A method, apparatus and device for cross-network transmission of target data

CN121567398BActive Publication Date: 2026-06-30HEFEI TANOVO INFORMATION SECURITY TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HEFEI TANOVO INFORMATION SECURITY TECH CO LTD
Filing Date
2025-11-24
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

Existing technologies have problems such as data leakage risk, complex encryption and decryption operations, high hardware resource consumption, and poor business timeliness in cross-network transmission of target data.

Method used

The target data is encrypted once using an attribute-based ciphertext encryption tool to generate an encrypted data packet, which is then transmitted unidirectionally through a physically isolated network. The packet is decrypted only within the target network, and security verification and transmission are performed using dynamic port and optical gate technologies.

Benefits of technology

It achieves end-to-end encrypted transmission, eliminates the risk of data leakage, simplifies the encryption and decryption process, reduces hardware resource consumption, ensures business timeliness, reduces manual intervention, and adapts to scenarios with high security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121567398B_ABST
    Figure CN121567398B_ABST
Patent Text Reader

Abstract

This invention provides a method, apparatus, and device for cross-network transmission of target data. The transmission method includes: acquiring target data from a local first network and an attribute-based ciphertext encryption tool sent by a second network physically isolated from the first network; encrypting the target data using the attribute-based ciphertext encryption tool to obtain an encrypted data packet; unidirectionally transmitting the encrypted data packet to a third network via the second network; and decrypting the encrypted data packet on the third network to obtain decrypted data. This invention enables the target data to be encrypted only once to obtain an encrypted data packet, and the encrypted data packet is transmitted unidirectionally to the third network in an encrypted state throughout the entire transmission process, and is decrypted only in the third network, with no plaintext exposure throughout the entire process, thus eliminating the risk of data leakage at the source of the transmission link.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of data transmission technology, and in particular to a method, apparatus and device for cross-network transmission of target data. Background Technology

[0002] Currently, cross-network transmission of target data includes two transmission methods. The first is the manual transfer method, which involves exporting the target data locally via USB flash drive or hard drive and then physically transferring it to the business network for import. When manual transfer is used, the target data is stored in plaintext on the USB flash drive, and loss or interception in the intermediate links may lead to data leakage. Manual copying is time-consuming and cannot be transmitted in real time, affecting business timeliness. Manual operation lacks auditing.

[0003] Some systems use dual encryption mechanisms for cross-network transmission. This involves encrypting the target data locally using algorithm A, and then decrypting it before re-encrypting it using algorithm B before transmitting it to the dedicated business network. At the moment of cross-network transmission, the target data is in plaintext, and the dual encryption requires multiple encryption and decryption operations, which consumes a lot of CPU resources and time, increasing hardware costs. Summary of the Invention

[0004] The technical problem to be solved by the embodiments of the present invention is to provide a method, apparatus and device for cross-network transmission of target data, which can encrypt the target data only once to obtain an encrypted data packet, and the encrypted data packet is forwarded in an encrypted state through a second network and transmitted unidirectionally to a third network, and decrypted only in the third network, with no plaintext exposure throughout the process, thus eliminating the risk of data leakage from the root of the transmission link.

[0005] To solve the above-mentioned technical problems, the technical solution of this invention is as follows: A method for cross-network transmission of target data, comprising:

[0006] Acquire target data from the local first network and attribute-based ciphertext encryption tools sent from a second network that is physically isolated from the first network;

[0007] The target data is encrypted using the attribute-based ciphertext encryption tool to obtain an encrypted data packet;

[0008] The encrypted data packet is sent unidirectionally from the second network to the third network, so that the third network decrypts the encrypted data packet to obtain decrypted data.

[0009] Optionally, the target data is encrypted using the attribute-based ciphertext encryption tool to obtain an encrypted data packet, including:

[0010] The original data in the target data is encrypted using the attribute-based ciphertext encryption tool to obtain attribute-based ciphertext;

[0011] The data access policy in the target data is encrypted to obtain a policy tag;

[0012] The attribute base ciphertext and policy tag are bound and combined to obtain an encrypted data packet.

[0013] Optionally, transmitting the encrypted data packet unidirectionally to the third network via the second network includes:

[0014] The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network;

[0015] Encrypted data packets are forwarded unidirectionally to the third network via the optical gate of the second network.

[0016] Optionally, sending encrypted data packets to the optical gate of the second network through the dynamic port of the first network includes:

[0017] The encrypted data packet is verified. If the verification passes, the dynamic port of the first network is opened.

[0018] The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network;

[0019] After the transmission is complete, close the dynamic port of the first network.

[0020] Optionally, the third network decrypts the encrypted data packet to obtain decrypted data, including:

[0021] The third network extracts and verifies the policy marker in the encrypted data packet;

[0022] If the verification passes, the attribute-based ciphertext in the encrypted data packet is decrypted to obtain decrypted data including the original data.

[0023] Optionally, the above transmission method further includes:

[0024] If the policy tag verification in the encrypted data packet fails, the first transmission log is generated and output.

[0025] Optionally, the above transmission method further includes:

[0026] If the policy flag in the encrypted data packet passes the verification, a second transmission log is generated and output.

[0027] Embodiments of the present invention also provide a cross-network transmission device for target data, comprising:

[0028] The acquisition module is used to acquire target data in the local first network and attribute-based ciphertext encryption tools sent by a second network that is physically isolated from the first network;

[0029] The processing module is used to encrypt the target data using the attribute-based ciphertext encryption tool to obtain an encrypted data packet; to send the encrypted data packet unidirectionally to the third network via the second network; and to decrypt the encrypted data packet via the third network to obtain decrypted data.

[0030] Embodiments of the present invention also provide a computing device, comprising:

[0031] One or more processors;

[0032] A storage device for storing one or more programs that, when executed by one or more processors, cause the one or more processors to perform the method as described above.

[0033] Embodiments of the present invention also provide a computing device readable storage medium storing a program that, when executed by a processor, implements the method described above.

[0034] The above-described solutions of the embodiments of the present invention have at least the following beneficial effects:

[0035] The above-described solution of this invention encrypts the target data only once to obtain an encrypted data packet. The encrypted data packet is forwarded in an encrypted state through the second network and transmitted unidirectionally to the third network. It is decrypted only in the third network. There is no plaintext exposure throughout the process, thus eliminating the risk of data leakage from the root of the transmission link.

[0036] It adopts a single encryption logic of one-time encryption + end-to-end encrypted transmission + terminal decryption, reducing intermediate processing steps and lowering security risks in the encryption process.

[0037] Encrypted data packets can be transmitted directly and unidirectionally via network links without manual intervention, enabling real-time / near real-time cross-network transmission of target data and ensuring business timeliness.

[0038] It requires only one encryption and one decryption, simplifying the data processing flow, reducing hardware resource consumption, and improving the overall efficiency of data transmission.

[0039] The single-time encryption / decryption logic has low hardware resource requirements, eliminating the need for additional hardware upgrades and significantly reducing hardware costs and maintenance burden.

[0040] The entire process is transmitted automatically via the network, requiring no human intervention, thus reducing manpower and the risk of human error. Attached Figure Description

[0041] Figure 1 This is a flowchart illustrating a method for cross-network transmission of target data provided in an embodiment of the present invention.

[0042] Figure 2This is a flowchart illustrating the cross-network transmission method for target data provided in an embodiment of the present invention.

[0043] Figure 3 This is a schematic diagram of a cross-network transmission device for target data provided in an embodiment of the present invention. Detailed Implementation

[0044] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the invention and to fully convey the scope of the invention to those skilled in the art.

[0045] like Figure 1 , 2 As shown, an embodiment of the present invention provides a method for cross-network transmission of target data, including:

[0046] Step 11: Obtain the target data in the local first network and the attribute-based ciphertext encryption tool sent by the second network, which is physically isolated from the first network;

[0047] Step 12: Encrypt the target data using the attribute-based ciphertext encryption tool to obtain an encrypted data packet;

[0048] Step 13: The encrypted data packet is sent unidirectionally from the second network to the third network; the third network then decrypts the encrypted data packet to obtain decrypted data.

[0049] Specifically, the target data may include: structured data (such as database tables, JSON format business data), unstructured data (such as PDF documents, video files, compressed packages), and semi-structured data (such as XML logs); the first network may be a local network; the second network may be the Internet; and the third network may be a business private network (internal network).

[0050] The first network and the second network can be physically isolated through a network gateway.

[0051] In this example, the target data is encrypted only once to obtain an encrypted data packet. The encrypted data packet is forwarded in an encrypted state through the second network and transmitted unidirectionally to the third network. It is decrypted only in the third network. There is no plaintext exposure throughout the process, eliminating the risk of data leakage at the source of the transmission link.

[0052] It adopts a single encryption logic of one-time encryption + end-to-end encrypted transmission + terminal decryption, reducing intermediate processing steps and lowering security risks in the encryption process.

[0053] Encrypted data packets can be transmitted directly and unidirectionally via network links without manual intervention, enabling real-time / near real-time cross-network transmission of target data and ensuring business timeliness.

[0054] It requires only one encryption and one decryption, simplifying the data processing flow, reducing hardware resource consumption, and improving the overall efficiency of data transmission.

[0055] The single-time encryption / decryption logic has low hardware resource requirements, eliminating the need for additional hardware upgrades and significantly reducing hardware costs and maintenance burden.

[0056] The entire process is transmitted automatically via the network, requiring no human intervention, thus reducing manpower and the risk of human error.

[0057] In an optional embodiment of the present invention, in step 11, target data in a local first network and attribute-based ciphertext encryption tools sent by a second network physically isolated from the first network are obtained.

[0058] Specifically, the target data is stored on a local network, and the attribute-based ciphertext encryption tool is sent by a second network that is physically isolated from the first network and deployed on the local network.

[0059] In this example, the first network and the second network are physically isolated, which blocks the possibility of raw data flowing directly into the second network without encryption from the network architecture, thus avoiding the leakage of raw data due to network layer vulnerabilities.

[0060] The attribute-based ciphertext encryption tool is provided by a second network and deployed on the local network. This ensures both the professionalism and adaptability of the encryption tool, and guarantees that the encryption operation is completed locally in a closed loop, without the need to transmit the original data to an external network for encryption processing, thus further enhancing data security.

[0061] In an optional embodiment of the present invention, step 12, encrypting the target data using the attribute-based ciphertext encryption tool to obtain an encrypted data packet, includes:

[0062] Step 121: Encrypt the original data in the target data using the attribute-based ciphertext encryption tool to obtain the attribute-based ciphertext; specifically, through... Determine the attribute base ciphertext;

[0063] in, CT For attribute-based ciphertext, ABE data For attribute-based encryption functions, PK For the system public key, M The original data in the target data. S The attribute set of the original data (such as labels describing data characteristics, such as security level = high, department = finance, etc.);

[0064] Step 122: Encrypt the data access policy in the target data to obtain a policy tag; specifically, through... Determine the strategy flag;

[0065] in, T For policy tagging, Enc policy Encryption functions for access policies, SK The policy encryption key, P For data access strategies;

[0066] Step 123: Bind and combine the attribute base ciphertext and policy tag to obtain an encrypted data packet; specifically, through... Identify the encrypted data packet;

[0067] in, Pkg To encrypt data packets, CT For attribute-based ciphertext, T Used as a strategy marker.

[0068] Specifically, the raw data can be the basic content of the target data that carries core business information, such as database table records in structured data, business details in JSON format business data; PDF document text, audio and video streams of video files, and raw file content in compressed packages in unstructured data; and specific records in XML logs in semi-structured data. The data access strategy can be rules or conditions that specify who can access and how to access the above raw data, used to control access permissions to the raw data and ensure that the raw data is only used by authorized objects in the prescribed manner after decryption.

[0069] In this example, attribute-based encryption is used on the original data, making decryption permissions strongly correlated with the data's attribute characteristics (such as security level, department, etc.). For example, the ciphertext corresponding to the attribute set of security level = high + department = finance can only be decrypted by users holding the private key matching the attributes (such as high-privilege personnel in the finance department), achieving fine-grained control of data authorization based on attributes and preventing unauthorized access to the decrypted data.

[0070] It can accurately adapt to the permission division of complex business scenarios (such as the differentiated access needs of different departments and different security levels of data), and strictly limit the scope of data use from the decryption stage.

[0071] Data access policies (such as downloading and accessing data for target users requiring logging) are encrypted with a key using a separate policy encryption function to create a policy token. This prevents unauthorized access, modification, or bypassing of the policy during transmission. For example, if the policy is transmitted in plaintext, it could be modified by a malicious user to allow access to all users. The encrypted policy token only becomes effective after being decrypted with the corresponding key in a third-party network, ensuring the integrity and authority of the access rules and guaranteeing that the use of decrypted data must adhere to the preset policy.

[0072] The raw data (core business content) and access policies (access control rules) employ different encryption logics and keys (system public key and policy encryption key), and their encryption mechanisms are independent of each other. Even if one encryption method is at risk due to an accident (such as public key leakage), the other encryption can still protect data security (for example, if the policy tag is not decrypted, even if the original data ciphertext is cracked, the legitimate access method cannot be determined), significantly reducing the probability of the overall encryption system failing.

[0073] The encrypted data packet is composed of attribute-based ciphertext and policy tags, both of which are encrypted. External attackers cannot identify the original data content, attribute set, or access policy from the data packet, and it is even more difficult to establish the correlation between data content and access permissions, reducing the possibility of targeted attacks (for example, it is impossible to specifically attack the corresponding ciphertext by identifying financial data tags).

[0074] The encrypted policy tag is only decrypted and takes effect within a third-party network, preventing the policy from being interfered with during transmission or storage (such as bypassing the policy to directly access data). This ensures that the entire process from data transmission to use is subject to preset rules, making it particularly suitable for scenarios with strict data access control (such as financial and government data).

[0075] In an optional embodiment of the present invention, step 13, which involves unidirectionally sending the encrypted data packet to the third network via the second network, includes:

[0076] Step 131: Send the encrypted data packet to the optical gate of the second network through the dynamic port of the first network;

[0077] Step 132: The encrypted data packet is forwarded unidirectionally to the third network through the optical gate of the second network.

[0078] Specifically, the optical shutter employs a disconnected data transfer mechanism (without real-time bidirectional connection) to achieve unidirectional network transmission.

[0079] The first network first performs integrity, format and security checks on the encrypted data packets. After the checks are passed, a dynamic port (such as the range of 40000-65535) is randomly assigned from a preset port pool. The encrypted data packets use the dynamic port as the source port, encapsulate the TCP / IP protocol and forward them to the optical gate intranet unit of the second network (only the fixed listening port is open to receive data) through the first network boundary device. The dynamic port is immediately closed after the transmission ends to avoid port exposure.

[0080] After receiving a data packet, the internal network unit of the optical gate strips the TCP / IP header, retaining only the encrypted payload temporarily stored in a read-only buffer, and then disconnects the physical connection with the buffer. The external network unit of the optical gate establishes a temporary connection with the buffer, extracts the data, and forwards it unidirectionally to the receiving node of the third network via a dedicated link of the second network. Throughout the process, the third network is prohibited from transmitting data back to the second network, thus achieving secure unidirectional transmission of encrypted data packets.

[0081] In this example, the optical gate adopts a disconnected data transfer mechanism with no real-time bidirectional connection, achieving physical-level unidirectional isolation, completely blocking the reverse attack path, and preventing the reverse connection from the third network to the first and second networks, which is more secure than traditional firewalls.

[0082] The first network uses dynamic ports, which are randomly assigned and closed after transmission, to avoid targeted attacks on fixed ports, reduce the port exposure surface, and lower security management costs.

[0083] The optical shutter does not parse data packet content, adapts to encrypted packet transmission characteristics, is compatible with heterogeneous network protocols, and ensures transmission efficiency and stability. Simultaneously, as the sole channel, the optical shutter can centrally record transmission logs, meeting the requirements for one-way network isolation and monitoring, enabling auditable and controllable transmission behavior, and is suitable for high-security scenarios.

[0084] In an optional embodiment of the present invention, step 131, sending the encrypted data packet to the optical gate of the second network through the dynamic port of the first network, includes:

[0085] Step 1311: Verify the encrypted data packet. If the verification is successful, open the dynamic port of the first network.

[0086] Step 1312: Send the encrypted data packet to the optical gate of the second network through the dynamic port of the first network;

[0087] Step 1313: After the transmission is complete, close the dynamic port of the first network.

[0088] Specifically, the verification of the encrypted data packet may include: integrity verification, format compliance verification, and security compliance verification;

[0089] Integrity verification: Verifies whether the encrypted data packet has been tampered with during storage or preprocessing within the first network.

[0090] Compliance verification: Ensure that the structure of the encrypted data packet conforms to the cross-network transmission protocol specifications to avoid the optical gate or second network being unable to recognize it due to format errors;

[0091] Security and compliance verification: Further filter potential risks and prevent malicious data from being mixed into the transmission process.

[0092] If all three types of verifications pass (i.e., integrity is consistent, format is compliant, and there are no security risks), the first network will trigger the dynamic port opening command (the subsequent operation of step 1311). If any verification fails, the data packet will be intercepted and the dynamic port will not be opened, thus ensuring the security and effectiveness of cross-network transmission from the source.

[0093] In this example, triple verification strengthens the security defense at the source of transmission: integrity verification prevents data tampering, format compliance verification ensures transmission compatibility, and security compliance verification filters malicious data. Only data packets that pass full verification can trigger port opening, intercepting risky data at the source and preventing abnormal data packets from entering the transmission link.

[0094] Dynamic ports are opened on demand and closed when not in use. They are only temporarily enabled after verification and closed immediately after transmission is completed, minimizing port exposure time and attack surface. Compared to fixed ports or ports that are opened without verification, their anti-attack capability is significantly improved.

[0095] The verification mechanism, in conjunction with the dynamic port, not only ensures the security and validity of data packets transmitted across networks, preventing optical gate or secondary network transmission failures due to data issues and guaranteeing transmission stability, but also saves transmission resources by intercepting invalid data, improving the overall efficiency of cross-network transmission and further perfecting the security management system for cross-network transmission.

[0096] In an optional embodiment of the present invention, in step 13, the third network decrypts the encrypted data packet to obtain decrypted data, including:

[0097] Step 133: The third network extracts and verifies the policy flag in the encrypted data packet; specifically, according to... Determine the strategy flag;

[0098] in, T For policy tagging, Extract1 To extract the strategy tagging function, Pkg To encrypt data packets;

[0099] It can also generate unique identifiers (such as timestamps + data packet hash values).

[0100] Step 134: If the verification passes, decrypt the attribute-based ciphertext in the encrypted data packet to obtain decrypted data including the original data; specifically, if If yes, then the verification is successful;

[0101] in, Verify Label the validation function for the strategy. T For policy tagging, SK * For policy encryption key SK The corresponding decryption key, True Verification passed (the strategy was not tampered with and is legal);

[0102] according to Determine the attribute base ciphertext;

[0103] Among them, C T For attribute-based ciphertext, Extract2 To extract the base ciphertext function, Pkg To encrypt data packets;

[0104] according to Determine the decrypted data, including the original data;

[0105] in, M This includes decrypted data containing the original data. ABE decrypt For attribute base decryption functions, C T For attribute-based ciphertext, SK user For third-party network authorized users' private keys, S * For the attribute set of the original data S The corresponding set of attributes of the decryptor.

[0106] In this example, the unique identification mechanism enhances data traceability. The generated timestamp + hash value unique identifier can accurately locate data packets, facilitating full lifecycle tracking and adapting to auditing and troubleshooting needs.

[0107] Policy tag verification forms the first line of defense for access control. Policy tags are extracted and verified first. Decryption is only allowed if the corresponding decryption key is successfully verified (confirming that the policy has not been tampered with and is legitimate). This ensures the authority of access rules and prevents uncontrolled access due to malicious tampering of policies.

[0108] Attribute-based decryption enables fine-grained access control. After extracting the attribute-based ciphertext, it needs to be decrypted using the authorized user's private key and the matching actual attribute set. Only the attribute matcher can obtain the original data, achieving precise access control based on attribute authorization and preventing the decrypted data from being misused by unauthorized objects.

[0109] The layered decryption mechanism enhances overall security. Policy verification and attribute-based decryption form a dual verification process. Even if the attribute-based ciphertext is cracked, valid data cannot be obtained without policy verification, reducing the risk of failure in a single step. Meanwhile, the streamlined process of temporary storage, retrieval, verification, and decryption ensures that the decryption process is standardized and controllable, adapting to the data usage requirements of high-security scenarios and balancing security with flexible access control.

[0110] In an optional embodiment of the present invention, step 13, the above-mentioned transmission method further includes:

[0111] Step 135: If the policy tag verification in the encrypted data packet fails, generate and output the first transmission log.

[0112] Specifically, when the policy tag verification function returns the result as False (Right now When collecting data, the following information is collected: the unique identifier of the temporarily stored encrypted data packet (such as timestamp + data packet hash value), the policy tag extraction result, the reason for verification failure (such as key mismatch, policy tag tampering, policy format abnormality, etc.), the execution time of the verification operation, the IP of the third network receiving node, and the ID of the current accessing user.

[0113] According to the preset log format (such as time, log type, data packet identifier, operation step, failure reason, and related information), the above information is encapsulated into the first transmission log;

[0114] The first transmission log is synchronously output to the log storage server of the third network (for long-term retention and auditing traceability) and the operation and maintenance alarm platform (for real-time push alarm notifications to remind staff to investigate anomalies). At the same time, the subsequent decryption process is terminated, and the temporarily stored data packets are kept in a read-only state (to facilitate problem location).

[0115] This example enables precise tracing of abnormal behavior. Logs collect core information such as unique identifiers (timestamp + hash value), failure reasons, and execution time. Combined with preset format specifications, it provides a complete chain of evidence for auditing, which can quickly locate the source of abnormal data packets, the fault link, and related users, meeting the traceability requirements for data security compliance.

[0116] A real-time alarm and response mechanism is established, and logs are pushed synchronously to the operation and maintenance alarm platform, enabling staff to detect risks such as policy tampering and key mismatch in a timely manner, and intervene in the investigation in a timely manner (such as intercepting malicious data packets and fixing key synchronization problems), so as to prevent abnormal data from being further transferred and control security risks in the early stage of decryption.

[0117] To ensure the controllability of data and processes, the decryption process is terminated immediately upon verification failure, and the data packet is kept in a read-only state. This prevents unauthorized decryption and preserves the original data for problem localization, avoiding data loss or tampering due to improper exception handling.

[0118] Strengthening the end-to-end security loop, logs are stored on the storage server for a long time. This allows for the analysis of attack patterns and high-frequency failure points based on historical data, providing data support for optimizing encryption strategies and improving verification mechanisms. This forms a security loop of anomaly detection, alarm, tracing, and optimization, significantly improving the ability to resist risks in cross-network transmission.

[0119] In an optional embodiment of the present invention, step 13, the above-mentioned transmission method further includes:

[0120] Step 136: If the policy flag in the encrypted data packet passes the verification, generate and output the second transmission log.

[0121] Specifically, when the policy tag verification function returns the result as True The data collected includes: the unique identifier of the temporarily stored encrypted data packet, the policy tag extraction result, the verification pass conclusion, the execution time of the verification operation, the IP of the third network receiving node, and the permission template matched after the policy is decrypted.

[0122] According to the preset log format (such as time|log type|data packet identifier|operation step|pass conclusion|permission matching information), the above information is encapsulated into a second transmission log (the log type is marked as policy verification passed).

[0123] The second transmission log is output to the log storage server of the third network (classified and archived with the first transmission log), and the log association identifier is synchronized to the decryption module as a compliance credential for the decryption operation, ensuring that the decryption process is traceable.

[0124] In this example, a complete compliance audit chain is constructed. Logs record key information such as unique identifiers, verification conclusions, and execution times, and are archived according to a preset format, clearly presenting the entire process details of policy verification. Combined with the first transmission logs, this creates a complete log system of anomalies and normal operations, meeting the data security regulations' requirements for auditable operations and providing clear evidence for compliance checks.

[0125] Strengthen the legitimacy endorsement of the decryption process, synchronize the log association identifier to the decryption module as a compliance credential, ensure that subsequent attribute-based ciphertext decryption operations are based on verified legitimate policies, realize the permission linkage between verification and decryption, avoid decryption without credentials or unauthorized operations, and safeguard the legitimacy of data access from the process perspective.

[0126] It supports permission tracing and analysis. The log contains the permission template matched after policy decryption, which can trace the authorization scope corresponding to the data packet (such as the allowed user attributes and permission level). This makes it easier for administrators to review the rationality of permission allocation, discover permission configuration vulnerabilities in a timely manner (such as over-authorization), and provide data support for optimizing access policies.

[0127] Enhancing the transparency and controllability of the transmission process, by recording key information in the normal verification process in detail, allows administrators to fully grasp the flow trajectory of legitimate data packets. Combined with historical logs, characteristics such as data transmission peaks and high-frequency access objects can be analyzed, providing a basis for decision-making on network resource allocation and transmission efficiency optimization, and improving the refined management system for cross-network transmission.

[0128] Example 1

[0129] An organization needs to transmit its quarterly financial statements (structured data), customer credit video (unstructured data), and business operation XML logs (semi-structured data) from its local network to its dedicated business network, with the entire process forwarded via the Internet.

[0130] A method for cross-network transmission of target data, comprising:

[0131] Step 21, Obtaining Data and Encryption Tools:

[0132] The target data is stored on the local first network server. The attribute-based encrypted text is sent over the Internet, which is physically isolated from the first network. After local security testing, it is deployed on the first network. Staff retrieve financial statements (including revenue data and expenditure details) from the local database and obtain customer credit videos and XML operation logs from the storage server. All raw data does not leave the local first network.

[0133] Step 22, generate data packets using layered encryption:

[0134] For the content of financial statements, attribute-based ciphertext is generated by using the attribute-based encryption function and the system public key, based on the security level = high + department = financial attribute set;

[0135] The data access policy can only be downloaded by the finance manager. Access must be logged and encrypted using the policy encryption key through the access policy encryption function to generate a policy tag.

[0136] By combining attribute base ciphertext and policy tags, an encrypted data packet is obtained, with no plaintext exposed throughout the entire process;

[0137] Step 23, Verification and One-Way Transmission:

[0138] The local network performs triple verification on encrypted data packets: verifying that the file has not been tampered with (integrity), that the format conforms to cross-network protocols (compliance), and that there is no malicious code (security). After the verification is passed, a random dynamic port (such as port 54321) is opened.

[0139] Encrypted data packets are sent to the optical gateway via a dynamic port to the Internet. The optical gateway then forwards the data packets unidirectionally to the dedicated business network via a disconnected data transfer mechanism (first storing and then pushing). Once the transmission is complete, the dynamic port is immediately closed.

[0140] Step 24, Private Network Decryption and Log Management:

[0141] The business private network receives encrypted data packets and generates a unique identifier (such as 202410011530 + hash value a1b2c3), which is temporarily stored on the server;

[0142] Extract the policy flag, verify it with the corresponding decryption key (confirming that the policy has not been tampered with), generate a second transmission log (recording the flag, the pass conclusion, and the matching financial manager permission template), and synchronize it to the decryption module as proof;

[0143] Extract the attribute-based ciphertext. The finance manager decrypts it using their personal private key and the attribute set: Department = Finance + Position = Manager. This allows them to obtain the original financial statements, videos, and logs. Other department personnel are unable to decrypt the data due to attribute mismatch.

[0144] If attribute-based ciphertext verification fails during a transmission (e.g., key mismatch), the system immediately generates the first transmission log (including the reason for failure and the accessing user ID), pushes an alarm to the operation and maintenance platform, terminates decryption, and locks the data packet for investigation.

[0145] This invention features end-to-end encrypted transmission with terminal decryption, eliminating the risk of plaintext exposure; local closed-loop encryption prevents the leakage of original data; attribute-based encryption and policy encryption provide dual protection; optical gates provide physical isolation to block reverse attacks; and dynamic ports reduce the exposure surface, ensuring data security from the source to the transmission link in all aspects.

[0146] A single encryption / decryption process reduces hardware resource consumption and lowers costs; automatic network transmission eliminates the need for manual intervention, enabling real-time transmission and improving business efficiency; local encryption tools avoid network dependence and are adapted for efficient processing of large volumes of data.

[0147] The attribute-based decryption mechanism accurately adapts to the permission division of multiple scenarios, policy encryption ensures the authority of access rules, and layered verification reduces the risk of failure in a single link, meeting the high security requirements of finance, government affairs, and other sectors.

[0148] A complete logging system enables end-to-end auditing and traceability, real-time alerts for abnormal logs form a security closed loop, and two-way log classification and archiving supports permission analysis and resource optimization, fully complying with data security regulations.

[0149] like Figure 3 As shown, embodiments of the present invention also provide a cross-network transmission device 30 for target data, comprising:

[0150] The acquisition module 31 is used to acquire target data in the local first network and attribute-based ciphertext encryption tools sent by a second network that is physically isolated from the first network;

[0151] Processing module 32 is used to encrypt the target data using the attribute-based ciphertext encryption tool to obtain an encrypted data packet; send the encrypted data packet unidirectionally to the third network via the second network; and enable the third network to decrypt the encrypted data packet to obtain decrypted data.

[0152] Optionally, the target data is encrypted using the attribute-based ciphertext encryption tool to obtain an encrypted data packet, including:

[0153] The original data in the target data is encrypted using the attribute-based ciphertext encryption tool to obtain attribute-based ciphertext;

[0154] The data access policy in the target data is encrypted to obtain a policy tag;

[0155] The attribute base ciphertext and policy tag are bound and combined to obtain an encrypted data packet.

[0156] Optionally, transmitting the encrypted data packet unidirectionally to the third network via the second network includes:

[0157] The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network;

[0158] Encrypted data packets are forwarded unidirectionally to the third network via the optical gate of the second network.

[0159] Optionally, sending encrypted data packets to the optical gate of the second network through the dynamic port of the first network includes:

[0160] The encrypted data packet is verified. If the verification passes, the dynamic port of the first network is opened.

[0161] The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network;

[0162] After the transmission is complete, close the dynamic port of the first network.

[0163] Optionally, the third network decrypts the encrypted data packet to obtain decrypted data, including:

[0164] The third network extracts and verifies the policy marker in the encrypted data packet;

[0165] If the verification passes, the attribute-based ciphertext in the encrypted data packet is decrypted to obtain decrypted data including the original data.

[0166] Optionally, the transmission device 30 further includes:

[0167] If the policy tag verification in the encrypted data packet fails, the first transmission log is generated and output.

[0168] Optionally, the transmission device 30 further includes:

[0169] If the policy flag in the encrypted data packet passes the verification, a second transmission log is generated and output.

[0170] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0171] Embodiments of the present invention also provide a computing device, including: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described above. All implementations in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0172] Embodiments of the present invention also provide a computing device readable storage medium storing instructions that, when executed on a computing device, cause the computing device to perform the method described above. All implementations in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.

[0173] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computing device software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0174] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0175] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0176] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0177] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0178] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computing device-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computing device software product is stored in a storage medium and includes several instructions to cause a computing device (which may be a personal computing device, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0179] Furthermore, it should be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of the present invention. Moreover, the steps performing the above-described series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve using basic programming skills after reading the description of the present invention.

[0180] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a known general-purpose device. Therefore, the object of the present invention can also be achieved simply by providing a program product containing program code implementing the method or apparatus. That is, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any known storage medium or any storage medium developed in the future. It should also be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent to the present invention. Furthermore, the steps performing the above series of processes can naturally be performed in the order described, but are not necessarily required to be performed in chronological order. Some steps can be performed in parallel or independently of each other.

[0181] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for cross-network transmission of target data, characterized by, include: Acquire target data from the local first network and attribute-based ciphertext encryption tools sent from a second network that is physically isolated from the first network; The target data is encrypted using the attribute-based ciphertext encryption tool to obtain an encrypted data packet; The encrypted data packet is sent unidirectionally from the second network to the third network, allowing the third network to decrypt the encrypted data packet and obtain decrypted data. If the policy flag verification in the encrypted data packet fails, generate and output the first transmission log; If the policy flag in the encrypted data packet passes the verification, a second transmission log is generated and output. The target data is encrypted using the attribute-based ciphertext encryption tool to obtain an encrypted data packet, including: The original data in the target data is encrypted using the attribute-based ciphertext encryption tool to obtain the attribute-based ciphertext; through... Determine the attribute base ciphertext; in, CT For attribute-based ciphertext, ABE data For attribute-based encryption functions, PK For the system public key, M The original data in the target data. S The attribute set of the original data; The data access policy in the target data is encrypted to obtain a policy tag; through Determine the strategy flag; in, T For policy tagging, Enc policy Encryption functions for access policies, SK The policy encryption key, P For data access strategies; The attribute base ciphertext and policy tag are bound and combined to obtain an encrypted data packet; through... Identify the encrypted data packet; in, Pkg To encrypt data packets, CT For attribute-based ciphertext, T Mark the strategy; Sending encrypted data packets unidirectionally to the third network via the second network includes: The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network; The encrypted data packets are forwarded unidirectionally to the third network via the optical gate of the second network; the optical gate adopts a disconnected data transfer mechanism, without real-time bidirectional connection, to realize unidirectional network transmission. Sending encrypted data packets to the optical gate of the second network through the dynamic port of the first network includes: The encrypted data packet is verified. If the verification passes, the dynamic port of the first network is opened. The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network; After the transmission is complete, close the dynamic port of the first network; The verification of the encrypted data packet includes: integrity verification, format compliance verification, and security compliance verification; Integrity verification: Verifies whether the encrypted data packet has been tampered with during storage or preprocessing within the first network. Compliance verification: Ensure that the structure of the encrypted data packet conforms to the cross-network transmission protocol specifications to avoid the optical gate or second network being unable to recognize it due to format errors; Security and compliance verification: Further filter potential risks and prevent malicious data from being mixed into the transmission process; The third network decrypts the encrypted data packet to obtain decrypted data, including: Extract and verify the policy marker in the encrypted data packet from the third network; according to Determine the strategy flag; in, T For policy tagging, Extract1 To extract the strategy tagging function, Pkg To encrypt data packets; If the verification passes, the attribute-based ciphertext in the encrypted data packet is decrypted to obtain decrypted data including the original data; if If so, the verification is successful; in, Verify Label the validation function for the strategy. T For policy tagging, SK * To encrypt the key with the policy SK The corresponding decryption key, True Verification passed; according to Determine the attribute base ciphertext; Among them, C T For attribute-based ciphertext, Extract2 To extract the base ciphertext function, Pkg To encrypt data packets; according to Determine the decrypted data, including the original data; in, M This includes decrypted data containing the original data. ABE decrypt For attribute base decryption functions, C T For attribute-based ciphertext, SK user For third-party network authorized users' private keys, S * For the attribute set of the original data S The corresponding set of attributes of the decryptor.

2. A cross-network transmission device for target data, characterized in that, include: The acquisition module is used to acquire target data in the local first network and attribute-based ciphertext encryption tools sent by a second network that is physically isolated from the first network; The processing module is used to encrypt the target data using the attribute-based ciphertext encryption tool to obtain an encrypted data packet; to send the encrypted data packet unidirectionally to the third network via the second network; and to decrypt the encrypted data packet via the third network to obtain decrypted data. If the policy flag verification in the encrypted data packet fails, generate and output the first transmission log; If the policy flag in the encrypted data packet passes the verification, a second transmission log is generated and output. The target data is encrypted using the attribute-based ciphertext encryption tool to obtain an encrypted data packet, including: The original data in the target data is encrypted using the attribute-based ciphertext encryption tool to obtain the attribute-based ciphertext; through... Determine the attribute base ciphertext; in, CT For attribute-based ciphertext, ABE data For attribute-based encryption functions, PK For the system public key, M The original data in the target data. S The attribute set of the original data; The data access policy in the target data is encrypted to obtain a policy tag; through Determine the strategy flag; in, T For policy tagging, Enc policy Encryption functions for access policies, SK The policy encryption key, P For data access strategies; The attribute base ciphertext and policy tag are bound and combined to obtain an encrypted data packet; through... Identify the encrypted data packet; in, Pkg To encrypt data packets, CT For attribute-based ciphertext, T Mark the strategy; Sending encrypted data packets unidirectionally to the third network via the second network includes: The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network; The encrypted data packets are forwarded unidirectionally to the third network via the optical gate of the second network; the optical gate adopts a disconnected data transfer mechanism, without real-time bidirectional connection, to realize unidirectional network transmission. Sending encrypted data packets to the optical gate of the second network through the dynamic port of the first network includes: The encrypted data packet is verified. If the verification passes, the dynamic port of the first network is opened. The encrypted data packet is sent to the optical gate of the second network through the dynamic port of the first network; After the transmission is complete, close the dynamic port of the first network; The verification of the encrypted data packet includes: integrity verification, format compliance verification, and security compliance verification; Integrity verification: Verifies whether the encrypted data packet has been tampered with during storage or preprocessing within the first network. Compliance verification: Ensure that the structure of the encrypted data packet conforms to the cross-network transmission protocol specifications to avoid the optical gate or second network being unable to recognize it due to format errors; Security and compliance verification: Further filter potential risks and prevent malicious data from being mixed into the transmission process; The third network decrypts the encrypted data packet to obtain decrypted data, including: Extract and verify the policy marker in the encrypted data packet from the third network; according to Determine the strategy flag; in, T For policy tagging, Extract1 To extract the strategy tagging function, Pkg To encrypt data packets; If the verification passes, the attribute-based ciphertext in the encrypted data packet is decrypted to obtain decrypted data including the original data; if If so, the verification is successful; in, Verify Label the validation function for the strategy. T For policy tagging, SK * To encrypt the key with the policy SK The corresponding decryption key, True Verification passed; according to Determine the attribute base ciphertext; Among them, C T For attribute-based ciphertext, Extract2 To extract the base ciphertext function, Pkg To encrypt data packets; according to Determine the decrypted data, including the original data; in, M This includes decrypted data containing the original data. ABE decrypt For attribute base decryption functions, C T For attribute-based ciphertext, SK user For third-party network authorized users' private keys, S * For the attribute set of the original data S The corresponding set of attributes of the decryptor.

3. A computing device, characterized in that, include: One or more processors; A storage device for storing one or more programs that, when executed by one or more processors, cause the one or more processors to perform the method as described in claim 1.

4. A computing device readable storage medium, characterized in that, The computing device readable storage medium stores a program that, when executed by a processor, implements the method as described in claim 1.

Citation Information

Patent Citations

  • Cross-network data transmission method, device, equipment and medium

    CN115834584A

  • Isolation network equipment, cross-network cross-domain data one-way transmission system and cross-network cross-domain data one-way transmission method

    CN116886377A

  • Data security storage and sharing method for cross-network distributed platform

    CN118945180A