Method and system for realizing data transmission between networks based on image recognition
By employing an image recognition-based approach, custom pixel encoding, and a high-resolution camera, combined with integrity and security verification, secure, low-cost, and efficient data transmission between physically isolated networks is achieved. This solves the security risks and cost issues in existing technologies and improves the flexibility and reliability of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-04-10
AI Technical Summary
In existing technologies, data transmission between physically isolated networks suffers from high security risks, high cost and complexity, insufficient data transmission flexibility, lack of standardized data verification mechanisms, and high difficulty in implementation and maintenance.
Employing an image recognition-based approach, the system involves external data acquisition, image generation and display, image scanning, data parsing and processing, data verification, and data reception. It utilizes custom pixel encoding and a high-resolution camera to achieve data transmission, combining integrity and security verification, and supports multiple data formats and environmental adaptability.
It enables secure, low-cost, efficient, and highly reliable data transmission between networks, completely blocking malicious code and virus penetration paths, reducing hardware costs and operational complexity, improving data transmission capacity and integrity, and adapting to diverse data needs.
Smart Images

Figure CN121842335A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network data transmission, and particularly relates to a method for realizing data transmission between physically isolated networks based on image recognition. BACKGROUND
[0002] With the rapid development of information technology and the increasing severity of network security threats, secure data transmission between physically isolated networks has become an important research direction in the field of information security. Physical isolation refers to completely disconnecting internal networks from external networks through physical means to prevent malicious attacks and data leakage from external networks. However, in practical applications, necessary data exchange often needs to be carried out between internal and external networks, which puts forward higher requirements for data transmission technology in the physical isolation environment.
[0003] At present, data transmission technology based on image recognition provides an effective solution to the problem of data transmission between physically isolated networks. In the prior art, Chinese patent CN203219430U discloses a data transmission system based on image recognition in the case of network physical isolation, which generates images by encoding data through an internal network image transmission server, displays the images on a display terminal, and then collects and transmits the images to an external network image transmission server for decoding by an image acquisition terminal. Chinese patent CN110401673B provides a network data security transmission method, which realizes data transmission between physically isolated networks by scanning a two-dimensional code display area and adds an identity verification mechanism. Chinese patent CN104580243A discloses an apparatus for realizing data transmission between physically isolated networks based on hexadecimal codes, which converts source data into hexadecimal code character form for display, and collects and analyzes the data through an image acquisition device. Chinese patent CN104038739A describes a method for realizing one-way data transmission in the state of network physical isolation by scanning a two-dimensional code using a video, which realizes data transmission through a two-dimensional code generation module and an analysis module. Chinese patent CN103259781B discloses a data transmission system based on image recognition, which realizes secure and real-time data transmission from an internal network system to an external network system.
[0004] However, the prior art still has the following shortcomings: first, the traditional data transmission method such as copying through U disk, mobile hard disk and other physical media is easy to carry malicious code and virus, break through the internal network isolation boundary, cause data leakage or system paralysis, and has high security risk. Secondly, although the existing physical isolation transmission equipment can realize data transmission, the procurement and use cost is high, and professional personnel is needed for configuration, which limits its popularization in large-scale application. Thirdly, the current data transmission system often only processes specific image types, limiting the flexibility and adaptability of data transmission, and cannot meet the diversified data acquisition and transmission requirements. In addition, the existing technology lacks standardized data verification mechanism, and data loss or tampering may occur during transmission, and it is difficult to trace the data source and transmission record, affecting the integrity and credibility of the data. Finally, the existing data transmission scheme often needs to modify the network structure or add additional hardware devices when realizing data transmission between internal and external networks, increasing the difficulty of implementation and maintenance, and limiting its application in existing network environment. SUMMARY
[0005] In order to solve the technical problems of high security risk, high cost complexity, insufficient data transmission flexibility, lack of standardized data verification mechanism and difficult implementation and maintenance of traditional data transmission method, realize safe, low-cost, efficient and high-reliability inter-network data transmission, and provide a method for realizing inter-network data transmission based on image recognition.
[0006] The technical scheme adopted by the present application to solve its technical problems is to provide a method for realizing inter-network data transmission based on image recognition, applied between physically isolated external network and internal network, including external data acquisition step, image generation and display step, image scanning step, data analysis and processing step, data verification step and data receiving step.
[0007] The external data acquisition step acquires external data through the data acquisition terminal arranged on the external network side, and encrypts the acquired data by using an encryption algorithm.
[0008] The image generation and display step encodes the encrypted data to generate an image, and controls the display device to cyclically display the image.
[0009] The image scanning step scans and captures the image displayed on the display interface of the display device in real time through the image acquisition device fixedly arranged in front of the display interface.
[0010] The data analysis and processing step decodes the scanned and captured image, and decrypts the decoded data to obtain the original acquisition data.
[0011] The data verification step verifies the decrypted original acquisition data.
[0012] The data receiving step receives the valid data that passes the verification on the internal network side and stores it.
[0013] Preferably, the image generation and display step adopts a custom pixel encoding method to map each byte to a pixel, and each pixel supports 256 colors to represent one byte of data, and the image acquisition device adopts a high-resolution camera corresponding to each pixel of the display device to realize complete capture and restoration of full-frame image data.
[0014] Further, when the encrypted data volume exceeds the maximum pixel capacity of a single frame of image, the image generation and display step fragments the encrypted data and generates an image sequence containing multiple fragmented data for cyclic display, and the data analysis and processing step decodes the image sequence and splices the fragmented data.
[0015] Optionally, the data verification step adopts a verification mechanism including integrity verification and security verification, the integrity verification is realized by comparing the hash check code of the decrypted data, and the security verification adopts a behavior analysis model based on convolutional neural network (CNN) to perform behavior analysis and anomaly detection on the decrypted data.
[0016] Preferably, the external data acquisition step further includes data cleaning processing on the collected original data before encryption.
[0017] Further, the external data acquisition step supports data acquisition through at least one of a serial communication interface, an Ethernet interface, and an analog direct sampling interface.
[0018] Optionally, the external network side and the external network, and the internal network side and the internal network, communicate through a secure channel established based on IPSec VPN technology.
[0019] Preferably, the display device is an OLED display screen, and the brightness of the environment where the display device is located is adjusted through an ambient light adjusting device.
[0020] Further, the display state of the display device is detected by a pair of photoelectric sensors in the synchronous control device, and the image acquisition equipment is triggered to perform image acquisition.
[0021] The present application has the advantages of: transmission security and complete isolation; the image recognition technology based on custom pixel encoding realizes physical connection-free data transmission between the external network and the internal isolated network, completely blocks the penetration path of malicious code, viruses or attack links from the external network to the internal network, and guarantees network security from physical and logical double levels.
[0022] Hardware cost and operation simplification: Using general high-resolution cameras and custom coding schemes, instead of specialized industrial scan code cameras and two-dimensional code recognition modules, significantly reduces hardware procurement costs. The system only needs to deploy OLED display devices, general cameras and supporting control devices, without the need for complex network modification or special network gate equipment, greatly reducing deployment and operation complexity.
[0023] Data transmission capacity and efficiency improvement: Using custom pixel encoding, each pixel directly represents a byte of data through 256 colors, achieving a one-to-one correspondence between pixels and bytes, and significantly increasing the data capacity of a single image. Combined with the design of matching camera pixels and OLED display pixels, full-frame lossless capture and fast analysis are achieved, avoiding the limitations of traditional two-dimensional code encoding capacity and low analysis efficiency, especially suitable for large-capacity and high real-time data transmission scenarios.
[0024] Data integrity and transmission reliability: Through the strict correspondence between display pixels and acquisition pixels, combined with the fragmentation processing and sequence display mechanism, the complete transmission of large-capacity data is ensured. The system has built-in integrity verification and security verification based on CNN behavior analysis, effectively preventing data loss, tampering or abnormal injection during transmission.
[0025] System compatibility and scalability: Supports conversion and transmission of structured data such as text, JSON, XML, and unstructured data encoded in Base64. Using standardized OLED display and general image acquisition interfaces, the system does not rely on specific encoding formats (such as two-dimensional codes), and has high flexibility and ease of adaptation to different resolution and data format transmission requirements.
[0026] High device integration and environmental adaptability: The entire system uses OLED as a unified display medium, with advantages such as high contrast, fast response, and low power consumption, suitable for different lighting environments. Through ambient light adjustment and synchronous trigger control, the stability and recognition success rate of image acquisition are further improved, and the system has high overall integration and is suitable for deployment in industrial, office and other scenarios. BRIEF DESCRIPTION OF DRAWINGS
[0027] Figure 1 is the overall system architecture of the present scheme;
[0028] Figure 2 is the security verification mechanism diagram of the present scheme;
[0029] Figure 3 is the method step flowchart of the present scheme. DETAILED DESCRIPTION
[0030] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0031] Example 1
[0032] like Figure 1 As shown, this invention provides a system for data transmission between networks based on image recognition, used to transmit data between physically isolated external and internal networks. The system mainly comprises four core components: an external network data acquisition terminal, an image generation module, an internal network image server, and an internal network data receiving system.
[0033] The external network data acquisition terminal is located on the external network side and is primarily responsible for acquiring and encrypting external data. This terminal includes a motherboard, power supply, communication module, data encryption module, serial communication module, Ethernet communication module, and control port. The communication module uses a Gigabit Ethernet interface to establish a connection with the external network, supporting high-speed data transmission. The data encryption module uses the AES-256 symmetric encryption algorithm to encrypt the acquired raw data, ensuring data security during transmission. The serial communication module connects to external sensors via an RS-485 interface and supports multiple serial communication protocols. The Ethernet communication module achieves network connectivity via an RJ45 interface. The control port provides a USB interface and a touchscreen for easy device configuration and management.
[0034] The external network data acquisition terminal also integrates a data preprocessing unit. This unit performs data cleaning on the raw data before data encryption, including removing invalid data, standardizing the format, and checking data integrity, thereby improving the efficiency and accuracy of subsequent processing.
[0035] This terminal supports multiple data acquisition interface types, including serial communication interface, Ethernet interface, and analog direct acquisition interface. The serial communication interface supports standards such as RS-232 and RS-485, the Ethernet interface supports the TCP / IP protocol stack, and the analog direct acquisition interface supports direct acquisition from current and voltage transformers, adapting to the access requirements of different types of data sources.
[0036] The image generation module is integrated in the external network data collection terminal, and mainly functions to encode and generate images from the encrypted data and control the display. The module includes a data preprocessing unit, an image generation unit, and an image display unit. The image generation unit uses a custom pixel encoding method to map each byte of the encrypted data to a pixel, with each pixel representing a byte of data through 256 colors, to generate image data corresponding to the pixels of the OLED display screen. When the amount of encrypted data exceeds the maximum pixel capacity of a single frame of image, the image generation module automatically performs fragmentation processing on the encrypted data to generate an image sequence containing multiple fragmented data. The image display unit displays the generated images in a loop through the OLED display screen, and records metadata such as data generation time, data identification ID, data type, and fragmentation information, and stores them in a local log file.
[0037] The internal network image server is set on the internal network side and is in a physically isolated state from the external network data collection terminal. The server includes three main functional modules: an image scanning unit, a data analysis processing unit, and a data verification unit.
[0038] The image scanning unit uses a high-resolution camera with a pixel count consistent with that of the external OLED display screen, and is fixedly installed at a proper distance in front of the display interface to ensure complete coverage and clear capture of the display interface. The camera can capture images displayed on the display interface in real time, and the scanning frequency can be automatically adjusted according to the image update frequency.
[0039] The data analysis processing unit uses an embedded computer as the processing core to perform decoding operations on the captured images. According to the custom encoding rules, the unit restores the color value of each pixel to the corresponding byte data, realizing direct mapping from pixels to data. When receiving an image sequence, the unit can automatically identify the fragmentation information, perform image sequence decoding and fragmented data splicing, and reconstruct the complete encrypted data. Subsequently, the same AES-256 key as the encryption end is used to decrypt the decoded data, obtaining the original collected data.
[0040] As shown in Figures 2-3 The data verification unit uses a double verification mechanism, including integrity verification and security verification at two levels. Integrity verification is achieved by comparing the hash check code of the decrypted data, using SHA-3 or BLAKE2b hash algorithm to generate the check code, and confirming the integrity of the data in the transmission process through the check code comparison. The security verification uses a behavior analysis model based on convolutional neural network (CNN) to extract features, analyze behavior patterns, and detect anomalies of the decrypted data, identify potential security threats, and ensure the security of the received data.
[0041] The internal network data receiving system is arranged on the internal network side and communicates with the internal network image server through TCP / IP protocol to receive and store the valid data after verification.
[0042] In a preferred embodiment, the display device adopts an OLED display screen, which has the advantages of high contrast, fast response time and wide viewing angle, and is suitable for long-time continuous display application scenarios.
[0043] The system also includes an ambient light adjusting device for adjusting the brightness of the environment where the display device is located. This device adjusts the brightness output of the lamp to create optimal lighting conditions for image scanning, ensuring that the camera can clearly and accurately capture the display image, improving the success rate and accuracy of image recognition.
[0044] The system also includes a synchronization control device, which includes a photoelectric sensor installed near the display device to detect changes in the display state of the display device. When the display content is updated, the photoelectric sensor triggers the image scanning unit to perform image acquisition, achieving precise synchronization between display and scanning and avoiding data loss during image switching.
[0045] In a preferred embodiment, the external network data acquisition terminal communicates with the external network through a secure channel established based on IPSec VPN technology, uses encryption algorithms certified by the National Cryptography Administration, and combines SM1 / SM2 / SM3 encryption technology to ensure the security and confidentiality of the data transmission link.
[0046] In a preferred embodiment, the internal network image server can also communicate with the internal network through a secure channel established based on IPSec VPN technology, further enhancing the security protection capability of the entire data transmission link.
[0047] The system realizes data transmission between physically isolated networks through image encoding, effectively solving the security risk problems existing in traditional network interconnection methods. The data of the external network undergoes multiple processing steps such as encryption, encoding, display, scanning, decoding and decryption, ensuring the security and reliability of data transmission. At the same time, through the fragmentation processing mechanism and the verification mechanism, the complete transmission of large-capacity data and data quality are guaranteed.
[0048] Embodiment Two
[0049] The application provides a method for realizing data transmission between networks based on image recognition, which is applied between physically isolated external networks and internal networks, and the specific implementation process is as follows:
[0050] External data collection step: collect external data through the data collection terminal arranged on the external network side. The data collection terminal is connected with the external network through a 5G baseband chip, supports 5G network access, and ensures high-speed data transmission. The collection terminal is configured with various data collection interfaces, including a CAN bus for connecting external sensors, and RS-485, Ethernet and current and voltage transformer direct collection interfaces, which adapt to the data collection needs of different types of equipment. The collected external data is encrypted by a data encryption module, and the ChaCha20 encryption algorithm is used to encrypt the collected data. The algorithm has the characteristics of high security and high efficiency, and can effectively protect the security of data in the transmission process.
[0051] Image generation and display step: the encrypted data is encoded to generate an image through an image generation module. The image generation module is integrated in the external network data collection terminal, including a data preprocessing unit, an image generation unit and an image display unit. The data preprocessing unit performs data cleaning and encryption processing on the collected data to ensure data quality and security. The image generation unit adopts a custom pixel encoding method, maps each encrypted byte to a pixel, represents a byte through 256 colors, and generates image data corresponding to the pixels of the OLED display screen. When the data volume exceeds the capacity of a single frame of image, automatic fragmentation processing is performed. The image display unit controls the OLED display screen to cyclically display the generated image, records metadata such as data generation time, data identification ID, data type and fragmentation information, and stores them in the local log, which is convenient for subsequent data tracking and management.
[0052] Image scanning step: the image displayed on the display interface is captured in real time by an image acquisition device fixedly arranged in front of the display device display interface. The image acquisition device adopts a high-resolution camera with the same number of pixels as the external OLED display screen, and is fixedly installed at a proper distance in front of the external terminal display interface to ensure the best image acquisition effect. The system is configured with an adjusting lamp to adjust the brightness of the collection environment, and a pair of photoelectric sensors are arranged to realize synchronous control of image acquisition and display, avoiding timing errors in the collection process.
[0053] Data analysis and processing step: decode and process the captured image. The data analysis processing unit uses a high-performance GPU accelerated server to provide powerful image processing capabilities, which can quickly and accurately restore each pixel color value to corresponding byte data according to custom encoding rules. After decoding, the decrypted data is obtained by using ChaCha20 key decryption. The decryption process uses the corresponding key and algorithm as the encryption process to ensure the integrity and accuracy of the data.
[0054] Data verification step: verify the decrypted original collection data. The data verification unit uses a double verification mechanism, including integrity verification and security verification. Integrity verification is performed by comparing SHA-512 and BLAKE2b checksums. These two verification algorithms have high security and low collision rate characteristics, which can effectively detect whether the data has been damaged or tampered with during transmission. Security verification uses a convolutional neural network (CNN) based behavior analysis model to learn features and identify abnormal patterns in decrypted data, identify potential security threats and abnormal data, and improve the system's security protection capabilities.
[0055] Data receiving step: receive valid data that passes the verification on the internal network side. The internal network data receiving system connects to the internal network image server and receives the parsed valid data through the MQTT protocol. MQTT protocol has the characteristics of lightweight, low power consumption and high reliability, which is suitable for data transmission in Internet of Things environment. After receiving the valid data, the data receiving module performs data import and log recording. The data storage module uses PolarDB distributed database to store data, which has high performance, high availability and strong consistency, supports data retrieval and query by time and data identifier, and meets the needs of large-scale data storage and fast query.
[0056] The entire system also has a secure access area, including reverse physical isolation device, main station encryption device and data acquisition server. The main station encryption device is connected to the internal network security area link and is provided with an NGFW firewall to provide network level security protection. The data acquisition server has a built-in protocol module that supports Modbus TCP, OPC-UA and other communication protocols to receive and store different types of data, improving system compatibility and applicability. The system uses the SM9 password algorithm to establish a public network security channel, combined with SM2 encryption technology, to ensure the security and confidentiality of data transmission.
[0057] Through the organic combination of the above steps, secure data transmission between physically isolated networks is achieved, which not only ensures the physical isolation characteristics of the network, but also realizes effective data transmission, providing a safe and reliable solution for data exchange of critical information infrastructure.
[0058] Finally, it should be noted that the above only describes the preferred embodiments of the present application and is not intended to limit the present application. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art will appreciate that the technical solutions described in the foregoing embodiments can be modified or some technical features thereof can be replaced by equivalent features, and any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A device for realizing inter-network data transmission based on image recognition, applied between physically isolated external and internal networks, characterized in that, include: The data acquisition and encryption module is configured on the external network side to collect external data and encrypt the collected data. The image generation and display control module is used to encode the encrypted data to generate an image and control the display device to display the image in a loop. The image scanning module is used to capture images displayed on the display device in real time using a fixed image acquisition device; The data parsing and processing module, configured on the internal network side, is used to decode the scanned and captured images and decrypt the decoded data to obtain the original acquired data. The data verification module is used to verify the decrypted original collected data; The data receiving and storage module is used to receive and store valid data that has passed verification on the internal network side.
2. The apparatus according to claim 1, characterized in that, The image generation and display control module is specifically used to encode the encrypted data into an image using a custom pixel encoding method, wherein each encrypted data byte is mapped to one pixel of the image; the pixels of the image acquisition device used by the image scanning module correspond to the display pixels of the display device; and... The image generation and display control module is also used to: when the amount of encrypted data exceeds the maximum data capacity of a single frame image, to process the encrypted data into segments and generate an image sequence containing multiple segments for cyclic display; the data parsing and processing module is also used to decode the image sequence and stitch the segmented data together.
3. A system for data transmission between networks based on image recognition, used to transmit data between physically isolated external and internal networks, characterized in that, include: The data acquisition terminal, set up on the external network side, is used to collect external data and encrypt the collected data; The image generation module is used to encode encrypted data to generate images. A display device is used to cyclically display the images generated by the image generation module; An image acquisition device is fixedly installed in front of the display interface of the display device, and is used to scan and capture images displayed by the display device in real time. Image servers configured on the internal network side include: The data parsing and processing unit is used to decode the images captured by the image acquisition device and decrypt the decoded data to obtain the original acquisition data. A data verification unit is used to verify the original collected data; The data receiving system, located on the internal network side, is used to receive and store valid data that has passed the verification by the data verification unit.
4. The system according to claim 3, characterized in that, The image generation module uses a custom pixel encoding method to map each encrypted data byte to a pixel of the image displayed by the display device; the number of pixels in the image acquisition device is consistent with the number of display pixels in the display device.
5. The system according to claim 4, characterized in that, The image generation module is also used to segment the encrypted data when the amount of encrypted data exceeds the maximum data capacity of a single frame image, and generate an image sequence containing multiple segments of data, which is then displayed cyclically by the display device; the data parsing and processing unit is also used to decode the image sequence and splice the segmented data.
6. The system according to any one of claims 3 to 5, characterized in that, The data verification unit includes an integrity verification module and a security verification module; the integrity verification module performs integrity verification by comparing the hash checksum of the decrypted data; the security verification module uses a behavior analysis model based on a convolutional neural network (CNN) for security verification.
7. A method for data transmission between networks based on image recognition, applied between physically isolated external and internal networks, characterized in that, Includes the following steps: External data acquisition steps: Collect external data through a data acquisition terminal set up on the external network side, and encrypt the collected data; Image generation and display steps: Encode the encrypted data to generate an image, and control the display device to display the image in a loop; Image scanning step: The image displayed on the display interface is captured in real time by an image acquisition device that is fixedly installed in front of the display interface of the display device; Data parsing and processing steps: Decode the scanned and captured images, and decrypt the decoded data to obtain the original acquired data; Data verification steps: Verify the decrypted original collected data; Data receiving steps: Receive and store valid data that has passed verification on the internal network side.
8. The method according to claim 7, characterized in that, In the image generation and display step, a custom pixel encoding method is used to encode the encrypted data to generate an image. Each encrypted data byte is mapped to a pixel of the image, and the color of each pixel is used to represent a byte of data. The pixels of the image acquisition device correspond to the display pixels of the display device.
9. The method according to claim 8, characterized in that, When the amount of encrypted data exceeds the maximum data capacity of a single frame image, the image generation and display steps include: segmenting the encrypted data and generating an image sequence containing multiple segments for cyclic display; the data parsing and processing steps include: decoding the image sequence and splicing the segmented data.
10. The method according to any one of claims 7 to 9, characterized in that, The data verification steps include integrity verification and security verification; the integrity verification is achieved by comparing the hash checksum of the decrypted data; the security verification uses a behavior analysis model based on a convolutional neural network (CNN) to perform behavior analysis and anomaly detection on the decrypted data.
Citation Information
Patent Citations
Data Transmission System Based on Image Recognition
CN103259781B
Method and device for utilizing video scanning two-dimensional code to achieve unidirectional data transmission under network physical isolation state
CN104038739A
Device and method for implementing data transmission between physical isolation networks based on hexadecimal codes
CN104580243A
Methods and devices for secure data transmission between networks
CN110401673B
Data transmission system based on image recognition and under circumstance of network physical isolation
CN203219430U