Data transmission device and method in network-free environment
By using a bridging controller and data sharding mechanism in a network-free environment, the problems of cumbersome operation and poor security in data exchange between computers are solved, achieving efficient and reliable physically isolated data transmission, which is suitable for data backup in a network-free environment.
Patent Information
- Application Number
- CN202511185037.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-12-02
AI Technical Summary
Existing technologies for data exchange between computers in network-free environments suffer from cumbersome operations, low transmission efficiency, and poor security. In particular, they are unable to meet the stability and security requirements of data transmission in scenarios requiring physical isolation.
By employing a bridge controller with a built-in central processing unit, shared random access memory, direct memory access controller, and USB controller, a direct transmission channel is established. Through data fragmentation and acknowledgment response mechanisms, physically isolated data exchange is achieved, and software development is simplified by utilizing standard USB communication device class configurations.
It enables efficient, reliable, stable and secure data exchange in offline environments, reduces the risk of data loss, improves cross-platform compatibility and transmission stability, and ensures the accuracy of backup data.
Smart Images

Figure CN121056451A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data transmission, specifically to a data transmission device and method in a network-free environment. Background Technology
[0002] In existing technologies, data exchange between two computers is mainly conducted through networks (such as local area networks) or removable storage media (such as USB flash drives and external hard drives). However, network-based methods are relatively complex to configure and cannot achieve physical-level security isolation, making them susceptible to cross-infection of viruses or data theft. Using removable storage media is cumbersome to operate, also carries the risk of virus transmission, and its transmission efficiency is limited by the read / write speed of the media. Furthermore, some software solutions that connect via special USB cables heavily rely on the CPU processing power of both computers for data transmission, consuming significant system resources, resulting in unstable transmission rates, and failing to provide true physical isolation, thus failing to meet the high requirements for data transmission security and stability. Summary of the Invention
[0003] The purpose of this invention is to provide a data transmission device and method in a network-free environment to solve the problems mentioned in the background art.
[0004] The technical solution of this invention is as follows: a data transmission device in a network-free environment, comprising a bridge controller, wherein the bridge controller internally includes a central processing unit, a shared random access memory, a direct memory access controller, a first USB controller, and a second USB controller; the device further includes a first USB device connector connected to the first USB controller and a second USB device connector connected to the second USB controller; the first USB device connector is used to connect to a controlling computer, and the second USB device connector is used to connect to a controlled computer; the central processing unit is used to execute firmware to schedule data flow; the direct memory access controller is used, under the scheduling of the central processing unit, to establish a direct data transmission channel between the first USB controller, the shared random access memory, and the second USB controller, thereby realizing physically isolated data exchange between the controlling computer and the controlled computer.
[0005] Preferably, the first USB controller and the second USB controller each have a dedicated endpoint buffer register for temporarily storing data packets received or to be sent by the USB device connector.
[0006] Preferably, both the first USB controller and the second USB controller are configured as USB communication device class or vendor-defined class devices to allow applications of the controlling computer and the controlled computer to directly access their endpoints through a standard driver interface.
[0007] Preferably, a data transmission method in a network-free environment includes: Define a transmission data packet composed of data fragments, the transmission data packet is used to carry service message packets, and is divided into a header fragment containing a header identifier, a payload fragment containing the content of the service message packet, and a tail fragment containing the integrity verification information of the service message packet; The control computer generates a first transmission data packet carrying a backup request service message packet, and sends data fragments constituting the first transmission data packet to the device via the first USB device connector; The device forwards received data fragments from the first USB controller to the second USB controller via its internal direct transmission channel, and then sends them to the controlled computer via the second USB device connector; The controlled computer receives and reassembles the data fragments. After verifying the data integrity according to the packet tail fragments, it executes the instruction of the backup request service message packet and generates a second transmission data packet carrying the backup response service message packet. The data packet is then transmitted back to the controlling computer via the device through the opposite path.
[0008] Preferably, the backup request service message packet is a file acquisition request message, and its content feature list includes a message type field and a path information field of the file to be backed up; the backup response service message packet is a file acquisition response message, and its content feature list includes a message type field, a file read status code field, and a file binary content field.
[0009] Preferably, the content feature list of the file acquisition response message further includes a file data digest field, which the control computer uses to perform a final verification of the file's integrity after receiving the complete backup file.
[0010] Preferably, an acknowledgment response mechanism is introduced during the transmission of the data fragments. An acknowledgment response fragment is defined, whereby the sending computer enters a waiting state after sending each data fragment, and the receiving computer sends back a corresponding acknowledgment response fragment after successfully receiving and verifying a data fragment. After receiving the acknowledgment response fragment, the sending computer continues to send the next data fragment, and if it does not receive it within a timeout period, it performs a retransmission.
[0011] Preferably, the application programs within the control computer and the controlled computer open communication handles with the device through a standard driver interface provided by the operating system, and receive and send the data fragments through read and write operations on specific endpoints.
[0012] This invention provides an improved data transmission device and method for offline environments, which has the following advantages compared with the prior art: By using a bridge controller with a built-in direct memory access controller, a direct transmission channel is established between the controlling computer and the controlled computer, realizing efficient and reliable data exchange under physical isolation, avoiding the cumbersome and inefficient traditional manual media exchange. By setting dedicated endpoint buffer registers for the first USB controller and the second USB controller, the timing of the USB bus and the internal data bus of the device is effectively decoupled, reducing the risk of data loss due to timing mismatch and improving the reliability of data transmission. By configuring the device as a standard USB communication device or a manufacturer-defined device, upper-layer applications can directly access its endpoints through the operating system's general driver interface, avoiding the development of dedicated drivers, reducing software development complexity and cost, and enhancing cross-platform compatibility. By introducing an acknowledgment mechanism during data fragmentation, the sender only continues sending after receiving an acknowledgment response fragment from the receiver. If a timeout occurs, retransmission is performed, ensuring that each transmission unit is reliably received and fundamentally improving the stability of large-volume data transmission. By adding a file data digest field to the file retrieval response message, the control computer can use the digest for final integrity verification after receiving the backup file, adding an application-level data confirmation that transcends transport layer verification, thereby further ensuring the accuracy of the backup data. Attached Figure Description
[0013] The present invention will be further explained below with reference to the accompanying drawings and embodiments: Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation
[0014] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments; it should be understood that the specific embodiments herein are only used to explain the invention and are not intended to limit the invention. Before proceeding with a detailed description, the core terms involved in this embodiment will be defined in a unified and clear manner to ensure the clarity and accuracy of the specification, which forms the basis for those skilled in the art to understand and implement the present invention; Reference Figure 1The diagram illustrates a data transmission device in a network-free environment, comprising a bridge controller. The bridge controller internally includes a central processing unit (CPU), shared random access memory (RAM), a direct memory access controller (DMI), a first USB controller, and a second USB controller. The device further includes a first USB device connector connected to the first USB controller and a second USB device connector connected to the second USB controller. The first USB device connector is used to connect to a controlling computer, and the second USB device connector is used to connect to a controlled computer. The CPU executes firmware to schedule data flow. The DMI, under the scheduling of the CPU, establishes a direct data transmission channel between the first USB controller, the RAM, and the second USB controller, thereby achieving physically isolated data exchange between the controlling computer and the controlled computer.
[0015] In some data management applications requiring strict physical isolation, existing technologies typically rely on manual storage media exchange, a cumbersome and inefficient process. This embodiment provides a data transmission device for network-free environments. Its core bridging controller integrates a central processing unit (CPU), shared random access memory (RAM), a direct memory access controller (DRAM), and first and second USB controllers, forming a dedicated data transfer channel. The CPU, such as an STM32H7 series microcontroller, executes firmware logic. When the controlling computer initiates data transmission via the first USB device connector, the CPU schedules the DRAM to establish a direct transmission channel between the first USB controller, RAM, and second USB controller. This channel allows data to flow rapidly and unidirectionally from the controlling computer to the controlled computer, or vice versa, without processing through a general network protocol stack. This physically isolated data exchange provides an efficient and reliable technical path for data backup in network-free environments.
[0016] The first USB controller and the second USB controller each have a dedicated endpoint buffer register for temporarily storing data packets received or to be sent by the USB device connector.
[0017] To ensure data stability during high-speed transmission, both the first and second USB controllers are designed with dedicated endpoint buffer registers. These endpoint buffer registers provide a hardware-level data storage area for USB transaction processing. When a data packet arrives from the computer via the USB device connector, it is completely stored in the endpoint buffer register, awaiting further processing by the direct memory access controller. Similarly, data destined for the computer is first loaded into this buffer. This design effectively decouples the timing of the USB bus from the timing of the device's internal data bus, providing the direct memory access controller with a stable and reliable data source and destination address, thereby reducing the risk of data loss due to timing mismatches and improving the reliability of data transmission.
[0018] Both the first USB controller and the second USB controller are configured as USB communication device class or vendor-defined class devices to allow applications of the controlling computer and the controlled computer to directly access their endpoints through standard driver interfaces.
[0019] To simplify the development and deployment of the host computer software, the first and second USB controllers are configured at the firmware level as standard USB communication device classes or vendor-defined device classes. This configuration aims to ensure that when the device is connected to the controlling or controlled computer, it can be recognized by the operating system and have a generic driver, such as WinUSB or libusb, loaded. This allows upper-layer applications to directly read and write to the device's endpoints through the standard driver interface provided by the operating system. This approach avoids developing dedicated kernel-mode drivers for the device, reducing software development complexity and cost, and enhancing the device's compatibility and usability across different operating system platforms.
[0020] A data transmission method in a network-free environment includes: defining a transmission data packet composed of data fragments, the transmission data packet being used to carry a service message packet, and being divided into a header fragment containing a header identifier, a payload fragment containing the content of the service message packet, and a tail fragment containing integrity verification information of the service message packet; generating a first transmission data packet carrying a backup request service message packet on a control computer, and sending the data fragments constituting the first transmission data packet to the device via a first USB device connector; the device forwarding the received data fragments from the first USB controller to a second USB controller via its internal direct transmission channel, and sending them to the controlled computer via the second USB device connector; receiving and reassembling the data fragments on the controlled computer, verifying data integrity according to the tail fragment, executing the instruction of the backup request service message packet, generating a second transmission data packet carrying a backup response service message packet, and transmitting it back to the control computer via the device through the reverse path.
[0021] The backup method provided in this embodiment is based on establishing a structured data transmission protocol. This method first defines a three-layer data structure: data fragments, the smallest physical transmission unit; transmission data packets, logically encapsulated units; and service message packets carrying specific instructions. When a backup operation is required, the application program on the control computer encapsulates a backup request instruction into a service message packet, and then wraps this service message packet into a transmission data packet consisting of a header fragment, a payload fragment, and a tail fragment. Subsequently, these data fragments are sent sequentially to the device. The direct transmission channel within the device transparently forwards these fragments from one end to the other according to firmware logic. After receiving all the fragments, the controlled computer reconstructs the transmission data packet according to the fragment type and uses the checksum information in the tail fragment to verify whether any errors occurred in the service message packet during transmission. Only after successful verification is the backup instruction executed. This process is also applicable to the controlled end's return of backup data. By defining a clear data structure and interaction process, the accuracy and integrity of complex business operations performed on physically isolated channels are ensured.
[0022] The backup request service message packet is a file acquisition request message, and its content feature list includes a message type field and a path information field for the file to be backed up; the backup response service message packet is a file acquisition response message, and its content feature list includes a message type field, a file read status code field, and a file binary content field.
[0023] To clarify the business logic of data backup, the backup request business message packet is specifically defined as a file retrieval request message. The content feature list of this message is designed to include a clearly defined message type field and a path information field for the file to be backed up. When the controlling computer needs to back up a file on the controlled computer, its application constructs such a message, specifying the operation type and providing the exact storage location of the file. After parsing this message, the controlled computer locates and reads the file based on the path information field, and then constructs a file retrieval response message. The content feature list of this response message includes a message type field, a file read status code field indicating the file read result, and a binary content field carrying all the file's contents. Through this structured message definition, both computers can accurately understand each other's intentions and operation results, making the file-level data backup request and response process standardized and efficient.
[0024] The content feature list of the file acquisition response message further includes a file data digest field. After receiving the complete backup file, the control computer uses this digest field to perform a final verification of the file's integrity.
[0025] To further ensure the accuracy of backup data at the application level, the content feature list of the file retrieval response message has been expanded to include a file data digest field. After the controlled computer successfully reads the file to be backed up, it uses a deterministic hash algorithm, such as SHA-256, to calculate a fixed-length digest value from the complete binary content of the file and places this digest value into the file data digest field. Upon receiving a response message containing the file binary content field, the controlling computer also performs the same hash calculation on the received file content. By comparing its calculated digest value with the value of the file data digest field in the message, the controlling computer can reliably determine whether the backup file has maintained its integrity throughout the end-to-end process, thus adding an application-level data confirmation layer that goes beyond transport layer verification.
[0026] During the transmission of the data fragments, an acknowledgment response mechanism is introduced. An acknowledgment response fragment is defined. After each data fragment is sent, the sending computer enters a waiting state. After successfully receiving and verifying a data fragment, the receiving computer sends back a corresponding acknowledgment response fragment. After receiving the acknowledgment response fragment, the sending computer continues to send the next data fragment. If it does not receive the acknowledgment response fragment within a timeout period, it performs a retransmission.
[0027] To address potential momentary communication interruptions or data errors during USB transmission, an acknowledgment mechanism is introduced during data fragment transmission. The core of this mechanism is the definition of a special acknowledgment fragment. During data transmission, the sending computer pauses transmission and starts a timer after sending a data fragment. Whenever the receiving computer successfully receives a data fragment and verifies its integrity using its internal checksum, it immediately constructs and sends back an acknowledgment fragment. The sending computer will only continue sending subsequent data fragments if it receives this acknowledgment fragment before the timer expires. If no acknowledgment is received before the timer expires, the sending end assumes the previous data fragment has been lost and retransmits it. This fragment-by-fragment acknowledgment mechanism ensures that every smallest transmission unit in the data stream is reliably received by the other party, fundamentally improving the stability and reliability of large-volume data transmission over physical channels.
[0028] The application programs within the control computer and the controlled computer open communication handles with the device through the standard driver interface provided by the operating system, and receive and send data fragments through read and write operations on specific endpoints.
[0029] To enable communication between the application and the hardware device, the application within both the controlling and controlled computers utilizes standard driver interfaces provided by the operating system. When the application starts, it uses these interfaces to locate and open a handle for communication with the device, a process similar to opening a local file or port. Once the communication handle is successfully acquired, the application can use simple read / write functions to write data to specific output endpoints of the device to send data fragments, or read data from specific input endpoints to receive data fragments. The aim of this approach is to abstract the complex low-level USB protocol communication into high-level file streaming operations, allowing application developers to focus on business logic implementation without worrying about hardware details. This significantly simplifies software development and improves software stability and portability.
[0030] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A data transmission device for use in a network-free environment, characterized in that: The device includes a bridge controller, which internally houses a central processing unit, shared random access memory, a direct memory access controller, a first USB controller, and a second USB controller. The device also includes a first USB device connector connected to the first USB controller and a second USB device connector connected to the second USB controller. The first USB device connector is used to connect to a controlling computer, and the second USB device connector is used to connect to a controlled computer. The central processing unit executes firmware to schedule data flow. The direct memory access controller, under the scheduling of the central processing unit, establishes a direct data transmission channel between the first USB controller, the shared random access memory, and the second USB controller, thereby enabling physically isolated data exchange between the controlling computer and the controlled computer.
2. The data transmission device in a network-free environment according to claim 1, characterized in that: The first USB controller and the second USB controller each have a dedicated endpoint buffer register for temporarily storing data packets received or to be sent by the USB device connector.
3. The data transmission device in a network-free environment according to claim 1, characterized in that: Both the first USB controller and the second USB controller are configured as USB communication device class or vendor-defined class devices to allow applications of the controlling computer and the controlled computer to directly access their endpoints through standard driver interfaces.
4. A data transmission method in a network-free environment, applied to the data transmission device in a network-free environment as described in claims 1-3, characterized in that, include: Define a transmission data packet composed of data fragments, the transmission data packet is used to carry service message packets, and is divided into a header fragment containing a header identifier, a payload fragment containing the content of the service message packet, and a tail fragment containing the integrity verification information of the service message packet; The control computer generates a first transmission data packet carrying a backup request service message packet, and sends data fragments constituting the first transmission data packet to the device via the first USB device connector; The device forwards received data fragments from the first USB controller to the second USB controller via its internal direct transmission channel, and then sends them to the controlled computer via the second USB device connector; The controlled computer receives and reassembles the data fragments. After verifying the data integrity according to the packet tail fragments, it executes the instruction of the backup request service message packet and generates a second transmission data packet carrying the backup response service message packet. The data packet is then transmitted back to the controlling computer via the device through the opposite path.
5. A data transmission method in a network-free environment according to claim 4, characterized in that: The backup request service message packet is a file acquisition request message, and its content feature list includes a message type field and a path information field for the file to be backed up; the backup response service message packet is a file acquisition response message, and its content feature list includes a message type field, a file read status code field, and a file binary content field.
6. The data transmission method in a network-free environment according to claim 5, characterized in that: The content feature list of the file acquisition response message further includes a file data digest field. After receiving the complete backup file, the control computer uses this digest field to perform a final verification of the file's integrity.
7. A data transmission method in a network-free environment according to claim 4, characterized in that: During the transmission of the data fragments, an acknowledgment response mechanism is introduced; an acknowledgment response fragment is defined, in which the sending computer enters a waiting state after sending each data fragment, and the receiving computer sends back a corresponding acknowledgment response fragment after successfully receiving and verifying a data fragment. After receiving the acknowledgment response fragment, the sending computer continues to send the next data fragment. If it does not receive the response fragment within a timeout period, it will retransmit the data.
8. A data transmission method in a network-free environment according to claim 4, characterized in that: The application programs within the control computer and the controlled computer open communication handles with the device through the standard driver interface provided by the operating system, and receive and send data fragments through read and write operations on specific endpoints.
Citation Information
Patent Citations
Data transmission method and device, electronic equipment and storage medium
CN117453615A
Utilizing USB bridge interconnection for computing power sharing system
TWM670525U