Cross-network one-way file transmission method

Through the combined design of layer 2 switch port mirroring, TAP equipment and Modem, one-way file transmission across networks is realized, solving the security risks and reverse penetration problems of cross-network transmission, and ensuring the security and reliability of transmission.

CN120263783APending Publication Date: 2025-07-04CHINESE PEOPLES LIBERATION ARMY UNIT 63626
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510606642.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing cross-network one-way file transmission method has security risks, is prone to reverse penetration and limited transmission bandwidth.

Method used

The logical one-way and physical one-way design combined with Layer 2 switch port mirroring, TAP devices and Modem is adopted. Traffic replication is performed through switch port mirroring technology and TAP devices, and the physical one-way connection of Modem is used and packet capture is combined with Wireshark software to realize the one-way transmission of files from one physically isolated network to another network.

Benefits of technology

It realizes one-way transmission of files from one physically isolated network to another network, solves the risk of reverse penetration, ensures the security and reliability of transmission, and is suitable for multiple operating system platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263783A_ABST
    Figure CN120263783A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of file transmission, and discloses a cross-network one-way file transmission method, which comprises the following steps of: configuring a port 3 of a two-layer switch as an observation port, and sending all flows flowing in and out of a port 1 A of a mirroring two-layer switch to the observation port under a network; a terminal C network card 1 of the network B is not configured, data flowing into the terminal C network card 1 from an observation port is captured by using capture software, and all data interacting with the network A terminal are captured; the two-layer switch does not perform IP address configuration; and the terminal C network card 2 is connected with the intranet switch of the B network to realize transmission of the A network file to the B network. According to the invention, the problem of file transmission between different physically isolated networks is solved. The cross-network one-way transmission is realized by utilizing the logic one-way of the switch port mirror image, and the hidden risk problem that the file transmission between the two physical isolation networks is subjected to reverse osmosis is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of file transfer, and particularly relates to a cross-network unidirectional file transfer method. Background Art

[0002] Cross-network unidirectional file transfer is a normal business requirement for enterprises. For example, downloading files such as software, documents, and photos from the Internet and importing them into the enterprise internal network for use. How to safely achieve cross-network unidirectional file transfer is a problem that needs to be solved.

[0003] Existing cross-network unidirectional file transfer methods include: (1) using a one-way data writing mobile hard disk or USB flash drive for copy import; (2) using optical disc burning for import; (3) using NAT (Network Address Translation) technology to connect the internal network and the external network, and making access control policies on the firewall to achieve one-way import; (4) using a one-way network gateway for file transfer; (5) establishing a cross-network isolation area for cross-network file transfer; (6) using a one-way optical signal device for file transfer; (7) using a camera to scan two-dimensional codes for one-way file transfer.

[0004] Some existing cross-network unidirectional file transfer solutions have security risks, such as optical disc burning and USB flash drive copy methods, which are prone to misoperations resulting in cross-connection of storage media between different networks; some are vulnerable to reverse penetration, such as achieving one-way transmission through firewall access control policies; some have high costs but also have the risk of reverse penetration, such as one-way network gateways; some have limited transmission bandwidth and can only transmit text information, such as the camera scanning two-dimensional code method. Summary of the Invention

[0005] To overcome the above technical problems, the present invention provides a cross-network unidirectional file transfer method.

[0006] The present invention adopts the following technical solutions: A cross-network unidirectional file transfer method, configuring port 3 of a layer 2 switch as an observation port, mirroring all traffic flowing in and out under network A of port 1 of the layer 2 switch to the observation port; not configuring network card 1 of terminal C in network B, using packet capture software to capture the data flowing from the observation port into network card 1 of terminal C, and capturing all data interacting with terminals in network A; the switch uses the layer 2 mode without IP address configuration to prevent the switch from being invaded and its configuration from being modified; network card 2 of terminal C is connected to the internal network switch of network B to achieve the transfer of files from network A to network B. Terminals in network A cannot perceive and detect devices and terminals in network B. Network B can receive the mirrored traffic sent from the observation port of the layer 2 switch. The observation port of the layer 2 switch only has outgoing interface traffic. Network card 1 of terminal C is not configured and has no IP address, so it is impossible to penetrate and attack the layer 2 switch through the observation port.

[0007] Preferably, a TAP device is set between the observation port and the network card 1 of terminal C for traffic replication while isolating network A and network B; the network card 1 of terminal C in network B is physically connected to the unidirectional out interface of the TAP; the TAP is configured using an external computer and does not belong to either network A or network B.

[0008] Preferably, two Modems are added in series between the TAP device and terminal C for physical unidirectionality.

[0009] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention solves the problem of file transfer between physically isolated different networks. By using the port mirroring of the switch, the logical unidirectionality of the TAP (Test Access Point) device, the physical unidirectionality of the single-shot carrier of the Modem (modem) and the single connection of the coaxial cable, combined with the trace flow function of the Wireshark software, a cross-network unidirectional file transfer scheme is designed. This scheme realizes the unidirectional transfer of files from one network to another physically isolated network, and solves the risk and hidden danger problem of reverse penetration in file transfer between two physically isolated networks; By using the method of cascading logical unidirectionality and physical unidirectionality, the daily needs and risk control of cross-network unidirectional file transfer are realized by using devices such as switches, TAP devices, and modems. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Figure 1 is a schematic diagram of the connection of the port mirroring of the switch in the present invention; Figure 2 is a connection relationship diagram of the cascaded TAP device after the port mirroring of the switch in the present invention; Figure 3 is a connection relationship diagram of the Modem and the logical unidirectional system in the present invention; Figure 4 is a connection relationship diagram of the physical unidirectional system realized by the single connection of the coaxial cable of the Modem in the present invention; Figure 5 is a connection relationship diagram of data sending and receiving in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0011] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions throughout. Unless otherwise specified, the raw materials and equipment used can be purchased from the market or are commonly used in the art. The methods in the embodiments, unless otherwise specified, are conventional methods in the art. The embodiments described below with reference to the drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.

[0012] Embodiment 1 Transferring files using switch port mirroring technology: Switch port mirroring is a commonly used means for network operation and maintenance personnel to troubleshoot faults and prevent network risks. The connection of switch port mirroring is as follows Figure 1 shown. Connect the Console port of the Layer 2 switch using a serial cable, configure port 3 of the Layer 2 switch as the observation port, and mirror all the traffic flowing in and out of port 1 of the Layer 2 switch to the observation port. Do not configure the network card 1 of terminal C. Use the Wireshark packet capture software to capture the data flowing into network card 1 of terminal C from the observation port, and all the data interacting with terminal A can be captured. When the switch uses the Layer 2 mode without IP address configuration, it can prevent the switch from being invaded and its configuration from being modified. Network card 2 of terminal C is connected to the internal network switch. Terminal C and terminals A and B belong to different physical networks, and through this technology, the transfer of files from network A to network B is realized.

[0013] Terminals A and B belong to network A and cannot perceive and detect network devices and terminals in network B. Network B can receive the mirrored traffic sent from the observation port of the Layer 2 switch. The observation port of the switch only has outbound interface traffic. Network card 1 of terminal C is not configured and has no IP address, so it cannot perform a penetration attack on the Layer 2 switch through the observation port.

[0014] Embodiment 2 On the basis of Embodiment 1, a TAP device is added to form the Figure 2 connection relationship shown, which is used to replicate traffic while isolating network A and network B. For network card 1 of terminal C in network B, it is physically connected to the TAP, and the TAP is configured using an external computer and does not belong to any network. This design avoids the direct physical connection between network card 1 of terminal C and the Layer 2 switch in network A. When viewing the MAC address table on the Layer 2 switch, the MAC address of the corresponding interface of the TAP device is seen instead of the MAC address of terminal C. Since the outgoing interface of the TAP device connecting terminal C is also a unidirectional interface and cannot be penetrated and tested, the security of the unidirectional system is enhanced.

[0015] Embodiment 3 As Figure 3As shown in the figure, on the basis of Embodiment 2, two Modems are added between the TAP device and Terminal C for physical unidirectional design. Modem A and Modem B are connected by a coaxial cable. The network port of Modem A is connected to the traffic outflow port of the TAP device, and the network port of Modem B is connected to Network Card 1 of Terminal C. Under normal conditions, after setting the same modulation, demodulation, encoding, and decoding parameters for Modem A and Modem B, the transmission rate is set to the maximum value. After setting the transceiver frequency correctly, both Modems are in the carrier lock state. Before carrier transmission, a 10dB attenuator needs to be connected in series to the transceiver of the coaxial cable between Modem A and Modem B respectively, so that the received levels of the two Modems are within the normal range. It is tested that Terminal C can receive the mirrored traffic sent by the TAP device normally. When the carrier transmission of Modem B is turned off, Network Card 1 of Terminal C can still receive the mirrored traffic.

[0016] During the experiment, it is found that the network ports of some models of Modems are equivalent to Hubs and will directly forward data frames without any processing, while the network ports of some models of Modems are equivalent to switches and will discard unicast data frames with non-destination MAC addresses, while multicast and broadcast are not affected. We need to use Modems with network ports equivalent to Hubs for unidirectional file transmission.

[0017] Embodiment 4 The difference between this embodiment and Embodiment 3 is that the coaxial cable for Modem A to receive Modem B is disconnected, making it physically unidirectional between Modem A and Modem B, and finally achieving logical unidirectionality + physical unidirectionality for the entire system. Experimental verification shows that Terminal C can receive the traffic mirror data sent from Terminal A to Terminal B according to the Figure 4 connection relationship. However, due to the four-layer logical unidirectionality + physical unidirectionality protection, the possibility of reverse penetration from Network B to Network A is ensured to be 0, achieving 0 risk of reverse penetration for cross-network unidirectional file transmission.

[0018] Embodiment 5 File sending: Terminal A sends a file to Terminal B. The layer 2 switch mirrors the data sent from Terminal A to Terminal B and transmits the mirrored data unidirectionally to Terminal C through the TAP. Terminal C is responsible for parsing. The connection relationship is as Figure 5As shown in the figure. There are two ways for Terminal A to communicate with Terminal B. One is to send data using the TCP (Transmission Control Protocol) method. The advantage is that it is connection-oriented and reliable, but the real-time transmission performance is weak and the efficiency is relatively low. The other is to use the UDP (User Datagram Protocol) method. The advantage is good real-time transmission performance and high efficiency, but because it is not connection-oriented, the transmission quality is unreliable. The cross-network unidirectional file transfer designed in this paper has low requirements for real-time performance and transmission efficiency, but high requirements for reliability. Therefore, the TCP transmission method is adopted.

[0019] Terminal A can use HFS (Http File Server) to place the file to be transferred on the HTTP server, set the corresponding port. Based on the HTTP protocol, Terminal B only needs to enter the IP address and corresponding port number of Terminal A in the browser to see the file to be downloaded on the web page. Click on the file to download to achieve the transfer of the file from Terminal A to Terminal B.

[0020] Since the download service provided by the HFS software does not limit the speed by default, the maximum transmission rate measured in a gigabit Ethernet environment in the experiment is 10MB / s, that is, 80Mbps, far exceeding the bandwidth that the modem can transmit. When Terminal B downloads large files through Terminal A, the mirror traffic exceeds the tolerance range of the modem, which will cause packet loss. Assuming that the modem uses a high-order modulation and demodulation method and the transceiver rate parameter is set to 20Mbps, the transmission rate is 2.5MB / s. It is necessary to limit the port speed of the interface on the layer 2 switch to below 20480Kbps. Only in this way can the traffic flowing through the modem be smoothly sent to Terminal C, and Terminal C can successfully splice the packets. The HFS also has a speed limit function, but the experimental test conclusion is that there will be packet loss at the beginning of sending large files, resulting in the inability to splice back the original data and it cannot be used when transmitting large files. Therefore, it is recommended to limit the speed of the switch interface to match the rate with the modem.

[0021] Example Six File reception: When Terminal B requests and downloads the file on Terminal A, it is only to form a TCP data stream on the layer 2 switch. This data stream is sent by the layer 2 switch from the observation port to the TAP device, and the TAP device then sends this data stream to Terminal C. The prerequisite for Terminal C to receive the complete data stream is to start Wireshark for packet capture in advance. Capturing packets before Terminal B requests to download the file on Terminal A can prevent packet loss. The reason for choosing Wireshark for packet capture is that Wireshark is free and open-source and runs on different operating system platforms.

[0022] After the file transfer from terminal A to terminal B is completed, stop the Wireshark packet capture on terminal C, parse the data packets, select one of the TCP traffic flows from terminal A to terminal B, right-click -> Follow Flow -> TCP Flow, and the complete TCP flow of the transferred file can be obtained. Select to display and save the data as raw data, and then save it as the corresponding file format to terminal C. For example, if the file transferred from terminal A to terminal B is a jpg format picture, then the saved file is also named X.jpg, and the saved file can be directly opened with an image software. The file to be transferred can also be compressed and saved as a.zip format. When saving the file on terminal C, it is also saved as a.zip format file. After decompression, the file to be transferred can be obtained.

[0023] The present invention realizes one-way file transfer from network A to physically isolated network B. Terminals A and B cannot perceive the existence of network B where terminal C is located. Although terminal C in network B can receive file data from network A, due to the adoption of many one-way technologies, it is impossible to reverse from terminal C to network A to attack network A.

[0024] This solution solves the problem of file transfer between different physically isolated networks, and solves the problem of easy reverse penetration during file transfer between different networks. With each business system isolated by VPN, terminal users are faced with the problem of needing to transfer files across various physically isolated networks. This solution can realize one-way file transfer from physically isolated network A to network B, and has broad application prospects in units with a large variety of network types.

[0025] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to the above embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the claims and their equivalents.

Claims

1. A cross-network unidirectional file transfer method, characterized in that, Configure port 3 of the Layer 2 switch as the observation port, and mirror all the traffic flowing in and out under Network A of port 1 of the Layer 2 switch to the observation port; Do not configure the network card 1 of terminal C in Network B, and use packet capture software to capture the data flowing from the observation port into network card 1 of terminal C, and capture all the data interacting with the terminals in Network A; The switch uses the Layer 2 mode without IP address configuration to prevent the switch from being invaded and the configuration from being modified; Network card 2 of terminal C is connected to the internal network switch of Network B to realize the transmission of files from Network A to Network B. The terminals in Network A cannot perceive and detect the devices and terminals in Network B. Network B can receive the mirrored traffic sent from the observation port of the Layer 2 switch. There is only outgoing interface traffic at the observation port of the Layer 2 switch. Network card 1 of terminal C is not configured and has no IP address, so it is impossible to conduct a penetration attack on the Layer 2 switch through the observation port.

2. A cross-network one-way file transfer method according to claim 1, characterized in that Set up a TAP device between the observation port and network card 1 of terminal C to isolate Network A and Network B while replicating the traffic; Network card 1 of terminal C in Network B is physically connected to the unidirectional outgoing interface of the TAP. The TAP is configured using an external computer. The TAP does not belong to Network A nor Network B.

3. A cross-network unidirectional file transfer method according to claim 2, characterized in that Add two Modems in series between the TAP device and terminal C for physical unidirectionality.