DMZ-based unified network proxy service external data access method
By adopting an external data access method based on DMZ unified network proxy service in banking business, the security, efficiency and maintenance cost problems during external data access are solved, and higher security, efficiency and maintainability are achieved.
Patent Information
- Application Number
- CN202510333415.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art has serious security problems, low access efficiency, and high daily program maintenance costs when accessing external data in banking business.
Using an external data access method based on DMZ unified network proxy service, the security, efficiency and maintainability of external data are improved by deploying a unified network proxy server at the DMZ network layer. Specific steps include determining requirements and environmental configuration, functional development and process design, agent service deployment and testing, and system operation stage.
Through the multiple security mechanisms of the DMZ area and network proxy server, the security of the bank's internal network and external data access is significantly improved; the data caching module improves access efficiency; and the unified network proxy model reduces development and maintenance costs.
Smart Images

Figure CN120200797A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of digitalization of banking services, and particularly to an external data access method based on a DMZ unified network proxy service. Background Art
[0002] With the continuous expansion and digital transformation of commercial banking services, data, as one of the important production factors, banks need to obtain various data from the outside to support important business operations such as risk management, market analysis, customer marketing, and regulatory management. However, directly connecting to the external network to obtain data poses huge security risks, which may lead to the leakage of sensitive information within the bank and malicious attacks from the external network. Traditional security measures such as firewalls are insufficient in balancing the flexibility and security of external data access. The DMZ network, as a security strategy for isolating the internal and external networks, well meets the security requirements of banks for external data access.
[0003] External data, as an important and essential part of the big data field, data security is crucial for daily data interaction, and the DMZ network can well isolate the network and meet the requirements of data security. Deploying a unified network proxy at the DMZ network layer can better monitor and manage data interaction.
[0004] External data has characteristics such as multiple data sources, multiple data formats, and multiple data transmission methods. Currently, for different data sources, there are various access methods due to different access forms of data vendors. Each vendor or data source has a separate set of programs for data access.
[0005] Existing technical drawbacks:
[0006] 1) There are serious security problems. Unisolated network access may be subject to external network attacks;
[0007] 2) The access efficiency is low. Deploying multiple modules occupies a large amount of system and network resources, resulting in a decline in interaction performance;
[0008] 3) The daily program maintenance cost is high, the code is redundant, and there are problems such as duplicate development. Summary of the Invention
[0009] In view of the above problems, the present invention is proposed to provide an external data access method based on a DMZ unified network proxy service that overcomes the above problems or at least partially solves the above problems.
[0010] According to one aspect of the present invention, there is provided an external data access method based on a DMZ unified network proxy service, and the data access method includes:
[0011] Determine requirements and environment configuration;
[0012] Conduct functional development and process design;
[0013] Deploy the proxy service to the corresponding server as needed and test the service itself;
[0014] Enter the system operation stage.
[0015] Optionally, the determination of requirements and environment configuration specifically includes:
[0016] Apply for the software and hardware environment related to the deployment service;
[0017] Collect the data access requirements of each department to configure the permission table, and configure the routing table and access permission table according to different data vendors.
[0018] Optionally, the software and hardware environment specifically includes:
[0019] Host cluster, network firewall, network segment, network policy opening;
[0020] Include the whitelist for external network access and the load policy environment information for the internal network.
[0021] Optionally, the conduct of functional development and process design specifically includes:
[0022] Client request, the internal client of the bank initiates a request to access external data and sends the request to the network proxy server in the DMZ area;
[0023] Identity authentication and access control. The security authentication module of the network proxy server first authenticates the client. If the authentication is passed, the access control module checks whether the client has the permission to access the requested data according to the preset policy. If the permission is met, the request proceeds to the next step; if the authentication fails or there is no permission, the proxy server returns a denial of access message to the client;
[0024] Request forwarding and caching processing. For requests that pass authentication and access control, the request forwarding module forwards them to the external data server; if there is a valid cached copy of the requested data in the data caching module and the cache has not expired, the data is directly retrieved from the cache and returned to the client; otherwise, wait for the response from the external data server;
[0025] Response processing. When the response from the external data server is received, the proxy server returns the response data to the client;
[0026] If the data meets the caching conditions, the data caching module caches the data for subsequent use of the same request;
[0027] Encrypt the data during the entire data transmission process.
[0028] Optionally, the information of the access request includes the target external data server address, the request data type, and the content of the access protocol.
[0029] Optionally, the testing of the service itself specifically includes:
[0030] Function line testing to test whether various business scenarios can meet the requirements;
[0031] Performance testing to test the stability of the service in high-concurrency business scenarios;
[0032] Security testing to test the security of the service through security testing methods such as penetration testing, injection testing, and brute-force testing;
[0033] Perform corresponding repairs and optimizations according to the problems found in the testing.
[0034] Optionally, the entry into the system operation stage specifically includes:
[0035] When the in-house business system requests to access external enterprise-related data, the client generates a request containing the target address, request data type, and access protocol, and sends it to the network proxy server;
[0036] The security authentication module of the network proxy server performs identity authentication by checking the certificate and other authentication information provided by the client. After successful authentication, the access control module checks whether the business department where it is located has the permission to access enterprise industrial and commercial data. If so, the request is forwarded;
[0037] If there is a valid cached copy of the enterprise industrial and commercial data in the data cache module, the cached data is directly returned to the client; otherwise, the request forwarding module forwards the request to the external data vendor Zhongshu server;
[0038] After the external server responds, the proxy server returns the data to the client and caches the data;
[0039] Throughout the process, the transmission of data between the DMZ and the internal network, and between the DMZ and the external network is encrypted.
[0040] A method for accessing external data based on a DMZ unified network proxy service provided by the present invention, the data access method includes: determining requirements and environment configuration; performing function development and process design; deploying the proxy service to the corresponding server as needed, testing the service itself; entering the system operation stage. The unified network proxy mode architecture design improves operation and maintenance monitoring; the unified permission and security control improve the security of the system; the three-layer network architecture design provides better network isolation.
[0041] The above description is only an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention, it can be implemented according to the content of the specification. And in order to make the above and other objects, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are hereinafter specifically exemplified. Brief Description of the Drawings
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0043] Figure 1 The network topology diagram of a method for accessing external data based on a DMZ unified network proxy service provided by an embodiment of the present invention;
[0044] Figure 2 The architecture diagram of a method for accessing external data based on a DMZ unified network proxy service provided by an embodiment of the present invention;
[0045] Figure 3 The timing diagram of a method for accessing external data based on a DMZ unified network proxy service provided by an embodiment of the present invention. Detailed Embodiments
[0046] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0047] The terms "including" and "having" and any variations thereof in the description of the embodiments, claims and drawings of the present invention are intended to cover non-exclusive inclusion. For example, including a series of steps or units.
[0048] The technical solutions of the present invention will be further described in detail below with reference to the drawings and embodiments.
[0049] A method for accessing external data based on a DMZ unified network proxy service includes the following modules:
[0050] The network proxy server, as the core component, has multiple functional modules, including a request forwarding module, a data caching module, a security authentication module, and an access control module.
[0051] Request forwarding module: Receives access requests for external data from the business systems within the bank's internal network. Based on the target address and protocol type of the request, it forwards the request to the corresponding data server on the external network. Meanwhile, it receives the response from the external data server and passes the response back to the internal client.
[0052] Data caching module: Adopts a caching mechanism for frequently accessed external data. When the same request comes again, the data can be directly obtained from the cache, reducing repeated requests to the external network and improving access efficiency.
[0053] Security authentication module: Conducts identity authentication for access from the bank's internal network. Multiple authentication methods can be adopted, such as authentication methods based on combinations of certificates, usernames, and passwords. Only requests that pass the authentication will be processed, effectively controlling the access of the internal network to the external network.
[0054] Access control module: Controls the external data resources requested for access by the internal network business systems according to the preset access policies. The access policies can be based on factors such as the client's IP address and department to determine the accessible external data scope and permissions. For example, the inclusive business department can access specific corporate customer data, while other departments do not have this permission.
[0055] Such as Figures 1-3 As shown, a method for accessing external data based on DMZ network proxy services includes:
[0056] Determine requirements and environment configuration:
[0057] Firstly, it is necessary to apply for the deployment of software and hardware environments related to the service, including host clusters, network firewalls, network segments, and network policy activation. This includes environmental information such as white lists for external network access and load balancing policies for the internal network. Collect the data access requirements of each department to configure the permission table, and configure the routing table and access permission table according to different data vendors.
[0058] Function development and process design:
[0059] Client request: The internal client of the bank initiates an access request for external data. The request information includes the address of the target external data server, the type of requested data, the access protocol, etc., and sends the request to the network proxy server in the DMZ area.
[0060] Identity authentication and access control: The security authentication module of the network proxy server first conducts identity authentication for the client. If the authentication is passed, the access control module checks whether the client has the permission to access the requested data according to the preset policy. If the permissions are met, the request proceeds to the next step of processing; if the authentication fails or there is no permission, the proxy server returns a denied access message to the client.
[0061] Request forwarding and caching processing. For requests that pass authentication and access control, the request forwarding module forwards them to an external data server. If there is a valid cached copy of the requested data in the data caching module and the cache has not expired, the data is directly retrieved from the cache and returned to the client; otherwise, it waits for the response from the external data server.
[0062] Response processing. When the response from the external data server is received, the proxy server returns the response data to the client. At the same time, if the data meets the caching conditions, the data caching module caches it for subsequent use in the same request. During the entire data transmission process, the data is encrypted to ensure its confidentiality during transmission.
[0063] Testing and optimization:
[0064] Deploy the proxy service to the corresponding server as needed and test the service itself. This includes functional testing to check whether various business scenarios can meet the requirements; performance testing to test the stability of the service in high-concurrency business scenarios; security testing to test the security of the service through security testing methods such as penetration testing, injection testing, and brute-force testing; and perform corresponding repairs and optimizations based on the problems found in the testing, such as improving the high concurrency of the system through the caching mechanism and improving the system security through permission control, access control, and network whitelists.
[0065] System operation stage:
[0066] When the in-house business system (acting as a client) requests to access external enterprise-related data, the client generates a request containing the target address (the address of the Zhongshu manufacturer's server), the type of requested data (such as the enterprise's industrial and commercial data, credit data), and the access protocol (such as HTTPS), and sends it to the network proxy server.
[0067] The security authentication module of the network proxy server performs identity authentication by checking the certificate and other authentication information provided by the client. After successful authentication, the access control module checks whether the business department has the permission to access the enterprise's industrial and commercial data. If so, the request is forwarded.
[0068] If there is a valid cached copy of the enterprise's industrial and commercial data in the data caching module, the cached data is directly returned to the client; otherwise, the request forwarding module forwards the request to the external data manufacturer's Zhongshu server.
[0069] After the external server responds, the proxy server returns the data to the client and caches the data. Throughout the process, the data transmission between the DMZ and the internal network, and between the DMZ and the external network is encrypted.
[0070] The present invention aims to propose a method based on a unified network proxy module in the DMZ. By writing a general network proxy module and combining configuration-based development, the method realizes unified network access to multiple external data sources. The present invention supports multiple network protocols such as HTTP, HTTPS, and SFTP, meets complex and changing business requirements, significantly improves the interaction efficiency, and reduces the development and maintenance costs.
[0071] 1) Enhanced security: Through multiple security mechanisms in the DMZ area and the network proxy server, including identity authentication, access control, and data encryption, it effectively prevents external malicious attacks and internal illegal access, and ensures the security of the bank's internal network and external data access.
[0072] 2) Improved access efficiency: The data caching module can reduce repeated requests for external data, accelerate the data access speed, improve the efficiency of the bank's internal business system in obtaining external data, and thus enhance the timeliness and accuracy of banking business processing.
[0073] 3) Reduced development and maintenance costs: By developing and deploying a unified network proxy module, all network interactions of external data can be realized through this module, greatly reducing the development cycle and daily maintenance costs.
[0074] Beneficial effects: The unified network proxy mode architecture design improves operation and maintenance monitoring; the unified permission and security control improve the security of the system; the three-layer network architecture design provides better network isolation.
[0075] The above specific implementation manners further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are only the specific implementation manners of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for accessing external data based on a DMZ unified network proxy service, characterized in that: The data access method comprises: Determine requirements and environment configuration; Carry out function development and process design; Deploy the proxy service to the corresponding server as needed and test the service itself; Enter the system operation phase.
2. According to claim 1, a method for accessing external data based on DMZ unified network proxy service, characterized in that: The determination of requirements and environment configuration specifically includes: You need to apply for the software and hardware environment related to the deployment service; Collect the data access requirements of each department and configure the permission table, and configure the routing table and access permission table according to different data vendors.
3. The external data access method based on DMZ unified network proxy service according to claim 2 is characterized in that: The software and hardware environment specifically includes: Host cluster, network firewall, network segment, and network policy activation; Including the whitelist for external network access and the load policy environment information of the internal network.
4. The external data access method based on DMZ unified network proxy service according to claim 1, characterized in that: The functional development and process design specifically include: Client request: The internal client of the bank initiates a request to access external data and sends the request to the network proxy server in the DMZ area; Identity authentication and access control,The security authentication module of the network proxy server first authenticates the client. If the authentication is successful, the access control module checks whether the client has the authority to access the requested data according to the preset policy. If the authority meets the requirements, the request will proceed to the next step of processing; if the authentication fails or there is no authority, the proxy server returns a denial of access information to the client; Request forwarding and cache processing: For requests that pass authentication and access control, the request forwarding module forwards them to the external data server; if there is a valid cache copy of the requested data in the data cache module and the cache has not expired, the data is directly extracted from the cache and returned to the client; otherwise, wait for the response of the external data server; Response processing: after receiving the response from the external data server, the proxy server returns the response data to the client; If the data meets the cache conditions, the data cache module caches the data for subsequent identical requests; The data is encrypted during the entire data transmission process.
5. The external data access method based on DMZ unified network proxy service according to claim 4 is characterized in that: The information of the access request includes the target external data server address, the requested data type, and the content of the access protocol.
6. The external data access method based on DMZ unified network proxy service according to claim 1 is characterized in that: The testing of the service itself specifically includes: Functional testing to test whether various business scenarios can meet the requirements; Performance testing, testing the stability of services in high-concurrency business scenarios; Security testing: testing the security of services through penetration testing, injection testing, and brute force testing security testing methods; Make corresponding repairs and optimizations based on the problems found in the test.
7. The external data access method based on DMZ unified network proxy service according to claim 1, characterized in that: The entering the system operation stage specifically includes: When the in-house business system requests access to external enterprise-related data, the client generates a request containing the target address, requested data type, and access protocol, and sends it to the network proxy server; The security authentication module of the network proxy server performs identity authentication by checking the certificate and other authentication information provided by the client. After the authentication is passed, the access control module checks whether the business department has the authority to access the enterprise's industrial and commercial data. If so, the request is forwarded; If there is a valid cached copy of the enterprise's industrial and commercial data in the data cache module, the cached data will be directly returned to the client; otherwise, the request forwarding module will forward the request to the external data vendor's central server; After the external server responds, the proxy server returns the data to the client and caches the data; During the entire process, data transmission between the DMZ and the internal network, and between the DMZ and the external network is encrypted.