Trusted security protection method and equipment based on network isolation

By introducing a security software module between the business software and the network gateway for digital certificate authentication and continuous protection, the problem of insufficient external network software identity authentication and integrity protection in existing technologies is solved, achieving end-to-end trusted security protection and improving the security and compliance of critical infrastructure.

CN121567449APending Publication Date: 2026-02-24SHANGHAI GIDEKANG TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511905374.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-17
Publication Date
2026-02-24

AI Technical Summary

Technical Problem

Existing network isolation solutions lack identity authentication and integrity protection for external network business software in critical infrastructure. This allows malicious software that has compromised legitimate servers to easily communicate with the internal network through the network gateway, creating a security blind spot.

Method used

A security software module is introduced between the business software and the network gateway. It uses digital certificates for two-way authentication to verify the identity and integrity of the business software. After successful authentication, a secure data transmission channel is established to collaboratively perform continuous protection.

Benefits of technology

Build an end-to-end defense-in-depth system to improve the overall security level of the system, detect software anomalies and interrupt threats in real time, reduce the complexity and cost of system upgrades, and meet high-level compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121567449A_ABST
    Figure CN121567449A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network isolation security, and provides a credible security protection method and equipment based on network isolation, and the method comprises the steps: setting a security software module between business software deployed in an extranet and a gatekeeper between the extranet and an intranet; before the service software initiates access to the intranet equipment, the security software module and the gatekeeper perform bidirectional security authentication based on the digital certificate, and the identity and integrity of the service software are verified in the authentication process; only after the authentication step is successfully completed, a trusted security data transmission channel is established between the security software module and the gatekeeper; and in the process that the service software performs service interaction with the intranet equipment through the security data transmission channel, the security software module and the gatekeeper cooperatively execute continuous security protection. According to the invention, the security defense line is substantially moved forward and extends to the service software, so that strong identity authentication of the access subject is realized, and the overall security of the key information infrastructure is systematically improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network isolation security technology, and in particular to a trusted security protection method and device based on network isolation. Background Technology

[0002] In critical national infrastructure industries such as power, petroleum, and chemicals, network architecture design generally follows the principles of "security zoning, dedicated networks, horizontal isolation, and vertical authentication" to ensure the safe and stable operation of core production control systems. Dividing the entire network into a production control zone (internal network) and a management information zone (external network) is the most basic security zoning method. The production control zone is directly responsible for monitoring and controlling the power production process, requiring extremely high real-time performance, reliability, and security. The management information zone primarily handles non-real-time tasks such as office work, management, and data analysis. To prevent security threats from the external network from penetrating the internal network, physical isolation gateways (hereinafter referred to as "gateways") become the core equipment for achieving horizontal isolation. Through their unique hardware architecture and security protocols, gateways, while severing direct TCP / IP connections between the internal and external networks, use proprietary protocols for secure and controllable data transfer, thereby ensuring necessary data exchange while achieving effective isolation of network boundaries.

[0003] The currently widely adopted security protection solution involves deploying business software such as production monitoring and data acquisition in the management information zone on the external network, and deploying control equipment such as PLCs, RTUs, and protection devices in the production control zone on the internal network, with the two connected via a network gateway. Under this architecture, data flows from business software accessing internal network devices must undergo strict inspection and forwarding by the network gateway.

[0004] However, existing network gateway-based isolation solutions have a significant security weakness: their protection focus is entirely on the network boundary itself, lacking effective authentication and integrity protection for external network application software that crosses the boundary. Many application software programs, especially those developed early on or from third parties, may have been designed with functionality in mind, but inherently flawed in their security features, such as lacking strong authentication mechanisms, unencrypted communication processes, and vulnerability to tampering or replacement. In traditional network gateway solutions, filtering and control are primarily based on network layer information such as IP addresses, ports, and protocols. Once an IP address is authorized, any software running on that host (including malware or tampered application software) can use this channel to communicate with the internal network.

[0005] Chinese patent CN103491072A discloses a boundary access control method based on a dual unidirectional isolation gateway. The core authentication unit of this scheme is an "application server," whose verified identity information (such as server name and IP address) belongs to the machine or device level. It cannot identify and verify the identity and integrity of specific business software or processes running on this server. If a legitimate server is compromised, malicious software or tampered legitimate software running on it can easily exploit the server's legitimate identity to pass authentication, thus creating a security blind spot and failing to prevent attacks originating from within the server using "legitimate identity, illegitimate software."

[0006] Therefore, how to introduce trusted authentication and continuous protection mechanisms between business software and network gateways, move the security defense line from the network boundary to the business software itself, achieve comprehensive verification of the identity, state, and behavior of the access subject (software), and build an end-to-end trusted security protection system from external network applications to internal network devices has become an urgent technical problem to be solved. Summary of the Invention

[0007] In view of this, in order to overcome the shortcomings of the prior art, the present invention aims to provide a trusted security protection method and device based on network isolation.

[0008] According to a first aspect of the present invention, a trusted security protection method based on network isolation is provided, the method comprising: Step S1: Configure a security software module between the business software deployed on the external network and the network gateway set up between the external network and the internal network; Step S2: Before the business software initiates access to the intranet device, the security software module and the network gateway perform two-way security authentication based on digital certificates, and verify the identity and integrity of the business software during the authentication process; Step S3: Only after the authentication step is successfully completed, establish a trusted secure data transmission channel between the security software module and the gateway; Step S4: During the process of business software interacting with intranet devices through a secure data transmission channel, the security software module and the network gateway work together to perform continuous security protection.

[0009] Optionally, in the trusted security protection method based on network isolation of the present invention, in step S1, the security software module is independently deployed on the external network application terminal where the business software is located, and runs in conjunction with the business software. The security software module acts as a proxy and security intermediary for all communication between the business software and the network gateway, and is responsible for handling security authentication, data encryption and protection interaction with the network gateway, while the business software itself does not need to be modified in any way.

[0010] Optionally, in the trusted security protection method based on network isolation of the present invention, in step S2, the security software module and the network gateway perform two-way security authentication based on digital certificates in the following manner: Configure digital certificates issued by trusted authorities for the security software module, the external network processing unit of the network gateway, and the internal network processing unit. During the authentication initialization phase, the security software module and the external network processing unit of the gateway exchange and verify each other's digital certificates to verify the legitimacy of each other's identities.

[0011] Optionally, in the trusted security protection method based on network isolation of the present invention, in step S2, the external network processing unit of the network gateway locally maintains a real-time updated certificate revocation list. Each time the security software module and the network gateway perform bidirectional security authentication, the certificate revocation list is queried to confirm that the other party's certificate has not been revoked.

[0012] Optionally, in the trusted security protection method based on network isolation of the present invention, step S2 verifies the identity and integrity of the business software during the authentication process in the following manner: The security software module sends the attribute information related to the application hardware and business software carried in its digital certificate to the network gateway. The network gateway then matches and verifies the received attribute information against a pre-stored list of legitimate authorizations. The security software module calculates the hash value of the executable file or key components of the business software in real time and sends the hash value to the network gateway. The network gateway compares the received hash value with the pre-stored baseline hash value to confirm that the business software has not been tampered with.

[0013] Optionally, in the trusted security protection method based on network isolation of the present invention, the attribute information carried in the digital certificate related to the application hardware and business software includes at least: the unique hardware serial number of the application motherboard, the version identifier of the business software, and the hash value of the business software file content and installation directory path.

[0014] Optionally, in the trusted security protection method based on network isolation of the present invention, after establishing a trusted secure data transmission channel in step S3, the service data flows in the following manner: The business software delivers the business data to be sent to the security software module. The security software module uses a session encryption algorithm and message authentication key negotiated with the network gateway to encrypt the business data and encapsulate it with a message authentication code. The encapsulated data is sent to the external network processing unit of the gateway through a secure data transmission channel. After decryption and integrity verification, it is forwarded to the internal network processing unit through the gateway's internal secure transfer mechanism and finally delivered to the target internal network device.

[0015] Optionally, in the trusted security protection method based on network isolation of the present invention, in step S3, the security software module and the external network processing unit of the network gateway use the public keys in each other's digital certificates to negotiate and generate a session encryption algorithm and a message authentication key for secure data transmission channels through a standard key exchange protocol.

[0016] Optionally, in the trusted security protection method based on network isolation of the present invention, in step S4, the security software module and the network gateway cooperate to perform continuous security protection in the following manner: During the operation of the business software, the network gateway requests the security software module to re-initiate a simplified authentication process according to a preset time interval or based on specific security event triggering conditions. The simplified authentication process includes at least verifying the liveness status of the critical processes of the business software and confirming the freshness of the current session key.

[0017] According to a second aspect of the present invention, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method described in the first aspect of the present invention.

[0018] The trusted security protection method and device based on network isolation of the present invention have the following beneficial technical effects: 1. Build an end-to-end defense-in-depth system to significantly improve the overall security level of the system.

[0019] By substantially moving the security defense line forward and extending it to the business software itself, strong identity authentication of the access subject (business software and its host environment) is achieved through two-way authentication based on digital certificates; by comparing software hash values, the integrity of business software at startup and during operation is ensured, effectively resisting threats such as man-in-the-middle attacks and software tampering attacks that use legitimate network channels for illegal access, and systematically improving the overall security of critical information infrastructure.

[0020] 2. Achieve continuous and dynamic protection throughout the lifecycle of business software, and enhance the real-time nature of security response.

[0021] Through periodic lightweight re-authentication, session state monitoring, and continuous encryption and integrity protection of communication data, the system can detect abnormal changes in the business software's operating environment or its own state in real time. Once an anomaly is detected, the system can immediately issue an alert and terminate the session, significantly shortening the exposure time of security threats and enhancing the system's dynamic security defense capabilities.

[0022] 3. While ensuring enhanced security, it maintains compatibility with existing business systems and software, resulting in low deployment costs.

[0023] No source code modification or functional restructuring is required for existing business software. The business software can maintain its original logic and seamlessly integrate into the security protection system through transparent technologies such as network proxies or API hooks. This feature allows the solution to be smoothly integrated into various existing systems, especially those using traditional designs or third-party closed-source business software, greatly reducing the complexity, risk, and cost of system upgrades and modifications.

[0024] 4. Provide sophisticated security control measures to help meet high-level compliance requirements.

[0025] This enables granular access control from the "server IP address" level to the "specific software on a specific server" level. Administrators can formulate refined security policies based on the software's identity, version, and integrity status, improving the accuracy of security management and providing strong technical support for meeting the high-standard compliance requirements of industries such as power, energy, and finance for access control of critical systems. Attached Figure Description

[0026] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0027] Figure 1 This is a schematic diagram of the trusted secure network isolation architecture on which the method of Exemplary Embodiment 1 of the present invention is based; Figure 2 This is a schematic diagram of the security authentication process before the business software runs in the method of Exemplary Embodiment 2 of the present invention; Figure 3 This is a schematic diagram of the security protection process of the method in exemplary embodiment 3 of the present invention during the operation of business software; Figure 4 This is a flowchart illustrating the steps of a trusted security protection method based on network isolation according to an exemplary embodiment 4 of the present invention. Figure 5 This is a schematic diagram of the structure of the device provided by the present invention. Detailed Implementation

[0028] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.

[0029] It should be noted that, in the absence of conflict, the following embodiments and features can be combined with each other; and, based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0030] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein. Example 1

[0031] Exemplary embodiment 1 of the present invention provides a trusted security protection method based on network isolation. Figure 1 This is a schematic diagram of the trusted secure network isolation architecture on which the method of Exemplary Embodiment 1 of the present invention is based.

[0032] like Figure 1 As shown, in this embodiment, by adding security authentication between the gateway and the security software on the application side, and the authentication information including the hardware information of the application side, the information of the business software, the information of the external network processing unit, the information of the internal network processing unit, and the information of the internal network device, the overall system security, including the application side, is improved. The business software on the application side can be the same as the software in the system without a gateway.

[0033] The security authentication in this embodiment is based on digital certificates. The external network processing unit, the internal network processing unit, and the application terminal each possess digital certificates. The key information in the digital certificate of the network gateway is the network gateway public key and network gateway identity information. The key information in the digital certificate of the application terminal is the application public key, application terminal system information, and application terminal business software information, including hardware serial number, operating system version, software version number, software file content, and the hash value of the installation directory, etc. Example 2

[0034] Exemplary embodiment 2 of the present invention provides a trusted security protection method based on network isolation. Figure 2 This is a schematic diagram of the security authentication process before the business software runs in the method of Exemplary Embodiment 2 of the present invention, as shown below. Figure 2 As shown, the security authentication process before the business software runs begins with the security software module actively initiating an authentication request to the external network processing unit of the gateway. This request triggers a two-way authentication and session initialization process based on digital certificates.

[0035] First, the security software module sends its own digital certificate to the external network processing unit of the gateway. This certificate contains not only the application's public key but also embedded hardware identifiers of the application (such as hardware serial number), operating system version, and attribute information of the business software to be verified (such as software version number, file content, and hash value of the installation path). Upon receiving the certificate, the external network processing unit performs two core verifications: first, verifying the authenticity and validity of the certificate itself, including checking the issuing authority and validity period; second, comparing the hardware and software information extracted from the certificate with a pre-stored list of legitimate authorizations to confirm the legitimacy of the application's identity. Next, the external network processing unit sends its own digital certificate to the security software module, which then verifies the gateway's identity. After successful two-way authentication, the process enters the software integrity verification stage: the security software module calculates the hash value of the key executable files of the business software in real time and sends this hash value to the gateway; the gateway compares this hash value with a pre-stored, trusted baseline hash value. Only when the real-time hash value is completely consistent with the baseline value is it determined that the business software has not been tampered with, and its integrity is guaranteed.

[0036] After all the above steps are successfully completed, the external network processing unit of the gateway and the security software module negotiate and generate a temporary session key, and formally establish an encrypted secure data transmission channel. At this point, the authentication process is complete, and the business software is granted permission to access internal network devices through this secure channel. If any step of the authentication fails, the connection is immediately terminated and a security log is recorded.

[0037] Traditional security solutions stop at the network boundary (gateway), creating a defense gap of "strong boundaries, vulnerable endpoints." This embodiment substantially moves the security defense forward and extends it to the business software itself. Through two-way authentication based on digital certificates, it achieves strong identity verification of the access subject (business software and its host environment); through software hash value comparison, it ensures the integrity of the business software during startup and operation. This mechanism, which uses "trustworthy identity" and "trustworthy state" as prerequisites for access, combined with the original network layer protection of the gateway, forms a complete trust chain and defense-in-depth system covering "access subject - transmission channel - access object," effectively resisting threats such as man-in-the-middle attacks and software tampering attacks that use legitimate network channels for illegal access, systematically improving the overall security of critical information infrastructure. Example 3

[0038] Exemplary embodiment 3 of the present invention provides a trusted security protection method based on network isolation. Figure 3 This is a schematic diagram illustrating the security protection process of the method according to Exemplary Embodiment 3 of the present invention during the operation of business software, as shown below. Figure 3As shown, once the security authentication process is completed, the business software connects to the gateway and sends business data to the gateway. During this period, the security software and the gateway continue to provide security protection.

[0039] The security protection process during business software operation continues after security authentication is passed and a secure channel is established. The core of this process is the uninterrupted collaborative monitoring and protection between the security software module and the network gateway. At the data transmission level, all business data sent from the business software is intercepted by the security software module and encrypted using the established session key, and a message authentication code is calculated to ensure the confidentiality and integrity of the data before it is sent to the secure channel. Upon receiving the data, the network gateway's external network processing unit first verifies the message authentication code, then decrypts and restores the original data, and securely forwards the data to the internal network via its internal secure transfer mechanism. Simultaneously, the system implements periodic session health checks and lightweight re-authentication. The network gateway can periodically or randomly request the security software module to resubmit the business software's process status information or quick verification credentials to confirm that the software has not undergone any abnormal changes or been subjected to malicious injection during operation. Furthermore, the gateway continuously analyzes access behavior patterns through the secure channel, comparing them with predefined whitelists or normal behavior models. Upon detecting unauthorized access, abnormal frequency, or suspected attack traffic, it immediately initiates appropriate measures, such as issuing real-time alerts, suspending suspicious sessions, or temporarily elevating the application's authentication level. This series of continuous encrypted transmission, status verification, and behavior monitoring activities together constitute a proactive protection loop during the operation of business software, ensuring security throughout its entire lifecycle from startup to shutdown.

[0040] Through periodic lightweight re-authentication, session state monitoring, and continuous encryption and integrity protection of communication data, the system can detect abnormal changes in the business software's operating environment or its own state in real time (such as process injection or file tampering). Once an anomaly is detected, the system can immediately issue an alarm and interrupt the session, realizing a transformation from "static protection" to "dynamic monitoring" and from "passive response" to "proactive blocking," greatly shortening the exposure time of security threats and improving the system's dynamic security defense capabilities. Example 4

[0041] Exemplary embodiment 4 of the present invention provides a trusted security protection method based on network isolation. Figure 4 This is a flowchart illustrating the steps of a trusted security protection method based on network isolation according to an exemplary embodiment 4 of the present invention. Figure 4 As shown, the method of this embodiment is implemented according to the following steps: Step S1: Configure a security software module between the business software deployed on the external network and the network gateway set between the external network and the internal network.

[0042] In this embodiment, the security software module is independently deployed on the external network application where the business software resides, running in parallel with the business software. This security software module acts as a proxy and security intermediary for all communication between the business software and the network gateway, handling security authentication, data encryption, and protection interactions with the gateway, without requiring any modifications to the business software itself. The business software can maintain its original logic and seamlessly integrate into the security protection system through transparent technologies such as network proxies or API hooks. This allows the method of this embodiment to be smoothly integrated into various existing systems, especially those using traditional designs or third-party closed-source business software, greatly reducing the complexity, risk, and cost of system upgrades and modifications.

[0043] Step S2: Before the business software initiates access to the intranet device, the security software module and the network gateway perform two-way security authentication based on digital certificates, and verify the identity and integrity of the business software during the authentication process.

[0044] In this embodiment, the security software module and the gateway perform bidirectional security authentication based on digital certificates in the following manner: Digital certificates issued by trusted authorities are configured for the security software module, the gateway's external network processing unit, and the gateway's internal network processing unit, respectively; during the authentication initialization phase, the security software module and the gateway's external network processing unit exchange and verify each other's digital certificates to verify the legitimacy of their identities. It should be noted that in this embodiment, the gateway's external network processing unit locally maintains a real-time updated certificate revocation list. Each time bidirectional security authentication between the security software module and the gateway is performed, this certificate revocation list is queried to confirm that the other party's certificate has not been revoked.

[0045] In this embodiment, the identity and integrity of the business software are verified during the authentication process as follows: The security software module sends the attribute information related to the application hardware and business software carried in its digital certificate to the network gateway. The network gateway matches and verifies the received attribute information against a pre-stored list of legitimate authorizations. In practical applications, the attribute information related to the application hardware and business software carried in the digital certificate includes at least: the unique hardware serial number of the application motherboard, the version identifier of the business software, and the hash values ​​of the business software file content and installation directory path. The security software module calculates the hash value of the executable file or key components of the business software in real time and sends the hash value to the network gateway. The network gateway compares the received hash value with a pre-stored baseline hash value to confirm that the business software has not been tampered with.

[0046] This embodiment of the method uses digital certificates to bind information such as hardware serial numbers, software versions, software file contents, and installation directory paths, enabling access control granularity to be refined from the "server IP address" level to the "specific software on a specific server" level. Administrators can formulate granular security policies based on the software's identity, version, and integrity status (e.g., only allowing specific versions of unmodified software to access specific devices), which not only improves the accuracy of security management but also provides strong technical support for meeting the high-standard compliance requirements (such as Cybersecurity Classified Protection 2.0 and industry security protection standards) for access control of critical systems in industries such as power, energy, and finance.

[0047] Step S3: Only after the authentication step is successfully completed, establish a trusted secure data transmission channel between the security software module and the gateway.

[0048] In this embodiment, after a trusted secure data transmission channel is established, the business data flows as follows: the business software delivers the business data to be sent to the security software module, which uses a session encryption algorithm and message authentication key negotiated with the gateway to encrypt the business data and encapsulate it with a message authentication code; the encapsulated data is sent to the gateway's external network processing unit through the secure data transmission channel, and after decryption and integrity verification, it is forwarded to the internal network processing unit through the gateway's internal secure transfer mechanism, and finally delivered to the target internal network device.

[0049] It should be noted that in this embodiment, the security software module and the external network processing unit of the gateway use the public keys in each other's digital certificates to negotiate and generate a session encryption algorithm and message authentication key for the secure data transmission channel through a standard key exchange protocol.

[0050] Step S4: During the process of business software interacting with intranet devices through a secure data transmission channel, the security software module and the network gateway work together to perform continuous security protection.

[0051] As an optional example, in this embodiment, during the operation of the business software, the gateway requests the security software module to re-initiate a simplified authentication process at preset time intervals or based on specific security event triggering conditions. The simplified authentication process includes at least verifying the liveness status of the critical processes of the business software and confirming the freshness of the current session key.

[0052] like Figure 5As shown, the present invention also provides a device including a processor 210, a communication interface 220, a memory 230 for storing processor-executable computer programs, and a communication bus 240. The processor 210, communication interface 220, and memory 230 communicate with each other via the communication bus 240. The processor 210 implements the aforementioned trusted security protection method based on network isolation by running the executable computer program.

[0053] The computer program in memory 230, when implemented as a software functional unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0054] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected based on actual needs to achieve the purpose of this embodiment. Those skilled in the art can understand and implement this without any creative effort.

[0055] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of various embodiments or some parts of embodiments.

[0056] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A trusted security protection method based on network isolation, characterized in that, The method includes: Step S1: Configure a security software module between the business software deployed on the external network and the network gateway set up between the external network and the internal network; Step S2: Before the business software initiates access to the intranet device, the security software module and the network gateway perform two-way security authentication based on digital certificates, and verify the identity and integrity of the business software during the authentication process; Step S3: Only after the authentication step is successfully completed, establish a trusted secure data transmission channel between the security software module and the gateway; Step S4: During the process of business software interacting with intranet devices through a secure data transmission channel, the security software module and the network gateway work together to perform continuous security protection.

2. The trusted security protection method based on network isolation according to claim 1, characterized in that, In step S1, the security software module is independently deployed on the external network application terminal where the business software is located, and runs in conjunction with the business software. This security software module acts as a proxy and security intermediary for all communication between the business software and the network gateway, and is responsible for handling security authentication, data encryption and protection interaction with the network gateway, while the business software itself does not need to be modified.

3. The trusted security protection method based on network isolation according to claim 1, characterized in that, In step S2, the security software module and the gateway perform two-way security authentication based on digital certificates in the following manner: Configure digital certificates issued by trusted authorities for the security software module, the external network processing unit of the network gateway, and the internal network processing unit. During the authentication initialization phase, the security software module and the external network processing unit of the gateway exchange and verify each other's digital certificates to verify the legitimacy of each other's identities.

4. The trusted security protection method based on network isolation according to claim 1, characterized in that, In step S2, the external network processing unit of the gateway maintains a real-time updated certificate revocation list locally. Each time the security software module and the gateway perform two-way security authentication, the gateway queries the certificate revocation list to confirm that the other party's certificate has not been revoked.

5. The trusted security protection method based on network isolation according to claim 3, characterized in that, In step S2, the identity and integrity of the business software are verified during the authentication process in the following manner: The security software module sends the attribute information related to the application hardware and business software carried in its digital certificate to the network gateway. The network gateway then matches and verifies the received attribute information against a pre-stored list of legitimate authorizations. The security software module calculates the hash value of the executable file or key components of the business software in real time and sends the hash value to the network gateway. The network gateway compares the received hash value with the pre-stored baseline hash value to confirm that the business software has not been tampered with.

6. The trusted security protection method based on network isolation according to claim 5, characterized in that, The attribute information carried in the digital certificate that is related to the application hardware and business software includes at least: the unique hardware serial number of the application motherboard, the version identifier of the business software, and the hash value of the business software file content and installation directory path.

7. The trusted security protection method based on network isolation according to claim 1, characterized in that, In step S3, after establishing a trusted secure data transmission channel, the business data flows as follows: The business software delivers the business data to be sent to the security software module. The security software module uses a session encryption algorithm and message authentication key negotiated with the network gateway to encrypt the business data and encapsulate it with a message authentication code. The encapsulated data is sent to the external network processing unit of the gateway through a secure data transmission channel. After decryption and integrity verification, it is forwarded to the internal network processing unit through the gateway's internal secure transfer mechanism and finally delivered to the target internal network device.

8. The trusted security protection method based on network isolation according to claim 7, characterized in that, In step S3, the security software module and the external network processing unit of the gateway use the public keys in each other's digital certificates to negotiate and generate a session encryption algorithm and message authentication key for the secure data transmission channel through a standard key exchange protocol.

9. The trusted security protection method based on network isolation according to claim 1, characterized in that, In step S4, the security software module and the gateway work together to perform continuous security protection in the following manner: During the operation of the business software, the gateway requests the security software module to re-initiate a simplified authentication process at preset time intervals or based on specific security event triggering conditions. This simplified authentication process includes at least verifying the liveness of the critical processes of the business software and confirming the freshness of the current session key.

10. A computer device, characterized in that, The computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Boundary access control method based on double one-way separation gatekeepers

    CN103491072A