A Security Sharing and Exchange Method and System Based on Dual One-Way Optical Gates

By deploying shared switching services in the optical gate isolation network, using the universal unique interface name and TCP/IP protocol, the problems of high code invasiveness and information leakage in cross-optical gate data transmission are solved, and a secure and monitoring transmission closed loop is achieved.

CN120091014BActive Publication Date: 2025-07-18中国司法大数据研究院有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510226673.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-07-18
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

The existing cross-optical gate data transmission methods have problems with high code intrusion and high security domain IP and port information leakage, and it is impossible to achieve secure exchange without exposing IP and ports.

Method used

By deploying shared switching services in two networks isolated by the optical gate, using the entire domain unique interface name and TCP/IP protocol, file transmission and HTTP parameter requests are realized, and a monitoring module and push module are combined to form a transmission closed loop.

Benefits of technology

It realizes that without leaking IP and port information, reduces the intrusion of service application code, ensures the security and monitoring capabilities of data transmission, and forms a transmission closed loop.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120091014B_ABST
    Figure CN120091014B_ABST
Patent Text Reader

Abstract

The present invention discloses a secure sharing and exchange method and system based on a double one-way optical gateway. In the present invention, a sharing and exchange service is respectively deployed in two networks isolated by the optical gateway, and the interface information of the service applications that need to interact across the optical gateway is registered on the sharing and exchange service; each of the networks includes a database for storing registration information, transmission records, transmitted application names, transmission status, transmission time, transmission content, and return results; through the application registration step and the globally unique interface name, on the basis of not leaking IPs and ports to different secure network domains, business application cross-optical gateway file transfer and HTTP parameter requests are realized based on the TCP / IP protocol, reducing the intrusion into the business application code; the present invention realizes the monitoring of data transmission during the transmission process; after the transmission is completed, the receiving side transmits the transmitted application name, transmission parameters or file name, and sending time back to the transmission initiating side to form a transmission closed loop.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and relates to a secure sharing and exchange method and system based on a double unidirectional optical gateway. Background Art

[0002] With the development of information technology, network security has become increasingly important in production. In addition to the common security reinforcement against SQL injection, XSS attacks, CSRF attacks, etc., isolating important classified data environments and ordinary data environments through network security isolation optical gateways has gradually become a common technical means to protect important data. The optical gateway realizes the one-way transmission of data between different networks (two completely isolated networks or internal and external networks) through fiber optic channels, and is physically disconnected in the reverse direction to ensure the security of the isolated network and the confidentiality of information. The optical gateway uses high-performance chips to enhance the data ferry ability and conducts data exchange through proprietary component devices, security protocols, and encryption verification mechanisms, completely blocking the direct TCP / IP connection between networks.

[0003] On the other hand, in the process of transmitting confidential information in some state organs, it is impossible to use the IP mapping method to transmit data unidirectionally from a low-security domain to a high-security domain, that is, the application in the low-security domain cannot directly call the IP port of the application in the high-security domain for data interaction. Therefore, a data exchange intermediate platform is required to achieve secure data exchange without leaking the IP port to the business application in the low-security domain.

[0004] Currently, the existing cross-optical gateway data transmission methods have the following disadvantages:

[0005] 1. Most of the existing solutions use the file ferry method for cross-optical gateway data transfer, which requires implementing a call method in the business application code and has a high invasiveness to the application code.

[0006] 2. The existing cross-optical gateway web request proxy method cannot protect the IP and port information of different, especially high-security domains, from being leaked during the communication process. Summary of the Invention

[0007] Aiming at the problems existing in the prior art, the purpose of the present invention is to provide a secure sharing and exchange method and system based on a double unidirectional optical gateway.

[0008] The present invention realizes file transfer and HTTP parameter requests across the optical gateway based on the TCP / IP protocol for business applications without leaking the IP and port to different security network domains through the application registration step and a globally unique interface name, reducing the invasiveness to the business application code.

[0009] During the transmission process, the present invention records the application name, the content transmitted, the transmission time, and the reception time to monitor the data transmission.

[0010] After the transmission is completed, on the receiving side, after receiving and sending to Service Application B, the application name, transmission parameters, or file name, and sending time of the transmission are used to generate a JSON file and send it back to the transmission initiating side, so as to perceive the data transmission efficiency and form a transmission closed loop.

[0011] The technical solution of the present invention is as follows:

[0012] A secure sharing and exchange method based on a dual unidirectional optical switch, the steps of which include:

[0013] 1) A sharing and exchange service is respectively deployed in two networks isolated by the optical switch, and the interface information of service applications that need to interact across the optical switch is registered on the sharing and exchange service; each of the networks includes a database for storing registration information, transmission records, transmitted application names, transmission status, transmission time, transmission content, and return results; the two networks are respectively denoted as Network A and Network B, the sharing and exchange service deployed in Network A domain is denoted as Secure Sharing and Exchange Service A, and the sharing and exchange service deployed in Network B domain is denoted as Secure Sharing and Exchange Service B; Network A sends data to Network B through the first optical switch, and Network B sends data to Network A through the second optical switch. The front-end machine and back-end machine of the first optical switch are configured with a storage path named after the interface name of Application B in Network B, and the front-end machine and back-end machine of the second optical switch are configured with a storage path named after the interface name of Application A in Network A;

[0014] 2) Application A encapsulates business files or business interface data, the interface name of Application B, and the authentication parameters of Secure Sharing and Exchange Service A, and sends a file transmission request to Push Module A of Secure Sharing and Exchange Service A through the HTTP / HTTPS protocol;

[0015] 3) Push Module A of Secure Sharing and Exchange Service A parses the received file transmission request to obtain the authentication parameters, verifies the legitimacy of the request according to the authentication parameters, and returns authentication failure if the verification fails; if the authentication passes, go to step 4);

[0016] 4) Push Module A retrieves according to the interface name parsed from the request in the registration information on Secure Sharing and Exchange Service A. If the interface name exists in the registration information on Secure Sharing and Exchange Service A, go to step 5);

[0017] 5) Push Module A reads the transmitted business file or encapsulates the business interface data into a JSON file and pushes it to the storage path named after the business interface of the front-end machine of the first optical switch, and records the business interface name, transmission file name, and time of transmission;

[0018] 6) The monitoring module B of the secure sharing and exchange service B monitors the post-machine of the optical switch on the network B side. When a new file is detected, it obtains the interface name corresponding to the new file, and then encapsulates the new file and its corresponding interface name and sends a file push request to the push module B of the secure sharing and exchange service B through the HTTP / HTTPS protocol.

[0019] 7) The push module B of the secure sharing and exchange service B parses the interface name obtained from the received file push request and the service file or service interface data in the new file, obtains the URL corresponding to the interface name from the database of network B, and sends a file processing request to application B through the HTTP / HTTPS protocol for the transfer object; the transfer object is the service file or service interface data.

[0020] 8) After receiving the file processing request, application B encapsulates the processing result, the interface name of application A, and the authentication parameters of the sharing and exchange service B, and sends a processing result transmission request to the push module B of the secure sharing and exchange service B through the HTTP / HTTPS protocol.

[0021] 9) The push module B receives and parses the processing result transmission request, encapsulates the processing result data and the interface name into a JSON file according to the sending time, and pushes it to the storage path named by the interface on the second optical switch front-end machine.

[0022] 10) The monitoring module A of the secure sharing and exchange service A monitors the post-machine of the second optical switch. When a new file is detected, it parses the content of the new file to obtain the interface name, and encapsulates the new file and the interface name and sends a data push request to the push module A of the secure sharing and exchange service A through the HTTP / HTTPS protocol.

[0023] 11) The push module A parses the data push request sent by the monitoring module A to obtain the interface name and the processing result; then it obtains the corresponding interface URL from the database of network A according to the interface name, and sends the processing result to application A through the HTTP / HTTPS protocol.

[0024] Further, the registered interface information includes the sending-end interface name, the sending-end interface URL, the receiving-end interface name, and the receiving-end interface URL.

[0025] Further, the front-end machine and the post-machine of the network are configured with a storage path named by the receiving-end interface name.

[0026] Further, the monitoring module B obtains the interface name according to the storage path of the new file.

[0027] Further, in step 2), when a service file needs to be transmitted, Application A encapsulates the service file, interface name, and authentication parameters in the form of form-data; when service interface data needs to be transmitted, Application A encapsulates the interface name, authentication parameters, and service interface data in the form of JSON.

[0028] Further, in step 6), when it is detected that a new file is a non-JSON file, Monitoring Module B reads the content of the new file as a parameter, and encapsulates and sends the parameter and the interface name to the processing file interface of Push Module B using HTTP / HTTPS; when it is detected that a new file is a JSON file, Monitoring Module B parses the JSON file, and uses the parsed result and the interface name as request parameters to call the processing request interface of Push Module B in the form of HTTP / HTTPS.

[0029] A secure sharing and exchange system based on a double one-way optical switch, characterized by comprising an optical switch and a sharing and exchange service unit, wherein the sharing and exchange service unit includes a push module and a monitoring module;

[0030] The optical switch is used to isolate two networks; in each of the two networks, a sharing and exchange service unit is deployed, and the interface information of service applications that need to interact across the optical switch is registered on the sharing and exchange service; in each of the two networks, there is a database for storing registration information, transmission records, transmitted application names, transmission status, transmission time, transmission content, and return results; the two networks are respectively denoted as Network A and Network B, the sharing and exchange service deployed in Network A is denoted as Secure Sharing and Exchange Service A, and the sharing and exchange service deployed in Network B is denoted as Secure Sharing and Exchange Service B; Network A sends data to Network B through the first optical switch, and Network B sends data to Network A through the second optical switch. The front-end and back-end machines of the first optical switch are configured with a storage path named after the interface name of Application B in Network B, and the front-end and back-end machines of the second optical switch are configured with a storage path named after the interface name of Application A in Network A;

[0031] The push module A of the secure sharing and exchange service A is used to receive the file transfer request sent by Application A in Network A domain after encapsulating the service file or service interface data, the receiving end interface name, and the authentication parameters of the secure sharing and exchange service A through the HTTP / HTTPS protocol; and to parse the received file transfer request to obtain the authentication parameters, verify the legitimacy of the request according to the authentication parameters, return authentication failure if the verification fails, and if the authentication passes, retrieve according to the interface name parsed from the request in the registration information on the secure sharing and exchange service A. If the interface name exists in the registration information on the secure sharing and exchange service A; then read the transmitted service file or encapsulate the service interface data into a JSON file and push it to the storage path named after the service interface on the front-end machine of the first optical isolation device, and record the service interface name, the transmitted file name, and the time of transmission; and to parse the data push request sent by the monitoring module A, obtain the interface name and the processing result; then obtain the corresponding interface URL from the database of Network A according to the interface name, and send the processing result to Application A through the HTTP / HTTPS protocol;

[0032] The monitoring module A is used to monitor the back-end machine of the second optical isolation device. When a new file is detected, it parses the content of the new file to obtain the interface name, and encapsulates the new file and the interface name and sends a data push request to the push module A of the secure sharing and exchange service A through the HTTP / HTTPS protocol;

[0033] The monitoring module B of the secure sharing and exchange service B is used to monitor the back-end machine of the optical isolation device on the Network B side. When a new file is detected, it obtains the interface name corresponding to the new file, and then encapsulates the new file and its corresponding interface name and sends a file push request to the push module B of the secure sharing and exchange service B through the HTTP / HTTPS protocol;

[0034] The push module B is used to obtain the interface name parsed from the received file push request and the service file or service interface data in the new file, obtain the URL corresponding to the interface name from the database of Network B, and send a file processing request to Application B through the HTTP / HTTPS protocol for the transmission object; the transmission object is the service file or service interface data; and to receive and parse the processing result transmission request, encapsulate the processing result data and the interface name into a JSON file according to the sending time and push it to the storage path named after the interface on the front-end machine of the second optical isolation device.

[0035] The advantages of the present invention are as follows:

[0036] This solution takes into account the security of data transmission. On the basis of fully protecting the data in the high-security domain, it realizes transmission based on the TCP / IP protocol, reduces the intrusion into the application code, and can monitor the transmission status at the same time. After the receiving side receives and processes the file, it makes a callback and transmits the relevant content to form a transmission closed-loop. Description of the Drawings

[0037] Figure 1 It is the working flowchart of the security exchange service. Detailed Implementation Modes

[0038] The present invention will be further described in detail below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0039] The core of the present invention is to realize the secure interaction of the service applications on both sides of the optical isolation gateway based on the TCP / IP protocol without exposing the service application IP and ports in the network domains on both sides of the optical isolation gateway to each other. The present invention supports processing file transfer and API interface data interaction, has the characteristics of low code intrusion, and at the same time provides a data transmission monitoring function to monitor the transmission status, transmission time, etc. of the data to ensure the integrity of data transmission and closed-loop management of transmission.

[0040] One set of the secure sharing and exchange service based on the dual unidirectional isolation optical isolation gateway is deployed in each of the different security domains on both sides of the optical isolation gateway. Figure 1 As shown in the working flowchart of the security exchange service, service application A (referred to as application A for short) and the secure sharing and exchange service A are deployed in the network A domain of the sending end, and service application B (referred to as application B for short) and the secure sharing and exchange service B are deployed in the network B domain of the receiving end.

[0041] The technical solution provided by the present invention is as follows:

[0042] (1) Register the interface information of the service applications that need to interact across the optical isolation gateway on the sharing and exchange service, including the interface names (globally unique) and interface URLs of the sending end (application A) and the receiving end (application B), etc. The above information is stored in the database; after registration, configure the storage paths named after the interface name of the receiving end (application B) on the front-end and back-end machines of the first optical isolation gateway, and configure the storage paths named after the interface name of the sending end (application A) on the front-end and back-end machines of the second optical isolation gateway. In addition to the registration information, the database will also store transmission records, including the application name, transmission status, transmission time, transmission content, and return results of the transmission.

[0043] (2) Application A encapsulates the service files or service interface data to be transmitted to application B, the interface name of application B, and the authentication parameters of the sharing and exchange service in a specific format (such as JSON), and sends a file transfer request to the push module of the secure sharing and exchange service A through the HTTP / HTTPS protocol.

[0044] (3) The push module of the secure sharing and exchange service A receives the file transfer request and parses it to obtain information such as authentication parameters, interface names, business files, or business interface data.

[0045] (4) The push module of the secure sharing and exchange service A verifies the legality of the file transfer request according to the authentication parameters. If the verification fails, the push module returns an authentication failure message; if the verification passes, the subsequent processing step (5) is carried out. Among them, the authentication method can be TOKEN or ciphertext.

[0046] (5) The push module of the secure sharing and exchange service A retrieves the interface name according to the registration information in step (1). If it exists, it proceeds to the next step; if it does not exist, an error message is returned.

[0047] (6) The push module of the secure sharing and exchange service A reads the transmitted business file or encapsulates the business interface data into a JSON file and pushes it to the storage path named by the business interface on the first light gate front-end machine.

[0048] (7) The push module of the secure sharing and exchange service A records and stores the business interface name, the name of the transmitted file (business file or JSON file), and the time of transmission.

[0049] (8) The monitoring module B of the secure sharing and exchange service B monitors the back-end machine of the light gate on the network B side. When a new file (i.e., the business file or the JSON file encapsulating the business interface data described in step 6) is detected, the interface name is obtained according to the storage path of the new file, and the new file and the interface name are encapsulated and sent to the push module B of the secure sharing and exchange service B as a file push request through the HTTP / HTTPS protocol.

[0050] (9) The push module B of the secure sharing and exchange service B receives the file push request from the monitoring module B and parses it to obtain the interface name and the business file or business interface data in the new file. The corresponding interface URL is obtained from the database in step (1) through the interface name, and the business file or business interface data is sent to application B as a file processing request through the HTTP / HTTPS protocol.

[0051] (10) After receiving the file processing request, application B encapsulates the processing result, the interface name of application A, and the authentication parameters of the sharing and exchange service B in a specific format and sends a processing result transmission request to the push module B of the secure sharing and exchange service B through the HTTP / HTTPS protocol.

[0052] (11) The push module B of the secure sharing and exchange service B receives the processing result transmission request and parses it. The processing result data and interface name are encapsulated into a JSON file according to the sending time and pushed to the storage path named after the interface of the second optical isolation pre-processor.

[0053] (12) The monitoring module A of the secure sharing and exchange service A monitors the post-processor of the second optical isolation. When a new file is detected, the content of the new file is parsed to obtain the interface name. After encapsulating the new file and the interface name, a data push request is sent to the push module A of the secure sharing and exchange service A through the HTTP / HTTPS protocol.

[0054] (13) The push module A of the secure sharing and exchange service A parses the data push request sent by the monitoring module A to obtain the interface name and the processing result. The push module A obtains the corresponding interface URL from the database of network A according to the interface name and sends the processing result to application A through the HTTP / HTTPS protocol.

[0055] (14) Thus, application A obtains the processing result of application B.

[0056] Further, in the above step (1), to ensure that the URL information does not pass through the optical isolation, the interface names of each application B, the interface names of each application A, and the interface URLs are stored in the secure sharing and exchange service A, and the interface names of each application B, the interface URLs, and the interface names of application A are stored in the secure sharing and exchange service B.

[0057] Further, in the above step (2), for the case where application A transmits business files, application A encapsulates the business files, interface names, and authentication parameters in the form of form-data; for the case where application A needs to send business interface data, application A encapsulates the interface name, authentication parameters, and business interface data in the form of JSON.

[0058] Further, in the above step (7), when the received file is a non-JSON file, the monitoring module reads the file content, encapsulates the parameter and the interface name using the HTTP / HTTPS protocol, and sends them to the processing file interface of the push module; when the received file is a JSON file, the monitoring module parses the JSON file, and uses the parsed result and the interface name as request parameters to call the processing request interface of the push module using the HTTP / HTTPS protocol.

[0059] Although specific embodiments of the present invention are disclosed for illustrative purposes, which are intended to assist in understanding the content of the present invention and implementing it accordingly, those skilled in the art can understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the content disclosed in the best embodiments, and the scope of protection claimed by the present invention shall be defined by the scope defined in the claims.

Claims

1. A secure sharing and exchange method based on a double one-way optical switch, the steps of which include: 1) Deploy a sharing and exchange service in each of the two networks isolated by the optical switch, and register the interface information of the service applications that need to interact across the optical switch on the sharing and exchange service; Each of the networks includes a database for storing registration information, transmission records, transmitted application names, transmission status, transmission time, transmission content, and return results; the two networks are respectively denoted as Network A and Network B, the sharing and exchange service deployed in Network A domain is denoted as Secure Sharing and Exchange Service A, and the sharing and exchange service deployed in Network B domain is denoted as Secure Sharing and Exchange Service B; Network A sends data to Network B via the first optical switch, and Network B sends data to Network A via the second optical switch. The front-end and back-end machines of the first optical switch are configured with a storage path named after the interface name of Application B in Network B, and the front-end and back-end machines of the second optical switch are configured with a storage path named after the interface name of Application A in Network A; 2) Application A encapsulates the service file or service interface data, the interface name of Application B, and the authentication parameters of Secure Sharing and Exchange Service A, and sends a file transfer request to Push Module A of Secure Sharing and Exchange Service A through the HTTP / HTTPS protocol; 3) Push Module A of Secure Sharing and Exchange Service A parses the received file transfer request to obtain the authentication parameters, verifies the legitimacy of the request according to the authentication parameters, and returns authentication failure if the verification fails; if the authentication passes, proceed to step 4); 4) Push Module A retrieves according to the interface name parsed from the request in the registration information on Secure Sharing and Exchange Service A. If the interface name exists in the registration information on Secure Sharing and Exchange Service A, proceed to step 5); 5) Push Module A reads the transmitted service file or encapsulates the service interface data into a JSON file and pushes it to the storage path named after the service interface of the front-end machine of the first optical switch, and records the service interface name, transmitted file name, and time of transmission; 6) Monitoring Module B of Secure Sharing and Exchange Service B monitors the back-end machine of the optical switch on the Network B side. When a new file is detected, it obtains the interface name corresponding to the new file, and then encapsulates the new file and its corresponding interface name and sends a file push request to Push Module B of Secure Sharing and Exchange Service B through the HTTP / HTTPS protocol; 7) Push Module B of Secure Sharing and Exchange Service B parses the received file push request to obtain the interface name and the service file or service interface data in the new file, obtains the URL corresponding to the interface name from the database of Network B, and sends a file processing request to Application B through the HTTP / HTTPS protocol for the transmission object; the transmission object is the service file or service interface data; 8) After receiving the file processing request, Application B encapsulates the processing result, the interface name of Application A, and the authentication parameters of Secure Sharing and Exchange Service B, and sends a processing result transmission request to Push Module B of Secure Sharing and Exchange Service B through the HTTP / HTTPS protocol; 9) The Push Module B receives the processing result transmission request, parses it, encapsulates the processing result data and the interface name into a JSON file according to the sending time, and pushes it to the storage path named after the interface on the second light gateway front-end machine; 10) The Monitoring Module A of the Secure Sharing and Exchange Service A monitors the back-end machine of the second light gateway. When a new file is detected, it parses the content of the new file to obtain the interface name, encapsulates the new file and the interface name, and sends a data push request to the Push Module A of the Secure Sharing and Exchange Service A via the HTTP / HTTPS protocol; 11) The Push Module A parses the data push request sent by the Monitoring Module A, obtains the interface name and the processing result; then obtains the corresponding interface URL from the database of Network A according to the interface name, and sends the processing result to Application A via the HTTP / HTTPS protocol.

2. The method according to claim 1, wherein The registered interface information includes the sending-end interface name, the sending-end interface URL, the receiving-end interface name, and the receiving-end interface URL.

3. The method according to claim 2, wherein The front-end machine and the back-end machine of the network are configured with a storage path named after the receiving-end interface name.

4. The method according to claim 1 or 2 or 3, characterized in that, The Monitoring Module B obtains the interface name according to the storage path of the new file.

5. The method according to claim 1 or 2 or 3, characterized in that In step 2), when a business file needs to be transmitted, Application A encapsulates the business file, the interface name, and the authentication parameters in the form of form-data; When business interface data needs to be transmitted, Application A encapsulates the interface name, the authentication parameters, and the business interface data in JSON format.

6. The method according to claim 1 or 2 or 3, characterized in that, In step 6), when it is detected that the new file is a non-JSON file, the Monitoring Module B reads the content of the new file as a parameter, and encapsulates and sends the parameter and the interface name to the processing file interface of the Push Module B using HTTP / HTTPS; when it is detected that the new file is a JSON file, the Monitoring Module B parses the JSON file, and uses the parsed result and the interface name as request parameters to call the processing request interface of the Push Module B in an HTTP / HTTPS manner.

7. A secure sharing and exchange system based on a double one-way optical shutter, characterized in that, It includes a light gateway and a sharing and exchange service unit, and the sharing and exchange service unit includes a push module and a monitoring module; The light gateway is used to isolate two networks; a sharing and exchange service unit is deployed in each of the networks, and the interface information of the business applications that need to interact across the light gateway is registered on the sharing and exchange service; each network includes a database for storing registration information, transmission records, transmitted application names, transmission status, transmission time, transmission content, and return results; the two networks are respectively denoted as Network A and Network B, the sharing and exchange service deployed in the Network A domain is denoted as the Secure Sharing and Exchange Service A, and the sharing and exchange service deployed in the Network B domain is denoted as the Secure Sharing and Exchange Service B; Network A sends data to Network B via the first light gateway, and Network B sends data to Network A via the second light gateway. The front-end machine and the back-end machine of the first light gateway are configured with a storage path named after the interface name of Application B in Network B, and the front-end machine and the back-end machine of the second light gateway are configured with a storage path named after the interface name of Application A in Network A; The push module A of the secure sharing and exchange service A is used to receive the file transfer requests sent by Application A in Network A domain after encapsulating business files or business interface data, the receiving end interface name, and the authentication parameters of the sharing and exchange service A through the HTTP / HTTPS protocol; and to parse the received file transfer requests to obtain the authentication parameters, verify the legitimacy of the requests based on the authentication parameters, return authentication failure if the verification fails, and if the authentication passes, retrieve according to the interface name parsed from the requests in the registration information on the secure sharing and exchange service A. If the interface name exists in the registration information on the secure sharing and exchange service A; then read the transferred business files or encapsulate the business interface data into a JSON file and push it to the storage path named after the business interface on the front-end machine of the first air gap, and record the business interface name, the transferred file name, and the time of transfer; And parse the data push requests sent by the monitoring module A to obtain the interface name and the processing result; then obtain the corresponding interface URL from the database of Network A according to the interface name, and send the processing result to Application A through the HTTP / HTTPS protocol; The monitoring module A is used to monitor the back-end machine of the second air gap. When a new file is detected, parse the content of the new file to obtain the interface name, encapsulate the new file and the interface name, and send a data push request to the push module A of the secure sharing and exchange service A through the HTTP / HTTPS protocol; The monitoring module B of the secure sharing and exchange service B is used to monitor the back-end machine of the air gap on the Network B side. When a new file is detected, obtain the interface name corresponding to the new file, and then encapsulate the new file and its corresponding interface name and send a file push request to the push module B of the secure sharing and exchange service B through the HTTP / HTTPS protocol; The push module B is used to obtain the interface name parsed from the received file push request and the business files or business interface data in the new file, obtain the URL corresponding to the interface name from the database of Network B, and send a file processing request to Application B through the HTTP / HTTPS protocol for the transfer object; the transfer object is the business file or business interface data; And receive and parse the processing result transfer requests, encapsulate the processing result data and the interface name into a JSON file according to the sending time, and push it to the storage path named after the interface on the front-end machine of the second air gap.

8. The system according to claim 7, wherein The registered interface information includes the sending end interface name, the sending end interface URL, the receiving end interface name, and the receiving end interface URL.

9. The system according to claim 8, wherein The front-end machine and the back-end machine of the network are configured with a storage path named after the receiving end interface name.

Citation Information

Patent Citations

  • Cross-domain microservice registration and release method and system based on file exchange

    CN111447256A

  • Fencing off cluster services based on shared storage access keys

    US20240004712A1