Security network distribution equipment, method and device based on physical isolation and storage medium

By using a physically isolated secure network distribution device, the problem of one-to-many concurrent data distribution in cross-domain scenarios is solved, enabling device-by-device identity authentication and access control, ensuring data security and reliability, and improving operational efficiency and compatibility.

CN121530702APending Publication Date: 2026-02-13WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511781905.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-29
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing technologies cannot achieve secure and automated one-to-many concurrent data distribution in cross-domain and cross-security domain scenarios. They lack packet-by-packet authentication and continuous encryption, resulting in insufficient data legitimacy verification and the risk of information leakage.

Method used

A secure network distribution device based on physical isolation is adopted, including a main control processing module, an interface processing module, an encryption/decryption processing module, an upstream isolation module, and a downstream isolation module. They are connected through a VPX backplane to realize data encryption/decryption and security authentication, and support two-way identity authentication and access control of the IPSec protocol.

Benefits of technology

It achieves device-by-device authentication and access control in one-to-many concurrent distribution scenarios under the premise of physical isolation, ensuring data confidentiality, blocking unauthorized access paths, improving operational efficiency and reliability, and ensuring compatibility and scalability in heterogeneous network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530702A_ABST
    Figure CN121530702A_ABST
Patent Text Reader

Abstract

The invention discloses secure network distribution equipment based on physical isolation. The network distribution equipment comprises a main control processing module, an interface processing module, an encryption and decryption processing module, an upward isolation module and a downward isolation module, the main control processing module is used for performing management control and data interaction scheduling on each module; the interface processing module is used for realizing data input and output with external equipment; the encryption and decryption processing module is used for carrying out encryption and decryption operation on the data transmitted by the network distribution equipment and locally stored data; the upper isolation module and the lower isolation module are used for establishing a physical isolation channel between the network distribution equipment and the upper-level equipment or a plurality of lower-level equipment to perform security authentication; the modules in the secure network distribution device are connected and communicated through the VPX structure backboard. According to the embodiment of the invention, device-by-device identity authentication and access control in a one-to-many concurrent distribution scene can be realized, and modularization and maintainability of a hardware architecture are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and more particularly to a secure network distribution device based on physical isolation, a method, an apparatus and a storage medium. BACKGROUND

[0002] With the deep integration of informatization and industrialization, various key infrastructures, confidential units and large enterprises have generally constructed an internal / external network separation architecture with extremely high security requirements. In the cross-network and cross-security domain scenario, the superior control center needs to efficiently and reliably distribute business data, policy configuration or patch files to a large number of subordinate nodes, and real-time status information is collected. The traditional method relies on manual disk copying or simple protocol conversion, which cannot meet the modern business needs, and therefore there is an urgent need for a technical solution that can realize secure and automated network distribution under the premise of physical isolation.

[0003] The prior art has obvious deficiencies. Most solutions only realize single-point or single-file transparent transmission, lack support for one-to-many concurrent distribution and reverse transmission, and cannot complete identity authentication and continuous encryption for each packet. The data legitimacy check only filters the protocol header or uses a static whitelist, which cannot complete identity authentication and continuous encryption for each packet, and there is a risk of forgery, replay and tampering. The solution relies on the TCP / IP protocol stack, which is difficult to block hidden channels and virus horizontal transmission. The above defects make the prior art difficult to meet the strict requirements of data distribution in terms of security, reliability and operation efficiency, and cannot fully guarantee the legitimacy and security of the data, which poses a risk of information leakage and illegal access. SUMMARY

[0004] In view of at least one defect or improvement requirement of the prior art, the present application provides a secure network distribution device based on physical isolation, a method, an apparatus and a storage medium, which can solve at least one of the problems in the background art.

[0005] To achieve the above-mentioned purpose, according to the first aspect of the present application, a secure network distribution device based on physical isolation is provided, which comprises a master control module, an interface processing module, an encryption and decryption processing module, an upper isolation module and a lower isolation module. The master control module is used for managing and controlling each module and scheduling data interaction. The interface processing module is used for realizing data input and output with external devices. The encryption and decryption processing module is used for performing encryption and decryption operations on data transmitted through the network distribution device and locally stored data. The upper isolation module is used for establishing a first physical isolation channel between the network distribution device and a superior device in a superior network, and performing security authentication. The pair of upper isolation modules are used for establishing a second physical isolation channel between the network distribution device and a plurality of subordinate devices in a subordinate network, and performing security authentication. The modules in the secure network distribution device are connected and communicated through a VPX structure backplane.

[0006] Further, the secure network distribution device based on physical isolation includes the pair of upper isolation modules and the pair of lower isolation modules, which comprise an external network processing unit, an internal network processing unit and an isolation exchange unit. The isolation exchange unit is connected with the external network processing unit and the internal network processing unit, and is used for establishing two one-way data transmission channels between the external network processing unit and the internal network processing unit, and realizing legality judgment of data exchange.

[0007] Further, the secure network distribution device based on physical isolation further comprises an access authentication module. The access authentication module is used for performing two-way identity authentication with an external device based on an IPSec protocol, establishing an access control list, and performing identity authentication on each data packet.

[0008] Further, the secure network distribution device based on physical isolation comprises a software architecture of the main control processing module, which comprises an interface operation layer, a business processing layer and an interface implementation layer. The interface operation layer is used for data display and management. The business processing layer is used for business logic processing. The interface implementation layer is used for providing a running platform, data storage and a business support interface.

[0009] Further, the secure network distribution device based on physical isolation comprises a software architecture of the pair of upper isolation modules and the pair of lower isolation modules, which comprises a business control layer, a data processing layer and an interface implementation layer. The business control layer is used for authenticating and exchanging protocols of incoming and outgoing business data. The data processing layer is used for completing encryption and decryption processing and strategy matching in two directions of data in and out. The interface implementation layer is used for providing a running platform and a data storage space.

[0010] According to a second aspect of the present application, a secure network distribution method based on physical isolation is also provided, which comprises the following steps: The network distribution device receives relevant information which needs to be distributed to a plurality of subordinate devices and which is sent by a superior device through a special protocol in an online point-to-point manner. Receiving the network access application and service data application sent by the plurality of subordinate devices to the superior device, judging whether each subordinate device belongs to the device responsible for distribution by the network distribution device one by one, if yes, forwarding the network access application data and response data between the superior device and the subordinate device, if not, not processing the application of the subordinate device; Receiving and saving the service data application of the subordinate device sent by the superior device point to point; Distributing the service data applied by each subordinate device through the dedicated store multi-point protocol, and reporting the response result point to point to the superior device.

[0011] Further, the above-mentioned secure network distribution method based on physical isolation further comprises transmitting the information data of the subordinate device to the superior device, specifically comprising: Receiving the subordinate device information reported by the subordinate device point to point; Saving the subordinate device information; Reporting all the subordinate device information to the superior device point to point.

[0012] Further, the above-mentioned secure network distribution method based on physical isolation, the step of judging whether each subordinate device belongs to the device responsible for distribution by the network distribution device one by one comprises bidirectional authentication based on the IPSec protocol with the subordinate device, establishing an access control list, and packet-by-packet authentication of the subsequent transmitted data packets.

[0013] According to the third aspect of the present application, a secure network distribution device based on physical isolation is also provided, comprising at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program, when the computer program is executed by the processing unit, the processing unit executes the steps of any one of the above-mentioned methods.

[0014] According to the fourth aspect of the present application, a storage medium is also provided, which stores a computer program executable by a secure network distribution device based on physical isolation, when the computer program runs on the secure network distribution device based on physical isolation, the secure network distribution device based on physical isolation executes the steps of any one of the above-mentioned methods.

[0015] Overall, compared with the prior art, the above technical solutions conceived by the present application can achieve the following beneficial effects: The secure network distribution device based on physical isolation provided by the embodiment of the application can realize unified allocation of internal resources and task cooperation of the device to improve operation efficiency and reliability, provide a standardized physical access interface for the upper and lower devices to ensure compatibility and scalability in a heterogeneous network environment, complete data confidentiality protection to prevent transmission and cache stages from being stolen or tampered with, block illegal access and attack paths to protect the legality of upper and lower link access, realize device-by-device identity authentication and access control in a one-to-many concurrent distribution scenario to prevent unauthorized device access, and build a high-speed and reliable internal data bus to realize low-delay and high-bandwidth interaction between modules, thereby guaranteeing the modularity and maintainability of the hardware architecture. BRIEF DESCRIPTION OF DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0017] Figure 1 A structural schematic diagram of a secure network distribution device based on physical isolation provided by the embodiment of the application is provided. Figure 2 A system deployment schematic diagram of a secure network distribution device based on physical isolation provided by the embodiment of the application is provided. Figure 3 A control principle schematic diagram of an isolation module of a secure network distribution device based on physical isolation provided by the embodiment of the application is provided. Figure 4 A device security isolation schematic diagram of a secure network distribution device based on physical isolation provided by the embodiment of the application is provided. DETAILED DESCRIPTION

[0018] In order to make the objects, technical solutions and advantages of the application clearer, the following will further describe the application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the application, and are not used to limit the application. In addition, the technical features involved in each embodiment of the application described below can be combined with each other as long as there is no conflict.

[0019] The terms "first", "second", "third", and the like in the description and in the claims of the present application and above-described drawings are used for distinguishing between similar objects talking nothing about their particular order. Moreover, the terms "comprises", "comprising", "has", "having", "includes", "including", and the like are to be construed open-ended, allowing for instances where there are equivalents to the recited elements that are not literally present. For example, a process, method, article, or apparatus that "comprises" or "has" a list of steps or elements is not necessarily limited to only those steps or elements literally present. Rather, the term "comprises" or "has" is intended to capture the recited elements and equivalents thereof.

[0020] Figure 1 A structure schematic diagram of a secure network distribution device based on physical isolation provided by an embodiment of the present application is shown in Figure 1 A secure network distribution device based on physical isolation is provided by an embodiment of the present application, which comprises a master processing module, an interface processing module, an encryption and decryption processing module, an upper isolation module and a lower isolation module. The master processing module is configured to manage and control each module and schedule data interaction. The interface processing module is configured to realize data input and output with external devices. The encryption and decryption processing module is configured to perform encryption and decryption operation on data transmitted via the network distribution device and locally stored data. The upper isolation module is configured to establish a first physical isolation channel between the network distribution device and a superior device in a superior network, and perform security authentication. The lower isolation module is configured to establish a second physical isolation channel between the network distribution device and a plurality of subordinate devices in a subordinate network, and perform security authentication. Each module in the secure network distribution device is connected and communicates through a VPX structure backplane.

[0021] Specifically, the secure network distribution device based on physical isolation provided by an embodiment of the present application is composed of a master processing module, an interface processing module, an encryption and decryption processing module, an upper isolation module and a lower isolation module, and each module is connected and communicates through a VPX structure backplane to realize unified connection and communication of power supply, signals and data buses.

[0022] The master processing module is the core of the device, runs a customized embedded operating system, is responsible for initializing, state monitoring, task scheduling and abnormal reset of each module, and collects information of each module in real time through a backplane management bus to realize centralized management.

[0023] The interface processing module provides a control interface to the outside, such as Figure 2As shown, for receiving the special protocol data packet sent by the superior device, and sending the point-to-multipoint protocol frame to the subordinate device; all external signals are connected to the backplane switching network after isolation, to ensure that external electrical interference cannot be transmitted into the internal module.

[0024] The encryption and decryption processing module is plugged on the VPX backplane in the form of PCIe, and performs decryption on the uplink external network raw data on the backplane data plane, and performs encryption on the downlink internal network service data on the same plane of the backplane, and the operation result is directly returned to the main control processing module through the backplane shared memory, without leaking plaintext.

[0025] The up-isolation module and the down-isolation module are connected to the main control processing module through two independent channels of the backplane, to realize physical isolation of the superior network and the subordinate network, and to complete hardware-level security authentication handshake by the main control processing module when the link is established, and to allow the data frame to enter the backplane switching plane for subsequent processing after the authentication is passed.

[0026] The physical isolation-based secure network distribution device provided by the embodiment of the application can realize unified allocation of internal resources and task cooperation to improve operation efficiency and reliability, provide standardized physical access interfaces for the superior and subordinate devices to ensure compatibility and scalability in a heterogeneous network environment, complete data confidentiality protection to prevent transmission and cache stages from being stolen or tampered with, block illegal access and attack paths to ensure the legality of superior and subordinate link access, realize device-by-device identity authentication and access control in a one-to-many concurrent distribution scenario to prevent unauthorized device access, and build a high-speed and reliable internal data bus to realize low-latency and high-bandwidth interaction between modules, thereby ensuring the modularity and maintainability of the hardware architecture.

[0027] Optionally, the physical isolation-based secure network distribution device provided by the embodiment of the application includes an external network processing unit, an internal network processing unit, and an isolation switching unit. The isolation switching unit is connected with the external network processing unit and the internal network processing unit, and is configured to establish two one-way data transmission channels between the external network processing unit and the internal network processing unit, to realize legality judgment of data exchange.

[0028] Specifically, the up-isolation module and the down-isolation module both adopt the same three-unit architecture, for example, Figure 3As shown, each of the outer network processing unit, the inner network processing unit and the isolation switching unit are connected in sequence through a board-level high-speed bus. The isolation switching unit is an independent hardware module, which has a built-in special storage medium and protocol conversion logic. The isolation switching unit is connected to the outer network processing unit and the inner network processing unit through two groups of physically isolated links, respectively. The two channels of data transmission are opposite in direction and have no reverse signal return, thereby constituting physical isolation.

[0029] The legality judgment of data exchange is performed by the isolation switching unit. When the outer network processing unit receives a network data packet from a superior or subordinate device, the IP header and the protocol header are stripped, and the original data is written into the storage medium of the isolation switching unit through a first one-way channel. After the writing is completed, the connection is immediately disconnected. The isolation switching unit performs integrity verification on the data, including data length verification and digest comparison. After the verification is passed, it is considered that the legality judgment is completed, and the data is forwarded to the inner network processing unit through a second one-way channel for TCP / UDP re-encapsulation. In the reverse process, the inner network processing unit sends data to the isolation switching unit, which is forwarded to the outer network processing unit after integrity verification for protocol header reconstruction and sending out. Through the independent operation and disconnection mechanism of the above two one-way channels, physical isolation and legality judgment between the inner and outer networks are realized.

[0030] Optionally, the physical isolation-based secure network distribution device provided by the embodiment of the present application further comprises an access authentication module. The access authentication module is configured to perform bidirectional identity authentication with the external device based on the IPSec protocol, establish an access control list, and perform identity authentication on each data packet in transmission.

[0031] Specifically, the access authentication module runs as a software component between the interface processing module and the encryption and decryption processing module, and cooperates with each isolation module. The module implements bidirectional identity authentication based on the IPSec protocol stack: when an external device (superior or subordinate device) first connects to the network distribution device, the access authentication module triggers a handshake, completes device-level bidirectional identity authentication through a pre-shared key or digital certificate, generates a security association after the authentication is passed, and establishes an access control list. The list records the IP address, device ID and session key of the authorized device. Through IPSec protocol encryption transmission and packet-by-packet continuous authentication, access control and full-life-cycle data security of the external device are realized.

[0032] Optionally, the physical isolation-based secure network distribution device provided by the embodiment of the present application, the software architecture of the main control processing module includes an interface operation layer, a business processing layer and an interface implementation layer. The interface operation layer is configured to display and manage data. The business processing layer is configured to process business logic. The interface implementation layer is configured to provide a running platform, data storage and a business support interface.

[0033] Specifically, the physical isolation-based secure network distribution device provided by the embodiment of the present application adopts a three-layer design for the software architecture of the master processing module, namely, an interface operation layer, a service processing layer and an interface implementation layer, and each layer realizes data interaction through backplane shared memory and a message queue. The interface operation layer is responsible for real-time display of running states of each module, distribution task progress and alarm logs, and provides management interfaces such as access control list configuration and device parameter modification, so that an operator can intuitively monitor the device and service flow.

[0034] The service processing layer runs on the multi-core processor of the master processing module, parses special protocol data sent by a superior device to extract subordinate device identification information, generates a distribution strategy and dispatches encryption and decryption processing modules to perform packet-by-packet encryption and decryption operations, coordinates the timing of the up-isolation module and the down-isolation module to control unidirectional channel switching, processes abnormal events reported by the interface processing module and triggers a retransmission or a fuse mechanism.

[0035] The interface implementation layer is responsible for providing an operating platform, a data storage space and a service support interface for the upper layer, specifically including accessing registers of each hardware module through a PCIe driver, utilizing a database to persistently store device information authentication strategies and logs, so as to realize stable operation and function extension of the master processing module.

[0036] Optionally, the physical isolation-based secure network distribution device provided by the embodiment of the present application, the software architecture of the up-isolation module and the down-isolation module includes a service control layer, a data processing layer and an interface implementation layer; The service control layer is configured to authenticate and exchange protocols for incoming and outgoing service data. The data processing layer is configured to complete encryption and decryption processing and strategy matching in two directions of data. The interface implementation layer is configured to provide an operating platform and a data storage space.

[0037] Specifically, the up-isolation module and the down-isolation module adopt the same three-layer software architecture. The service control layer is responsible for authenticating and exchanging protocols for incoming and outgoing service data: when the external network processing unit receives an IPSec encrypted data packet sent by a superior or subordinate device, the layer calls the encryption and decryption processing module to verify the authentication header or encapsulated security payload integrity of the data packet, completes identity authentication, then peels off the standard IP protocol header, encapsulates the data payload as a special isolation exchange protocol frame, and sends it to the data processing layer; in the reverse process, the layer receives the response data returned by the internal network processing unit, re-encapsulates it as an IPSec protocol and forwards it to the external device.

[0038] The data processing layer is mounted between the service control layer and the interface implementation layer, and completes encryption and decryption processing and policy matching in two directions of data in and out: in the data entering direction, the original data forwarded by the service control layer is received, policy matching is performed according to the access control list issued by the master processing module, and the data packet meeting the condition is allowed to enter; in the data outgoing direction, the decrypted data transmitted by the isolation switching unit is subjected to integrity check, and after passing the check, the encryption and decryption processing module is called to re-encrypt and send the data to the service control layer.

[0039] The interface implementation layer is constructed based on the hardware driver of the isolation module and the embedded database, and provides a running platform and a data storage space for the upper layer: the data channel access with the master processing module is realized through the VPX backplane driver, the authentication policy, the encryption and decryption key and the service session state are saved by the database, and the running platform, the data storage space and the service support interface are provided to the service control layer and the data processing layer through the standard API interface, so that the isolation module can independently run and complete the security isolation function.

[0040] The embodiment of the application also provides a secure network distribution method based on physical isolation, comprising the following steps: The network distribution device receives the related information of the subordinate devices which needs to be distributed to the plurality of subordinate devices sent by the superior device through the special protocol online point-to-point; The network distribution device receives the network access application and the service data application sent by the plurality of subordinate devices to the superior device, and judges whether each subordinate device belongs to the device responsible for distribution by the network distribution device, if yes, forwards the network access application data and the response data between the superior device and the subordinate device, if not, does not process the application of the subordinate device; The network distribution device receives and saves the service data of the subordinate device application sent by the superior device point-to-point; The network distribution device distributes the service data applied by each subordinate device through the special shop to multiple point protocol, and reports the response result to the superior device point-to-point.

[0041] Specifically, as shown in the figure, Figure 4 The basic flow of the network distribution device distributing data from the superior device to the subordinate device is as follows: The network online transmission channel is established to the superior, and the superior device transmits all the related information of the subordinate devices which needs to be distributed to the network distribution device through the special protocol online point-to-point.

[0042] The plurality of subordinate devices initiates the network access application and the service data application to the superior device through the network distribution device. The network distribution device judges whether each subordinate device is the device responsible for distribution by itself. If yes, forwards the network access application data and the response data between the superior device and the subordinate device. If not, does not process the application of the subordinate device.

[0043] The superior device point-to-point issues the service data applied by the subordinate device to the network distribution device for storage.

[0044] The network distribution device distributes the service data applied by the subordinate device to multiple subordinate devices through a dedicated point-to-multipoint protocol, and reports the response result point-to-point to the superior device.

[0045] Optionally, the physical isolation-based secure network distribution method provided in the embodiments of the present application further comprises transmitting information data of the subordinate device to the superior device, specifically comprising: receiving the subordinate device information reported point-to-point by the subordinate device; storing the subordinate device information; reporting all the subordinate device information point-to-point to the superior device.

[0046] Specifically, the network distribution device can also support transmitting the information data of the subordinate device to the superior device, and the basic flow is as follows: The subordinate device reports local information point-to-point to the network distribution device.

[0047] The network distribution device stores the received subordinate device information.

[0048] The network distribution device reports all the subordinate device information point-to-point to the superior device.

[0049] Optionally, the physical isolation-based secure network distribution method provided in the embodiments of the present application comprises performing bidirectional authentication with the subordinate device based on an IPSec protocol, establishing an access control list, and performing packet-by-packet authentication on the data packets transmitted subsequently, in the step of judging whether each subordinate device belongs to the devices responsible for distribution by the network distribution device.

[0050] The detailed flow of the data isolation exchange in the present embodiment in which data is transmitted from the external network to the internal network is described as follows: (1) The external network device sends a network data packet to the external network processing unit of the isolation module of the network distribution device.

[0051] (2) The external network processing unit initiates a data connection of a non-TCP / IP protocol to the internal dedicated isolation exchange unit, and the data transmission direction of the data connection is unidirectional.

[0052] (3) The external network processing unit strips off the IP header and the protocol header of the data, and writes the original data into the storage medium of the dedicated isolation exchange unit through the unidirectional data channel.

[0053] (4) After receiving the data, the dedicated isolation exchange unit disconnects the data connection with the external network processing unit.

[0054] (5) The dedicated isolation exchange unit implements data integrity verification.

[0055] (6) After the data is verified, the special isolated switching unit initiates a non-TCP / IP protocol data connection to the inner network processing unit, and the data transmission direction of the data connection is also unidirectional.

[0056] (7) The special isolated switching unit sends the exchanged data to the inner network processing unit through the unidirectional data channel.

[0057] (8) After the special isolated switching unit sends the data, the data connection with the inner network processing unit is disconnected.

[0058] (9) The inner network processing unit encapsulates the data in a protocol and a TCP / UDP, and then sends the re-encapsulated IP packet to the master processing module for processing.

[0059] The data isolation and exchange process in which the data is transmitted from the inner network to the outer network in the embodiment of the application is described in detail as follows: (1) The inner network processing unit of the isolation module of the network distribution device receives the network data packet transferred from the device.

[0060] (2) The inner network processing unit initiates a non-TCP / IP protocol data connection to the special isolated switching unit, and the data transmission direction of the data connection is unidirectional.

[0061] (3) The inner network processing unit sends the exchanged data to the internal special isolated switching unit through the unidirectional data channel.

[0062] (4) After the special isolated switching unit receives the data, the data connection with the inner network processing unit is disconnected.

[0063] (5) The special isolated switching unit performs integrity checking on the data.

[0064] (6) The special isolated switching unit initiates a non-TCP / IP protocol data connection to the outer network processing unit, and the data transmission direction of the data connection is also unidirectional.

[0065] (7) The special isolated switching unit sends the original data to the outer network processing unit through the unidirectional data channel.

[0066] (8) After the special isolated switching unit sends the data, the data connection with the outer inner network processing unit is disconnected.

[0067] (9) The outer network processing unit recombines the IP header and the protocol header of the data, and sends the network data packet to the outer network device.

[0068] The application further provides a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of the method. The computer readable storage medium can include, but is not limited to, any type of disk, including a floppy disk, an optical disk, a DVD, a CD-ROM, a micro drive, a magneto-optical disk, a ROM, a RAM, an EPROM, an EEPROM, a DRAM, a VRAM, a flash memory device, a magnetic card or an optical card, a nanosystem (including a molecular memory IC), or any type of medium or device suitable for storing instructions and / or data.

[0069] It should be noted that, for the foregoing method embodiments, in order to simply describe, they are all described as a series of action combinations, but those skilled in the art should know that the application is not limited to the order of the actions described, because according to the application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily necessary for the application.

[0070] In the above embodiments, the description of each embodiment is focused on, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0071] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are only schematic. The division of the units is only a logical function division. There can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some services interfaces, devices or units, and can be electrical or other forms.

[0072] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0073] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0074] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable memory. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present application. The aforementioned memory includes: a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0075] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing relevant hardware, and the program can be stored in a computer readable memory, which can include a flash disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.

[0076] The above is only exemplary embodiments of the present disclosure, and cannot limit the scope of the present disclosure. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure are still within the scope of the present disclosure. Those skilled in the art will easily think of embodiments of the present disclosure after considering the specification and practicing the disclosure herein. The present application is intended to cover any variations, uses or adaptive changes of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only considered as exemplary, and the scope and spirit of the present disclosure are defined by the claims.

[0077] The technical features of the above embodiments can be combined in any way. To make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not contradict, they should be considered within the scope of the present disclosure.

[0078] Those skilled in the art readily understand that the above only describes preferred embodiments of the present application and is not intended to limit the present application. Any modification, equivalent replacement and improvement made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A secure network distribution device based on physical isolation, characterized in that, The network distribution device includes a main control processing module, an interface processing module, an encryption / decryption processing module, an upstream isolation module, and a downstream isolation module; The main control processing module is used to manage, control, and schedule data interaction among the various modules. The interface processing module is used to realize data input and output with external devices; The encryption / decryption processing module is used to perform encryption / decryption operations on data transmitted via the network distribution device and data stored locally; The upper isolation module is used to establish a first physical isolation channel between the network distribution device and the upper-level device in the upper-level network for security authentication. The downstream isolation module is used to establish a second physical isolation channel between the network distribution device and multiple downstream devices in the downstream network for security authentication. The modules within the secure network distribution device are connected and communicate via a VPX backplane.

2. The secure network distribution device based on physical isolation according to claim 1, characterized in that, The upper isolation module and the lower isolation module include an external network processing unit, an internal network processing unit, and an isolation switching unit; The isolation switching unit is connected to both the external network processing unit and the internal network processing unit, and is used to establish two unidirectional data transmission channels between the external network processing unit and the internal network processing unit to realize the legality judgment of data exchange.

3. The secure network distribution device based on physical isolation according to claim 1, characterized in that, It also includes an access authentication module; The access authentication module is used to perform two-way identity authentication with external devices based on the IPSec protocol, establish an access control list, and authenticate each transmitted data packet.

4. The secure network distribution device based on physical isolation according to claim 1, characterized in that, The software architecture of the main control processing module includes a user interface operation layer, a business processing layer, and an interface implementation layer. The interface operation layer is used for data display and management; The business processing layer is used for business logic processing; The interface implementation layer is used to provide interfaces for the operating platform, data storage, and business support.

5. The secure network distribution device based on physical isolation according to claim 1, characterized in that, The software architecture of the upper isolation module and the lower isolation module includes a business control layer, a data processing layer, and an interface implementation layer; The business control layer is used for authenticating and exchanging protocols for incoming and outgoing business data; The data processing layer is used to complete encryption and decryption processing and strategy matching in both directions of data input and output; The interface implementation layer is used to provide a running platform and data storage space.

6. A secure network distribution method based on physical isolation, characterized in that, Includes the following steps: The network distribution device receives relevant information that needs to be distributed to multiple subordinate devices, sent online point-to-point by the superior device via a dedicated protocol. The system receives network access applications and service data applications sent from multiple lower-level devices to a higher-level device. It then determines whether each lower-level device is a device that the network distribution device is responsible for distributing. If so, the system forwards the network access application data and response data between the higher-level device and the lower-level device. If not, the system does not process the application from the lower-level device. Receive and save the service data requested by the lower-level device, which is sent point-to-point by the upper-level device; The dedicated store distributes the requested business data to each lower-level device through the multipoint protocol, and reports the response results to the upper-level device point-to-point.

7. The secure network distribution method based on physical isolation as described in claim 6, characterized in that, This also includes transmitting information data from lower-level devices to higher-level devices, specifically including: Receive information about the subordinate devices reported point-to-point by the subordinate devices; Save the information of the lower-level devices; All information from lower-level devices is aggregated and reported point-to-point to the higher-level device.

8. The secure network distribution method based on physical isolation as described in claim 6, characterized in that, The step of determining whether each subordinate device belongs to the network distribution device responsible for distribution includes performing two-way authentication with subordinate devices based on the IPSec protocol, establishing an access control list, and authenticating each data packet transmitted subsequently.

9. A secure network distribution device based on physical isolation, characterized in that, It includes at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program that, when executed by the processing unit, causes the processing unit to perform the steps of the method according to any one of claims 6 to 8.

10. A storage medium, characterized in that, It stores a computer program executable by a physically isolated secure network distribution device, which, when run on the physically isolated secure network distribution device, causes the physically isolated secure network distribution device to perform the steps of the method according to any one of claims 6 to 8.