Multi-channel isolation transmission system and method based on programmable logic device

By adopting a multi-channel isolated transmission system based on programmable logic devices in the gate isolation device system, the binding between each session and a single transmission channel is realized, solving the problems of insufficient session isolation and low transmission efficiency in the existing system, and improving system security and data transmission efficiency.

CN120104527APending Publication Date: 2025-06-06NARI INFORMATION & COMM TECH +4
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510108436.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

In the existing gate isolation device system, the number of channels is limited, and the sessions are not isolated at the hardware level, which poses a security risk; at the same time, the transmission efficiency is low, and session information needs to be added to the data, and when the number of sessions is large, computing resources are wasted.

Method used

A multi-channel isolated transmission system based on programmable logic devices is adopted. By starting a work thread equal to the number of processor cores on the intranet processing unit and the external network processing unit, each work thread is bound to a processor core, and each session is bound to a transmission channel on a dedicated isolation component, so that a single transmission channel is bound to only one session.

Benefits of technology

At the hardware level, the isolation between sessions is realized, which improves system security; at the same time, the burden on transmission channels is reduced, data transmission efficiency is improved, and unnecessary time-consuming session search is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120104527A_ABST
    Figure CN120104527A_ABST
Patent Text Reader

Abstract

The invention discloses a multichannel isolated transmission system and method based on a programmable logic device. The system comprises an intranet processing unit, an extranet processing unit and a special isolation component, the intranet processing unit and the extranet processing unit respectively comprise a multi-core processor, the number of cores of the processors is equal to the number of working threads on the intranet processing unit and the extranet processing unit, each working thread is bound with one processor core, and the number of the working threads is equal to the number of the working threads on the extranet processing unit. Each working thread supports processing of a plurality of sessions, each session is bound with one transmission channel on the special isolation component, and session data is transmitted through the corresponding transmission channel. According to the invention, a single transmission channel is only bound with one session, isolation between sessions is realized on a hardware level, session information does not need to be added in the data written into the transmission channel, the burden of the transmission channel is reduced, and the system security and the data transmission efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data transmission, and in particular to a multi-channel isolation transmission system and method based on programmable logic devices. Background Art

[0002] The network gate isolation device system is a product designed for data exchange between two independent networks with different security levels. It has been used at the boundary of high-security intranet and low-security extranet in important places such as government, medical, and energy. It is a special device for realizing non-network transmission data exchange between intranet and extranet. The mainstream network gate isolation device system adopts a "2+1" architecture, which consists of an intranet processing module, an extranet processing module, and a special isolation module. The intranet processing module is connected to the intranet business machine, and the extranet processing module is connected to the extranet business machine.

[0003] The core isolation components in existing network firewall isolation device systems are generally implemented using foreign dedicated processors, which have low autonomy and controllability and cannot fundamentally avoid risks such as backdoor implantation, data eavesdropping, and supply chain attacks.

[0004] Reference Figure 1 The existing network gate isolation device system generally adopts multi-channel transmission, and the steps of data exchange are as follows:

[0005] First, the intranet business machine initiates a request to establish a session to the network gate isolation device system. After receiving the request, the intranet processing module of the network gate isolation device system assigns a pre-established work thread to handle the session request, and initiates a request to establish a session to the external network processing module through the transmission channel of the dedicated isolation module bound to the work thread. After receiving the session establishment request, the work thread of the external network processing module sends a session establishment request to the external network business machine to complete the session establishment.

[0006] Secondly, the data from the intranet business machine to the extranet business machine is transmitted in sequence according to the business path of intranet business machine->internet processing module of the network gate isolation device system->dedicated isolation module->external processing module->external business machine.

[0007] Finally, after the data transmission is completed, the session ends. Both the intranet business machine and the extranet business machine can actively close the session. After receiving the session closing request, the intranet processing module or the extranet processing module will notify the other end to close the session.

[0008] After analyzing the above multi-channel network gate isolation transmission technology solution, it is not difficult to find that the existing technical solution has the following two shortcomings:

[0009] (1) The number of channels is limited, and multiple sessions need to be processed concurrently in a single transmission channel, such as Figure 1Channel 1-1 to channel 1-N refer to multiple sessions that transmit data through channel 1. Multiple sessions share one channel, and the sessions are not isolated at the hardware level, posing a security risk.

[0010] (2) When the internal network processing module writes the transmission data into the transmission channel, it must add session information to the transmission data, which reduces the transmission efficiency. After the external network processing module reads the data from the transmission channel, it must find the corresponding session through the session information. When the number of sessions is large, it will waste computing resources and time, further reducing the transmission efficiency. Summary of the invention

[0011] The purpose of this section is to summarize some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the specification abstract and the invention title of the present invention to avoid blurring the purpose of this section, the specification abstract and the invention title, and such simplifications or omissions cannot be used to limit the scope of the present invention.

[0012] In view of the problems existing in the above-mentioned prior art, the present invention is proposed. The present invention provides a multi-channel isolation transmission system and method based on programmable logic devices, which realizes that a single transmission channel is bound to only one session, isolates the sessions at the hardware level, improves system security, reduces the burden on the transmission channel, and improves data transmission efficiency.

[0013] In order to achieve the above-mentioned object of the invention, the present invention adopts the following technical scheme:

[0014] In a first aspect, a multi-channel isolated transmission system based on a programmable logic device includes: an internal network processing unit, an external network processing unit and a dedicated isolation component, the internal network processing unit and the external network processing unit respectively include a multi-core processor, the number of processor cores is equal to the number of working threads on the internal network processing unit and the external network processing unit, each working thread is bound to a processor core, each working thread supports processing a number of sessions, each session is bound to a transmission channel on the dedicated isolation component, and the session data is transmitted through the corresponding transmission channel.

[0015] According to certain embodiments of the first aspect, each session is bound to a transmission channel on a dedicated isolation component, and the method is as follows: when the intranet processing unit and the extranet processing unit are initialized, the host side data write address and the data read address of the corresponding channel are respectively sent to the dedicated isolation component, and the dedicated isolation component binds the data write address and the data read address of each channel to the transmission channel to form a data transfer table.

[0016] According to certain embodiments of the first aspect, session data is transmitted through a corresponding transmission channel as follows: after receiving the data, the dedicated isolation component queries the transmission channel from the data transfer table according to the data write address, and writes the data into the transmission channel; when forwarding the data, the data read address corresponding to the transmission channel is searched according to the data transfer table, and the data is forwarded to the corresponding processing unit.

[0017] According to certain embodiments of the first aspect, the dedicated isolation component includes an autonomously controllable programmable logic device and a random access memory, data search and forwarding control are performed by the autonomously controllable programmable logic device, the transmission channel is set in the random access memory, and the random access memory is responsible for data caching.

[0018] According to certain embodiments of the first aspect, the internal network processing unit and the external network processing unit are connected to the dedicated isolation component via a high-speed interconnect interface.

[0019] According to certain embodiments of the first aspect, the high-speed interconnect interface adopts a PCIe interface.

[0020] According to certain implementations of the first aspect, the intranet processing unit is connected to the intranet service machine via a first network interface, and the extranet processing unit is connected to the extranet service machine via a second network interface.

[0021] In a second aspect, a multi-channel isolation transmission method based on a programmable logic device is applied to a multi-channel isolation transmission system including an internal network processing unit, an external network processing unit and a dedicated isolation component, the method comprising:

[0022] Start several worker threads on the intranet processing unit and the extranet processing unit respectively. The number of worker threads is equal to the number of processor cores. Each worker thread is bound to a processor core. Each worker thread supports processing several sessions.

[0023] When the internal network processing unit and the external network processing unit are initialized, the host side data write address and data read address of the corresponding channel are sent to the dedicated isolation component respectively, and the dedicated isolation component binds the data write address and data read address of each channel with the transmission channel to form a data transfer table;

[0024] The intranet processing unit or the extranet processing unit sends data to the dedicated isolation component according to business needs;

[0025] After receiving the data, the dedicated isolation component queries the transmission channel from the data transfer table according to the data write address and writes the data into the transmission channel; when forwarding the data, it searches the data read address corresponding to the transmission channel according to the data transfer table and forwards the data to the corresponding processing unit.

[0026] According to certain implementations of the second aspect, before the intranet processing unit and the external network processing unit transmit data, a session connection is also established, the party initiating the session between the intranet processing unit and the external network processing unit is called the current processing unit, and the party receiving the session request is called the other party processing unit, and the connection establishment method is as follows:

[0027] The current processing unit allocates a transmission channel for the session and binds it according to the session establishment request received from the corresponding service machine, and sends the bound session information to the other processing unit according to the allocated transmission channel. The other processing unit generates a session with the corresponding service machine and binds the session with the current transmission channel for reading data.

[0028] The other processing unit sends a session establishment request to the corresponding service machine according to the session information transmitted by the current processing unit, and transmits the session establishment information to the current processing unit through the bound transmission channel according to the session confirmation information of the corresponding service machine;

[0029] The current processing unit locates the corresponding session through the bound transmission channel according to the session establishment information and notifies the initiator of the session. At this time, the session establishment between the intranet service machine and the extranet service machine is completed.

[0030] According to some implementations of the second aspect, the process of transmitting data between the internal network processing unit and the external network processing unit includes:

[0031] When the intranet business machine actively sends data, the data is pushed to the intranet processing unit. After receiving the data pushed by the intranet business machine, the intranet processing unit writes a DMA request command to the dedicated isolation component according to the bound transmission channel; when the dedicated isolation component detects the DMA command, it stores it in the command buffer area waiting for the execution command, and the dedicated isolation component parses the command to query the transmission channel from the data transfer table and sends a corresponding DMA read operation request. After receiving the DMA request, the intranet processing unit sends the data pushed by the intranet business machine to the transmission channel corresponding to the dedicated isolation component through the high-speed transmission interface, and caches it in the dedicated isolation component; when the dedicated isolation component forwards data, it searches for the data read address corresponding to the transmission channel according to the data transfer table, forwards the data to the external network processing unit, sends a DMA write request to the external network processing unit, and the external network processing unit reads the data cached in the corresponding channel according to the corresponding information and sends it to the external network business machine;

[0032] When the external network business machine actively sends data, the data is pushed to the external network processing unit. After the external network processing unit receives the data pushed by the external network business machine, it writes a DMA request command to the dedicated isolation component according to the bound transmission channel; when the dedicated isolation component detects the DMA command, it stores it in the command buffer area waiting for the execution command. The dedicated isolation component parses the command and queries the transmission channel from the data transfer table, and sends a corresponding DMA read operation request. After receiving the DMA request, the external network processing unit sends the data pushed by the external network business machine to the transmission channel corresponding to the dedicated isolation component through the high-speed transmission interface, and caches it in the dedicated isolation component; when the dedicated isolation component forwards data, it searches for the data read address corresponding to the transmission channel according to the data transfer table, forwards the data to the internal network processing unit, sends a DMA write request to the internal network processing unit, and the internal network processing unit reads the data cached in the corresponding channel according to the corresponding information, and sends it to the internal network business machine.

[0033] According to some embodiments of the second aspect, the method further comprises a connection closing phase:

[0034] When the intranet service machine actively closes the session, it sends a session closing request to the intranet processing unit. After the intranet processing unit locates the transmission channel bound to the session and sends an internal session closing request to the external network processing unit, the intranet session is closed and the binding relationship between the session and the transmission channel is disconnected. After receiving the session closing request, the external network processing unit locates the corresponding session, disconnects the binding relationship between the session and the transmission channel, and finally closes the session with the external network service machine.

[0035] When the external network business machine actively closes the session, it sends a session closing request to the external network processing unit. After the external network processing unit locates the transmission channel bound to the session and sends an internal session closing request to the internal network processing unit, it closes the external network session and disconnects the binding relationship between the session and the transmission channel. After receiving the session closing request, the internal network processing unit locates the corresponding session, disconnects the binding relationship between the session and the transmission channel, and finally closes the session with the internal network business machine.

[0036] Compared with the prior art, the present invention has the following beneficial effects: (1) Several working threads are started in the intranet processing unit and the extranet processing unit respectively, the number of working threads is equal to the number of cores of the processor, and the working threads are bound to the processor cores one by one, and each working thread supports processing multiple sessions; several transmission channels are designed on the dedicated isolation component, and the sessions are bound to the transmission channels one by one. By binding a single transmission channel to only one session, the isolation between sessions is achieved at the hardware level, thereby improving the security of the system. (2) After the session is bound to the transmission channel, before writing data to the transmission channel, the transmission channel can be directly located according to the session, and before writing data to the session, the session can also be directly located according to the transmission channel, thereby reducing unnecessary session search time and improving data transmission efficiency. In addition, it is not necessary to add session information to the data written to the transmission channel, thereby reducing the burden on the transmission channel. (3) As the core component of the network gate isolation system, the dedicated isolation component adopts an autonomous and controllable programmable logic device, which can enhance the autonomous controllability of the device and reduce the possibility of supply chain attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 It is a schematic diagram of the structure of a network gate isolation system in the prior art;

[0038] Figure 2 It is a structural schematic diagram of a multi-channel isolation transmission system based on a programmable logic device of the present invention;

[0039] Figure 3 The present invention is a flowchart of a multi-channel isolation transmission method based on a programmable logic device. DETAILED DESCRIPTION

[0040] The technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings.

[0041] Reference Figure 2 The embodiment of the present invention provides a multi-channel isolation transmission system based on programmable logic devices, which mainly includes an internal network processing unit, an external network processing unit and a dedicated isolation component.

[0042] The internal network processing unit includes an internal network processor with M MPU cores, the internal network processor is connected to the internal network PCIe interface and the first network interface, is connected to the dedicated isolation component through the internal network PCIe interface, and is connected to the internal network business machine through the first network interface. The external network processing unit includes an external network processor with M CPU cores, the external network processor is connected to the external network PCIe interface and the second network interface, is connected to the dedicated isolation component through the external network PCIe interface, and is connected to the external network business machine through the second network interface. The core of the dedicated isolation component is an autonomous controllable programmable logic device, which is connected to the internal network processing unit and the external network processing unit through the PCIe interface.

[0043] The intranet processor of the present invention has M CPU cores, M working threads are run on the intranet processing unit, and each working thread is bound to an intranet CPU core. The external network processor has M CPU cores, M working threads are run on the external network processing unit, and each working thread is bound to an external network CPU core. An intranet working thread can process N sessions, and an external network working thread can process N sessions corresponding to the intranet. A session inside the intranet processing unit can use a transmission channel alone to exchange data with the corresponding session inside the external network processing unit. The present invention realizes highly parallel processing capabilities by binding a working thread to each CPU core, and each working thread can process N sessions. This one-to-one binding ensures that each CPU core can independently and efficiently process multiple sessions without reducing efficiency due to shared resources. Compared with the prior art, which is limited by FPGA resources and communication schemes, and multiple sessions share a transmission channel, the present invention can better utilize the parallel processing advantages of multi-core processors, thereby improving the overall data processing speed and system throughput.

[0044] The core components of the dedicated isolation component are the self-controlled programmable logic device and RAM (random access memory) chip. The self-controlled programmable logic device is responsible for data forwarding, and the RAM chip is responsible for data caching. Figure 2 As shown. M×N transmission channels are opened in the RAM, and each channel is bound to a session for data transmission of the session. The binding relationship here is realized by associating the read-write address with the transmission channel through the internal and external network processing units, without the need for session information. Specifically, when the internal network processing unit and the external network processing unit are initialized, the host-side data write address and data read-out address corresponding to the M×N channels are sent to the dedicated isolation component respectively, and the dedicated isolation component binds the data write address and data read-out address of each channel to the transmission channel to form a data transfer table, which is stored in the autonomous controllable programmable logic device. That is, the logic device uses a register to store the channel information corresponding to each read-write address. After receiving the data, the dedicated isolation component queries the transmission channel from the data transfer table according to the data write address and writes the data into the transmission channel; when forwarding the data, the data read-out address corresponding to the transmission channel is searched according to the data transfer table, and the data is forwarded to the corresponding processing unit. Here, the M×N channels of the internal and external network processing units are the "transmission channels" mentioned in the context, that is, the M×N channels of the internal and external network processing units correspond one-to-one to the M×N channels on the dedicated isolation component to form a transmission channel. The data write address and the data read address here are written into the internal register of the dedicated isolation component when the internal and external network processing units load the driver of the dedicated isolation component.

[0045] Taking the example of the internal network processing unit using the 1-3 channel to send data to the external network processing unit, the internal network processing unit allocates a data write address for the 1-3 channel when loading the driver of the dedicated isolation component, sends the data write address to the dedicated isolation component, and the dedicated isolation component records it into the internal register. The internal network processing unit sends data to the dedicated isolation component. After receiving the data, the dedicated isolation component queries channel 1-3 according to the address of the data write end and writes the data into channel 1-3. When loading the driver of the dedicated isolation component, the external network processing unit allocates a data read address for the 1-3 channel, sends the data read address to the dedicated isolation component, and the dedicated isolation component records it into the internal register. When the dedicated isolation component forwards data, it reversely checks the address of the data read end through channel 1-3 and forwards the data to the external network processing unit.

[0046] The dedicated isolation component of the present invention is connected to the intranet processing unit and the extranet processing unit respectively through the PCIe interface, and has high data transmission efficiency. The intranet processing unit and the extranet processing unit respectively start a number of working threads, the number of working threads is equal to the number of cores of the processor, and the working threads are bound to the processor cores one by one; the dedicated isolation component adopts an autonomous controllable programmable logic device, and a number of transmission channels are designed on the autonomous controllable programmable logic device. The sessions in the intranet processing unit and the extranet processing unit are bound to the transmission channels in the dedicated isolation component one by one, so that a single transmission channel is bound to only one session, and isolation between sessions is achieved at the hardware level, thereby improving system security. After the session is bound to the transmission channel, before writing data to the transmission channel, the transmission channel can be directly located according to the session; before writing data to the session, the session can also be directly located according to the transmission channel, thereby reducing unnecessary session search time.

[0047] Reference Figure 3 The process of data transmission between the internal network processing unit and the external network processing unit can be divided into a connection establishment phase, a data transmission phase, and a connection closing phase. The internal network processing unit and the external network processing unit are also referred to as the internal network unit and the external network unit.

[0048] (1) Connection establishment phase:

[0049] The party initiating the session between the internal network processing unit and the external network processing unit is called the current processing unit, and the party receiving the session request is called the other party processing unit;

[0050] The current processing unit allocates a transmission channel for the session and binds it according to the session establishment request received from the corresponding service machine, and sends the bound session information to the other processing unit according to the allocated transmission channel. The other processing unit generates a session with the corresponding service machine and binds the session with the current transmission channel for reading data.

[0051] The other processing unit sends a session establishment request to the corresponding service machine according to the session information transmitted by the current processing unit, and transmits the session establishment information to the current processing unit through the bound transmission channel according to the session confirmation information of the corresponding service machine;

[0052] The current processing unit locates the corresponding session through the bound transmission channel according to the session establishment information and notifies the initiator of the session. At this time, the session establishment between the intranet service machine and the extranet service machine is completed.

[0053] (2) Data transmission stage:

[0054] As described above, when the internal network processing unit and the external network processing unit are initialized, the host side data write address and data read address corresponding to the M×N channels are sent to the dedicated isolation component, and the dedicated isolation component binds the data write address and data read address of each channel to the transmission channel to form a data transfer table, which is stored in the autonomous controllable programmable logic device. Data transmission is completed based on the data transfer table.

[0055] When the intranet business machine actively sends data, it first pushes the data to the intranet processing unit. After receiving the data pushed by the intranet business machine, the intranet processing unit writes a DMA request command to the dedicated isolation component according to the bound transmission channel. When the dedicated isolation component detects the DMA command, it stores it in the command buffer waiting for the execution command. The dedicated isolation component parses the command and queries the transmission channel from the data transfer table, and sends the corresponding DMA read operation request. After receiving the DMA request, the intranet processing unit sends the data pushed by the intranet business machine to the transmission channel corresponding to the dedicated isolation component through the high-speed transmission interface PCIe, and caches it in the dedicated isolation component. When the dedicated isolation component forwards data, it searches for the data read address corresponding to the transmission channel according to the data transfer table, forwards the data to the external network processing unit, sends a DMA write request to the external network processing unit, and the external network processing unit reads the data cached in the corresponding channel according to the corresponding information and sends it to the external network business machine. During this process, the intranet processing unit can directly locate the transmission channel based on the session, and the external network processing unit can locate the session information based on the transmission channel of the read data, and push data to the external network business machine through the located session. There is no need to perform session search, and there is no need to carry session-related information in the transmitted data, which significantly improves efficiency.

[0056] Similarly, when the external network business machine actively sends data, it first pushes the data to the external network processing unit. After the external network processing unit receives the data pushed by the external network business machine, it writes a DMA request command to the dedicated isolation component according to the bound transmission channel; when the dedicated isolation component detects the DMA command, it stores it in the command buffer area waiting for the execution command. The dedicated isolation component parses the command and queries the transmission channel from the data transfer table, and sends the corresponding DMA read operation request. After receiving the DMA request, the external network processing unit sends the data pushed by the external network business machine to the transmission channel corresponding to the dedicated isolation component through the high-speed transmission interface PCIe, and caches it in the dedicated isolation component. When the dedicated isolation component forwards data, it searches for the data read address corresponding to the transmission channel according to the data transfer table, forwards the data to the internal network processing unit, and sends a DMA write request to the internal network processing unit. The internal network processing unit reads the data cached in the corresponding channel according to the corresponding information and sends it to the internal network business machine, thus completing the data transmission from the external network business machine to the internal network business machine.

[0057] (3) Connection closing phase:

[0058] When the intranet service machine actively closes the session, it first sends a session closing request to the intranet processing unit. After the intranet processing unit locates the transmission channel bound to the session and sends an internal session closing request to the external network processing unit, the intranet session is closed and the binding relationship between the session and the transmission channel is disconnected. After receiving the session closing request, the external network processing unit locates the corresponding session, disconnects the binding relationship between the session and the transmission channel, and finally closes the session with the external network service machine.

[0059] When the external network business machine actively closes the session, it first sends a session closing request to the external network processing unit. After the external network processing unit locates the transmission channel bound to the session and sends an internal session closing request to the internal network processing unit, it closes the external network session and disconnects the binding relationship between the session and the transmission channel. After receiving the session closing request, the internal network processing unit locates the corresponding session, disconnects the binding relationship between the session and the transmission channel, and finally closes the session with the internal network business machine.

[0060] In one embodiment, the specific steps of multi-channel isolation transmission based on autonomous controllable programmable logic devices are as follows:

[0061] Step 1: The intranet processing unit receives a connection establishment request from an intranet service machine and authenticates the intranet service machine according to the access control policy. If the IP, MAC and other information of the intranet service machine are not in the access control policy of the intranet processing unit, the intranet processing unit rejects the session establishment request.

[0062] Step 2: The intranet processing unit selects a currently available transmission channel. If there is no available transmission channel, the session establishment request of the intranet service machine is rejected. Otherwise, the selected transmission channel is bound to the current session.

[0063] Step 3: The intranet service unit sends an internal session establishment request to the external network transmission channel through the selected transmission channel. The connection request message carries the semi-connected session information between the intranet service machine and the intranet processing unit.

[0064] Step 4: After receiving the new session connection request, the external network processing unit generates a new session with the external network service machine (without establishing a connection), and binds the session to the current transmission channel for reading data.

[0065] Step 5: The external network processing unit sends a session establishment request to the external network server based on the session information transmitted by the internal network processing unit.

[0066] Step 6: The external network processing unit waits for the session confirmation information from the external network service machine. If no response is received within the time limit or an incorrect confirmation information is received, the internal network processing unit is notified to close the session, and then the current session of the external network processing unit is closed.

[0067] Step 7: After receiving the correct confirmation information, the external network processing unit transmits the session establishment information to the internal network processing unit through the bound transmission channel.

[0068] Step 8: After receiving the message of session establishment, the intranet processing unit quickly locates the corresponding session through the transmission channel and notifies the initiator of the session. At this point, the session establishment between the intranet service machine and the extranet service machine is completed.

[0069] Step 9: When the intranet business machine actively sends data, the data is first pushed to the intranet processing unit. The intranet processing unit locates the transmission channel bound to it based on the session information, and pushes the data to the external network processing unit through the transmission channel. The external network processing unit locates the session information based on the transmission channel for reading the data, and pushes the data to the external network business machine through the located session.

[0070] Step 10: When the external network business machine actively sends data, the process is the same as step 9, but the transmission direction is opposite.

[0071] Step 11: When the intranet business machine actively closes the session, it first sends a session closing request to the intranet processing unit. The intranet processing unit locates the transmission channel bound to the session and sends an internal session closing request to the external network processing unit, then closes the intranet session and disconnects the binding relationship between the session and the transmission channel.

[0072] Step 12: After receiving the request to close the session, the external network processing unit locates the corresponding session, disconnects the binding relationship between the session and the transmission channel, and finally closes the session with the external network service machine.

[0073] Step 13: When the external network business machine actively closes the session, the steps are the same as 11-12, and the transmission direction is opposite.

[0074] The present invention improves the existing network gate isolation device system. By binding a single transmission channel to only one session, the data written into the transmission channel does not need to add session information, which reduces the burden on the transmission channel. After reading the data from the transmission channel, it directly locates the channel bound to the channel, reducing the steps of session search and improving data transmission efficiency. The dedicated isolation component is the core component of the network gate isolation system. It adopts an autonomous and controllable programmable logic device, which can enhance the autonomous controllability of the equipment and reduce the risk of supply chain attacks.

Claims

1. A multi-channel isolation transmission system based on programmable logic devices, characterized in that: include: The internal network processing unit, the external network processing unit and the dedicated isolation component, the internal network processing unit and the external network processing unit respectively include a multi-core processor, the number of processor cores is equal to the number of working threads on the internal network processing unit and the external network processing unit, each working thread is bound to a processor core, each working thread supports processing several sessions, each session is bound to a transmission channel on the dedicated isolation component, and the session data is transmitted through the corresponding transmission channel.

2. The system according to claim 1, characterized in that Each session is bound to a transmission channel on a dedicated isolation component in the following manner: when the intranet processing unit and the extranet processing unit are initialized, the host-side data write address and the data read address of the corresponding channel are respectively sent to the dedicated isolation component. The dedicated isolation component binds the data write address and the data read address of each channel to the transmission channel to form a data transfer table.

3. The system according to claim 2, characterized in that The session data is transmitted through the corresponding transmission channel in the following method: after receiving the data, the dedicated isolation component queries the transmission channel from the data transfer table according to the data write address and writes the data into the transmission channel; when forwarding the data, the data read address corresponding to the transmission channel is searched according to the data transfer table and the data is forwarded to the corresponding processing unit.

4. The system according to claim 3, characterized in that The dedicated isolation component includes an autonomous controllable programmable logic device and a random access memory. Data search and forwarding control are completed by the autonomous controllable programmable logic device. The transmission channel is set in the random access memory, and the random access memory is responsible for data caching.

5. The system according to claim 1, characterized in that The internal network processing unit and the external network processing unit are connected to the dedicated isolation component through a high-speed interconnection interface.

6. The system according to claim 1, characterized in that The internal network processing unit is connected to the internal network service machine through a first network interface, and the external network processing unit is connected to the external network service machine through a second network interface.

7. A multi-channel isolation transmission method based on programmable logic devices, characterized in that: Applied to a multi-channel isolation transmission system including an internal network processing unit, an external network processing unit and a dedicated isolation component, the method includes: Start several worker threads on the intranet processing unit and the extranet processing unit respectively. The number of worker threads is equal to the number of processor cores. Each worker thread is bound to a processor core. Each worker thread supports processing several sessions. When the internal network processing unit and the external network processing unit are initialized, the host side data write address and data read address of the corresponding channel are sent to the dedicated isolation component respectively, and the dedicated isolation component binds the data write address and data read address of each channel with the transmission channel to form a data transfer table; The intranet processing unit or the extranet processing unit sends data to the dedicated isolation component according to business needs; After receiving the data, the dedicated isolation component queries the transmission channel from the data transfer table according to the data write address and writes the data into the transmission channel; when forwarding the data, it searches the data read address corresponding to the transmission channel according to the data transfer table and forwards the data to the corresponding processing unit.

8. The method according to claim 7, characterized in that Before the internal network processing unit and the external network processing unit transmit data, a session connection is also established. The party initiating the session between the internal network processing unit and the external network processing unit is called the current processing unit, and the party receiving the session request is called the other party processing unit. The connection establishment method is as follows: The current processing unit allocates a transmission channel for the session and binds it according to the session establishment request received from the corresponding service machine, and sends the bound session information to the other processing unit according to the allocated transmission channel. The other processing unit generates a session with the corresponding service machine and binds the session with the current transmission channel for reading data. The other processing unit sends a session establishment request to the corresponding service machine according to the session information transmitted by the current processing unit, and transmits the session establishment information to the current processing unit through the bound transmission channel according to the session confirmation information of the corresponding service machine; The current processing unit locates the corresponding session through the bound transmission channel according to the session establishment information and notifies the initiator of the session. At this time, the session establishment between the intranet service machine and the extranet service machine is completed.

9. The method according to claim 7, characterized in that: The process of transmitting data between the intranet processing unit and the extranet processing unit includes: When the intranet business machine actively sends data, the data is pushed to the intranet processing unit. After receiving the data pushed by the intranet business machine, the intranet processing unit writes a DMA request command to the dedicated isolation component according to the bound transmission channel; when the dedicated isolation component detects the DMA command, it stores it in the command buffer area waiting for the execution command, and the dedicated isolation component parses the command to query the transmission channel from the data transfer table and sends a corresponding DMA read operation request. After receiving the DMA request, the intranet processing unit sends the data pushed by the intranet business machine to the transmission channel corresponding to the dedicated isolation component through the high-speed transmission interface, and caches it in the dedicated isolation component; when the dedicated isolation component forwards data, it searches for the data read address corresponding to the transmission channel according to the data transfer table, forwards the data to the external network processing unit, sends a DMA write request to the external network processing unit, and the external network processing unit reads the data cached in the corresponding channel according to the corresponding information and sends it to the external network business machine; When the external network business machine actively sends data, the data is pushed to the external network processing unit. After the external network processing unit receives the data pushed by the external network business machine, it writes a DMA request command to the dedicated isolation component according to the bound transmission channel; when the dedicated isolation component detects the DMA command, it stores it in the command buffer area waiting for the execution command. The dedicated isolation component parses the command and queries the transmission channel from the data transfer table, and sends a corresponding DMA read operation request. After receiving the DMA request, the external network processing unit sends the data pushed by the external network business machine to the transmission channel corresponding to the dedicated isolation component through the high-speed transmission interface, and caches it in the dedicated isolation component; when the dedicated isolation component forwards data, it searches for the data read address corresponding to the transmission channel according to the data transfer table, forwards the data to the internal network processing unit, sends a DMA write request to the internal network processing unit, and the internal network processing unit reads the data cached in the corresponding channel according to the corresponding information, and sends it to the internal network business machine.

10. The method according to claim 7, characterized in that It also includes the connection closing phase: When the intranet service machine actively closes the session, it sends a session closing request to the intranet processing unit. After the intranet processing unit locates the transmission channel bound to the session and sends an internal session closing request to the external network processing unit, the intranet session is closed and the binding relationship between the session and the transmission channel is disconnected. After receiving the session closing request, the external network processing unit locates the corresponding session, disconnects the binding relationship between the session and the transmission channel, and finally closes the session with the external network service machine. When the external network business machine actively closes the session, it sends a session closing request to the external network processing unit. After the external network processing unit locates the transmission channel bound to the session and sends an internal session closing request to the internal network processing unit, it closes the external network session and disconnects the binding relationship between the session and the transmission channel. After receiving the session closing request, the internal network processing unit locates the corresponding session, disconnects the binding relationship between the session and the transmission channel, and finally closes the session with the internal network business machine.