Data cross-network exchange method, device and system

By providing a cross-network switching method that is compatible with multiple cross-network switching devices, the management problems caused by the diversity and complexity of cross-network switching devices are solved, unified management and efficient operation and maintenance are achieved, and network operation efficiency and security protection capabilities are improved.

CN120090846APending Publication Date: 2025-06-03BEIJING GUOYUN DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510249034.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

In the prior art, the diversity and complexity of cross-network switching equipment leads to enterprises that need to invest a lot of resources in business integration, configuration management and later maintenance, making it difficult to achieve unified management and efficient operation and maintenance.

Method used

It provides a cross-network data exchange method, device and system, which is compatible with a variety of cross-network switching devices, flexibly configures transmission strategies according to requirements and hardware devices, and provides unified calling methods and standards to realize unified managed cross-network data exchange.

Benefits of technology

Through this method, enterprises can improve network operation efficiency, reduce maintenance costs, and enhance security protection capabilities of confidential networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090846A_ABST
    Figure CN120090846A_ABST
Patent Text Reader

Abstract

The invention provides a data cross-network exchange method, device and system. The system comprises an application data receiving module, a first public buffer area, a security detection module, a data routing configuration library, a first data exchange processing module, a data security encryption module, a sending cache library, a first message queue, an exchange data sending module, a first exchange equipment integration module, a second exchange equipment integration module and an exchange data receiving module. The cooperation among the second public buffer area, the data format conversion module, the second data exchange processing module, the data security decryption module, the distribution cache library, the second message queue and the application data distribution module can be compatible with various hardware devices, the unified cross-network data exchange service is realized, the flexibility and the expandability are improved, and the data exchange efficiency is improved. And safe, efficient and reliable transmission of data among different networks is ensured. The maintenance cost of networks with different security levels under the condition of physical isolation is reduced, and the security protection capability of the confidential network is further enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method, device, and system for cross-network data exchange. Background Art

[0002] In the context of the increasingly severe threat of high-tech espionage, in order to ensure that the internal network of classified units is protected from external, especially illegal intrusion from overseas networks, implementing a strict physical isolation strategy between classified networks and public networks has become a key measure. By establishing a closed classified network environment, this measure clearly defines the security boundary, significantly improves the controllability and protection ability of the network, and lays a solid foundation for internal management and security prevention. As an important means of network security and data protection, physical isolation technology has been widely integrated into the construction of modern network systems.

[0003] However, although physical isolation strengthens the security barrier, it also brings new challenges to data circulation between networks. Given that the need for data exchange does not disappear due to isolation, it is inevitable to develop and implement an efficient solution for data and file exchange between isolated networks. In the current market, there are various technical approaches and tools to meet this demand, including but not limited to cross-network exchange hardware devices such as VPN gateways, ordinary network gates, unidirectional optical gates, image ferry machines, and optical disc ferry machines. The integration solution of cross-network isolation exchange devices needs to comprehensively consider business requirements, security requirements, and technical feasibility, and through in-depth customization of business systems, can achieve safe and efficient data exchange under strict physical isolation conditions.

[0004] The diversity and complexity of cross-network exchange devices in the current market pose challenges to the operation and maintenance management of enterprises. Different brands and models of devices need to be adapted to their respective exchange systems, resulting in enterprises having to invest a large amount of resources in business integration, configuration management, and subsequent maintenance, and it is difficult to achieve unified management and efficient operation and maintenance. Summary of the Invention

[0005] The purpose of this application is to provide a method, device, and system for cross-network data exchange, which can be compatible with a variety of cross-network exchange devices, flexibly configure transmission strategies according to requirements and hardware devices, provide a unified call method and standard externally, and achieve cross-network data exchange with unified management, which helps to improve the network operation efficiency of enterprises, reduce maintenance costs, and further enhance the security protection ability of classified networks.

[0006] In a first aspect, the present application provides a method for cross-network data exchange. The method includes: receiving a data file to be exchanged sent by a target application and storing the data file in a first common buffer; performing a security detection operation on all data files in the first common buffer; obtaining the data files that pass the security detection and the routing unique identifier, retrieving a data routing configuration library according to the routing unique identifier to obtain routing information and device information, and performing device type matching according to the data confidentiality level in the routing information to obtain the device type; generating a task file corresponding to the data file based on the routing information and the device information, and performing encryption processing on the data file; storing the task file and the encrypted data file in a sending cache library, and generating sending task information and storing it in a first message queue; reading the first message queue to obtain the sending task information, and determining the data file and the task file to be sent; sending the data file and the task file to be sent to a cross-network exchange hardware device corresponding to the device type, so that the cross-network exchange hardware device ferries the data file and the task file; receiving the data file and the task file transmitted by the cross-network exchange hardware device, and storing the data file and the task file in a second common buffer; scanning and parsing the task file in the second common buffer, and performing integrity verification on the data file that has been transmitted according to the parsed file hash value; if the file is incomplete, deleting the relevant data file and task file in the second common buffer; if the file is complete, verifying and decrypting the data file; performing format conversion on the decrypted data file according to the target data format recorded in the task file; storing the data file after format conversion in a distribution cache library, and generating distribution task information and storing it in a second message queue; reading the second message queue to obtain the distribution task information, and obtaining the corresponding data file from the distribution cache library and sending it to the target application.

[0007] Second aspect, the present application further provides a data cross-network exchange device, which includes: an application data receiving module, configured to receive a data file to be exchanged sent by a target application and store the data file in a first common buffer; a security detection module, configured to perform a security detection operation on all data files in the first common buffer; a first data exchange processing module, configured to obtain the data files and routing unique identifiers that have passed the security detection, retrieve a data routing configuration library according to the routing unique identifiers, obtain routing information and device information, and perform device type matching according to the data classification level in the routing information to obtain a device type; generate a paired task file based on the routing information and device information, and encrypt the data file through a data security encryption module; the first data exchange processing module is further configured to store the task file and the encrypted data file in a sending cache library, and generate sending task information and store it in a first message queue; a data exchange sending module, configured to read the first message queue to obtain the sending task information, and determine the data file and task file to be sent; a first exchange device integration module, configured to send the data file and task file to be sent to a cross-network exchange hardware device corresponding to the device type, so that the cross-network exchange hardware device ferries the data file and the task file; a second exchange device integration module, configured to receive the data file and task file transmitted by the cross-network exchange hardware device; a data exchange receiving module, configured to store the data file and task file in a second common buffer; a second data exchange processing module, configured to scan and parse the task file in the second common buffer, and perform integrity verification on the data file that has been transmitted according to the parsed file hash value; if the file is incomplete, delete the relevant data file and task file in the second common buffer; if the file is complete, verify and decrypt the data file through a data security decryption module; through a data format conversion module, convert the format of the decrypted data file according to the target data format recorded in the task file; the second data exchange processing module is further configured to store the data file after format conversion in a distribution cache library, and generate distribution task information and store it in a second message queue; an application data distribution module, configured to read the second message queue to obtain the distribution task information, and obtain the corresponding data file from the distribution cache library and send it to the target application.

[0008] Third aspect, the present application further provides a data cross-network exchange system, which includes: a server and multiple cross-network exchange hardware devices connected by communication; the server is configured with the data cross-network exchange device as described in the second aspect, and is used to execute the data cross-network exchange method as described in any item of the first aspect.

[0009] Fourth aspect, the present application further provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions cause the processor to implement the method described in the first aspect above.

[0010] In the data cross-network exchange method, device, and system provided by this application, first, receive the data file to be exchanged sent by the target application, and store the data file in the first common buffer; perform a security detection operation on all data files in the first common buffer; obtain the data files that pass the security detection and the routing unique identifier, retrieve the data routing configuration library according to the routing unique identifier, obtain the routing information and device information, and perform device type matching according to the data confidentiality level in the routing information to obtain the device type; generate a task file corresponding to the data file based on the routing information and device information, and perform encryption processing on the data file; store the task file and the encrypted data file in the sending cache library, and generate sending task information and store it in the first message queue; read the first message queue to obtain the sending task information, and determine the data file and task file to be sent; send the data file and task file to be sent to the cross-network exchange hardware device corresponding to the device type, so that the cross-network exchange hardware device ferries the data file and task file; receive the data file and task file transmitted by the cross-network exchange hardware device, and store the data file and task file in the second common buffer; scan and parse the task file in the second common buffer, and perform integrity verification on the data file that has been transmitted according to the parsed file hash value; if the file is incomplete, delete the relevant data file and task file in the second common buffer; if the file is complete, verify and decrypt the data file; perform format conversion on the decrypted data file according to the target data format recorded in the task file; store the data file after format conversion in the distribution cache library, and generate distribution task information and store it in the second message queue; read the second message queue to obtain the distribution task information, and obtain the corresponding data file from the distribution cache library and send it to the target application. This application can be compatible with a variety of cross-network exchange devices, flexibly configure transmission strategies according to requirements and hardware devices, provide a unified call method and standard externally, realize unified management of cross-network data exchange, help improve the network operation efficiency of enterprises, reduce maintenance costs, and further enhance the security protection ability of the confidential network. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0012] Figure 1 It is a flowchart of a data cross-network exchange method provided by an embodiment of the present application;

[0013] Figure 2Schematic diagram of modules in a server corresponding to a data cross-network exchange method provided by an embodiment of the present application;

[0014] Figure 3 Partial flowchart of another data cross-network exchange method provided by an embodiment of the present application;

[0015] Figure 4 Partial flowchart of another data cross-network exchange method provided by an embodiment of the present application;

[0016] Figure 5 Schematic diagram of the structure of a data cross-network exchange system provided by an embodiment of the present application. Detailed implementation manners

[0017] The technical solutions of the present application will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0018] The following is a description of the integration of several common existing cross-network isolation and exchange devices:

[0019] (1) VPN gateway integration:

[0020] VPN gateways are usually used to establish secure remote access connections. However, in cross-network isolation scenarios, specific tunnels and encryption protocols need to be configured to achieve controlled data transmission between the classified network and the public network. During integration, it is necessary to ensure that the authentication, authorization, and encryption mechanisms of the VPN gateway match the security policies of the business system. At the same time, a reasonable access control list (ACL) should be designed to strictly restrict data flow and access permissions. In addition, monitoring and log auditing functions are also essential to detect and respond to potential security incidents in a timely manner.

[0021] (2) Ordinary air gap integration:

[0022] Ordinary air gaps achieve data exchange between two networks through the "store and forward" mechanism. There is a strict security isolation unit inside to prevent direct network connections and data leakage. During integration, it is necessary to customize the data packet format, transmission rules, and filtering strategies according to the specific requirements of the business system. At the same time, considering the latency that the air gap may introduce, it is necessary to optimize the data transmission logic of the business system to ensure the real-time and integrity of data transmission. In addition, the maintenance management and fault recovery mechanisms of the air gap should also be considered in the integration.

[0023] (3) Unidirectional optical gap integration:

[0024] The one-way optical gateway utilizes the one-way transmission characteristic of optical signals to achieve the one-way flow of data from one network to another network, and is an ideal choice to ensure the one-way transmission of high-security-level data. During integration, it is necessary to ensure that the business system can adapt to the data format and transmission protocol of the one-way optical gateway. At the same time, a reasonable data transmission process should be designed to ensure the accuracy and integrity of the data. Due to the irreversibility of the one-way optical gateway, it is also necessary to consider how to effectively process and store these data in the target network, and how to implement the necessary feedback mechanism (such as status confirmation).

[0025] (4) Integration of image ferry:

[0026] The image ferry converts the image data into a digital format for cross-network transmission by scanning the content displayed on the screen. During integration, attention should be paid to the scanning accuracy, recognition accuracy of the image ferry, and the interface docking ability with the business system. At the same time, a strict data processing process should be established, including image encryption, compression, storage, and transmission, etc., to ensure the security and efficiency of the data during cross-network transmission.

[0027] (5) Integration of optical disc ferry:

[0028] The optical disc ferry uses a physical medium (optical disc) as the data carrier to achieve data exchange between two physically isolated networks. During integration, an automated optical disc reading, writing, and transmission system should be designed to reduce the security risks brought by human operations. At the same time, it is also necessary to consider how to combine with the data backup and recovery strategies of the business system to cope with possible data loss or damage situations.

[0029] In summary, the integration scheme of cross-network isolation and exchange devices needs to comprehensively consider business requirements, security requirements, and technical feasibility. All of them need to be deeply customized and transformed for the business system to achieve safe and efficient data exchange under strict physical isolation conditions. In the existing technology, devices of different brands and models need to be adapted to their respective exchange systems, resulting in a large amount of resources required by enterprises in business integration, configuration management, and later maintenance, and it is difficult to achieve unified management and efficient operation and maintenance.

[0030] Based on this, the embodiments of the present application provide a data cross-network exchange method, device, and system, which can be compatible with various cross-network exchange devices, flexibly configure transmission strategies according to requirements and hardware devices, provide a unified call method and standard externally, and achieve unified management of cross-network data exchange, which helps to improve the network operation efficiency of enterprises, reduce maintenance costs, and further enhance the security protection ability of classified networks. For the convenience of understanding this embodiment, first, a data cross-network exchange method disclosed in the embodiments of the present application will be introduced in detail.

[0031] Figure 1The flowchart of a data cross - network exchange method provided by an embodiment of this application. This method can be applied to a server in a data cross - network exchange system and is executed by a data cross - network exchange device (i.e., multiple functional modules) configured in the server. The method specifically includes the following steps:

[0032] Step S101: Receive the data file to be exchanged sent by the target application and store the data file in the first common buffer;

[0033] The data files stored in the first common buffer support streaming data, text data, binary data, structured data, and unstructured data.

[0034] Step S102: Perform a security detection operation on all data files in the first common buffer;

[0035] Perform security checks and filtering on the data files stored in the first common buffer to prevent the leakage of malicious code or sensitive information.

[0036] Step S103: Obtain the data files and routing unique identifiers that pass the security detection, retrieve the data routing configuration library according to the routing unique identifiers, obtain routing information and device information, perform device type matching according to the data confidentiality level in the routing information to obtain the device type; generate a task file corresponding to the data file based on the routing information and device information, and encrypt the data file;

[0037] The above - mentioned data routing configuration library is used to maintain cross - network exchange device information and transmission policies. The cross - network exchange device information includes: device unique number, device name, device model, device type, device protocol, affiliated manufacturer, associated relationship, device IP, device port, and single - transmission data volume limit; the transmission policies include application unique ID, application name, supported confidentiality level, transmission mode, and transmission type. The exchange routing configuration library can also maintain the IP and port information of the exchange devices within the same network segment.

[0038] The above - mentioned routing information includes: data type, data confidentiality level, priority, sender name, receiver name, data size, receive timestamp, and target format; the information in the task file includes: data file name, sender name, receiver name, receiver protocol, receiver IP, receiver port, receiver address, data confidentiality level, and target data format.

[0039] The above encryption processing of the data file can ensure the confidentiality and integrity of the data during transmission. It uses a variety of national cryptographic algorithms, such as SM1, SM2, SM3, SM4, SM7, SM9, etc., to meet different security requirements, and also includes functions such as sensitive content identification and data desensitization to protect sensitive data from being leaked.

[0040] Step S104: Store the task file and the encrypted data file into the sending cache library, and generate sending task information to be stored in the first message queue.

[0041] The above-mentioned sending task information includes: device unique identifier, device type, device protocol, device IP, device port, data file name, and task file name.

[0042] Step S105: Read the first message queue to obtain the sending task information, and determine the data file and task file to be sent.

[0043] Read the first message queue according to the first-in-first-out principle to obtain the sending task information.

[0044] Step S106: Send the data file and task file to be sent to the cross-network exchange hardware device corresponding to the device type, so that the cross-network exchange hardware device ferries the data file and task file.

[0045] Step S107: Receive the data file and task file transmitted by the cross-network exchange hardware device, and store the data file and task file into the second common buffer.

[0046] Step S108: Scan and parse the task file in the second common buffer, and perform integrity verification on the data file that has been transmitted according to the parsed file hash value; if the file is incomplete, delete the relevant data file and task file in the second common buffer; if the file is complete, verify and decrypt the data file; according to the target data format recorded in the task file, perform format conversion on the decrypted data file.

[0047] Convert and adapt data in different formats to ensure the compatibility and readability of data between different systems or networks, and support multiple data formats such as XML, JSON, CSV, database tables, etc.

[0048] Step S109: Store the data file after format conversion into the distribution cache library, and generate distribution task information to be stored in the second message queue.

[0049] Step S110: Read the second message queue to obtain the distribution task information, and obtain the corresponding data file from the distribution cache library and send it to the target application.

[0050] The data cross-network exchange method provided by the embodiments of this application can be compatible with a variety of cross-network exchange devices, flexibly configure transmission strategies according to requirements and hardware devices, provide a unified call method and standard externally, realize unified management of cross-network data exchange, help improve the network operation efficiency of enterprises, reduce maintenance costs, and further enhance the security protection ability of the confidential network.

[0051] The embodiment of the present application also provides another data cross-network exchange method, which is implemented on the basis of the previous embodiment and adds a judgment process for device transmission limitations, as follows:

[0052] Before the step of generating a task file corresponding to the data file based on the routing information and device information, it further includes: judging whether the data file exceeds the device transmission limitation; if so, numbering the slices of the data file, and for the sliced data file, executing the step of generating a task file corresponding to the data file based on the routing information and device information; if not, directly executing the step of generating a task file corresponding to the data file based on the routing information and device information.

[0053] Before the step of converting the format of the decrypted data file according to the target data format recorded in the task file, it further includes: judging whether the decrypted data file is a sharded file; if so, reorganizing the sharded data file after decryption according to the number; based on the reorganized data file, continuing to execute the step of converting the format of the decrypted data file according to the target data format recorded in the task file; if not, directly executing the step of converting the format of the decrypted data file according to the target data format recorded in the task file.

[0054] The specific device type matching process is also refined, as follows:

[0055] The step of matching the device type according to the data confidentiality level in the routing information includes: if the data confidentiality level is from a non-secret network to a non-secret network, the device type used is a VPN gateway; if the data confidentiality level is the same confidentiality level network, the device types used are a network isolation device or an optical isolation device; if the data confidentiality level is from a low confidentiality level network to a high confidentiality level network, the device types collected are a unidirectional optical isolation device, an image or an optical disc ferry; if the data confidentiality level is from a high confidentiality level network to a low confidentiality level network, the device type used is an optical disc ferry.

[0056] Before introducing the specific method of this embodiment, first elaborate on each functional module configured in the server that executes this method, such as Figure 2 As shown, each functional module includes: an application data receiving module 1, a first common buffer 2, a security detection module 3, a data routing configuration library 4, a first data exchange processing module 5, a data security encryption module 6, a sending buffer library 7, a first message queue 8, an exchange data sending module 9, a first exchange device integration module 10, a second exchange device integration module 11, an exchange data receiving module 12, a second common buffer 13, a data format conversion module 14, a second data exchange processing module 15, a data security decryption module 16, a distribution buffer library 17, a second message queue 18, and an application data distribution module 19.

[0057] The application data receiving module 1 is used to send the data to be exchanged from the source network or system to the cross-network data exchange system, that is, to receive the data file to be exchanged sent by the target application. The first common buffer 2 is used to temporarily store the data file sent from the source network or system to the cross-network data exchange system. The security detection module 3 is used to perform security checks and filtering on the data stored in the first common buffer 2 to prevent the leakage of malicious code or sensitive information.

[0058] The data routing configuration library 4 is used to maintain cross-network switching device information and transmission policies. The cross-network switching device information includes device unique number, device name, device model, device type, device protocol, affiliated manufacturer, and associated relationship; the transmission policies include application unique ID, application name, supported security level, transmission mode, and transmission type. The switching routing configuration library 4 can also maintain the IP and port information of the switching devices within the local network segment.

[0059] The first data exchange processing module 5 and the second data exchange processing module 15 are used for data reception, storage, forwarding, and processing. The data security encryption module 6 is used to encrypt the data to ensure the confidentiality and integrity of the data during transmission. It adopts a variety of national cryptographic algorithms, such as SM1, SM2, SM3, SM4, SM7, SM9, etc., to meet different security requirements, and also includes functions such as sensitive content identification and data desensitization to protect sensitive data from being leaked.

[0060] The sending cache library 7 is used to store the data files and task files processed by the data exchange processing module 5. The first message queue 8 is used to store the task information generated by the first data exchange processing module 5 according to the first-in, first-out principle.

[0061] The exchange data sending module 9 is used to read the task information stored in the first message queue 8 according to the first-in, first-out principle, obtain the data files and task files to be sent according to the task information, and hand them over to the first switching device integration module 10 to be sent to the cross-network switching hardware device. The first switching device integration module 10 and the second switching device integration module 11 are used to integrate and adapt to a variety of cross-network switching hardware devices, establish and maintain communication channels between cross-networks, and support a variety of network protocols and communication technologies, such as TCP / IP, HTTP, FTP, etc., to adapt to different network environments and hardware devices.

[0062] The second switching device integration module 11 is used to receive the data files and task files ferried by the first switching device integration module 10 through the cross-network switching hardware device. The data exchange receiving module 12 is used to receive the data files and task files sent by the second switching device integration module 11, and store the data files and task files into the second common buffer 13. The second data exchange processing module 15 is used to receive, store, forward and process the files in the second common buffer 13. The data format conversion module 14 is used to convert and adapt data in different formats to ensure the compatibility and readability of data between different systems or networks, and supports multiple data formats such as XML, JSON, CSV, database tables, etc. The data security decryption module 16 is used to decrypt encrypted data, and it supports multiple national cryptographic algorithms.

[0063] The distribution cache library 17 is used to store the exchanged data processed by the second data exchange processing module 15. The second message queue 18 is used to store the distribution task information generated by the second data exchange processing module 15 according to the first-in, first-out principle. The application data distribution module 19 is used to call the application callback address, read the distribution task information stored in the second message queue 18 according to the first-in, first-out principle, obtain the data to be sent according to the task information, and send the data to the target application.

[0064] Based on the above modules, the specific process of the data cross-network exchange method in this embodiment is as Figure 3 and Figure 4 shown:

[0065] Step 0: Any application sends any data; the data to be exchanged is sent from the source network or system to the cross-network data exchange system. That is, the application data receiving module 1 receives the data file to be exchanged sent by the target application;

[0066] Step 1: The relevant application first establishes a connection with the application data receiving module 1 and verifies the user identity to prevent unauthorized applications from making illegal connections, identify and block malicious attackers such as man-in-the-middle attacks or rollback attacks, who may try to tamper with or steal the transmitted data.

[0067] Step 2: Establish a dedicated transmission link (including streaming transmission, block transmission, interactive transmission) and obtain the unique routing identifier.

[0068] Step 3: Receive the application data and store it in the first common buffer 2 in the form of files (supporting streaming data, text data, binary data, structured data, unstructured data).

[0069] Step 4: The security detection module 3 first performs antivirus and malicious code detection operations on all files in the first common buffer 2.

[0070] Step 5: The first data exchange processing module 5 obtains the file that has passed the security check and the routing unique identifier.

[0071] Step 6: Retrieve the data routing configuration library 4 according to the routing unique identifier to obtain routing information (including data type, data classification level, priority, sender name, recipient name, data size, receive timestamp, target format) and device information (including device unique number, device type, device protocol, device IP, device port, single transmission data volume limit).

[0072] Step 7: Match the device type according to the obtained network classification level.

[0073] Step 8: Use a VPN gateway for non-classified network to non-classified network; use a network isolation device or optical isolation device for the same classification level network; use a unidirectional optical isolation device, image or optical disc ferry for low classification level network to high classification level network; use an optical disc ferry for high classification level network to low classification level network.

[0074] Step 9: The first data exchange processing module 5 obtains the routing, device information and the data file in the first common buffer 2.

[0075] Step 10: Determine whether the data file exceeds the device transmission limit; if so, execute Step 11. Otherwise, go to Step 12.

[0076] Step 11: The first data exchange processing module 5 numbers the slices of all types of data files and generates a paired task file (file information includes data file name, sender name, recipient name, recipient protocol, recipient IP, recipient port, recipient address, data classification level, target format), and then sends the sliced data file to the data security encryption module 6.

[0077] Step 12: The data security encryption module 6 encrypts the data file and returns the encrypted data file and the file hash value to the first data exchange processing module 5 together.

[0078] Step 13: The first data exchange processing module 5 stores the task file and the encrypted data file in the send cache library 7, and generates send task information (including device unique number, device type, device protocol, device IP, device port, data file name, task file name) and stores it in the first message queue 8.

[0079] Step 14: Delete the corresponding file in the first common buffer 2.

[0080] Step 15: The exchange data sending module 9 reads the first message queue 8 to obtain the send task information, and sends the corresponding data file and task file to the first exchange device integration module 10.

[0081] Step 16. The first switching device integration module 10 sends the data file and the task file to the corresponding cross-network switching hardware device, and deletes the relevant data files in the sending cache library.

[0082] Step 17. The cross-network switching hardware device ferries the data file and the task file.

[0083] Step 18. The second switching device integration module 11 receives the data file and the task file transmitted by the cross-network switching hardware device, and sends them to the switching data receiving module 12.

[0084] Step 19. The switching data receiving module 12 stores the data file and the task file in the second common buffer 13.

[0085] Step 20. The second data exchange processing module 15 scans and parses all the task files in the second common buffer 13 and obtains the information in the files, and performs integrity verification on the data files that have been transmitted according to the data file hash values recorded in the information.

[0086] Step 21. Whether the file is complete; if so, execute Step 22. Otherwise, go to Step 28.

[0087] Step 22. The data security decryption module 16 verifies and decrypts the data file, and sends it to the second data exchange processing module 15.

[0088] Step 23. The second data exchange processing module 15 determines whether the data file is a fragmented file; if so, execute Step 24. Otherwise, go to Step 25.

[0089] Step 24. The second data exchange processing module 15 reorganizes the decrypted fragmented data files according to the numbers.

[0090] Step 25. The second data exchange processing module 15 sends the data file to the data format conversion module 14.

[0091] Step 26. The data format conversion module 14 converts the data file according to the target data format recorded in the task file, and returns it to the second data exchange processing module 15.

[0092] Step 27. The second data exchange processing module 15 stores the data in the distribution cache library 17, and generates distribution task information (including the sender name, the receiver name, the receiver protocol, the receiver IP, the receiver port, the receiver address, the data classification level, the target format, the data cache information) and stores it in the second message queue 18.

[0093] Step 28. Delete the relevant data files and task files in the second common buffer 13.

[0094] Step 29: The application data distribution module 19 reads the second message queue 18 according to the first-in, first-out principle to obtain distribution task information, and obtains the corresponding data from the distribution cache library 17 and sends it to the target application.

[0095] Step 30: Determine whether the data distribution is successful; if so, execute Step 31. Otherwise, execute Step 27.

[0096] Step 31: After successful distribution, delete the relevant data in the distribution cache library 17.

[0097] Step 32: End.

[0098] In this embodiment, the routing unique identifier can adopt a hierarchical structure, and the format is as follows:

[0099] [Network domain code]-[Subnet code]-[Device code]-[Random suffix]

[0100] Network domain code: Used to identify the network domain to which it belongs, usually 2 fixed bytes, composed of letters and numbers.

[0101] Subnet code: Used to identify the subnet within the network domain, usually 2 fixed bytes, composed of letters and numbers.

[0102] Device code: Used to identify the specific device within the subnet, usually 3 fixed bytes, composed of letters and numbers.

[0103] Random suffix: Used to ensure uniqueness, usually 4 fixed bytes, hexadecimal numbers.

[0104] The following lists a specific routing embodiment: For example, in actual applications, a unique routing identifier is: "OPA-DC1-RTR1-A1B2". Under the established routing hierarchical structure, the benefits it brings to the overall solution in the process of identifier generation, parsing, and information transmission are as follows:

[0105] (1) Identifier generation process:

[0106] Clear planning: "OPA" as the network domain code clearly identifies the specific network domain to which this route belongs, which may represent a specific operator or a large enterprise network organization, etc. "DC1" as the subnet code clearly indicates that this is a specific subnet within the network domain "OPA", most likely a subnet in a specific area such as a data center. "RTR1" as the device code clearly identifies which transmission device within this subnet it is. This hierarchical structure enables the orderly division of routing identifiers according to the actual architecture and functional areas of the network when planning and allocating routing identifiers, facilitating unified management and planning by network administrators and reducing confusion and errors in identifier allocation.

[0107] Ensure uniqueness: The final "A1B2" serves as a random suffix, further ensuring the uniqueness of this routing identifier across the entire network. Even if there are multiple similarly named subnets or devices in the network, this random suffix can ensure that each routing identifier is unique, avoiding network communication problems caused by duplicate identifiers.

[0108] (2) Identification resolution process:

[0109] Quick positioning: When a cross-network service receives a data packet containing this routing identifier, it can quickly resolve it according to the hierarchical structure. First, determine the large network domain to which the data is to be sent through "OPA", then locate the specific subnet within this network domain based on "DC1", and finally find the target device within the subnet through "RTR1". This quick positioning ability greatly improves the efficiency of data forwarding and reduces the transmission delay of data in the network.

[0110] Optimize the path: During the information transmission process, cross-network devices in the network can calculate the best transmission path based on the hierarchical information in this routing identifier, combined with the network topology and the current network status. For example, knowing that the target is the "RTR1" device in the "DC1" subnet of the "OPA" network domain, the cross-network service can select the optimal link for data forwarding, avoiding unnecessary detours and transmissions, and improving the efficiency and reliability of information transmission.

[0111] Support for expansion: If the network needs to be expanded, such as adding new subnets in the "OPA" network domain or adding new devices in the "DC1" subnet, it can still be allocated according to the existing routing identifier structure. New subnets can be allocated codes similar to "DC2", etc., and new devices can be allocated codes such as "RTR2", etc., and a unique random suffix is generated for them, which not only maintains the consistency of the routing identifier system but also supports the expansion and upgrade of the network well.

[0112] Security control: Based on this unique routing identifier, refined security policies can be implemented. For example, an access control list (ACL) can be set to only allow data packets from specific sources to access the device identified by "OPA-DC1-RTR1-A1B2", or restrict this device to communicate only with specific network domains and subnets, thereby enhancing the security of the network and preventing security problems such as illegal access and data leakage.

[0113] In another preferred embodiment, the following several optimizations are also carried out:

[0114] 1. Example of security level definition:

[0115] - Low security level: LL (Low-Level), identified by a green link, e.g., OPA-DC1-LL-RTR1-****;

[0116] - High security level: HS (High-Security), identified by a red link, e.g., OPA-DC1-HS-RTR5-****;

[0117] - Reserved bandwidth link: HS-R (Reserved), identified by a purple link, e.g., OPA-DC1-HS-R-RTR9-****.

[0118] 2. Process of dynamic path selection implementation:

[0119] (1) Path identification generation stage

[0120] When a new transmission request is created, the system automatically generates a path identification containing security attributes:

[0121] Example: OPA-DC1-LL-RTR1-A1B2 (low security link);

[0122] The generation rules are as follows:

[0123] - Network domain (OPA) → subnet (DC1) → security level (LL) → device type (RTR) → random suffix (A1B2);

[0124] - The security level field is extended to three levels: LL / HS / HS-R.

[0125] (2) Path detection stage

[0126] The system automatically detects available paths according to the security level identification in the packet header.

[0127] 3. Example of transmission scenarios:

[0128] Scenario 1: Low security level transmission (file transfer)

[0129] Initial selected link: OPA-DC1-LL-RTR1-A1B2 (bandwidth 1Gbps); When there is a sudden high security transmission, the system automatically interrupts the LL link and switches the original transmission link to: OPA-DC1-HS-RTR5-C3D4 (bandwidth 500Mbps); At the same time, 30% of the bandwidth of the HS-R link OPA-DC1-HS-R-RTR9-E5F6 is reserved.

[0130] Scenario 2: High security level transmission (encrypted video conference)

[0131] Forced selected link: OPA-DC2-HS-RTR3-G7H8 (bandwidth 800Mbps);

[0132] Standby path: OPA-DC2-HS-R-RTR6-K9L0 (reserved bandwidth link).

[0133] 4. Interruption recovery mechanism:

[0134] When high-priority transmission preempts the link, the system will perform the following two steps:

[0135] (1) Record the state of the interrupted transmission: OPA-DC1-LL-RTR1-A1B2 → Save the transmission offset;

[0136] (2) Recovery is triggered under the following three conditions: high-priority transmission is completed, a new available LL link is detected, and the preset retry time threshold is reached.

[0137] 5. Example of security policy implementation:

[0138] The ACL rules based on path identification are as follows:

[0139]

[0140] 6. Bandwidth guarantee mechanism:

[0141] Adopt a three-level bandwidth pool design:

[0142] - HS-R link: 30% fixed reserved bandwidth (purple link);

[0143] - HS link: Dynamically allocate 50% bandwidth;

[0144] - LL link: Maximum occupancy of 20% bandwidth.

[0145] The above design achieves the following advantages:

[0146] 1. Path traceability: Quickly locate the fault point through structured identification;

[0147] 2. Security isolation: Physical / logical separation of different-level links;

[0148] 3. Resource optimization: Dynamic bandwidth allocation + priority preemption mechanism;

[0149] 4. Expansion ability: New devices only need to expand the identification suffix according to the specification.

[0150] In view of the diversity and complexity of cross-network switching devices in the prior art, the embodiments of the present application propose a data cross-network switching method, aiming to achieve unified management, efficient operation and maintenance, and flexible expansion of cross-network data exchange by integrating common cross-network isolation switching hardware devices. Among the functional modules required to implement this method, a unified switching device integration module is designed, which is mainly responsible for hardware interface and protocol adaptation. As the bridge between the system and cross-network isolation switching hardware devices, this module selects corresponding hardware devices for data transmission according to task configuration information. Through this module, hardware devices of different brands and models can work under a unified framework, greatly simplifying the complexity of business system transformation and hardware device integration.

[0151] Meanwhile, in view of the problem of complex configuration of cross-network isolation switching devices, a data exchange processing module is designed in the embodiments of the present application. This module can receive, store, forward, and process data according to preset security policies and routing configuration information, and automatically generate switching tasks, thus greatly simplifying the configuration process and improving operation efficiency.

[0152] Secondly, considering that new cross-network isolation switching hardware devices may be introduced in the future, the embodiments of the present application fully consider flexibility and compatibility in design. Through modular design, by separately updating the switching device integration module, new hardware devices can be easily connected to the system without large-scale transformation of the existing system. At the same time, the application data receiving module and application data distribution module of the system also provide rich interface forms, facilitating users to carry out customized development according to actual needs.

[0153] To sum up, the embodiments of the present application achieve unified management, efficient operation and maintenance, and flexible expansion of cross-network data exchange by integrating common cross-network isolation switching hardware devices in the market. Ensure the safe, efficient, and reliable transmission of data between different networks. Help reduce the maintenance cost of different classified networks in the case of physical isolation, and further enhance the security protection ability of classified networks. Users will be able to significantly reduce the integration complexity and management cost of cross-network data exchange, improve the security and efficiency of data exchange, and have significant economic benefits and security guarantees.

[0154] The specific analysis is as follows:

[0155] (1) Advantage analysis

[0156] ① Highly integrated, unified service:

[0157] Technical background: Traditional cross-network data exchange often relies on a variety of independent hardware devices, and each device may only support specific types of data exchange or specific network protocols, resulting in complex and difficult-to-manage business systems.

[0158] Advantages of the embodiments of the present application: By integrating cross-network exchange hardware devices, the embodiments of the present application provide a centralized data exchange platform that is compatible with a variety of hardware devices and implements unified cross-network data exchange services. This integrated design simplifies the business system architecture, reduces management complexity, and improves the flexibility and scalability of the overall system.

[0159] ②Strong flexibility and scalability:

[0160] Technical background: Existing cross-network data exchange solutions are often limited by specific hardware or software architectures and are difficult to adapt to rapidly changing data exchange requirements or new network environments.

[0161] Advantages of the embodiments of the present application: The unified integrated platform of the embodiments of the present application adopts a modular design, which can easily add or replace hardware devices and support new data exchange protocols or functions. This design enables the system to flexibly respond to new demands and technological changes that may arise in the future, ensuring the long-term availability and advancement of the system.

[0162] ③Data security, efficiency and reliability:

[0163] Technical background: In cross-network data exchange, data security and transmission efficiency are two key challenges. Traditional solutions may compromise on security or efficiency and are difficult to meet the security protection needs of high-density networks.

[0164] Advantages of the embodiments of this application: The embodiments of this application ensure the security of data when it is transmitted between different networks through built-in security policies and routing configuration information. At the same time, the intelligent task generation and dynamic configuration adjustment functions make the data exchange process both efficient and reliable. This dual guarantee improves the overall quality and security of cross-network data exchange.

[0165] ④Reduce maintenance costs and enhance safety protection

[0166] Technical background: Physically isolated network environments often require a large amount of hardware equipment and human resources to maintain, which is costly and inefficient.

[0167] Advantages of the embodiments of this application: Through a unified and integrated cross-network exchange platform, the embodiments of this application reduce the number of hardware devices and the complexity of maintenance, thereby significantly reducing maintenance costs. At the same time, the built-in security protection mechanism and intelligent monitoring function further enhance the security protection capabilities of confidential networks and reduce security risks.

[0168] (2) The effects produced:

[0169] ① Improve business efficiency:

[0170] The unified integrated cross-network exchange platform simplifies the data exchange process, shortens the data exchange time, and improves the business processing efficiency.

[0171] ② Optimize resource utilization:

[0172] Through intelligent task generation and dynamic configuration adjustment, the embodiments of this application achieve the optimal utilization of resources, avoiding resource waste and performance bottlenecks.

[0173] ③ Enhance user experience:

[0174] The simplified system architecture and unified service interface enable users to perform data exchange operations more conveniently, enhancing the user experience.

[0175] ④ Promote technological innovation:

[0176] The modular design and scalability of the embodiments of this application provide a solid foundation for future technological innovation and upgrading, promoting the continuous development of cross-network data exchange technology.

[0177] In summary, the embodiments of this application achieve the simplification, efficiency, security, and scalability of cross-network data exchange by uniformly integrating cross-network exchange hardware devices, significantly reducing the maintenance cost, enhancing the security protection ability, and bringing a revolutionary change to the field of cross-network data exchange.

[0178] Based on the above method embodiments, the embodiments of this application also provide a data cross-network exchange device. See Figure 2As shown in the figure, the device includes: an application data receiving module 1, which is used to receive the data file to be exchanged sent by the target application and store the data file in the first common buffer 2; a security detection module 3, which is used to perform security detection operations on all data files in the first common buffer 2; a first data exchange processing module 5, which is used to obtain the data file and the routing unique identifier after passing the security detection, retrieve the data routing configuration library 4 according to the routing unique identifier, obtain the routing information and device information, and perform device type matching according to the data confidentiality level in the routing information to obtain the device type; generate a paired task file based on the routing information and device information, and encrypt the data file through the data security encryption module 6; the first data exchange processing module 5 is also used to store the task file and the encrypted data file in the sending cache library 7 and generate sending task information and store it in the first message queue 8; an exchange data sending module 9, which is used to read the first message queue 8 to obtain the sending task information and determine the data file and task file to be sent; a first exchange device integration module 10, which sends the data file and task file to be sent to the cross-network exchange hardware device corresponding to the device type, so that the cross-network exchange hardware device ferries the data file and task file; a second exchange device integration module 11, which is used to receive the data file and task file transmitted by the cross-network exchange hardware device; an exchange data receiving module 12, which is used to store the data file and task file in the second common buffer 13; a second data exchange processing module 15, which is used to scan and parse the task file in the second common buffer 13, and perform integrity verification on the data file that has been transmitted according to the parsed file hash value; if the file is incomplete, delete the relevant data file and task file in the second common buffer 13; if the file is complete, verify and decrypt the data file through the data security decryption module 16; through the data format conversion module 14, convert the format of the decrypted data file according to the target data format recorded in the task file; the second data exchange processing module 15 is also used to store the data file after format conversion in the distribution cache library 17 and generate distribution task information and store it in the second message queue 18; an application data distribution module 19, which is used to read the second message queue 18 to obtain the distribution task information and obtain the corresponding data file from the distribution cache library 17 and send it to the target application.

[0179] Further, the above-mentioned first data exchange processing module 5 is also used to judge whether the data file exceeds the device transmission limit before the step of generating a task file corresponding to the data file based on the routing information and device information; if so, number the slices of the data file, and for the sliced data file, execute the step of generating a task file corresponding to the data file based on the routing information and device information; if not, directly execute the step of generating a task file corresponding to the data file based on the routing information and device information.

[0180] Further, the above-mentioned second data exchange processing module 15 is further configured to, before the step of performing format conversion on the decrypted data file according to the target data format recorded in the task file, determine whether the decrypted data file is a sharded file; if so, reorganize the decrypted sharded data file according to the numbers; continue to execute the step of performing format conversion on the decrypted data file according to the target data format recorded in the task file based on the reorganized data file; if not, directly execute the step of performing format conversion on the decrypted data file according to the target data format recorded in the task file.

[0181] Further, the above-mentioned routing information includes: data type, data classification level, priority, sender name, recipient name, data size, reception timestamp, and target format; the device information includes: device unique number, device name, device model, device type, device protocol, affiliated manufacturer, associated relationship, device IP, device port, and single-transmission data volume limit; the information in the task file includes: data file name, sender name, recipient name, recipient protocol, recipient IP, recipient port, recipient address, data classification level, and target data format; the sending task information includes: device unique number, device type, device protocol, device IP, device port, data file name, and task file name.

[0182] Further, the above-mentioned first data exchange processing module 5 is further configured to: if the data classification level is from non-classified network to non-classified network, the device type adopted is a VPN gateway; if the data classification level is the same classified network, the device type adopted is a network isolation device or an optical isolation device; if the data classification level is from low-classified network to high-classified network, the device type collected is a unidirectional optical isolation device, an image, or an optical disc ferry; if the data classification level is from high-classified network to low-classified network, the device type adopted is an optical disc ferry.

[0183] Further, the data files stored in the first common buffer support streaming data, text data, binary data, structured data, and unstructured data.

[0184] Further, the above-mentioned device further includes: a deletion module, configured to, after the step of storing the task file and the encrypted data file in the sending cache library and generating the sending task information and storing it in the first message queue, delete the data files in the first common buffer; after the step of storing the format-converted data file in the distribution cache library and generating the distribution task information and storing it in the second message queue, continue to execute the step of deleting the relevant data files and task files in the second common buffer; after the step of obtaining the corresponding data file from the distribution cache library and sending it to the target application, determine whether the data distribution is successful; if so, delete the relevant data in the distribution cache library.

[0185] The device provided in the embodiments of the present application has the same implementation principle and technical effects as those in the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the embodiments of the device, reference may be made to the corresponding content in the foregoing method embodiments.

[0186] Based on the foregoing method embodiments and device embodiments, the embodiments of the present application further provide a data cross-network exchange system. As shown in Figure 5 the figure, the system includes: a server 52 and a plurality of cross-network exchange hardware devices 54 that are communicatively connected; a data cross-network exchange device 522 as described in the device embodiments is configured in the server 52 and is used to execute the data cross-network exchange method as described in the method embodiments.

[0187] The system provided in the embodiments of the present application has the same implementation principle and technical effects as those in the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the embodiments of the system, reference may be made to the corresponding content in the foregoing method embodiments.

[0188] The embodiments of the present application further provide a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions cause the processor to implement the foregoing method. For specific implementation, reference may be made to the foregoing method embodiments and will not be elaborated herein.

[0189] The computer program product of the method, device, and electronic device provided in the embodiments of the present application includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the method described in the foregoing method embodiments. For specific implementation, reference may be made to the method embodiments and will not be elaborated herein.

[0190] Unless otherwise specifically stated, the relative steps, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of the present application.

[0191] If the said function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program code.

[0192] In the description of the present application, it should be noted that the orientation or positional relationship indicated by terms such as "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present application. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.

[0193] Finally, it should be noted that the above-described embodiments are only specific embodiments of the present application, used to illustrate the technical solutions of the present application, rather than limiting it. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that any person skilled in the art within the technical scope disclosed in the present application can still modify the technical solutions described in the foregoing embodiments or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for exchanging data across networks, characterized in that: The method comprises: Receiving a data file to be exchanged sent by a target application, and storing the data file in a first public buffer; Performing a security check operation on all data files in the first public buffer; Acquire a data file that has passed the security check and a unique routing identifier, retrieve a data routing configuration library according to the unique routing identifier, obtain routing information and device information, and match the device type according to the data confidentiality level in the routing information to obtain the device type; generate a task file corresponding to the data file based on the routing information and device information, and encrypt the data file; store the task file and the encrypted data file in a sending cache library, and generate sending task information and store it in a first message queue; Reading the first message queue to obtain sending task information, determining the data file and task file to be sent; sending the data file and task file to be sent to the cross-network switching hardware device corresponding to the device type, so that the cross-network switching hardware device can ferry the data file and the task file; Receiving data files and task files transmitted by the cross-network exchange hardware device, and storing the data files and task files in a second public buffer; Scan and parse the task file in the second public buffer, and perform integrity check on the data file that has been transferred according to the parsed file hash value; if the file is incomplete, delete the relevant data file and task file in the second public buffer; if the file is complete, verify and decrypt the data file; According to the target data format recorded in the task file, the decrypted data file is format converted; the format-converted data file is stored in the distribution cache library, and the distribution task information is generated and stored in the second message queue; The second message queue is read to obtain the distribution task information, and the corresponding data file is obtained from the distribution cache library and sent to the target application.

2. The method according to claim 1, characterized in that Before the step of generating a task file corresponding to the data file based on the routing information and the device information, the method further includes: Determining whether the data file exceeds the device transmission limit; If yes, the data file is sliced ​​and numbered, and for the sliced ​​data file, the step of generating a task file corresponding to the data file based on the routing information and the device information is performed; If not, directly execute the step of generating the task file corresponding to the data file based on the routing information and the device information.

3. The method according to claim 1, characterized in that: Before the step of converting the format of the decrypted data file according to the target data format recorded in the task file, the step also includes: Determine whether the decrypted data file is a fragmented file; If yes, reorganize the decrypted segmented data files according to the numbers; continue to perform the step of converting the format of the decrypted data files according to the target data format recorded in the task file based on the reorganized data files; If not, directly execute the step of converting the format of the decrypted data file according to the target data format recorded in the task file.

4. The method according to claim 1, characterized in that: The routing information includes: data type, data confidentiality level, priority, sender name, receiver name, data size, receiving timestamp and target format; the device information includes: device unique number, device name, device model, device type, device protocol, manufacturer, associated network, device IP, device port and single transmission data volume limit; the information in the task file includes: data file name, sender name, receiver name, receiver protocol, receiver IP, receiver port, receiver address, data confidentiality level and target data format; the sending task information includes: device unique number, device type, device protocol, device IP, device port, data file name and task file name.

5. The method according to claim 1, characterized in that The step of matching the device type according to the data confidentiality level in the routing information includes: If the data confidentiality level is from non-confidential network to non-confidential network, the device type used is VPN gateway; If the data security level is the same as the security level network, the device type used is a network gate or an optical gate; If the data security level is from a low-security network to a high-security network, the type of data acquisition equipment is a one-way optical gate, an image or optical disk shuttle; If the data security level is from a high-security network to a low-security network, the device type used is a CD shuttle.

6. The method according to claim 1, characterized in that The data files stored in the first public buffer support streaming data, text data, binary data, structured data and unstructured data.

7. The method according to claim 1, characterized in that After the steps of storing the task file and the encrypted data file in the sending cache and generating sending task information and storing it in the first message queue, the method further includes: Deleting the data files in the first public cache area; After the steps of storing the format-converted data file into the distribution cache library, generating distribution task information and storing it into the second message queue, continuing to execute the step of deleting the relevant data file and task file in the second public buffer; After the step of acquiring the corresponding data file from the distribution cache library and sending it to the target application, the method further includes: Determine whether the data distribution is successful; if so, delete the relevant data in the distribution cache.

8. A data cross-network exchange device, characterized in that: The device comprises: An application data receiving module, used for receiving a data file to be exchanged sent by a target application, and storing the data file in a first public buffer; A security detection module, used for performing a security detection operation on all data files in the first public buffer; The first data exchange processing module is used to obtain the data file and the unique routing identifier after passing the security detection, retrieve the data routing configuration library according to the unique routing identifier, obtain the routing information and the device information, and match the device type according to the data confidentiality level in the routing information to obtain the device type; generate a paired task file based on the routing information and the device information, and encrypt the data file through the data security encryption module; the first data exchange processing module is also used to store the task file and the encrypted data file into the sending cache library, and generate sending task information and store it into the first message queue; The exchange data sending module is used to read the first message queue to obtain the sending task information and determine the data file and task file to be sent; A first switching device integration module sends the data file and task file to be sent to the cross-network switching hardware device corresponding to the device type, so that the cross-network switching hardware device can ferry the data file and the task file; A second switching device integration module, used for receiving data files and task files transmitted by the cross-network switching hardware device; The exchange data receiving module is used to store the data file and the task file into the second public buffer; The second data exchange processing module is used to scan and parse the task file in the second public buffer, and perform integrity check on the data file that has been transferred according to the parsed file hash value; if the file is incomplete, delete the relevant data file and task file in the second public buffer; if the file is complete, verify and decrypt the data file through the data security decryption module; perform format conversion on the decrypted data file according to the target data format recorded in the task file through the data format conversion module; the second data exchange processing module is also used to store the format-converted data file into the distribution cache library, and generate distribution task information and store it in the second message queue; The application data distribution module is used to read the second message queue to obtain distribution task information, and obtain the corresponding data file from the distribution cache library and send it to the target application.

9. A data cross-network exchange system, characterized in that: The system comprises: a communicatively connected server and a plurality of cross-network exchange hardware devices; the server is provided with the cross-network data exchange apparatus as claimed in claim 8, for executing the cross-network data exchange method as claimed in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to implement the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • A data security exchange method under a cross-network environment

    CN120614207B

  • A data transmission method, system, device and storage medium for a unidirectional optical shutter

    CN122513198A