Intranet and extranet file ferrying system and method using one-way gatekeeper

By using a one-way gateway to transfer files between internal and external networks, and by employing forward and reverse isolation devices and proxy software, the system achieves one-way and secure data transmission, thereby resolving information security threats brought about by the intelligence of external networks and improving the security and controllability of data transmission.

CN120880772APending Publication Date: 2025-10-31HUANENG GANSU ENERGY DEV CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511230324.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In existing technologies, the intelligence level of external networks has increased, but at the same time, the risk of network attacks has also increased. Sensitive information is easily stolen, leading to information security threats, especially when it is difficult to guarantee the security of data transmission between internal and external networks.

Method used

The internal and external network file transfer system, which adopts a one-way network gateway, achieves unidirectional data transmission through forward and reverse isolation devices. Combined with internal and external network proxy software and cross-network data exchange software, it performs data packet processing, encryption, and compression, supports virus scanning and sensitive file identification, and achieves security and controllability of data transmission.

Benefits of technology

It improves the security of data transmission between internal and external networks, prevents data reverse transmission, supports virus scanning and sensitive file identification, and ensures the security, reliability and practicality of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880772A_ABST
    Figure CN120880772A_ABST
Patent Text Reader

Abstract

The invention discloses an intranet and extranet file ferrying system and method using a one-way gatekeeper. The system comprises an office extranet, an extranet server, an office intranet, an intranet server, a forward isolation device and a reverse isolation device. The office external network is connected with the external network server, the office internal network is connected with the internal network server, the output end of the internal network server is connected with the input end of the external network server through a forward isolation device, and the output end of the external network server is connected with the input end of the internal network server through a reverse isolation device. The system and the method can improve the security of data transmission between the internal and external networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data transmission technology and relates to a file transfer system and method for internal and external networks using a one-way gateway. Background Technology

[0002] In today's information age, the technological wave is sweeping the globe at an unprecedented speed. The internet, as a crucial product of this era, has permeated every corner of society extensively and deeply. Like a vast, invisible net, it tightly connects the world, with information exploding in volume, encompassing everything from the minutiae of daily life to cutting-edge international scientific research, from lighthearted entertainment gossip to in-depth analysis of major political and economic events—truly all-encompassing. Simultaneously, the internet's intelligence is constantly improving. Intelligent search engines can accurately pinpoint user needs, personalized recommendation systems can provide customized content based on browsing habits, and AI chatbots can answer users' questions anytime. With its convenience, efficiency, and richness, the internet is gradually becoming an indispensable part of people's lives.

[0003] The development of the internet is a double-edged sword. While bringing numerous conveniences, it also presents a series of problems that cannot be ignored. In the workplace, the internet is undoubtedly a powerful tool. When employees encounter difficulties at work, they can find clues to solutions in a vast amount of information with just a click of the mouse; researchers can access the latest research results and experimental data through the internet, providing references for their research; and corporate managers can use the internet to understand market dynamics and competitor information, enabling them to formulate more scientific and rational strategic decisions. However, while bringing convenience, the internet also poses a serious threat to information security. Cyberattack methods are becoming increasingly complex and diverse. Hackers can steal sensitive information from individuals and businesses, such as personal identification information, bank account passwords, and corporate trade secrets, through methods such as implanting malicious software and launching phishing attacks. Once this information is leaked, it will not only cause economic losses and privacy problems for individuals, but may also cause serious reputational damage and economic losses to companies, and even affect national security and stability. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of the prior art and provide a system and method for transferring files between internal and external networks using a one-way gateway. This system and method can improve the security of data transmission between internal and external networks.

[0005] To achieve the above objectives, this invention discloses an internal and external network file transfer system using a one-way gateway, comprising an office external network, an external network server, an office internal network, an internal network server, a forward isolation device, and a reverse isolation device;

[0006] The office external network is connected to the external network server, and the office internal network is connected to the internal network server. The output of the internal network server is connected to the input of the external network server through a forward isolation device, and the output of the external network server is connected to the input of the internal network server through a reverse isolation device.

[0007] Furthermore, the intranet server includes intranet cross-network data exchange software and intranet proxy software, and the extranet server includes extranet proxy software and extranet cross-network data exchange software. The office extranet is connected to the extranet proxy software through the extranet cross-network data exchange software, and the office intranet is connected to the intranet proxy software through the intranet cross-network data exchange software. The output end of the intranet proxy software is connected to the input end of the extranet proxy software through a forward isolation device, and the output end of the extranet proxy software is connected to the input end of the intranet proxy software through a reverse isolation device.

[0008] This invention discloses a method for transferring files between internal and external networks using a one-way gateway. Based on a system for transferring files between internal and external networks using a one-way gateway, it includes initiating cross-network transmission within the internal network and transferring data from the internal network to the external network.

[0009] Furthermore, the process of initiating cross-network transmission within the intranet is as follows:

[0010] The intranet cross-network data exchange software initiates a cross-network task.

[0011] The intranet proxy software sends connection establishment and cross-network transmission initiation messages through the forward isolation device;

[0012] The external network proxy software connects to the external network cross-network data exchange software and forwards the cross-network transmission message.

[0013] External network cross-network data exchange software may initiate or interrupt cross-network transmission.

[0014] Furthermore, the process by which the external network cross-network data exchange software initiates or interrupts cross-network transmission is as follows:

[0015] After receiving the message to start a cross-network transmission task, the external network cross-network data exchange software checks the user's permissions and whether the disk space of the user's network meets the cross-network transmission conditions. If it does, it replies that the cross-network transmission was started successfully; otherwise, it replies that the cross-network transmission failed and interrupts the cross-network transmission.

[0016] Furthermore, the process of transmitting data across networks from the intranet to the extranet is as follows:

[0017] The intranet cross-network data exchange software begins transmitting data;

[0018] The intranet proxy software performs TCP data packet assembly, data processing, adds packet headers, and forwards the data.

[0019] The external network proxy software parses the data packet header, restores the data, obtains the original data, and then forwards the original data to the external network cross-network transmission and switching software;

[0020] The external network cross-network transmission and exchange software stores the received data and sends a data confirmation packet back to the external network proxy software;

[0021] The external network proxy software receives the data confirmation packet, compresses and encrypts it, adds a data packet header, and sends it to the internal network proxy software through the reverse isolation device.

[0022] The intranet proxy software parses the data packet header, restores the data, and forwards the confirmation message.

[0023] Furthermore, the process of initiating data transmission is as follows:

[0024] The intranet cross-network data exchange software begins a single 4MB data transfer, using a TCP connection to send data to the intranet agent software.

[0025] Furthermore, the data packet header includes the data packet type, data packet size, and whether the data packet is compressed or encrypted.

[0026] This invention discloses a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the method for transferring files between internal and external networks using a one-way gateway.

[0027] This invention discloses a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the method for transferring files between internal and external networks using a one-way gateway.

[0028] The present invention has the following beneficial effects:

[0029] The file transfer system and method for internal and external networks using a one-way gateway described in this invention employs two isolation devices to ensure that data exchange between the internal and external networks can only be transmitted unidirectionally through these isolation devices, achieving "lateral isolation" and providing higher security. In addition, when data is transferred to the cloud drive, it can automatically detect and remove viruses and supports online updates of the virus database, making it highly practical and effectively improving the security of data transmission. Attached Figure Description

[0030] The accompanying drawings, which form part of this specification, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings:

[0031] Figure 1 This is a system structure diagram of the present invention;

[0032] Figure 2 This is a schematic diagram illustrating the process of initiating cross-network transmission within an intranet in this invention;

[0033] Figure 3 This is a schematic diagram of the data transmission process from the intranet to the extranet in this invention. Detailed Implementation

[0034] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0035] In the description of this invention, it should be understood that the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0036] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0037] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Additionally, the character " / " in this invention generally indicates that the preceding and following objects have an "or" relationship.

[0038] It should be understood that although terms such as first, second, third, etc., may be used in the embodiments of the present invention to describe the preset range, these preset ranges should not be limited to these terms. These terms are only used to distinguish the preset ranges from one another. For example, without departing from the scope of the embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.

[0039] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."

[0040] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0041] The accompanying drawings illustrate various structural schematic diagrams according to embodiments disclosed in this invention. These drawings are not to scale, and some details have been enlarged for clarity, and some details may have been omitted. The shapes of the various regions and layers shown in the drawings, as well as their relative sizes and positional relationships, are merely exemplary and may deviate from reality due to manufacturing tolerances or technical limitations. Furthermore, those skilled in the art can design regions / layers with different shapes, sizes, and relative positions as needed.

[0042] Example 1

[0043] refer to Figure 1 The internal and external network file transfer system using a one-way gateway described in this invention includes an office intranet, an office extranet, an intranet server, an extranet server, a forward isolation device, and a reverse isolation device. The intranet server includes intranet cross-network data exchange software and intranet proxy software. The extranet server includes extranet proxy software and extranet cross-network data exchange software. The office extranet is connected to the extranet proxy software via the extranet cross-network data exchange software. The office intranet is connected to the intranet proxy software via the intranet cross-network data exchange software. The output of the intranet proxy software is connected to the input of the extranet proxy software via the forward isolation device. The output of the extranet proxy software is connected to the input of the intranet proxy software via the reverse isolation device.

[0044] The internal and external network file transfer system using a one-way gateway described in this invention can achieve the following functions:

[0045] 1) File transfer across networks;

[0046] Data is transmitted using the TCP protocol and adaptively compressed.

[0047] Files can be transferred between internal and external networks, supporting any file format.

[0048] The transmission progress is displayed in real time.

[0049] Provides functions for recording and querying transmission results.

[0050] Supports ultra-fast transfer of already transferred files.

[0051] It can support the simultaneous transfer of multiple files by multiple tasks.

[0052] 2) Virus detection and removal;

[0053] The software provides virus scanning and removal functions, has a built-in antivirus engine, supports the open-source ClamAV antivirus engine, and allows users to set timed updates of the antivirus engine.

[0054] 3) Sensitive file identification;

[0055] Both intranet and extranet cross-network data exchange software support custom sensitive information. Multiple identification methods can be used to improve the accuracy of sensitive information identification. For example, if a file transmitted across networks contains sensitive information, it can be directly intercepted or trigger subsequent approval processes. The following identification methods are supported:

[0056] 31) File format check: Identify file formats and block unknown formats, executable programs, code, encrypted files, multi-compressed files, etc., to ensure the blocking and monitoring of the spread of unknown malicious files.

[0057] 32) File attribute check: Check elements such as file size and MD5 hash. If they do not meet the cross-network requirements, the file will be directly blocked or the subsequent approval process will be triggered.

[0058] 33) File DNA check: Users upload sensitive files to the backend or automatically collect file DNA for cross-network files that have failed the approval process. Finally, file DNA is generated and checked based on the preset matching degree. If the matching degree is higher than the requirement, the current data is considered to be too important and should not be transmitted across the network. It can be directly intercepted or the subsequent approval process can be triggered.

[0059] 34) Document content inspection: Identify information in various locations such as the document body, headers and footers, and property pages, and match it with preset keyword values ​​or regular expressions to determine the frequency of occurrence.

[0060] 35) File recognition with reserved extension interfaces: This allows for expansion to recognize compressed file content, file types within files, source code within Office documents, text within images using OCR, and nested images within documents using OCR. Future development of new file recognition rules or the introduction of large AI models is also possible.

[0061] 4) Integrated approval process;

[0062] According to the preset data control process, the upload and cross-network data transmission behaviors that trigger the data sensitive information check are subject to approval management. The approval is carried out by roles such as data administrators. If the approval is not granted, the upload and cross-network behaviors are blocked.

[0063] 5) Personal cloud storage;

[0064] It offers a personal cloud storage function, supports username and password login, and automatically synchronizes user information between internal and external networks.

[0065] Administrators can configure the cloud storage space size, and users can check the cloud storage space usage after logging in.

[0066] After logging in, users can upload and download files of any format. When uploading files, they can enable sensitive file identification and virus scanning. Users can also delete files that they no longer need.

[0067] The cloud storage service supports both browser-based (BS) and client-based (CS) architectures. The CS architecture client supports drag-and-drop file uploads, allowing multiple files to be uploaded simultaneously.

[0068] It provides a recycle bin function, allowing files to be recovered within a fixed period after deletion, and also supports permanent deletion of files in the recycle bin.

[0069] 6) Connection management and data forwarding;

[0070] Intranet proxy software and extranet proxy software provide TCP connection management for upper-layer business systems. The intranet and extranet TCP connections maintain a one-to-one correspondence. Data from other software received by the intranet proxy software TCP connection is forwarded to the corresponding extranet software TCP connection, and data from other software received by the extranet proxy software TCP connection is forwarded to the corresponding intranet application software TCP connection.

[0071] Intranet proxy software and extranet proxy software provide connection management for data channels of dedicated security isolation devices in the power industry, and perform load balancing and fault redundancy for data channels of the same type.

[0072] 7) Supports forwarding different types of data;

[0073] Intranet proxy software and extranet proxy software use different subprocesses to forward different types of data, such as cross-network file data and intranet / extranet organizational structure synchronization data. Different types of data are independent of each other, and even if a certain type of data is abnormal, other types of data can still be forwarded normally.

[0074] 8) Load balancing and fault redundancy of multiple isolation devices;

[0075] The load balancing of the forward and reverse isolation devices uses a weighted round-robin strategy, which allocates requests according to the bandwidth weight of the isolation device, with the isolation device with a higher weight handling more requests.

[0076] The forward and reverse isolation devices have fault redundancy. When an isolation device fails, the agent software is still available, but the bandwidth will be reduced. The log records no longer use the abnormal isolation device. When the isolation device recovers, the agent software merges the recovered bandwidth of the isolation device to improve transmission efficiency.

[0077] 9) Resume data transmission after interruption;

[0078] Both intranet cross-network data exchange software and extranet cross-network data exchange software support the function of resuming interrupted transmission. If data transmission is interrupted due to network jitter, interruption or other reasons, the system will automatically record the data transmission position and automatically retransmit the data after the network is restored, so that data will not be lost due to network failure.

[0079] 10) Compression and encryption;

[0080] Both intranet and extranet proxy software support adaptive compression algorithms, automatically selecting whether to compress or not based on the file's compression ratio;

[0081] Intranet and extranet proxy software provide data encryption based on national cryptographic algorithms. Even if one-way TCP data is illegally eavesdropped on, the true content of the TCP data cannot be intercepted, thus increasing the security of the system.

[0082] 11) Supports multiple clients;

[0083] It supports three access methods: browser, Windows client, and Linux client. The web client provides services through a browser and supports Windows, Linux, and domestically produced terminals. The Linux client supports domestically produced chips from Zhaoxin, Hygon, Feipeng, and Kunpeng, as well as domestically produced operating systems from Kylin and Tongxin.

[0084] Example 2

[0085] refer to Figure 2 and Figure 3The method for transferring files between internal and external networks using a one-way gateway as described in this invention includes the following steps:

[0086] 1) Initiate cross-network transmission within the intranet;

[0087] The specific process of step 1) is as follows:

[0088] 11) The intranet cross-network data exchange software starts the cross-network task;

[0089] Intranet users initiate cross-network transfer tasks through the cloud storage client. The intranet cross-network data exchange software uses TCP to connect to the intranet proxy software and sends a message to initiate cross-network transfer.

[0090] 12) The intranet proxy software sends connection establishment and cross-network transmission initiation messages through the forward isolation device;

[0091] The internal network proxy software and the external network proxy software transmit data through a forward isolation device, using a unidirectional TCP data transmission channel. Data can only be sent from the internal network to the external network. A fixed data channel is established between the internal and external network proxy software upon system startup. When the internal network proxy software receives a new TCP connection from the cross-network switching system, it defines this connection establishment action as a new connection message and sends it to the external network proxy software.

[0092] 13) The external network proxy software connects to the external network cross-network data exchange software and forwards the message to initiate cross-network transmission;

[0093] When the external proxy software receives the connection establishment message sent by the internal proxy software, it establishes a TCP connection with the external cross-network data exchange software, and the external proxy software forwards the cross-network transmission start message to the external cross-network data exchange software.

[0094] 14) External network cross-network data exchange software initiates or interrupts cross-network transmission;

[0095] After receiving the message to start a cross-network transmission task, the external network cross-network data exchange software checks whether the user's permissions, the disk space of the user's network, etc., meet the conditions for cross-network transmission. If they meet the conditions, it replies that the cross-network transmission was started successfully; otherwise, it replies that the cross-network transmission failed and interrupts the cross-network transmission.

[0096] 2) Data transmission process from intranet to extranet;

[0097] After an intranet user initiates a cross-network transfer task, the intranet cross-network transfer software sends a maximum of 4MB of data to the external cross-network transfer software at a time (files larger than 4MB require multiple transmissions; if the file is smaller than 4MB, it is transferred according to its actual size). After the transmission is complete, the file hash value is verified to check if the file was transmitted correctly. The following is the process for sending a single 4MB of data across networks:

[0098] 21) The intranet cross-network data exchange software begins transmitting data;

[0099] The intranet cross-network data exchange software begins a single 4MB data transfer, using a TCP connection to send data to the intranet agent software.

[0100] 22) The intranet proxy software performs TCP data packet assembly, data processing, adds data packet headers, and forwards the data.

[0101] Because TCP data streams can experience packet fragmentation and reassembly, the intranet proxy software receives data multiple times and reassembles the data packets according to the agreed packet size and data transmission timeout.

[0102] After detecting that a complete data packet has been received, the data is compressed and encrypted.

[0103] Data compression strategy: When the data length L > 300 bytes, the data will be compressed. If the data compression rate C < 0.85 for 3 consecutive times, the session file is considered compressible and subsequent data in this session will be compressed directly. Otherwise, the data in this session will not be compressed.

[0104] The intranet proxy software uses the national cryptographic SM4 encryption algorithm in CTR mode to encrypt data and automatically synchronizes the encryption / decryption counter sequence, ensuring data security while also taking into account transmission efficiency and software stability.

[0105] A packet header is added, defining the packet type as "transmitted data" and including information such as the actual data length and whether the data is compressed. After data processing, the internal network proxy software forwards the packet to the external network proxy software through the forward isolation device.

[0106] 23) External network proxy software parses data packet headers, restores data, and forwards the original data;

[0107] The external network proxy software receives data packet headers and receives data based on these headers. After parsing the headers, it decrypts the data and, depending on the data compression attribute, chooses whether to decompress and restore the data. After restoring the data, the external network proxy software forwards the original data to the external network cross-network transmission and switching software.

[0108] 24) External network cross-network transmission and exchange of soft reply confirmation messages;

[0109] After storing the data, the external network cross-network transmission and exchange software sends a data confirmation packet back to the external network proxy software.

[0110] 25) External network proxy software processes data, adds data packet headers, and forwards them;

[0111] After receiving the complete data acknowledgment packet, the external proxy software compresses and encrypts it, using the same compression strategy and encryption method as described in Section 22). A data packet header is added, containing the data packet type, size, and whether the data packet is compressed. The data packet type is "Send Data Acknowledgment." After processing, the external proxy software forwards the acknowledgment data to the internal proxy software via the reverse isolation device.

[0112] 26) The intranet proxy software parses the data packet header, restores the data, and forwards the confirmation message;

[0113] The intranet proxy software receives the data packet header and receives confirmation data based on the data packet header. It then parses the data packet header to decrypt the data and selects whether to decompress and restore the data based on the data compression attribute. After the data is restored, the intranet proxy software forwards the original confirmation data to the intranet cross-network data exchange software.

[0114] Example 3

[0115] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the method for transferring files between internal and external networks using a unidirectional network gateway. The memory may include main memory, such as high-speed random access memory (RAM), and may also include non-volatile memory, such as at least one disk storage device. The processor, network interface, and memory are interconnected via an internal bus, which may be an industry-standard architecture bus, a peripheral component interconnection standard bus, or an extended industry-standard architecture bus. The bus can be categorized as an address bus, data bus, or control bus. The memory stores the program; specifically, the program may include program code, which includes computer operation instructions. The memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0116] Example 4

[0117] A computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method for transferring files between internal and external networks using a unidirectional network gateway. Specifically, the computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. The volatile memory may include random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include read-only memory (ROM), hard disk, flash memory, optical disk, magnetic disk, etc.

[0118] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0119] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0120] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0121] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0122] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and disclosure of the invention. This application is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.

[0123] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

[0124] The above description is merely a preferred embodiment of the present invention and does not constitute any limitation on the present invention. Any simple modifications, alterations, or equivalent structural changes made to the above embodiments based on the technical essence of the present invention shall still fall within the protection scope of the present invention.

Claims

1. A file transfer system between internal and external networks using a one-way gateway, characterized in that, This includes the office external network, external network server, office internal network, internal network server, forward isolation device, and reverse isolation device; The office external network is connected to the external network server, and the office internal network is connected to the internal network server. The output of the internal network server is connected to the input of the external network server through a forward isolation device, and the output of the external network server is connected to the input of the internal network server through a reverse isolation device.

2. The file transfer system between internal and external networks using a one-way gateway as described in claim 1, characterized in that, The intranet server includes intranet cross-network data exchange software and intranet proxy software, while the extranet server includes extranet proxy software and extranet cross-network data exchange software. The office extranet is connected to the extranet proxy software via the extranet cross-network data exchange software, and the office intranet is connected to the intranet proxy software via the intranet cross-network data exchange software. The output of the intranet proxy software is connected to the input of the extranet proxy software via a forward isolation device, and the output of the extranet proxy software is connected to the input of the intranet proxy software via a reverse isolation device.

3. A method for transferring files between internal and external networks using a one-way gateway, characterized in that, The file transfer system between internal and external networks using a one-way gateway as described in claim 2 includes initiating cross-network transmission within the internal network and transmitting data from the internal network to the external network.

4. The method for transferring files between internal and external networks using a one-way gateway according to claim 3, characterized in that, The process of initiating cross-network transmission within the intranet is as follows: The intranet cross-network data exchange software initiates a cross-network task. The intranet proxy software sends connection establishment and cross-network transmission initiation messages through the forward isolation device; The external network proxy software connects to the external network cross-network data exchange software and forwards the cross-network transmission message. External network cross-network data exchange software may initiate or interrupt cross-network transmission.

5. The method for transferring files between internal and external networks using a one-way gateway according to claim 4, characterized in that, The process by which the external network cross-network data exchange software initiates or interrupts cross-network transmission is as follows: After receiving the message to start a cross-network transmission task, the external network cross-network data exchange software checks the user's permissions and whether the disk space of the user's network meets the cross-network transmission conditions. If it does, it replies that the cross-network transmission was started successfully; otherwise, it replies that the cross-network transmission failed and interrupts the cross-network transmission.

6. The method for transferring files between internal and external networks using a one-way gateway according to claim 4, characterized in that, The process of transmitting data across networks from the intranet to the extranet is as follows: The intranet cross-network data exchange software begins transmitting data; The intranet proxy software performs TCP data packet assembly, data processing, adds packet headers, and forwards the data. The external network proxy software parses the data packet header, restores the data, obtains the original data, and then forwards the original data to the external network cross-network transmission and switching software; The external network cross-network transmission and exchange software stores the received data and sends a data confirmation packet back to the external network proxy software; The external network proxy software receives the data confirmation packet, compresses and encrypts it, adds a data packet header, and sends it to the internal network proxy software through the reverse isolation device. The intranet proxy software parses the data packet header, restores the data, and forwards the confirmation message.

7. The method for transferring files between internal and external networks using a one-way gateway according to claim 6, characterized in that, The process of initiating data transmission is as follows: The intranet cross-network data exchange software begins a single 4MB data transfer, using a TCP connection to send data to the intranet agent software.

8. The method for transferring files between internal and external networks using a one-way gateway according to claim 6, characterized in that, The data packet header contains the data packet type, data packet size, and whether the data packet is compressed or encrypted.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method for transferring files between internal and external networks using a one-way gateway as described in any one of claims 3-8.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method for transferring files between internal and external networks using a one-way gateway as described in any one of claims 3-8.