Data ferry method, device, system, apparatus and storage medium

By constructing a network topology and defining a ferry state machine, the problem of low efficiency in manual storage medium ferrying was solved, and efficient and secure data transmission in complex network environments was achieved.

CN120358088BActive Publication Date: 2025-11-18BEIJING ANNING INNOVATION NETWORK TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510837245.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-11-18
Estimated Expiration
2045-06-23

AI Technical Summary

Technical Problem

In existing technologies, manual storage medium transfer relies on manual operation, which cannot respond to sudden high-frequency data transmission demands, resulting in low data transfer efficiency.

Method used

The network topology and state machine for data ferrying are pre-constructed, the ferrying states and state transition logic are defined, and the state machine controls the ferry network to transmit data between different network domains, satisfying isolation requirements and security.

Benefits of technology

It enables efficient control of data transmission in complex network environments, quickly adapts to various data transmission scenarios, avoids data leakage and external attacks, and improves data transfer efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358088B_ABST
    Figure CN120358088B_ABST
Patent Text Reader

Abstract

The application discloses a data ferrying method, device, system, equipment and storage medium, relates to the technical field of communication, and splits the data ferrying process into flexibly defined ferrying states and state transitions through a ferrying state machine, can efficiently control the transmission of data between different network domains while meeting the isolation requirements, and effectively avoids data leakage and external attacks. The method comprises the following steps: constructing a network topology structure of data ferrying in advance, wherein the network topology structure comprises a network domain set and a ferrying network set; defining a ferrying state machine on the basis of the network topology structure, wherein the ferrying state machine is a state model for describing the data transmission of the ferrying network between at least two network domains, and the ferrying state machine comprises at least one ferrying state and state transition logic; and changing the connection state combination formed by the ferrying network and the at least two network domains according to the state transition logic, so as to control the data transmission of the ferrying network between the at least two network domains.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a data transfer method, apparatus, system, device, and storage medium. Background Technology

[0002] In complex network environments, the need for secure isolation is growing, such as in scenarios involving industrial control networks and office networks, or financial core systems and external interface networks. In these scenarios, direct data exchange can pose serious security risks. To address this, data can be transferred from one network environment to another via data bridging, ensuring secure data transmission while maintaining network isolation.

[0003] In related technologies, data transfer can be performed manually between networks or systems with different security levels using physical storage media. This process primarily relies on physical isolation to prevent network attacks and is suitable for low-frequency, low-risk scenarios. For example, manually copying data between physically isolated networks using storage devices such as USB flash drives or external hard drives. However, this manual storage media transfer method depends on manual operation and cannot respond to sudden high-frequency data transfer demands, resulting in low data transfer efficiency. Summary of the Invention

[0004] In view of this, this application provides a data transfer method, apparatus, system, device and storage device, the main purpose of which is to solve the problem that the existing technology of using manual storage media for data transfer relies on manual operation, which cannot respond to sudden high-frequency data transfer demands, resulting in low data transfer efficiency.

[0005] According to the first aspect of this application, a data transfer method is provided, comprising:

[0006] A network topology for data ferrying is pre-constructed. The network topology includes a set of network domains and a set of ferry networks. The set of network domains includes at least two network domains that satisfy isolation relationships. The set of ferry networks includes at least one ferry network. A ferry network is connected to at least two network domains.

[0007] Based on the network topology, a ferry state machine is defined. The ferry state machine is a state model that describes the data transmission of the ferry network between at least two network domains. The ferry state machine includes at least one ferry state and state transition logic. Each ferry state corresponds to a network connection combination. The network connection state is a combination of connection states formed by the ferry network and at least two network domains.

[0008] The state transition logic is used to change the connection state combination between the ferry network and at least two network domains to control the ferry network to transmit data between the at least two network domains.

[0009] Furthermore, the step of defining a ferry state machine based on the network topology includes:

[0010] Based on the network topology, at least one ferry state is set according to the combination of connection states formed by the ferry network and at least two network domains. The combination of connection states includes an on state and a off state. The on state is when the ferry network is connected to the network domain, and the off state is when the ferry network is not connected to the network domain.

[0011] Based on the network topology, state transition logic is set according to the events that trigger state transitions during data transfer and the constraints that drive state transitions. The state transition logic executes state transitions when at least one constraint is met, based on the intent to trigger state transitions through events. The events include external events and / or internal events, and the constraints include at least one of time constraints, sequence constraints, and verification constraints.

[0012] Based on the at least one ferry state and the state transition logic, a ferry state machine is defined such that the ferry state machine controls the at least one ferry state to run sequentially during the data ferry process according to the state transition logic.

[0013] Furthermore, the step of setting at least one ferry state based on the combination of connection states formed by the ferry network and at least two network domains includes:

[0014] Based on the combination of connection states formed by the ferry network and at least two network domains, select a valid combination of connection states that satisfies the connection state constraints, which include network domain isolation constraints and data flow constraints.

[0015] Using a predefined logical correspondence, the connection states in the effective connection state combination are converted into at least one ferry state.

[0016] Furthermore, based on the events that trigger state transitions during the data transfer process and the constraints that drive the state transitions, the state transition logic is set, including...

[0017] The events that trigger state transitions during the data transfer process and the constraints that drive state transitions are combined to obtain a state transition matrix. The state transition matrix is ​​used to define the events that can be triggered for each state, and at the same time, constraints are added to each event.

[0018] Based on the state transition matrix, set the state transition logic.

[0019] Furthermore, before changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic to control the ferry network to transmit data between the at least two network domains, the method further includes:

[0020] Acquire a first combination of connection states between the data ferry network and at least two network domains in the current ferry state and a second combination of connection states in the target ferry state;

[0021] Accordingly, according to the state transition logic, the connection state combination formed by the ferry network and at least two network domains is transferred from the first connection state combination to the second connection state combination, so as to control the ferry network to transmit data between the at least two network domains.

[0022] Further, the step of transferring the connection state combination formed by the ferry network and at least two network domains from the first connection state combination to the second connection state combination according to the state transition logic, so as to control the ferry network to perform data transmission between the at least two network domains, includes:

[0023] The current ferry state is monitored according to the state transition logic. If the current ferry state triggers a state transition event, the state transition is executed after verifying that the state transition process meets the constraints.

[0024] During the state transition, the connection state combination formed by the ferry network and at least two network domains is transferred from the first connection state combination to the second connection state combination, so as to control the ferry network to transmit data between the at least two network domains.

[0025] Further, the step of changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic to control the ferry network to transmit data between the at least two network domains includes:

[0026] During the process of changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, the data flow direction corresponding to the ferry network and network domains after the state transition is obtained.

[0027] The ferry network is controlled to transmit data between at least two network domains based on the data flow direction.

[0028] According to a second aspect of this application, a data transfer device is provided, comprising:

[0029] A construction unit is used to pre-construct a network topology for data ferrying. The network topology includes a set of network domains and a set of ferry networks. The set of network domains includes at least two network domains that satisfy isolation relationships. The set of ferry networks includes at least one ferry network, and a ferry network is connected to at least two network domains.

[0030] A definition unit is used to define a ferry state machine based on the network topology. The ferry state machine is a state model describing the data transmission of the ferry network between at least two network domains. The ferry state machine includes at least one ferry state and state transition logic. Each ferry state corresponds to a network connection combination. The network connection state is a combination of connection states formed by the ferry network and at least two network domains.

[0031] The control unit is configured to change the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, so as to control the ferry network to transmit data between the at least two network domains.

[0032] Further, the defining unit includes:

[0033] The first setting module is used to set at least one ferry state based on the network topology and according to the connection state combination formed by the ferry network and at least two network domains. The connection state combination includes a connected state and a disconnected state. The connected state is when the ferry network is connected to the network domain, and the disconnected state is when the ferry network is not connected to the network domain.

[0034] The second setting module is used to set state transition logic based on the network topology, according to the events that trigger state transitions during data transfer and the constraints that drive state transitions. The state transition logic executes state transitions when at least one constraint is met, based on the intent to trigger state transitions through events. The events include external events and / or internal events, and the constraints include at least one of time constraints, sequence constraints, and verification constraints.

[0035] A definition module is used to define a ferry state machine based on the at least one ferry state and the state transition logic, so that the ferry state machine controls the at least one ferry state to run sequentially during the data ferry process according to the state transition logic.

[0036] Furthermore, the first setting module is specifically used for:

[0037] Based on the combination of connection states formed by the ferry network and at least two network domains, select a valid combination of connection states that satisfies the connection state constraints, which include network domain isolation constraints and data flow constraints.

[0038] Using a predefined logical correspondence, the connection states in the effective connection state combination are converted into at least one ferry state.

[0039] Furthermore, the second setting module is specifically used for:

[0040] Based on the combination of connection states formed by the ferry network and at least two network domains, select a valid combination of connection states that satisfies the connection state constraints, which include network domain isolation constraints and data flow constraints.

[0041] Using a predefined logical correspondence, the connection states in the effective connection state combination are converted into at least one ferry state.

[0042] Furthermore, the device also includes:

[0043] The acquisition unit is configured to acquire, before the connection state combination formed by the data ferry network and at least two network domains is changed according to the state transition logic to control the data ferry network to transmit data between the at least two network domains, a first connection state combination of the data ferry network and at least two network domains in the current ferry state and a second connection state combination in the target ferry state.

[0044] Accordingly, the control unit is specifically configured to transfer the connection state combination formed by the ferry network and at least two network domains from the first connection state combination to the second connection state combination according to the state transition logic, so as to control the ferry network to perform data transmission between the at least two network domains.

[0045] Furthermore, the control unit is specifically used for:

[0046] The current ferry state is monitored according to the state transition logic. If the current ferry state triggers a state transition event, the state transition is executed after verifying that the state transition process meets the constraints.

[0047] During the state transition, the connection state combination formed by the ferry network and at least two network domains is transferred from the first connection state combination to the second connection state combination, so as to control the ferry network to transmit data between the at least two network domains.

[0048] Furthermore, the control unit is specifically used for:

[0049] During the process of changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, the data flow direction corresponding to the ferry network and network domains after the state transition is obtained.

[0050] The ferry network is controlled to transmit data between at least two network domains based on the data flow direction.

[0051] According to a third aspect of this application, a data ferry system is provided, including a ferry network, at least two network domains, and a ferry state machine; the ferry state machine is used to control the at least two network domains and the ferry system to perform the steps of the data ferry method described in the first aspect.

[0052] According to a fourth aspect of this application, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in the first aspect above.

[0053] According to a fifth aspect of this application, a readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first aspect above.

[0054] By employing the above technical solutions, this application provides a data transfer method, apparatus, system, device, and storage medium. Compared with the current method of manually operating physical storage media to achieve data transfer, this application pre-constructs a network topology for data transfer. The network topology includes a set of network domains and a set of transfer networks. The set of network domains includes at least two network domains that satisfy isolation relationships, and the set of transfer networks includes at least one transfer network. Each transfer network is communicable with at least two network domains. Based on the network topology, a transfer state machine is defined. The transfer state machine is a state model describing the data transfer of the transfer network between at least two network domains. The transfer state machine includes at least one transfer state and state transition logic. Each transfer state corresponds to a network connection combination, and the network connection state is the connection state combination formed by the transfer network and at least two network domains. The connection state combination formed by the transfer network and at least two network domains is changed according to the state transition logic to control the transfer network to perform data transfer between the at least two network domains. The entire process uses a ferry state machine to break down the data ferry flow into flexibly defined ferry states and state transitions. This ensures that only data that meets the state transition logic can be transmitted, efficiently controlling data transmission between different network domains while meeting isolation requirements. This effectively prevents data leakage and external attacks, allowing the data ferry process to quickly adapt to various complex data transmission scenarios and improve data ferry efficiency.

[0055] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0056] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0057] Figure 1 This is a flowchart illustrating a data transfer method in one embodiment of this application;

[0058] Figure 2 yes Figure 1 A flowchart illustrating a specific implementation method for step 102;

[0059] Figure 3 This is a flowchart illustrating the data transfer method in another embodiment of this application;

[0060] Figure 4 yes Figure 1 A schematic diagram of a specific implementation method for step 103;

[0061] Figure 5 This is a schematic diagram of the structure of a data transfer device in one embodiment of this application;

[0062] Figure 6 This is a schematic diagram of the device structure of a computer device provided in an embodiment of the present invention. Detailed Implementation

[0063] The invention will now be discussed with reference to several exemplary embodiments. It should be understood that these embodiments are described merely to enable those skilled in the art to better understand and thus implement the invention, and are not intended to imply any limitation on the scope of the invention.

[0064] As used herein, the term "comprising" and its variations are to be interpreted as open-ended terms meaning "including but not limited to". The term "based on" is to be interpreted as "at least partially based on". The terms "one embodiment" and "an embodiment" are to be interpreted as "at least one embodiment". The term "another embodiment" is to be interpreted as "at least one other embodiment".

[0065] In related technologies, data transfer can be performed manually between networks or systems with different security levels using physical storage media. This process primarily relies on physical isolation to prevent network attacks and is suitable for low-frequency, low-risk scenarios. For example, manually copying data between physically isolated networks using storage devices such as USB flash drives or external hard drives. However, this manual storage media transfer method depends on manual operation and cannot respond to sudden high-frequency data transfer demands, resulting in low data transfer efficiency.

[0066] To address this problem, this embodiment provides a data transfer method, such as... Figure 1 As shown, it includes the following steps:

[0067] 101. Pre-construct the network topology for data transfer.

[0068] The network topology includes a set of network domains and a set of ferry networks. The set of network domains includes at least two network domains that satisfy isolation requirements. These network domains can be internal network domains, i.e., highly secure private networks built within an enterprise or organization, typically physically or logically isolated from external public networks. They can also be external network domains, i.e., untrusted networks directly connected to public networks, facing security threats from the outside. Accordingly, the set of network domains can consist of at least two internal network domains, at least two external network domains, or at least one internal network domain and at least one external network domain.

[0069] The above set of network domains can be represented as ,in, For any network domain, arbitrary and The isolation relationship must be satisfied, meaning there is no direct connection between network domains.

[0070] The set of ferry networks includes at least one ferry network, and each ferry network is connected to at least two network domains. A ferry network can be a unidirectional data flow ferry network, meaning that data can only flow from the first network domain to the second network domain, while data cannot flow from the second network domain to the first network domain. Alternatively, a ferry network can be a bidirectional data flow ferry network, meaning that data can flow from the first network domain to the second network domain, and data can also flow from the second network domain to the first network domain. Accordingly, the set of ferry networks can consist of at least one unidirectional data flow ferry network and / or at least one bidirectional data flow ferry network.

[0071] The above set of ferry networks can be represented as in, For any ferry network, a ferry network At least two network domains must be connected to make the ferry network work. It is communicable with at least two network domains.

[0072] Understandably, at least two network domains that satisfy the isolation relationship cannot be directly connected and need to be relayed through a ferry network. For example, the set of ferry networks includes ferry network M, and the set of network domains includes network domain D1 and network domain D2. Network domain D1 cannot be directly connected to network domain D2. Instead, ferry network M is used as an intermediate bridge to connect network domain D1 and network D2 to the ferry network. In this case, ferry network M is connected to both network domain D1 and network D2.

[0073] In this example, the data ferry network topology isolates different network domains and utilizes the ferry network to achieve secure data transmission between them. This approach is suitable for scenarios with extremely high data security and isolation requirements. For example, it can be used in scenarios where strict physical isolation is required between classified and public networks, or in scenarios where controlled data exchange is needed between government networks of different security levels.

[0074] 102. Based on the network topology, define a ferry state machine.

[0075] The ferry state machine is a state model describing the data transmission of a ferry network between at least two network domains. This model controls the changing states of data transmission between different network domains, ensuring data flow complies with security policies. The ferry state machine includes at least one ferry state and state transition logic. Each ferry state corresponds to a network connection combination. The network connection state is a combination of connection states formed by the ferry network and at least two network domains. The connection state can be either on or off. For example, the ferry network may be off with both network domains, on with some network domains and off with the rest, or on with both network domains.

[0076] In this embodiment, the state transition logic is essentially a predefined triggering event for initiating the ferry state transition and the constraints driving the ferry state transition. Generally speaking, ferry state transitions need to be based on data transmission requirements and security policies.

[0077] On one hand, a state transition requires the fulfillment of a triggering event. This triggering event can be a data request, such as network domain A initiating a request to transfer a file to network domain B. It can also be a security authentication, such as network domain B completing the authentication required by network domain A. Furthermore, it can be a policy compliance check, such as whether the data content conforms to the transmission policy.

[0078] On the other hand, the transition between ferry states must satisfy constraints. These constraints can be directional constraints on data transmission. These directional constraints can be unidirectional transitions. For example, a ferry state transition controls the unidirectional transmission of data between network domain A and network domain B. That is, ferry state 1 (ferry network connected to network domain A) can switch to ferry state 2 (ferry network connected to network domain B). Ferry state 2 cannot directly switch to ferry state 1; it requires an intermediate ferry state or an independent ferry network. This directional constraint can also be a bidirectional transition. For example, a ferry state transition controls the mutual transmission of data between network domain A and network domain B. That is, ferry state 1 (ferry network connected to network domain A) can switch to ferry state 2 (ferry network connected to network domain B), and ferry state 2 can also switch back to ferry state 1. This directional constraint can also be a multi-domain cascading transfer. For example, the transfer of a ferry state controls the sequential transmission of data between network domains A, B, and C. That is, ferry state 1 (ferry network connected to network domain A) can switch to ferry state 2 (ferry network connected to network domain B), and ferry state 2 can switch to ferry state 3 (ferry network connected to network domain C). This constraint can also be a data security constraint. Here, the data security constraint requires that the ferry state transfer meet the principle of least connections. For example, in the current ferry state, only network domain A and the ferry network, and the ferry network and network domain B are allowed to be connected; other ferry networks and network domains are disconnected. In this way, the current ferry state can only realize data transmission between network domain A and network domain B. The data security constraint can also require that the ferry state transfer verify user identity or device permissions. For example, only administrators or authorized devices can switch from ferry state 1 to ferry state 2. Data security constraints here can also be data compliance constraints for state transitions. For example, if state 1 allows file transfers, then file types need to be verified, and data that violates format, content, or sensitivity levels must be prohibited from transmission. Furthermore, to better control the sequence of state transitions, this constraint can also be a state transition sequence constraint. This sequence constraint could be that during a state transition, all network domains connected to the source state's ferry network must be disconnected before establishing a new connection in the target state. For example, in Ferry State 1, the ferry network is connected to both network domain A and network domain B, with the data transmission link being network domain A - ferry network - network domain B. In Ferry State 2, the ferry network is connected to both network domain A and network domain B, with the data link being network domain B - ferry network - network domain A. When switching from Ferry State 1 to Ferry State 2, although the ferry network is connected to both network domain A and network domain B, it is necessary to first disconnect the ferry network connected to network domain A and network domain B in the source Ferry State 1, and then establish the connection between the ferry network and network domain A and network domain B in Ferry State 2.

[0079] 103. According to the state transition logic, change the connection state combination formed by the ferry network and at least two network domains to control the ferry network to transmit data between the at least two network domains.

[0080] Understandably, the state transition logic can control the switching of the ferry state and can change the combination of connection states formed by the ferry network and at least two network domains. For ferry networks and network domains in the on state, data transmission in at least one direction can be realized. For ferry networks and network domains in the off state, data transmission cannot be realized.

[0081] Taking two ferry state transition processes as an example, the network topology of data ferrying includes a ferry network, network domain 1, and network domain 2. The state transition logic is as follows: ferry state S0 transitions to ferry state S1. Specifically, in the state transition process, ferry state S0 is when the ferry network is disconnected from both network domain 1 and network domain 2, while ferry state S1 is when the ferry network is connected to network domain A. The triggering event for the state transition is a data transmission request, and the constraint condition is that the data transmission policy has been authorized. When network domain 1 and / or network domain 2 requests data transmission, it triggers the transition from ferry state S0 to ferry state S1. Then, based on the constraint condition, it is determined whether both network domain 1 and network domain 2 have passed authentication. If the constraint condition is met, it drives the transition from ferry state S0 to ferry state S1, controlling network domain A to transmit data to the ferry network.

[0082] Taking four ferry-like transition processes as an example, the network topology of data ferrying also includes a ferry network, as well as network domain 1 and network domain 2. The state transition logic is as follows: ferry state S0 transitions to ferry state S1, ferry state S1 transitions to ferry state S2, ferry state S2 transitions to ferry state S3, and ferry state S3 transitions to ferry state S4. Specifically, in the state transition process, ferry state S0 is when the ferry network and network domain 1 are in a connected state, and the ferry network and network domain 2 are in a disconnected state. The triggering event for the state transition is the transmission end response, and the constraint condition is to maintain the connection for a duration t1. When network domain 1 initiates the transmission end response and the connection duration between the ferry network and network domain 1 reaches t1, the ferry state S0 is driven to switch to ferry state S1. In the first state, the ferry network is disconnected from both network domain 1 and network domain 2. The state transition is triggered by a data transmission request, with the constraint of maintaining the disconnection for a duration of t2. When network domain 2 initiates a data transmission request and the disconnection duration reaches t2, the ferry network transitions from state S1 to state S2. In the second state, the ferry network is disconnected from network domain 1 but connected to network domain 2. The state transition is triggered by a transmission termination response, with the constraint of maintaining the connection for a duration of t3. When network domain 2 initiates a transmission termination response and the connection duration between the ferry network and network domain 2 reaches t3, the ferry network transitions from state S2 to state S3. In the third state, the ferry network is disconnected from both network domain 1 and network domain 2. The state transition is triggered by a data transmission request, with the constraint of maintaining the disconnection for a duration of t4. When either network domain initiates a data transmission request and the disconnection duration reaches t4, the ferry network transitions from state S3 to state S4. For the ferry state S4, if the data transmission request originates from network domain 1, and the constraint condition maintains the disconnection duration the same as t1, then ferry state S4 is equivalent to ferry state S0. In this case, the ferry state machine is essentially a sequential loop of state transitions formed by ferry states S0-S2-S2-S3. The order of these state transitions can be flexibly configured according to business requirements. Correspondingly, in ferry states S1 and S3, the ferry network is connected to only one network domain, ensuring that network domain A and network domain B can transmit data while maintaining isolation. Due to the constraint time setting during state transitions, the connection status between the ferry network and different network domains has timeliness. This makes data transmission and disconnection between the ferry network and different network domains controllable, greatly improving the efficiency of data ferrying.

[0083] The data transfer method provided in this application, compared with the current method of manually operating physical storage media to achieve data transfer, pre-constructs a network topology for data transfer. The network topology includes a set of network domains and a set of transfer networks. The set of network domains includes at least two network domains that satisfy isolation relationships, and the set of transfer networks includes at least one transfer network. Each transfer network is communicable with at least two network domains. Based on the network topology, a transfer state machine is defined. The transfer state machine is a state model describing the data transfer of the transfer network between at least two network domains. The transfer state machine includes at least one transfer state and state transition logic. Each transfer state corresponds to a network connection combination, and the network connection state is the connection state combination formed by the transfer network and at least two network domains. The connection state combination formed by the transfer network and at least two network domains is changed according to the state transition logic to control the transfer network to perform data transfer between the at least two network domains. The entire process uses a ferry state machine to break down the data ferry flow into flexibly defined ferry states and state transitions. This ensures that only data that meets the state transition logic can be transmitted, efficiently controlling data transmission between different network domains while meeting isolation requirements. This effectively prevents data leakage and external attacks, allowing the data ferry process to quickly adapt to various complex data transmission scenarios and improve data ferry efficiency.

[0084] In practical applications, network topology defines a set of network domains and a set of ferry networks. The set of network domains can be represented as Γ = ,in, Let the isolation relationship be R⊆Γ×Γ, at least two network domains , Satisfy: ∀ , ∈Γ, ( , )∈R⇔ and They are isolated from each other. The set of ferry networks Δ= Each ferry network Has a set of connection ports Each ferry network It also has an isolation control matrix ,in, =1, network domain With network domain In the on state, =0, network domain With network domain It is in the disconnected state.

[0085] In practical applications, a ferry state machine is essentially a cross-network transmission control model based on finite state automata theory. Its core lies in the closed loop formed by the definition of the ferry state and the state transition logic, transforming the data ferry process from an unordered set of operations into a controllable, ordered model to meet the security and compliance requirements of data transmission in network isolation environments. Specifically, for example... Figure 2 As shown, Figure 1 Step 102 in the intermediate step includes the following steps:

[0086] 201. Based on the network topology, at least one ferry state is set according to the combination of connection states formed by the ferry network and at least two network domains.

[0087] 202. Based on the network topology, state transition logic is set according to the events that trigger state transitions during data transfer and the constraints that drive state transitions.

[0088] 203. Based on the at least one ferry state and the state transition logic, define a ferry state machine so that the ferry state machine controls the at least one ferry state to run sequentially during the data ferry process according to the state transition logic.

[0089] In this embodiment, the connection state combination includes an on state and an off state. The on state is when the ferry network is connected to the network domain, and the off state is when the ferry network is not connected to the network domain. Here, the ferry network is only connected to one network domain in a single ferry state. For example, the connection state combinations formed by a ferry network and two network domains include: {ferry network disconnected from network domain 1, ferry network disconnected from network domain 2}, {ferry network connected to network domain 1, ferry network disconnected from network domain 2}, {ferry network disconnected from network domain 1, ferry network connected to network domain 2}; the connection state combinations formed by a ferry network and three network domains include: {ferry network disconnected from network domain 1, ferry network disconnected from network domain 2, ferry network disconnected from network domain 3}, {ferry network connected to network domain 1, ferry network disconnected from network domain 2, ferry network disconnected from network domain 3}, {ferry network disconnected from network domain 1, ferry network connected to network domain 2, ferry network disconnected from network domain 3}, {ferry network disconnected from network domain 1, ferry network disconnected from network domain 2, ferry network connected to network domain 3}.

[0090] Specifically, based on the combination of connection states formed by the ferry network and at least two network domains, a valid combination of connection states satisfying connection state constraints can be selected. These constraints include network domain isolation constraints and data flow constraints. Then, using predefined logical correspondences, the connection states in the valid combination of connection states are converted into at least one ferry state. The network domain isolation constraints can be set according to the network domain scenario, including group isolation constraints (e.g., dividing network domains into sending and receiving groups, with each group only allowing unidirectional communication with the ferry network), and cascading isolation (e.g., connecting multiple ferry networks in series, with each ferry network connecting only two network domains to avoid direct interaction between multiple network domains). The data flow constraints can be set for different ferry scenarios. In a unidirectional ferry scenario, a valid connection state includes data transmission from network domain A to network domain B, but not data transmission from network domain B to network domain A. In a bidirectional ferry scenario, a valid connection state includes data transmission from network domain A to network domain B, and data transmission from network domain B to network domain A.

[0091] In this embodiment, the state transition logic triggers the intention of state transition through events and executes the state transition when at least one constraint condition is met. Events include external events and / or internal events. Internal events are triggered by the user or an external system. These can be data transmission requests initiated by network domain A (e.g., clicking a button, API call), or confirmation of data reception by network domain A (e.g., button confirmation, automatic service startup). Internal events are automatically triggered by the system. These can be data reception completion (e.g., cache reaching a set threshold, file transfer completed), or scheduled task triggers (e.g., daily data synchronization at 8 AM), or verification failures (e.g., hash value mismatch, virus scan finding anomalies). It should be noted that if multiple events are triggered in combination, the state transition can be implemented using logical AND (e.g., satisfying both external request and scheduled trigger events), or logical OR (e.g., satisfying either external request or scheduled trigger event). Constraints include at least one of time constraints, sequence constraints, and verification constraints. Here, time constraints can be for transmission time, state time, etc., sequence constraints can be for the order of state transitions, and verification constraints can be for data format, data integrity, etc. It should be noted that if there are conflicting constraints, the priority of the constraints can be defined. For example, time constraints have higher priority than sequence constraints; even if the data meets the sequence constraints, if the time constraints are not met, the state transition cannot be performed.

[0092] In this way, the state transition logic can use event-driven state transitions and filter illegal operations with constraints, transforming the complex cross-network data transfer process into a verifiable finite state transition chain. This satisfies both business flexibility and ensures the security and reliability of the data transfer process through multiple constraints.

[0093] Specifically, the events that trigger state transitions during data transfer and the constraints that drive state transitions can be combined to obtain a state transition matrix. This matrix defines the allowed events for each state and adds constraints to each event. Then, state transition logic is set based on the state transition matrix. Here, the state transition matrix can be represented as a triplet of the transfer state set, event set, and constraint set. For example, the state transition matrix can be represented as follows:

[0094]

[0095] In practical applications, the ferry state machine can be represented as M = ,in, This is a set of ferry states, each corresponding to a specific connection configuration. , A collection of events, including timed events. Data arrival event Validation result events v∈{success, failure}, etc. Among these, events... For the state transition logic, here This represents an empty event; in this case, the state transition can be achieved without triggering an event, satisfying the condition. Make the ferry state When the event is triggered Driven by the ferry state Transfer to ferry status ,in, In the initial ferry state, F S is the set of termination states. For any state transition... It needs to meet the following constraints: isolation constraint, that is, any two network domains must be isolated; time constraint, that is, the transition state after the switch must remain greater than 0 for a period of time; data integrity constraint, that is, the integrity of the data must be verified during the state transition; and order constraint, that is, the order of the transition states during the state transition must be predetermined.

[0096] In practical applications, to accurately control the state combinations of connections between the ferry network and different network domains during data ferrying, further, such as... Figure 3 As shown, prior to step 103, the method further includes the following steps:

[0097] 301. Obtain the first connection state combination of the data transfer network and at least two network domains in the current transfer state and the second connection state combination in the target transfer state.

[0098] Accordingly, in step 103, the connection state combination formed by the ferry network and at least two network domains is transferred from the first connection state combination to the second connection state combination according to the state transition logic, so as to control the ferry network to transmit data between the at least two network domains.

[0099] In this embodiment, the first connection state combination in the current ferry state can be that the ferry network and network domain 1 are in an on state, and the ferry network and network domain 2 are in a disconnected state. At this time, the ferry network receives data from network domain 1. The second connection state combination in the target ferry state can be that the ferry network and network domain 1 are in a disconnected state, and the ferry network and network domain 2 are in an on state. At this time, the ferry network sends the verified data received from network domain 1 to network domain 2. This allows control over data transmission between network domain 1 and network domain 2.

[0100] It is understandable that the triggering conditions for the above state transition process can be manual, such as when the administrator issues a switching command through the console, or automatic, such as when data reception is completed, when security verification is passed, or when a set time window is reached.

[0101] Specifically, the data transfer process can be described by combining the event triggering mechanism, constraints, and the execution process of state transition. The current transfer state can be monitored according to the state transition logic. If the current transfer state triggers a state transition event, the state transition is executed after verifying that the state transition process meets the constraints. During the state transition, the connection state combination formed by the transfer network and at least two network domains is transferred from the first connection state combination to the second connection state combination to control the transfer network to transmit data between at least two network domains.

[0102] In practical applications, considering that the data flow direction can be altered during data transfer, obtaining the data flow direction can strictly limit data flow to the target network domain, allowing it to flow only unidirectionally or bidirectionally from the source network domain. This prevents unverified cross-domain data transmission and avoids the leakage of sensitive information. Specifically, for example... Figure 4 As shown, Figure 1 Step 103 includes the following steps:

[0103] 401. During the process of changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, the data flow direction corresponding to the ferry network and the network domain after the state transition is obtained.

[0104] 402. Control the ferry network to transmit data between the at least two network domains according to the data flow direction.

[0105] In this embodiment, the state transition process changes the data flow direction between the ferry network and at least two network domains. The data flow direction corresponding to the entire ferry state machine is usually pre-set before data transmission. For example, if network domain A needs to transmit data to network B, in a data ferry scenario using one ferry network, the overall data flow direction corresponding to the ferry state is network domain A → ferry network → network domain B. Alternatively, if network domain A needs to transmit data to both network B and network domain C, in a data ferry scenario using one ferry network, the overall data flow direction corresponding to the ferry state includes network domain A → ferry network → network domain B and network domain A → ferry network → network domain C. Correspondingly, the data flow direction corresponding to each ferry state in the ferry state machine, as part of the overall data flow direction, is also pre-set, but can be changed according to the actual application scenario. For example, if the current data flow direction of the ferry state is network domain A → ferry network, and the target ferry state is ferry network → network domain B, then the ferry network is controlled to transmit data from network domain A to network domain B according to the data flow direction.

[0106] Furthermore, as Figure 1-4 To specifically implement the method, this application provides a data transfer device, such as... Figure 5 As shown, the device includes: a construction unit 51, a definition unit 52, and a control unit 53.

[0107] Construction unit 51 is used to pre-construct a network topology structure for data ferrying. The network topology structure includes a set of network domains and a set of ferry networks. The set of network domains includes at least two network domains that satisfy isolation relationships. The set of ferry networks includes at least one ferry network. A ferry network is connected to at least two network domains.

[0108] Definition unit 52 is used to define a ferry state machine based on the network topology. The ferry state machine is a state model describing the data transmission of the ferry network between at least two network domains. The ferry state machine includes at least one ferry state and state transition logic. Each ferry state corresponds to a network connection combination. The network connection state is a combination of connection states formed by the ferry network and at least two network domains.

[0109] The control unit 53 is configured to change the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, so as to control the ferry network to transmit data between the at least two network domains.

[0110] The data transfer device provided in this application, compared with the current method of manually operating physical storage media to achieve data transfer, pre-constructs a network topology for data transfer. The network topology includes a set of network domains and a set of transfer networks. The set of network domains includes at least two network domains that satisfy isolation relationships, and the set of transfer networks includes at least one transfer network. Each transfer network is communicable with at least two network domains. Based on the network topology, a transfer state machine is defined. The transfer state machine is a state model describing the data transfer of the transfer network between at least two network domains. The transfer state machine includes at least one transfer state and state transition logic. Each transfer state corresponds to a network connection combination, which is a combination of connection states formed by the transfer network and at least two network domains. The connection state combination formed by the transfer network and at least two network domains is changed according to the state transition logic to control the transfer network to perform data transfer between the at least two network domains. The entire process uses a ferry state machine to break down the data ferry flow into flexibly defined ferry states and state transitions. This ensures that only data that meets the state transition logic can be transmitted, efficiently controlling data transmission between different network domains while meeting isolation requirements. This effectively prevents data leakage and external attacks, allowing the data ferry process to quickly adapt to various complex data transmission scenarios and improve data ferry efficiency.

[0111] In practical application scenarios, the defined unit includes:

[0112] The first setting module is used to set at least one ferry state based on the network topology and according to the connection state combination formed by the ferry network and at least two network domains. The connection state combination includes a connected state and a disconnected state. The connected state is when the ferry network is connected to the network domain, and the disconnected state is when the ferry network is not connected to the network domain.

[0113] The second setting module is used to set state transition logic based on the network topology, according to the events that trigger state transitions during data transfer and the constraints that drive state transitions. The state transition logic executes state transitions when at least one constraint is met, based on the intent to trigger state transitions through events. The events include external events and / or internal events, and the constraints include at least one of time constraints, sequence constraints, and verification constraints.

[0114] A definition module is used to define a ferry state machine based on the at least one ferry state and the state transition logic, so that the ferry state machine controls the at least one ferry state to run sequentially during the data ferry process according to the state transition logic.

[0115] In practical applications, the first setting module is specifically used for:

[0116] Based on the combination of connection states formed by the ferry network and at least two network domains, select a valid combination of connection states that satisfies the connection state constraints, which include network domain isolation constraints and data flow constraints.

[0117] Using a predefined logical correspondence, the connection states in the effective connection state combination are converted into at least one ferry state.

[0118] In practical applications, the second setting module is specifically used for:

[0119] Based on the combination of connection states formed by the ferry network and at least two network domains, select a valid combination of connection states that satisfies the connection state constraints, which include network domain isolation constraints and data flow constraints.

[0120] Using a predefined logical correspondence, the connection states in the effective connection state combination are converted into at least one ferry state.

[0121] In practical applications, the device further includes:

[0122] The acquisition unit is configured to acquire, before the connection state combination formed by the data ferry network and at least two network domains is changed according to the state transition logic to control the data ferry network to transmit data between the at least two network domains, a first connection state combination of the data ferry network and at least two network domains in the current ferry state and a second connection state combination in the target ferry state.

[0123] Accordingly, the control unit is specifically configured to transfer the connection state combination formed by the ferry network and at least two network domains from the first connection state combination to the second connection state combination according to the state transition logic, so as to control the ferry network to perform data transmission between the at least two network domains.

[0124] In practical applications, the control unit is further used for:

[0125] The current ferry state is monitored according to the state transition logic. If the current ferry state triggers a state transition event, the state transition is executed after verifying that the state transition process meets the constraints.

[0126] During the state transition, the connection state combination formed by the ferry network and at least two network domains is transferred from the first connection state combination to the second connection state combination, so as to control the ferry network to transmit data between the at least two network domains.

[0127] In practical applications, the control unit is further used for:

[0128] During the process of changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, the data flow direction corresponding to the ferry network and network domains after the state transition is obtained.

[0129] The ferry network is controlled to transmit data between at least two network domains based on the data flow direction.

[0130] It should be noted that other corresponding descriptions of the functional units involved in the data transfer device provided in this embodiment can be found in [reference needed]. Figures 1-4 The corresponding description in [the document] will not be repeated here.

[0131] Furthermore, as Figure 1-4 In a specific implementation of the method, this application provides a data transfer system, including a transfer network, at least two network domains, and a transfer state machine; the transfer state machine is used to control the at least two network domains and the transfer system to perform the above-described... Figures 1-4 The data transfer method shown.

[0132] Based on the above, Figures 1-4 Accordingly, this application embodiment also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the above-described method. Figures 1-4 The data transfer method shown.

[0133] Based on this understanding, the technical solution of this application can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or portable hard drive), and includes several instructions to cause a computer device (such as a personal computer, server, or network device) to execute the methods described in the various implementation scenarios of this application.

[0134] Based on the above, Figures 1-4 The method shown, and Figure 5 To achieve the above objectives, this application also provides a physical device for a data transfer method, as illustrated in the virtual device embodiment. Specifically, this device can be a computer, smartphone, tablet, smartwatch, server, or network device, etc. The physical device includes a storage medium and a processor; the storage medium stores a computer program; the processor executes the computer program to implement the above-described... Figures 1-4 The data transfer method shown.

[0135] Optionally, the physical device may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.

[0136] In an exemplary embodiment, see Figure 6 The aforementioned physical device includes a communication bus, a processor, a memory, and a communication interface. It may also include input / output interfaces and a display device. The various functional units can communicate with each other via the bus. The memory stores computer programs, and the processor executes the programs stored in the memory to perform the data transfer method described in the above embodiments.

[0137] Those skilled in the art will understand that the physical device structure for data transfer provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.

[0138] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the aforementioned data transfer device, supporting the operation of information processing programs and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software in the information processing device.

[0139] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented using software plus necessary general-purpose hardware platforms, or it can be implemented in hardware. By applying the technical solution of this application, compared with the existing methods, this application breaks down the data transfer process into flexibly defined transfer states and state transitions through a transfer state machine. In this way, only data that meets the state transition logic can be transmitted, which can efficiently control the transmission of data between different network domains while meeting isolation requirements, effectively avoiding data leakage and external attacks. This allows the data transfer process to quickly adapt to various complex data transmission scenarios and improves data transfer efficiency.

[0140] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or can be modified to be located in one or more apparatuses different from this embodiment. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.

[0141] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.

Claims

1. A data transfer method, characterized in that, include: A network topology for data ferrying is pre-constructed. The network topology includes a set of network domains and a set of ferry networks. The set of network domains includes at least two network domains that satisfy isolation relationships. The set of ferry networks includes at least one ferry network. A ferry network is connected to at least two network domains. Based on the network topology, a ferry state machine is defined. The ferry state machine is a state model describing the data transmission of the ferry network between at least two network domains. The ferry state machine includes at least one ferry state and state transition logic. Each ferry state corresponds to a network connection combination. The network connection state is a combination of connection states formed by the ferry network and at least two network domains. The state transition logic includes predefined triggering events for triggering ferry state transitions and constraints for driving ferry state transitions, which are used to control the switching of ferry states. The state transition logic is used to change the connection state combination between the ferry network and at least two network domains to control the ferry network to transmit data between the at least two network domains.

2. The method according to claim 1, characterized in that, Based on the aforementioned network topology, a ferry state machine is defined, including: Based on the network topology, at least one ferry state is set according to the combination of connection states formed by the ferry network and at least two network domains. The combination of connection states includes an on state and a off state. The on state is when the ferry network is connected to the network domain, and the off state is when the ferry network is not connected to the network domain. Based on the network topology, state transition logic is set according to the events that trigger state transitions during data transfer and the constraints that drive state transitions. The state transition logic executes state transitions when at least one constraint is met, based on the intent to trigger state transitions through events. The events include external events and / or internal events, and the constraints include at least one of time constraints, sequence constraints, and verification constraints. Based on the at least one ferry state and the state transition logic, a ferry state machine is defined such that the ferry state machine controls the at least one ferry state to run sequentially during the data ferry process according to the state transition logic.

3. The method according to claim 2, characterized in that, The step of setting at least one ferry state based on the combination of connection states formed by the ferry network and at least two network domains includes: Based on the combination of connection states formed by the ferry network and at least two network domains, select a valid combination of connection states that satisfies the connection state constraints, which include network domain isolation constraints and data flow constraints. Using a predefined logical correspondence, the connection states in the effective connection state combination are converted into at least one ferry state.

4. The method according to claim 2, characterized in that, The state transition logic is set based on the events that trigger state transitions during data transfer and the constraints that drive state transitions, including... The events that trigger state transitions during the data transfer process and the constraints that drive state transitions are combined to obtain a state transition matrix. The state transition matrix is ​​used to define the events that can be triggered for each state, and at the same time, constraints are added to each event. Based on the state transition matrix, set the state transition logic.

5. The method according to any one of claims 1-4, characterized in that, Before changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic to control the ferry network to transmit data between the at least two network domains, the method further includes: Acquire a first combination of connection states between the data ferry network and at least two network domains in the current ferry state and a second combination of connection states in the target ferry state; Accordingly, according to the state transition logic, the connection state combination formed by the ferry network and at least two network domains is transferred from the first connection state combination to the second connection state combination, so as to control the ferry network to transmit data between the at least two network domains; The step of transferring the connection state combination formed by the ferry network and at least two network domains from the first connection state combination to the second connection state combination according to the state transition logic, so as to control the ferry network to perform data transmission between the at least two network domains, includes: The current ferry state is monitored according to the state transition logic. If the current ferry state triggers a state transition event, the state transition is executed after verifying that the state transition process meets the constraints. During the state transition, the connection state combination formed by the ferry network and at least two network domains is transferred from the first connection state combination to the second connection state combination, so as to control the ferry network to transmit data between the at least two network domains.

6. The method according to any one of claims 1-4, characterized in that, The step of changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic to control the ferry network to transmit data between the at least two network domains includes: During the process of changing the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, the data flow direction corresponding to the ferry network and network domains after the state transition is obtained. The ferry network is controlled to transmit data between at least two network domains based on the data flow direction.

7. A data transfer device, characterized in that, include: A construction unit is used to pre-construct a network topology for data ferrying. The network topology includes a set of network domains and a set of ferry networks. The set of network domains includes at least two network domains that satisfy isolation relationships. The set of ferry networks includes at least one ferry network, and a ferry network is connected to at least two network domains. A definition unit is used to define a ferry state machine based on the network topology. The ferry state machine is a state model describing the data transmission of the ferry network between at least two network domains. The ferry state machine includes at least one ferry state and state transition logic. Each ferry state corresponds to a network connection combination. The network connection state is a connection state combination formed by the ferry network and at least two network domains. The state transition logic includes predefined triggering events for triggering ferry state transitions and constraints for driving ferry state transitions, used to control the switching of ferry states. The control unit is configured to change the connection state combination formed by the ferry network and at least two network domains according to the state transition logic, so as to control the ferry network to transmit data between the at least two network domains.

8. A data transfer system, characterized in that, It includes a ferry network, at least two network domains, and a ferry state machine; the ferry state machine is used to control the at least two network domains and the ferry system to perform the data ferry method according to any one of claims 1-6.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the data transfer method according to any one of claims 1 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the data transfer method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • File transmission system and method based on multi-type network isolation environment

    CN116248667A