Internal and external network data security exchange platform integration method and system
By building a three-layer network topology structure and configuring security policies, unstructured and structured data exchange, and performing file and database synchronization planning, the problems of single protection strategies, insufficient data synchronization and inflexible topology configuration in the internal and external network data exchange technology are solved, and efficient and secure internal and external network data exchange and synchronization are achieved.
Patent Information
- Application Number
- CN202510101986.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-06-27
AI Technical Summary
The existing internal and external network data exchange technology has a single protection strategy, insufficient synchronization of structured and unstructured data, and inflexible topological configuration, making it difficult to efficiently realize internal and external network data exchange and synchronization while ensuring data security.
Build a three-layer network topology, configure security policies, perform unstructured data exchange and structured data exchange, and perform file synchronization planning and database synchronization planning respectively.
By building a three-layer network topology and configuring security policies, the internal and external network data exchange process is optimized, the system's security and stability are improved, the data flow is efficient and controllable, the integrity and security of unstructured data are effectively guaranteed, the efficiency and reliability of file transmission are improved, and the real-time and consistency of structured data are ensured.
Smart Images

Figure CN120223350A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security exchange, and specifically to an integration method and system for an internal and external network data security exchange platform. Background Art
[0002] With the continuous development of information technology, network security has become a key issue in the current data exchange field. Especially in enterprise information systems, the security issue of internal and external network data exchange has become increasingly prominent. The traditional internal and external network isolation method controls data transmission through a single firewall device. Although it can effectively prevent external attacks, it also exposes the problems of the transmission efficiency and synchronization of unstructured data and structured data. In recent years, with the rapid development of big data, cloud computing, and artificial intelligence technologies, how to improve the efficiency of data exchange while ensuring data security has become a hot issue of concern to domestic and foreign scholars and technical personnel. Various new security protocols and transmission technologies have been gradually proposed, such as multi-level security design based on network topology, synchronous exchange solutions based on databases, etc. These emerging technologies aim to improve the security, stability, and synchronization in the data exchange process and explore technical solutions that not only meet performance requirements but also comply with security standards.
[0003] Although the existing network data exchange technologies have solved the problems of data synchronization and security to a certain extent, there are still obvious deficiencies. On the one hand, most of the existing technologies rely on a single network security strategy and are difficult to cope with increasingly complex network attacks. The existing security strategies mostly adopt firewalls and intrusion detection systems. However, with the continuous update of network attack means, the defense effect of these traditional methods gradually decreases, and they cannot effectively prevent complex attacks during the internal and external network data exchange process. At the same time, the current data exchange often fails to take into account the synchronization of structured and unstructured data, resulting in limited flexibility and scalability of the system. The existing technical solutions usually focus on the exchange and synchronization of structured data and are relatively weak in the processing of unstructured data, failing to effectively meet the diverse needs of business systems during data exchange. Further, the traditional network topology structure cannot dynamically adjust security strategies and is often prone to unforeseen security risks during the data exchange process. Therefore, there is an urgent need for a new method to solve these problems, by flexibly configuring security strategies and supporting the efficient synchronization of unstructured data and structured data, to further enhance the security and reliability of internal and external network data exchange. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the technical problem to be solved by the present invention is that the existing internal and external network data exchange technologies have a single protection strategy, insufficient synchronization of structured and unstructured data, inflexible configuration of the topology structure, and the problem of how to efficiently implement internal and external network data exchange and synchronization while ensuring data security.
[0006] To solve the above technical problems, the present invention provides the following technical solutions: An integration method for an internal and external network data security exchange platform, including constructing a three-layer network topology structure and configuring security policies; performing unstructured data exchange and executing file synchronization planning; performing structured data exchange and executing database synchronization planning.
[0007] As a preferred solution of the integration method for the internal and external network data security exchange platform of the present invention, wherein: the construction of the three-layer network topology structure includes setting up a Demilitarized Zone (DMZ) between the internal and external networks, deploying an FTP server and a cache server in the DMZ, and the three-layer network topology structure includes a core layer, an aggregation layer, and an access layer.
[0008] The core layer includes a core switch and gigabit Ethernet interfaces for high-speed data transmission and redundant connections.
[0009] The aggregation layer connects the core layer and the access layer, and executes policy implementation, security control, and service quality management.
[0010] The access layer provides network connections for internal users and external visitors. The DMZ is located between the aggregation layer and the external network. A firewall is deployed between the DMZ and the external network and between the DMZ and the internal network respectively for two-way security isolation, and the servers providing services to the outside are placed in the DMZ.
[0011] As a preferred solution of the integration method for the internal and external network data security exchange platform of the present invention, wherein: the configuration of the security policy includes configuring an access control list (ACLs) for the FTP service to restrict file transfer only to authorized application systems, configuring ACLs on the three-layer switch to control communication between different VLANs, and setting different ACL rules on the ACL according to work requirements to allow or deny communication between different VLANs, including data transmission and service protocols.
[0012] The application logs in to the three-layer switch through SSH, Console, or Telnet respectively. The ACL rules monitor the traffic situation passing through the ACL through the rules of different VLANs and the IP and port types of the application, and perform control.
[0013] As a preferred solution of the integrated method for the internal and external network data security exchange platform described in the present invention, wherein: the unstructured data exchange is performed by the platform providing a cache server to perform unstructured data exchange in a file synchronization manner according to the internal and external network exchange requirements of unstructured data. The unstructured data includes document files, audio and video files, and office files.
[0014] The internal and external network exchange requirements of unstructured data include the application system uploading or downloading files to or from the cache server of the internal and external network data security exchange platform, and the FTP method is used for uploading or downloading files.
[0015] The synchronization direction of the energy data center is one-way.
[0016] The index requirements of the energy data center include the data file processing throughput and the daily data exchange volume.
[0017] As a preferred solution of the integrated method for the internal and external network data security exchange platform described in the present invention, wherein: the execution of the file synchronization plan includes determining the files to be synchronized according to the service requirements and setting the synchronization rules.
[0018] Classify the historical data, classify it respectively from the source, access frequency and data life cycle, and formulate real-time synchronization, timed synchronization and low-peak batch synchronization to keep the data of each server synchronized.
[0019] Perform hash verification and digital signature on the uploaded data, confirm the consistency of the file before and after synchronization through the hash value, and verify the file source and integrity through the digital signature.
[0020] As a preferred solution of the integrated method for the internal and external network data security exchange platform described in the present invention, wherein: the structured data exchange is performed by the platform providing a cache server to perform structured data exchange in a database synchronization manner according to the internal and external network exchange requirements of structured data.
[0021] The internal and external network exchange requirements of structured data include the energy data center writing or reading data to or from the cache server of the internal and external network data security exchange platform by itself. The protocol is standard sql. The energy data center is the source of the data. Determine the data content and target to be written, and sort out and prepare the structured data related to energy according to the service requirements.
[0022] The energy data center uses the standard SQL protocol to connect to the cache server of the internal and external network data security exchange platform. After the connection is established, the energy data center writes the data to the cache server.
[0023] When the energy data center needs to read data, it uses the standard SQL protocol to connect to the cache server. After a successful connection, the energy data center sends a read request to the cache server, specifying the data range and conditions to be read. The cache server retrieves the qualified data from the stored data according to the request and returns it to the energy data center.
[0024] As a preferred solution of the integrated method for the internal and external network data security exchange platform of the present invention, wherein: the execution of the database synchronization plan includes synchronizing the database synchronization support tables and performing field synchronization. Based on the tables or fields determined by the energy data center and the internal and external network exchange platform that need to be synchronized, the database log file is parsed to obtain the user's change operations on the database, and the incremental data in the database is captured by analyzing the change operations.
[0025] The performance indicators of the energy data center include throughput, the number of database-to-database exchange records, and the number of synchronized data tables.
[0026] Another object of the present invention is to provide an integrated system for the internal and external network data security exchange platform, which can solve the problems of low database synchronization efficiency and inaccurate data synchronization in the current structured data exchange technology by performing structured data exchange and executing the database synchronization plan.
[0027] As a preferred solution of the integrated system for the internal and external network data security exchange platform of the present invention, wherein: it includes a security policy configuration module, a file synchronization module, and a database synchronization module.
[0028] The security policy configuration module is used to construct a three-layer network topology structure and configure security policies; the file synchronization module is used to perform unstructured data exchange and execute the file synchronization plan; the database synchronization module is used to perform structured data exchange and execute the database synchronization plan.
[0029] A computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it realizes the steps of the integrated method for the internal and external network data security exchange platform.
[0030] A computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, it realizes the steps of the integrated method for the internal and external network data security exchange platform.
[0031] Advantages of the present invention: The integrated method of the internal and external network data security exchange platform provided by the present invention constructs a three-layer network topology structure, configures security policies, and optimizes the data exchange process between the internal and external networks. It not only improves the security and stability of the system, but also ensures the efficiency and controllability of the data flow. It performs unstructured data exchange, executes file synchronization planning, effectively guarantees the integrity and security of unstructured data, improves the efficiency and reliability of file transmission, reduces the risks caused by data transmission errors, improves the efficiency and accuracy of business operations, performs structured data exchange, executes database synchronization planning, ensures the real-time nature and consistency of energy data, not only optimizes the data transmission process, but also improves the performance of the system. The present invention achieves better effects in terms of improving the security of internal and external network data exchange, optimizing data synchronization efficiency, and enhancing system reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0033] Figure 1 It is the overall flowchart of an integrated method for an internal and external network data security exchange platform provided by the first embodiment of the present invention.
[0034] Figure 2 It is the three-layer network topology diagram of an integrated method for an internal and external network data security exchange platform provided by the first embodiment of the present invention.
[0035] Figure 3 It is the unstructured data exchange flowchart of an integrated method for an internal and external network data security exchange platform provided by the first embodiment of the present invention.
[0036] Figure 4 It is the structured data exchange flowchart of an integrated method for an internal and external network data security exchange platform provided by the first embodiment of the present invention.
[0037] Figure 5 It is the overall flowchart of an integrated system for an internal and external network data security exchange platform provided by the third embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0039] Example 1. Refer to Figures 1 - 4 , which is an embodiment of the present invention, and provides an integrated method for an internal and external network data security exchange platform, including:
[0040] S1: Construct a three-layer network topology structure and configure security policies.
[0041] Furthermore, constructing a three-layer network topology structure includes setting up a demilitarized zone (DMZ) between the internal and external networks, deploying an FTP server and a cache server in the DMZ, and the three-layer network topology structure includes a core layer, an aggregation layer, and an access layer.
[0042] Refer to Figure 2 , the core layer includes a core switch and gigabit Ethernet interfaces for high-speed data transmission and redundant connections; the aggregation layer connects the core layer and the access layer, performs policy implementation (such as VLAN division, route summarization), security control, and quality of service (QoS) management; the access layer provides network connections for internal users and external visitors. The DMZ is located between the aggregation layer and the external network, and a firewall is deployed between the DMZ and the external network and between the DMZ and the internal network for two-way security isolation. Servers providing services to the outside (such as Web servers, mail servers, FTP servers, DNS servers, etc.) are placed in the DMZ.
[0043] It should be noted that configuring security policies includes configuring access control lists (ACLs) for the FTP service to restrict file transfer only to authorized application systems, configuring ACLs on the three-layer switch to control communication between different VLANs, and setting different ACL rules on the ACL according to work requirements to allow or deny communication between different VLANs, including data transmission and service protocols.
[0044] The application logs in to the three-layer switch through SSH, Console, or Telnet respectively. The ACL rules monitor the traffic situation passing through the ACL through the rules of different VLANs and the IP and port types of the application and perform control.
[0045] It should also be noted that the DMZ (Demilitarized Zone) is an important part of the network security architecture. It is located between the internal network and the external network. The DMZ is used to place servers that provide services to the outside, such as Web servers, mail servers, etc. By means of a firewall, the traffic between the internal network and the external network is isolated, enhancing the security of the internal and external networks and preventing direct external attacks from entering the internal network; QoS (Quality of Service) is a network management technology used to provide different priorities for different types of traffic in a computer network to ensure network stability and efficiency. Especially in the case of limited bandwidth, by setting QoS policies, network administrators can control the bandwidth of specific applications or services, giving priority to delay-sensitive data streams (such as voice and video), thereby improving the quality and experience of data transmission and helping to achieve better traffic management. When multiple network services are running in parallel, it ensures the performance of critical applications; A Web server is a computer program or hardware that provides Web pages and other related resources (such as pictures, videos, and files). The Web server receives requests from clients (such as Web browsers) according to the HTTP (HyperText Transfer Protocol) and responds to the requests, transmitting data to the clients. The Web server is used to host static content (such as HTML files) and dynamic content (generated by server-side scripts, such as PHP, ASP, etc.); The DNS server (Domain Name System Server) is a system that converts domain names into IP addresses. When a user enters a domain name in a browser, the DNS server resolves the domain name into the corresponding IP address, enabling the user to access the corresponding web page or service. DNS is one of the infrastructures of the Internet, ensuring that users can access various resources globally through friendly domain names; FTP (File Transfer Protocol) is used to transfer files between computers. FTP uploads and downloads files through the client-server method and is used to exchange large files or a large number of files; ACLs (Access Control Lists) are used to manage traffic and access permissions on network devices (such as routers, switches). By configuring ACLs, it is possible to specify which users or devices can access network resources and define the types of access allowed or denied to enhance system security; VLAN (Virtual Local Area Network technology) is used to divide logical network segments on the physical network infrastructure. Through VLAN, devices in the same physical network are grouped to form multiple local area networks logically, thereby improving network security, manageability, and scalability;SSH (Secure Shell, a network protocol) is used for secure remote login and data transfer in an insecure network environment. SSH provides an encrypted communication method to ensure the confidentiality and integrity of data transfer; Console refers to the physical interface or command-line interface for managing devices, which is used to directly interact with a computer or network device. In a network device, the Console port is used for device management through a serial connection, which is commonly used in network configuration, troubleshooting, and other operations; Telnet is a protocol used for remote login and management of network devices.
[0046] It should also be noted that by constructing a three-layer network topology and configuring security policies, efficient isolation between the internal and external networks and fine-grained management of data flows have been achieved. The three-layer network topology includes a core layer, an aggregation layer, and an access layer. The core layer provides high-speed data transfer and redundant connections through core switches and gigabit Ethernet interfaces, ensuring the high availability and stability of the entire system; the aggregation layer is responsible for connecting the core layer and the access layer, implementing policy enforcement and security control, thereby optimizing the routing and management of data flows, while the access layer provides access for different users, ensuring that internal and external devices can efficiently and securely access the required resources; particularly importantly, a demilitarized zone (DMZ) is set up between the aggregation layer and the external network, and an FTP server and a cache server are deployed in the DMZ, which not only ensures the security of external services but also prevents external attacks from directly affecting the internal network. By deploying firewalls between the DMZ and the internal and external networks and cooperating with strategies such as access control lists (ACLs), the isolation of the network is further enhanced, potential attack paths are prevented, internal network data leakage and malicious intrusion are effectively prevented, and a solid security protection layer is provided, which not only enhances the anti-interference ability of the system but also optimizes the data flow control in different network environments, can adapt to changing security requirements, and ensures the secure transmission and access control of data in a complex internal and external network environment.
[0047] S2: Perform unstructured data exchange and execute file synchronization planning.
[0048] Furthermore, performing unstructured data exchange includes providing a cache server by the platform for unstructured data exchange in the form of file synchronization according to the internal and external network exchange requirements of unstructured data. Unstructured data includes document files, audio and video files, and office files. The unstructured data exchange process refers to Figure 3 .
[0049] The internal and external network exchange requirements of unstructured data include the application system uploading or downloading files to or from the cache server of the internal and external network data security exchange platform, and the file uploading or downloading adopts the FTP method.
[0050] The synchronization direction of the energy data center is one-way.
[0051] The index requirements of the energy data center include a data file processing throughput of 560 Mbps and a daily data exchange volume of 100 (unit: M).
[0052] It should be noted that implementing the file synchronization plan includes determining the files to be synchronized according to business requirements and setting synchronization rules.
[0053] Classify the historical data, classify it respectively from the source, access frequency, and data life cycle (mainly the update frequency), and formulate real-time synchronization, scheduled synchronization, and off-peak batch synchronization to keep the data of each server synchronized.
[0054] Upload the data for hash verification and digital signature. Confirm the consistency of the files before and after synchronization through the hash value, and verify the file source and integrity through the digital signature.
[0055] It should also be noted that for unstructured data exchange, implementing the file synchronization plan provides an efficient data exchange platform through the cache server, enabling the application system to securely upload or download data to the platform via FTP. This solution not only ensures the secure exchange of data but also improves the transmission speed and stability when the system processes a large amount of unstructured data; when implementing the file synchronization plan, according to business requirements and the data life cycle, the files to be synchronized are determined and different synchronization rules are set, such as real-time synchronization, scheduled synchronization, and off-peak batch synchronization. This flexible synchronization strategy can dynamically adjust the synchronization method according to the characteristics of the data and business requirements, thus maximizing the performance of the system, avoiding data transmission pressure during peak hours, and ensuring the stable operation of the system; the hash verification and digital signature technologies are adopted to ensure the consistency and integrity of the data during the synchronization process. The hash value is used to verify the consistency of the files before and after synchronization, while the digital signature verifies the file source and integrity, avoiding data tampering or loss during transmission, further improving the reliability of data exchange, and at the same time improving the efficiency and accuracy of data transmission, enhancing the stability and controllability of the system in a complex environment.
[0056] S3: Conduct structured data exchange and implement the database synchronization plan.
[0057] Furthermore, conducting structured data exchange includes providing a cache server by the platform for structured data exchange in the form of database synchronization according to the structured data internal and external network exchange requirements. The structured data exchange process refers to Figure 4 .
[0058] The structured data exchange requirements between the internal and external networks include that the energy data center writes or reads data to / from the cache server of the internal and external network data security exchange platform by itself. The protocol is standard SQL. The energy data center is the data source, determines the data content and target to be written, and sorts and prepares the structured data related to energy according to business requirements.
[0059] The energy data center uses the standard SQL protocol to connect to the cache server of the internal and external network data security exchange platform. After the connection is established, the energy data center writes data to the cache server.
[0060] When the energy data center needs to read data, it uses the standard SQL protocol to connect to the cache server. After the connection is successful, the energy data center sends a read request to the cache server, specifying the data range and conditions to be read. The cache server retrieves the qualified data from the stored data according to the request and returns it to the energy data center.
[0061] It should be noted that implementing the database synchronization plan includes synchronizing the database synchronization support tables and performing field synchronization. Based on the tables or fields to be synchronized determined by the energy data center and the internal and external network exchange platform, the database log file is parsed to obtain the user's change operations on the database, and the incremental data in the database is captured by analyzing the change operations.
[0062] The performance indicators of the energy data center include a throughput of 560 Mbps, the number of database-to-database exchange records (records / second), and the number of synchronized data tables (sheets).
[0063] It should also be noted that SQL (Structured Query Language), the standard query language for database management and operations, is the core tool for processing structured data and is used for querying, inserting, updating, and deleting operations on the database. Through the SQL language, users manage the data in the relational database, enabling seamless synchronous exchange of structured data, ensuring the high efficiency and accuracy of data transmission; the database synchronization plan further improves the accuracy and real-time performance of data exchange, avoids problems such as duplicate data or data lag that may occur in traditional synchronization technologies, supports field synchronization, ensures that each field in the database table can be synchronized to the target system in a timely manner, thus achieving high-precision database synchronization; through precise data synchronization and incremental data capture technologies, the data transmission efficiency between the energy data center and the internal and external network data platforms is improved, and the consistency and accuracy of the data are ensured, supporting large-scale and high-throughput data exchange requirements. Through precise database synchronization planning, the synchronization delay and data consistency problems in traditional structured data exchange technologies are successfully solved, improving the real-time performance, accuracy, and efficiency of data exchange, and providing strong technical support for complex business data exchange.
[0064] Embodiment 2, an embodiment of the present invention, provides an integrated method for the internal and external network data security exchange platform. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0065] First of all, a typical three-layer network topology was constructed in the experiment, including a core layer, an aggregation layer and an access layer; the core layer mainly includes high-speed switches and Gigabit Ethernet interfaces, which are responsible for realizing high-speed data transmission and redundant connections to ensure the high availability of the network. The aggregation layer is used to connect the core layer and the access layer, implement security policies and manage traffic to avoid unnecessary traffic interference. The access layer provides network connections for internal and external users to ensure the normal operation of various data exchanges and applications; a demilitarized zone (DMZ) was set between the core layer and the access layer, and an FTP server and a cache server were deployed in the demilitarized zone to specifically handle data exchange requests from the external to the internal or from the internal to the external. In order to enhance the security of the network and prevent external attacks, all traffic between the internal and external networks is isolated by a firewall; the experiment managed and optimized the communication of different VLANs. In order to improve security and traffic management efficiency, ACLs (Access Control Lists) policies were adopted. By configuring different ACL rules, the access permissions between different VLANs were restricted, and the transmission direction of the data flow was controlled. Specifically, only authorized application systems can upload or download files through the FTP service. On the three-layer switch, the communication between each VLAN was finely controlled through ACL rules to ensure the security of data exchange; in the process of unstructured data exchange, the platform synchronizes files through the cache server. Different from the traditional file exchange method, in the process of file upload and download, the FTP protocol is combined with hash verification and digital signature to ensure the integrity and consistency of file synchronization. During the file synchronization process, according to the source, access frequency and life cycle of the data, three different synchronization modes of real-time synchronization, scheduled synchronization and off-peak batch synchronization are set to optimize the efficiency of data exchange and ensure data consistency under high load conditions; in the process of structured data exchange, the experiment designed a database synchronization process, and data exchange was carried out based on the standard SQL protocol. The energy data center in the experiment exchanged structured data with the internal and external network data security exchange platform through the standard SQL protocol. During this process, all data tables and fields that need to be synchronized were accurately configured to ensure data consistency and real-time performance. At the same time, by parsing the database log file, incremental data was captured, avoiding the problems of repeated synchronization and delay existing in the traditional database synchronization method, thus improving the synchronization efficiency; according to the experimental results, the present invention has advantages and creativity in improving network performance, data synchronization efficiency, transmission rate, synchronization accuracy, reducing error rate and reducing system downtime.
[0066] Example 3. Referring to Figure 5 , an embodiment of the present invention provides an integrated system for secure data exchange platform between internal and external networks, including a security policy configuration module, a file synchronization module, and a database synchronization module.
[0067] Among them, the security policy configuration module is used to construct a three-layer network topology structure and configure security policies; the file synchronization module is used for unstructured data exchange and execute file synchronization planning; the database synchronization module is used for structured data exchange and execute database synchronization planning.
[0068] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0069] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or used in combination with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0070] More specific examples (a non-exhaustive list) of computer-readable media include the following: electrical connections (electronic devices) having one or more wirings, portable computer diskettes (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber devices, and portable compact disc read-only memory (CDROM). Additionally, the computer-readable media can even be paper or other suitable media on which a program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or otherwise processing it as appropriate, and then storing it in a computer memory.
[0071] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, the multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc. It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
[0072] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. A method for integrating an intranet and extranet data security exchange platform, characterized in that: include: Build a three-layer network topology and configure security policies; Conduct unstructured data exchange and execute file synchronization planning; Perform structured data exchange and execute database synchronization planning.
2. The method for integrating an intranet and extranet data security exchange platform according to claim 1, characterized in that: The construction of the three-layer network topology structure includes setting up a demilitarized zone (DMZ) between the internal and external networks, deploying an FTP server and a cache server in the demilitarized zone, and the three-layer network topology structure includes a core layer, a convergence layer, and an access layer; The core layer includes core switches and Gigabit Ethernet interfaces for high-speed data transmission and redundant connections; The aggregation layer connects the core layer to the access layer, performs policy implementation, security control, and service quality management; The access layer provides network connections for internal users and external visitors. The DMZ is located between the aggregation layer and the external network. A firewall is deployed between the DMZ and the external network and between the DMZ and the internal network for two-way security isolation. Servers that provide services to the outside world are placed in the DMZ.
3. The method for integrating an intranet and extranet data security exchange platform as claimed in claim 2, characterized in that: The configuration of security policies includes configuring access control lists (ACLs) for FTP services to restrict file transfer to authorized application systems only, configuring ACLs on layer 3 switches to control communication between different VLANs, and setting different ACL rules on ACLs according to work requirements to allow or deny communication between different VLANs, including data transmission and service protocols; The application logs in to the Layer 3 switch through SSH, Console or Telnet. The ACL rules monitor and control the traffic passing through the ACL through different VLAN rules, application IP and port types.
4. The method for integrating an intranet and extranet data security exchange platform as claimed in claim 3, characterized in that: The unstructured data exchange includes the platform providing a cache server to exchange unstructured data in a file synchronization manner according to the unstructured data intranet and extranet exchange requirements. The unstructured data includes document files, audio and video files, and office files. The demand for unstructured data exchange between the intranet and the intranet includes the application system uploading or downloading files to the cache server of the intranet and the intranet data security exchange platform, and the uploading or downloading of files adopts FTP; The synchronization direction of the energy data center is unidirectional; The energy data center indicator requirements include data file processing throughput and daily data exchange volume.
5. The method for integrating an intranet and extranet data security exchange platform as claimed in claim 4, characterized in that: The execution file synchronization plan includes determining the files to be synchronized according to business needs and setting synchronization rules; Classify historical data based on source, access frequency, and data life cycle, formulate real-time synchronization, scheduled synchronization, and off-peak batch synchronization to keep data synchronization on each server; The uploaded data is hash-checked and digitally signed, the consistency of the files before and after synchronization is confirmed by the hash value, and the source and integrity of the files are verified by the digital signature.
6. The method for integrating an intranet and extranet data security exchange platform as claimed in claim 5, characterized in that: The structured data exchange includes the platform providing a cache server to exchange structured data in a database synchronization manner according to the structured data intranet and extranet exchange requirements; The demand for structured data exchange between the intranet and the intranet includes the energy data center writing or reading data to or from the cache server of the intranet and the intranet data security exchange platform. The protocol is standard SQL. The energy data center is the source of the data. It determines the content and target of the data to be written, and organizes and prepares the energy-related structured data according to business needs. The energy data center uses the standard SQL protocol to connect to the cache server of the intranet and extranet data security exchange platform. After the connection is established, the energy data center writes the data to the cache server; When the energy data center needs to read data, it uses the standard SQL protocol to connect to the cache server. After the connection is successful, the energy data center sends a read request to the cache server, specifying the data range and conditions to be read. The cache server retrieves the data that meets the conditions from the stored data based on the request and returns it to the energy data center.
7. The method for integrating an intranet and extranet data security exchange platform as claimed in claim 6, characterized in that: The execution of database synchronization planning includes synchronizing the database synchronization support table and field synchronization, parsing the database log file based on the tables or fields that need to be synchronized determined by the energy data center and the internal and external network exchange platform, obtaining the user's change operations on the database, and capturing the incremental data in the database by analyzing the change operations; Energy data center performance indicators include throughput, number of database-to-database exchange records, and number of synchronized data tables.
8. A system using the method for integrating an intranet and extranet data security exchange platform as claimed in any one of claims 1 to 7, characterized in that: Including security policy configuration module, file synchronization module, and database synchronization module; The security policy configuration module is used to build a three-layer network topology and configure security policies; The file synchronization module is used to exchange unstructured data and execute file synchronization planning; The database synchronization module is used to perform structured data exchange and execute database synchronization planning.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method for integrating an intranet and extranet data security exchange platform according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for integrating an intranet and extranet data security exchange platform according to any one of claims 1 to 7 are implemented.