Cross-network data transmission method and system
By employing a cross-network data transmission method that combines process approval, national cryptographic algorithm authentication and encrypted transmission, fragmented parallel transmission, and multi-level verification, the security, efficiency, and compliance issues between multiple network regions are resolved, achieving secure, controllable, efficient, and reliable data transmission and detailed auditing throughout the entire process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- IND BANK CO
- Filing Date
- 2026-03-19
- Publication Date
- 2026-05-08
AI Technical Summary
In critical industries and enterprises, data transmission between multiple isolated network areas or those with different security levels presents security risks, low transmission efficiency, and difficulties in ensuring compliance. Existing technologies lack comprehensive solutions.
By implementing process approval, establishing a two-way authentication and encrypted transmission channel based on national cryptographic algorithms, fragmented parallel transmission, and multi-level integrity verification, combined with centralized audit log recording, a closed-loop solution for cross-network data transmission is formed.
It enables secure, controllable, efficient, and reliable data transmission across network boundaries, meets compliance audit requirements, prevents data leakage and tampering, improves transmission efficiency and reliability, adapts to complex network environments, and provides comprehensive audit support.
Smart Images

Figure CN122001671A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of network security and data communication technology, and more particularly to a cross-network data transmission method and system. Background Technology
[0002] Within key industries and enterprises, multiple isolated network zones with varying security levels (such as office networks and production networks, intranets and private networks) typically exist. Data transmission between these networks faces multiple challenges: First, the data transmission process requires strict security control to prevent sensitive information leakage, virus propagation, and other security risks. Traditional methods rely on manual approval and media copying, which are inefficient and have audit blind spots. Second, network boundaries are usually equipped with firewalls, limiting direct connectivity, and ensuring the trustworthiness of the transmission channel and communication encryption is crucial. Third, large file or massive data transmissions demand high timeliness and reliability. Traditional single-threaded transmission methods are inefficient and lack effective integrity verification mechanisms, making it difficult to guarantee that data has not been tampered with or damaged during transmission. Finally, the entire transmission process needs to meet compliance requirements, achieving full auditability from approval and transmission to completion. Existing technical solutions often only improve at a single level (such as encryption or fragmentation), lacking a comprehensive solution that deeply integrates approval processes, high-strength national cryptographic security systems, efficient transmission mechanisms, and complete audit trails. Summary of the Invention
[0003] The purpose of this application is to overcome the shortcomings of existing technologies and provide a cross-network data transmission method and system, aiming to achieve secure, controllable, efficient, and reliable file transmission across network boundaries throughout the entire process, while meeting stringent compliance audit requirements. Specifically, the objectives are: to ensure the security of transmitted content through pre-process approval and security testing; to establish a trusted channel through two-way authentication and encryption based on national cryptographic algorithms; to improve transmission efficiency and data integrity assurance capabilities through fragmentation parallelism and multi-level verification mechanisms; and to achieve full traceability through centralized audit log recording.
[0004] To achieve the above objectives, this application provides a cross-network data transmission method, comprising: performing security detection and analysis on files uploaded to the source data site based on the approval result of a user-submitted cross-network file transfer request, and obtaining a securely processed file; establishing an encrypted transmission channel between the source and target ends based on a pre-configured transmission strategy and security authentication requirements, through two-way identity authentication based on a national cryptographic digital certificate and online certificate status query; performing fragmented parallel transmission of file data according to the encrypted transmission channel, and performing fragment-level and file-level integrity verification before and after the file data transmission based on the national cryptographic SM3 algorithm; and recording an audit log containing user, approval, transmission, and verification information on the management site based on the transmission completion result.
[0005] In the above cross-network data transmission method, optionally, establishing an encrypted transmission channel between the source and the target includes: querying the OCSP service of the management station to obtain the certificate validity verification result when communication is initiated, based on the national cryptographic digital certificate issued by the management station for each node; performing two-way identity authentication based on the verification result and the certificate two-way exchange mechanism to establish an encrypted communication link.
[0006] In the above cross-network data transmission method, optionally, performing fragmented parallel transmission of file data according to the encrypted transmission channel includes: dividing the file data into multiple fragments according to the transmission strategy; and transmitting the multiple fragments through a parallel pipeline mechanism.
[0007] In the above cross-network data transmission method, optionally, performing fragment-level and file-level integrity verification based on the national cryptographic SM3 algorithm before and after the file data transmission includes: after at least one fragment transmission is completed, generating the hash value of the corresponding fragment based on the national cryptographic SM3 algorithm and verifying it; after all the file data is transmitted, generating the hash value of the entire file based on the national cryptographic SM3 algorithm and verifying it.
[0008] In the above cross-network data transmission method, optionally, performing fragmented parallel transmission of file data according to the encrypted transmission channel further includes: when the source end and the target end network cannot be directly connected, forwarding data through a relay station; wherein, the relay station establishes encrypted links with the source end and the target end respectively through two-way identity authentication based on national cryptographic digital certificates, and transparently forwards the file data between the encrypted links.
[0009] Optionally, in the above cross-network data transmission method, the method further includes: managing the site to review and issue site certificates to nodes that obtain controlled access based on the site registration request; and triggering a certificate renewal process a preset period before the site certificate expires based on the certificate validity period monitoring results.
[0010] This application also provides a cross-network data transmission system applicable to the aforementioned cross-network data transmission method, comprising: a management station for receiving and processing cross-network file transmission requests to complete process approval, and issuing and managing national cryptographic digital certificates for each node in the system; multiple data stations deployed in different network areas for performing security detection and analysis on approved files, and establishing an encrypted transmission channel with the target end based on the national cryptographic digital certificate to perform file fragment transmission and integrity verification; and relay stations for establishing encrypted links and transparently forwarding data when the source and target networks cannot be directly connected.
[0011] In the above system, optionally, the management site further includes: a policy control module for configuring transmission policies, which control the target, bandwidth and concurrency of file transmission; and a certificate authority module for issuing certificates, maintaining a certificate trust list and providing OCSP status query services to support the two-way authentication.
[0012] In the above system, optionally, the data station further includes: a security service interface module, used to call virus scanning, data leakage prevention detection and encryption services to perform secure processing of files; and a transmission engine module, used to perform file fragmentation, parallel transmission, breakpoint resumption and integrity verification based on the national cryptographic SM3 algorithm.
[0013] In the above system, optionally, the cross-network data transmission system adopts an architecture that combines centralized management and control with distributed services, wherein the management site is centrally deployed and the multiple data sites are distributed and deployed in the network areas of each branch office.
[0014] This application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described method.
[0015] This application also provides a computer-readable storage medium storing a computer program that performs the above-described methods.
[0016] This application also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the above-described method.
[0017] The beneficial technical effects of this application are as follows: By organically integrating multiple stages such as process approval, security detection, two-way identity authentication and online status verification (OCSP) based on national cryptographic digital certificates (SM certificates), establishment of encrypted transmission channels, parallel transmission of file fragments, and dual integrity verification at the fragment and file levels based on the national cryptographic SM3 algorithm, as well as centralized audit log recording, a complete closed-loop solution for cross-network data transmission is formed. Specifically, 1) Comprehensive security assurance: A defense-in-depth system is built from three dimensions: pre-process approval (process approval, file security detection), during the process (two-way identity authentication and encrypted transmission based on national cryptographic algorithms), and post-process (integrity verification, audit logs), which significantly improves the security, reliability, and compliance of cross-network data transmission and effectively prevents risks such as unauthorized access, data leakage, and content tampering. 2) Highly efficient and reliable transmission: By adopting fragmented parallel transmission and pipeline mechanisms, network bandwidth is fully utilized, greatly improving the transmission efficiency of large files or batch data; combined with the ability to resume transmission after interruption and the two-level SM3 hash verification mechanism at the fragment and file levels, the reliability of the data transmission process and the integrity and consistency of the results are ensured. 3) Flexible Adaptability: By introducing a relay site mechanism, the transmission problem when the source and target networks cannot be directly connected is solved, enhancing the system's deployment flexibility in complex network topology environments; the architecture combining centralized management and distributed services facilitates unified policy management and efficient distributed execution. 4) Complete Auditability: The management site centrally records audit logs covering all elements such as users, approvals, transmissions, and verifications, providing detailed data support for security incident tracing, compliance checks, and operational analysis. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, do not constitute a limitation thereof. In the drawings: Figure 1 This is a schematic flowchart illustrating a cross-network data transmission method provided in an embodiment of this application; Figure 2 A schematic diagram illustrating the process of establishing an encrypted transmission channel according to an embodiment of this application; Figure 3 This is a schematic diagram of the process of fragmented parallel transmission provided in an embodiment of this application; Figure 4 This is a flowchart illustrating a multi-level integrity verification process provided in an embodiment of this application. Figure 5 This is a schematic diagram of the relay forwarding transmission process provided in an embodiment of this application; Figure 6 This is a schematic diagram of the structure of a cross-network data transmission system provided in an embodiment of this application; Figure 7 This is a schematic diagram of the structure of a data station provided in an embodiment of this application; Figure 8 This is a schematic diagram of the system architecture provided in an embodiment of this application; Figure 9 This is a schematic diagram of a site registration process provided in an embodiment of this application; Figure 10 This is a schematic diagram of a transmission certificate issuance process provided in an embodiment of this application; Figure 11 This is a schematic diagram of a data transmission process within a network domain provided in an embodiment of this application; Figure 12 This is a schematic diagram of an inter-domain data transmission process provided in an embodiment of this application; Figure 13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0019] The following will describe in detail the implementation methods of this application with reference to the accompanying drawings and embodiments, so as to fully understand how this application uses technical means to solve technical problems and achieve technical effects, and to implement it accordingly. It should be noted that, as long as there is no conflict, the various embodiments and features in each embodiment of this application can be combined with each other, and the resulting technical solutions are all within the protection scope of this application.
[0020] Furthermore, the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0021] It should be noted that in the description of this application, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The term "national cryptographic algorithm" refers to commercial cryptographic algorithm systems approved and recognized by the national cryptographic management department, including but not limited to SM2 (elliptic curve public key cryptography), SM3 (hash algorithm), and SM4 (block cipher algorithm). The term "digital certificate" in this context primarily refers to a digital credential issued based on the national cryptographic algorithm system to identify the identity of a network entity; it can also be called a "site certificate" or "SM certificate." The term "fragment" has the same meaning as "data block" and "data segment," all referring to a transmission unit formed by dividing a complete file.
[0022] In one embodiment of this application, a cross-network data transmission method is provided, the method comprising: Based on the approval results of the user's cross-network file transfer request process, the files uploaded to the source data site are subjected to security detection and analysis to obtain the files after security processing; Based on the pre-configured transmission strategy and security authentication requirements, an encrypted transmission channel is established between the source and target ends through two-way identity authentication based on national cryptographic digital certificates and online certificate status query. The file data is fragmented and transmitted in parallel according to the encrypted transmission channel, and fragment-level and file-level integrity checks are performed before and after the file data is transmitted based on the national cryptographic SM3 algorithm; Based on the transmission completion result, an audit log containing user, approval, transmission and verification information is recorded on the management site.
[0023] Specifically, the cross-network data transmission method provided in this application mainly includes the following steps: integrating process approval, content security, transmission security, and audit traceability, to achieve full lifecycle management of file exchange across network boundaries (such as different security domains or different branch network networks). Figure 1 As shown, the method mainly includes the following steps: S110: Security detection and processing based on approval results.
[0024] A user initiates a cross-network file transfer request through a client (such as a web portal). This request includes information such as the file to be transferred, the specified target network area, and the business reason. The request is submitted to a centrally deployed management site (or control center). The management site processes the request according to a pre-defined electronic workflow related to the target network security level. For example, a request to transfer to the core production network may require approval from both the technical lead and the security officer. The workflow approval result (approval or rejection) is generated and recorded by the management site. The workflow only continues if the approval result is "approved."
[0025] Subsequently, the user actually transmits the file to be transferred to the source data station (also known as the edge transmission node) in their network area. The source data station does not directly store the file but immediately initiates security detection and analysis. This analysis process is completed through the data station's security service interface module, calling integrated third-party security capabilities, typically including: Malicious code detection: calling an antivirus engine to perform a deep scan of the file. Content compliance check: performing Data Loss Prevention (DLP) policy matching to detect whether the file contains sensitive information such as ID numbers or trade secrets. Optional, format conversion and encryption: according to the policy, the file is formatted or pre-encrypted using the national cryptographic algorithm SM4.
[0026] Only files that pass all security checks are marked as secure and allowed to enter the subsequent transmission queue. Files that fail will be quarantined, triggering an alert to notify the approver and security administrator.
[0027] S120: Establishment of a secure channel based on national cryptographic certificates.
[0028] Before transmitting file content, a high-security communication channel must be established between the source and destination data stations. This step is performed based on the management station's pre-configured transmission policies (such as a list of allowed peers) and mandatory security authentication requirements.
[0029] Specifically, the channel establishment relies on the national cryptographic digital certificate system. The management site, acting as a private certificate authority (CA), issues unique SM2 format digital certificates to each data station and relay station in the system. When establishing a channel: Online Certificate Status Verification: When the source server attempts to connect to the target server, it first queries the OCSP (Online Certificate Status Protocol) service on the management site to verify whether the target server's certificate is currently valid or has been revoked. This ensures dynamic, real-time authentication, rather than relying solely on the certificate's expiration date. The target server also queries the source server's certificate status. The certificate validity verification result obtained in this step forms the basis for subsequent authentication.
[0030] Two-way authentication and key negotiation: After both parties' certificates are verified as valid, they perform two-way authentication by exchanging certificates. Each party verifies the signature of the other party's certificate using a pre-configured public key of the management site's root certificate, confirming that the other party is a legitimate, controlled node within the system. After successful authentication, both parties negotiate and generate a symmetric session key (e.g., for the SM4 algorithm) using the SM2 algorithm's key exchange protocol, which is used only in this session.
[0031] Encrypted transmission channel established: Using the aforementioned session key, an encrypted communication link is established between the source and destination. This link is transparent to upper-layer applications; all application data transmitted through it will be automatically encrypted and protected for integrity, thus forming a secure encrypted transmission channel.
[0032] S130: Fragmented parallel transmission and multi-level integrity verification.
[0033] For large file transfers, this application employs an efficient and reliable fragmentation parallel mechanism.
[0034] Fragmented Parallel Transmission: The transmission engine divides the securely processed file into multiple fragments according to a strategy (such as fixed fragment size or dynamic adjustment). Subsequently, transmission is performed through a parallel pipeline mechanism. That is, multiple fragments are sent simultaneously through the encrypted transmission channel (parallel), and the transmission, reception, verification, and storage of a single fragment can overlap (pipeline), greatly improving bandwidth utilization and overall transmission efficiency. This mechanism inherently supports resuming interrupted transmissions; the transmission status of each fragment is recorded independently, and after an interruption is resumed, only the unfinished fragments can be retransmitted.
[0035] Integrity verification: To ensure that the data is absolutely error-free during and after transmission, a dual verification based on the national cryptographic SM3 algorithm is adopted.
[0036] Fragment-level verification: This is performed immediately after at least one fragment has been transmitted. The source calculates the SM3 hash of the fragment before sending it and sends it along with the encrypted data. The destination calculates the SM3 hash of the received data and compares it. If they do not match, a retransmission of that specific fragment is requested. This verification ensures the correctness of each data block in real time during transmission.
[0037] File-level verification is performed after all file data has been transmitted. The target end reassembles all successfully received fragments in sequence and calculates the SM3 hash value of the entire reconstructed file. Simultaneously, it obtains the SM3 hash value of the original complete file calculated by the source end before transmission (this can be sent with the transmission metadata or obtained separately). The two are then compared. Only if the file-level verification also passes is the transmission confirmed as successful. This ensures the overall consistency of the file from end to end.
[0038] S140: Full-process audit log recording.
[0039] Regardless of whether the transmission succeeds or fails, the management site will generate a structured audit log based on the transmission completion result. This log centrally records all the key elements of this transmission activity, including at least: User Information: The identity of the request initiator. Approval Information: Approval process ID, approver, approval result and time. Transmission Information: Source and destination site identifiers, filename, size, transmission start and end times, and actual transmission rate. Verification Information: Fragment-level verification statistics (e.g., pass rate) and the final SM3 hash value at the file level.
[0040] These logs are stored in a security database at the management site for post-incident tracing, compliance review, and operational analysis.
[0041] In one embodiment of this application, establishing an encrypted transmission channel between the source and the target includes: Based on the national cryptographic digital certificates issued by the management site for each node, the system queries the OCSP service of the management site to obtain the certificate validity verification result when communication is initiated. Based on the verification results and the two-way certificate exchange mechanism, two-way identity authentication is performed to establish an encrypted communication link.
[0042] Specifically, such as Figure 2 As shown, establishing an encrypted transmission channel between the source data station and the target data station includes the following sub-steps: S121: Initiate connection and certificate status query.
[0043] When a source data site needs to transfer files to a target data site, it first initiates a connection request. Before or during the formal cryptographic handshake (such as a variant of TLS based on Chinese cryptographic algorithms), the source site, acting as an OCSP client, constructs a query request containing the target certificate's serial number and sends it to the OCSP service interface provided by the management site. The management site's OCSP service queries its maintained certificate status database and returns a response message signed by the management site's CA private key. This message explicitly indicates whether the target certificate is currently in a "normal," "revoked," or "unknown" state. This query result is the certificate validity verification result.
[0044] S122: Authentication and key exchange based on verification results.
[0045] Upon receiving the OCSP response, the source verifies its signature and confirms that the target's certificate status is "normal." Only after successful verification will the source proceed with the cryptographic handshake. During the handshake phase, both parties exchange their respective national cryptographic digital certificates (a two-way certificate exchange mechanism). Each party uses a pre-configured public key of the management site's root certificate to verify the signature chain of the peer's certificate, ensuring that the certificate was issued by a trusted CA and has not been tampered with. This process achieves strict two-way authentication.
[0046] S123: Establishment of encrypted communication link.
[0047] After successful two-way authentication, the communicating parties negotiate a common session master key using the SM2 key exchange algorithm without transmitting the key itself. Based on this master key, keys for subsequent data encryption (such as using the SM4 algorithm) and message authentication are derived. Thus, an encrypted communication link with confidentiality, integrity, and authentication capabilities is successfully established at the transport or application layer, providing pipeline security for file data transmission.
[0048] In one embodiment of this application, performing fragmented parallel transmission of file data according to the encrypted transmission channel includes: The file data is divided into multiple fragments according to the transmission strategy; The multiple fragments are transmitted via a parallel pipeline mechanism.
[0049] Specifically, such as Figure 3 As shown, the file data is fragmented and transmitted in parallel according to the encrypted transmission channel, specifically including: S131: Strategic file fragmentation.
[0050] The transmission engine reads the transmission policy issued by the management site or configured locally. This policy includes fragmentation rules, such as: "For files larger than 10MB, fragment them into 1MB chunks; for files smaller than 10MB, treat them as a single chunk." Based on these rules, the transmission engine logically divides the file data to be transmitted into multiple chunks. Each chunk is assigned a unique index number for sequential reassembly.
[0051] S132: Parallel pipelined transmission.
[0052] The transmission engine employs a parallel pipeline mechanism to schedule the transmission of these multiple fragments. It maintains a configurable-size transmission task queue (window). The engine retrieves multiple fragment tasks from the queue and simultaneously initiates transmission (parallel) to the target end through the established encrypted transmission channel. Meanwhile, for fragments that have already been sent, the engine asynchronously processes the reception acknowledgment or verification result returned by the target end; and for fragments whose reception has been successfully confirmed, their occupied network transmission "slots" are released to start the transmission of the next fragment to be transmitted. In this way, the fragment "sending," "in-transit acknowledgment," and "subsequent task preparation" stages form an overlapping pipeline, thereby continuously maintaining a high utilization rate of network bandwidth and significantly improving the transmission efficiency of large files or batch files.
[0053] In one embodiment of this application, performing fragment-level and file-level integrity checks before and after file data transmission based on the national cryptographic SM3 algorithm includes: After at least one fragment is transmitted, the hash value of the corresponding fragment is generated based on the national cryptographic SM3 algorithm and verified. After all the file data has been transmitted, the hash value of the entire file is generated based on the national cryptographic SM3 algorithm and then verified.
[0054] Specifically, such as Figure 4 As shown, based on the national cryptographic SM3 algorithm, fragment-level and file-level integrity checks are performed before and after file data transmission, specifically including: S133: Fragment-level hash generation and verification.
[0055] This verification occurs during or after the transmission of each fragment. At the source end, when preparing to send a fragment, the transmission engine calls the SM3 national cryptographic algorithm library to generate a hash value (also known as a hash or digest) for the corresponding fragment based on its binary data. This hash value, as the "digital fingerprint" of the fragment, is appended to the fragment data packet (protected within the encrypted channel) and sent to the destination end.
[0056] At the destination, upon successfully receiving a data fragment, the transmission engine immediately generates a hash value for the received raw data using the same SM3 algorithm. It then compares the calculated hash value with the hash value received from the source. If they are identical, the verification passes, and the fragment is marked as valid; otherwise, the verification fails, and the destination sends a retransmission request for that specific fragment to the source.
[0057] S134: File-level hash generation and verification.
[0058] This verification occurs after all fragment transmissions are complete and fragment-level verifications have passed. At the destination, the transmission engine, following the fragment index order, concatenates all verified fragment data in memory or temporary storage to reconstruct a complete file. Subsequently, it generates the overall file's SM3 hash value from the reconstructed file data.
[0059] Meanwhile, the source end calculates the SM3 hash value of the original complete file before the transmission begins. This value can be sent to the target end via a separate metadata channel, or the target end can actively request it from the source end during file-level verification.
[0060] Finally, the target end compares its calculated overall file hash value with the original file hash value obtained from the source end. If they match, it proves that no errors occurred during the file transmission and the data is complete; otherwise, the file transmission is considered a failure.
[0061] In one embodiment of this application, performing fragmented parallel transmission of file data according to the encrypted transmission channel further includes: When the source and destination networks are not directly connected, data is forwarded through relay stations; The relay station establishes encrypted links with both the source and target ends through two-way identity authentication based on national cryptographic digital certificates, and transparently forwards file data between the encrypted links.
[0062] Specifically, such as Figure 5 As shown, in some network architectures, due to firewall policies, network isolation, and other reasons, the networks where the source data station and the target data station reside cannot be directly connected. To solve this problem, this application introduces a relay station.
[0063] The specific process is as follows: First, the source data station and the relay station establish a first encrypted link (link 1) through the two-way identity authentication process based on national cryptographic digital certificates described in the aforementioned embodiments. Similarly, a second encrypted link (link 2) is also independently established between the relay station and the target data station.
[0064] During file data transfer, the source sends encrypted file fragments to a relay station. The core function of the relay station is transparent data forwarding; that is, it does not decrypt the application-layer data content, but only acts as a network-layer relay proxy, forwarding the received encrypted data stream to the target end as is. The target end ultimately receives and decrypts the data from a second encrypted link. In this way, the relay station is only responsible for connectivity and cannot eavesdrop on the actual content being transmitted, achieving transmission across strict network boundaries while ensuring security.
[0065] In one embodiment of this application, the method further includes: Based on the site registration request, the management site reviews and issues site certificates to nodes that obtain controlled access; Based on the certificate validity monitoring results, the certificate renewal process is triggered one preset period before the site certificate expires.
[0066] Specifically, to ensure the continued trustworthiness of the identities of all nodes in the system, this application also includes a site certificate registration and update process: Controlled Access and Certificate Issuance: When a new network area needs to access the system, its corresponding data station or relay station will initiate a site registration request to the management station. The administrator of the management station reviews the request to confirm its identity and access permissions. After approval, the management station's Certificate Authority (CA) module issues a unique site certificate (i.e., a national cryptographic digital certificate) for the site. Only nodes that obtain a valid certificate can become controlled access nodes within the system and participate in subsequent authentication and transmission.
[0067] Automatic Certificate Renewal: The CA module of the management site continuously monitors the validity period of all issued certificates. When it detects that a site's certificate is about to expire (for example, within a preset period before expiration, such as 30 days), the system automatically triggers the certificate renewal process. This process includes automatically generating a new certificate and securely distributing it to the corresponding site. The site completes the renewal before the old certificate expires, thus ensuring that service is not interrupted due to certificate expiration and maintaining the continuous and secure operation of the system.
[0068] This application also provides a cross-network data transmission system applicable to the aforementioned cross-network data transmission method, comprising: The management site is used to receive and process cross-network file transfer requests to complete the process approval, and to issue and manage national cryptographic digital certificates for each node in the system; Multiple data stations, deployed in different network areas, are used to perform security testing and analysis on approved documents, and establish encrypted transmission channels with the target end based on the national cryptographic digital certificate to perform file fragment transmission and integrity verification; Relay stations are used to establish encrypted links and transparently forward data when the source and destination networks are not directly connected.
[0069] In the above embodiments, the management site further includes: a policy control module for configuring transmission policies, wherein the transmission policies are used to control the target, bandwidth and concurrency of file transmission; and a certificate authority module for issuing certificates, maintaining a certificate trust list and providing OCSP status query services to support the two-way authentication.
[0070] Specifically, such as Figure 6 As shown, the system adopts an architecture that combines centralized management and distributed services, specifically including: Management Site: As the core control and audit node of the system, it is typically deployed centrally in a trusted management area. Its main responsibilities include: Receive and process cross-network file transfer requests submitted by users through a web portal or API, and drive and complete multi-level electronic workflow approvals.
[0071] As the trust anchor of the system, it issues and manages national cryptographic digital certificates for all other nodes in the system.
[0072] Furthermore, the management site includes: a policy control module for centralized configuration and management of transmission policies. These policies specify detailed control parameters for file transfers, such as: allowed or prohibited target networks (target control), maximum network bandwidth available to each task or user (bandwidth control), and the number of concurrent transmission tasks allowed (concurrency control). A Certificate Authority (CA) module, acting as a private certificate authority, is responsible for issuing certificates, maintaining a trust list (whitelist) of all valid certificates, managing the Certificate Revocation List (CRL), and providing crucial OCSP status query services, offering real-time status support for two-way authentication between nodes.
[0073] Multiple data sites: These sites are distributed across branch network areas or different security domains and are the direct executors of file transfers. Each data site logically includes: a security service interface module: This module provides standardized interfaces for flexibly invoking third-party security services, such as virus scanning engines, data leakage prevention systems for data leakage detection, and national cryptographic algorithm libraries for file encryption, thereby achieving comprehensive security processing of uploaded files. A transmission engine module: This is the core transmission component of the data site, responsible for specifically executing file fragmentation, parallel transmission through multiple threads or connections, supporting breakpoint resumption after transmission interruption, and integrity verification calculation and comparison based on the national cryptographic SM3 algorithm.
[0074] Relay site: As an optional special node, it is used to build a bridge between the source and destination in scenarios with limited network connectivity. Its function is to establish independent encrypted links with both the source and destination when the networks at both ends cannot be directly connected, and to transparently forward the encrypted file data stream between the two links without performing business logic parsing itself.
[0075] In another embodiment of this application, the data station further includes: The security service interface module is used to call virus scanning, data leakage prevention detection and encryption services to perform secure processing on files; The transmission engine module is used to perform file fragmentation, parallel transmission, breakpoint resumption, and integrity verification based on the national cryptographic SM3 algorithm.
[0076] Specifically, such as Figure 7 As shown, a typical data station mainly includes two functional modules: Security Service Interface Module: This module serves as a bridge connecting the data site with the external security ecosystem. Through well-defined APIs, it integrates various security capabilities: It calls the scanning interface of external antivirus engines to scan files for viruses and detect known malicious code; it calls the detection interface of DLP (Data Loss Prevention) systems to perform data leakage prevention detection based on content recognition policies, preventing the unauthorized dissemination of sensitive information; and it calls cryptographic services compliant with national cryptographic standards to provide additional encryption services (such as SM4 encryption) for highly sensitive files, providing an extra layer of data protection even within established encrypted channels.
[0077] This module is responsible for scheduling these services, summarizing and analyzing the results, and ultimately deciding whether a file can be transferred.
[0078] Transmission Engine Module: This module is the "engine" of data transmission, responsible for efficiently and reliably completing file movement. Its core functions include: File Splitting: Splitting large files into smaller units more suitable for network transmission according to a strategy. Parallel Transmission: Managing multiple transmission threads or connections to send multiple fragments simultaneously, maximizing bandwidth utilization. Resume Transmission: Persistently recording the transmission progress of each fragment, supporting continuation of transmission from the last interruption rather than restarting. Integrity Verification Based on the Chinese National Cryptographic Algorithm SM3: Calculating and comparing the SM3 hash values of fragments and the entire file during and after transmission to ensure data integrity.
[0079] In one embodiment of this application, the cross-network data transmission system adopts an architecture that combines centralized management and distributed services, wherein the management site is centrally deployed and the multiple data sites are distributed and deployed in the network areas of each branch office.
[0080] Specifically, such as Figure 8As shown, the system adopts a typical hybrid architecture pattern that combines centralized management and distributed services.
[0081] Centralized control is reflected in the fact that the management site serves as the sole center for control, policy, identity, and auditing, with centralized deployment. This ensures policy consistency, the uniqueness of the identity source, and the centralization of audit logs, facilitating overall management and security compliance.
[0082] Distributed services are characterized by multiple data stations being deployed across various branch network areas according to business needs, such as headquarters data centers, branch office networks, and remote R&D networks. Each data station provides secure file processing and high-speed transmission services within its local network, enabling it to handle user requests locally, reducing bottlenecks in data transmission paths for management stations, and meeting the requirements for localized data processing.
[0083] This architecture achieves both strict central control and the flexibility and scalability of a distributed system, making it ideal for secure data exchange scenarios across regions and networks for large organizations.
[0084] To facilitate a clearer understanding of the application of the cross-network data transmission method and system provided in this application in practical work, the above embodiments are integrated and described below with reference to actual application processes. Those skilled in the art will understand that these embodiments do not limit this application in any way.
[0085] This application introduces a national cryptographic digital certificate authentication mechanism, with the system management site responsible for the full lifecycle management of certificates, uniformly maintaining and updating the certificate trust list, and performing two-way authentication and encrypted transmission for both the management channel and the transmission channel to ensure the security of data transmission.
[0086] I. OCSP Mechanism: 1. The management site deploys an OCSP server, responsible for responding to certificate status queries. The OCSP server uses a dedicated OCSP response signing certificate (issued by the management site's CA) to sign the responses; 2. Each data station and relay station has a built-in OCSP client. When verifying certificates, in addition to checking the CRL, it is also necessary to query the OCSP server to obtain the real-time certificate status. 3. To improve performance and high availability, the OCSP server is deployed in a cluster. OCSP cluster status data is synchronized in real time to ensure consistent results from all responders. Cluster load balancing guarantees high service availability. Data sites and relay sites can cache OCSP responses, but the caching time cannot exceed the nextUpdate time specified in the OCSP response. When the OCSP service is unavailable, data sites and relay sites will switch to a backup authentication method (CRL) for certificate verification. 4. Specify the OCSP server address in the certificate. Data stations and relay stations will use this address to query the OCSP.
[0087] II. Site Registration (Management Channel): The site registration process mainly involves the interaction between the management site, data site, and relay site. Taking the process between the management site and the data site as an example, such as... Figure 9 As shown: 1. The data site deployment package includes a default certificate, which will initiate a registration request to the management site after deployment. 2. The management site determines whether the data site is accessing for the first time, and the administrator manually verifies and confirms the access. After the administrator's approval, the management site notifies the data site to generate a new asymmetric key and management certificate request file based on the current site information; 3. The data site submits the request file to the management site. The management site issues a management certificate and adds the certificate to the certificate trust list. The new certificate is registered as "valid" in the OCSP responder. At the same time, the built-in certificate of the data site is revoked and marked as "revoked" in the OCSP. The Certificate Revocation List (CRL) is updated. 4. The management site returns the new management certificate to the data site. The data site updates the built-in certificate and stores it in encryption. It configures the OCSP client parameters, including the OCSP service address of the management site, and tests the OCSP query function to ensure that the certificate status can be obtained normally. 5. The management site and data site monitor the validity period of management certificates (validity period 30 days) through scheduled tasks. The renewal process is automatically initiated 10 days before the certificate expires. 6. The data station generates a new asymmetric key and management certificate request file based on the current site information and submits it to the management station. The management station issues a new management certificate and updates the certificate trust list. The data station installs the new certificate and supports both the old and new certificates simultaneously for a period of time (dual certificate transition period) to ensure uninterrupted business operations. After the transition period ends, the old certificate is revoked.
[0088] III. Issuance of Transmission Certificates: The certificate issuance process mainly involves the interaction between the management site and the data site, and the process is as follows: Figure 10 As shown: 1. The data site submits a management certificate to the management site. The management node queries the OCSP service to verify the current status of the certificate and the integrity of the certificate chain, so as to realize two-way identity authentication between the data site and the management site. 2. After the management site verifies the data station's information, it checks whether the data station has already issued a transmission certificate. If not, it notifies the data station to generate a new asymmetric key and a transmission certificate request file. 3. The data station generates a new asymmetric key and certificate request file based on the current node information and submits it to the management station. The management station issues a transmission certificate, adds the new transmission certificate to the trust list, and registers the certificate status in the OCSP system; 4. The management site will return the transmission certificate to the data site for updating. The data site will install the transmission certificate, configure regular OCSP checks, set the OCSP status check cycle (once per hour) and response caching policy, and set the handling process when the certificate status is abnormal. 5. The periodic renewal of the transmission certificate (valid for 30 days) is monitored and triggered by the management site. Ten days before the certificate expires, the management site notifies the data site to initiate the renewal process. 6. The data station generates a new asymmetric key and a transmission certificate request file based on the current site information and submits it to the management station. The management station issues a new transmission certificate and updates the certificate trust list. The data station installs the new certificate and supports both the old and new certificates simultaneously for a period of time (dual certificate transition period) to ensure uninterrupted service. After the transition period ends, the old certificate is revoked.
[0089] IV. Data transmission within the network domain (transmission channel): The data transmission process within a network domain mainly involves interaction between data stations, and the process is as follows: Figure 11 As shown: 1. Data sites use national cryptographic certificates for two-way identity verification; 2. The data station receives the client certificate from the peer data station, verifies the validity of the certificate (including certificate chain, validity period, CRL check), and queries the OCSP server to confirm the certificate status (whether it has been revoked). 3. After completing the client certificate verification, send the server certificate to the peer. The peer verifies the validity of the server certificate (including certificate chain, validity period, CRL check) and queries the OCSP server to confirm the certificate status (whether it has been revoked). 4. After the server certificate is verified, an encrypted channel is established for data transmission.
[0090] V. Inter-domain data transmission (transmission channel): Inter-domain data transmission mainly involves interaction between data stations and relay stations, and the process is as follows: Figure 12 As shown: 1. Data station A and relay station use national cryptographic certificates for two-way identity verification; 2. Upon receiving the authentication certificate from data site A, the relay site verifies the certificate's validity (including certificate chain, validity period, and CRL check) and queries the OCSP server to confirm the certificate status (whether it has been revoked). After completing the authentication certificate verification, the relay site sends the authentication certificate to data site A for authentication. 3. Data station A receives the authentication certificate from the relay station, verifies its validity (including certificate chain, validity period, and CRL check), and queries the OCSP server to confirm the certificate status (whether it has been revoked). After completing two-way authentication, it sends data receiving target information (data station B). 4. The relay station sends an authentication certificate to data station B based on the target information sent by data station A; 5. Data station B receives the authentication certificate from the relay station, verifies the certificate's validity (including certificate chain, validity period, and CRL check), and queries the OCSP server to confirm the certificate status (whether it has been revoked). After completing the authentication certificate verification, it sends the authentication certificate to the relay station for authentication. 6. Upon receiving the authentication certificate from data site B, the relay site verifies the certificate's validity (including certificate chain, validity period, and CRL check) and queries the OCSP server to confirm the certificate status (whether it has been revoked). After completing two-way authentication, it sends a message to data site A indicating that the relay channel has been established. 7. Data station A receives the relay channel establishment information and performs cross-network data transmission.
[0091] The beneficial technical effects of this application are as follows: By organically integrating multiple stages such as process approval, security detection, two-way identity authentication and online status verification (OCSP) based on national cryptographic digital certificates (SM certificates), establishment of encrypted transmission channels, parallel transmission of file fragments, and dual integrity verification at the fragment and file levels based on the national cryptographic SM3 algorithm, as well as centralized audit log recording, a complete closed-loop solution for cross-network data transmission is formed. Specifically, 1) Comprehensive security assurance: A defense-in-depth system is built from three dimensions: pre-process approval (process approval, file security detection), during the process (two-way identity authentication and encrypted transmission based on national cryptographic algorithms), and post-process (integrity verification, audit logs), which significantly improves the security, reliability, and compliance of cross-network data transmission and effectively prevents risks such as unauthorized access, data leakage, and content tampering. 2) Highly efficient and reliable transmission: By adopting fragmented parallel transmission and pipeline mechanisms, network bandwidth is fully utilized, greatly improving the transmission efficiency of large files or batch data; combined with the ability to resume transmission after interruption and the two-level SM3 hash verification mechanism at the fragment and file levels, the reliability of the data transmission process and the integrity and consistency of the results are ensured. 3) Flexible Adaptability: By introducing a relay site mechanism, the transmission problem when the source and target networks cannot be directly connected is solved, enhancing the system's deployment flexibility in complex network topology environments; the architecture combining centralized management and distributed services facilitates unified policy management and efficient distributed execution. 4) Complete Auditability: The management site centrally records audit logs covering all elements such as users, approvals, transmissions, and verifications, providing detailed data support for security incident tracing, compliance checks, and operational analysis.
[0092] This application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described method.
[0093] This application also provides a computer-readable storage medium storing a computer program that performs the above-described methods.
[0094] This application also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the above-described method.
[0095] like Figure 13 As shown, the electronic device 600 may also include: a communication module 110, an input unit 120, an audio processor 130, a display 160, and a power supply 170. It is worth noting that the electronic device 600 does not necessarily need to include these components. Figure 13 All components shown; in addition, the electronic device 600 may also include Figure 13 For components not shown, please refer to existing technologies.
[0096] like Figure 13 As shown, the central processing unit 100, sometimes also referred to as a controller or operating control, may include a microprocessor or other processor device and / or logic device. The central processing unit 100 receives inputs and controls the operation of various components of the electronic device 600.
[0097] The memory 140 may be, for example, one or more of a cache, flash memory, hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices. It may store the aforementioned failure-related information, and also store a program for executing that information. The central processing unit 100 may execute the program stored in the memory 140 to perform information storage or processing, etc.
[0098] Input unit 120 provides input to central processing unit 100. Input unit 120 may be, for example, a keypad or touch input device. Power supply 170 provides power to electronic device 600. Display 160 displays images and text. Display may be, for example, an LCD display, but is not limited thereto.
[0099] The memory 140 can be a solid-state memory, such as a read-only memory (ROM), random access memory (RAM), a SIM card, etc. It can also be a memory that retains information even when power is off, can be selectively erased, and contains more data; examples of this type of memory are sometimes referred to as EPROMs. The memory 140 can also be some other type of device. The memory 140 includes a buffer memory 141 (sometimes referred to as a buffer). The memory 140 may include an application / function storage unit 142 for storing application programs and function programs or processes for executing the operation of the electronic device 600 via the central processing unit 100.
[0100] The memory 140 may also include a data storage unit (data 143) for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit (driver 144) of the memory 140 may include various drivers for the electronic device's communication functions and / or for performing other functions of the electronic device (such as messaging applications, address book applications, etc.).
[0101] The communication module 110 is a transmitter / receiver that transmits and receives signals via the antenna 111. The communication module (transmitter / receiver) 110 is coupled to the central processing unit 100 to provide input signals and receive output signals, which can be the same as in a conventional mobile communication terminal.
[0102] Based on different communication technologies, multiple communication modules 110 can be configured in the same electronic device, such as cellular network modules, Bluetooth modules, and / or wireless LAN modules. The communication module (transmitter / receiver) 110 is also coupled to a speaker 131 and a microphone 132 via an audio processor 130 to provide audio output via the speaker 131 and receive audio input from the microphone 132, thereby enabling typical telecommunications functions. The audio processor 130 may include any suitable buffer, decoder, amplifier, etc. Additionally, the audio processor 130 is coupled to a central processing unit 100, enabling on-device recording via the microphone 132 and on-device playback of stored audio via the speaker 131.
[0103] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0104] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0105] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0106] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0107] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above descriptions are merely specific embodiments of this application and are not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for cross-network data transmission, characterized in that, The method includes: Based on the approval results of the user's cross-network file transfer request process, the files uploaded to the source data site are subjected to security detection and analysis to obtain the files after security processing; Based on the pre-configured transmission strategy and security authentication requirements, an encrypted transmission channel is established between the source and target ends through two-way identity authentication based on national cryptographic digital certificates and online certificate status query. The file data is fragmented and transmitted in parallel according to the encrypted transmission channel, and fragment-level and file-level integrity checks are performed before and after the file data is transmitted based on the national cryptographic SM3 algorithm; Based on the transmission completion result, an audit log containing user, approval, transmission and verification information is recorded on the management site.
2. The cross-network data transmission method according to claim 1, characterized in that, Establishing an encrypted transmission channel between the source and the destination includes: Based on the national cryptographic digital certificates issued by the management site for each node, the system queries the OCSP service of the management site to obtain the certificate validity verification result when communication is initiated. Based on the verification results and the two-way certificate exchange mechanism, two-way identity authentication is performed to establish an encrypted communication link.
3. The cross-network data transmission method according to claim 1, characterized in that, Performing fragmented parallel transmission of file data according to the encrypted transmission channel includes: The file data is divided into multiple fragments according to the transmission strategy; The multiple fragments are transmitted via a parallel pipeline mechanism.
4. The cross-network data transmission method according to claim 3, characterized in that, The integrity checks performed before and after the file data transmission based on the national cryptographic SM3 algorithm include: After at least one fragment is transmitted, the hash value of the corresponding fragment is generated based on the national cryptographic SM3 algorithm and verified. After all the file data has been transmitted, the hash value of the entire file is generated based on the national cryptographic SM3 algorithm and then verified.
5. The cross-network data transmission method according to claim 1, characterized in that, Performing fragmented parallel transmission of file data according to the encrypted transmission channel also includes: When the source and destination networks are not directly connected, data is forwarded through relay stations; The relay station establishes encrypted links with both the source and target ends through two-way identity authentication based on national cryptographic digital certificates, and transparently forwards file data between the encrypted links.
6. The cross-network data transmission method according to claim 1, characterized in that, The method further includes: Based on the site registration request, the management site reviews and issues site certificates to nodes that obtain controlled access; Based on the certificate validity monitoring results, the certificate renewal process is triggered one preset period before the site certificate expires.
7. A cross-network data transmission system applicable to the cross-network data transmission method according to any one of claims 1 to 6, characterized in that, include: The management site is used to receive and process cross-network file transfer requests to complete the process approval, and to issue and manage national cryptographic digital certificates for each node in the system; Multiple data stations, deployed in different network areas, are used to perform security testing and analysis on approved documents, and establish encrypted transmission channels with the target end based on the national cryptographic digital certificate to perform file fragment transmission and integrity verification; Relay stations are used to establish encrypted links and transparently forward data when the source and destination networks are not directly connected.
8. The system according to claim 7, characterized in that, The management site also includes: The strategy control module is used to configure the transmission strategy, which controls the target, bandwidth and concurrency of file transmission. The Certificate Authority module is used to issue certificates, maintain a certificate trust list, and provide OCSP status query services to support the two-way authentication.
9. The system according to claim 7, characterized in that, The data site also includes: The security service interface module is used to call virus scanning, data leakage prevention detection and encryption services to perform secure processing on files; The transmission engine module is used to perform file fragmentation, parallel transmission, breakpoint resumption, and integrity verification based on the national cryptographic SM3 algorithm.
10. The system according to claim 7, characterized in that, The cross-network data transmission system adopts an architecture that combines centralized management and distributed services, wherein the management site is centrally deployed and the multiple data sites are distributed and deployed in the network areas of each branch office.
11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 6.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of any one of claims 1 to 6.
13. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 6.