Electronic information safety monitoring system based on computer network
By constructing multiple protection measures through triggering devices, isolation devices, and authentication systems, and combining them with local area networks and alarms, the system solves the problem of insufficient security in existing computer network security systems, enabling timely alarms and authentication, and ensuring network security.
Patent Information
- Application Number
- CN202423085825.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2034-12-13
AI Technical Summary
Existing computer network security systems fail to issue timely alerts after firewalls are breached, lack authentication procedures, and cannot proactively detect transmitted information, resulting in poor security performance.
Multiple protection measures are constructed by employing triggering devices, isolation devices, and authentication systems. Combined with the first and second regional local area networks, comprehensive protection is achieved through alarms, isolating switch modules, and SoC on-chip systems, enabling autonomous information collection and identity verification.
It enables timely alerts when unsafe information is detected, autonomously collects and transmits information, and ensures network security through multiple protection measures, including authentication and network connectivity support.
Smart Images

Figure CN223553338U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of electronic information technology, and more specifically to an electronic information security monitoring system based on computer networks. Background Technology
[0002] With the rapid development of computer and network communication technologies, the widespread application of computer networks in various fields has greatly improved user work efficiency and made daily life more convenient. Users on opposite sides of the globe can communicate with each other via the internet. However, while the internet brings enormous benefits to users, hackers have begun to attack servers and databases through network viruses, causing huge losses to legitimate users. Due to the high speed of network transmission, even with numerous firewall and antivirus software programs, vulnerabilities still exist, allowing hackers to exploit them for attacks. Current technology often uses a single firewall to protect the entire system, making it easy for hackers to manipulate the system if they understand its vulnerabilities, resulting in relatively poor security.
[0003] For example, Chinese Patent Publication No. CN 207070092 U discloses a computer network information security system, including an external network, an outer firewall, a system risk assessment module, a network isolator, and an access control server. One end of the external network is connected to the outer firewall, one end of the outer firewall is connected to an inner firewall, the other end of the outer firewall is connected to the system risk assessment module, one end of the system risk assessment module is connected to a data decompressor, one end of the inner firewall is connected to the network isolator, one end of the network isolator is connected to the access control server, one end of the access control server is connected to a data compressor, and the other end of the access control server is connected to a database. However, in use, if an insecure situation occurs, it cannot promptly alert the user through an alarm, and it cannot actively detect transmitted information. For example, Chinese Patent Publication No. CN 209070534 U discloses a computer network information security system that can only issue an alarm when insecure information is detected, only verifying the information but not identifying the identity, lacking an identity verification step, resulting in poor security performance, and failing to guarantee basic network connectivity when a threat occurs.
[0004] Therefore, how to propose an electronic information security monitoring system based on computer networks, construct multiple protection measures through triggering devices, isolation devices and authentication systems to provide comprehensive protection, and support full network connectivity of protection measures by setting up a first regional local area network and a second regional local area network are problems that urgently need to be solved by those skilled in the art. Utility Model Content
[0005] In view of this, the present invention provides an electronic information security monitoring system based on a computer network. This system employs multiple protection measures, including triggering devices, isolation devices, and authentication systems, to provide comprehensive protection. Furthermore, it supports full network connectivity of these protection measures through the establishment of a first regional local area network (LAN) and a second regional LAN. To achieve the above objectives, the present invention adopts the following technical solution:
[0006] An electronic information security monitoring system based on a computer network includes: a main network access port, a triggering device, an isolation device, an authentication system, a switch, a network surge protection module, a first regional local area network (LAN), and a second regional LAN. The main network access port is connected to the triggering device, the isolation device, and the network surge protection module via signals. The triggering device is connected to the isolation device via signals. The isolation device is connected to the authentication system via signals. The authentication system is connected to the first regional LAN via signals through the switch. The network surge protection module is connected to the switch via signals through the second regional LAN.
[0007] Optionally, the triggering device includes a driver module and an output triggering module. The driver module is signal-connected to the output triggering module, the output triggering module is signal-connected to the network access port, and the driver module is signal-connected to the isolation device.
[0008] Optionally, the isolation device includes a hazard assessment module, a main controller, a drive controller module, and a disconnect switch module. One end of the hazard assessment module is connected to the main network port, and the other end is connected to the main controller. The main controller is signal-connected to the disconnect switch module through the drive controller module.
[0009] Optionally, it also includes an alarm, which is an audible and visual alarm, and the alarm is signal-connected to the main controller.
[0010] Optionally, it may also include a first memory, which is signal-connected to the main controller.
[0011] Optionally, the authentication system includes a firewall and a SoC (System-on-a-Chip), with the firewall signal-connected to the SoC.
[0012] Optionally, a second memory may also be included, which is connected to the SoC on-chip system signals.
[0013] Optionally, it may also include a power supply module, which is electrically connected to the SoC on-chip system.
[0014] Optionally, the SoC provides authentication protocols conforming to RFC2865 and RFC4511 specifications, and supports Portal authentication system, private identity authentication system, and hybrid authentication systems of different identities.
[0015] As can be seen from the above technical solution, compared with the prior art, this utility model discloses an electronic information security monitoring system based on a computer network, which has the following beneficial effects:
[0016] This invention proposes an electronic information security monitoring system based on a computer network, comprising: a main network access port, a triggering device, an isolation device, an authentication system, a switch, a network surge protection module, a first regional local area network (LAN), and a second regional LAN. The main network access port is signal-connected to the triggering device, the isolation device, and the network surge protection module, respectively. The triggering device is signal-connected to the isolation device. The isolation device is signal-connected to the authentication system. The authentication system is signal-connected to the first regional LAN via the switch. The network surge protection module is signal-connected to the switch via the second regional LAN. This invention, through the alarm setting, can trigger an alarm simultaneously upon detecting unsafe information, allowing users to receive alarm information promptly. Through the output trigger module setting, it can autonomously output and collect transmitted information, and autonomously judge the collected data. The SoC (System-on-a-Chip) provides authentication protocols conforming to RFC2865 and RFC4511 standards. Simultaneously, the SoC supports Portal authentication systems, private identity authentication systems, and hybrid authentication systems, thereby accepting authentication requests from network devices and security devices and verifying them through existing identity authentication procedures. This utility model constructs multiple protection measures through a triggering device, an isolation device, and an authentication system to provide comprehensive protection, and supports full network connectivity for protection measures by setting up a first regional local area network and a second regional local area network. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this utility model or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this utility model. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0018] Figure 1 This utility model provides a schematic diagram of the structure of an electronic information security monitoring system based on a computer network.
[0019] Figure 2 This is a schematic diagram of the SoC (System-on-a-Chip) structure provided by this utility model. Detailed Implementation
[0020] The technical solutions of the present utility model will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present utility model, and not all embodiments. Based on the embodiments of the present utility model, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of the present utility model.
[0021] This utility model discloses an electronic information security monitoring system based on a computer network, comprising: a main network access port, a triggering device, an isolation device, an authentication system, a switch, a network surge protection module, a first regional local area network (LAN), and a second regional LAN; the main network access port is signal-connected to the triggering device, the isolation device, and the network surge protection module respectively, and the triggering device is signal-connected to the isolation device; the isolation device is signal-connected to the authentication system, the authentication system is signal-connected to the first regional LAN via the switch, and the network surge protection module is signal-connected to the switch via the second regional LAN.
[0022] Furthermore, the triggering device includes a driver module and an output triggering module. The driver module is signal-connected to the output triggering module, the output triggering module is signal-connected to the main network port, and the driver module is signal-connected to the isolation device. Through the output triggering module, it can autonomously output and collect transmission information, and autonomously judge the collected data.
[0023] Furthermore, the isolation device includes a hazard assessment module, a main controller, a drive controller module, and a disconnect switch module. One end of the hazard assessment module is connected to the main network port, and the other end is connected to the main controller. The main controller is signal-connected to the disconnect switch module through the drive controller module.
[0024] Specifically, the disconnect switch module is an electromagnetic disconnect switch, and the electromagnetic disconnect switch is connected to the data line connectors between the main network port and the disconnect switch module. The function of the disconnect switch module is to connect or disconnect the main network port and the disconnect switch module. Specifically, the main network port includes multiple network input interfaces and multiple network output interfaces. The main network port is adapted to a signal surge protection module, which protects multiple input signals. The multiple network output interfaces are connected to the hazard assessment module, the disconnect switch module, and the network surge protection module, respectively. The signal surge protection module is a signal surge protector that detects overvoltage in the communication line and responds quickly when an overvoltage is detected, leading the overvoltage to the ground wire to protect the communication equipment from damage. It can effectively absorb and eliminate overvoltages generated by lightning strikes, preventing lightning damage to the communication line. It has a fast response characteristic, and can immediately activate the protection mechanism when an overvoltage or lightning strike is detected to protect the equipment in the communication line.
[0025] Furthermore, it also includes an alarm, which is an audible and visual alarm, and is signal-connected to the main controller. The audible and visual alarm includes a speaker assembly and an indicator light assembly. Through the alarm's settings, it can simultaneously detect unsafe information and trigger an alarm. The speaker assembly and indicator light assembly provide dual alerts, ensuring the user receives alarm information promptly.
[0026] Furthermore, it also includes a first memory, which is signal-connected to the main controller, and is used to store abnormal information and trust information.
[0027] Furthermore, the main controller is a Siemens S7-1200 / 1500 PLC controller, which is a programmable logic device used in industrial automation and control systems. It is used to receive monitoring data acquired by the monitoring module from the data acquisition module, and upload the received data to the server and data storage module for storage.
[0028] Furthermore, the authentication system includes a firewall and a SoC (System-on-a-Chip), the firewall being signal-connected to the SoC, and the firewall including an internal firewall and an external firewall.
[0029] Furthermore, it also includes a second memory, which is connected to the SoC on-chip system signal and is used to store abnormal information and authentication information.
[0030] Furthermore, it also includes a power supply module, which is electrically connected to the SoC on-chip system and outputs a 5V / 1A power supply.
[0031] Furthermore, the SoC provides authentication protocols conforming to RFC2865 and RFC4511 specifications, and supports Portal authentication system, private identity authentication system, and hybrid authentication systems of different identities.
[0032] Specifically, the SoC (System-on-a-Chip) includes the U1N chip, such as... Figure 2 As shown, the T5 pin of the U1N chip is connected in parallel with the power supply module and capacitor C9. The U5, W6, and V6 pins of the U1N chip are connected in parallel with capacitors C12, C164, and C13. The F18 pin of the U1N chip is connected to the J2 interface. The W16 and W18 pins of the U1N chip are grounded. The V8 pin of the U1N chip is connected in parallel with capacitor C10 and crystal oscillator X1. The other end of crystal oscillator X1 is connected to capacitor C11 and the U8 pin of the U1N chip. One end of capacitors C9, C12, C164, C13, C10, and C11 is grounded, and one end of the J2 interface is grounded. The F18 pin of the U1N chip receives an external start signal.
[0033] In a specific implementation, the network surge protection module is connected to the switch via a second local area network (LAN). The network surge protection module protects the second LAN from lightning strikes and overvoltage, ensuring the safe and stable operation of the network system and thus guaranteeing the accuracy of server data.
[0034] In a specific embodiment, the working principle of the triggering device and the isolation device in a computer network-based electronic information security monitoring system is as follows:
[0035] S1: Periodic collection and detection of information to be detected: The driver module periodically drives the output trigger module, and the output trigger module outputs a pre-programmed code. This code can combine the information transmitted on the main network port, and the combined data encoding information is transmitted to the hazard assessment module.
[0036] S2: Determine if the detected information is dangerous: Based on the data encoding information collected by the hazard assessment module received by the main controller in step S1, determine whether it is dangerous information: No: Repeat step S1 and continue detection; Yes: An unsafe information appears and enter the alert state.
[0037] S3: Stop information transmission and alarm: According to the alarm state entered in step S2, the main controller outputs an alarm through the alarm device and controls the isolation switch module to disconnect through the drive controller module, thereby disconnecting the transmission line between the main network port and the firewall.
[0038] In a specific implementation, this invention, through the setting of the output trigger module, can autonomously output and collect transmission information, and can autonomously judge the collected data information. The function of the isolation switch module is to connect or disconnect the main network port and the isolation switch module. The external firewall is set at the isolation switch module for the first layer of isolation. On this basis, through the setting of the alarm, it can play an alarm function when unsafe information is detected, so that users can receive alarm information in time. The internal firewall is set at the hard drive access point for the second layer of security protection. The SoC on-chip system provides authentication protocols of RFC2865 and RFC4511 specifications. At the same time, the SoC on-chip system supports the Portal authentication system, the private identity authentication system, and the hybrid system of different identity authentication systems, so as to accept authentication requests from network devices and security devices, and verify them through existing identity authentication programs for the third layer of protection. Through the trigger device, isolation device, and authentication system, multiple protection measures are constructed to provide comprehensive protection. Finally, the security information is exchanged with the first regional local area network through the switch.
[0039] Furthermore, the aforementioned computer network-based electronic information security monitoring system is applied to switches and interactive local area networks (LANs). These LANs are divided into multiple registered LANs as needed. Based on different security requirements during actual use, these LANs are categorized into two different levels: the first LAN is the working area with the highest security level; the second LAN is the external network server area with the lowest security level. Even after the isolating switch module disconnects the network connection of the first LAN, it is still necessary to ensure the normal internet access of the second LAN. Therefore, the second LAN is connected to the main network port through a network surge protector module to meet the requirements of full network connectivity.
[0040] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.
[0041] The above description of the disclosed embodiments enables those skilled in the art to make or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An electronic information security monitoring system based on a computer network, characterized in that, include: The system includes a main network access port, a triggering device, an isolation device, an authentication system, a switch, a network surge protection module, a first regional LAN, and a second regional LAN. The main network access port is connected to the triggering device, the isolation device, and the network surge protection module. The triggering device is connected to the isolation device. The isolation device is connected to the authentication system. The authentication system is connected to the first regional LAN via the switch. The network surge protection module is connected to the switch via the second regional LAN.
2. The electronic information security monitoring system based on a computer network according to claim 1, characterized in that, The triggering device includes a driver module and an output triggering module. The driver module is signal-connected to the output triggering module, the output triggering module is signal-connected to the network access port, and the driver module is signal-connected to the isolation device.
3. The electronic information security monitoring system based on a computer network according to claim 1, characterized in that, The isolation device includes a hazard assessment module, a main controller, a drive controller module, and a disconnect switch module. One end of the hazard assessment module is connected to the main network port, and the other end is connected to the main controller. The main controller is signal-connected to the disconnect switch module through the drive controller module.
4. The electronic information security monitoring system based on a computer network according to claim 3, characterized in that, It also includes an alarm, which is an audible and visual alarm, and the alarm is signal-connected to the main controller.
5. The electronic information security monitoring system based on a computer network according to claim 3, characterized in that, It also includes a first memory, which is signal-connected to the main controller.
6. The electronic information security monitoring system based on a computer network according to claim 1, characterized in that, The authentication system includes a firewall and a SoC (System-on-a-Chip), with the firewall and the SoC connected by signals.
7. The electronic information security monitoring system based on a computer network according to claim 6, characterized in that, It also includes a second memory, which is connected to the SoC on-chip system signal.
8. The electronic information security monitoring system based on a computer network according to claim 6, characterized in that, It also includes a power supply module, which is electrically connected to the SoC on-chip system.
9. The electronic information security monitoring system based on a computer network according to claim 6, characterized in that, The SoC provides authentication protocols conforming to RFC2865 and RFC4511 specifications, and supports Portal authentication system, private identity authentication system, and hybrid authentication systems of different identities.
Citation Information
Patent Citations
Computer network information safety coefficient
CN207070092U
A computer network information security system
CN209070534U