Data sandbox local area networking structure with high security

By adopting spatial physical isolation layout and dedicated security hardware in local networking, the data security problem of data sandbox is solved, the internal data leakage risk is reduced, and data security and management control are improved.

CN223067107UActive Publication Date: 2025-07-04ZHONGKE TONGLIAN (BEIJING) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202422307913.X
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2025-07-04
Estimated Expiration
2034-09-23

AI Technical Summary

Technical Problem

The existing local networking methods cannot effectively ensure the data security of data sandboxes, especially the high risk of internal data leakage and the lack of dedicated network security hardware equipment.

Method used

The data sandbox local networking structure adopts a spatial physical isolation layout, including a server, a first switch, a bastion machine, a management terminal and a second switch. The local user terminal removes or blocks the external data interface, and conducts data interaction core communication through the bastion machine, combining special security hardware to improve data security.

Benefits of technology

Through the combination of physical isolation and dedicated hardware, the risk of internal data leakage is reduced and data security and management control is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223067107U_ABST
    Figure CN223067107U_ABST
Patent Text Reader

Abstract

The utility model relates to the technical field of data sandboxes, and provides a data sandbox local area networking structure with high safety, which comprises local area network core equipment and a plurality of local area user terminals which are in spatial physical isolation layout with the local area network core equipment, the local area network core equipment comprises a server, a first switch, a bastion host, a management terminal and a second switch; the first switch is respectively connected with the server, the bastion host, the management terminal and the second switch; the second switch is respectively connected with a plurality of local user terminals; the local user terminal adopts computer equipment with an external data interface removed or blocked, and the management terminal is provided with the external data interface. By adopting physical isolation and a bastion host, a computer with an external data interface removed or blocked is adopted for a local user terminal, so that the risk of internal data leakage is reduced, and the data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The utility model relates to the technical field of local area networking, and particularly relates to a data sandbox local area networking structure with high security. Background Art

[0002] The data security of a data sandbox is very important. However, in the existing local area networking methods, the data security of the data sandbox cannot be guaranteed. On the one hand, the data storage devices in the local area network and the local user terminals are not reasonably arranged and are managed without distinction, resulting in easy access to the data storage devices. On the other hand, software programs or network protocols are used in local area networking to improve data security, and dedicated network security hardware devices are not set up. These software programs or network protocols are easily breached using network technology. As a result, the data security control of the hardware devices of the current data sandbox system constructed by local area networking is weak, especially the risk of internal user data leakage is high. Summary of the Utility Model

[0003] To solve the above technical problems, the utility model provides a data sandbox local area networking structure with high security, which includes a local area network core device and multiple local user terminals that are physically isolated from it in space. The local area network core device includes a server, a first switch, a bastion host, a management terminal, and a second switch. The first switch is respectively connected to the server, the bastion host, the management terminal, and the second switch. The second switch is respectively connected to multiple local user terminals. The local user terminal uses a computer device with external data interfaces removed or blocked, and the management terminal is provided with external data interfaces.

[0004] Optionally, multiple servers are provided and are connected to each other through a third switch, and the first switch is connected to the servers through the third switch.

[0005] Optionally, the first switch is further connected to a video monitoring subsystem, and the video monitoring subsystem includes an optical network unit, a first camera, a second camera, a third camera, an optical line terminal, and a monitoring terminal.

[0006] The first switch is respectively connected to the optical line terminal and the monitoring terminal. The optical line terminal is connected to the optical network unit by optical fiber, and the optical network unit is respectively connected to the first camera, the second camera, and the third camera.

[0007] The first camera is installed facing the management terminal area. The second camera is installed facing the local user terminal area. The third camera is installed facing the server area.

[0008] Optionally, the management terminal is a desktop computer device including a computer mainframe, and the external data interface is provided on the computer mainframe; the computer mainframe is installed in a safety box, and the safety box is provided with a safety lock.

[0009] Optionally, the monitoring terminal is connected to a data collector, the data collector is connected to a face recognition device, and the face recognition device is arranged at the access control position.

[0010] Optionally, the data collector is connected to a thermometer, the thermometer is a non-contact thermometer, and the thermometer is arranged at the access control position.

[0011] Optionally, a ventilation opening is formed in the shell of the safety box, a shutter is installed at the ventilation opening by riveting or welding, an exhaust fan is installed inside the ventilation opening, and the exhaust fan is electrically connected to the computer mainframe of the management terminal.

[0012] Optionally, the server, the first switch, and the bastion host are installed in a server cabinet; the server cabinet includes a cabinet door, the cabinet door includes a shell, a fan, and a heat exchanger, the heat exchanger is installed inside the shell, the fan is installed on the outer surface of the shell, the heat exchanger is provided with a cold source interface, a temperature sensor is installed inside the server cabinet, and the fan and the temperature sensor are connected to the data collector.

[0013] Optionally, a network connection switching device is arranged between the first switch and the second switch, the network connection switching device includes a housing and a switching control board installed inside the housing, the switching control board is provided with a main network interface, a first interface, a second interface, a third interface, a full network connection button, a first connection button, a second connection button, and a third connection button; the main network interface is connected to the first switch, the first interface is connected to the second switch, the second switch is a local area network switch, the second interface is connected to a government affairs network terminal through a government affairs extranet, and the third interface is connected to an Internet terminal through the Internet; the full network connection button controls the first switch to be connected to the second switch, the government affairs extranet, and the Internet at the same time, the first connection button controls the first switch to be only connected to the second switch, the second connection button controls the first switch to be only connected to the government affairs extranet, and the third connection button controls the first switch to be only connected to the Internet.

[0014] Optionally, the first camera, the second camera, and the third camera all adopt digital cameras with a pixel count of not less than 5 million; the monitoring terminal is connected to an alarm.

[0015] The data sandbox local area networking structure with high security of the present utility model constructs a data sandbox system with a server, a first switch, a bastion host, a management terminal, a second switch, and multiple local user terminals. The bastion host is connected through the first switch. Since the first switch is the core communication position for data interaction in the data sandbox system, setting the bastion host here is beneficial to data security. In addition, the server, the first switch, the bastion host, the management terminal, the second switch, which are the core devices of the local area network, and the local user terminals are implemented with a spatial isolation layout, that is, the core devices of the local area network are set in a data machine room with closed management, and general users cannot access the core devices of the local area network. Only the management terminal in the core devices of the local area network in the data sandbox system is provided with an external data interface to support data import, export, cut, or copy, etc., to provide basic data for data processing. For the local user terminals that can be accessed by users, computers with external data interfaces removed or blocked are used, so that the local user terminals do not support connecting to devices other than the above devices that can copy and save data (such as optical discs, USB flash drives, hard disks, mobile phones, and digital cameras, etc.), preventing users of the local user terminals from cutting or copying and transferring data. The present utility model combines isolation and dedicated security hardware (bastion host) in local area networking to reduce the risk of internal data leakage and improve data security.

[0016] Other features and advantages of the present utility model will be described in the subsequent description, and, in part, will be obvious from the description, or will be understood by implementing the present utility model. The objectives and other advantages of the present utility model can be achieved and obtained through the structures specifically pointed out in this application document.

[0017] The technical solutions of the present utility model will be further described in detail below through the accompanying drawings and embodiments. Description of the Drawings

[0018] The accompanying drawings are used to provide a further understanding of the present utility model, and constitute a part of the description. They are used together with the embodiments of the present utility model to explain the present utility model, and do not constitute a limitation to the present utility model. In the accompanying drawings:

[0019] Figure 1 is a schematic diagram of a data sandbox local area networking structure with high security in an embodiment of the present utility model;

[0020] Figure 2 is a schematic diagram of a video monitoring subsystem adopted in an embodiment of the data sandbox local area networking structure with high security of the present utility model;

[0021] Figure 3 is a connection schematic diagram of a thermometer and a face recognition device adopted in an embodiment of the data sandbox local area networking structure with high security of the present utility model;

[0022] Figure 4 Schematic diagram of the heat dissipation port of the management terminal host chassis adopted in the embodiment of the data sandbox local area networking structure with high security of the present utility model;

[0023] Figure 5 Schematic diagram of the server cabinet and the servers, the first switch, and the bastion host installed therein adopted in the embodiment of the data sandbox local area networking structure with high security of the present utility model;

[0024] Figure 6 Schematic diagram of the server cabinet and the cabinet door adopted in the embodiment of the data sandbox local area networking structure with high security of the present utility model;

[0025] Figure 7 Schematic diagram of the network connection switching device adopted in the embodiment of the data sandbox local area networking structure with high security of the present utility model.

[0026] In the figure: 1. Server, 2. First switch, 3. Bastion host, 4. Management terminal, 5. Second switch, 6. Local user terminal, 7. External data interface, 8. Third switch, 9. Security box, 10. Security lock, 11. Optical network unit, 12. First camera, 13. Second camera, 14. Third camera, 15. Optical line terminal, 16. Monitoring terminal, 17. Face recognition device, 18. Temperature measuring instrument, 19. Data collector, 20. Blinds, 21. Server cabinet, 22. Cabinet door, 23. Fan, 24. Display screen, 25. Cold source interface, 26. Network connection switching device, 27. Switching control board, 28. Total network interface, 29. First interface, 30. Second interface, 31. Third interface, 32. Whole network connection button, 33. First connection button, 34. Second connection button, 35. Third connection button, 36. Government affairs network terminal, 37. Internet terminal. Detailed implementation manners

[0027] The following describes the preferred embodiments of the present utility model with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present utility model, and are not used to limit the present utility model.

[0028] As Figure 1As shown in the figure, an embodiment of the present utility model provides a data sandbox local area networking structure with high security, which includes a local area network core device and a plurality of local user terminals 6 that are physically isolated from it in space. The local area network core device includes a server 1, a first switch 2, a bastion host 3, a management terminal 4, and a second switch 5. The first switch 2 is respectively connected to the server 1, the bastion host 3, the management terminal 4, and the second switch 5. The second switch 5 is respectively connected to a plurality of local user terminals 6. The local user terminal 6 uses a computer with external data interfaces removed or blocked, and the management terminal 4 is provided with an external data interface 7.

[0029] The working principle and beneficial effects of the above technical solution are as follows: In this solution, a data sandbox system is constructed with a server, a first switch, a bastion host, a management terminal, a second switch, and multiple local user terminals, which can be connected via network cables using RS485 interfaces; the bastion host is connected through the first switch. Since the first switch is the core communication location for data interaction in the data sandbox system, setting the bastion host here is beneficial for data security; in addition, the server, the first switch, the bastion host, the management terminal, the second switch, which are the core devices of the local area network, and the local user terminals are arranged with spatial isolation, that is, the core devices of the local area network are set in a data machine room with closed management, and ordinary users cannot access the core devices of the local area network. Only the management terminal in the core devices of the local area network in the data sandbox system is provided with external data interfaces to support data import, export, cut, or copy, etc., providing basic data for data processing; for the local user terminals that users can access, computers with external data interfaces removed or blocked are used, so that the local user terminals do not support connecting to devices other than the above devices that can copy and save data (such as optical discs, USB flash drives, hard disks, mobile phones, and digital cameras, etc.), preventing the users of the local user terminals from cutting or copying and transferring data. This solution combines isolation and dedicated security hardware (bastion host) in local area networking, reducing the risk of internal data leakage and improving data security; among them, the blocking can be achieved by packing and isolating the components with external data interfaces on the local user terminals. The local user terminals and the management terminal generally use desktop computers, and the desktop computers at least include components such as computer hosts, monitors, keyboards, and mice; the server can use an Intel Xeon 4110 (2.1GHz / 8 cores / 11MB / 85W) processor, configured with 8 * 32GB DDR4 memory, 2 pieces of 600G 10k SAS hard disks, a 12Gb SAS RAID card with 2GB cache, 4 gigabit Ethernet interfaces, 2 10Gb optical network interfaces, and a 550W redundant power supply; the first switch can use an Ethernet switch host, supporting 48 SFP Plus ports and 6 QSFP Plus ports, configured with 2 250W AC power modules, 33 SFP+ 10G modules (850nm, 300m, LC), and 3 fan modules (side air outlet on the fan panel); the second switch can use an Ethernet switch host, supporting 48 10 / 100 / 1000BASE-T electrical ports and 4 1G / 10GBASE-X SFP+ ports, supporting AC, configured with 4 SFP+ 10G modules (850nm, 300m, LC); the bastion host can use a standard rack-mounted software and hardware integrated device, with 4 gigabit electrical ports, supporting no less than 200 device authorizations.

[0030] In one embodiment, as Figure 1As shown, multiple servers 1 are provided and interconnected through a third switch 8, and the first switch 2 is connected to the servers 1 through the third switch 8.

[0031] The working principle and beneficial effects of the above technical solution are as follows: In this solution, multiple servers are interconnected by a third switch to form a server cluster, which can enhance the data processing ability of the data sandbox system. The multiple servers are uniformly connected to the first switch by the third switch, without changing the core position of data interaction of the first switch, so the data protection function of the bastion host connected to the first switch will not be affected. Among them, the third switch can adopt a 48SFP Plus + 2QSFP Plus + 2Slot Ethernet switch host, with 2 250W AC power supplies, 2 fan modules (air outlet on the power supply side), 4 SFP+ 10G modules (850nm, 300m, LC), and 4 electrical modules - SFP-GE- (RJ45).

[0032] In one embodiment, as Figure 2 shown, the first switch 2 is further connected to a video monitoring subsystem, and the video monitoring subsystem includes an optical network unit 11, a first camera 12, a second camera 13, a third camera 14, an optical line terminal 15, and a monitoring terminal 16;

[0033] The first switch 2 is respectively connected to the optical line terminal 15 and the monitoring terminal 16. The optical line terminal 15 is connected to the optical network unit 11 by optical fiber, and the optical network unit 11 is respectively connected to the first camera 12, the second camera 13, and the third camera 14;

[0034] The first camera 12 is installed facing the management terminal 4 area; the second camera 13 is installed facing the local user terminal 6 area; the third camera 14 is installed facing the server 1 area.

[0035] The working principle and beneficial effects of the above technical solution are as follows: In this solution, the video surveillance subsystem is connected through the first switch of the data sandbox system. The first camera is installed to shoot the monitoring management terminal area; the second camera is installed to shoot the local user terminal area; the third camera is installed to shoot the monitoring server area. The monitoring terminal checks whether there is any illegal data operation on the management terminal, local user terminal, and server location 24 hours a day, further improving data security. The video surveillance subsystem uses an optical network unit and an optical line terminal for optoelectronic signal conversion, and the optical network unit and the optical line terminal are connected by optical fiber, which can improve the signal transmission speed, prevent signal interference, and ensure the security of data signals. Among them, the monitoring terminal can be configured with a computer with an i5-9400F 8G 1T + 256G SSD 2G independent display and a host security chassis. The first camera, the second camera, and the third camera can all be selected as 12-megapixel digital cameras using the POE (Power Over Ethernet) power supply method to ensure image clarity.

[0036] In one embodiment, as Figure 2 shown, the management terminal 4 is a desktop computer device including a computer main unit, and the external data interface 7 is set on the computer main unit; the computer main unit is installed in the safety box 9, and the safety box 9 is provided with a safety lock 10;

[0037] As Figure 4 shown, a ventilation opening is provided on the shell of the safety box 9, and a shutter 20 is installed at the ventilation opening by riveting or welding. An exhaust fan is installed inside the ventilation opening, and the exhaust fan is electrically connected to the computer main unit of the management terminal 4.

[0038] The working principle and beneficial effects of the above technical solution are as follows: In this solution, a safety box is set for the management terminal computer main unit with a unique external data interface. The safety box can be made of metal materials, which can not only enhance the firmness of protection but also play a role in signal shielding. The computer main unit of the management terminal is locked into the safety box with a safety lock to prevent unauthorized personnel from stealing the data in the system through the external data interface of the management terminal computer main unit, thereby reducing the risk of data leakage and further improving data security. The safety box is provided with a ventilation opening with a shutter, which can facilitate the heat dissipation of the computer main unit of the management terminal. An exhaust fan is installed inside the ventilation opening to accelerate air convection and enhance the heat dissipation effect, ensuring the temperature environment for its normal operation. The shutter installed by riveting or welding can also prevent outsiders from stealing the data in the system through the ventilation opening using the external data interface.

[0039] In one embodiment, as Figure 3As shown, the monitoring terminal 16 is connected to a data collector 19, the data collector 19 is connected to a face recognition device 17, the face recognition device 17 is set at the access control position, and the access control is connected to the monitoring terminal 16;

[0040] The data collector 19 is connected to a thermometer 18. The thermometer 18 is a non-contact thermometer and is set at the access control position.

[0041] The working principle and beneficial effects of the above technical solution are as follows: In this solution, by connecting the face recognition device through the data collector and setting the face recognition device at the access control position, the entry and exit of personnel can be monitored to prevent unauthorized personnel from accessing the data sandbox system or prevent someone from entering restricted areas (such as the server area and the management terminal area) beyond their authority; by setting a thermometer at the access control position, the body temperature of relevant personnel can be measured to pay attention to the health and safety of personnel; the non-contact thermometer can prevent cross-infection among different personnel.

[0042] In one embodiment, as Figure 5 shown, the server 1, the first switch 2 and the bastion host 3 are installed in the server cabinet 21;

[0043] As Figure 6 shown, the server cabinet 21 includes a cabinet door 22. The cabinet door 22 includes a housing, a fan 23 and a heat exchanger. The heat exchanger is installed inside the housing, the fan 23 is installed on the outer surface of the housing, the heat exchanger is provided with a cold source interface 25, a temperature sensor is installed inside the server cabinet 21, and the fan 23 and the temperature sensor are connected to the data collector 19.

[0044] The working principle and beneficial effects of the above technical solution are as follows: In this solution, by setting a server cabinet and installing the server, the first switch and the bastion host uniformly, the security management of the server, the first switch and the bastion host can be strengthened; since the server, the first switch and the bastion host generate heat during operation and have certain requirements for the operating environment temperature, a cabinet door with a fan and a heat exchanger is set on the server cabinet. The cabinet door is connected to the server cabinet by a hinge for convenient opening and closing of the cabinet door. The heat exchanger is connected to an external cold source (such as cold water with a lower temperature, chilled water of an air conditioner or refrigerant, etc.) through the cold source interface. Through forced air convection by the fan, the heat in the ambient air is taken away, so that the server cabinet maintains a working temperature suitable for the operation of the server, the first switch and the bastion host; the server cabinet and the cabinet door can be made of metal to further enhance the heat dissipation effect.

[0045] In one embodiment, as Figure 7As shown, a network connection switching device 26 is provided between the first switch 2 and the second switch 5. The network connection switching device 26 includes a housing and a switching control board 27 installed inside the housing. The switching control board 27 is provided with a main network interface 28, a first interface 29, a second interface 30, a third interface 31, a full network connection button 32, a first connection button 33, a second connection button 34, and a third connection button 35. The main network interface 28 is connected to the first switch 2, the first interface 29 is connected to the second switch 5. The second switch 5 is a local area network switch. The second interface 30 is connected to a government network terminal 36 through the government extranet, and the third interface 31 is connected to an Internet terminal 37 through the Internet. The full network connection button 32 controls the first switch 2 to be connected to the second switch 5, the government extranet, and the Internet simultaneously. The first connection button 33 controls the first switch 2 to be only connected to the second switch 5. The second connection button 34 controls the first switch 2 to be only connected to the government extranet. The third connection button 35 controls the first switch 2 to be only connected to the Internet.

[0046] The working principle and beneficial effects of the above technical solution are as follows: In this solution, a network connection switching device is provided, including a housing and a switching control board installed inside the housing. The switching control board is provided with a main network interface, a first interface, a second interface, a third interface, a full network connection button, a first connection button, a second connection button, and a third connection button. The housing is provided with avoidance holes for the main network interface, the first interface, the second interface, the third interface, the full network connection button, the first connection button, the second connection button, and the third connection button. When it is necessary to connect to the local area network, the government extranet, and the Internet simultaneously, pressing the full network connection button can achieve this. Pressing the first connection button, the second connection button, or the third connection button respectively can achieve separate connections to the local area network, the government extranet, or the Internet. By setting the network connection switching device, the three-network (local area network, government extranet, and Internet) selection and switching of the data sandbox system are realized, with simple and convenient operation and easy control.

[0047] In one embodiment, the first camera 12, the second camera 13, and the third camera 14 all use digital cameras with a pixel count of not less than 5 million pixels. The monitoring terminal 16 is connected to an alarm.

[0048] The working principle and beneficial effects of the above technical solution are as follows: In this solution, it is specified that the first camera, the second camera, and the third camera all adopt digital cameras with a pixel count of not less than 5 million pixels to ensure the clarity of the images captured by video surveillance, enhance the recognizability of the images, and improve the surveillance effect; by connecting the monitoring terminal to an alarm, the alarm can be a buzzer. When the surveillance detects an unauthorized person breaking in, or someone breaking into a restricted area without permission, or someone engaging in a pre-set behavior that violates safety management, an alarm is issued through the alarm, which can prompt the security management personnel to pay attention or take corresponding measures in a timely manner.

[0049] Obviously, those skilled in the art can make various changes and modifications to the present utility model without departing from the spirit and scope of the present utility model. Thus, if these modifications and variations of the present utility model fall within the scope of the claims of the present utility model and their equivalent technologies, the present utility model also intends to include these modifications and variations.

Claims

1. A local networking structure of a data sandbox with high security, characterized in that, It includes a local area network core device and multiple local user terminals (6) that are physically isolated from it in space. The local area network core device includes a server (1), a first switch (2), a bastion host (3), a management terminal (4), and a second switch (5); the first switch (2) is respectively connected to the server (1), the bastion host (3), the management terminal (4), and the second switch (5); the second switch (5) is respectively connected to multiple local user terminals (6); the local user terminals (6) are computer devices with external data interfaces removed or blocked, and the management terminal (4) is provided with an external data interface (7).

2. The data sandbox local networking structure with high security according to claim 1, wherein Multiple servers (1) are provided and are interconnected through a third switch (8), and the first switch (2) is connected to the servers (1) through the third switch (8).

3. The data sandbox local networking structure with high security according to claim 1, characterized in that The first switch (2) is also connected to a video monitoring subsystem. The video monitoring subsystem includes an optical network unit (11), a first camera (12), a second camera (13), a third camera (14), an optical line terminal (15), and a monitoring terminal (16); The first switch (2) is respectively connected to the optical line terminal (15) and the monitoring terminal (16). The optical line terminal (15) is connected to the optical network unit (11) by optical fiber, and the optical network unit (11) is respectively connected to the first camera (12), the second camera (13), and the third camera (14); The first camera (12) is installed facing the area of the management terminal (4); the second camera (13) is installed facing the area of the local user terminals (6); the third camera (14) is installed facing the area of the server (1).

4. The local networking structure of the data sandbox with high security according to claim 1, characterized in that, The management terminal (4) is a desktop computer device including a computer mainframe, and the external data interface (7) is provided on the computer mainframe; the computer mainframe is installed in a security box (9), and the security box (9) is provided with a security lock (10).

5. The data sandbox local networking structure with high security according to claim 3, characterized in that, The monitoring terminal (16) is connected to a data collector (19), the data collector (19) is connected to a face recognition device (17), and the face recognition device (17) is set at the access control position.

6. The data sandbox local networking structure with high security according to claim 5, characterized in that The data collector (19) is connected to a temperature measuring instrument (18). The temperature measuring instrument (18) is a non-contact temperature measuring instrument, and the temperature measuring instrument (18) is set at the access control position.

7. The high-security data sandbox local area networking structure according to claim 4, characterized in that The housing of the security box (9) is provided with a ventilation opening. The ventilation opening is installed with a shutter (20) by riveting or welding. A exhaust fan is installed inside the ventilation opening, and the exhaust fan is electrically connected to the computer mainframe of the management terminal (4).

8. The data sandbox local networking structure with high security according to claim 6, characterized in that, The server (1), the first switch (2) and the bastion host (3) are installed in the server cabinet (21); the server cabinet (21) includes a cabinet door (22), and the cabinet door (22) includes a housing, a blower (23) and a heat exchanger. The heat exchanger is installed in the housing, the blower (23) is installed on the outer surface of the housing, the heat exchanger is provided with a cold source interface (25), a temperature sensor is installed inside the server cabinet (21), and the blower (23) and the temperature sensor are connected to a data collector (19).

9. The high-security data sandbox local area networking structure according to claim 1, wherein A network connection switching device (26) is arranged between the first switch (2) and the second switch (5). The network connection switching device (26) includes a housing and a switching control board (27) installed in the housing. The switching control board (27) is provided with a main network interface (28), a first interface (29), a second interface (30), a third interface (31), a full network connection button (32), a first connection button (33), a second connection button (34) and a third connection button (35); the main network interface (28) is connected to the first switch (2), the first interface (29) is connected to the second switch (5), the second switch (5) is a local area network switch, the second interface (30) is connected to a government network terminal (36) through a government extranet, and the third interface (31) is connected to an Internet terminal (37) through the Internet; the full network connection button (32) controls the first switch (2) to be simultaneously connected to the second switch (5), the government extranet and the Internet, the first connection button (33) controls the first switch (2) to be only connected to the second switch (5), the second connection button (34) controls the first switch (2) to be only connected to the government extranet, and the third connection button (35) controls the first switch (2) to be only connected to the Internet.

10. The high-security data sandbox local area networking structure according to claim 3, wherein The first camera (12), the second camera (13) and the third camera (14) all adopt digital cameras with a pixel count of not less than 5 million pixels; the monitoring terminal (16) is connected to an alarm.