Large Instrument Data Security Controlled Access Management System
By constructing a closed local area network and a central data server, the network security and data transmission issues in the access and management of large-scale instrument data in universities and research institutions have been resolved, realizing secure and convenient data flow and standardized management, and improving system stability and research efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SICHUAN UNIV
- Filing Date
- 2026-03-05
- Publication Date
- 2026-05-26
AI Technical Summary
The access and management of large-scale instrument data in universities and research institutions suffers from problems such as uncontrolled network boundaries and insecure data flow, making them vulnerable to network attacks and virus intrusions. Furthermore, data exchange relying on removable storage media carries uncontrollable risks.
Build a closed local area network, isolate the Internet through a router, prohibit the use of removable storage media, establish a data sharing storage area, and introduce a central data server for identity authentication and access control to achieve controlled access and management of data.
It has improved the security of the instrument control system, increased the efficiency of data flow and standardized management, reduced the risk of security incidents and improved the efficiency of scientific research.
Smart Images

Figure CN122093151A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security and large-scale scientific instrument management technology, specifically relating to a controlled access and management system for large-scale instrument data. By constructing a closed local area network, it enables controlled and secure access and transmission of scientific instrument data. This invention is primarily applied to key laboratories in universities, research institutes, and enterprises for managing experimental data generated by high-value large-scale analytical instruments such as mass spectrometers, nuclear magnetic resonance spectrometers, and chromatographs. Background Technology
[0002] Currently, universities and research institutions generally adopt two traditional modes for accessing and managing large-scale instrument data: one is to directly connect the instrument control host to the open campus or the Internet and access the data through remote desktop or shared folders; the other is to physically isolate the data but rely on manual operation, that is, to manually copy the data between the instrument host and the user terminal using portable storage media such as USB flash drives or external hard drives.
[0003] Existing technical problems:
[0004] Network boundary out of control: The instrument host is directly exposed to the public network, lacking effective network isolation and access control, making it extremely vulnerable to external network attacks, virus intrusions and unauthorized access, resulting in exceptionally fragile system security.
[0005] Insecure data transfer path: Relying on mobile storage media for data exchange creates an uncontrollable virus transmission channel, and the operation process cannot be audited. Data is at risk of leakage, damage, or infection with malware during transmission, directly threatening the stable operation of the instrument control system. Summary of the Invention
[0006] The purpose of this invention is to build a secure and convenient intranet data access channel for authorized researchers in a closed environment that completely isolates the Internet and mobile storage media, while absolutely protecting the instrument control system from external threats, thus achieving a balance between controlled data flow and strict system protection.
[0007] To achieve the above objectives, this invention provides a secure and controlled access and management system for large-scale instrument data. This system is physically isolated from the internet and prohibits the use of removable storage media. Its core lies in constructing a multi-layered controlled data environment, mainly comprising:
[0008] Closed network layer: This layer utilizes network devices, such as routers, to build a separate, physically isolated local area network (LAN) from the internet. This network connects only the instrument control host and authorized user access terminals, such as laptops.
[0009] Data sharing and access layer: A data sharing storage area, such as a shared folder, is set up on the instrument control host. Authorized user terminals can directly access this area through a network path (such as \\hostname\\shared folder) via a closed local area network to browse and download data.
[0010] Management and Audit Layer (Optional Expansion): A central data server (such as NAS) can be introduced to automatically collect data from multiple instruments and deploy a web-based intranet data portal, providing a unified browser access interface. The system can be configured with user authentication, hierarchical access control, and logs of all data access and download operations, enabling auditable management.
[0011] The construction method follows the principle of "starting from a point and expanding to a surface, rapid verification, and iterative expansion". First, the feasibility of the infrastructure is quickly deployed and verified in a single laboratory using simple network equipment. Then, the network equipment is gradually upgraded, the coverage is expanded, the central data management platform is integrated, and finally, the connection with the university-level teaching and research information platform is achieved.
[0012] Compared with the prior art, the present invention has the following significant effects:
[0013] 1. Fundamentally enhanced security: By physically isolating the internet and disabling mobile media, the main paths for external network attacks and virus transmission are cut off at the source, ensuring the system purity and stability of the instrument control host and greatly reducing the risk of instrument failure and data loss due to security incidents.
[0014] 2. Significantly improved data transfer efficiency: Researchers no longer need to go to the instrument site or rely on USB flash drives to copy data. They can access and download the required data anytime within the authorized area via the intranet. The operation is convenient, greatly saving time and improving the efficiency of scientific research.
[0015] 3. Standardized and auditable management: Through a unified access point, access control and operation logs, the data flow process is made transparent and traceable, which helps to implement data security responsibilities and promotes the transformation of scientific research data management from a private and decentralized model to a centralized and standardized governance model.
[0016] 4. Low implementation cost and flexible path: In the initial stage, low-cost network equipment can be used to quickly deploy and verify the core logic, addressing pressing security pain points and reducing implementation barriers and risks. Subsequent upgrades to a platform-based solution are possible as needed, demonstrating good scalability and replicability. Attached Figure Description
[0017] Figure 1 This is a schematic diagram of the structure of the present invention. Detailed Implementation
[0018] The specific technical solutions of the present invention will be described with reference to the embodiments. For example... Figure 1 As shown, theoretically, by connecting to a router with a network cable, the router emits a signal over a certain area. When a mobile phone is within this area, it can connect to the internet and access the internet.
[0019] However, in this design, the router is not connected to a network cable, only to a power source. The area it emits that is not connected to the internet is called a local area network (LAN). When a computer is connected to the LAN, it cannot access anything. But if the liquid phase computer is also connected to the LAN, and the liquid phase computer and the visitor's computer are in the same LAN, although neither can access the internet, they can access each other. The visitor's computer does not need to enable sharing, while the liquid phase computer can access the internet by enabling sharing first. The liquid phase computer only needs to enable the copy function. The liquid phase computer is not connected to the internet at all and cannot be too far from the router.
[0020] In summary, the following steps can be taken on the visitor's computer.
[0021] 1. Connect to the router
[0022] 2. Add a network location
[0023] 3. Add a shared IP address for the liquid chromatography computer.
[0024] 4. Accessing liquid phase data
[0025] The goal of this embodiment is to enable visitors' personal laptops to safely and conveniently read and copy data files from the computers of large laboratory instruments (such as high performance liquid chromatographs, HPLC) in a closed environment without internet connection, completely replacing USB flash drives and eliminating the risk of viruses.
[0026] I. Core Principle: Building a "Data Reading Room"
[0027] Imagine this solution as establishing a "data reading room" accessible only to internal staff:
[0028] 1. Router = Reading Room Building: It provides a private space (wireless signal) and stipulates that "this building is completely isolated from the outside world (Internet)".
[0029] 2. Instrument Computer (Host) = Archivist: It brings the documents (experimental data) to the reading room and places them in a specific, locked glass cabinet (read-only shared folder). Everyone can see and copy them, but cannot modify or add anything else.
[0030] 3. Visitor's laptop = Reader: The visitor enters the building and receives a "borrowing card" (network location mapping) that can directly open that specific glass case.
[0031] 4. The whole process: Once the "building" is built, the "administrator" is in place, and the "library card" is issued, visitors only need to enter the building (connect to Wi-Fi), swipe their card (double-click the shortcut), and they can directly view and copy the latest documents.
[0032] II. Detailed operating steps:
[0033] Part 1: Setting up the "Data Reading Room" (one-time setup);
[0034] Step 1: Prepare and configure the router (build the "building");
[0035] Equipment: Prepare a regular home wireless router (new or old).
[0036] Connection: Only plug the power cord into the router (connect the power). Never plug any network cable from a wall port or external network into the port on the router labeled "WAN" or "Internet".
[0037] Access Settings: Use your phone or computer to connect to the default Wi-Fi network (usually password-free) listed on the label on the back of the router. Open your browser and enter the router's management address (e.g., 192.168.1.1 or 192.168.0.1, see the label on the back of the router). Log in to the management interface (username and password are usually admin / admin, see the label on the back of the router).
[0038] Configure your wireless network: Locate the "Wireless Settings" or "Wi-Fi Settings" option.
[0039] Set the network name (SSID): for example, set it to HPLC_Data_Room.
[0040] Set a Wi-Fi password: For security, please set a strong password, such as LabData2026!. Write down this name and password.
[0041] Save and restart the router. At this point, a closed wireless network named HPLC_Data_Room, isolated from the internet, has been created.
[0042] Step 2: Configure the instrument computer ("File Administrator" registration);
[0043] Connect to the network: Turn on the control computer of the high-performance liquid chromatograph (HPLC) and connect it to the HPLC_Data_Room wireless network you just created (or connect it to the LAN port of the router using an Ethernet cable). Enter the password set by the user.
[0044] Create a shared folder: On this instrument computer, find a suitable disk (such as drive D) and create a new folder. It is recommended to name it something clear and easy to understand, such as: Instrument Data Export or HPLC_Export.
[0045] This folder is the location where all data files that need to be exported in the future should be saved or generated by default.
[0046] Setting up folder sharing (critical security steps): Right-click the folder and select "Properties". Switch to the "Sharing" tab. Click the "Advanced sharing..." button. In the pop-up window, check "Share this folder".
[0047] Click the "Permissions" button.
[0048] Key settings: In the pop-up permissions window, ensure that Everyone (or the corresponding user) is selected in "Group or user names," and then in the permissions list below, only check "Read." This means that other computers can only view and copy, but cannot delete or modify. Click "OK" all the way through and close all windows.
[0049] Record key information: Note down the "computer name" of this instrument's computer on this network. To find it: Right-click "This PC" on the desktop -> "Properties", and view the "Device Name". For example: DESKTOP-AGRO9K3.
[0050] Also, note down the name of this shared folder (which is the share name you just set; if you don't change it, it's usually the original folder name).
[0051] Part Two: Issuing Visitors' "Library Cards" (a one-time setup on the visitor's personal laptop)
[0052] Step 3: Connect and map the network drive;
[0053] Connect to the network: Turn on your personal laptop and connect to the same wireless network, HPLC_Data_Room. Enter the password.
[0054] Open File Explorer: Press Win+E or double-click "This PC" on the desktop.
[0055] To add a network location: Right-click in a blank area of the "This PC" window. Select "Add a network location." An "Add Network Location Wizard" window will pop up; click "Next." Select "Choose a custom network location," and click "Next."
[0056] Enter the address: In the input box below "Internet address or network address (A):", enter the address of the instrument's computer. The format is fixed as: \\computer name\shared folder name.
[0057] For example, based on previous records, if the computer name is DESKTOP-AGRO9K3 and the share name is HPLC_Export, then you should enter: \\DESKTOP-AGRO9K3\HPLC_Export
[0058] (Note: The forward slash is reversed, \, not the / commonly used in web addresses).
[0059] After you have finished entering the information, click "Next".
[0060] Naming and Completion: If the address is correct, the wizard will prompt the visitor to name this network location. You can choose a name that is easy for you to identify, such as "Laboratory HPLC Data Cabinet". Click "Next", and then click "Finish".
[0061] Mapping complete: At this point, in addition to the C drive and D drive, a network location shortcut named "Laboratory HPLC Data Cabinet" will appear in the user's "This PC". The "borrowing card" is now ready.
[0062] III. Daily usage procedures;
[0063] In the future, whenever a user needs to retrieve data from the instrument, they only need to repeat the following two steps:
[0064] 1. Enter the “Building”: Ensure that the visitor’s laptop is connected to the HPLC_Data_Room Wi-Fi.
[0065] 2. "Swipe Card" Access: Open "This PC" and double-click the "Laboratory HPLC Data Cabinet" icon. The visitor will immediately see a file list containing all the latest files from the instrument data export folder on the instrument computer! You can directly open and view these files. Select a file, press Ctrl+C to copy, and then paste (Ctrl+V) it to any location on your personal computer.
[0066] Throughout the entire process, both the personal laptops and the instrument computers were in a completely closed environment, unrelated to the internet, and the data was transmitted as securely and quickly as if it were in the same room.
[0067] IV. Important Precautions (To Ensure Success and Safety)
[0068] 1. Physical isolation is fundamental: Ensure that no network cable is connected to the router's WAN port. This is the cornerstone of the security of this solution.
[0069] 2. Distance and signal: The instrument computer and personal laptop need to be within the effective range of the router's wireless signal and cannot be too far away.
[0070] 3. Read-only permissions: Ensure that the shared folder on the instrument's computer has only "read" permissions. This is crucial to prevent accidental access or potential risks from affecting the instrument's computer.
[0071] 4. Initial connection may require credentials: Upon first connection, the system may pop up a window asking for a username and password. Usually, you can simply enter the login username and password for the instrument's computer (if you don't remember them, you can create a simple dedicated account on the instrument's computer for sharing).
[0072] 5. Troubleshooting: If you cannot connect by double-clicking the shortcut in the future, please first check two things: ① Is your laptop connected to the HPLC_Data_Room Wi-Fi? ② Is the instrument computer powered on and connected to the same Wi-Fi network?
[0073] Through the above extremely detailed steps, even users without professional IT knowledge can successfully deploy and use this secure and efficient data sharing system, completely eliminating the need for USB drives and improving the efficiency of scientific research.
Claims
1. A large-scale instrument data security-controlled access and management system, characterized in that, The system is physically isolated from the internet and prohibits the use of removable storage media, constructing a multi-layered controlled data environment, including: Closed network layer: Using network devices, a separate, physically isolated private local area network is constructed; this network connects only the instrument control host and the access terminals of authorized users; Data sharing and access layer: A data sharing storage area is set up on the instrument control host. Through a closed local area network, authorized user terminals can directly access this area via network path to browse and download data.
2. The large-scale instrument data security controlled access and management system according to claim 1, characterized in that, Also includes: Management and Audit Layer: A central data server is introduced to automatically collect data from multiple instruments, and a web-based intranet data portal is deployed to provide a unified browser access interface; user authentication and hierarchical access control are configured, and all data access and download operation logs are recorded to achieve auditable management.