Cross-network data security interaction method and system between security isolation networks
By implementing in-depth security auditing and content reconstruction on the private network side, the security blind spot problem of encrypted channels in the secure isolation network architecture is solved, and the security and controllability of cross-network data transmission are improved.
Patent Information
- Application Number
- CN202511503334.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-21
- Publication Date
- 2026-01-13
AI Technical Summary
In existing secure isolation network architectures, boundary isolation devices such as network gateways cannot decrypt and perform deep content inspection on the transmitted payload of end-to-end encrypted channels, making the encrypted channels a security blind spot that attackers can exploit to leak data and launch attacks.
Deep security auditing is implemented on the private network side. By obtaining users' historical and daily behavioral characteristics, access requests are audited for security, and encryption, content reconstruction, and protocol standardization are performed to generate standardized access requests. These requests are then sent to the Internet side through a network gateway to achieve secure access to the Internet.
It effectively identifies and blocks malicious attacks hidden in encrypted channels, achieves deep cleaning and formatting of transmitted data, eliminates security blind spots, and improves the security and controllability of cross-network data transmission.
Smart Images

Figure CN121333697A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data transmission technology, and in particular to a method and system for secure cross-network data interaction between securely isolated networks. Background Technology
[0002] As the informatization level of sectors such as government, finance, and military continues to improve, the demand for data interaction between dedicated business networks and the Internet is becoming increasingly frequent. However, due to security and compliance requirements, these critical information systems typically adopt a secure isolation network architecture, that is, to securely isolate the dedicated business network from the Internet through network boundary security products such as network gateways or optical gateways, in order to prevent the leakage of sensitive information and external attacks and intrusions.
[0003] In existing technologies, network gateways, optical gateways, and other boundary isolation devices primarily rely on protocol stripping and shallow content filtering technologies. Their security mechanisms have a fundamental weakness: to ensure transmission efficiency and maintain physical / logical isolation, these devices typically do not decrypt or perform deep content inspection on end-to-end encrypted (such as SSL / TLS or Chinese cryptographic algorithms) transmission payloads. This makes the encrypted channel itself a "security blind spot." Attackers (such as malicious internal users or external attackers who have infiltrated the private network) can exploit this blind spot to pre-embed malicious scripts, data-disclosing code, or APT attack payloads into the data at the source of the request before transmitting it through the encrypted channel. Network gateway devices can only check the "external" characteristics of data packets, such as protocol compliance, allowing malicious content hidden in encrypted traffic to easily bypass boundary security detection, directly leading to serious security risks such as data leakage and persistent attacks.
[0004] Therefore, how to improve the security of data transmission under a secure isolated network architecture has become a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] In view of this, this disclosure proposes a method and system for secure cross-network data interaction between secure isolated networks, which can improve the security of data transmission under a secure isolated network architecture.
[0006] According to a first aspect of this disclosure, a method for secure cross-network data interaction between securely isolated networks is provided, the method being implemented on the private network side, including: In response to a user's request to access the Internet from the private network side, an access request is generated from the Internet side. Based on the access request, the user's historical behavior characteristics and current day behavior characteristics are obtained, and the access request is security audited based on the historical behavior characteristics and the current day behavior characteristics. Access requests that pass the security audit are encrypted, reconstructed, and standardized according to protocols to generate standardized access requests. These standardized access requests are then sent to the Internet via a network gateway to achieve secure access to the Internet.
[0007] In one possible implementation, when obtaining the user's historical behavioral characteristics and current day's behavioral characteristics based on the access request, the following is included: User information is parsed from the access request; Based on the user information, obtain historical behavioral characteristics associated with the user information; Based on the user information, obtain the daily session information associated with the user information, and parse the daily session information to obtain the daily behavioral characteristics.
[0008] In one possible implementation, when performing security audits on the access requests based on the historical behavioral characteristics and the current day's behavioral characteristics, the following is included: Based on the aforementioned historical behavioral characteristics, it is determined whether the user is a high-risk user; If it is determined that the user is not a high-risk user, based on the historical behavioral characteristics and the current day's behavioral characteristics, it is determined whether the user has any abnormal behavior; If it is determined that the user does not exhibit any abnormal behavior, the access request is processed for sensitive information to obtain an access request that passes the security audit.
[0009] In one possible implementation, determining whether the user exhibits abnormal behavior based on the historical behavioral characteristics and the current day's behavioral characteristics includes: Based on the behavioral characteristics of the day and the preset static audit rules, it is initially determined whether the user has any abnormal behavior; If it is initially determined that the user does not have any abnormal behavior, then based on the historical behavior characteristics and the current day's behavior characteristics, it is determined again whether the user has any abnormal behavior. If the user is found to have no abnormal behavior again, the session information to which the access request belongs is obtained, and based on the session information to which the access request belongs, the user is finally determined to have no abnormal behavior.
[0010] In one possible implementation, a circuit breaker session is triggered for access requests that fail the security audit, and a corresponding security alert is pushed.
[0011] In one possible implementation, the security audit also includes generating a security audit log and storing the security audit log in anonymized form.
[0012] According to a second aspect of this disclosure, a method for secure cross-network data interaction between securely isolated networks is provided, the method being implemented on the Internet side, including: Obtain standardized access requests sent from the private network side; Based on the standardized access request, the browser is automatically opened and the corresponding Internet page is accessed, or the corresponding response data is generated.
[0013] In one possible implementation, after generating the corresponding response data, the following is also included: Sensitive information processing is performed on the response data to obtain desensitized response data; The de-identified response data is encrypted, its content reconstructed, and its protocol standardized to generate standardized response data. The standardized response data is returned to the private network side through the network gateway.
[0014] According to a third aspect of this disclosure, a cross-network data security interaction system between securely isolated networks is provided, comprising: a private network side device and an internet side device, wherein the private network side device includes a first user terminal deployed on the private network side, a security detection module, and a private network security proxy gateway; the internet side device includes a second user terminal deployed on the internet side and a data and content filtering module; The first user terminal is used to generate an access request from the Internet side in response to a user on the private network side accessing the Internet. The security detection module is used to obtain the user's historical behavior characteristics and current behavior characteristics based on the access request, and to perform security audit on the access request based on the historical behavior characteristics and the current behavior characteristics. The dedicated network security proxy gateway is used to encrypt, reconstruct, and standardize the protocol of the access requests that pass the security audit, generate standardized access requests, and send the standardized access requests to the Internet side through the network gateway to achieve secure access to the Internet. The second user terminal is used to obtain standardized access requests sent by the private network side, and based on the standardized access requests, automatically open a browser and access the corresponding Internet page and / or generate corresponding response data; The data and content filtering module is used to process the response data for sensitive information to obtain desensitized response data, encrypt the desensitized response data, reconstruct the content and standardize the protocol to generate standardized response data, and return the standardized response data to the private network side through the network gateway.
[0015] In one possible implementation, the security detection module is further configured to: generate security audit logs during security auditing, and store the security audit logs in anonymized form.
[0016] This disclosure provides a method and system for secure cross-network data interaction between securely isolated networks. The method includes: responding to a user's access to the Internet from the private network side and generating an access request from the Internet side; based on the access request, obtaining the user's historical and current behavioral characteristics, and performing security auditing on the access request based on these characteristics; encrypting, reconstructing, and standardizing the protocol of the audited access request to generate a standardized access request, and sending the standardized access request to the Internet side through a network gateway to achieve secure access to the Internet. This method can improve the security of data transmission under a securely isolated network architecture.
[0017] Other features and aspects of this disclosure will become clear from the following detailed description of exemplary embodiments with reference to the accompanying drawings. Attached Figure Description
[0018] The accompanying drawings, which are included in and form part of this specification, illustrate exemplary embodiments, features, and aspects of this disclosure together with the specification and serve to explain the principles of this disclosure.
[0019] Figure 1 A flowchart illustrating a method for secure cross-network data interaction between securely isolated networks according to an embodiment of the present disclosure is shown. Figure 2 A flowchart illustrating a method for secure cross-network data interaction between secure isolated networks according to another embodiment of this disclosure; Figure 3 A flowchart illustrating a method for secure cross-network data interaction between secure isolated networks according to yet another embodiment of the present disclosure; Figure 4 A schematic block diagram of a cross-network data security interaction system between secure isolated networks according to an embodiment of the present disclosure is shown. Detailed Implementation
[0020] Various exemplary embodiments, features, and aspects of this disclosure will now be described in detail with reference to the accompanying drawings. The same reference numerals in the drawings denote elements that have the same or similar functions. Although various aspects of the embodiments are shown in the drawings, they are not necessarily drawn to scale unless specifically indicated otherwise.
[0021] The term “exemplary” as used herein means “serving as an example, embodiment, or illustration.” Any embodiment illustrated herein as “exemplary” is not necessarily to be construed as superior to or better than other embodiments.
[0022] Furthermore, to better illustrate this disclosure, numerous specific details are set forth in the following detailed description. Those skilled in the art will understand that this disclosure can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art have not been described in detail in order to highlight the main points of this disclosure.
[0023] <Method Example 1> Figure 1 A flowchart illustrating a method for secure cross-network data interaction between securely isolated networks according to an embodiment of this disclosure is shown. This method is implemented on the private network side, such as... Figure 1 As shown, the method includes steps S1100-S1300.
[0024] S1100, in response to a user's request to access the Internet from the private network side, generates an access request from the Internet side. Specifically, this access request is a JSON access request. After a user triggers Internet access from the private network side, anti-JS HOOK and anti-packet sniffing mechanisms are used to generate the Internet-side access request, effectively resisting attacks such as debugging injection during request generation.
[0025] S1200, based on access requests, obtains the user's historical and current day behavioral characteristics, and performs security audits on the access requests based on these characteristics. Historical behavioral characteristics include at least one of the following: frequently used IP address, frequently used User-Agent (UA), frequently used login location, frequently used device ID, average daily login frequency, operation time period distribution, and the current user's risk level label (low-risk, medium-risk, high-risk). Current day behavioral characteristics include at least one of the following: current day IP address, current day UA, current day login location, current day device ID, current day login frequency, and current day operation time period distribution.
[0026] In one possible implementation, when obtaining a user's historical and current behavioral characteristics based on an access request, the following steps may be included: First, user information is parsed from the access request. This user information can be a user ID or username used to uniquely identify a user; no specific limitation is made here.
[0027] Second, based on user information, historical behavioral characteristics associated with that information are obtained. Specifically, all historical session information of the user within the most recent defined time period is first obtained based on the user information. Then, statistical analysis is performed on all the obtained historical session information to obtain the user's frequently used IP address, frequently used User-Agent (UA), frequently used login location, frequently used device ID, average daily login frequency, and distribution of operation time periods, among other historical behavioral characteristics. It should also be noted that each time a user initiates an internet access request, a security audit is performed. During the security audit process, the user's risk level is determined based on the audit results, and the corresponding risk level label (low risk, medium risk, high risk) is recorded. Thus, after obtaining all historical session information of the user within the most recent defined time period, each historical session is iterated through. For the current historical session, the risk level label corresponding to all access requests in the current historical session is obtained. After the iteration is complete, the risk level labels corresponding to all access requests initiated by the user within the most recent defined time period are obtained. Based on the risk level labels corresponding to all access requests obtained, the current user's risk level label is determined.
[0028] Third, based on user information, obtain the daily conversation information associated with the user information, and parse the daily conversation information to obtain the user's daily behavioral characteristics. Specifically, statistical analysis of the obtained daily conversation information can yield the user's daily behavioral characteristics.
[0029] After obtaining a user's historical and current behavioral characteristics, security auditing can be performed on access requests based on these characteristics. The specific security auditing steps are as follows: First, based on historical behavioral characteristics, determine whether the user is a high-risk user. Specifically, historical behavioral characteristics include the current user's risk level label. If the current user's risk level label is high-risk, the user can be determined to be a high-risk user; otherwise, the user is a medium-to-low-risk user. If the user is determined to be a high-risk user, the current session request will be immediately interrupted (circuit breaker), triggering an automatic blocking process, generating a high-priority security alert for the security team or administrator to handle, and exiting the security audit process. This process will be referred to as the high-risk alert process below. If the user is determined to be a medium-to-low-risk user, the second step is allowed to proceed, but a medium-to-low-priority security alert will be generated simultaneously for the security team or administrator to handle, for manual review and subsequent adjustment of the user's risk level label. This process will be referred to as the medium-to-low-risk alert process below.
[0030] Second, if the user is determined not to be a high-risk user (i.e., the user is a low-to-medium risk user), then determine whether the user exhibits high-risk abnormal behavior. The specific detection process can be as follows: First, based on the user's behavioral characteristics for the day and preset static audit rules, a preliminary assessment is made to determine whether the user exhibits any high-risk abnormal behavior. These preset static audit rules include: blacklisted IP addresses, blacklisted user agents, blacklisted device IDs, blacklisted login locations, maximum daily login / operation counts, and allowed operation time periods. If any of these static audit rules are matched, the user is deemed to have exhibited high-risk abnormal behavior, and a high-risk alert process is initiated; otherwise, the user is deemed not to have exhibited high-risk abnormal behavior, and the next step is allowed, while a medium-to-low-risk alert process is initiated.
[0031] Secondly, after initially determining that a user does not exhibit high-risk abnormal behavior, a second assessment is made based on historical and current behavioral characteristics to determine whether the user exhibits high-risk abnormal behavior. This can be achieved using at least one dynamic abnormal behavior detection method from the following sources: distance metrics, probabilistic statistical models, and dynamic audit rules.
[0032] When determining whether a user exhibits high-risk abnormal behavior based on distance metrics, the following steps can be included: First, the user's multi-dimensional historical behavior features and multi-dimensional current-day behavior features are vectorized to obtain historical behavior feature vectors and current-day behavior feature vectors, respectively. Then, the cosine similarity between the historical behavior feature vectors and the current-day behavior feature vectors is calculated. Finally, the relationship between the cosine similarity and the preset safety baseline and high-risk threshold is determined: If the cosine similarity exceeds the high-risk threshold, it indicates a significant deviation between the user's current-day behavior and historical normal behavior, thus determining that the user exhibits high-risk abnormal behavior and initiating a high-level alarm process. If the cosine similarity exceeds the safety baseline but does not exceed the high-risk threshold, it indicates a slight deviation between the user's current-day behavior and historical normal behavior, thus determining that the user exhibits medium-to-low-risk abnormal behavior, allowing the next step to proceed and initiating a medium-to-low-risk alarm process. If the cosine similarity does not exceed the safety baseline, it indicates that the user's current-day behavior is consistent with historical normal behavior, i.e., no abnormal behavior has occurred, and the next step of judgment is directly executed. The formula for calculating the cosine similarity is shown below: In the formula, For the user's historical behavior feature vector, This is the user's behavioral feature vector for the day.
[0033] When determining whether a user exhibits high-risk abnormal behavior based on probabilistic statistical models, the process may include the following steps: First, obtain all historical session information of the user within the most recent set time period based on user information. Then, perform statistical analysis on all obtained historical session information to generate Gaussian distribution curves for various historical behavioral characteristics, such as IP address, User Agent, login location, device ID, number of logins, and operation time. Next, iterate through the Gaussian distribution curves of each historical behavioral characteristic. Based on the Gaussian distribution curve of the current historical behavioral characteristic, calculate the probability density of the corresponding daily behavioral characteristic on its Gaussian distribution curve. Based on the probability density of the corresponding daily behavioral characteristic on its Gaussian distribution curve, determine the deviation between the corresponding daily behavioral characteristic and historical normal behavioral characteristics. After the iteration, obtain the deviation between each daily behavioral characteristic and historical normal behavioral characteristics. Finally, based on the deviation between each daily behavioral characteristic and historical normal behavioral characteristics, determine whether the user exhibits abnormal behavior and the level of abnormal behavior. If the user is determined to have high-risk abnormal behavior, initiate a high-level alarm process. If the user is determined to have only low-to-medium level abnormal behavior, allow execution to proceed to the next step and initiate a low-to-medium risk alarm process. If it is determined that the user does not exhibit any abnormal behavior, proceed to the next step of the judgment.
[0034] The expressions for the Gaussian distribution curves of each historical behavioral characteristic are shown below: In the formula, Let the probability density of the behavioral characteristics of the day be the Gaussian distribution curve. This is a numerical representation of the behavioral characteristics of the day. This represents the average value of the historical behavioral characteristics corresponding to the current behavioral characteristics. Let be the numerical standard deviation of the historical behavioral characteristics corresponding to the current behavioral characteristics. The numerical standard deviation of the historical behavioral characteristics corresponding to the current behavioral characteristics.
[0035] When determining whether a user exhibits high-risk abnormal behavior based on dynamic audit rules, the following steps may be included: First, obtain pre-defined dynamic audit rules, which set dynamic detection rules for each security level. Each level's detection rules consist of detection thresholds for multiple dimensions of features, such as IP change thresholds, device number change thresholds, and geographic location offset thresholds. Second, determine whether the relationship between current and historical behavioral characteristics satisfies the dynamic detection rules for each security level, thereby determining whether the user exhibits abnormal behavior of the corresponding level. Similarly, if the user is determined to exhibit high-risk abnormal behavior, a high-level alarm process is initiated. If the user is determined to exhibit only low-to-medium level abnormal behavior, the next step is allowed and a low-to-medium risk alarm process is initiated. If the user is determined not to exhibit any abnormal behavior, the next step is directly executed.
[0036] Finally, upon re-evaluating that the user does not exhibit any high-risk abnormal behavior, the session information to which the access request belongs is obtained. Based on this session information, the system ultimately determines whether the user exhibits any high-risk abnormal behavior. Specifically, the session information to which the access request belongs is obtained, along with all access requests within that session. The consistency between these access requests and whether each access request constitutes a complete session are then assessed. Based on the consistency and integrity results, the system determines whether the user exhibits abnormal behavior and the severity of such behavior. Similarly, if the user is determined to exhibit high-risk abnormal behavior, a high-level alert process is initiated. If the user is determined to exhibit only low-to-medium-level abnormal behavior, the next step is allowed, and a low-to-medium-risk alert process is initiated. If the user is determined to exhibit no abnormal behavior, the system proceeds to the next step of sensitive information processing.
[0037] Third, if it is ultimately determined that the user does not exhibit any high-risk or abnormal behavior, the access request undergoes sensitive information processing to obtain an access request that passes the security audit. This may specifically include the following steps: First, the access request is parsed. Specifically, for structured data in the access request, such as JSON data, form parameters, and database fields, key-value pairs are identified. For document files included in the access request, such as PDFs, Word documents, and Excel files, the built-in document content parsing engine extracts the text content. For images or scanned documents included in the access request, the OCR engine automatically extracts the text content. This OCR engine supports multilingual recognition. By introducing the document content parsing engine and the OCR engine, text recognition of document files, images, and scanned documents in access requests can be achieved, thus ensuring that sensitive information in document files, images, and scanned documents attached to access requests can also be processed, improving the coverage of sensitive information processing.
[0038] Secondly, based on a pre-configured sensitive information detection algorithm, sensitive information is detected in the text content parsed from the access request. This algorithm comprehensively utilizes multiple methods, including regular expression rule base detection, sensitive field name detection, and keyword blacklist detection, to achieve a comprehensive scan of content in different formats.
[0039] Specifically, for the structured text in the access request, each parsed key-value pair is checked to see if the key field contains any sensitive fields specified in the sensitive field database. The sensitive fields specified in the database can include password, token, phone number, idNumber, etc. This database can be managed through a configuration center and supports multi-tenancy, multi-environment isolation, and online hot updates.
[0040] The system sequentially performs regular expression rule base detection and keyword blacklist detection on text content identified from document files, images, and scanned documents. Regular expression rule base detection first scans the text content, using predefined regular expression patterns to identify sensitive information with fixed formats, such as ID card numbers, mobile phone numbers, email addresses, and bank card numbers. The regular expression rule base is also managed by the configuration center, supporting rule version control and hot updates for rapid adaptation to new detection requirements. Text content that fails to match the regular expression rules further enters the keyword blacklist detection stage: the system compares the text with a multi-level categorized keyword blacklist to detect whether it contains prohibited or risky words defined in the blacklist. The keyword blacklist is also centrally managed and dynamically updated through the configuration center.
[0041] Furthermore, the aforementioned sensitive field name detection and keyword blacklist detection both support multilingual word segmentation, fuzzy matching, and synonym expansion, thereby improving the accuracy of sensitive information identification.
[0042] After identifying the aforementioned sensitive information, sensitive word detection results will be generated based on the identification results. Specifically, if illegal / violation content is detected during sensitive information detection, the access request will be marked as "illegal data," the current request or storage process will be immediately terminated, a standardized error response will be returned, a security alert log will be recorded, the information will be written to the compliance audit system, and a security notification (email, SMS, IM robot, SIEM integration) will be triggered. If legal but sensitive content is detected during sensitive information detection, the access request will be marked as "requires de-identification" and de-identification will be performed, resulting in an access request that passes the security audit. If no illegal data or data requiring de-identification is detected during sensitive information detection, the access request will be directly treated as an access request that passes the security audit.
[0043] When performing desensitization on access requests that require data masking, the following steps can be included: Iterating through the sensitive words contained in the text content of the access request; for each currently detected sensitive word, obtaining the desensitization level set for that word; obtaining a desensitization template matching that level; and using that template to mask the sensitive word. After the iteration is complete, the desensitized access request will be acceptable for security auditing. The desensitization levels for each sensitive word and the corresponding desensitization templates can be visually managed and updated online through a configuration center.
[0044] By performing the above-mentioned sensitive word detection and de-identification processing, access requests that have passed the security audit can be returned.
[0045] In one possible implementation, security auditing also includes generating security audit logs and storing them in anonymized form. These security audit logs include information such as the processing time, target, algorithm, result, and any related alarms triggered for each processing step. Furthermore, each operation performed on both the private network and internet sides during the entire data interaction process of the access request will also generate corresponding security audit logs. All security audit logs for this access request will be aggregated to generate a fully visualized audit chain for the entire access request process, ensuring that all interactive operations are traceable, auditable, and archiveable.
[0046] In this embodiment, a comprehensive logging and auditing mechanism runs throughout the entire process, covering all processing operations from request initiation, inter-network bridging, and data response to terminal reception. The visualized audit chain breaks down the audit silos of traditional network boundary security products such as gateways or optical gateways, ensuring that every data exchange is traceable, monitorable, and responsive. All security audit logs support anonymized storage and contextual traceability, providing a complete chain of evidence for anomaly analysis, responsibility allocation, and risk review, ultimately achieving legal compliance and secure controllable cross-network data interaction between securely isolated networks.
[0047] After receiving the access request that has passed the security audit, step S1300 is executed. This involves encrypting, reconstructing the content, and standardizing the protocol of the security-audited access request to generate a standardized access request. This standardized access request is then sent to the internet side via a network gateway to achieve secure internet access. Specifically, after obtaining the security-audited access request, it is first encrypted using the national cryptographic algorithm SM4, and then transmitted via an HTTPS channel, ensuring that the data is not intercepted or tampered with during transmission. Simultaneously, the returned data is also decrypted using SM4 and sent back to the user terminal on the private network side, thus forming an end-to-end encrypted closed loop to ensure link security. After encrypting the access request, the encrypted access request is further reconstructed and standardized via a content security proxy gateway deployed on the private network side. This ensures that the processed access request is compatible with modern web technology architectures, improving system availability and compatibility.
[0048] This disclosure provides a method for secure cross-network data interaction between securely isolated networks. The method is implemented on the private network side and includes: responding to a user's access to the Internet on the private network side and generating an access request on the Internet side; based on the access request, obtaining the user's historical behavior characteristics and current day behavior characteristics, and performing security audit on the access request based on the historical behavior characteristics and current day behavior characteristics; encrypting, reconstructing the content, and standardizing the protocol of the access request that passes the security audit to generate a standardized access request, and sending the standardized access request to the Internet side through a network gateway to achieve secure access to the Internet.
[0049] This disclosure effectively addresses the inherent security blind spots in traditional isolation architectures relying on network gateways or optical gateways by implementing deep security auditing and proactive content control on the private network side. Background technology indicates that because boundary devices typically do not decrypt or perform deep inspection of encrypted payloads, attackers can exploit this blind spot to hide malicious content. This solution moves the security defense line forward to the private network side, performing real-time security auditing before data transmission. This allows for the identification and blocking of abnormal access attempts, preventing malicious attacks hidden in encrypted channels from reaching the boundary. Furthermore, by reconstructing the content and standardizing the protocols of audited requests, deep cleaning and formatting of transmitted data is achieved, effectively stripping away potential malicious code, desensitizing sensitive information, and eliminating security risks caused by protocol compatibility. This paradigm shift from "passive isolation" to "proactive auditing and control" systematically fills the gap in content inspection of encrypted channels while maintaining the advantages of physical network isolation, significantly improving the overall security and controllability of cross-network data transmission.
[0050] <Method Example 2> Figure 2A flowchart illustrating a method for secure cross-network data interaction between securely isolated networks according to an embodiment of this disclosure is shown. This method is implemented from the Internet side, such as... Figure 2 As shown, the method includes steps S2100-S2200.
[0051] S2100: Obtain standardized access requests sent from the private network side.
[0052] S2200, based on standardized access requests, automatically opens a browser and accesses the corresponding internet pages and / or generates the corresponding response data.
[0053] In one possible implementation, when automatically opening a browser and accessing the corresponding internet page based on a standardized access request, the following steps are included: First, check whether the standardized access request contains a standard URL link; if there is no link, a pop-up window is directly displayed to the user; if a link exists, a liveness detection is performed, and if the link is valid, the browser is automatically opened on the user's terminal on the internet side and the corresponding internet page is accessed (if the page fails to open due to browser version or other issues, a pop-up window is displayed); if the link is invalid, the user is also notified.
[0054] When a standardized access request not only requires opening a browser and accessing the corresponding internet page but also requires returning data from that internet page, the standardized access request will be responded to, response data will be generated, and after the corresponding data is generated, sensitive information processing will be performed on the response data to obtain de-identified response data; the de-identified response data will be encrypted, content reconstructed, and protocol standardized to generate standardized response data; the standardized response data will be returned to the private network side through the network gateway.
[0055] <Method Example 3> Figure 3 A flowchart illustrating a method for secure cross-network data interaction between securely isolated networks according to an embodiment of this disclosure is provided. The method is implemented interactively by the private network side and the internet side, such as... Figure 3 As shown, the method includes: First, the access request on the Internet side is generated by the first user terminal deployed on the private network side.
[0056] Second, a security detection module is deployed on the private network side. Based on the access request, it obtains the user's historical behavior characteristics and current behavior characteristics, and performs security audit on the access request based on the user's historical behavior characteristics and current behavior characteristics to obtain access requests that pass the security audit.
[0057] Third, the private network security proxy gateway deployed on the private network side performs SM4 encryption, content reconstruction, and protocol standardization on access requests that have passed security audits, generates standardized access requests, and sends the standardized access requests to the Internet side through the network gateway.
[0058] Fourth, the second user terminal deployed on the Internet side obtains the standardized access request sent by the private network side, and based on the standardized access request, automatically opens a browser and accesses the corresponding Internet page and / or generates the corresponding response data.
[0059] Fifth, the data and content filtering module deployed on the Internet side processes the response data for sensitive information to obtain de-identified response data. The de-identified response data is then encrypted, reconstructed, and standardized according to protocols to generate standardized response data. The standardized response data is then returned to the private network side through the network gateway.
[0060] The implementation details of the above steps are described above and will not be repeated here.
[0061] <System Implementation Example> Figure 4 A schematic block diagram of a cross-network data security interaction device between securely isolated networks according to an embodiment of the present disclosure is shown. Figure 4 As shown, the device 100 includes: a private network side device 110 and an internet side device 120. The private network side device 110 includes a first user terminal 111 deployed on the private network side, a security detection module 112, and a private network security proxy gateway 113. The internet side device 120 includes a second user terminal 121 deployed on the internet side and a data and content filtering module 122. The first user terminal 111 is used to respond to the triggering of users on the private network accessing the Internet and generate an access request on the Internet side. The security detection module 112 is used to obtain the user's historical behavior characteristics and current behavior characteristics based on the access request, and to perform security audit on the access request based on the historical behavior characteristics and current behavior characteristics. The dedicated network security proxy gateway 113 is used to encrypt, reconstruct, and standardize the protocol of access requests that have passed security audits, generate standardized access requests, and send the standardized access requests to the Internet side through the network gateway to achieve secure access to the Internet. The second user terminal 121 is used to obtain standardized access requests sent by the private network side, and based on the standardized access requests, automatically open a browser and access the corresponding Internet pages and / or generate corresponding response data. The data and content filtering module 122 is used to process sensitive information in the response data to obtain desensitized response data. The desensitized response data is then encrypted, reconstructed, and standardized according to the protocol to generate standardized response data. The standardized response data is then returned to the private network side through the network gateway.
[0062] In one possible implementation, the security detection module 112 is further configured to: generate security audit logs during security auditing and store the security audit logs in anonymized form.
[0063] The various embodiments of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or technical improvements to the embodiments in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A method for secure cross-network data interaction between securely isolated networks, wherein the method is implemented on the private network side, characterized in that, include: In response to a user's request to access the Internet from the private network side, an access request is generated from the Internet side. Based on the access request, the user's historical behavior characteristics and current day behavior characteristics are obtained, and the access request is security audited based on the historical behavior characteristics and the current day behavior characteristics. Access requests that pass the security audit are encrypted, reconstructed, and standardized according to protocols to generate standardized access requests. These standardized access requests are then sent to the Internet via a network gateway to achieve secure access to the Internet.
2. The method according to claim 1, characterized in that, When obtaining the user's historical behavior characteristics and current day behavior characteristics based on the access request, the following are included: User information is parsed from the access request; Based on the user information, obtain historical behavioral characteristics associated with the user information; Based on the user information, obtain the daily session information associated with the user information, and parse the daily session information to obtain the daily behavioral characteristics.
3. The method according to claim 1, characterized in that, When performing security audits on the access requests based on the historical and current day behavior characteristics, the following are included: Based on the aforementioned historical behavioral characteristics, it is determined whether the user is a high-risk user; If it is determined that the user is not a high-risk user, based on the historical behavioral characteristics and the current day's behavioral characteristics, it is determined whether the user has any abnormal behavior; If it is determined that the user does not exhibit any abnormal behavior, the access request is processed for sensitive information to obtain an access request that passes the security audit.
4. The method according to claim 3, characterized in that, When determining whether a user exhibits abnormal behavior based on the historical behavioral characteristics and the current day's behavioral characteristics, the following steps are included: Based on the behavioral characteristics of the day and the preset static audit rules, it is initially determined whether the user has any abnormal behavior; If it is initially determined that the user does not have any abnormal behavior, then based on the historical behavior characteristics and the current day's behavior characteristics, it is determined again whether the user has any abnormal behavior. If the user is found to have no abnormal behavior again, the session information to which the access request belongs is obtained, and based on the session information to which the access request belongs, the user is finally determined to have no abnormal behavior.
5. The method according to claim 1, characterized in that, Circuit breaker operations are performed on access requests that fail the security audit, and corresponding security alerts are pushed.
6. The method according to claim 1, characterized in that, The security audit also includes generating security audit logs and storing the security audit logs in anonymized form.
7. A method for secure cross-network data interaction between securely isolated networks, the method being implemented from the Internet side, characterized in that, include: Obtain standardized access requests sent from the private network side; Based on the standardized access request, the browser is automatically opened and the corresponding Internet page is accessed, or the corresponding response data is generated.
8. The method according to claim 7, characterized in that, After generating the corresponding response data, it also includes: Sensitive information processing is performed on the response data to obtain desensitized response data; The de-identified response data is encrypted, its content reconstructed, and its protocol standardized to generate standardized response data. The standardized response data is returned to the private network side through the network gateway.
9. A secure cross-network data security interaction system between securely isolated networks, characterized in that, include: The device includes a private network side device and an internet side device, wherein the private network side device includes a first user terminal deployed on the private network side, a security detection module, and a private network security proxy gateway; the internet side device includes a second user terminal deployed on the internet side and a data and content filtering module. The first user terminal is used to generate an access request from the Internet side in response to a user on the private network side accessing the Internet. The security detection module is used to obtain the user's historical behavior characteristics and current behavior characteristics based on the access request, and to perform security audit on the access request based on the historical behavior characteristics and the current behavior characteristics. The dedicated network security proxy gateway is used to encrypt, reconstruct, and standardize the protocol of the access requests that pass the security audit, generate standardized access requests, and send the standardized access requests to the Internet side through the network gateway to achieve secure access to the Internet. The second user terminal is used to obtain standardized access requests sent by the private network side, and based on the standardized access requests, automatically open a browser and access the corresponding Internet page and / or generate corresponding response data; The data and content filtering module is used to process the response data for sensitive information to obtain desensitized response data, encrypt the desensitized response data, reconstruct the content and standardize the protocol to generate standardized response data, and return the standardized response data to the private network side through the network gateway.
10. The system according to claim 9, characterized in that, The security detection module is also used to: generate security audit logs during security audits and store the security audit logs in anonymized form.
Citation Information
Patent Citations
Video efficient and safe transmission and control method and system based on one-way optical shutter
CN118200675A
Access control method, device and equipment and computer storage medium
CN118740405A
Network isolation system supporting multi-dimensional auditing
CN120639366A
Public network accessing method and device and computer storage medium for user terminal of mobile private network
WO2018149342A1