Cross-network and cross-system data and file ferry transmission system and method
By using trusted optical disc modules and low-density network gate modules in high-density networks combined with AES encryption and audit modules, the problem of difficulty in balancing security and efficiency in cross-network and cross-system data exchange is solved, and safe and efficient data transmission and processing are achieved.
Patent Information
- Application Number
- CN202510350822.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-07-22
AI Technical Summary
Data exchange across networks and systems is difficult to balance efficiency, security and availability. The existing technology is difficult to effectively resist external network attacks and internal violations. The confidentiality levels of different networks and systems vary, and the data resource specifications are not unified and difficult to integrate.
The trusted optical disc module of the high-density zone network is used to realize offline ferry transmission, and the one-way gate module of the low-density zone network is used to realize unidirectional transmission. Combined with AES encryption and dynamic random characters to enhance password security, the first and second audit modules are introduced to record transmission logs, and the data processing efficiency is improved by using JSON formatting and serialization technology, and the modular design is adopted to ensure independent upgrade and expansion of the system.
It realizes secure and efficient data transmission between networks in different dense areas, ensures system data security and traceability, improves system transparency and data processing efficiency, reduces waiting time, and enhances the system's expansion and independent maintenance capabilities.
Smart Images

Figure CN120358229A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data processing, and particularly relates to a data and file ferry transmission system and method between different networks and systems. Background Art
[0002] With the development of business and the increasing demand for information sharing, data exchange across network domains and security zones has become increasingly frequent. While this data exchange changes network connectivity and enhances information interactivity, it also poses severe challenges to the information security and confidentiality system. The original balance state is broken, and new information security protection requirements emerge. Therefore, in data transmission, not only the feasibility and availability of the transmission method need to be considered, but also the security of the network and data.
[0003] The information ferry technology is a technology that controls data transmission through physical isolation, which can effectively resist external network attacks and internal unauthorized operations, prevent data leakage and the spread of malicious software. This technology has been widely applied in fields such as government, financial institutions, and enterprise data centers. However, the security levels, carrier networks, and deployment modes of systems between different networks and different systems within the same network vary. The specification standards of various data resources are not unified, and they are difficult to integrate due to their scattered distribution. It is very difficult to balance the efficiency, security, and availability of data transmission across different networks and systems. Summary of the Invention
[0004] The present invention provides a data and file ferry transmission system and method between different networks and systems. A secret domain communication module of a ferry module and a forwarding module is set in the high-security zone network, and a low-security zone network with an unpacking module and a packing module is set in the high-security zone network. Based on the above system, ferry transmission between different security zone networks is realized. The high-security zone to the low-security zone uses a trusted optical disc module to achieve offline ferry transmission, ensuring the security and traceability of system data; the low-security zone to the high-security zone realizes one-way transmission through a one-way network gate module. All transmissions use AES encryption, and dynamic random characters enhance the security and flexibility of the password. By introducing a first audit module and a second audit module, the transmission logs of the high- and low-security zone networks are recorded, facilitating tracking and auditing, and improving the transparency of the system. Preset transmission interfaces and regular calls are used to quickly collect and process data; JSON formatting and serialization technologies are used to improve data processing efficiency; the unpacking module and the business system cooperate efficiently to accelerate data distribution and processing. The asynchronous task mechanism reduces waiting time and improves the system response speed. The backup folder setting ensures data integrity and recoverability. Each component can be independently upgraded and maintained without affecting the overall operation, and the expandability of different security zone systems is strong.
[0005] In the first aspect of the present invention, there is provided a data and file ferry transmission system across networks and systems, including: a high-security zone network, including a secure domain communication module and several secure domain systems, where the secure domain communication module is used to obtain data files, process them to obtain secure domain data and files, and transmit them to an external network, and receive externally transmitted data and files, process them, and direct and distribute the data files to the corresponding secure domain systems, and the secure domain systems are used to transmit the processed data and files to the secure domain communication module and receive and process the data distributed by the secure domain communication module; a low-security zone network, including a service communication module and several service systems, where the service communication module is used to collect data and files to obtain service domain data and files, process and transmit the service domain data and files to the secure domain communication module, and receive the secure domain data and files and distribute them to the corresponding service systems, and the service systems are used to transmit data and files to the service communication module and receive and process the data distributed by the service communication module; a transmission transfer module is used to connect the secure domain communication module and the service communication module, and is used to transfer the secure domain data and files from the high-security zone network to the low-security zone network and the service domain data and files from the low-security zone network to the high-security zone network.
[0006] Preferably, the transmission transfer module includes a trusted optical disc module and a one-way network gateway module. The trusted optical disc module is respectively connected to the secure domain communication module and the service communication module through pluggable interfaces, and the one-way network gateway module is persistently connected to the secure domain communication module and the service communication module.
[0007] Preferably, the secure domain communication module includes a ferry module and a forwarding module, the service communication module includes an unpacking module and a packing module, and the transmission transfer module is respectively connected to the ferry module and the unpacking module through pluggable interfaces, and is used to transfer the secure domain data and files through the transmission transfer module to the unpacking module; the transmission transfer module is respectively connected to the packing module and the forwarding module to transfer the service domain data and files through the transmission transfer module to the forwarding module.
[0008] Preferably, the high-security zone network further includes a first audit module, and the low-security zone network further includes a second audit module. The first audit module and the second audit module are used to record and consult the logs of the data and file ferry transmission process.
[0009] In the second aspect of the present invention, there is provided a method for data and file ferry transmission across networks and systems, which is applied to the data and file ferry transmission system across networks and systems as described in any one of the above. The system includes a high-security zone network, a low-security zone network, and a transmission transfer module. The transmission of data and files from the high-security zone network to the low-security zone network is the first ferry transmission mode. The steps of the first ferry transmission mode include: Identify and desensitize through the secret domain system of the high-density area network to obtain the first data and files to be processed containing timestamps; Through the high-density area network, based on the first data and files to be processed, the secret domain communication module of the high-density area network obtains secret domain data and files; Through the secret domain communication module, based on the secret domain data and files, the secret domain data and files are transmitted to the transmission transfer module; Through the encryption, decryption process and transmission of the trusted optical disc module of the transmission transfer module, the unpacking module of the low-density area network obtains the secret domain data and files; The unpacking module checks and starts the task of distributing data and files based on the secret domain data and files, and the business system of the low-density area network receives and processes the corresponding data; The data and files are transmitted from the low-density area network to the high-density area network as the second ferry transmission mode. The steps of the second ferry transmission mode include: Through the business system, identify and obtain the second data and files to be processed containing timestamps; Through the low-density area network, based on the second data and files to be processed, the business communication module of the low-density area network obtains business domain data and files; Based on the business domain data and files, the secret domain communication module obtains the business domain data and files and starts the task of distributing data and files, and the secret domain system receives and processes the corresponding data; Through logging, obtain the log stream of the first audit module of the high-density area network and the log stream of the second audit module of the low-density area network based on the above process.
[0010] Preferably, the steps of obtaining secret domain data and files through the secret domain communication module of the high-density area network based on the first data and files to be processed specifically include: Several secret domain systems preset transmission interfaces and interface mapping dictionaries; The interface mapping dictionary is synchronized to the ferry module of the secret domain communication module; Through the ferry module, at a period of 1 hour, periodically call the transmission interface to obtain the first data and files to be processed; Based on the first data and files to be processed, merge and summarize to obtain the second data and files; Through data JSON formatting and serialization, obtain the secret domain data and files based on the second data and files.
[0011] Preferably, the steps of transmitting the secret domain data and files to the transmission transfer module through the secret domain communication module based on the secret domain data and files specifically include: The ferry module of the secure domain communication module triggers the secure domain data and files to be transferred to the packaged ferry module of the ferry module in the form of FTP; The mirror files of the secure domain data and files are stored in the backup folder created by the packaged ferry module with a lifecycle of 7 days; Delete the original secure domain data and files collected by the secure domain communication module; The packaged ferry module downloads the secure domain data and files to the trusted optical disc module of the transmission transfer module.
[0012] Preferably, the steps for the unpacking module to inspect and start the distribution data and file tasks based on the secure domain data and files, and for the business system in the low-security area network to receive and process the corresponding data are specifically as follows: Traverse the JSON data in the secure domain data and files, and further traverse each JSON to read the value with the key "serial" and compare it with the unpacking module's historical sequence value plus 1. If they are equal, the sequence value is incremented and updated, otherwise it terminates; The unpacking module parses the secure domain data and files into different distribution tasks and corresponding data and files according to different business identifiers; The unpacking module sorts the distribution tasks in a queue and distributes them in a first-in, first-out manner, waiting for the response of the corresponding business system; Receiving the response message from the corresponding business system triggers the unpacking module to distribute the next distribution task; The business system receives the data and performs classification processing of data addition, logical deletion, and revision through the parsed data by the identifier. When an error occurs in processing the newly added data, the data is processed according to the revision mode.
[0013] Preferably, the steps for the secure domain communication module to obtain the business domain data and files and start the distribution data and file tasks based on the business domain data and files are specifically as follows: Update the business domain data and files by adding a sequence number key-value pair; Preset a first constant with periodic changes, with a value range of 128 - 256, and the first constant is set in the high-security area network and the low-security area network; Generate a random character with a length of the first constant through the packaging module of the business communication module; Obtain the encrypted JSON data for each JSON file of the business domain data through the AES encryption algorithm; Obtain intermediate data by sequentially concatenating the random character and the JSON data; Update the intermediate data to the corresponding JSON to obtain encrypted data; The encrypted data, the service domain data, and the files in the files are transmitted to the forwarding module of the secure domain communication module through the one-way network isolation module of the transmission relay module; The encrypted data is updated based on the encrypted data by erasing characters with a length of the first constant; The service domain data and the files are obtained based on the encrypted data and the files through the AES decryption algorithm; Based on the service domain data and the files, the data and the files are distributed to the corresponding secure domain systems through the asynchronous task mechanism of the forwarding module.
[0014] Preferably, the steps of obtaining the secure domain data and the files based on the second data and the files through data JSON formatting and serialization specifically include: The ferry module initializes the sequence value, and if it already exists, increments the sequence value; The third data in JSON format is obtained based on the paging, table name, and the second data of the second data through classification; By traversing each JSON object in the third data and inserting a key-value pair with the key "serial" and the value of the sequence value in the JSON object, the fourth data is obtained; The secure domain data and the files are obtained based on the fourth data, the second data, and the files in the files through mapping; The secure domain data and the files are saved to the folder of "YYYYMMdd / HH" created by the ferry module according to the current time.
[0015] Due to the adoption of the above technical solutions, the present invention has the following advantages and positive effects compared with the prior art: Introduce multiple secure transmission mechanisms: The transmission relay module includes a trusted optical disc module and a one-way network isolation module, and different transmission strategies are implemented for different transmission directions: The data and files in the high-security area network are transmitted to the low-security area network through the trusted optical disc module to achieve offline ferry transmission, ensuring the system data security and data transmission granular traceability of the high-security area network. The data and files in the low-security area network are transmitted to the high-security area network through the one-way network isolation module to achieve one-way transmission from the low-security area network to the high-security area network; Further, whether using the trusted optical disc module or the one-way network isolation module to transmit data, data encryption is used to avoid data and file transmission risks during the transmission process. When transmitting from the low-security area network to the high-security area network, the security and flexibility of the password are enhanced by splicing random characters with a dynamic length and AES-encrypted data for decryption. The first audit module and the second audit module are introduced in the system to record and query the transmission logs of the high-security area network and the low-security area network, facilitating tracking and auditing, and improving the transparency and traceability of the system.
[0016] Efficiency improvement: By presetting the transmission interface and the interface mapping dictionary, and regularly calling the transmission interface, the rapid collection and processing of data are realized. Using JSON formatting and serialization technologies improves the efficiency and accuracy of data processing. The efficient cooperation between the unpacking module and the business system ensures the rapid distribution and processing of data.
[0017] Enhanced data security: By setting up a backup folder, the integrity and recoverability of data are ensured. The application of the asynchronous task mechanism improves the system's response speed and processing capacity, reducing the waiting time caused by synchronous operations.
[0018] Modular design: Enables each component to be independently upgraded and maintained without affecting the operation of the entire system. At the same time, the system in different security zones has strong scalability. Description of the Drawings
[0019] The following further elaborates on the specific implementation manners of the present invention in conjunction with the drawings, where: Figure 1 is a framework schematic diagram of a data and file ferry transmission system between different networks and systems in the present invention; Figure 2 is a working schematic diagram of the secure domain system and the ferry module in a method for data and file ferry transmission between different networks and systems in the present invention; Figure 3 is a process schematic diagram of data and files being transmitted from a high-security zone network to a low-security zone network in a method for data and file ferry transmission between different networks and systems in the present invention; Figure 4 is a process schematic diagram of data and files being transmitted from a low-security zone network to a high-security zone network in a method for data and file ferry transmission between different networks and systems in the present invention; Figure 5 is a process schematic diagram of obtaining secure domain data and files in a method for data and file ferry transmission between different networks and systems in the present invention; Figure 6 is a working flow chart of the packing module and the one-way network isolation module in a method for data and file ferry transmission between different networks and systems in the present invention; Figure 7 is a working flow chart of the forwarding module in a method for data and file ferry transmission between different networks and systems in the present invention. Specific Embodiments
[0020] The following further elaborates on the present invention in conjunction with the drawings and specific embodiments. According to the following description and the claims, the advantages and features of the present invention will be clearer. It should be noted that the drawings are all in a very simplified form and use non-precise ratios, only for the purpose of conveniently and clearly assisting in explaining the objectives of the embodiments of the present invention.
[0021] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the attached drawings). If the specific posture changes, the directional indication will also change accordingly.
[0022] The first embodiment See Figure 1 : The first aspect of the present invention provides a cross-network and cross-system data and file ferry transmission system, including: a high-density area network, including a secret domain communication module and several secret domain systems. The secret domain communication module is used to obtain data files, process them to obtain secret domain data and files, and transmit them to the external network, and receive the data and files transmitted externally, process them, and direct and distribute the data files to the corresponding secret domain systems. The secret domain systems are used to transmit the processed data and files to the secret domain communication module and to receive and process the data distributed by the secret domain communication module; a low-density area network, including a service communication module and several service systems. The service communication module is used to collect data and files to obtain service domain data and files, process and transmit the service domain data and files to the secret domain communication module, and to receive secret domain data and files and distribute them to the corresponding service systems. The service systems are used to transmit data and files to the service communication module and to receive and process the data distributed by the service communication module; a transmission transfer module is used to connect the secret domain communication module and the service communication module, and is used to transfer secret domain data and files from the high-density area network to the low-density area network and service domain data and files from the low-density area network to the high-density area network.
[0023] The system includes two mutually isolated high-density area networks and low-density area networks; the high-density area network includes several secret domain systems, and the low-density area network includes several service systems; in order to realize the data file communication between the secret domain systems and the service systems, system module and corresponding adaptation method designs are made. The high-density area network also includes a secret domain communication module. Further, the secret domain communication module includes a ferry module and a forwarding module. The ferry module includes an aggregation module and a packaged ferry module; the low-density area network also includes a service communication module. The service communication module includes an unpacking module and a packaging module; the transmission transfer module includes a trusted optical disc module and a one-way network gate module. Through modular design of different transmission nodes, data security and system scalability are achieved.
[0024] Continue to refer to Figure 1 , preferably, the transmission transfer module includes a trusted optical disc module and a one-way network gate module. The trusted optical disc module is respectively connected to the secret domain communication module and the service communication module through a pluggable interface, and the one-way network gate module is persistently connected to the secret domain communication module and the service communication module respectively.
[0025] The one-way network isolation module maintains persistent connectivity with the secure domain communication module and the service communication module and is unidirectional in the data transmission direction, effectively preventing security threats that may be brought about by reverse transmission. The trusted optical disc module, as a physical medium, has good isolation. When the high-security area network transmits data to the low-security area network, the data and files to be transmitted are manually triggered and written into the trusted optical disc module. The trusted optical disc module encrypts the data during the process of writing to the optical disc and stores it in the trusted optical disc. Then, through the decryption process of the trusted optical disc module, the original written data file is obtained and the data and files are transmitted to the low-security area network, achieving physical isolation between the high-security area network and the external network. At the same time, the log stream of the operation behavior is also retained, greatly reducing the risk of network attacks and ensuring the security of sensitive data during transmission.
[0026] See Figure 1 and Figure 2 , preferably, the secure domain communication module includes a ferry module and a forwarding module, the service communication module includes an unpacking module and a packing module, and the transmission transfer module is respectively connected to the ferry module and the unpacking module through a pluggable interface for transmitting secure domain data and files through the transmission transfer module to the unpacking module; the transmission transfer module is respectively connected to the packing module and the forwarding module for transmitting service domain data and files through the transmission transfer module to the forwarding module.
[0027] Optionally, the ferry module includes an aggregation module and a packed ferry module. The aggregation module is used to aggregate the data and files of the secure domain system and for transmitting the corresponding data and files to the packed ferry module. The packed ferry module receives the data and files and transmits them to the transmission transfer module.
[0028] The modular design enables the system to cooperate efficiently and enhances the scalability of the system. The different connection methods of the transmission transfer module with different modules enhance the security and controllability of data transmission.
[0029] See Figure 7 , preferably, the high-security area network further includes a first audit module, and the low-security area network further includes a second audit module. The first audit module and the second audit module are used to record and consult the logs of the data and file ferry transmission process.
[0030] The first audit module in the high-security area network and the second audit module in the low-security area network enhance data transmission monitoring, optimize management and operation and maintenance efficiency, and provide a basis for fault troubleshooting, ferry transmission performance analysis, and risk assessment.
[0031] Second Embodiment See Figure 1 , Figure 3 , Figure 4 and Figure 5, the second aspect of the present invention provides a method for cross-network and cross-system data and file ferry transmission, which is applied to the cross-network and cross-system data and file ferry transmission system of any of the above. The system includes a high-density area network, a low-density area network, and a transmission transfer module. The data and files are transmitted from the high-density area network to the low-density area network as the first ferry transmission mode. The steps of the first ferry transmission mode include: The secret domain system of the high-density area network identifies and desensitizes to obtain the first data and files to be processed with time stamps; Based on the first data and files to be processed, the secret domain communication module of the high-density area network obtains the secret domain data and files through the high-density area network; Based on the secret domain data and files, the secret domain data and files are transmitted to the transmission transfer module through the secret domain communication module; Through the encryption, decryption process and transmission of the trusted optical disc module of the transmission transfer module, the unpacking module of the low-density area network obtains the secret domain data and files; The unpacking module checks and starts the task of distributing data and files based on the secret domain data and files, and the business system of the low-density area network receives and processes the corresponding data; The data and files are transmitted from the low-density area network to the high-density area network as the second ferry transmission mode. The steps of the second ferry transmission mode include: The business system identifies and obtains the second data and files to be processed with time stamps; Based on the second data and files to be processed, the business communication module of the low-density area network obtains the business domain data and files through the low-density area network; Based on the business domain data and files, the secret domain communication module obtains the business domain data and files and starts the task of distributing data and files, and the secret domain system receives and processes the corresponding data; Based on the above process, the log streams of the first audit module of the high-density area network and the log streams of the second audit module of the low-density area network are obtained through logging.
[0032] See Figure 3 and Figure 5 , preferably, the step of the secret domain communication module of the high-density area network obtaining the secret domain data and files based on the first data and files to be processed specifically includes: A number of secret domain systems preset transmission interfaces and interface mapping dictionaries; The interface mapping dictionary is synchronized to the ferry module of the secret domain communication module; The ferry module periodically calls the transmission interface every 1 hour to obtain the first data and files to be processed; Based on the first data and files to be processed, the second data and files are merged and summarized; Based on the second data and files, the secret domain data and files are obtained through data JSON formatting and serialization.
[0033] The first ferry transmission mode is used to transfer data and files from a high-density network to a low-density network. The specific process of the first ferry transmission mode is as follows: Several secret domain systems have preset transmission interfaces and interface mapping dictionaries, and the interface mapping dictionaries are synchronized to the collection module of the ferry module of the secret domain communication module. The secret domain system identifies the data and files to be transmitted. Each piece of data in the data and files to be transmitted contains a timestamp and a synchronization identifier. The synchronization identifiers are: add, delete, and modify. The secret domain system further determines whether the data marked as deleted is a logical deletion or a physical deletion. If it is a physical deletion, the data identifier is changed to a logical deletion. The collection module of the ferry module sets a periodic task with a period of 1 hour to periodically traverse the transmission interface of each secret domain system in the high-density area network to pull data. The specific steps are that the collection module of the ferry module reads the current time, and the collection module of the ferry module uploads a time range of [currentTime.getHour-2:50:00,currentTime.getHour -1:59:59]. Obtain the first data and files to be processed; merge the first data and files to be processed obtained from different secret domain systems to obtain the second data and files. Obtain the sequence value of the ferry module, and initialize the sequence value if it does not exist; and increment the sequence value; Generate different JSON format data sets in the second data and file according to the paging and table name dimensions; the table name includes the sub-business system name and the target table name to be operated; add a pair of key-value pairs to the JSON format data set: "serial": self-incrementing sequence value; the JSON format data set is saved as a file, and the file name rule is: tableName_page number of the page.json. Based on the JSON format data set and the files in the second data and file, the secret domain data and files are obtained; the collection module of the ferry module creates a folder, and the folder name is defined by converting the current time obtained into "YYYYMMdd / HH", and the secret domain data and files are saved to the folder; The packaging and ferrying module of the ferrying module of the secret domain communication module is clicked and triggered: the secret domain data and files are transmitted to the packaging and ferrying module of the ferrying module in the form of FTP; the packaging and ferrying module of the ferrying module stores the mirror files of the secret domain data and files in the back folder, and the storage period is 7 days; deletes the secret domain data and files under the YYYYMMdd / HH file of the collection module of the ferrying module; the packaging and ferrying module downloads the secret domain data and files to the trusted CD module of the transmission transit module.
[0034] The trusted optical disc module of the transmission transit module encrypts and decrypts the process and transmits the unpacking module of the low-density area network to obtain the secret area data and files; Traverse the JSON data in the secret domain data and files, further traverse each JSON and read the value with the key value of "serial" and compare it with the historical sequence value of the unpacking module plus 1. If they are equal, the sequence value is incremented and updated, otherwise it is terminated; the unpacking module parses the secret domain data and files into different distribution tasks and corresponding data and files according to different business identifiers; the unpacking module sorts the distribution tasks according to the queue and distributes them in a first-in-first-out manner, waiting for the corresponding business system to respond; the receipt of a response message from the corresponding business system triggers the unpacking module to distribute the next distribution task; the business system receives the data and processes the parsed data through identification, logical deletion, and revision classification, and processes the data according to the revision mode when an error is reported when processing the newly added data.
[0035] The second ferry transmission mode is to transfer data and files from the low-density area network to the high-density area network. The specific steps are as follows: Obtaining the second data or file to be processed containing a timestamp and a synchronization identifier through the business system identification, where the synchronization identifier is: added, deleted, or modified; Different business systems transmit the second to-be-processed data and files to the packaging module of the business communication module to obtain the business domain data and files; The packaging module starts a periodic task with a duration of 15 minutes. The business domain data and files are serialized and encrypted and then transmitted to the forwarding module of the high-density area network. The specific steps are as follows: Get the serial value variable of the packaging module, initialize it if it does not exist, and increment the sequence value. Update a key-value pair to the business domain data and files. The key-value pair style is: "serial": auto-increment sequence value; A first constant with a preset periodic change, whose value range is 128 - 256, is set in the high-density area network and the low-density area network; a random character with a length of the first constant is generated by the packaging module of the service communication module; encrypted JSON data is obtained for each JSON file of the service domain data through the AES encryption algorithm; intermediate data is obtained by sequentially splicing based on the random character and the JSON data; the intermediate data is updated to the corresponding JSON to obtain encrypted data; the encrypted data, the service domain data, and the files in the files are transmitted to the forwarding module of the secure domain communication module through the one-way network isolation module of the transmission relay module; the encrypted data is updated based on the encrypted data by erasing characters with a length of the first constant; the service domain data and the files are obtained based on the encrypted data and the files through the AES decryption algorithm; the service domain data is verified through serialization. If the verification passes, the forwarding module triggers the verification task distribution. The specific steps are as follows: The secure domain system presets a rest receiving interface, which includes elements such as uri, input parameter specifications, and interface identifiers. The rest receiving interface is pre-registered in the forwarding module. The forwarding module traverses the service domain data and parses the forwarding tasks according to the interface identifier and timestamp, queues different tasks, and distributes tasks in a first-in, first-out manner. It judges whether there are in-transit tasks in the forwarding task module. If there are, it waits. If not, it obtains the first task in the queue and sends the distribution task according to the interface specification. After the sending is successful, it remains in the waiting state. If the secure domain system responds, the next task is executed.
[0036] The log streams of the first audit module in the high-density area network and the log streams of the second audit module in the low-density area network are obtained by recording the transmission processes based on the first ferry transmission mode and the second ferry transmission mode through logs.
[0037] See Figure 3 , preferably, the steps of implementing the transmission of secure domain data and files to the transmission relay module through the secure domain communication module based on the secure domain data and files specifically include: The ferry module of the secure domain communication module triggers the secure domain data and files to be transmitted to the packaged ferry module of the ferry module in the form of FTP; The mirror files of the secure domain data and files are stored in a backup folder created by the packaged ferry module with a lifecycle of 7 days; The original collected secure domain data and files of the secure domain communication module are deleted; The packaged ferry module downloads the secure domain data and files to the trusted optical disc module of the transmission relay module.
[0038] The steps of implementing the transmission to the transmission relay module through the secure domain communication module based on the secure domain data and files improve the transmission efficiency, stability, security, and integrity of the data and files, providing a reliable guarantee for the ferry transmission of data and files across networks and systems.
[0039] See Figure 3 , preferably, the steps for the unpacking module to verify, start the distribution of data, and file tasks based on the encrypted domain data and files, and for the business system in the low-density area network to receive and process the corresponding data specifically include: Traverse the JSON data in the encrypted domain data and files, further traverse each JSON to read the value with the key "serial" and compare it with the unpacking module's historical sequence value plus 1. If they are equal, the sequence value is incremented and updated; otherwise, it terminates; The unpacking module parses the encrypted domain data and files into different distribution tasks and the corresponding adapted data and files according to different business identifiers; The unpacking module sorts the distribution tasks in a queue and distributes them in a first-in, first-out manner, waiting for the response of the corresponding business system; Receiving the response message from the corresponding adapted business system triggers the unpacking module to distribute the next distribution task; When the business system receives data, it performs classification processing on the parsed data through identification, including addition, logical deletion, and revision. When an error occurs during the processing of new data, the data is processed according to the revision mode.
[0040] The unpacking module verifies based on the sequence value to ensure data consistency, and then distributes tasks in a first-in, first-out manner according to the queue sorting, effectively improving accuracy and efficiency. After the business system receives data, it can automatically perform classification processing, including operations such as addition, logical deletion, and revision. When an error occurs during the processing of new data, it automatically switches to the revision mode processing method to ensure the reliability of data processing. The overall process optimizes the efficiency of cross-regional data transmission and processing, and enhances the coordination and stability of the system.
[0041] See Figure 4 、 Figure 6 and Figure 7 , preferably, the steps for the encrypted domain communication module to obtain the business domain data and files based on the business domain data and files and start the distribution of data and file tasks specifically include: Update the business domain data and files by adding a serial number key-value pair; Preset a first constant with periodic changes, with a value range of 128 - 256. The first constant is set in the high-density area network and the low-density area network; Generate a random character with a length of the first constant through the packing module of the business communication module; Obtain the encrypted JSON data for each JSON file in the business domain data through the AES encryption algorithm; Obtain intermediate data by sequentially concatenating based on the random character and the JSON data; Update the intermediate data to the corresponding JSON to obtain encrypted data; The unidirectional gateway module of the transmission relay module transfers the encrypted data, service domain data, and files in the file to the forwarding module of the secure domain communication module; Update the encrypted data by erasing characters of a first constant length based on the encrypted data; Obtain the service domain data and files based on the encrypted data and the file through the AES decryption algorithm; Implement the distribution of the data and files to the corresponding secure domain systems based on the service domain data and files through the asynchronous task mechanism of the forwarding module.
[0042] Through steps such as preset constants, random character generation, AES encryption, data splicing, secure transmission, character erasure, data decryption, and asynchronous distribution, the efficient and secure processing and distribution of service domain data and files in the secure domain communication module are realized. It ensures the security and confidentiality of data and file transmission, and also ensures the efficient transmission of data and files to the corresponding secure domain systems.
[0043] See Figure 3 and Figure 5 , preferably, the steps of obtaining the secure domain data and files based on the second data and files through data JSON formatting and serialization specifically include: The ferry module initializes the sequence value, and if it already exists, increments the sequence value; Obtain the third data in JSON format based on the paging, table name, and second data of the second data through classification; Traverse each JSON object in the third data, and insert a key-value pair with the key "serial" and the value being the sequence value into the JSON object to obtain the fourth data; Obtain the secure domain data and files based on the fourth data, the second data, and the files in the file through mapping; Save the secure domain data and files to the folder of "YYYYMMdd / HH" created by the ferry module according to the current time.
[0044] Through the initialization of the sequence value of the ferry module (incrementing to ensure uniqueness), classification based on the paging and table name of the second data and JSON formatting to generate the third data, traversing and inserting the "serial" key-value pair to obtain the fourth data, mapping to generate the secure domain data and files, and finally creating a folder according to the current time for saving, the orderly generation and management of the secure domain data and files are realized, improving the data and file processing efficiency and traceability.
[0045] In the description of the present application, it should be noted that the orientation or positional relationship indicated by terms such as "inner" and "outer" is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of this application is usually placed during use. It is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present application. In addition, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0046] It should also be noted that unless otherwise clearly specified and defined, the terms "arrangement" and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be directly connected, or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.
[0047] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific identification content executed by the above-described system and device can refer to the corresponding process in the foregoing method embodiments.
[0048] The embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings, but the present invention is not limited to the above embodiments. Even if various changes are made to the present invention, provided that these changes fall within the scope of the claims of the present invention and their equivalent technologies, they still fall within the protection scope of the present invention.
Claims
1. A data and file ferry transmission system across networks and systems, characterized in that Comprising: A high-security area network, including a secure domain communication module and a number of secure domain systems. The secure domain communication module is used to obtain encrypted domain data and files through data file processing, transmit them to an external network, receive externally transmitted data and files for processing, and direct and distribute data files to the corresponding secure domain systems. The secure domain systems are used to transmit processed data and files to the secure domain communication module and to receive and process the data distributed by the secure domain communication module; A low-security area network, including a service communication module and a number of service systems. The service communication module is used to collect data and files to obtain service domain data and files, process and transmit the service domain data and files to the secure domain communication module, and to receive the encrypted domain data and files and distribute them to the corresponding service systems. The service systems are used to transmit data and files to the service communication module and to receive and process the data distributed by the service communication module; A transmission transfer module is used to connect the secure domain communication module and the service communication module, and is used for transmitting the encrypted domain data and files from the high-security area network to the low-security area network and the service domain data and files from the low-security area network to the high-security area network.
2. The cross-network and cross-system data and file ferry transmission system according to claim 1, characterized in that, The transmission transfer module includes a trusted optical disc module and a one-way network gateway module. The trusted optical disc module is respectively connected to the secure domain communication module and the service communication module through a pluggable interface, and the one-way network gateway module is persistently connected to the secure domain communication module and the service communication module.
3. The data and file ferry transmission system across networks and systems according to claim 1, characterized in that The secure domain communication module includes a ferry module and a forwarding module. The service communication module includes an unpacking module and a packing module. The transmission transfer module is respectively connected to the ferry module and the unpacking module through a pluggable interface, and is used to transmit the encrypted domain data and files through the transmission transfer module to the unpacking module; the transmission transfer module is respectively connected to the packing module and the forwarding module to transmit service domain data and files through the transmission transfer module to the forwarding module.
4. The cross-network and cross-system data and file ferry transmission system according to claim 1, wherein The high-security area network further includes a first audit module, and the low-security area network further includes a second audit module. The first audit module and the second audit module are used to record and review the logs of the data and file ferry transmission process.
5. A method for cross-network and cross-system data and file ferry transmission, which is applied to the cross-network and cross-system data and file ferry transmission system described in any one of claims 1-4. The system includes a high-density area network, a low-density area network, and a transmission transfer module, and is characterized in that, The transmission of data and files from the high-security area network to the low-security area network is the first ferry transmission mode. The steps of the first ferry transmission mode include: The secure domain systems in the high-security area network identify and desensitize to obtain the first data and files to be processed with timestamps; Based on the first data and files to be processed, the secure domain communication module in the high-security area network obtains encrypted domain data and files; Based on the encrypted domain data and files, the secure domain communication module transmits the encrypted domain data and files to the transmission transfer module; Through the encryption, decryption process and transmission of the trusted optical disc module of the transmission transfer module, the unpacking module in the low-security area network obtains the encrypted domain data and files; The unpacking module checks and starts to distribute data and file tasks based on the encrypted domain data and files, and the service systems in the low-security area network receive and process the corresponding data; The transfer of data and files from the low-security network to the high-security network is the second ferry transfer mode, and the steps of the second ferry transfer mode include: Obtaining the second data and files to be processed with timestamps through the recognition of the business system; Based on the second data and files, the business communication module of the low-security network obtains business domain data and files through the low-security network; Based on the business domain data and files, the secure domain communication module obtains the business domain data and files and starts the task of distributing data and files, and receives and processes the corresponding data through the secure domain system; Based on the above process, the log streams of the first audit module of the high-security network and the log streams of the second audit module of the low-security network are obtained through log recording; 6. A method for cross-network and cross-system data and file ferry transmission according to claim 5, characterized in that, The steps for the secure domain communication module of the high-security network to obtain secure domain data and files based on the first data and files to be processed specifically include: A number of the secure domain systems preset transmission interfaces and interface mapping dictionaries; The interface mapping dictionary is synchronized to the ferry module of the secure domain communication module; The ferry module periodically calls the transmission interface every 1h to obtain the first data and files to be processed; Based on the first data and files to be processed, the second data and files are obtained through merging and summarization; Based on the second data and files, the secure domain data and files are obtained through data JSON formatting and serialization; 7. A method for cross-network and cross-system data and file ferry transmission according to claim 5, characterized in that The steps for the secure domain communication module to transfer the secure domain data and files to the transmission transfer module based on the secure domain data and files specifically include: The ferry module of the secure domain communication module triggers the secure domain data and files to be transferred to the packaged ferry module of the ferry module in FTP form; The mirror files of the secure domain data and files are stored in the backup folder created by the packaged ferry module with a lifecycle of 7 days; The original collected secure domain data and files of the secure domain communication module are deleted; The packaged ferry module downloads the secure domain data and files to the trusted optical disc module of the transmission transfer module; 8. A method for cross-network and cross-system data and file ferry transmission according to claim 5, characterized in that The steps for the unpacking module to inspect and start the task of distributing data and files based on the secure domain data and files, and for the business system of the low-security network to receive and process the corresponding data specifically include: Traverse the JSON data in the secure domain data and files, and further traverse each JSON to read the value with the key "serial" and compare it with the unpacking module's historical sequence value plus 1. If they are equal, the sequence value is incremented and updated, otherwise it terminates; The unpacking module parses the secure domain data and files into different distribution tasks and adapted data and files according to different business identifiers; The unpacking module sorts the distribution tasks in a queue and distributes them in a first-in, first-out manner, waiting for the response of the corresponding business system; Receiving the response message of the adapted business system triggers the unpacking module to distribute the next distribution task; When the business system receives data, it performs classification processing of data addition, logical deletion, and revision through identifier pair parsing. When an error occurs during the processing of new data, the data is processed in the revision mode.
9. A method for cross-network and cross-system data and file ferry transmission according to claim 5, characterized in that The steps of implementing the secure domain communication module based on the service domain data and files to obtain the service domain data and files and start the data and file distribution tasks specifically include: Updating the service domain data and files by adding a sequence number key-value pair; Presetting a first constant with periodic changes, whose value range is 128 - 256, and the first constant is set in the high-security area network and the low-security area network; Generating a random character with a length of the first constant through the packaging module of the service communication module; Obtaining encrypted JSON data for each JSON file of the service domain data through the AES encryption algorithm; Obtaining intermediate data by sequentially splicing based on the random character and the JSON data; Updating the intermediate data to the corresponding JSON to obtain encrypted data; Transmitting the encrypted data and the files in the service domain data and files to the forwarding module of the secure domain communication module through the one-way network isolation module of the transmission relay module; Updating the encrypted data by erasing characters with a length of the first constant based on the encrypted data; Obtaining the service domain data and files based on the encrypted data and the files through the AES decryption algorithm; Implementing the distribution of data and files to the corresponding secure domain systems based on the service domain data and files through the asynchronous task mechanism of the forwarding module.
10. A method for cross-network and cross-system data and file ferry transmission according to claim 6, characterized in that The steps of obtaining the secure domain data and files based on the second data and files through data JSON formatting and serialization specifically include: Initializing the sequence value of the ferry module, and incrementing the sequence value if it already exists; Obtaining third data in JSON format by classifying the paging, table name of the second data, and the second data; Obtaining fourth data by traversing each JSON object in the third data and inserting a key-value pair with the key "serial" and the value being the sequence value into the JSON object; Obtaining the secure domain data and files based on the fourth data, the second data, and the files in the second data and files through mapping; Saving the secure domain data and files to the folder of "YYYYMMdd / HH" created by the ferry module according to the current time.
Citation Information
Cited By
Data security exchange method in cross-network environment
CN120614207A