Front digital boundary secure exchange method and system based on optical one-way transmission characteristic and storage medium
Through the pre-digital boundary security exchange method based on the optical one-way transmission characteristics, data encryption, decryption and verification are used for data encryption, decryption and identification, combined with the one-way data transmission optical gateway connection pool and asynchronous processing technology, the high cost of data transmission in the internal and external networks and insufficient data integrity in the existing technology is solved, and safe and efficient data exchange is achieved.
Patent Information
- Application Number
- CN202510492973.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the use of physical isolation equipment to achieve data transmission in the internal and external networks has problems such as high cost, complex deployment and insufficient data integrity guarantee, especially the physical gate based on optical one-way transmission is difficult to guarantee data integrity.
The pre-digital boundary security exchange method based on the optical one-way transmission characteristics is adopted, and the request and response data is encrypted, decrypted and checked through the service external network and intranet front-digital boundary security gateway, and data transmission is transmitted using the one-way data transmission optical gate connection pool, and asynchronous processing and connection pool technology are introduced to optimize data transmission efficiency.
It realizes safe and efficient data exchange between different dense networks, reduces the adaptation workload and time cost, improves the efficiency and security of data exchange, and ensures the integrity and security of data transmission.
Smart Images

Figure CN120342694A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly relates to a pre - digital boundary security exchange method, system and storage medium based on the unidirectional optical transmission characteristic. Background Art
[0002] With the rapid development of the Internet, higher requirements are put forward for the security and integrity of data transmission in various business applications. In actual business, classified enterprises and institutions usually operate in an intranet environment. However, due to the need for collaborative work, there is still a demand for data exchange between different - level classified networks. In the prior art, physical isolation devices (such as traditional security gateways) are often used to achieve data transmission between the internal and external networks. However, these devices are costly, complex to deploy, and difficult to meet the adaptation requirements of different services. In particular, although the physical gateway based on unidirectional optical transmission can ensure the security of unidirectional data transmission, its inherent unidirectional characteristic makes it difficult to guarantee data integrity, and the workload for adapting applications is huge. Summary of the Invention
[0003] The purpose of this application is to provide a pre - digital boundary security exchange method, system and storage medium based on the unidirectional optical transmission characteristic, so as to solve the problems of high cost, complex deployment and insufficient data integrity guarantee in using physical isolation devices to achieve data transmission between the internal and external networks in the prior art.
[0004] To achieve the above purpose, an embodiment of this application provides a pre - digital boundary security exchange method based on the unidirectional optical transmission characteristic, which is applied to a pre - digital boundary security exchange system. The software modules of the pre - digital boundary security exchange system include a business external network pre - digital boundary security gateway and an internal network pre - digital boundary security gateway. The hardware devices of the pre - digital boundary security exchange system include: an external network optical gateway and an internal network optical gateway. The pre - digital boundary security exchange method includes:
[0005] Using an exchange account and a secret key, send a request with the account information carried in the request header to the business external network pre - digital boundary security gateway;
[0006] After receiving the request, the business external network pre - digital boundary security gateway parses the request context parameters, performs a legality check on the carried exchange account, secret key and other request parameters, and signs and encrypts the request context parameters;
[0007] After the legality check passes, the business external network pre - digital boundary security gateway encapsulates the request context parameters into a request data packet, uses the unidirectional data transmission optical gateway connection pool from the external network to the internal network, and after obtaining a connection, sends the request data packet to the internal network pre - digital boundary security gateway;
[0008] After the intranet front-end digital boundary security gateway receives the request data packet, it decrypts and verifies the signature of the request message in it. After successful verification, it reconstructs the request message and sends it to the real target server to obtain the result;
[0009] After the intranet front-end digital boundary security gateway obtains the result, it binds and encapsulates the obtained response data packet with the request unique link ID in the request data packet, and uses the one-way data transmission air gap connection pool from the intranet to the extranet to send the response data packet to the business extranet front-end digital boundary security gateway;
[0010] The business extranet front-end digital boundary security gateway obtains the response data packet from the intranet front-end digital boundary security gateway, parses the request unique link ID from the response data packet, and synchronizes the current result to the initiated request, and the entire request ends.
[0011] Optionally, the request context parameters include request headers, request methods, request paths, request parameters, and file processing.
[0012] Optionally, when using the one-way data transmission air gap connection pool from the extranet to the intranet, after obtaining the connection, the request data packet is sent to the intranet front-end digital boundary security gateway, which specifically includes:
[0013] The business extranet front-end digital boundary security gateway obtains a connection from the external network air gap, sends the request data packet to the external network air gap, the external network air gap automatically ferries the request data packet to the internal network air gap, and the internal network air gap pushes the request data packet to the intranet front-end digital boundary security gateway.
[0014] Optionally, when using the one-way data transmission air gap connection pool from the intranet to the extranet to send the response data packet to the business extranet front-end digital boundary security gateway, it specifically includes:
[0015] The intranet front-end digital boundary security gateway obtains a connection from the internal network air gap, sends the response data packet to the internal network air gap, the internal network air gap automatically ferries the response data packet to the external network air gap, and the external network air gap pushes the response data packet to the business extranet front-end digital boundary security gateway.
[0016] Optionally, it further includes:
[0017] Using an exchange account and secret key, send a request with account information carried in the request header to the intranet front-end digital boundary security gateway;
[0018] The intranet front-end digital boundary security gateway receives the request, parses the request context parameters, verifies the legality of the carried exchange account, secret key, and other request parameters, and signs and encrypts the request context parameters;
[0019] After the legality verification is passed, the intranet front-end digital boundary security gateway encapsulates the request context parameters into a request data packet, uses the one-way data transmission optical isolation connection pool from the intranet to the extranet, and after obtaining a connection, sends the request data packet to the business extranet front-end digital boundary security gateway;
[0020] After the business extranet front-end digital boundary security gateway receives the request data packet, it decrypts and verifies the signature of the request message therein. After successful verification, it reconstructs the request message and sends it to the real target server to obtain the result;
[0021] After the business extranet front-end digital boundary security gateway obtains the result, it binds and encapsulates the obtained response data packet with the request unique link ID in the request data packet, and uses the one-way data transmission optical isolation connection pool from the extranet to the intranet to send the response data packet to the intranet front-end digital boundary security gateway;
[0022] The intranet front-end digital boundary security gateway obtains the response data packet from the business extranet front-end digital boundary security gateway, parses the request unique link ID from the response data packet, and synchronizes the result of this time to the initiated request, and the entire request ends.
[0023] To achieve the above object, the present application also provides a front-end digital boundary security exchange system based on the one-way optical transmission characteristic, including:
[0024] Request legality verification module: Parse and verify the legality of the request source end and the target end to ensure the security of the request;
[0025] Request message processing module: Parse, perform security verification, route parsing and proxy on the request message;
[0026] One-way data transmission module: Establish a unilateral data transmission channel through a one-way optical transmission device, and connect and pool and manage the transmission connection between the front-end digital boundary security exchange system and the physical optical isolation;
[0027] Request reconstruction module: Reconstruct the received request and send it to the target server;
[0028] Result synchronization module: By constructing a result synchronizer, without relying on the TCP protocol, correctly synchronize the response result of the target server to the original request;
[0029] Security policy module: Based on the authorization policy and time policy of the access source and the access target, use the SM2 / SM3 / SM4 algorithm to sign / verify the signature and encrypt / decrypt the transmitted data.
[0030] Optionally, the one-way data transmission module uses pooling technology to maintain the optical isolation connection.
[0031] Optionally, the request legality verification module is specifically configured to verify the exchange account, key, and request parameters of the request.
[0032] Optionally, the request message processing module serializes and deserializes the request data through Google Protobuf.
[0033] To achieve the above object, the present application further provides a computer storage medium, on which a computer program is stored, and when the computer program is executed by a machine, the steps of the method described above are implemented.
[0034] Through this exchange system, users can securely and efficiently exchange data between different security level network regions without caring about the underlying adaptation details of the optical unidirectional transmission device.
[0035] As a middleware service for data security exchange between different security level network domains, the preposed digital boundary security exchange system takes into account both security and data concurrent exchange performance. The system has realized the following innovative features:
[0036] 1. Standard and compliance, developed and constructed based on the relevant guiding requirements for secure transmission between different security level network domains, using unidirectional optical conduction devices.
[0037] 2. As an application layer data exchange security exchange system, while ensuring security, it also takes into account concurrent performance. The SERVER implemented based on the NIO technical solution is used to efficiently receive and process concurrent requests.
[0038] 3. Multilevel caching and asynchronous processing, parsing and verifying the legality of request parameters to improve the performance of logical verification and concurrent processing capabilities.
[0039] 4. Unidirectional optical gateway connection pooling, performing pooling processing to maintain the connection status, thereby reducing the overhead caused by frequent creation and destruction of connections.
[0040] 5. Based on a custom efficient data message, ensuring the efficiency and security of message encoding and decoding.
[0041] 6. Using national cryptography SM2 / SM3 / SM4 to sign / verify and encrypt / decrypt the data packets during the transmission process to ensure the security of data transmission.
[0042] 7. Providing multi-level security policies, including service authorization access source and target control, timeout control and other custom policies to control access to requests, ensuring that only authorized applications and requests can pass through the gateway for data exchange.
[0043] 8. Using cross-platform high-performance serializers and deserializers to process the transmitted data messages, thereby reducing the message sub-section size and improving the serialization and deserialization efficiency.
[0044] 9. Build an efficient one-way data synchronization mechanism to ensure that the final result can be synchronized to the correct request.
[0045] 10. Simplify the application access process. Only by configuring the security key can cross-network data transmission be completed, completely avoiding the complexity of application access between multi-classification network domains, and greatly saving the access cost.
[0046] In summary, through this application, the business party can significantly reduce the adaptation workload and time cost, and further improve the efficiency and security of data exchange.
[0047] The technical solution of this application has the following advantages:
[0048] Improved security: Based on the physical isolation characteristics of optical one-way transmission, combined with national cryptography algorithms (SM2 / SM3 / SM4) for data encryption and signature verification, comprehensively ensuring the security and confidentiality of data transmission.
[0049] Guaranteed data integrity: Through the result synchronization module, ensure that the requests and response results in the one-way data transmission process can be correctly matched to avoid data loss.
[0050] High-performance support: Introduce asynchronous processing and connection pool technologies to optimize data transmission efficiency and system resource utilization, and easily handle high-concurrency requests.
[0051] Simplified access: The business party only needs to configure the exchange account and key to achieve data transmission, reducing the cost and difficulty of complex adaptation in traditional systems.
[0052] Wide application range: Support cross-platform deployment, adapt to different operating system environments, can be extended for multiple business scenarios, and have good versatility and scalability. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the implementation manners of this application or the technical solutions in the prior art, the following will briefly introduce the drawings required for the implementation manners or the description of the prior art. Obviously, the drawings described below are only exemplary, and for those of ordinary skill in the art, without creative efforts, other implementation drawings can be obtained according to the provided drawings.
[0054] Figure 1 It is a flowchart of a prefrontal digital boundary security exchange method based on the characteristics of optical one-way transmission provided for at least one embodiment of this application;
[0055] Figure 2 It is a schematic diagram of requests and data between different classification domains of a prefrontal digital boundary security exchange system based on the characteristics of optical one-way transmission provided for at least one embodiment of this application;
[0056] Figure 3 Schematic diagram of the request and data transmission network structure from the service external network to the internal network of a pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic provided by at least one embodiment of the present application;
[0057] Figure 4 Schematic diagram of the request and data transmission network structure from the internal network to the service external network of a pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic provided by at least one embodiment of the present application;
[0058] Figure 5 Logic diagram of the request and data transmission from the service external network to the internal network of a pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic provided by at least one embodiment of the present application;
[0059] Figure 6 Logic diagram of the request and data transmission from the internal network to the service external network of a pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic provided by at least one embodiment of the present application;
[0060] Figure 7 Timing diagram of the request and data transmission from the service external network to the internal network of a pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic provided by at least one embodiment of the present application;
[0061] Figure 8 Timing diagram of the request and data transmission from the internal network to the service external network of a pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic provided by at least one embodiment of the present application. Detailed implementation manners
[0062] The following specific embodiments illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present application belong to the scope of protection of the present application.
[0063] It should be noted that in the claims and the specification of the present application, the steps can be executed basically in parallel or in the reverse order under appropriate circumstances, depending on the functions involved.
[0064] In addition, the technical features involved in different implementation manners of the present application described below can be combined with each other as long as they do not conflict with each other.
[0065] An embodiment of the present application provides a pre - digital boundary security exchange method based on the unidirectional transmission characteristic of light. Refer to Figure 1 , Figure 1 is a flowchart of a pre - digital boundary security exchange method based on the unidirectional transmission characteristic of light provided in at least one embodiment of the present application. It should be understood that the method may also include additional boxes not shown and / or boxes shown may be omitted, and the scope of the present application is not limited in this regard. In addition, this embodiment is a method for the business external network to initiate a request to the internal network through the pre - digital boundary security exchange system. What is shown is the full process of a request initiated by the business external network through the pre - digital boundary security exchange system to the internal network and obtaining the final response result. In the embodiment, the cooperation of two pre - digital boundary security exchange systems in two different classified network domains is involved to achieve the purpose of request and result response between the external network and the internal network. It should be understood that the method for the internal network to initiate a request to the business external network through the pre - digital boundary security exchange system also belongs to the protection scope of the present application.
[0066] The following embodiments are not intended to limit the usage form of the pre - boundary security exchange system. It can work independently at any node that requires boundary security protection and network proxy, does not completely rely on the optical switch to work, can be independent between the client and the server to be protected, and when working between multiple network domains, as long as it is ensured that unidirectional optical switch devices are deployed between each network domain for communication guarantee, the data transmission and secure exchange can be realized.
[0067] Refer to Figures 2 to 8 , the software modules of the pre - digital boundary security exchange system for implementing the pre - digital boundary security exchange method based on the unidirectional transmission characteristic of light include a business external network pre - digital boundary security gateway and an internal network pre - digital boundary security gateway. The hardware devices of the pre - digital boundary security exchange system include: an external network optical switch and an internal network optical switch. Among them, Figure 2 shows the data flow principle of requests and data between different classified domains through the unidirectional optical transmission device. By using the unidirectional transmission characteristic of light, data can only be transmitted from one classified network domain to another classified network domain. Figure 3 and Figure 4 show the request and data transmission network structures, corresponding to the respective network nodes passed by the requests initiated by the clients in the two classified network domains of the business external network and the internal network. Figure 5 and Figure 6 show the full - process logic diagrams of request and data transmission, corresponding to the logical processes of a complete processing and response of requests initiated by clients in two different classified levels of the business external network and the internal network and the request messages. Figure 7 and Figure 8 show the timing diagrams of request and data transmission, corresponding to the logical steps involved from the requests initiated by clients in two different classified levels of the business external network and the internal network to the final response.
[0068] Step 1: Receive application requests
[0069] The APP uses the exchange account and secret key opened by the digital boundary security gateway in the business external network pre - front end, and sends a request to the digital boundary security gateway in the business external network pre - front end by carrying the account information in the request header.
[0070] Step 2: Parse and verify request parameters
[0071] The digital boundary security gateway in the business external network pre - front end receives the request, parses the request context parameters, performs a legality check on the carried exchange account, secret key, and other request parameters, and signs and encrypts the request context parameters using the national cryptographic algorithm.
[0072] In some embodiments, the request context parameters include the request header, request method, request path, request parameters, and file processing.
[0073] Step 3: Package and send the message
[0074] After the legality check passes, the digital boundary security gateway in the business external network pre - front end packages the request context parameters into a request data packet, uses the one - way data transfer optical switch connection pool from the external network to the internal network, and after obtaining a connection, sends the request data packet to the digital boundary security gateway in the internal network pre - front end.
[0075] In some embodiments, the use of the one - way data transfer optical switch connection pool from the external network to the internal network and, after obtaining a connection, sending the request data packet to the digital boundary security gateway in the internal network pre - front end specifically includes:
[0076] The digital boundary security gateway in the business external network pre - front end obtains a connection from the external network optical switch, sends the request data packet to the external network optical switch, the external network optical switch automatically ferries the request data packet to the internal network optical switch, and the internal network optical switch pushes the request data packet to the digital boundary security gateway in the internal network pre - front end.
[0077] Step 4: Decode the message and reconstruct the request
[0078] After the digital boundary security gateway in the internal network pre - front end receives the request data packet, it decrypts and verifies the signature of the request message therein. After the verification is successful, it reconstructs the request message and sends it to the real target server to obtain the result.
[0079] Step 5: Result processing
[0080] After the digital boundary security gateway in the internal network pre - front end obtains the result, it binds and packages the obtained response data packet with the request unique link ID in the request data packet, and uses the one - way data transfer optical switch connection pool from the internal network to the external network to send the response data packet to the digital boundary security gateway in the business external network pre - front end.
[0081] In some embodiments, using the one-way data transmission air gap connection pool from the internal network to the external network, the response data packet is sent to the digital boundary security gateway in front of the business external network, which specifically includes:
[0082] The digital boundary security gateway in front of the internal network obtains a connection from the internal network air gap, sends the response data packet to the internal network air gap, the internal network air gap automatically ferries the response data packet to the external network air gap, and the external network air gap pushes the response data packet to the digital boundary security gateway in front of the business external network.
[0083] Step 6 Result synchronization
[0084] The digital boundary security gateway in front of the business external network obtains the response data packet from the digital boundary security gateway in front of the internal network, parses the request unique link ID from the response data packet, and synchronizes the current result to the request initiated by the APP, and the entire request ends.
[0085] In some embodiments, the method for the internal network to initiate a request to the business external network through the digital boundary security exchange system in front includes:
[0086] Using the exchange account and secret key, send a request with the account information carried in the request header to the digital boundary security gateway in front of the internal network;
[0087] The digital boundary security gateway in front of the internal network receives the request, parses the request context parameters, performs a legality check on the carried exchange account and secret key as well as the remaining request parameters, and signs and encrypts the request context parameters;
[0088] After the legality check passes, the digital boundary security gateway in front of the internal network encapsulates the request context parameters into a request data packet, uses the one-way data transmission air gap connection pool from the internal network to the external network, and after obtaining a connection, sends the request data packet to the digital boundary security gateway in front of the business external network;
[0089] After receiving the request data packet, the digital boundary security gateway in front of the business external network decrypts and verifies the signature of the request message therein. After the verification is successful, it reconstructs the request message and sends it to the real target server to obtain the result;
[0090] After the digital boundary security gateway in front of the business external network obtains the result, it binds and encapsulates the obtained response data packet with the request unique link ID in the request data packet, and uses the one-way data transmission air gap connection pool from the external network to the internal network to send the response data packet to the digital boundary security gateway in front of the internal network;
[0091] The digital boundary security gateway in front of the internal network obtains the response data packet from the digital boundary security gateway in front of the business external network, parses the request unique link ID from the response data packet, and synchronizes the current result to the initiated request, and the entire request ends.
[0092] An embodiment of the present application further provides a pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic, including: A request legality verification module: parsing and verifying the legality of the request source end and the target end to ensure the security of the request;
[0093] A request message processing module: parsing, security verifying, route parsing and proxying the request message;
[0094] A unidirectional data transmission module: establishing a unilateral data transmission channel through a unidirectional optical transmission device, connecting and pooling and managing the transmission connection between the pre - digital boundary security exchange system and the physical optical switch;
[0095] A request reconstruction module: reconstructing the received request and sending it to the target server;
[0096] A result synchronization module: correctly synchronizing the response result of the target server to the original request without relying on the TCP protocol by constructing a result synchronizer;
[0097] A security policy module: based on the authorization policy and time policy of the access source and the access target, using SM2 / SM3 / SM4 algorithms to sign / verify and encrypt / decrypt the transmitted data to ensure the security of the request.
[0098] In some embodiments, the unidirectional data transmission module uses pooling technology to maintain the optical switch connection, avoiding the performance overhead caused by frequent creation and destruction of connections to support high - concurrent data transmission requirements.
[0099] In some embodiments, the request legality verification module is specifically used to verify the exchange account, key and request parameters of the request to ensure the reliability and security of the request source.
[0100] In some embodiments, the request message processing module serializes and deserializes the request data through Google Protobuf to reduce the message volume and improve the processing efficiency.
[0101] In some embodiments, the result synchronization module ensures the integrity and accuracy of the response data during the result synchronization process by constructing a distributed cache.
[0102] In some embodiments, the pre - digital boundary security exchange system enforces access policies during data transmission, including time - based access control policies and authorization policies based on the target service.
[0103] In some embodiments, the security policy module uses the national cipher SM4 algorithm to encrypt the transmitted data to ensure the confidentiality and anti - tampering property of the data during cross - network domain transmission.
[0104] In some embodiments, the pre - digital boundary security exchange system constructs an asynchronous HTTP server through the Netty framework to receive and process concurrent client requests, improving the performance and concurrency of network services.
[0105] In some embodiments, the optical switch connection pool of the unidirectional data transmission module supports dynamic adjustment of the number of connections to adapt to different business requirements and concurrent loads.
[0106] In some embodiments, the pre - digital boundary security exchange system supports cross - platform deployment, adapts to multiple operating system environments, and can be extended for other scenarios that require secure unidirectional data transmission.
[0107] Specifically, the client sends a request through the pre - digital boundary security exchange system. The exchange system parses the request message and verifies its legality. After passing the verification, the exchange system serializes and encrypts the request data. The optical switch is connection - pooled to unidirectionally transmit the data in the current network zone to the target network zone, reducing the loss caused by repeatedly creating connections. The pre - digital boundary security exchange system forcibly enables the matching policy for the access source and access target, and is also equipped with a configurable time policy. The two policies can be used simultaneously. The national cryptography algorithms SM2 / SM3 / SM4 are used to sign and encrypt the message data during the transmission process to ensure the integrity and security of data transmission. The pre - digital boundary security exchange system performs data transmission based on the unidirectional optical switch and does not support the TCP three - way handshake. To ensure a complete path for a single request and response, the pre - digital boundary security exchange system constructs a result synchronizer to correctly synchronize the final result to the original request, ensuring a seamless and secure data exchange for the APP side. Due to the particularity of the unidirectional data transmission based on the unidirectional optical switch in the pre - digital boundary security exchange system, during the process from a complete request to the final result response, any node may encounter exceptions and faults. When an exception occurs, the pre - digital boundary security exchange system can perform a perfect and friendly handling for specific exceptions and synchronize them to the client in a timely manner. At the same time, the entire process and details of the pre - digital boundary security exchange system are logged, ensuring that subsequent troubleshooting can quickly locate the problem.
[0108] For the specific implementation method, refer to the foregoing method embodiments and will not be elaborated here.
[0109] This application can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer - readable storage medium having computer - readable program instructions thereon for performing various aspects of this application.
[0110] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device such as a punch card or raised structures in grooves having instructions stored thereon, and any suitable combination of the foregoing. The computer-readable storage medium as used herein is not construed as an instantaneous signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0111] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to various computing / processing devices, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include a copper transmission cable, an optical fiber transmission, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.
[0112] The computer program instructions for performing the operations of the present application may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer-readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer-readable program instructions to implement various aspects of the present application.
[0113] Aspects of the present application are described herein with reference to the flowchart and / or block diagram of a method, system, and computer program product according to an embodiment of the present application. It should be understood that each block of the flowchart and / or block diagram, and the combination of blocks in the flowchart and / or block diagram, can be implemented by computer-readable program instructions.
[0114] These computer-readable program instructions may be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine such that when these instructions are executed by the processing unit of the computer or other programmable data processing device, a device is produced that implements the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium, and these instructions cause a computer, a programmable data processing device, and / or other devices to operate in a specific manner. Thus, the computer-readable medium storing the instructions includes a manufactured article that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0115] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to generate a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other devices implement the functions / actions specified in one or more boxes of the flowchart and / or block diagram.
[0116] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0117] Note that unless otherwise directly stated, all features disclosed in this specification (including any appended claims, abstract, and drawings) may be replaced by alternative features serving the same, equivalent, or similar purpose. Therefore, unless otherwise explicitly stated, each feature disclosed is only an example of a group of equivalent or similar features. Where used, the terms "further", "preferably", "furthermore", and "more preferably" are simple introductions to another embodiment elaborated on the basis of the foregoing embodiments. The content following the "further", "preferably", "furthermore", or "more preferably" in combination with the foregoing embodiments constitutes a complete composition of another embodiment. A further embodiment can be arbitrarily combined from several "further", "preferably", "furthermore", or "more preferably" settings following the same embodiment.
[0118] Although the present application has been described in detail above using general descriptions and specific examples, modifications or improvements can be made to it on the basis of the present application, which will be obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present application fall within the scope of protection claimed in the present application.
Claims
1. A pre - digital boundary security exchange method based on the unidirectional light transmission characteristic, characterized in that, Applied to the front-end digital boundary security exchange system, the software modules of the front-end digital boundary security exchange system include the business external network front-end digital boundary security gateway and the internal network front-end digital boundary security gateway, and the hardware devices of the front-end digital boundary security exchange system include: the external network air gap and the internal network air gap. The front-end digital boundary security exchange method includes: Using the exchange account and secret key, send a request with the account information carried in the request header to the business external network front-end digital boundary security gateway; The business external network front-end digital boundary security gateway receives the request, parses the request context parameters, performs legality verification on the carried exchange account, secret key and other request parameters, and signs and encrypts the request context parameters; After the legality verification passes, the business external network front-end digital boundary security gateway encapsulates the request context parameters into a request data packet, uses the one-way data transmission air gap connection pool from the external network to the internal network, and after obtaining a connection, sends the request data packet to the internal network front-end digital boundary security gateway; After the internal network front-end digital boundary security gateway receives the request data packet, decrypts and verifies the signature of the request message therein. After the verification is successful, reconstructs the request message and sends it to the real target server to obtain the result; After the internal network front-end digital boundary security gateway obtains the result, binds and encapsulates the obtained response data packet with the request unique link ID in the request data packet, and uses the one-way data transmission air gap connection pool from the internal network to the external network to send the response data packet to the business external network front-end digital boundary security gateway; The business external network front-end digital boundary security gateway obtains the response data packet from the internal network front-end digital boundary security gateway, parses the request unique link ID from the response data packet, and synchronizes the current result to the initiated request, and the entire request ends.
2. The front-end digital boundary security exchange method based on the one-way optical transmission characteristic according to claim 1, characterized in that The request context parameters include the request header, request method, request path, request parameters, and file processing.
3. The pre - digital boundary security exchange method based on the one - way light transmission characteristic according to claim 1, wherein, The using the one-way data transmission air gap connection pool from the external network to the internal network and sending the request data packet to the internal network front-end digital boundary security gateway after obtaining a connection specifically includes: The business external network front-end digital boundary security gateway obtains a connection from the external network air gap, sends the request data packet to the external network air gap, the external network air gap automatically ferries the request data packet to the internal network air gap, and the internal network air gap pushes the request data packet to the internal network front-end digital boundary security gateway.
4. The pre - digital boundary security exchange method based on the unidirectional optical transmission characteristic according to claim 1, wherein, The using the one-way data transmission air gap connection pool from the internal network to the external network and sending the response data packet to the business external network front-end digital boundary security gateway specifically includes: The internal network front-end digital boundary security gateway obtains a connection from the internal network air gap, sends the response data packet to the internal network air gap, the internal network air gap automatically ferries the response data packet to the external network air gap, and the external network air gap pushes the response data packet to the business external network front-end digital boundary security gateway.
5. The pre - digital boundary security exchange method based on the unidirectional optical transmission characteristic according to claim 1, wherein, It further includes: Using the exchange account and secret key, send a request with the account information carried in the request header to the internal network front-end digital boundary security gateway; The intranet front-end digital boundary security gateway receives the request, parses the request context parameters, performs a legality check on the carried exchange account, secret key, and other request parameters, and signs and encrypts the request context parameters. After the legality check passes, the intranet front-end digital boundary security gateway encapsulates the request context parameters into a request data packet, uses the one-way data transmission optical switch connection pool from the intranet to the extranet, and after obtaining a connection, sends the request data packet to the service extranet front-end digital boundary security gateway. After the service extranet front-end digital boundary security gateway receives the request data packet, it decrypts and verifies the signature of the request message therein. After the verification is successful, it reconstructs the request message and sends it to the real target server to obtain the result. After the service extranet front-end digital boundary security gateway obtains the result, it binds and encapsulates the obtained response data packet with the request unique link ID in the request data packet, and uses the one-way data transmission optical switch connection pool from the extranet to the intranet to send the response data packet to the intranet front-end digital boundary security gateway. The intranet front-end digital boundary security gateway obtains the response data packet from the service extranet front-end digital boundary security gateway, parses the request unique link ID from the response data packet, and synchronizes the current result to the initiated request, and the entire request ends.
6. A pre - digital boundary security exchange system based on the unidirectional optical transmission characteristic, characterized in that, Including: Request legality check module: Parses and checks the legality of the request source and target to ensure the security of the request. Request message processing module: Parses, performs security checks, route parsing, and proxying on the request message. One-way data transmission module: Establishes a unilateral data transmission channel through one-way optical transmission devices, and connects and pool-manages the transmission connection between the front-end digital boundary security exchange system and the physical optical switch. Request reconstruction module: Reconstructs the received request and sends it to the target server. Result synchronization module: Correctly synchronizes the response result of the target server to the original request without relying on the TCP protocol by constructing a result synchronizer. Security policy module: Based on the authorization policy and time policy of the access source and access target, uses the SM2 / SM3 / SM4 algorithm to sign / verify the signature and encrypt / decrypt the transmitted data.
7. The front-end digital boundary security exchange system based on the one-way optical transmission characteristic according to claim 6, wherein The one-way data transmission module uses pooling technology to maintain the optical switch connection.
8. The front-end digital boundary security exchange system based on the one-way optical transmission characteristic according to claim 6, wherein The request legality check module is specifically used to verify the exchange account, key, and request parameters of the request.
9. The front-end digital boundary security exchange system based on the one-way optical transmission characteristic according to claim 6, wherein The request message processing module performs serialization and deserialization processing on the request data through Google Protobuf.
10. A computer storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a machine, it implements the steps of the method according to any one of claims 1 to 5.
Citation Information
Cited By
Transmission system based on double unidirectional transmission links and state monitoring and tracing method thereof
CN121356778A
Transmission system based on dual unidirectional transmission link and its state monitoring and tracing method
CN121356778B
High-bandwidth transmission system and transmission method based on unidirectional transmission
CN121531176A
High-bandwidth transmission system and transmission method based on unidirectional transmission
CN121531176B