a data link layer packet header. The second public network request data packet is a data packet obtained by encapsulating the second public packet header and the packet body according to the public network protocol stack.

[0057] Specifically, the second gateway can receive the private network data packets sent by the first gateway, parse the private network data packets to obtain the private network packet header and the packet body, then perform address conversion on the private network packet header to obtain the second public network packet header. For example, based on the information in the private network packet header, determine the source address and the destination address in the second public network packet header; then, encapsulate the second public network packet header and the packet body according to the public network protocol stack to obtain the second public network request data packet, and send the second public network request data packet to the server in the core network.

[0058] Optionally, the second gateway further includes a fourth network card. The fourth network card accesses the core network, and the fourth network card is connected to the third network card; Exemplarily, as Figure 3 shown is another structural schematic diagram of the network isolation system provided by the embodiment of the present application. Figure 3 The first gateway in [the figure] includes a first network card and a second network card, the second gateway includes a third network card and a fourth network card, and the second network card is connected to the third network card; The first network card accesses the application network and can communicate with m clients in the application network; The fourth network card accesses the core network and can communicate with n servers in the core network.

[0059] Furthermore, performing address conversion on the private network packet header of the private network data packet by the second gateway to obtain the second public network packet header, and encapsulating the second public network packet header and the packet body to obtain the second public network request data packet includes Sb1 - Sb4:

[0060] Sb1. Receive the private network data packet sent by the second network card through the third network card, and parse the private network data packet to obtain the private network packet header and the packet body.

[0061] Specifically, the second gateway receives the private network data packet sent by the second network card through the third network card, and parses the private network data packet according to the private network protocol stack to obtain the private network packet header and the packet body, that is, perform parsing of the second private layer on the private network data packet to obtain the second private packet header and the first private layer data packet, and when the content of the frame type field in the second private packet header is the private frame type, perform parsing of the first private layer on the first private layer data packet to obtain the first private packet header and the packet body; The private frame type among them is the frame type corresponding to the private network protocol stack.

[0062] Specifically, the private network data packet is parsed at the second private layer according to the private network protocol stack to obtain the header information and the data body. At this time, the header information is the second private packet header, and the data body is the first private layer data packet. Then, compare the content of the frame type field in the second private packet header with the private frame type. If the content of the frame type field in the second private packet header is the private frame type, it indicates that the private network data packet is a data packet sent by the first gateway through a non-IP communication protocol. At this time, the first private layer data packet can be further parsed at the first private layer to obtain the first private packet header and the packet body. If the content of the frame type field in the second private packet header is not the private frame type, it indicates that the received data packet at this time is not a data packet sent by the first gateway through a non-IP communication protocol, but a data packet sent by other devices through an IP communication protocol. At this time, discard the data packet.

[0063] In the embodiment of the present application, the data packets received by the second gateway include not only the data packets sent by the first gateway through the second network card, but also the data packets sent by other devices. Therefore, when the content of the frame type field in the second private packet header is the private frame type, the data packet is further parsed at the first private layer, which can filter the data packets encapsulated by the public network protocol stack, thereby ensuring the non-IP communication function between the first gateway and the second gateway, reducing the risk of the core network being attacked due to forged IP data packets, and ensuring the operation security of the core network.

[0064] Sb2. Use the port number of the fourth network card as the source port number of the transport layer, use the port number of the server in the private network packet header as the destination port number of the transport layer, perform encapsulation of the transport layer to obtain the transport layer packet header, and add the transport layer packet header before the packet body to obtain the transport layer data packet.

[0065] Specifically, since the fourth network card is connected to the core network, the network isolation system transmits data with the server in the core network through the fourth network card of the second gateway, so as to realize the communication between the network isolation system and the server. Therefore, after obtaining the private network packet header and the packet body, perform encapsulation of the transport layer, that is, the second gateway selects an unused port number from the available port number range of the fourth network card as the source port number of the transport layer, that is, uses the port number of the fourth network card as the source port number of the transport layer, then obtains the port number of the server from the private network packet header, and uses the port number of the server as the destination port number of the transport layer, perform encapsulation of the transport layer to obtain the transport layer packet header, and then add the transport layer packet header before the packet body to obtain the transport layer data packet.

[0066] Sb3. Use the logical address of the fourth network card as the source address of the network layer, use the logical address of the server in the private network packet header as the destination address of the network layer, perform encapsulation of the network layer to obtain the network layer packet header, and add the network layer packet header before the transport layer data packet to obtain the network layer data packet.

[0067] Specifically, after obtaining the transport layer data packet, network layer encapsulation is performed. That is, the second gateway uses the logical address of the fourth network card as the source address of the network layer, and obtains the logical address of the server from the private network packet header. Then, the logical address of the server is used as the destination address of the network layer to perform network layer encapsulation, obtaining a network layer packet header, and adding the network layer packet header to the front of the transport layer data packet to obtain a network layer data packet.

[0068] Sb4. Use the physical address of the fourth network card as the source address of the data link layer, and use the physical address of the server as the destination address of the data link layer to perform data link layer encapsulation, obtaining a data link layer packet header, and adding the data link layer packet header to the front of the network layer data packet to obtain a second public network request data packet.

[0069] Specifically, after obtaining the network layer data packet, data link layer encapsulation is performed. That is, the second gateway queries the second preset relationship table based on the logical address of the server. The second preset relationship table is used to store the mapping relationship between the logical address and the physical address of the server, from which the physical address of the server can be obtained. Then, the physical address of the fourth network card is used as the source address of the data link layer, and the physical address of the server is used as the destination address of the data link layer to perform data link layer encapsulation, obtaining a data link layer packet header, and adding the data link layer packet header to the front of the network layer data packet to obtain a second public network request data packet.

[0070] In the embodiment of the present application, based on the port number, logical address, and physical address of the fourth network card, as well as the port number, logical address, and physical address of the server, encapsulation of the transport layer, network layer, and data link layer is performed in sequence, which can accurately convert the private network data packet into a second public network request data packet, thereby realizing the network isolation function of the network isolation system.

[0071] After obtaining the second public network request data packet, the second public network request data packet is sent to the server in the core network through the fourth network card of the second gateway. That is, the fourth network card sends the second public network request data packet to the server through the physical layer, so that the server can parse the second public network request data packet according to the public network protocol stack and feedback the response data packet of the second public network request data packet. Sending the data packet to the server through the fourth network card can improve the communication efficiency between the second gateway and the server, and is convenient for monitoring network activities and data auditing, thereby ensuring the operation safety of the server.

[0072] Optionally, after the private network packet header of the private network packet is address-converted by the second gateway to obtain the second public network packet header, and the second public network packet header and the packet body are encapsulated to obtain the second public network request packet, a dynamic mapping relationship can be established through the second gateway and the dynamic mapping relationship can be stored. At this time, the dynamic mapping relationship is the relationship between the logical address information of the client and the logical address information of the fourth network card. The logical address information of the client is the source address in the first private packet header of the private network packet, that is, the logical address and port number of the client. The logical address information of the fourth network card includes the source port number in the transport layer packet header of the second public network request packet and the source address in the network layer packet header, that is, the port number and logical address of the fourth network card. By establishing the dynamic mapping relationship, an accurate data basis is provided for subsequent address conversion of the response packet.

[0073] Optionally, after the second public network request packet is sent to the server in the core network through the second gateway, the response packet of the server for the second public network request packet can be received through the fourth network card, and based on the dynamic mapping relationship, the packet header of the response packet is address-converted so that the destination address of the first private layer is the logical address information of the client.

[0074] Specifically, after the second public network request packet is sent to the server in the core network through the second gateway, the server can receive the second public network request packet sent by the fourth network card, parse the second public network request packet according to the public network protocol stack to obtain the second public network packet header and the packet body, then parse the packet body at the application layer to obtain the request data, and generate the response data corresponding to the request data (such as the data corresponding to the SQL statement or the operation execution result). Then, the response data is encapsulated at the application layer, transport layer, network layer, and data link layer in sequence according to the public network protocol stack to obtain the response packet, and the response packet is sent to the fourth network card. Among them, the source port number of the response packet at the transport layer is the port number of the server in the second public network packet header, the destination port number at the transport layer is the port number of the fourth network card in the second public network packet header, the source address at the network layer is the logical address of the server, the destination address at the network layer is the logical address of the fourth network card in the second public network packet header, the source address at the data link layer is the physical address of the server, and the destination address at the data link layer is the physical address of the fourth network card in the second public network packet header.

[0075] Then, the second gateway receives the response packet from the server for the second public network request packet through the fourth network card, and parses the response packet according to the public network protocol stack to obtain the first public network response packet header and the response packet body. At this time, the response packet body is the packet encapsulated at the application layer. Then, obtain the destination port number at the transport layer and the destination address at the network layer from the first public network response packet header, get the port number and logical address of the fourth network card, and query the dynamic mapping relationship based on the port number and logical address of the fourth network card to obtain the logical address information of the corresponding client, that is, the port number and logical address of the client. Then, perform address conversion on the packet header of the response packet (i.e., the first public network response packet header) according to the private network protocol stack to obtain the private network response packet header, and add the private network response packet header in front of the response packet body to obtain the private network response packet. After that, send the private network response packet to the second network card through the third network card; wherein, the source address of the private network response packet in the first private layer is the logical address information of the server, the destination address in the first private layer is the logical address information of the client, the source address in the second private layer is the physical address of the third network card, the destination address in the second private layer is the physical address of the second network card, and, the frame type in the second private layer is the private frame type. It should be noted that after the second gateway performs address conversion on the packet header of the response packet based on the dynamic mapping relationship to obtain the private network response packet header, clear the dynamic mapping relationship.

[0076] After that, the first gateway receives the private network response packet sent by the third network card through the second network card, and performs parsing on the private network response packet in the second private layer. If the content of the frame type field is the private frame type, continue to perform parsing in the first private layer to obtain the private network response packet header and the response packet body. Then, perform address conversion on the private network response packet header to obtain the second public network response packet header, and add the second public network response packet header in front of the response packet body to obtain the second public network response packet; wherein, the source port number of the second public network response packet at the transport layer is the port number of the first network card (i.e., the port number of the first network card in the first public network packet header), the destination port number at the transport layer is the port number of the client in the private network response packet header, the source address at the network layer is the logical address of the first network card, the destination address at the network layer is the logical address of the client in the private network response packet header, the source address at the data link layer is the physical address of the first network card, and, the destination address at the data link layer is the physical address of the client in the private network response packet header.

[0077] In the technical solution of the embodiment of the present application, the first gateway receives the first public network request data packet sent by the client in the application network; the first gateway performs address conversion on the first public network packet header to obtain a private network packet header, encapsulates the private network packet header and the packet body to obtain a private network data packet, and sends the private network data packet to the second gateway; the second gateway performs address conversion on the private network packet header of the private network data packet to obtain a second public network packet header, encapsulates the second public network packet header and the packet body to obtain a second public network request data packet, and sends the second public network request data packet to the server in the core network. In the above technical solution, the first gateway converts the first public network request data packet sent by the client in the application network into a private network data packet, and then the second gateway converts the private network data packet into a second public network request data packet and sends the second public network request data packet to the server in the core network. Through the first gateway and the second gateway of the network isolation system, the logical isolation function between the application network and the core network is realized, and there is no need to deploy hardware devices such as network gates for physical isolation, which reduces the cost. Moreover, the installation, deployment and maintenance of the network isolation system are relatively simple. At the same time, the first gateway and the second gateway can perform dynamic resource allocation according to the actual situation (such as dynamically allocating port numbers, etc.), which improves the data throughput rate, and improves the data transmission efficiency, shortens the transmission delay, and solves the problems of high cost, low data throughput rate and long delay existing in the network isolation method of the prior art; in addition, the first gateway and the second gateway communicate through a private network protocol stack instead of a public network protocol stack including an IP communication protocol, which can realize non-IP communication between the first gateway and the second gateway, thereby reducing the risk of the core network being attacked due to forged IP data packets, and thus ensuring the operation security of the core network.

[0078] Figure 4 is a schematic structural diagram of a network isolation device provided by an embodiment of the present application. Referring to Figure 4 , the network isolation device may include:

[0079] A receiving module 410, configured to receive, through the first gateway, a first public network request data packet sent by a client in the application network; the first public network request data packet includes a first public network packet header and a packet body;

[0080] A first conversion module 420, configured to perform address conversion on the first public network packet header through the first gateway to obtain a private network packet header, encapsulate the private network packet header and the packet body to obtain a private network data packet, and send the private network data packet to the second gateway;

[0081] A second conversion module 430, configured to perform address conversion on the private network packet header of the private network data packet through the second gateway to obtain a second public network packet header, encapsulate the second public network packet header and the packet body to obtain a second public network request data packet, and send the second public network request data packet to a server in the core network.

[0082] In one embodiment, the first gateway includes a first network card and a second network card that are connected to each other. The second gateway includes a third network card, and the second network card is connected to the third network card. The first network card accesses the application network. The source address information in the first public network packet header includes the logical address information of the client, and the destination address information in the first public network packet header includes the logical address information of the first network card. The private network packet header includes a first private packet header and a second private packet header. The first conversion module 420 performs address conversion on the first public network packet header through the first gateway to obtain the private network packet header, encapsulates the private network packet header and the packet body to obtain the private network data packet, including: determining the server in the core network accessed by the client based on the logical address information of the first network card; using the logical address information of the client as the source address of the first private layer and the logical address information of the server as the destination address of the first private layer to perform encapsulation of the first private layer to obtain the first private packet header, and adding the first private packet header before the packet body to obtain the first private layer data packet; using the physical address of the second network card as the source address of the second private layer and the physical address of the third network card as the destination address of the second private layer to perform encapsulation of the second private layer to obtain the second private packet header, and adding the second private packet header before the first private layer data packet to obtain the private network data packet.

[0083] In one embodiment, the second gateway further includes a fourth network card. The fourth network card accesses the core network, and the fourth network card is connected to the third network card. The second conversion module 430 sends a second public network request data packet to the server in the core network through the second gateway, including: sending the second public network request data packet to the server in the core network through the fourth network card, so that the server parses the second public network request data packet according to the public network protocol stack and feeds back the response data packet of the second public network request data packet.

[0084] In one embodiment, the public network protocol stack includes an application layer, a transport layer, a network layer, and a data link layer. The packet body is a data packet encapsulated by the application layer. The logical address information includes a logical address and a port number. The second public network packet header includes a transport layer packet header, a network layer packet header, and a data link layer packet header. The second conversion module 430 performs address conversion on the private network packet header of the private network data packet through the second gateway to obtain the second public network packet header, encapsulates the second public network packet header and the packet body to obtain the second public network request data packet, including: receiving the private network data packet sent by the second network card through the third network card and parsing the private network data packet to obtain the private network packet header and the packet body; using the port number of the fourth network card as the source port number of the transport layer, using the port number of the server in the private network packet header as the destination port number of the transport layer, performing encapsulation of the transport layer to obtain the transport layer packet header, and adding the transport layer packet header before the packet body to obtain the transport layer data packet; using the logical address of the fourth network card as the source address of the network layer, using the logical address of the server in the private network packet header as the destination address of the network layer, performing encapsulation of the network layer to obtain the network layer packet header, and adding the network layer packet header before the transport layer data packet to obtain the network layer data packet; using the physical address of the fourth network card as the source address of the data link layer, using the physical address of the server as the destination address of the data link layer, performing encapsulation of the data link layer to obtain the data link layer packet header, and adding the data link layer packet header before the network layer data packet to obtain the second public network request data packet.

[0085] In one embodiment, the second conversion module 430 parses the private network data packet through the second gateway to obtain the private network packet header and the packet body, including: parsing the private network data packet at the second private layer to obtain the second private packet header and the first private layer data packet; when the content of the frame type field in the second private packet header is the private frame type, parsing the first private layer data packet at the first private layer to obtain the first private packet header and the packet body.

[0086] In one embodiment, the network isolation device further includes a relationship establishment module. The relationship establishment module is specifically configured to: after performing address conversion on the private network packet header of the private network data packet through the second gateway to obtain the second public network packet header, encapsulating the second public network packet header and the packet body to obtain the second public network request data packet, establish a dynamic mapping relationship through the second gateway. The dynamic mapping relationship is the relationship between the logical address information of the client and the logical address information of the fourth network card;

[0087] The network isolation device further includes a third conversion module. The third conversion module is specifically configured to: after sending the second public network request data packet to the server in the core network through the second gateway, receive the response data packet of the server for the second public network request data packet through the fourth network card, and perform address conversion on the packet header of the response data packet based on the dynamic mapping relationship, so that the destination address of the first private layer is the logical address information of the client.

[0088] In one embodiment, the first conversion module 420 determines the server in the core network accessed by the client through the first gateway based on the logical address information of the first network card, including: querying a preset static mapping relationship based on the logical address information of the first network card to determine the server in the core network accessed by the client, where the preset static mapping relationship includes the relationship between the logical address information of the first network card and the logical address information of the server.

[0089] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above division of each functional module is used as an example. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the above-described functional modules can refer to the corresponding process in the foregoing method embodiments and will not be elaborated herein.

[0090] The network isolation device provided in this embodiment is applicable to the network isolation method provided in any of the above embodiments and has corresponding functions and beneficial effects.

[0091] Figure 5 It is a schematic structural diagram of an electronic device provided in an embodiment of the present application. Figure 5 The block diagram of an exemplary electronic device 11 suitable for implementing the embodiments of the present application is shown. Figure 5 The shown electronic device 11 is only an example and should not impose any limitation on the functions and usage scope of this embodiment.

[0092] As Figure 5 shown, the electronic device 11 is presented in the form of a general-purpose computing electronic device. The components of the electronic device 11 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).

[0093] The bus 18 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus structures. For example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0094] The electronic device 11 typically includes a variety of computer system-readable media. These media can be any available media accessible by the electronic device 11, including volatile and non-volatile media, removable and non-removable media.

[0095] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The electronic device 11 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 34 may be used for reading and writing on non-removable, non-volatile magnetic media ( Figure 5 not shown, typically referred to as a "hard disk drive"). Although Figure 5 not shown in the figure, a disk drive for reading and writing on removable non-volatile disks (such as a "floppy disk"), and an optical disk drive for reading and writing on removable non-volatile optical disks (such as CD-ROM, DVD-ROM or other optical media) may be provided. In these cases, each drive may be connected to the bus 18 through one or more data media interfaces. The system memory 28 may include at least one program product having a set (e.g., at least one) of program modules that are configured to perform the functions of the embodiments of the present application.

[0096] A program / utilities 40 having a set (at least one) of program modules 42 may be stored, for example, in the system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules 42 generally perform the functions and / or methods in the embodiments described in the present application.

[0097] The electronic device 11 may also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and may also communicate with one or more devices that enable a user to interact with the electronic device 11, and / or communicate with any device that enables the electronic device 11 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication may be carried out through an input / output (I / O) interface 22. Moreover, the electronic device 11 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 20.

[0098] As Figure 5 shown, the network adapter 20 communicates with other modules of the electronic device 11 through the bus 18. It should be understood that although Figure 5 not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 11, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0099] The processing unit 16 executes various functional applications and page displays by running the programs stored in the system memory 28, such as implementing a network isolation method provided in this embodiment, which is applied to a network isolation system. The network isolation system includes a first gateway and a second gateway connected to each other. The first gateway accesses the application network, and the second gateway accesses the core network. The method includes:

[0100] Receiving, by the first gateway, a first public network request data packet sent by a client in the application network; the first public network request data packet includes a first public network header and a packet body;

[0101] Performing, by the first gateway, address conversion on the first public network header to obtain a private network header, encapsulating the private network header and the packet body to obtain a private network data packet, and sending the private network data packet to the second gateway;

[0102] Performing, by the second gateway, address conversion on the private network header of the private network data packet to obtain a second public network header, encapsulating the second public network header and the packet body to obtain a second public network request data packet, and sending the second public network request data packet to a server in the core network.

[0103] Of course, those skilled in the art can understand that the processor can also implement the technical solutions of the network isolation method provided in any embodiment of the present application.

[0104] The embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements, for example, a network isolation method provided in the embodiment of the present application, which is applied to a network isolation system. The network isolation system includes a first gateway and a second gateway connected to each other. The first gateway accesses the application network, and the second gateway accesses the core network. The method includes:

[0105] Receiving, by the first gateway, a first public network request data packet sent by a client in the application network; the first public network request data packet includes a first public network header and a packet body;

[0106] Performing, by the first gateway, address conversion on the first public network header to obtain a private network header, encapsulating the private network header and the packet body to obtain a private network data packet, and sending the private network data packet to the second gateway;

[0107] Performing, by the second gateway, address conversion on the private network header of the private network data packet to obtain a second public network header, encapsulating the second public network header and the packet body to obtain a second public network request data packet, and sending the second public network request data packet to a server in the core network.

[0108] The computer storage medium of this embodiment may adopt any combination of one or more computer-readable media. The computer-readable media can be computer-readable signal media or computer-readable storage media. The computer-readable storage media can be, for example, but not limited to: electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage media include: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this document, the computer-readable storage media can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or component.

[0109] The computer-readable signal media can include data signals propagated in a baseband or as part of a carrier wave, which carry computer-readable program codes. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal media can also be any computer-readable medium other than the computer-readable storage media, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, device, or component.

[0110] The program codes contained on the computer-readable media can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0111] The computer program codes for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program codes can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0112] Those of ordinary skill in the art should understand that the various modules or steps of the present application described above can be implemented using a general-purpose computing device. They can be concentrated on a single computing device or distributed across a network composed of multiple computing devices. Optionally, they can be implemented using program code executable by a computer device, so that they can be stored in a storage device and executed by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.

[0113] In addition, in the technical solution of the present application, the acquisition, storage, use, processing, etc. of data all comply with the relevant provisions of national laws and regulations.

[0114] Note that the above is only the preferred embodiment of the present application and the applied technical principle. Those skilled in the art will understand that the present application is not limited to the specific embodiment here, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments. Without departing from the inventive concept of the present application, more other equivalent embodiments can be included, and the scope of the present application is determined by the scope of the appended claims.

Claims

1. A network isolation method, characterized in that: Applied to a network isolation system, the network isolation system includes a first gateway and a second gateway connected to each other, the first gateway accesses an application network, and the second gateway accesses a core network, the method includes: receiving, through the first gateway, a first public network request data packet sent by a client in the application network; the first public network request data packet includes a first public network packet header and a packet body; Performing address translation on the first public network packet header through the first gateway to obtain a private network packet header, encapsulating the private network packet header and the packet body to obtain a private network data packet, and sending the private network data packet to the second gateway; The private network header of the private network data packet is address translated through the second gateway to obtain a second public network header, the second public network header and the packet body are encapsulated to obtain a second public network request data packet, and the second public network request data packet is sent to the server in the core network.

2. The network isolation method according to claim 1, characterized in that: The first gateway includes a first network card and a second network card connected to each other, the second gateway includes a third network card, the second network card is connected to the third network card, the first network card is connected to the application network, the source address information in the first public network packet header includes the logical address information of the client, the destination address information in the first public network packet header includes the logical address information of the first network card, the private network packet header includes a first private packet header and a second private packet header, and the first gateway performs address conversion on the first public network packet header to obtain a private network packet header, encapsulates the private network packet header and the packet body to obtain a private network data packet, including: Determining a server in the core network accessed by the client based on the logical address information of the first network card; Using the logical address information of the client as the source address of the first private layer, using the logical address information of the server as the destination address of the first private layer, performing encapsulation of the first private layer to obtain the first private packet header, and adding the first private packet header to the front of the packet body to obtain a first private layer data packet; The physical address of the second network card is used as the source address of the second private layer, and the physical address of the third network card is used as the destination address of the second private layer, and the second private layer is encapsulated to obtain the second private packet header, and the second private packet header is added to the front of the first private layer data packet to obtain the private network data packet.

3. The network isolation method according to claim 2, characterized in that: The second gateway further includes a fourth network card, the fourth network card is connected to the core network, the fourth network card is connected to the third network card, and the second public network request data packet is sent to the server in the core network through the second gateway, including: The second public network request data packet is sent to the server in the core network through the fourth network card, so that the server parses the second public network request data packet according to the public network protocol stack and feeds back a response data packet of the second public network request data packet.

4. The network isolation method according to claim 3, characterized in that: The public network protocol stack includes an application layer, a transport layer, a network layer and a data link layer, the packet body is a data packet encapsulated by the application layer, the logical address information includes a logical address and a port number, the second public network packet header includes a transport layer packet header, a network layer packet header and a data link layer packet header, the second gateway performs address conversion on the private network packet header of the private network data packet to obtain a second public network packet header, encapsulates the second public network packet header and the packet body to obtain a second public network request data packet, including: Receiving the private network data packet sent by the second network card through the third network card, and parsing the private network data packet to obtain the private network packet header and the packet body; Using the port number of the fourth network card as the source port number of the transport layer, using the port number of the server in the private network packet header as the destination port number of the transport layer, performing transport layer encapsulation to obtain the transport layer packet header, and adding the transport layer packet header to the front of the packet body to obtain a transport layer data packet; Using the logical address of the fourth network card as the source address of the network layer, using the logical address of the server in the private network packet header as the destination address of the network layer, performing network layer encapsulation to obtain the network layer packet header, and adding the network layer packet header to the front of the transport layer data packet to obtain a network layer data packet; The physical address of the fourth network card is used as the source address of the data link layer, and the physical address of the server is used as the destination address of the data link layer. The data link layer is encapsulated to obtain the data link layer header, and the data link layer header is added to the front of the network layer data packet to obtain the second public network request data packet.

5. The network isolation method according to claim 4, characterized in that: Parsing the private network data packet through the second gateway to obtain the private network packet header and the packet body includes: Performing second private layer parsing on the private network data packet to obtain the second private packet header and the first private layer data packet; When the content of the frame type field of the second private packet header is a private frame type, the first private layer data packet is parsed at the first private layer to obtain the first private packet header and the packet body.

6. The network isolation method according to claim 4, characterized in that: After performing address translation on the private network header of the private network data packet through the second gateway to obtain a second public network header, encapsulating the second public network header and the packet body to obtain a second public network request data packet, the method further includes: Establishing a dynamic mapping relationship through the second gateway, where the dynamic mapping relationship is the relationship between the logical address information of the client and the logical address information of the fourth network card; After sending the second public network request data packet to the server in the core network through the second gateway, the method further includes: The server's response data packet to the second public network request data packet is received through the fourth network card, and based on the dynamic mapping relationship, the packet header of the response data packet is address translated so that the destination address of the first private layer is the logical address information of the client.

7. The network isolation method according to claim 2, characterized in that: Determining, by the first gateway based on the logical address information of the first network card, a server in the core network accessed by the client, includes: The preset static mapping relationship is queried based on the logical address information of the first network card to determine the server in the core network accessed by the client, wherein the preset static mapping relationship includes the relationship between the logical address information of the first network card and the logical address information of the server.

8. A network isolation device, characterized in that: Applied to a network isolation system, the network isolation system includes a first gateway and a second gateway connected to each other, the first gateway accesses an application network, and the second gateway accesses a core network, the device includes: A receiving module, configured to receive, through the first gateway, a first public network request data packet sent by a client in the application network; the first public network request data packet includes a first public network packet header and a packet body; A first conversion module, configured to perform address conversion on the first public network packet header through the first gateway to obtain a private network packet header, encapsulate the private network packet header and the packet body to obtain a private network data packet, and send the private network data packet to the second gateway; The second conversion module is used to perform address conversion on the private network header of the private network data packet through the second gateway to obtain a second public network header, encapsulate the second public network header and the packet body to obtain a second public network request data packet, and send the second public network request data packet to the server in the core network.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the network isolation method described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the network isolation method as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Information safe transmission control method between inside network and outside network and gateway thereof

    CN102882828A

  • Method for building multi-server remote intelligent monitoring system based on WINCC platform

    CN107861378A

  • Network security isolation and data exchange oil field power plant network application system

    CN110278184A

  • Equipment, system and method for reliably transmitting multiple paths of data

    CN114826813A

  • Cross-electric-power-safety-area http asynchronous transmission method and device and storage medium

    CN115643221A

Cited By

  • Data transmission method, device and system, gateway, storage medium and program product

    CN120711073A