Cross-network one-way data security exchange method and system
By stripping protocol headers between networks, encapsulating them into a preset format, and transmitting them using a one-way physically isolated link, the security and protocol compatibility issues of data transmission between networks are solved, achieving security and protocol compatibility for cross-network data exchange.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING AEROSPACE CONTROL CENT
- Filing Date
- 2025-12-24
- Publication Date
- 2026-05-01
AI Technical Summary
Existing technologies for data transmission between networks suffer from limitations such as incomplete physical isolation in traditional bidirectional transmission and the inability of unidirectional optical transmission to support the TCP protocol, leading to network risks of external attacks and limited transmission range.
By receiving and stripping network protocol headers, application data is encapsulated into a preset format, transmitted using a one-way physically isolated link, and security compliance checks and protocol reconstruction are performed at the receiving end, supporting cross-network one-way data exchange of TCP and UDP protocols.
It achieves security and protocol compatibility in cross-network data exchange, solves the problems of incomplete physical isolation and limited TCP protocol support in traditional technologies, and enhances network security and transmission range.
Smart Images

Figure CN121966940A_ABST
Abstract
Description
A method and system for secure one-way data exchange across networks Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method and system for secure cross-network one-way data exchange. Background Technology
[0002] Currently, to address the information transmission needs between networks with different security levels, natures, and management requirements, firewall technology is typically used to control data flow, antivirus probes, honeypots, and intrusion detection technologies are used to monitor abnormal network behavior, encryption devices are deployed to achieve encrypted information transmission, and proxy devices are set up between security domains to reassemble and encapsulate data packets, or one-way security isolation devices are used to achieve one-way information transmission.
[0003] However, existing technologies have the following shortcomings: On the one hand, in daily use, traditional security technologies (or products) mostly transmit data bidirectionally and fail to achieve complete physical isolation, which means that the network still faces the risk of external attacks; on the other hand, although existing unidirectional optical transmission technology has achieved physical isolation, its unidirectional transmission characteristics cannot support data transmission based on the TCP protocol, and there are obvious limitations in the range of information transmission.
[0004] Therefore, there is an urgent need to provide a technical solution to address the above problems. Summary of the Invention
[0005] To address the aforementioned technical problems, this invention provides a method and system for secure one-way data exchange across networks.
[0006] In a first aspect, the present invention provides a cross-network one-way secure data exchange method. The technical solution of the method is as follows: receiving a first data packet from a first network, the first data packet adopting a first network communication protocol; stripping the protocol of the first data packet by removing the protocol header of the first network communication protocol to obtain first application data, and encapsulating the first application data into a preset internal exchange format to generate a first exchange data unit; sending the first exchange data unit to a receiving point of a second network through a one-way physically isolated link; at the receiving point of the second network, performing security compliance verification on the first exchange data unit, and parsing the format of the first exchange data unit that passes the verification to extract the first application data; according to the communication protocol requirements of the second network, re-encapsulating the first application data into a second data packet adopting the second network communication protocol, and sending the second data packet to a target node within the second network.
[0007] The beneficial effects of the cross-network one-way secure data exchange method of the present invention are as follows: The method of the present invention receives and strips the first network protocol header, encapsulates the application data in a preset format, and transmits it through a one-way physically isolated link. It performs security compliance verification and protocol reconstruction in the second network, which solves the limitations of incomplete physical isolation in traditional bidirectional transmission and the inability of one-way optical transmission to support the TCP protocol, thereby improving the security and protocol compatibility of cross-network data exchange.
[0008] Based on the above scheme, the cross-network one-way secure data exchange method of the present invention can be further improved as follows.
[0009] In one alternative approach, the first network communication protocol and the second network communication protocol are either TCP or UDP.
[0010] The advantages of adopting the above optional methods are: further support for the two mainstream transport layer protocols, TCP and UDP, expanding the scope of application, enabling more types of application data to be exchanged securely in one direction across the network, and overcoming the limitation that traditional one-way optical transmission cannot support the TCP protocol.
[0011] In one alternative approach, the unidirectional physical isolation link is a physical channel established using unidirectional optical transmission technology.
[0012] The advantages of adopting the above-mentioned optional methods are: further utilizing unidirectional optical transmission technology to establish a physical channel, achieving true physical isolation between the transmitter and receiver, eliminating the possibility of reverse data flow at the physical level, and improving the security of cross-network data exchange.
[0013] In one alternative approach, the security compliance verification process includes: checking the protocol format compliance of the first exchanged data unit and identifying the characteristics of abnormal data packets.
[0014] The advantages of adopting the above-mentioned optional methods are: further checking the protocol format compliance of the exchanged data units and identifying the characteristics of abnormal data packets, filtering out non-compliant data and potentially threatening data, and enhancing the security protection capabilities during the data exchange process.
[0015] Secondly, the present invention provides a cross-network one-way secure data exchange method. The technical solution of the method is as follows: receiving a third data packet from a second network, the third data packet adopting the second network communication protocol; stripping the protocol of the third data packet by removing the protocol header of the second network communication protocol to obtain second application data, and encapsulating the second application data into a preset internal exchange format to generate a second exchange data unit; sending the second exchange data unit to a receiving point of a first network through a one-way physically isolated link; at the receiving point of the first network, performing security compliance verification on the second exchange data unit, and parsing the format of the second exchange data unit that passes the verification to extract the second application data; according to the communication protocol requirements of the first network, re-encapsulating the second application data into a fourth data packet adopting the first network communication protocol, and sending the fourth data packet to a target node within the first network.
[0016] The beneficial effects of the cross-network one-way secure data exchange method of the present invention are as follows: The method of the present invention receives a second network data packet through a one-way physically isolated link, and after protocol stripping and format conversion and security compliance verification at the first network receiving point, it is re-encapsulated into a first network protocol data packet. This solves the problem of external attack risk caused by the failure of traditional bidirectional transmission to achieve complete physical isolation, realizes cross-network secure data exchange, and breaks through the application limitation of one-way optical transmission technology that cannot support the TCP protocol.
[0017] Based on the above scheme, the cross-network one-way secure data exchange method of the present invention can be further improved as follows.
[0018] In one alternative approach, the first network communication protocol and the second network communication protocol are either TCP or UDP.
[0019] The advantages of adopting the above optional method are: further supporting the two mainstream transport layer protocols, TCP and UDP, in reverse transmission, expanding the scope of application of reverse transmission, and enabling more types of application data to be exchanged securely in one direction across networks from the second network to the first network.
[0020] In one alternative approach, the unidirectional physical isolation link is a physical channel established using unidirectional optical transmission technology.
[0021] The advantages of adopting the above-mentioned optional methods are: further establishing a physical channel by using unidirectional optical transmission technology in reverse transmission, realizing true physical isolation between the transmitter and receiver, eliminating the possibility of reverse data flow at the physical level, and ensuring the security of reverse data exchange.
[0022] In one alternative approach, the security compliance verification process includes: checking the protocol format compliance of the second exchanged data unit and identifying the characteristics of abnormal data packets.
[0023] The advantages of adopting the above-mentioned optional methods are: further performing protocol format compliance checks and abnormal data packet feature identification on the exchanged data units in the reverse transmission, filtering out non-compliant data and potentially threatening data, and enhancing the security protection capabilities of reverse data exchange.
[0024] Thirdly, the present invention provides a cross-network one-way secure data exchange system. The technical solution of the system is as follows: a first receiving module, used to receive a first data packet from a first network, the first data packet adopting a first network communication protocol; a first generating module, used to strip the protocol of the first data packet, remove the protocol header of the first network communication protocol to obtain first application data, and encapsulate the first application data into a preset internal exchange format to generate a first exchange data unit; a first sending module, used to send the first exchange data unit to a receiving point of a second network through a one-way physically isolated link; a first parsing module, used to perform security compliance verification on the first exchange data unit at the receiving point of the second network, and to perform format parsing on the first exchange data unit that passes the verification to extract the first application data; a first encapsulation module, used to re-encapsulate the first application data into a second data packet adopting the second network communication protocol according to the communication protocol requirements of the second network, and send the second data packet to a target node in the second network.
[0025] The beneficial effects of the cross-network one-way data security exchange system of the present invention are as follows: The system of the present invention receives and strips the first network protocol header, encapsulates the application data in a preset format, and transmits it through a one-way physically isolated link. It performs security compliance verification and protocol reconstruction in the second network, which solves the limitations of incomplete physical isolation in traditional bidirectional transmission and the inability of one-way optical transmission to support the TCP protocol, thereby improving the security and protocol compatibility of cross-network data exchange.
[0026] Fourthly, this invention provides a cross-network one-way secure data exchange system. The technical solution of this system is as follows: a second receiving module, used to receive a third data packet from a second network, wherein the third data packet adopts the second network communication protocol; a second generating module, used to strip the protocol of the third data packet, remove the protocol header of the second network communication protocol to obtain second application data, and encapsulate the second application data into a preset internal exchange format to generate a second exchange data unit; a second sending module, used to send the second exchange data unit to a receiving point of a first network through a one-way physically isolated link; a second parsing module, used to perform security compliance verification on the second exchange data unit at the receiving point of the first network, and to perform format parsing on the second exchange data unit that passes the verification to extract the second application data; a second encapsulation module, used to re-encapsulate the second application data into a fourth data packet adopting the first network communication protocol according to the communication protocol requirements of the first network, and send the fourth data packet to a target node in the first network.
[0027] The beneficial effects of the cross-network one-way data security exchange system of the present invention are as follows: The system of the present invention receives the second network data packet through a one-way physically isolated link, and after protocol stripping and format conversion and security compliance verification at the first network receiving point, it is re-encapsulated into the first network protocol data packet. This solves the problem of external attack risk caused by the failure of traditional bidirectional transmission to achieve complete physical isolation, realizes cross-network data security exchange, and breaks through the application limitation of one-way optical transmission technology that cannot support the TCP protocol.
[0028] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0029] The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of the invention. Throughout the drawings, the same reference numerals denote the same components. In the drawings: Figure 1 is a flowchart illustrating a first embodiment of a cross-network one-way secure data exchange method according to the present invention; Figure 2 is a flowchart illustrating a second embodiment of a cross-network one-way secure data exchange method according to the present invention; Figure 3 is a schematic diagram illustrating the principle of the cross-network one-way secure data exchange method; Figure 4 is a structural schematic diagram illustrating a first embodiment of a cross-network one-way secure data exchange system according to the present invention; Figure 5 is a structural schematic diagram illustrating a second embodiment of a cross-network one-way secure data exchange system according to the present invention. Detailed Implementation
[0030] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein.
[0031] Figure 1 shows a flowchart of a first embodiment of a cross-network one-way secure data exchange method provided by the present invention. This cross-network one-way secure data exchange method can be executed by electronic devices such as terminal devices or servers. The terminal device can be any fixed or mobile terminal such as user equipment (UE), mobile device, user terminal, terminal, cellular phone, cordless phone, personal digital assistant (PDA), handheld device, computing device, vehicle-mounted device, or wearable device. The server can be a single server or a server cluster composed of multiple servers. Any electronic device can implement the cross-network one-way secure data exchange method by having its processor call computer-readable instructions stored in its memory. As shown in Figure 1, the method includes the following steps: S110, receiving a first data packet from a first network, wherein the first data packet adopts a first network communication protocol.
[0032] The first network refers to one of the networks that needs to exchange data securely, typically with a high security level or specific management requirements; for example, an organization's internal security network. The first data packet refers to a data unit encapsulated according to a specific network communication protocol, originating from the first network and intended for transmission to another network; for example, a web page request data packet encapsulated in Transmission Control Protocol (TCP) format sent by a terminal in an internal security network attempting to access external resources. The first network communication protocol refers to the network communication rules and formats followed in the first network for encapsulating and transmitting the first data packet; for example, the Transmission Control Protocol (TCP).
[0033] S120. The first data packet is stripped of its protocol header to obtain the first application data, and the first application data is encapsulated into a preset internal exchange format to generate a first exchange data unit.
[0034] Protocol stripping refers to the process of removing the network protocol encapsulation header information from a data packet to extract the actual application data it carries. For example, removing the Internet Protocol header and Transmission Control Protocol (TCP) header from a Transmission Control Protocol (TCP) data packet yields the Hypertext Transfer Protocol (HTTP) request content. The protocol header refers to the format and control information appended to the application data in a network communication protocol, used to control the data transmission format. Examples include the source port number, destination port number, sequence number, and acknowledgment number in a TCP data packet. The first application data refers to the actual data content obtained after protocol stripping from the first data packet, excluding the underlying network protocol encapsulation information. For example, the HTTP request string "GET / page HTTP / 1.1" obtained after stripping the protocol header from a TCP data packet. The internal exchange format refers to a predefined, dedicated data encapsulation format for securely transmitting application data over a unidirectional physically isolated link. For example, a dedicated binary encapsulation format that adds checksum and sequence number fields to the data block header for transmitting data between isolated devices. The first exchange data unit refers to a data unit formed by encapsulating the first application data according to the internal exchange format and preparing to transmit it through a one-way physically isolated link; for example, a data block formed by packaging the string "GET / pageHTTP / 1.1" according to a dedicated binary encapsulation format.
[0035] S130. The first exchange data unit is sent to the receiving point of the second network through a one-way physical isolation link.
[0036] A unidirectional physically isolated link refers to a communication link that allows data to flow only from one end to the other, and ensures that reverse transmission is physically impossible through physical means; for example, a signal channel composed of a unidirectional optical fiber with a light-emitting device at the transmitting end and only a photosensitive receiver at the receiving end. The second network refers to another network that securely exchanges data with the first network, typically with a different security level or management domain; for example, an external network connected to an organization's internal security network that has access to the public internet. The receiving point refers to the logical or physical location on the target network side responsible for receiving the exchanged data units transmitted through the unidirectional physically isolated link and performing subsequent secure processing; for example, a security device deployed at the external network boundary, connected to a unidirectional optical fiber to receive optical signals and perform photoelectric conversion.
[0037] S140. At the receiving point of the second network, the first exchange data unit is subjected to security compliance verification, and the format of the first exchange data unit that passes the verification is parsed to extract the first application data.
[0038] Security compliance verification refers to the process of checking received exchanged data units to determine whether they conform to predetermined security policies and data format specifications; for example, checking whether the dedicated binary encapsulation format of the data unit is correct and scanning its content for characteristic patterns of known malicious code. Format parsing refers to the process of processing exchanged data units that have passed security compliance verification and extracting the original application data from their internal exchange format; for example, removing the header and checksum of the dedicated binary encapsulation format data block to restore the string "GET / page HTTP / 1.1".
[0039] S150. According to the communication protocol requirements of the second network, the first application data is repackaged into a second data packet using the second network communication protocol, and the second data packet is sent to the target node in the second network.
[0040] The communication protocol requirements refer to the network communication protocol specifications that the target network must follow when receiving and sending data; for example, external networks generally require the use of Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) for communication. The second network communication protocol refers to the network communication rules and formats followed in the second network for encapsulating and transmitting data; for example, UDP. The second data packet refers to a data unit that can be transmitted normally in the second network after application data has been re-encapsulated according to the requirements of the second network communication protocol; for example, encapsulating the string "GET / page HTTP / 1.1" into a UDP data packet and filling in the source and destination Internet Protocol addresses and port numbers required by the external network. The target node refers to the terminal device or server to which the data packet ultimately needs to be delivered in the target network; for example, a web server on the external network with the example Internet Protocol address.
[0041] The technical solution of this embodiment receives and strips the first network protocol header, encapsulates the application data in a preset format, and transmits it through a one-way physically isolated link. It then performs security compliance verification and protocol reconstruction in the second network, which solves the limitations of incomplete physical isolation in traditional bidirectional transmission and the inability of one-way optical transmission to support the TCP protocol, thereby improving the security and protocol compatibility of cross-network data exchange.
[0042] In one alternative approach, the first network communication protocol and the second network communication protocol are either TCP or UDP.
[0043] TCP refers to a connection-oriented, reliable, byte-stream-based transport layer communication protocol; for example, it's used to ensure the integrity and reliable transmission of data in applications such as web browsing and email. UDP refers to a connectionless, best-effort delivery transport layer communication protocol; for example, it's used in scenarios such as Domain Name System (DNS) queries and real-time video streaming.
[0044] Among the above optional methods, the two mainstream transport layer protocols, TCP and UDP, are further supported, expanding the scope of application and enabling more types of application data to be exchanged securely in one direction across the network, overcoming the limitation that traditional one-way optical transmission cannot support the TCP protocol.
[0045] In one alternative approach, the unidirectional physical isolation link is a physical channel established using unidirectional optical transmission technology.
[0046] Unidirectional optical transmission technology refers to the technology of transmitting data in one direction using the unidirectional propagation property of light. For example, an electrical signal is converted into an optical signal by a light-emitting device and emitted, which is received and converted back into an electrical signal by a photosensitive receiver at the other end, while there is no light-emitting device in the reverse direction. A physical channel refers to a pathway made of physical media used for transmitting signals or data; for example, the optical fiber used to connect the light-emitting device and the photosensitive receiver.
[0047] Among the above-mentioned optional methods, unidirectional optical transmission technology is further used to establish a physical channel, achieving true physical isolation between the transmitter and receiver, eliminating the possibility of reverse data flow at the physical level, and improving the security of cross-network data exchange.
[0048] In one alternative approach, the security compliance verification process includes: checking the protocol format compliance of the first exchanged data unit and identifying the characteristics of abnormal data packets.
[0049] Protocol format compliance refers to the consistency between the structure, field length, and encoding method of exchanged data units and the predetermined internal exchange format specifications; for example, checking whether the length of the received data block is within the predetermined range and whether the specific identification field in the data block header is correct. Abnormal packet characteristics refer to specific patterns, code sequences, or structures in the data packet that may indicate a security threat; for example, excessively long strings contained in the data content, known specific attack code fragments, or machine code sequences that match the characteristics of buffer overflow attacks.
[0050] Among the above optional methods, further protocol format compliance checks and abnormal data packet feature identification are performed on the exchanged data units to filter out non-compliant data and potentially threatening data, thereby enhancing the security protection capabilities during the data exchange process.
[0051] Figure 2 shows a flowchart of a second embodiment of a cross-network one-way secure data exchange method provided by the present invention. This cross-network one-way secure data exchange method can be executed by electronic devices such as terminal devices or servers. The terminal device can be any fixed or mobile terminal such as user equipment (UE), mobile device, user terminal, terminal, cellular phone, cordless phone, personal digital assistant (PDA), handheld device, computing device, vehicle-mounted device, or wearable device. The server can be a single server or a server cluster composed of multiple servers. Any electronic device can implement the cross-network one-way secure data exchange method by having its processor call computer-readable instructions stored in its memory. As shown in Figure 2, the method includes the following steps: S210, receiving a third data packet from a second network, wherein the third data packet uses the second network communication protocol.
[0052] The third data packet refers to a data unit encapsulated according to a specific network communication protocol that is sent from the second network and needs to be transmitted to the first network; for example, the response of an external web server to a request from the internal network is encapsulated as a data packet in the Transmission Control Protocol format.
[0053] S220. The third data packet is stripped of its protocol header to obtain the second application data, and the second application data is encapsulated into a preset internal exchange format to generate a second exchange data unit.
[0054] The second application data refers to the actual data content that needs to be transmitted to the first network, obtained after protocol stripping from the third data packet; for example, the "HTTP / 1.1 200 OK" status code and Hypertext Markup Language (HTML) webpage content obtained after stripping the protocol header from the Transmission Control Protocol (TCP) response packet. The second exchange data unit refers to a data unit formed by encapsulating the second application data according to an internal exchange format, ready to be sent to the first network via a unidirectional physically isolated link; for example, a data block formed by packaging the Hypertext Transfer Protocol (HTTP) response content according to a dedicated binary encapsulation format.
[0055] S230. The second exchange data unit is sent to the receiving point of the first network through a one-way physical isolation link.
[0056] S240. At the receiving point of the first network, the second exchange data unit is subjected to security compliance verification, and the format of the second exchange data unit that passes the verification is parsed to extract the second application data.
[0057] S250. According to the communication protocol requirements of the first network, the second application data is repackaged into a fourth data packet using the first network communication protocol, and the fourth data packet is sent to the target node in the first network.
[0058] The fourth data packet refers to a data unit that can be transmitted normally in the first network after the second application data is repackaged according to the requirements of the first network communication protocol; for example, the content of a hypertext markup language webpage is repackaged into a transmission control protocol data packet, and the destination address is the internal network terminal that originally issued the request.
[0059] The technical solution of this embodiment receives the second network data packet through a one-way physically isolated link. After protocol stripping and format conversion, and security compliance verification at the first network receiving point, it is re-encapsulated into the first network protocol data packet. This solves the problem of external attack risk caused by the failure of traditional bidirectional transmission to achieve complete physical isolation, realizes cross-network data security exchange, and breaks through the application limitation of one-way optical transmission technology in not supporting the TCP protocol.
[0060] In one alternative approach, the first network communication protocol and the second network communication protocol are either TCP or UDP.
[0061] Among the above optional methods, the two mainstream transport layer protocols, TCP and UDP, are further supported in reverse transmission, expanding the scope of application of reverse transmission and enabling more types of application data to be exchanged securely in one direction across networks from the second network to the first network.
[0062] In one alternative approach, the unidirectional physical isolation link is a physical channel established using unidirectional optical transmission technology.
[0063] Among the above-mentioned optional methods, a physical channel can be further established by using unidirectional optical transmission technology in the reverse transmission to achieve true physical isolation between the transmitter and receiver, physically eliminating the possibility of reverse data flow and ensuring the security of reverse data exchange.
[0064] In one alternative approach, the security compliance verification process includes: checking the protocol format compliance of the second exchanged data unit and identifying the characteristics of abnormal data packets.
[0065] In the above-mentioned optional methods, further protocol format compliance checks and abnormal data packet feature identification are performed on the exchanged data units during reverse transmission to filter out non-compliant data and potentially threatening data, thereby enhancing the security protection capabilities of reverse data exchange.
[0066] It should be noted that Figure 3 illustrates the specific principle of the cross-network one-way secure data exchange method. The processing flow of data streams between different security domains is as follows: TCP / IP data streams are intercepted, filtered and discarded according to the TCP / IP protocol format, restored to upper-layer application data, and then encapsulated into a specific protocol for secure processing. Finally, secure exchange of application data between the internal and external networks is achieved through data transfer.
[0067] ① For unidirectional data services based on the UDP protocol, the process includes two directions: 1) In the inward-outward direction, data packets are sent from the internal network to Node 1 in the form of IP data packets through Channel 1. Node 1 performs protocol stripping on the data packets, removing the IP and UDP protocol headers to obtain the application data, and encapsulates the application data into a preset internal exchange format to generate exchange data units. Node 1 sends the exchange data units to Node 2 through Channel 2. Channel 2 constitutes a unidirectional physically isolated link. At Node 2, the received exchange data units undergo security compliance verification, including checking the protocol format compliance of the exchange data units and identifying abnormal data packet characteristics. Node 2 internally sends the verified data outward in a unidirectional transmission form, sending it to Node 3 through Channel 3. Channel 3 also constitutes a unidirectional physically isolated link. Node 3 parses the received data, extracts the application data from the internal exchange format, and re-encapsulates the application data into the original data packet format using UDP and IP protocols according to the communication protocol requirements of the external network, finally sending it to the external network through Channel 4.
[0068] 2) In the outward-to-inward direction, data packets are sent from the external network to node 4 via channel 5 in IP packet format. At node 4, the data packets are stripped of their protocols, removing the IP and UDP headers to obtain the application data. This application data is then encapsulated into a preset internal exchange format, generating exchange data units. Node 4 sends these exchange data units to node 5 via channel 6. Channel 6 forms a unidirectional physically isolated link. At node 5, the received exchange data units undergo security compliance verification. Node 5 internally transmits the verified data outward via channel 7 to node 6 in a unidirectional manner. Channel 7 also forms a unidirectional physically isolated link. Node 6 parses the received data, extracts the application data from the internal exchange format, and re-encapsulates the application data into the original data packet format using UDP and IP protocols according to the communication protocol requirements of the internal network. Finally, it sends the data to the internal network via channel 8.
[0069] ② For bidirectional data services based on the TCP protocol, assume the business scenario is that a terminal on an external network accesses a server on an internal network, and the process includes two stages: request and response.
[0070] 1) In the request phase, the data packet is sent from the external network and enters Node 8 via channel 13. Node 8 performs protocol stripping on the data packet, removing the TCP and IP protocol headers to obtain the application data. It then re-encapsulates the application data into UDP and IP protocol data packets and sends it to Node 4 via channel 4. Node 4 performs protocol stripping on the data packet again, removing the UDP and IP protocol headers to obtain the application data. It then encapsulates the application data into a preset internal exchange format, generating exchange data units. Node 4 sends the exchange data units to Node 5 via channel 6. After security compliance verification at Node 5, Node 5 internally transmits the verified data outwards in a unidirectional manner via channel 7 to Node 6. Node 6 parses the received data, extracts the application data from the internal exchange format, and re-encapsulates the application data into UDP and IP protocol data packet formats, sending it to Node 7 via channel 9. Node 7 performs protocol stripping on the UDP packet, removing the UDP and IP protocol headers to obtain the application data. Based on the communication protocol requirements of the internal network, it re-encapsulates the application data into a packet using TCP and IP protocols, and finally sends it to the internal network server.
[0071] 2) In the response phase, after receiving the request data packet, the internal network server sends a response data packet to Node 7 via channel 9. Node 7 performs protocol stripping on the data packet, removing the TCP and IP protocol headers to obtain the application data. It then repackages the application data into UDP and IP protocol data packets and sends it to Node 1 via channel 10. Node 1 performs protocol stripping on the data packet, removing the UDP and IP protocol headers to obtain the application data. It then repackages the application data into a preset internal exchange format, generating exchange data units. Node 1 sends the exchange data units to Node 2 via channel 2. After security compliance verification at Node 2, Node 2 internally transmits the verified data outwards in a unidirectional manner via channel 3 to Node 3. Node 3 parses the received data, extracts the application data from the internal exchange format, and repackages the application data into UDP and IP protocol data packet formats, sending it to Node 8 via channel 11. Node 8 performs protocol stripping on the UDP packet, removing the UDP and IP protocol headers to obtain the application data. Based on the communication protocol requirements of the external network, it re-encapsulates the application data into a packet using TCP and IP protocols, and finally sends it to the external network server to establish a connection and forward subsequent data packets.
[0072] Figure 4 shows a schematic diagram of a first embodiment of a cross-network one-way data security exchange system 300 provided by the present invention. As shown in Figure 4, the cross-network one-way data security exchange system 300 includes: a first receiving module 301, used to receive a first data packet from a first network, the first data packet adopting a first network communication protocol; a first generating module 302, used to strip the protocol of the first data packet, remove the protocol header of the first network communication protocol to obtain first application data, and encapsulate the first application data into a preset internal exchange format to generate a first exchange data unit; a first sending module 303, used to send the first exchange data unit to a receiving point of a second network through a one-way physically isolated link; a first parsing module 304, used to perform security compliance verification on the first exchange data unit at the receiving point of the second network, and to perform format parsing on the first exchange data unit that passes the verification to extract the first application data; and a first encapsulation module 305, used to re-encapsulate the first application data into a second data packet adopting the second network communication protocol according to the communication protocol requirements of the second network, and send the second data packet to a target node in the second network.
[0073] It should be noted that the beneficial effects of the cross-network one-way data security exchange system 300 provided in the above embodiments are the same as the beneficial effects of the cross-network one-way data security exchange method described above, and will not be repeated here.
[0074] Figure 5 shows a schematic diagram of a second embodiment of a cross-network one-way data security exchange system 400 provided by the present invention. As shown in Figure 5, the cross-network one-way data security exchange system 400 includes: a second receiving module 401, used to receive a third data packet from a second network, wherein the third data packet adopts a second network communication protocol; a second generating module 402, used to strip the protocol of the third data packet, remove the protocol header of the second network communication protocol to obtain second application data, and encapsulate the second application data into a preset internal exchange format to generate a second exchange data unit; a second sending module 403, used to send the second exchange data unit to a receiving point of a first network through a one-way physically isolated link; a second parsing module 404, used to perform security compliance verification on the second exchange data unit at the receiving point of the first network, and to perform format parsing on the second exchange data unit that passes the verification to extract the second application data; and a second encapsulation module 405, used to re-encapsulate the second application data into a fourth data packet adopting the first network communication protocol according to the communication protocol requirements of the first network, and send the fourth data packet to a target node in the first network.
[0075] It should be noted that the beneficial effects of the cross-network one-way data security exchange system 400 provided in the above embodiments are the same as the beneficial effects of the cross-network one-way data security exchange method described above, and will not be repeated here.
[0076] Furthermore, the system provided in the above embodiments is only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the system can be divided into different functional modules according to the actual situation to complete all or part of the functions described above. In addition, the system and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.
[0077] The cross-network one-way data security exchange system of the present invention can be a computer program (including program code) running on a computer device. For example, the cross-network one-way data security exchange system of the present invention is an application software that can be used to execute the corresponding steps in the cross-network one-way data security exchange method of the present invention.
[0078] In some embodiments, the cross-network one-way data security exchange system of the present invention can be implemented in a combination of hardware and software. As an example, the cross-network one-way data security exchange system of the present invention can be a processor in the form of a hardware decoding processor, which is programmed to execute the cross-network one-way data security exchange method of the present invention. For example, the processor in the form of a hardware decoding processor can be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0079] The modules described in the embodiments of this invention can be implemented in software or hardware. The names of the modules are not, in some cases, limiting the scope of the module itself.
[0080] The above description is merely a preferred embodiment of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this invention is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this invention.
[0081] It should be noted that the terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and represent a limitation on a specific order or sequence. Where appropriate, the order of use for similar objects can be interchanged so that the embodiments of this application described herein can be implemented in an order other than that shown or described.
[0082] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for secure one-way data exchange across networks, characterized in that, include: Receive a first data packet from a first network, wherein the first data packet uses the first network communication protocol; The first data packet is stripped of its protocol header to obtain the first application data, and the first application data is encapsulated into a preset internal exchange format to generate a first exchange data unit. The first exchange data unit is sent to the receiving point of the second network via a one-way physically isolated link; At the receiving point of the second network, the first exchange data unit is subjected to security compliance verification, and the format of the first exchange data unit that passes the verification is parsed to extract the first application data. According to the communication protocol requirements of the second network, the first application data is repackaged into a second data packet using the second network communication protocol, and the second data packet is sent to the target node in the second network.
2. The cross-network one-way secure data exchange method according to claim 1, characterized in that, The first network communication protocol and the second network communication protocol are either TCP or UDP.
3. The cross-network one-way secure data exchange method according to claim 1, characterized in that, The unidirectional physical isolation link is a physical channel established using unidirectional optical transmission technology.
4. The cross-network one-way secure data exchange method according to claim 1, characterized in that, The security compliance verification process includes: checking the protocol format compliance of the first exchanged data unit and identifying the characteristics of abnormal data packets.
5. A method for secure one-way data exchange across networks, characterized in that, include: Receive a third data packet from a second network, wherein the third data packet uses the second network communication protocol; The third data packet is stripped of its protocol header to obtain the second application data. The second application data is then encapsulated into a preset internal exchange format to generate a second exchange data unit. The second exchange data unit is then sent to the receiving point of the first network via a unidirectional physical isolation link. At the receiving point of the first network, the second exchange data unit is subjected to security compliance verification. The second exchange data unit that passes the verification is then parsed to extract the second application data. According to the communication protocol requirements of the first network, the second application data is repackaged into a fourth data packet using the first network communication protocol, and the fourth data packet is sent to the target node in the first network.
6. The cross-network one-way secure data exchange method according to claim 5, characterized in that, The first network communication protocol and the second network communication protocol are either TCP or UDP.
7. The cross-network one-way secure data exchange method according to claim 5, characterized in that, The unidirectional physical isolation link is a physical channel established using unidirectional optical transmission technology.
8. The cross-network one-way secure data exchange method according to claim 5, characterized in that, The security compliance verification process includes: checking the protocol format compliance of the second exchange data unit and identifying the characteristics of abnormal data packets.
9. A cross-network one-way secure data exchange system, characterized in that, include: A first receiving module is configured to receive a first data packet from a first network, wherein the first data packet adopts the first network communication protocol; The first generation module is used to strip the protocol of the first data packet, remove the protocol header of the first network communication protocol, obtain the first application data, and encapsulate the first application data into a preset internal exchange format to generate a first exchange data unit. The first sending module is used to send the first exchange data unit to the receiving point of the second network through a one-way physically isolated link; The first parsing module is used to perform security compliance verification on the first exchange data unit at the receiving point of the second network, and to perform format parsing on the first exchange data unit that passes the verification to extract the first application data. The first encapsulation module is used to re-encapsulate the first application data into a second data packet using the second network communication protocol according to the communication protocol requirements of the second network, and send the second data packet to the target node in the second network.
10. A cross-network one-way secure data exchange system, characterized in that, include: The second receiving module is used to receive a third data packet from the second network, wherein the third data packet adopts the communication protocol of the second network; The second generation module is used to strip the protocol of the third data packet, remove the protocol header of the second network communication protocol, obtain the second application data, and encapsulate the second application data into a preset internal exchange format to generate a second exchange data unit. The second sending module is used to send the second exchange data unit to the receiving point of the first network through a one-way physically isolated link; The second parsing module is used to perform security compliance verification on the second exchange data unit at the receiving point of the first network, and to perform format parsing on the second exchange data unit that passes the verification to extract the second application data. The second encapsulation module is used to re-encapsulate the second application data into a fourth data packet using the first network communication protocol according to the communication protocol requirements of the first network, and send the fourth data packet to the target node in the first network.
Citation Information
Patent Citations
Device for safely isolating and exchanging industrial control networks
CN104486336A
Network data security exchange method and system
CN107172020A
Unidirectional isolation GAP and data transmission method
CN108234506A
System and method for cross-network and cross-domain transmission based on physical isolation
CN117978447A