File security sharing method and system based on database internal and external network isolation device

By adopting a security architecture of file encryption and key separation in the internal and external network isolation device, the poor realization and storage risks of file sharing in the internal and external networks are solved, and efficient and secure file sharing is achieved, which is suitable for high isolation requirements such as government and military industry.

CN120372649APending Publication Date: 2025-07-25ZHANGYE POWER SUPPLY COMPANY OF STATE GRID GANSU ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510455648.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, file sharing in the internal and external networks is poor, there is a risk of file storage on the external network being out of the library, and relying on the database leads to low data transmission efficiency, which cannot effectively solve the problem of large file storage.

Method used

Using an asymmetric security architecture separated from file encryption and key management, the files are split and stored in a strong isolation proxy database through the internal and external network isolation device. The external network system obtains and decrypts files through specific drivers to ensure that the key is not synchronized to the external network with the data. Combined with asynchronous instruction triggering and boundary authentication mechanisms, incremental synchronization and instruction-based decoupling access is achieved.

Benefits of technology

It significantly improves file confidentiality and real-timeness in cross-net environments, avoids the risk of plain text data and keys being stored in the same domain, meets the requirements of high-level data compliance and forensics, and ensures the security and compliance of file sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372649A_ABST
    Figure CN120372649A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of database intranet and extranet isolation devices, and discloses a file security sharing method and system based on a database intranet and extranet isolation device. Intranet files are safely and efficiently synchronized to an extranet to be directly accessed by extranet users, the problem that the intranet files cannot be shared or are shared inefficiently is solved, meanwhile, the files stored in the extranet are encrypted by using a randomly generated encryption key, one file has one key, the keys are stored in an intranet isolation device, the files and the keys are separately stored, and the storage efficiency is improved. The problems that file extranet storage is unsafe, and library separation risks exist are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to, but is not limited to, the technical field of database internal and external network isolation devices, and particularly relates to a method and system for secure file sharing based on a database internal and external network isolation device. Background Art

[0002] There are many strong isolation devices based on relational databases on the market currently. The data transmission between the internal and external networks of this device is established on the reading and writing of multiple databases. The external network can only connect to the proxy database in the internal network through a specific encryption protocol, and realizes the secure sharing of internal and external network data through the reading and writing of data.

[0003] SHA256 is a cryptographic hash function algorithm, which is a method of creating a small digital "fingerprint" from any kind of data. The hash function compresses the message or data into a digest, making the data volume smaller and fixing the data format. This algorithm shuffles and mixes the data and re-creates a fingerprint called a hash value (or hash value). For data of any length, SHA256 will generate a hash value of 256 bits. A tiny change in the data will result in a different hash value, and it often has the function of verifying data integrity.

[0004] The full name of the AES encryption algorithm is Advanced Encryption Standard, which is one of the most common symmetric encryption algorithms and is often used for the fast encryption and decryption of data.

[0005] The RSA algorithm is an asymmetric encryption algorithm. Data encryption and decryption require a pair of keys (public key, private key) to cooperate. Only one key can be used to decrypt the data encrypted by the other key. The encryption and decryption are asymmetric. It is extremely difficult to crack the encrypted data or it cannot be cracked with current technology, and it has high security for data encryption.

[0006] In existing requirements, in many cases, large companies have their own internal networks, and many materials are stored in the internal network or operated in the internal network. The external network cannot store some materials. In most cases, employees need to access the materials stored in the internal network in a working environment without an internal network. The restrictions of the internal network prevent employees from accessing or accessing through media or paper materials. Accessing through media or paper has problems such as uncontrollable data security and inconvenient access.

[0007] In view of the above analysis, the technical problems that urgently need to be solved in the prior art are:

[0008] (1) Most of the existing system files do not have internal and external network file sharing, or realize the internal and external networks through manual file copying via storage media. The current method has poor file sharing implementation and is powerless for large-scale data systems. At the same time, storing files on the external network has risks such as database disconnection.

[0009] (2) Some systems access through the database of the isolation device. The files of the internal and external network systems are stored on the database, and the files are obtained through data query during reading. The current method overly relies on the database, and the data access is prone to reach the database I / O bottleneck, affecting the user experience of the system. At the same time, there is an upper limit on the size of data stored in a single field of the database, and large files cannot be stored. Summary of the Invention

[0010] Aiming at the problems existing in the prior art, the present invention provides a method and system for secure file sharing based on a database internal and external network isolation device.

[0011] The present invention is implemented as follows. A method for secure file sharing based on a database internal and external network isolation device, characterized in that the method for secure file sharing based on a database internal and external network isolation device specifically includes:

[0012] S1: After the internal network user uploads and archives the file, it triggers the file synchronization of the internal network system and encrypts the file;

[0013] S2: Split the encrypted file, split it into a specified size and sign it, and then store the file shards in the strongly isolated proxy database in the split order, and generate a file synchronization instruction and store it in the instruction table;

[0014] S3: The external network system polls the instruction table to obtain the file synchronization instruction data;

[0015] S4: The external network user issues a request to read a specified file. The external network system obtains the file information from the isolation device proxy database securely through a specific driver according to the user's needs;

[0016] S5: According to the file information, the external network system obtains the encrypted file in the external network file storage system, obtains the AES encryption key according to the file information, and the external network system decrypts the encrypted file with AES and returns it to the external network user.

[0017] Further, in S1, the internal network system randomly generates a random AES key; uses the key to perform AES symmetric encryption on the file; performs a signature digest on the encrypted file (performs a hashing operation (SHA256)); stores the encrypted file information (key) in the proxy database of the strongly isolated system.

[0018] Further, in step S3, the read file synchronization instruction data is marked as being in synchronization and the synchronization timeout duration; according to the data in the synchronization instruction, the file fragment data is read and the completeness verification is performed; the files are pieced together according to the file order and the file completeness is verified; the synchronization instruction data is deleted, and the file fragment data is deleted; the update information data is updated, the file is marked as having been synchronized, and the external network file storage location information is stored.

[0019] Another object of the present invention is to provide a file secure sharing system based on a database internal and external network isolation device, which specifically includes:

[0020] An internal network system for storing, archiving, and encrypting files;

[0021] An isolation device for storing keys;

[0022] An external network system for decrypting the encrypted file and returning it to the external network user.

[0023] Combined with the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solutions to be protected by the present invention are:

[0024] Through the asymmetric security architecture design that separates file encryption from key management, the present invention significantly improves the confidentiality of files in a cross-network environment. The system adopts the strategy of "one key per file", and all keys are randomly generated by the internal network key management module (KMS) and encapsulated and stored in a strong isolation area, without being synchronized to the external network along with the encrypted data, avoiding the systematic leakage risk caused by the co-domain storage of "plaintext data + plaintext key". This architecture meets the compliance requirements of "physical isolation + dynamic key" for critical data in "Grade Protection 2.0", and is one of the core mechanisms for solving the problem of secure sharing in an internal and external network isolation environment.

[0025] Traditional internal and external network file synchronization relies on offline copying or FTP gateway transmission, which has problems such as low efficiency and inconsistent data versions. This solution uses a strong isolation proxy database to build a one-way path, and through the data splitting and polling scheduling mechanism, it avoids the security vulnerabilities caused by two-way communication. Without the awareness of external network users, the system realizes incremental synchronization of files and command decoupled access, greatly improving the real-time performance and system maintainability of cross-domain file sharing, and is applicable to the document service requirements in scenarios with high isolation requirements such as government, military, and power.

[0026] Through encrypted file sharding and signature addition, multi-channel integrity verification, and full-process access instruction logging, this system constructs a "chain audit" mechanism from archiving, transmission to external network access, ensuring that each access can be traced back to the original operation subject and timestamp. At the same time, combined with asynchronous instruction triggering and boundary authentication mechanisms, it effectively curbs typical threat scenarios such as unauthorized pulling and replay attacks, realizes a double closed-loop of compliance audit and technical protection, and meets the high-level data compliance and forensics requirements.

[0027] During the whole process of decrypting encrypted files at the external network end, the present invention introduces a sandbox execution environment and temporary-state memory decryption technology to ensure that the decrypted plaintext data only resides in a controlled buffer, is immediately destroyed after file processing, and the encryption key does not fall to disk and cannot be exported. This design fully follows the principle of "minimum residence time + minimum exposure surface", effectively preventing the risk of plaintext leakage caused by unexpected paths such as operating system caches and disk residues. While strengthening the security of file use, it realizes an engineering balance between performance and security. Brief Description of the Drawings

[0028] Figure 1 is a flowchart of a method for secure file sharing based on a database internal and external network isolation device provided by an embodiment of the present invention;

[0029] Figure 2 is a system architecture diagram of secure file sharing based on a database internal and external network isolation device provided by an embodiment of the present invention. Detailed Embodiments

[0030] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0031] As Figure 1 shown, an embodiment of the present invention provides a method for secure file sharing based on a database internal and external network isolation device, which specifically includes:

[0032] S1: After an internal network user uploads a file for archiving, it triggers file synchronization of the internal network system and encrypts the file;

[0033] S2: Split the encrypted file, split it into a specified size and sign it, and then store the file shards in a strongly isolated proxy database in the split order, generate a file synchronization instruction and store it in the instruction table;

[0034] S3: The external network system polls the instruction table to obtain file synchronization instruction data;

[0035] S4: The external network user sends a request to read a specified file. The external network system securely obtains file information from the proxy database of the isolation device through a specific driver according to the user's needs.

[0036] S5: According to the file information, the external network system obtains the encrypted file in the external network file storage system, obtains the AES encryption key according to the file information, decrypts the encrypted file by the external network system using AES, and returns it to the external network user.

[0037] In the intranet environment, the file archiving operation starts the file synchronization process through the application system event trigger mechanism. The archived file is first encrypted by the AES-256 symmetric encryption algorithm. The encryption key is dynamically generated by the intranet key management service (KMS) and bound to the user access context to prevent the exposure of plaintext data before transmission. This operation adopts a full-volume encryption strategy and combines file metadata for hash signature to ensure that data blocks are traceable and the integrity is verifiable in subsequent sharding operations, strengthening the anti-tampering ability in the transmission link.

[0038] The encrypted file is sharded by a splitting algorithm (such as a fixed block size or content recognition demarcation). Each piece is signed and marked with an ordered index, and then written into a strongly isolated proxy database (such as an intermediate jump area database) deployed at the boundary between the internal and external networks. Such a database ensures that intranet data only flows outwards and there is no reverse access path through a type of one-way channel access policy (such as cutting off the two-way data channel and privileged SQL proxy). At the same time, each write operation generates a synchronization instruction containing key parameters such as file index, encryption method, and check digest. This instruction is written into the instruction table of the database and serves as the access index for external network reading.

[0039] The external network system does not have direct query permission for the intranet database, but accesses the instruction table of the isolation database in an asynchronous polling manner. When a new instruction appears, the external network system parses its metadata content and automatically triggers the process of pulling file fragments. Through a configured specific file proxy driver (such as based on a custom FUSE or NIO transport channel), reads each encrypted file fragment in index order, avoids the high-concurrency transmission pressure caused by direct whole-file transmission, and performs integrity verification on each fragment to prevent data injection or contamination risks in the middleware storage layer.

[0040] After an external network user submits an access request, the system schedules the access key control module based on the request context (such as user identity credentials and access privilege identifiers), securely obtains the bound AES key from the key service interface, and completes data splicing and decryption in combination with the previously pulled encrypted shards. The decryption operation is completed in a sandbox environment or temporary memory to ensure that the key and plaintext data are not written to disk or cached, preventing the risks of key leakage and secondary reuse. Finally, the user obtains read-only access rights to the target file in the external network system, forming a full-process closed-loop file security sharing mechanism of "encryption - splitting - isolated storage - instruction scheduling - decryption access".

[0041] In S1, the internal network system randomly generates a random AES key; uses the key to perform AES symmetric encryption on the file; performs a signature digest on the encrypted file (performs a hashing operation (SHA256)); stores the encrypted file information (key) in the proxy database of the strongly isolated system.

[0042] In S3, mark the read file synchronization instruction data as being synchronized and the synchronization timeout duration; according to the data in the synchronization instruction, read the file fragment data and perform a completeness check; piece together the files according to the file order and check the file completeness; delete the synchronization instruction data and delete the file fragment data; update the update information data, mark that the file has been synchronized, and store the external network file storage location information.

[0043] As Figure 2 shown, a file security sharing system based on a database internal and external network isolation device provided by an embodiment of the present invention specifically includes:

[0044] An internal network system, used for file storage, archiving, and encryption;

[0045] An isolation device, used for storing keys;

[0046] An external network system, used for decrypting the encrypted file and returning it to the external network user.

[0047] The internal network system of this system is responsible for file storage, archiving, and secure encryption. After an internal network user uploads a file, the system randomly generates an AES key to perform AES symmetric encryption on the file, and at the same time calculates the SHA-256 hash digest of the file to ensure file integrity. The encrypted file is split into multiple fragments of a specified size, each fragment is attached with a unique digital signature, and they are stored in the strongly isolated proxy database in the splitting order. At the same time, a file synchronization instruction is generated, recording the encryption key, file storage location information, and synchronization status.

[0048] To ensure the physical security isolation between the internal and external networks, this system uses a strong isolation proxy database as an intermediate storage area. All file transfers are controlled by security instructions to avoid direct access to file data. The external network system polls the file synchronization instruction table in the proxy database. When a new synchronization task is detected, the external network system reads the file fragment data and performs an integrity check (comparing the SHA-256 signature) simultaneously. After all file fragments are successfully read, the external network system assembles the file in sequence. After confirming data consistency, it deletes the synchronization instruction data and file fragment data, and updates the external network file storage location information to ensure the integrity and security of the data.

[0049] When an external network user needs to access a file, they first initiate a file read request to the external network system. The external network system obtains the encrypted file data from the storage system and the corresponding AES encryption key from the isolation device proxy database. Since the AES key is always stored in a strongly isolated secure environment and is securely called through a specific driver, external network users cannot directly access the key. The external network system uses the security key to perform AES decryption and returns the decrypted original file to the external network user to ensure that the data is not exposed or leaked during the decryption process.

[0050] The system adopts a strict access permission control mechanism. All operations are authenticated and logged to ensure that only authorized users can access and operate on files. At the same time, the external network system sets a synchronization timeout duration. If the file fails to complete synchronization within the specified time, the system will automatically interrupt the synchronization process and send a security alert to the management end to prevent data leakage or abuse. In addition, the isolation device adopts multiple security protection measures, including data integrity verification, prevention of unauthorized key reading, and real-time monitoring of abnormal access, to ensure the data security and protection capabilities of the entire system.

[0051] Through the separation of the internal and external networks, a strong isolation database, AES encryption, and a secure synchronization mechanism, the present invention realizes efficient and secure file sharing while ensuring data security, providing a reliable data sharing solution for enterprises or government agencies in an internal and external network isolation environment.

[0052] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated designed hardware. Those of ordinary skill in the art can understand that the above devices and methods can be implemented using computer-executable instructions and / or included in processor control code, for example, such code is provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and their modules of the present invention can be implemented by hardware circuits of programmable hardware devices such as very large scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, or can be implemented by a combination of the above hardware circuits and software such as firmware.

[0053] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall all be covered by the protection scope of the present invention.

Claims

1. A file security sharing method based on an internal and external network isolation device for a database, characterized in that, It includes the following steps: S1: The intranet user uploads a file and performs AES symmetric encryption on the file; S2: The encrypted file is split, the split file fragments are signed, and stored in the isolation device proxy database in the split order. At the same time, a file synchronization instruction is generated and stored in the instruction table; S3: The external network system polls the instruction table, obtains the file synchronization instruction, and obtains the file fragment data according to the instruction; S4: The external network user issues a file reading request, and the external network system obtains the encrypted file information from the isolation device proxy database through a specific driver based on the instruction information; S5: The external network system obtains the encrypted file from the external network storage system, obtains the AES key for decryption, and returns the file data to the external network user after decryption; S6: After the file synchronization is completed, the corresponding synchronization instruction data in the instruction table is deleted, and the synchronized file fragment data is deleted.

2. The method according to claim 1, wherein In S1, the intranet system randomly generates an AES key, uses the key to perform AES encryption on the file, and calculates the SHA-256 hash value of the file and stores it in the isolation device proxy database.

3. The method according to claim 1, characterized in that In S2, the split file fragments are marked with unique identifiers and stored in the isolation device proxy database in order. At the same time, synchronization status information is generated to indicate the storage status of the file fragments.

4. The method according to claim 1, characterized in that, In S3, after the external network system obtains the file synchronization instruction data, it performs integrity verification on the file fragment data and marks the file synchronization status based on a preset synchronization timeout duration.

5. The method according to claim 1, characterized in that, In S4, based on the access request of the external network user, the external network system reads the file information through a specific interface of the isolation device, and obtains the corresponding file data after verifying the user identity based on the access permission.

6. The method according to claim 1, wherein In S5, the external network system decrypts the encrypted file using the AES key, deletes the key temporary storage data after decryption is completed, and returns the decrypted file data to the external network user.

7. The method according to claim 1, wherein In S6, after the file synchronization is completed, the file fragment data in the isolation device proxy database is deleted. At the same time, the file synchronization status information in the instruction table is updated, and the file synchronization is marked as completed.

8. A file security sharing system based on an internal and external network isolation device for a database, characterized in that, It includes: An intranet encryption module, which is used to receive the original file uploaded by the intranet user, generate a random AES key to encrypt the file, and calculate the SHA-256 hash value of the file; A file splitting and instruction generation module, which is used to perform data sharding on the encrypted file, sign each shard and assign a unique identifier, store the file fragments in the isolation device proxy database in the splitting order, and generate a file synchronization instruction containing synchronization information and write it into the instruction table; An external network polling and fragment pulling module, which is used for the external network system to periodically poll the instruction table, obtain the synchronization instruction, pull the encrypted file fragments from the isolation device proxy database according to the instruction content, and complete integrity verification and status marking; An external network file decryption module, which is used for the external network system to call the corresponding AES key for decryption operation after obtaining the complete file, clear the key cache after decryption is completed, and return the plaintext data to the external network user; The data cleaning and synchronization status management module is used to delete the corresponding file fragments and synchronization instruction data and update the synchronization completion status flag after the file is successfully synchronized.

9. The system according to claim 8, wherein The intranet encryption module includes a key generation unit and an encryption processing unit. The key generation unit is used to generate a one-time AES symmetric key for each uploaded file. The encryption processing unit encrypts the file based on the key and generates digest information. The digest information and the key are both stored in the isolation device proxy database and establish an associated mapping relationship with the file fragments.

10. The system according to claim 8, characterized in that, The extranet file decryption module includes a permission verification unit and a key invocation unit. The permission verification unit is used to authenticate the identity and verify the access permission of the file access request of the extranet user. The key invocation unit is used to call the corresponding AES key from the secure channel of the isolation database after the permission verification is passed and decrypt the encrypted file.