Cross-network data automatic import method and system for physically isolated networks

By using an automatic cross-network data import method, the automatic filtering, encryption, and distribution of cross-network data are achieved, solving the problems of low efficiency and poor security in traditional cross-network data import, improving data transmission efficiency and security, and supporting efficient collaboration between enterprises.

CN120614193BActive Publication Date: 2026-03-31SHIP INFORMATION RES CENT (NO 714 RES INST OF CHINA STATE SHIPBUILDING CORP) +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-03
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Traditional cross-network data import technologies cannot meet the high requirements of modern enterprises for data transmission efficiency and security. They rely on manual operation, which is inefficient and poses security risks. Optical disc transfers have poor real-time performance, low data capacity, and high costs.

Method used

The system employs an automatic cross-network data import method, which involves automated processing at the input, detection, and distribution ends, including data filtering, encryption, storage, and distribution. It uses a transfer device for USB flash drive transfer and introduces encryption and virus/Trojan detection mechanisms to ensure data security and integrity.

Benefits of technology

It improves data transmission efficiency, ensures data security and reliability, avoids the risk of oversight and mis-sending caused by human operation, supports data transfer between different networks and business systems, and has good compatibility and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614193B_ABST
    Figure CN120614193B_ABST
Patent Text Reader

Abstract

The application discloses a cross-network data automatic import method and system of a physically isolated network, which is used for relieving human labor from simple and repetitive information collection work by automatically performing data downloading, automatically packing, encrypting and storing data into a U disk, and tracking the whole process of the data, so that the imported data can be traced back. The U disk is transferred by using a physically isolated U disk transfer mechanism, so that the safety of the data is guaranteed at the physical level. In the killing stage, the U disk data packet is automatically read, and the decryption and killing process is strictly performed, so that errors caused by personnel operation are avoided, and the compliance of the process is ensured. In the distribution stage, the application result is strictly matched, so that the data can be accurately sent to the specified target user, the error of data misdelivery is reduced, and there is no data leakage risk. End-to-end data verification is performed without personnel participation, and there is no data tampering risk. In addition, the method also supports data transfer between different networks and business systems, and has good compatibility and expansibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of automatic cross-network data import technology for physically isolated networks, and in particular to a method and system for automatic cross-network data import for physically isolated networks. Background Technology

[0002] With the rapid advancement of information technology and networking, cross-network data transmission has become a crucial aspect of daily operations for modern enterprises and organizations. However, in certain scenarios, especially in applications involving high security and confidentiality, physically isolated networks remain the best option for ensuring data security. Within these physically isolated networks, achieving efficient and automated data transmission and import while ensuring data security and compliance has become a pressing technical challenge.

[0003] Currently, cross-network data import between most physically isolated networks still relies on manual operation. Traditional manual methods are not only labor-intensive and inefficient, but also prone to errors due to human error, potentially leading to serious security risks such as data leaks. Furthermore, traditional data import methods, such as CD-ROM transfers, suffer from poor real-time performance, low data capacity, and high costs, and require regular CD replacements. All these factors severely impact the efficiency and reliability of data transmission.

[0004] Therefore, traditional cross-network data import technology cannot meet the high requirements of modern enterprises for data transmission efficiency and security, and there is an urgent need for a more efficient, secure and automated technology to overcome the shortcomings of existing technologies. Summary of the Invention

[0005] This application provides a method and system for automatic cross-network data import in physically isolated networks, aiming to solve the problem that traditional cross-network data import technology cannot meet the high requirements of modern enterprises for data transmission efficiency and security.

[0006] Firstly, a method for automatically importing cross-network data in physically isolated networks is provided, applied to a system for automatically importing cross-network data in physically isolated networks. The system comprises an input terminal, a detection terminal, a distribution terminal, a transfer machine 1, and a transfer machine 2. The method includes:

[0007] S1. The input end continuously acquires the data to be transferred sent by ordinary users in network A and stores it locally;

[0008] S2. The input end automatically parses the information carried by the data to be transferred, filters the data that meets the transfer rules, and for the data that does not meet the rules, the input end automatically sends a reminder message to network A and records the log.

[0009] S3. The input end automatically parses the files and download links in the data to be transferred, automatically downloads the files, matches the security policy, packages and encrypts the data that meets the security policy, and controls the transfer machine 1 to insert a regular USB flash drive.

[0010] S4. The input terminal clears the data of the ordinary USB flash drive, stores the encrypted data to be transferred, and controls the transfer machine 1 to transfer the ordinary USB flash drive to the detection terminal after verifying its integrity, while deleting the local data to be transferred.

[0011] S5. The scanning end receives the data to be transferred from the ordinary USB flash drive, performs integrity verification and decryption on the data, and automatically calls the anti-virus tool to scan and remove viruses and Trojans from the data. The data without problems is re-encrypted and automatically stored in the secure USB flash drive. After verifying the integrity, it controls the transfer machine 2 to transfer the secure USB flash drive to the distribution end and records the log.

[0012] S6. The scanning end is connected to a read-only optical drive at the same time. After the optical disc is detected, the user ID and security level dialog box is automatically displayed. The data read from the optical disc is automatically scanned for viruses and Trojans by the anti-virus tool. Data without problems is encrypted and automatically stored in a secure USB flash drive. After verifying the integrity, the transfer machine 2 is controlled to transfer the secure USB flash drive to the distribution end and the log is recorded.

[0013] S7. After the distribution end detects the insertion of the secure USB drive, it automatically unlocks the secure USB drive, reads the transfer information in the secure USB drive, and matches it with the application record in network B;

[0014] S8. Based on the matching results of the application records, the distribution end performs integrity verification and decrypts the data that has passed the application from the secure USB drive, distributes it to the data receiving user in network B, clears the data to be transferred on the secure USB drive, and records the log.

[0015] Optionally, in the above scheme, the shuttle machine 1 is used to shuttle ordinary USB flash drives, and the shuttle machine 2 is used to shuttle confidential USB flash drives.

[0016] The input end, distribution end, and detection end all include three administrator roles that meet security and confidentiality requirements: system administrator, security and confidentiality administrator, and security auditor.

[0017] System administrators can add, delete, modify, and query information for regular users;

[0018] System administrators can set security policies including file type, file name, total length threshold of data to be transferred, and total number threshold of data to be transferred;

[0019] The system administrator configures which USB drives and CD drives are allowed access, and prevents USB drives not on the allowed list from writing or reading data.

[0020] System administrators can set a password for the secure USB drive;

[0021] System administrators can configure local storage space;

[0022] Security and confidentiality administrators can modify the security level and permissions of ordinary users, and can also view and retrieve the transfer logs of ordinary users;

[0023] Security auditors can view and retrieve the activity logs of system administrators and security administrators.

[0024] Optionally, in the above scheme, S1 includes:

[0025] S11. The network configuration of the input terminal is configured by the system administrator, including the server address, port, and protocol type;

[0026] S12. The input end uses the IMAP protocol to connect to the mail server. It logs in and authenticates on the IMAP server of network A, retrieves the specified email from the mailbox inbox, and downloads it to the local machine.

[0027] S13. The input terminal uses WebDAV and SCP protocols to connect to the file server. It logs in and authenticates on the WebDAV and SCP server of network A to obtain and download the specified file from the server.

[0028] S2 includes:

[0029] S21. The unique identifier, security level, and permissions of ordinary users together constitute the ferrying rules. The input end automatically clears the number of ferrying entries that do not conform to the ferrying rules.

[0030] S22. The permissions of ordinary users include ferry permissions and approval permissions.

[0031] Optionally, in the above scheme, S3 includes:

[0032] S31. Security policies include file type filtering, file name sensitive word filtering, total length threshold of data to be transferred, and total number threshold of data to be transferred.

[0033] S32. Log the matching results;

[0034] S33. Convert the downloaded email data to a format conforming to RFC822 and save it;

[0035] S34. The file link is downloaded automatically using the Selenium tool;

[0036] S35. The input terminal automatically identifies the USB flash drive's eligibility and rejects unauthorized USB flash drives;

[0037] S36. Data that conforms to security policies and transfer rules will be packaged and encrypted.

[0038] Optionally, in the above scheme, step S4 includes:

[0039] S41. Empty the USB drive before each transfer;

[0040] S42. Use the SM3 algorithm to verify the integrity of the data to be transferred.

[0041] Optionally, in the above scheme, step S5 includes:

[0042] S51. Use timed polling to detect the import of data packages from the USB drive;

[0043] S52. The antivirus tool running on the scanning end is a domestically produced software that has passed testing and certification, and has the ability to be continuously upgraded.

[0044] Optionally, in the above scheme, step S6 includes:

[0045] S61. The detection and removal terminal automatically identifies the access qualifications of optical drives and rejects unauthorized optical drives;

[0046] S62. The detection terminal automatically retrieves the user-input identifier, security level, and permissions, rejects users who do not match, generates logs, and ejects the CD.

[0047] Optionally, in the above scheme, step S7 includes:

[0048] S71. The distribution end uses the user identifier and security level to query the application records of the data receiving user in network B, parses the queried records, and obtains the address of the data receiving user in network B;

[0049] S72. The distribution end queries the application record in network B using the application number, parses the queried record, and obtains the address of the data receiving user in network B.

[0050] Optionally, in the above scheme, S8 includes:

[0051] S81. The approved data is copied from the secure USB drive to the local device, sent to the data receiving user, and then the local data is cleared.

[0052] S82. Data that is not approved will remain on the secure USB drive until it is deleted.

[0053] Secondly, a cross-network data automatic import system for physically isolated networks, the system comprising:

[0054] The input module is used to continuously acquire the data to be transferred sent by ordinary users in network A and store the data to be transferred in local storage; automatically parse the data to be transferred stored locally, filter data that meets preset rules, and automatically send reminder messages to network A and record logs for data that does not meet the rules; automatically parse the files and download links in the data to be transferred stored locally, automatically download the files, match the security policy, package and encrypt the data that meets the security policy, control the transfer machine 1 to insert an ordinary USB flash drive, store the encrypted data in the ordinary USB flash drive, and transfer it to the detection and removal module through the transfer machine 1, while deleting the local data to be transferred.

[0055] Transfer Machine 1: Used to transfer data that has been packaged and encrypted and stored on a USB flash drive to the detection module;

[0056] The scanning module receives ordinary USB flash drive data packets from the input module, verifies the data packets to ensure data integrity, and decrypts them; it then calls antivirus tools to scan the data packets for viruses and Trojans to ensure that the data is not affected by malicious software; it then re-encrypts the scanned data and stores it in a secure USB flash drive, and controls the transfer machine 2 to transfer the secure USB flash drive to the distribution module.

[0057] Transfer Machine 2: Used to transfer data that has been detected, encrypted again, and stored on a secure USB drive to the distribution module;

[0058] The distribution module is used to automatically unlock the secure USB drive after detecting its insertion, obtain and verify the data packets in the secure USB drive, and confirm the correctness of the data packets; clear data packets that do not meet the requirements to ensure the accuracy of data transmission; match the application records in network B according to the application information in the data packets, and decrypt the successfully matched data from the secure USB drive and distribute it to the target user.

[0059] Compared with the prior art, this application has at least the following beneficial effects:

[0060] Based on further analysis and research into existing technical problems, this application recognizes that traditional cross-network data import technologies cannot meet the high demands of modern enterprises for data transmission efficiency and security. By implementing an automated cross-network data import method, the entire process of data acquisition, filtering, encryption, storage, and distribution is automated, reducing the need for manual operation and significantly improving data transmission efficiency. Furthermore, encryption technology and virus / Trojan scanning are used throughout the transmission process to ensure data security in a physically isolated network environment and prevent security risks. Through periodic polling and automated tools such as Selenium, the input end can acquire and download data in real time, further improving the speed and accuracy of data processing. The scanning end automatically verifies and removes viruses from the data, avoiding oversights caused by human operation in traditional methods and ensuring data integrity and security. Finally, the distribution end ensures correct data distribution by accurately matching the application records of target users, avoiding the risk of mis-distribution or misuse. Overall, this invention, through automation, encryption, security checks, and precise matching, greatly improves the efficiency, security, and reliability of cross-network data import, effectively solving the problems in existing technologies.

[0061] This invention automates data downloading, freeing manpower from simple, repetitive information collection tasks. Data is automatically packaged, encrypted, and stored on a USB drive, with full log tracking ensuring data traceability. A physically isolated USB drive transfer mechanism guarantees data security at the physical level. During the detection phase, the system automatically reads the USB drive data packets, strictly adhering to decryption and detection procedures to avoid human error and ensure compliance. In the distribution phase, strict matching of application results ensures data is accurately sent to the designated target user, reducing the risk of misdelivery and leakage. End-to-end, unmanned data verification eliminates the risk of data tampering. Furthermore, this method supports data transfer between different networks and business systems, exhibiting excellent compatibility and scalability to adapt to evolving enterprise needs, providing strong technical support for efficient collaboration between enterprises and between departments within an enterprise. Attached Figure Description

[0062] Figure 1 A flowchart illustrating an embodiment of the present application of an automatic cross-network data import method for physically isolated networks;

[0063] Figure 2 This is a block diagram of the module architecture of an automatic cross-network data import system for physically isolated networks provided in one embodiment of this application. Detailed Implementation

[0064] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0065] In the description of this application: unless otherwise stated, "a plurality of" means two or more. The terms "first," "second," "third," etc., in this application are intended to distinguish the objects referred to and do not have any special meaning in terms of technical connotation (e.g., they should not be construed as an emphasis on importance or order). Expressions such as "comprising," "including," and "having" also mean "not limited to" (certain units, components, materials, steps, etc.).

[0066] In one embodiment, such as Figure 1 As shown, a method for automatically importing cross-network data in physically isolated networks is provided, applied to a system for automatically importing cross-network data in physically isolated networks. The system consists of an input terminal, a detection terminal, a distribution terminal, a transfer machine 1, and a transfer machine 2. The method includes:

[0067] S1. The input end continuously acquires the data to be transferred sent by ordinary users in network A and stores it locally;

[0068] S2. The input end automatically parses the information carried by the data to be transferred, filters the data that meets the transfer rules, and for the data that does not meet the rules, the input end automatically sends a reminder message to network A and records the log.

[0069] S3. The input end automatically parses the files and download links in the data to be transferred, automatically downloads the files, matches the security policy, packages and encrypts the data that meets the security policy, and controls the transfer machine 1 to insert a regular USB flash drive.

[0070] S4. The input terminal clears the data of the ordinary USB flash drive, stores the encrypted data to be transferred, and controls the transfer machine 1 to transfer the ordinary USB flash drive to the detection terminal after verifying its integrity, while deleting the local data to be transferred.

[0071] S5. The scanning end receives the data to be transferred from the ordinary USB flash drive, performs integrity verification and decryption on the data, and automatically calls the anti-virus tool to scan and remove viruses and Trojans from the data. The data without problems is re-encrypted and automatically stored in the secure USB flash drive. After verifying the integrity, it controls the transfer machine 2 to transfer the secure USB flash drive to the distribution end and records the log.

[0072] S6. The scanning end is connected to a read-only optical drive at the same time. After the optical disc is detected, the user ID and security level dialog box is automatically displayed. The data read from the optical disc is automatically scanned for viruses and Trojans by the anti-virus tool. Data without problems is encrypted and automatically stored in a secure USB flash drive. After verifying the integrity, the transfer machine 2 is controlled to transfer the secure USB flash drive to the distribution end and the log is recorded.

[0073] S7. After the distribution end detects the insertion of the secure USB drive, it automatically unlocks the secure USB drive, reads the transfer information in the secure USB drive, and matches it with the application record in network B;

[0074] S8. Based on the matching results of the application records, the distribution end performs integrity verification and decrypts the data that has passed the application from the secure USB drive, distributes it to the data receiving user in network B, clears the data to be transferred on the secure USB drive, and records the log.

[0075] In this embodiment, the shuttle machine 1 is used to shuttle ordinary USB flash drives, and the shuttle machine 2 is used to shuttle confidential USB flash drives;

[0076] The input end, distribution end, and detection end all include three administrator roles that meet security and confidentiality requirements: system administrator, security and confidentiality administrator, and security auditor.

[0077] System administrators can add, delete, modify, and query information for regular users;

[0078] System administrators can set security policies including file type, file name, total length threshold of data to be transferred, and total number threshold of data to be transferred;

[0079] The system administrator configures which USB drives and CD drives are allowed access, and prevents USB drives not on the allowed list from writing or reading data.

[0080] System administrators can set a password for the secure USB drive;

[0081] System administrators can configure local storage space;

[0082] Security and confidentiality administrators can modify the security level and permissions of ordinary users, and can also view and retrieve the transfer logs of ordinary users;

[0083] Security auditors can view and retrieve the activity logs of system administrators and security administrators.

[0084] In this embodiment, S1 includes:

[0085] S11. The network configuration of the input terminal is configured by the system administrator, including the server address, port, and protocol type;

[0086] S12. The input end uses the IMAP protocol to connect to the mail server. It logs in and authenticates on the IMAP server of network A, retrieves the specified email from the mailbox inbox, and downloads it to the local machine.

[0087] S13. The input terminal uses WebDAV and SCP protocols to connect to the file server. It logs in and authenticates on the WebDAV and SCP server of network A to obtain and download the specified file from the server.

[0088] S2 includes:

[0089] S21. The unique identifier, security level, and permissions of ordinary users together constitute the ferrying rules. The input end automatically clears the number of ferrying entries that do not conform to the ferrying rules.

[0090] S22. The permissions of ordinary users include ferry permissions and approval permissions.

[0091] In this embodiment, S3 includes:

[0092] S31. Security policies include file type filtering, file name sensitive word filtering, total length threshold of data to be transferred, and total number threshold of data to be transferred.

[0093] S32. Log the matching results;

[0094] S33. Convert the downloaded email data to a format conforming to RFC822 and save it;

[0095] S34. The file link is downloaded automatically using the Selenium tool;

[0096] S35. The input terminal automatically identifies the USB flash drive's eligibility and rejects unauthorized USB flash drives;

[0097] S36. Data that conforms to security policies and transfer rules will be packaged and encrypted.

[0098] In this embodiment, S4 includes:

[0099] S41. Empty the USB drive before each transfer;

[0100] S42. Use the SM3 algorithm to verify the integrity of the data to be transferred.

[0101] In this embodiment, S5 includes:

[0102] S51. Use timed polling to detect the import of data packages from the USB drive;

[0103] S52. The antivirus tool running on the scanning end is a domestically produced software that has passed testing and certification, and has the ability to be continuously upgraded.

[0104] In this embodiment, S6 includes:

[0105] S61. The detection and removal terminal automatically identifies the access qualifications of optical drives and rejects unauthorized optical drives;

[0106] S62. The detection terminal automatically retrieves the user-input identifier, security level, and permissions, rejects users who do not match, generates logs, and ejects the CD.

[0107] In this embodiment, S7 includes:

[0108] S71. The distribution end uses the user identifier and security level to query the application records of the data receiving user in network B, parses the queried records, and obtains the address of the data receiving user in network B;

[0109] S72. The distribution end queries the application record in network B using the application number, parses the queried record, and obtains the address of the data receiving user in network B.

[0110] In this embodiment, S8 includes:

[0111] S81. The approved data is copied from the secure USB drive to the local device, sent to the data receiving user, and then the local data is cleared.

[0112] S82. Data that is not approved will remain on the secure USB drive until it is deleted.

[0113] In this embodiment, the input terminal first continuously acquires the data to be transferred from network A through the configured mail server and file server connection methods. The mail server uses the IMAP protocol, and the file server uses the WebDAV or SCP protocol. During this process, the input terminal automatically connects to and logs into the mail and file servers of network A, acquires the data to be transferred, and stores it locally. This step uses a polling mechanism to maintain the real-time nature of data acquisition. The data stored locally will be parsed in subsequent processing.

[0114] After acquiring the data, the input end automatically parses the data stored locally for transfer. During parsing, the input end filters the data according to preset rules (such as filename, file extension, file size, etc.). For data that meets the rules, the input end continues with subsequent steps; for data that does not meet the rules, the input end sends a notification message to the corresponding server or mail server on network A, prompting the data provider to modify the data. This step reduces the need for manual intervention and improves the efficiency and accuracy of data processing.

[0115] After the data is filtered, the input terminal automatically parses the files and download links within the data and uses automated tools (such as Selenium) to simulate browser operations, automatically redirecting to the download links and downloading the file content. Once downloaded, the input terminal packages, encrypts, and saves the downloaded file to a regular USB flash drive. This encryption process ensures data security, preventing unauthorized access or tampering even during transmission. The data package stored on the USB flash drive is then transferred to the detection terminal via a USB flash drive transfer mechanism.

[0116] After receiving the data packet from the USB drive, the scanning client first verifies the packet to ensure the file is intact. During verification, the client uses antivirus tools to scan the data for viruses and Trojans, ensuring there are no potential security threats. This process is strictly enforced; all data that does not meet security standards is deleted, while data that meets security standards is stored on a dedicated USB drive for confidential data. The scanning client also generates detailed scanning logs, recording all information from the verification and cleanup process, providing traceable evidence for subsequent operations.

[0117] Upon receiving the secure USB drive, the distribution end first unlocks it to ensure data security and usability. The distribution end then further verifies the data packets to ensure their integrity. If the packet verification fails, the problematic packet is deleted. Next, based on the information carried in the data packets, the distribution end queries the target user's application records within network B and distributes data according to the matching records. Only valid data from approved applications is decrypted and ultimately distributed to the target user. Data from unsuccessful applications remains on the secure USB drive until it is deleted. This step ensures accurate data distribution and prevents the transmission of erroneous data.

[0118] The cross-network data automatic import method provided in this embodiment effectively solves the problems of low efficiency, numerous errors, and poor security associated with traditional manual methods by fully automating the data import, verification, antivirus, encryption, and distribution processes. Traditional cross-network data import typically requires manual intervention, such as manually acquiring data, filtering, downloading files, and encrypting and transmitting the data. With the automated method of this invention, the entire process of data acquisition, parsing, filtering, downloading, encryption, and transmission is completely automated. The system ensures real-time and rapid data acquisition and processing through periodic polling and automated tools (such as Selenium), greatly improving the efficiency of data import, especially during large-scale data transmission.

[0119] This embodiment introduces an encryption mechanism during data transmission to ensure that data transmitted in a physically isolated environment is not accessed or tampered with by unauthorized users. Furthermore, virus and Trojan detection on the scanning end further enhances data security. These security measures effectively prevent data leakage and infection problems caused by human error or system vulnerabilities in traditional data transmission methods, ensuring data security and integrity. Since the entire data import process is automated, steps traditionally reliant on manual operation are replaced by the automated system, avoiding oversights and errors inherent in human intervention. For example, in traditional manual methods, manual screening and reminders may lead to missed data processing or incorrect operations; however, this invention, through automated rule settings and reminder mechanisms, ensures that all data is processed correctly, greatly reducing the possibility of errors. In each step, the system generates detailed log records, including every operation during data acquisition, screening, downloading, encryption, detection, and distribution. These logs provide system administrators with a complete operation trajectory, making the entire data import process highly traceable. In case of problems, the root cause can be quickly located by reviewing the logs, thereby improving system maintainability. In traditional cross-network data transmission, human error can lead to mis-sending or improper distribution of data, increasing the risk of errors. This invention, however, ensures that each data packet is accurately distributed to the target user by precisely matching application records, thus avoiding mis-distribution. Through a rigorous data verification mechanism, the distribution end only sends data that conforms to the standards, ensuring data accuracy and reliability.

[0120] This embodiment achieves full automation of cross-network data import, requiring no manual intervention at any step from data acquisition to distribution. Automation not only improves the speed of data import but also reduces operational complexity, enabling the system to run continuously 24 hours a day without human intervention.

[0121] In one embodiment, a method for data transfer across network business systems based on a USB flash drive transfer mechanism is provided, including:

[0122] S1. The input terminal connects to and logs into the mail server or file server. The input terminal continuously obtains data to be transferred sent by ordinary users in network A and stores it locally.

[0123] S2. The unique identifier, security level, and permissions of ordinary users together constitute the transfer rules. The input end automatically parses the information carried by the data to be transferred, filters the data that conforms to the transfer rules, and for data that does not conform to the rules, the input end automatically sends a reminder message to network A and records the log.

[0124] S3. The security policy includes file type filtering, file name sensitive word filtering, total length threshold of data to be transferred, total number threshold of data to be transferred, automatic parsing of files and download links in the data to be transferred at the input end, automatic file download, matching the security policy, and after packaging and encrypting the data that meets the security policy, controlling the transfer machine 1 to insert a regular USB flash drive.

[0125] S4. The input terminal clears the data on the USB drive, stores the encrypted data to be transferred, and after verifying the integrity, controls the transfer machine 1 to transfer the USB drive to the detection terminal, while deleting the local data to be transferred.

[0126] S5. The scanning terminal receives the data to be transferred from the USB drive, performs integrity verification and decryption on the data, and automatically calls the antivirus tool to scan and remove viruses and Trojans from the data. Data without problems is re-encrypted and automatically stored in the secure USB drive. After verifying the integrity, the terminal controls the transfer machine 2 to transfer the secure USB drive to the distribution terminal and records the log.

[0127] S6. The scanning end is connected to a read-only optical drive. After the disc is detected, the user ID and security level dialog box is automatically displayed. The data read from the disc is automatically scanned for viruses and Trojans by the antivirus tool. Data without problems is encrypted and automatically stored in a secure USB drive. After verifying the integrity, the transfer machine 2 is controlled to transfer the secure USB drive to the distribution end and the log is recorded.

[0128] S7. After the distribution end detects the insertion of the secure USB drive, it automatically unlocks the secure USB drive, reads the information to be transferred from the secure USB drive, matches the application records in network B, parses the queried records through the application records, and obtains the address of the data receiving user in network B.

[0129] S8. The distribution end performs integrity verification and decryption on the approved data from the secure USB drive, then distributes it to the data receiving user in network B, clears the data to be transferred from the secure USB drive, and records the log.

[0130] In some implementations, step S1 includes:

[0131] S11. Data acquisition methods include IMAP mail, WebDAV, and SCP file transfer. The input terminal continuously polls the mail and file servers in network A, downloading new data immediately upon its arrival. The input terminal can be configured to connect to either the mail or file server, or both simultaneously.

[0132] S12. Following the system configuration in S11, connect to and log in to the mail server and file server of Network A, download the data to be transferred from the data provider of Network A to the local machine, and then delete the data to be transferred from the data provider of Network A.

[0133] In this embodiment, the mail server connection method includes: using the IMAP protocol to connect to the mail server, connecting to the IMAP mail server of network A through the mail server parameters configured in S11, performing login authentication on the IMAP server of network A, retrieving and downloading the specified email from the mailbox inbox.

[0134] In this embodiment, the file server connection method includes: using WebDAV and SCP protocols to connect to the file server; connecting to the WebDAV and SCP server of network A through the file server parameters configured in S11; performing login authentication on the WebDAV and SCP server of network A; and obtaining and downloading the specified file from the server.

[0135] In some implementations, step S2 includes:

[0136] S21. Message notifications are sent to the target user on the mail server via the SMTP protocol; if the connection is to a file server, messages are sent via the RESTful interface. When connecting to both types of servers simultaneously, email notifications are sent first.

[0137] In some implementations, step S3 includes:

[0138] S31. Convert the downloaded email data to a format conforming to RFC822 and save it;

[0139] S32. The file link is downloaded automatically using the Selenium tool;

[0140] S33. Using a combination of software and USB flash drive transfer mechanism, local data packets are transferred in a physically isolated manner.

[0141] S34. The system administrator configures the access permissions for USB drives. The input terminal will check the access qualifications of the USB drives and automatically reject unapproved USB drives.

[0142] In some implementations, step S4 includes:

[0143] S41. Use the SM3 algorithm to verify the correctness of data packets.

[0144] In some implementations, step S5 includes:

[0145] The antivirus tool running on the S51 detection terminal is a domestically produced software that has passed testing and certification, and has the ability to be continuously upgraded.

[0146] In some implementations, step S6 includes:

[0147] S61. The system administrator configures the access permissions for CD-ROM drives, and the anti-virus software automatically identifies the CD-ROM drive's access qualifications and denies access to unauthorized CD-ROM drives.

[0148] S62. The detection terminal automatically retrieves the user-input identifier, security level, and permissions, rejects users who do not match, generates logs, and ejects the CD.

[0149] In some implementations, S7 includes:

[0150] S71. The distribution end can query the application records of data receiving users in network B by user identifier and security level, parse the queried records, and obtain the address of the data receiving user in network B;

[0151] S72. The distribution end can query the application record in network B through the application number, parse the queried record, and obtain the address of the data receiving user in network B.

[0152] In some implementations, S8 includes:

[0153] S81. The approved data is copied from the secure USB drive to the local device, sent to the data receiving user, and then the local data is cleared.

[0154] S82. Data that is not approved will remain on the secure USB drive until it is deleted.

[0155] Compared to existing technologies, this embodiment can automatically perform data downloads, freeing manpower from simple and repetitive information collection tasks; data is automatically packaged, encrypted, and stored on a USB drive, with full log tracking, making imported data traceable; a physically isolated USB drive transfer mechanism ensures data security at the physical level; during the detection phase, the USB drive data package is automatically read, and decryption and detection processes are strictly executed to avoid errors caused by human operation and ensure compliance; during the distribution phase, application results are strictly matched to ensure that data is accurately sent to the designated target user, reducing the risk of mis-sending data and eliminating the risk of data leakage; end-to-end data verification without human intervention eliminates the risk of data tampering. Furthermore, this method supports data transfer between different networks and business systems, exhibiting good compatibility and scalability, adapting to the ever-changing needs of enterprises, and providing strong technical support for efficient collaboration between enterprises and between departments within an enterprise.

[0156] In one embodiment, a method for automatically importing cross-network data from physically isolated networks is provided, including:

[0157] S1. The input terminal connects to and logs into the mail server or file server. The input terminal continuously acquires data to be transferred sent by ordinary users in network A and stores it locally, including:

[0158] Data acquisition methods include IMAP email, WebDAV, and SCP file transfer. The input terminal continuously polls the mail and file servers in network A, downloading new data immediately upon its arrival. The input terminal can be configured to connect to either the mail or file server, or both simultaneously.

[0159] S2. A user's unique identifier, security level, and permissions together constitute the transfer rules. The input end automatically parses the information carried by the data to be transferred, filters data that conforms to the transfer rules, and for data that does not conform to the rules, the input end automatically sends an alert message to network A and records it in the log: the alert message is sent to the target user on the mail server via the SMTP protocol; if the connection is to a file server, the message is sent via the RESTful interface. When connecting to both servers simultaneously, email alerts are sent first.

[0160] S3. The security policy includes file type filtering, filename sensitive word filtering, total length threshold for data to be transferred, and total number threshold for data to be transferred. The input end automatically parses the files and download links in the data to be transferred, automatically downloads the files, matches them against the security policy, and after packaging and encrypting the data that meets the security policy, controls the transfer machine 1 to insert the USB flash drive.

[0161] The file link was downloaded automatically using the Selenium tool;

[0162] The system administrator configures the access permissions for USB drives. The input terminal checks the access qualifications of the USB drives and automatically rejects those that are not authorized.

[0163] S4. The input terminal clears the data on the USB drive, stores the encrypted data to be transferred, and controls the transfer machine 1 to transfer the USB drive to the detection terminal after verifying its integrity. At the same time, the local data to be transferred is deleted. The data integrity verification adopts the SM3 algorithm.

[0164] S5. The scanning terminal receives the data to be transferred from the USB drive, performs integrity verification and decryption on the data, and automatically calls the antivirus tool to scan and remove viruses and Trojans from the data. Data without problems is re-encrypted and automatically stored in the secure USB drive. After verifying the integrity, it controls the transfer machine 2 to transfer the secure USB drive to the distribution terminal and records the log: The antivirus tool running on the scanning terminal is a domestically produced software that has passed the test and certification and has sustainable upgrade capabilities.

[0165] S6. The scanning terminal simultaneously connects to a read-only optical drive. Upon detecting the inserted optical disc, it automatically displays a dialog box indicating the user's identifier and security level. Data read from the optical disc is automatically scanned for viruses and Trojans using antivirus tools. Data without issues is encrypted and automatically stored on a secure USB drive. After verifying integrity, the terminal controls transfer machine 2 to transfer the secure USB drive to the distribution terminal and records logs. The system administrator configures access permissions for optical drives, and the scanning terminal automatically identifies the optical drive's access qualifications, rejecting unauthorized drives. The scanning terminal automatically retrieves the user-input identifier, security level, and permissions, rejecting users who do not match, while simultaneously generating logs and ejecting the optical disc.

[0166] S7. Upon detecting the insertion of the secure USB drive, the distribution end automatically unlocks the USB drive, reads the transfer information from the USB drive, matches it with the application records within network B, and obtains the address of the data receiving user in network B by parsing the queried records. Alternatively, the distribution end can query the application records of the data receiving user in network B by user identifier and security level, and obtain the address of the data receiving user in network B by parsing the queried records.

[0167] S8. After the distribution end verifies the integrity of the approved data from the secure USB drive and decrypts it, it distributes it to the data receiving user in network B, clears the data to be transferred from the secure USB drive, and records the log: the approved data is copied from the secure USB drive to the local machine, sent to the data receiving user, and the local data is cleared; the unapproved data is always kept in the secure USB drive until it is cleared.

[0168] In one embodiment, a read-only optical drive is added to the distribution terminal, allowing the import of higher-security data, such as classified data, through the scanning terminal. The scanning terminal automatically reads the inserted optical disc, automatically opens the scanning tool to perform a scan, and records the scan log.

[0169] In one embodiment, such as Figure 2 As shown, a cross-network data automatic import system for physically isolated networks is provided, including the following program modules:

[0170] The input module is used to continuously acquire the data to be transferred from network A and store the data to be transferred in local storage; automatically parse the data to be transferred stored locally, filter data that meets preset rules, and automatically send reminder messages to network A and record logs for data that does not meet the rules; automatically parse the files and download links in the data to be transferred stored locally, automatically download the files, match the security policy, package and encrypt the data that meets the security policy, control the transfer machine 1 to insert a regular USB flash drive, and transfer the data to the detection and removal module through the transfer machine 1, while deleting the local data to be transferred.

[0171] Transfer Machine 1: Used to transfer data packaged and stored on a regular USB flash drive to the anti-virus module;

[0172] The scanning module receives ordinary USB flash drive data packets from the input module, verifies the data packets to ensure data integrity, and decrypts them; it then calls antivirus tools to scan the data packets for viruses and Trojans to ensure that the data is not affected by malicious software; it then re-encrypts the scanned data and stores it in the secure USB flash drive, and controls the USB flash drive transfer mechanism 2 to transfer the secure USB flash drive to the distribution module.

[0173] Transfer Machine 2: Used to transfer data that has been detected, encrypted again, and stored on a secure USB drive to the distribution module;

[0174] The distribution module is used to automatically unlock the secure USB drive after detecting its insertion, obtain and verify the data packets in the secure USB drive, and confirm the correctness of the data packets; clear data packets that do not meet the requirements to ensure the accuracy of data transmission; match the application record of the target user in network B according to the application information in the data packet, and decrypt the successfully matched data from the secure USB drive and distribute it to the target user.

[0175] The specific implementation details of each module can be found in the above description of the method for automatically importing cross-network data in physically isolated networks, and will not be repeated here.

[0176] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

Claims

1. A method for automatically importing cross-network data of a physically isolated network, characterized in that, The application relates to a cross-network data automatic import system applied to a physically isolated network, which is composed of an input end, a killing end, a distribution end, a ferry machine 1 and a ferry machine 2. S1. The input end continuously acquires normal user-sent data to be ferried in network A and stores the data in the local; S2. The input end automatically analyzes information carried by the data to be ferried, screens data meeting ferry rules, and sends a reminding message to network A and records a log for data not meeting the rules; S3. The input end automatically analyzes files and download links in the data to be ferried, automatically downloads the files, matches a safety strategy, packages and encrypts data meeting the safety strategy, and controls the ferry machine 1 to insert a normal U disk; S4. The input end empties data in the normal U disk, stores the encrypted data to be ferried, controls the ferry machine 1 to ferry the normal U disk to the killing end after verifying the integrity, and deletes the local data to be ferried; S5. The killing end receives the data to be ferried imported by the normal U disk, verifies the integrity of the data and decrypts the data, automatically calls a virus and Trojan killing tool to kill viruses and Trojans in the data, re-encrypts the data without problems and automatically stores the data in a secret U disk, controls the ferry machine 2 to ferry the secret U disk to the distribution end after verifying the integrity, and records a log; S6. The killing end is simultaneously connected with a read-only optical drive, automatically displays a user identifier and a secret level dialog box after recognizing the optical drive, reads data from the optical drive, automatically calls a virus and Trojan killing tool to kill viruses and Trojans in the data, encrypts the data without problems and automatically stores the data in the secret U disk, controls the ferry machine 2 to ferry the secret U disk to the distribution end after verifying the integrity, and records a log; S7. The distribution end detects the insertion of the secret U disk, automatically unlocks the secret U disk, reads data to be ferried in the secret U disk, and matches application records in network B; S8. The distribution end verifies the integrity of the data passed by the application from the secret U disk and decrypts the data, distributes the data to data receiving users in network B, empties the data to be ferried in the secret U disk, and records a log; S2 includes: S21. A normal user unique identifier, a secret level and a right jointly constitute a ferry rule, and the input end automatically removes data to be ferried not meeting the ferry rule; S22. The right of the normal user includes a ferry right and an approval right; S3 includes: S31. The safety strategy includes file type filtering, file name sensitive word filtering, total length threshold of the data to be ferried and total quantity threshold of the data to be ferried; S32. A matching result is recorded in a log; S33. Mail data content downloaded to the local is converted into a format meeting a RFC822 specification and saved; S34. A file link is automatically downloaded by using a selenium tool; S35. The input end automatically identifies U disk access qualification and rejects U disks without the access qualification; S36. Data meeting the safety strategy and the ferry rule is packaged and encrypted; S7 includes: S71. The distribution end queries application records of data receiving users in network B through a user identifier and a secret level, analyzes the queried records, and acquires an address of the data receiving user in network B. S72. The distribution end queries the application record in network B through the application number, parses the queried record, and obtains the address of the data receiving user in network B.

2. The method of claim 1, wherein, The shuttle machine 1 is used for shuttling ordinary U disks, and the shuttle machine 2 is used for shuttling secret U disks. The input end, the distribution end and the killing end all include three administrator roles of a system administrator, a security administrator and a security auditor meeting security and secrecy requirements. The system administrator can add, delete, modify and query the information of ordinary users. The system administrator can set security policies including file type, file name, total length threshold of data to be shuttled, total number threshold of data to be shuttled, etc. The system administrator can configure the U disk and optical drive that can be accessed, and the U disk not in the access list cannot write and read data. The system administrator can set the password of the secret U disk. The system administrator can configure the local storage space. The security administrator can modify the secret level and permission of the ordinary user, and can also view and retrieve the shuttle log of the ordinary user. The security auditor can view and retrieve the behavior log of the system administrator and the security administrator.

3. The method of claim 1, wherein, The S1 includes: S11. The network configuration connected by the input end is configured by the system administrator, including server address, port and protocol type. S12. The protocol used by the input end connected to the mail server is IMAP protocol, which logs in and authenticates on the IMAP server in network A, obtains the specified mail in the mailbox and downloads it to the local. S13. The protocol used by the input end connected to the file server is WebDAV or SCP protocol, which logs in and authenticates on the WebDAV or SCP server in network A, and obtains and downloads the specified file in the server.

4. The method of claim 1, wherein, The S4 includes: S41. The U disk is emptied before each shuttle; S42. The SM3 algorithm is used to check the integrity of the data to be shuttled.

5. The method of claim 1, wherein, The S5 includes: S51. The U disk data packet import is detected by using the timing polling method; S52. The antivirus tool running in the killing end is a domestic software authenticated by detection, and has the ability of continuous upgrade.

6. The method of claim 1, wherein, The S6 includes: S61. The killing end automatically identifies the access qualification of the optical drive and rejects the optical drive without access; S62. The killing end automatically retrieves the identification, secret level and permission input by the user, rejects the user who does not match, generates a log and pops up the optical disk.

7. The method of claim 1, wherein, The S8 includes: S81. The data approved by the application is copied to the local from the secret U disk, and the local data is cleared after being sent to the data receiving user; S82. The data not approved by the application always remains in the secret U disk until it is cleared.

8. A cross-network data auto-import system for physically isolated networks, comprising: The input end module is used to continuously obtain the data to be shuttled sent by the ordinary user in network A, and store the data to be shuttled to the local storage. ​ The automatic analysis of the data to be transferred stored locally, screening data in accordance with the preset rules, and sending a reminder message to the network A and recording the log for the data not in accordance with the rules; automatically analyzing the files and download links in the data to be transferred stored locally, automatically downloading the files, matching the security policy, packaging and encrypting the data in accordance with the security policy, and controlling the transfer machine 1 to insert a normal U disk, storing the encrypted data in the normal U disk, and transferring the data to the killing terminal module through the transfer machine 1, while deleting the local data to be transferred; the unique identifier, the secret level, and the permission of the ordinary user jointly constitute the transfer rule, and the input end automatically clears the data to be transferred not in accordance with the transfer rule; the permission of the ordinary user includes the transfer permission and the approval permission; The security policy includes file type filtering, file name sensitive word filtering, total length threshold of the data to be transferred, and total quantity threshold of the data to be transferred; The matching result is recorded in the log; the content of the downloaded email data is converted into a format in accordance with the RFC822 specification and saved; the file link is automatically downloaded using the selenium tool; the input end automatically identifies the U disk access qualification and refuses the U disk without access; the data in accordance with the security policy and the transfer rule is packaged and encrypted; The transfer machine 1 is used to transfer the data packaged and encrypted and stored in the U disk to the killing terminal module; The killing terminal module is used to receive the normal U disk data package transmitted by the input end module, check the data package, ensure the data integrity and decrypt the data package; call the antivirus tool to kill the virus and Trojan in the data package, ensure that the data is not affected by malicious software; re-encrypt the data passed by the killing into a secret U disk, and control the transfer machine 2 to transfer the secret U disk to the distribution terminal module; The transfer machine 2 is used to transfer the data re-encrypted and stored in the secret U disk to the distribution terminal module after the killing; The distribution terminal module is used to automatically unlock the secret U disk after detecting the insertion of the secret U disk, acquire and check the data package in the secret U disk, and confirm the correctness of the data package; clear the data package not in accordance with the requirements, and ensure the accuracy of data transmission; according to the application information in the data package, match the application record in the network B, and distribute the decrypted data from the secret U disk to the target user after the successful matching; The distribution terminal queries the application record of the data receiving user in the network B through the user identifier and the secret level, analyzes the queried record, and acquires the address of the data receiving user in the network B; The distribution terminal queries the application record in the network B through the application number, analyzes the queried record, and acquires the address of the data receiving user in the network B.

Citation Information

Patent Citations

  • Cross-network optical turntable isolation ferry machine and cross-network automatic data ferry method

    CN114205159A

  • Virtual extensible LAN intercommunication mechanism for multicast in networking

    US20180006930A1