Network space data security isolation device
By designing a cyberspace data security isolation device and adopting an automatic switching network card and alternating relay mode, the security problem of data exchange in different network environments is solved, realizing secure data isolation and fixed-point connection, and improving the security and integrity of data transmission.
Patent Information
- Application Number
- CN202423299283.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2034-12-31
AI Technical Summary
Existing geographic information data exchange platforms lack security in different network environments, especially in data exchange between institutional intranets and extranets where effective security isolation is difficult to achieve, and there is a risk of unauthorized users stealing or tampering with data.
Design a cyberspace data security isolation device, comprising a chassis, heat dissipation unit, input/output unit, motherboard unit, central processing unit, memory unit, hard disk unit, first network card unit and second network card unit. It achieves secure data isolation and fixed-point connection through automatic network card switching function, uses an alternating relay mode for data transmission, and interconnects through specific ports and network protocols.
It achieves secure data isolation in different network environments, improves the security of data exchange, prevents unauthorized access, and ensures the security and integrity of data transmission.
Smart Images

Figure CN223599873U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of spatial data sharing and exchange technology, and in particular to a network space data security isolation device. Background Technology
[0002] Data exchange technology is the technological foundation for integrating information resources using networks and an effective way to solve information sharing and updating. With the widespread application of geographic information technology in various industries, different fields have posed significant challenges to the secure sharing and exchange of spatial data resources. How to achieve secure sharing and exchange of heterogeneous spatial data resources, break down "information silos," and improve the efficiency of data sharing applications has become a current development trend.
[0003] Specifically, the technology for sharing and exchanging multi-source heterogeneous spatial data is a key link in solving the problem of mutual sharing and application of geographic information technology across different fields. Currently, the main approach to solving spatial data sharing and exchange between different fields is through a geographic information public service platform, which is both a distributed virtual information space and a centralized service system. However, due to inconsistencies in existing geographic electronic information systems regarding security platforms, application environments, data storage environments, and exchange standards, many difficulties arise in geographic information data exchange.
[0004] Currently, the main problems in geographic information data exchange are: how to ensure isolated data exchange, how to exchange heterogeneous data, how to exchange data between networks with different information access levels in a vertical system, how to exchange and share data between horizontally interconnected or physically isolated networks, and how to conduct cross-regional exchange, etc.
[0005] Based on this, patent document CN101431461A discloses an urban spatial information sharing platform, which includes a public information communication network, a spatial information exchange network, public spatial information resources and a comprehensive spatial database, a spatial information standard and specification module, spatial information management regulations, and institutional and user system modules; public spatial information resources are the core of the system, and the multi-level network management structure and institutional and user system modules exchange data with the public spatial information resources; the public information communication network includes a spatial metadata management system, a spatial information sharing platform service system, a spatial decision-making model sharing service system, a spatial information browsing and query service system, a spatial data conversion system, a spatial data compression and network transmission system, and a spatial data acquisition system.
[0006] Furthermore, another Chinese utility model patent CN220935201U discloses a geographic information data exchange platform, which includes a body. A cooling fan is provided on the right side of the body, and a data port is provided on the back of the body. A data plug is provided on the inner side of the data port. The data port includes three connection ports on the back of the body. One end of each of the three connection ports is fixedly connected to the back of the body. Crossbars are provided on the front and rear sides of the top of each connection port. Fixing plates are fixedly connected to both ends of two of the crossbars. The bottoms of the four fixing plates are fixedly connected to the four corners of the top of the connection port. Two sliding plates are provided between the two crossbars. The front and rear ends of the two sliding plates are slidably connected to the left and right ends of the surfaces of the two crossbars, respectively. The connection head and the connection port can be firmly connected to avoid accidental separation.
[0007] However, the aforementioned data exchange platforms still suffer from insufficient security. Specifically, spatial data sharing and exchange are relatively easy to achieve within the same network environment, such as data exchange between different departments within the same organization or entity's intranet; however, data exchange between different network environments, such as between an organization's or entity's intranet and external network, is more difficult to resolve. Furthermore, some unauthorized users may use illegal means to commit illegal acts during spatial data access, such as theft or tampering, in order to obtain spatial data information. Therefore, it is necessary to implement necessary security isolation between the sharing layers of network spatial data. Utility Model Content
[0008] Therefore, it is necessary to provide a cyberspace data security isolation device to address the technical issue of how to improve the security of shared data in space.
[0009] A cyberspace data security isolation device includes: a chassis, a heat dissipation unit, an input / output unit, a motherboard unit, a central processing unit (CPU), a memory unit, a hard disk unit, a first network interface card (NIC) unit, and a second NIC unit. The heat dissipation unit is disposed on one side of the chassis, and the input / output unit is disposed on the other side of the chassis. The motherboard unit, the CPU, the memory unit, the hard disk unit, the first NIC unit, and the second NIC unit are disposed within the chassis. The CPU, the memory unit, the first NIC unit, and the second NIC unit are respectively connected to the motherboard unit. The hard disk unit is disposed on an inner side of the chassis relative to the motherboard unit, and the hard disk unit is connected to the motherboard unit.
[0010] Furthermore, the chassis has a chassis shell, a grille panel, an input / output panel, and an air intake section.
[0011] Furthermore, the grille panel is provided on one side of the chassis housing, and the input / output panel is provided on the other side of the chassis housing relative to the grille panel.
[0012] Furthermore, the motherboard unit is connected to the inside of the input / output panel, and the input / output unit is connected to the outside of the input / output panel.
[0013] Furthermore, the air intake is disposed between the grille panel and the input / output panel.
[0014] Furthermore, the heat dissipation unit is provided with a first heat dissipation fan structure and a second heat dissipation fan structure.
[0015] Furthermore, the first cooling fan structure is disposed on the side of the grille panel shown, and the second cooling fan structure is disposed on the other side of the chassis housing relative to the air intake portion.
[0016] Furthermore, the input / output unit is equipped with several connectors, a first network card port, a second network card port, and several indicator light modules.
[0017] Furthermore, several of the connectors are evenly distributed in the input / output panel, and each connector is connected to the motherboard unit.
[0018] Furthermore, the first network card port is electrically connected to the first network card unit, and the second network card port is electrically connected to the second network card unit; a plurality of indicator light modules are evenly arranged in the input / output panel, and each indicator light module is electrically connected to the motherboard unit respectively.
[0019] In summary, this utility model discloses a network space data security isolation device comprising a chassis, a heat dissipation unit, an input / output unit, a motherboard unit, a central processing unit (CPU), a memory unit, a hard disk unit, a first network interface card (NIC) unit, and a second NIC unit. The heat dissipation unit is located on one side of the chassis, and the input / output unit is located on the other side. The motherboard unit, CPU, memory unit, hard disk unit, first NIC unit, and second NIC unit are housed within the chassis. The CPU, memory unit, first NIC unit, and second NIC unit are respectively connected to the motherboard unit. The hard disk unit is located on an inner side of the chassis relative to the motherboard unit and is connected to the motherboard unit. This utility model's network space data security isolation device can automatically switch NICs. During data extraction, it automatically switches NICs. Its preset operating program can first close its network connection with the switching management center; then, it reopens its network connection with the shared switching platform and connects to the shared switching platform's data server for data extraction. Once data extraction is complete, the network connection between the data source and the shared exchange platform is first closed, then the network connection between the data source and the exchange management center is opened, and finally, the data is uploaded. Therefore, this utility model's network space data security isolation device can achieve secure isolation and fixed-point connection of network space data, thereby improving the security of shared data in space. Thus, this utility model's network space data security isolation device solves the technical problem of how to improve the security of shared data in space. Attached Figure Description
[0020] Figure 1 This is a schematic diagram of the structure of a network space data security isolation device according to the present invention;
[0021] Figure 2 This is a schematic diagram of another part of the structure of the network space data security isolation device of this utility model;
[0022] Figure 3 This is a schematic diagram of the structure of a network space data security isolation device of this utility model from another direction. Detailed Implementation
[0023] To make the above-mentioned objects, features, and advantages of this utility model more apparent and understandable, the specific embodiments of this utility model will be described in detail below with reference to the accompanying drawings. Many specific details are set forth in the following description to provide a full understanding of this utility model. However, this utility model can be implemented in many other ways different from those described herein, and those skilled in the art can make similar modifications without departing from the spirit of this utility model. Therefore, this utility model is not limited to the specific embodiments disclosed below.
[0024] In the description of this utility model, it should be understood that the terms "center", "longitudinal", "transverse", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise", "axial", "radial", "circumferential", etc., indicating the orientation or positional relationship are based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing this utility model and simplifying the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this utility model.
[0025] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this utility model, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0026] In this utility model, unless otherwise explicitly specified and limited, the terms "installation," "connection," "joining," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this utility model according to the specific circumstances.
[0027] In this utility model, unless otherwise explicitly specified and limited, "above" or "below" the second feature can mean that the first feature is in direct contact with the second feature, or that the first feature is in indirect contact with the second feature through an intermediate medium. Furthermore, "above," "on top of," and "over" the second feature can mean that the first feature is directly above or diagonally above the second feature, or simply that the first feature is at a higher horizontal level than the second feature. "Below," "below," and "under" the second feature can mean that the first feature is directly below or diagonally below the second feature, or simply that the first feature is at a lower horizontal level than the second feature.
[0028] It should be noted that when an element is referred to as being "fixed to" or "set on" another element, it can be directly on the other element or there may be an intervening element. When an element is considered to be "connected to" another element, it can be directly connected to the other element or there may be an intervening element. The terms "vertical," "horizontal," "upper," "lower," "left," "right," and similar expressions used herein are for illustrative purposes only and do not represent the only possible implementation.
[0029] Specifically, a data sharing and exchange system that can improve the security performance of cyberspace data includes a switching center, a switching front-end server, and a security isolation device. Its working principle is as follows: In an intranet environment, the shared switching platform database connects to the switching center through the switching platform front-end server and the security isolation device; in a heterogeneous network environment, such as an external network environment dedicated to external user access, the spatial database connects to the switching center through the application system front-end server and the security isolation device. The data transmission between the switching center and the switching front-end server can adopt an alternating relay mode for secure data transmission.
[0030] More specifically, in the aforementioned alternating relay mode, completing one data exchange requires five steps, as follows:
[0031] S1: At the beginning, the security isolation devices between the front-end switch and the switching center, and between the switching center and the application system front-end switch, are in the disconnected state. The front-end switch extracts the data to be switched from the shared switching database according to the preset rules.
[0032] S2: Next, the security isolation device between the front-end switch and the switching center is connected to transmit the data to the switching center;
[0033] S3: Disconnect the security isolation device between the front-end switch and the switching center;
[0034] S4: A secure isolation device connecting the switching center and the application system front-end machine, downloading data from the switching center;
[0035] S5: Disconnect the security isolation device between the exchange center and the application system front-end machine, and update the downloaded data to the thematic spatial information database according to the preset rules.
[0036] Similarly, if the data is being uploaded from a thematic spatial information database to a shared exchange platform database, the above steps are simply reversed.
[0037] Therefore, please refer to the following: Figures 1 to 3This utility model discloses a network space data security isolation device, comprising: a chassis 1, a heat dissipation unit 2, an input / output unit 3, a motherboard unit 4, a central processing unit 5, a memory unit 6, a hard disk unit 7, a first network card unit 8, and a second network card unit 9; the heat dissipation unit 2 is disposed on one side of the chassis 1, and the input / output unit 3 is disposed on the other side of the chassis 1; the motherboard unit 4, the central processing unit 5, the memory unit 6, the hard disk unit 7, the first network card unit 8, and the second network card unit 9 are disposed within the chassis 1; the central processing unit 5, the memory unit 6, the first network card unit 8, and the second network card unit 9 are respectively connected to the motherboard unit 4; the hard disk unit 7 is disposed on an inner side of the chassis 1 relative to the motherboard unit 4, and the hard disk unit 7 is connected to the motherboard unit 4.
[0038] Specifically, a high-security data sharing and exchange system can adopt a structure of one exchange management center and multiple exchange front-end systems, with each exchange front-end system installed in a corresponding exchange front-end machine. Specifically, after the exchange front-end system uploads data, it can be directly stored in the exchange management center, while other exchange front-end machines can conveniently update the data at any time without waiting for the data provider's front-end machine to run.
[0039] The aforementioned management functions of the exchange management center mainly include: managing or registering exchange front-end machines, managing exchangeable data resources, authorizing exchangeable data resources (i.e., determining which exchange front-end machines can access or download which resources, or which resources can be accessed by which exchange front-end machines); exchange front-end machine access includes searching, uploading, and downloading; verification; and log management. The exchange management center can only be accessed passively; that is, only exchange front-end machines can actively access the exchange management center, and the exchange management center cannot actively access exchange front-end machines. Furthermore, communication between each exchange front-end machine and the exchange management center can be bridged by the network space data security isolation device described in this utility model, and this network space security isolation device can operate on specific ports and based on specific network protocols, thus further improving the security of data exchange. Moreover, the exchange management center administrator can view the data upload and download status in real time and query specific data such as the amount of data uploaded, downloaded, upload time, download time, and data updates within a specified time period.
[0040] Therefore, in the technical solution of the network space data security isolation device of this utility model, it can be interconnected with the aforementioned front-end switching machine to serve as a secure isolation connection bridge for network space data; it can be interconnected with the front-end switching machine based on a specific port and a specific network protocol. Specifically, a first network card unit 8 and a second network card unit 9 are respectively provided on the motherboard unit 4, thereby forming a dual-network card connection network management mode. The first network card unit 8 is connected to the shared switching platform database to realize the push of data from the shared switching platform database to the aforementioned front-end switching machine; the second network card unit 9 is connected to the aforementioned switching management center and can store the received data in the memory to the hard disk unit 6 or the hard disk unit 7.
[0041] In one specific embodiment, the functions of the aforementioned front-end switching unit can be combined with the network space data security isolation device of this invention, with both sharing the same hardware system, such as motherboard, CPU, memory modules, and hard disk; alternatively, it can use an independent hardware system and then interconnect with the network space data security isolation device of this invention through specific ports.
[0042] Therefore, when using the network space data security isolation device of this utility model to push and receive data, the data can be stored either in the memory unit 6 and the hard disk unit 7 provided in the network space data security isolation device of this utility model, or in the aforementioned front-end switching machine.
[0043] In summary, this utility model's network space data security isolation device can automatically switch network cards (NICs). During data extraction, it automatically switches NICs, and its preset operating program first closes the network connection with the switching management center; then, it opens the network connection with the shared switching platform and connects to the shared switching platform's data server for data extraction. Once data extraction is complete, it first closes the network connection with the shared switching platform, then opens the network connection with the switching management center, and finally uploads the data. Therefore, this utility model's network space data security isolation device can achieve secure isolation and fixed-point connection of network space data, thereby improving the security of shared data in the space.
[0044] Furthermore, in the practical operation of this network space data security isolation device, it was found that the hard disk unit 7 and the central processing unit 5 are the largest heat sources, which can seriously affect the stability of the system. Therefore, this network space data security isolation device proposes an efficient heat dissipation solution: the heat dissipation unit 2 is installed on the side of the chassis 1, and the hard disk unit 7 is positioned on another wall inside the chassis 1 relative to the motherboard unit 4. The hard disk unit 7 is then interconnected with the motherboard unit 4 via cables. This creates a smooth airflow within the chassis 1, and in the active cooling mode of the heat dissipation unit 2, the heat accumulated inside the chassis 1 can be quickly dissipated.
[0045] Furthermore, the chassis 1 has a chassis shell 101, a grille panel 102, an input / output panel 103, and an air duct 104; the grille panel 102 is disposed on one side of the chassis shell 101, the input / output panel 103 is disposed on the other side of the chassis shell 101 opposite to the grille panel 102, the motherboard unit 4 is connected to the inner side of the input / output panel 103, and the input / output unit 3 is connected to the outer side of the input / output panel 103; the air duct 104 is disposed between the grille panel 102 and the input / output panel 103.
[0046] Furthermore, the heat dissipation unit 2 is provided with a first heat dissipation fan structure 201 and a second heat dissipation fan structure 202; the first heat dissipation fan structure 201 is provided on the side of the grille panel 102 shown, and the second heat dissipation fan structure 202 is provided on the other side of the chassis housing 101 relative to the air intake part 104.
[0047] Specifically, to improve heat accumulation inside the chassis 1, the chassis shell 101 serves as the housing structure. A grille panel 102 and an input / output panel 103 are positioned opposite each other on one side of the chassis shell 101. The motherboard unit 4, which outputs heat, is positioned close to the inner side of the input / output panel 103, i.e., within the chassis shell 101. The input / output unit 3 is positioned on the other side of the input / output panel 103 and electrically connected to the motherboard unit 4. More specifically, the first cooling fan structure 201 is a dual-fan parallel structure, which can deliver airflow perpendicular to the motherboard unit 4. The second cooling fan structure 202 is a single-fan structure, and its oppositely positioned air intake 104 is a grille-equipped airflow structure, allowing airflow while also preventing dust. Based on this, the cross-flow cooling channel formed by the first cooling fan structure 201 and the second cooling fan structure 202 enables rapid heat dissipation.
[0048] Furthermore, the input / output unit 3 is provided with a plurality of connectors 301, a first network card port 302, a second network card port 303, and a plurality of indicator light modules 304; the plurality of connectors 301 are evenly distributed in the input / output panel 103, and each connector 301 is connected to the motherboard unit 4; the first network card port 302 is electrically connected to the first network card unit 8, and the second network card port 303 is electrically connected to the second network card unit 9; the plurality of indicator light modules 304 are evenly arranged in the input / output panel 103, and each indicator light module 304 is electrically connected to the motherboard unit 4 respectively.
[0049] Specifically, the contact 301 typically includes a power connector, a signal input / output connector, and a data input / output connector; the first network card port 302 and the second network card port 303 are used to connect to an external shared switching platform database or an external switching management center, respectively. The indicator light module 304 is used to display different operating modes, such as idle, data processing, or alarm mode.
[0050] In summary, the network space data security isolation device of this utility model is provided with a chassis 1, a heat dissipation unit 2, an input / output unit 3, a motherboard unit 4, a central processing unit 5, a memory unit 6, a hard disk unit 7, a first network card unit 8, and a second network card unit 9. The heat dissipation unit 2 is arranged on one side of the chassis 1, and the input / output unit 3 is arranged on the other side of the chassis 1. The motherboard unit 4, the central processing unit 5, the memory unit 6, the hard disk unit 7, the first network card unit 8, and the second network card unit 9 are arranged inside the chassis 1. The central processing unit 5, the memory unit 6, the first network card unit 8, and the second network card unit 9 are respectively connected to the motherboard unit 4. The hard disk unit 7 is arranged on one inner side of the chassis 1 relative to the motherboard unit 4, and the hard disk unit 7 is connected to the motherboard unit 4. This utility model discloses a network space data security isolation device that can automatically switch network cards. During data extraction, it automatically switches network cards. Its preset operating program first closes the network connection with the switching management center; then, it opens the network connection with the shared switching platform and connects to the data server of the shared switching platform for data extraction. When data extraction is complete, it first closes the network connection with the shared switching platform, then opens the network connection with the switching management center, and finally uploads the data. Therefore, this utility model's network space data security isolation device can achieve secure isolation and fixed-point connection of network space data, thereby improving the security of shared data in space. Thus, this utility model's network space data security isolation device solves the technical problem of how to improve the security of shared data in space.
[0051] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0052] The embodiments described above are merely illustrative of several implementations of this utility model, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the utility model patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this utility model, and these all fall within the protection scope of this utility model. Therefore, the protection scope of this utility model patent should be determined by the appended claims.
Claims
1. A network space data security isolation device, characterized in that, It includes: a chassis (1), a heat dissipation unit (2), an input / output unit (3), a motherboard unit (4), a central processing unit (5), a memory unit (6), a hard disk unit (7), a first network card unit (8), and a second network card unit (9); the heat dissipation unit (2) is arranged on one side of the chassis (1), and the input / output unit (3) is arranged on the other side of the chassis (1); the motherboard unit (4), the central processing unit (5), the memory unit (6), the hard disk unit (7), the first network card unit (8), and the second network card unit (9) are arranged in the chassis (1); the central processing unit (5), the memory unit (6), the first network card unit (8), and the second network card unit (9) are respectively connected to the motherboard unit (4); the hard disk unit (7) is arranged on one inner side of the chassis (1) relative to the motherboard unit (4), and the hard disk unit (7) is connected to the motherboard unit (4).
2. The network space data security isolation device according to claim 1, characterized in that: The chassis (1) has a chassis shell (101), a grille panel (102), an input / output panel (103), and an air intake (104).
3. A network space data security isolation device according to claim 2, characterized in that: The grille panel (102) is provided on one side of the chassis housing (101), and the input / output panel (103) is provided on the other side of the chassis housing (101) opposite to the grille panel (102).
4. A network space data security isolation device according to claim 3, characterized in that: The motherboard unit (4) is connected to the inside of the input / output panel (103), and the input / output unit (3) is connected to the outside of the input / output panel (103).
5. A network space data security isolation device according to claim 4, characterized in that: The air intake section (104) is disposed between the grille panel (102) and the input / output panel (103).
6. A network space data security isolation device according to claim 5, characterized in that: The heat dissipation unit (2) is provided with a first heat dissipation fan structure (201) and a second heat dissipation fan structure (202).
7. A network space data security isolation device according to claim 6, characterized in that: The first cooling fan structure (201) is disposed on the side of the grille panel (102) shown, and the second cooling fan structure (202) is disposed on the other side of the chassis housing (101) opposite to the air intake part (104).
8. A network space data security isolation device according to claim 7, characterized in that: The input / output unit (3) is provided with several connectors (301), a first network card port (302), a second network card port (303), and several indicator light modules (304).
9. A network space data security isolation device according to claim 8, characterized in that: Several connectors (301) are evenly distributed in the input / output panel (103), and each connector (301) is connected to the motherboard unit (4).
10. A network space data security isolation device according to claim 9, characterized in that: The first network card port (302) is electrically connected to the first network card unit (8), and the second network card port (303) is electrically connected to the second network card unit (9); a plurality of indicator light modules (304) are evenly arranged in the input / output panel (103), and each indicator light module (304) is electrically connected to the main board unit (4).
Citation Information
Patent Citations
City spacing information sharing platform
CN101431461A
Geographic information data exchange platform
CN220935201U