Internal and external network data security one-way transmission system and device

By using a series bridge device and employing a CPU chip, data security acceleration card, and database acceleration card, one-way encrypted data transmission between internal and external networks is achieved, solving the problem of insufficient data security in data transmission between internal and external networks and realizing secure isolation and data security between internal and external networks.

CN223809798UActive Publication Date: 2026-01-16STATISTICS BUREAU OF TIANQIAO DISTRICT JINAN CITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202520367424.5
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2026-01-16
Estimated Expiration
2035-03-04

AI Technical Summary

Technical Problem

Existing data transmission devices for internal and external networks cannot guarantee data security when the external network accesses the internal network, especially after network attacks breach network security devices, making the internal network server vulnerable to exposure.

Method used

By connecting two network bridge devices in series, one end connects to the internal network and the other end connects to the external network. The CPU chip, data security acceleration card and database acceleration card are used to realize one-way encrypted data transmission between the internal and external networks. The data acquisition module and storage module are connected to the internal and external network hosts through network interfaces respectively.

Benefits of technology

It enables secure one-way transmission of data between internal and external networks, ensuring complete isolation between internal network hosts and external network users, and guaranteeing data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223809798U_ABST
    Figure CN223809798U_ABST
Patent Text Reader

Abstract

The utility model relates to an internal and external network data security unidirectional transmission system and device, which belongs to the technical field of network data security, and comprises a first processor, and a data acquisition module, a data processing module and a data storage module which are respectively connected with the first processor, wherein the data acquisition module comprises a data receiving assembly and a data converter; and the data acquisition module and the data storage module are respectively connected with the intranet host and the extranet host through network interfaces so as to realize secure one-way transmission of intranet data and extranet data. According to the utility model, the two network bridge devices are connected in series, one end is connected with the intranet network, and the other end is connected with the extranet network, so that one-way data encryption transmission between the intranet network and the extranet network is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The utility model belongs to network data security technical field, concretely relates to a kind of internal and external network data security unidirectional transmission system and device. BACKGROUND

[0002] The statements herein provide only background information related to the utility model and do not necessarily constitute the prior art.

[0003] For data security requirements, some units need to establish internal network and internal data system simultaneously, and data storage, data monitoring and data analysis are also processed in internal system. If you want to access internal system through external network, retrieve data and monitor data, you need to use VPN encryption access technology. Under this design, external network user end is directly connected to internal network. At this time, the level of data security depends entirely on the protection strength and protection awareness of internal server, network firewall and external user end. When network attack breaks through network security equipment, all internal servers will be exposed. Therefore, the data security of the existing related device and component for realizing internal network data transmission through external network is not high, and it is difficult to ensure data security. UTILITY MODEL CONTENT

[0004] The utility model aims at providing a kind of internal and external network data security unidirectional transmission system and device, can be connected by the series connection of two net bridge devices, one end connects internal network, the other end connects external network, realizes the unidirectional data encryption transmission between internal network and external network.

[0005] A kind of internal and external network data security unidirectional transmission system, comprising:

[0006] First processor and data acquisition module, data processing module and data storage module connected with first processor respectively;Wherein, the data acquisition module includes data receiving component and data converter, specifically, the input end and output end of data receiving component are connected with external network interface and the input end of data converter respectively, the two output ends of data converter are connected with first processor and data processing module through internal bus and PCIE interface respectively;

[0007] The data acquisition module and data storage module are connected with internal host computer and external host computer respectively through network interface, to realize the safe unidirectional transmission of internal and external network data.

[0008] As a further technical solution, the first processor is CPU chip.

[0009] As a further technical solution, the data receiving component includes a WiFi signal receiver, a Bluetooth signal receiver and a network interface controller; wherein the input end of the WiFi signal receiver and the Bluetooth signal receiver is connected with an external device which does not transmit data through the network interface, and the input end of the network interface controller is connected with an internal network host through the network interface.

[0010] As a further technical solution, the data processing module is a data security acceleration card, and the model is NFP3800DPU.

[0011] As a further technical solution, the data security acceleration card is integrated with a data processing unit and a data security encryption and decryption unit, and is connected with the first processor through a PCIE interface.

[0012] As a further technical solution, the data storage module is a database acceleration card, and the model is CONFLUX TM -1900R; the database acceleration card is connected with the first processor through a PCIE interface; and the database acceleration card is integrated with a network interface card which is connected with an external network host through a network interface.

[0013] An internal and external network data security one-way transmission device includes a control mainboard, and the control mainboard is provided with a first processor mainboard and the internal and external network data security one-way transmission system.

[0014] As a further technical solution, the transmission device further includes a shell, and the control mainboard is fixed in the shell.

[0015] As a further technical solution, a double-row network interface is arranged outside the shell.

[0016] As a further technical solution, in the double-row network interface, one row is used for connecting an external network host, and the other row is used for connecting an internal network host; wherein each row of network interfaces includes a plurality of network interfaces, and each network interface can be connected with one host.

[0017] The beneficial effects of one or more of the above technical solutions are as follows:

[0018] The internal and external network data safe one-way transmission system provided by the utility model includes first treater, and data acquisition module, data processing module and data storage module connected with first treater respectively, wherein, data acquisition module and data storage module connect internal network host computer and external network host computer through network interface to realize safe one-way transmission of internal and external network data. BRIEF DESCRIPTION OF DRAWINGS

[0019] The drawings enclosed with the specification form a part of the application and serve to provide further understanding of the present application, the exemplary embodiments of the present application and the explanations thereof serve to explain the present application and do not constitute limitations to the present application.

[0020] Figure 1 It is a connection schematic view of the internal and external network data safe one-way transmission system in the utility model embodiment one.

[0021] Figure 2 It is a structure schematic view of the internal and external network data safe one-way transmission device in the utility model embodiment two. DETAILED DESCRIPTION

[0022] Embodiment one

[0023] The specific implementation of the present embodiment will be described below in combination with the drawings.

[0024] As Figure 1 described, the utility model embodiment provides a kind of internal and external network data safe one-way transmission system, comprising:

[0025] First treater, and data acquisition module, data processing module and data storage module connected with first treater respectively;Wherein, the data acquisition module includes data receiving component and data converter, specifically, the input end and the output end of the data receiving component are connected with the network interface outside and the input end of data converter respectively, two output ends of the data converter are connected with first treater and data processing module by internal bus and PCIE interface respectively;

[0026] The data acquisition module and data storage module connect internal network host computer and external network host computer through network interface to realize safe one-way transmission of internal and external network data.

[0027] The utility model provides a kind of inner and outer network data security unidirectional transmission system, can be connected by the series connection of two network bridge devices, one end connects inner network, the other end connects outer network, realizes the one-way data encryption transmission between inner network and outer network.

[0028] The embodiment provides a kind of inner and outer network data security unidirectional transmission system, including first processor, and respectively with the data acquisition module, data processing module and data storage module connected with first processor.

[0029] Wherein, the first processor is CPU chip, and model is Intel cool i9 13900K.Specifically, CPU chip is responsible for task scheduling, i.e.: when receiving the acquisition signal of data acquisition module is responsible for sending to data processing module, and the data after data module processing is sent to data storage module.It needs to be noted that the task scheduling function that CPU chip possesses in the embodiment is that any one CPU chip of existing can realize, therefore, the optimization and improvement of software function or code design are not involved in the utility model here, just utilize the hardware design of CPU chip to realize data transmission.

[0030] Wherein, data acquisition module includes data receiving component and data converter, specifically, the input end and the output end of data receiving component are connected with the network interface outside respectively and the input end of data converter, the two output ends of data converter are connected with first processor and data processing module by internal bus and PCIE interface respectively

[0031] Further, data receiving component includes WiFi signal receiver, bluetooth signal receiver and network interface controller;Wherein, the input end of WiFi signal receiver and bluetooth signal receiver is connected with external equipment without data transmission through network interface, and the input end of network interface controller is connected with inner network host through network interface.

[0032] Further, the data acquisition module is connected with the intranet host through a network interface, specifically, the data acquisition module is connected with the intranet host through the input end of the network interface controller; meanwhile, the input end of the WiFi signal receiver and the Bluetooth signal receiver is connected with the external equipment which does not transmit data through the network interface. Therefore, when the external equipment provided with the intranet cannot be connected in the form of the network interface, it can also be connected in the form of wireless or Bluetooth. In addition, it should be pointed out that the network interface mentioned in the embodiment is an Ethernet interface in the form of RJ-45 interface, but it can also be one or more of network interfaces including but not limited to RJ-11 interface, SC fiber interface, FDDI interface, AUI interface, BNC interface and Console interface, etc.

[0033] As shown in Figure 1 , the data processing module is connected with the first processor; specifically, the data processing module used in the utility model is a data security acceleration card, and the model number is NFP3800DPU.

[0034] Further, the data security acceleration card is integrated with a data processing unit and a data encryption and decryption unit, and is connected with the first processor through a PCIE interface. The data processing unit is used to analyze whether the collected data contains secret information, private information and non-public information according to the data security requirements, so that the data accessible to the external network is all safe data; the data encryption and decryption unit is used to encrypt or decrypt the data, thereby improving the data security.

[0035] It should be pointed out again that the data processing and data encryption and decryption functions of the data security acceleration card in the embodiment can be realized by any existing data security acceleration card, therefore, the utility model does not involve optimization and improvement of software functions or code design at this place.

[0036] As shown in Figure 1 , the data storage module is connected with the first processor and is connected with the external network host through a network interface, specifically, the data storage module used in the utility model is a database acceleration card, and the model number is CONFLUX TM -1900R (CONFLUX TM -1900R is a super high performance relational database operation acceleration card).

[0037] Further, the database acceleration card is connected with the first processor through a PCIE interface; meanwhile, the database acceleration card is integrated with a network interface card connected with the external network host through a network interface.

[0038] Thus, the internal and external network data security one-way transmission system can realize one-way data encryption transmission between the internal network and the external network through the series connection of the two network bridge devices, one end of which is connected with the internal network and the other end of which is connected with the external network.

[0039] Embodiment two

[0040] As Figure 2 shown, the utility model discloses a kind of internal and external network data security one-way transmission device, including control mainboard and casing.

[0041] Further, first processor mainboard is provided on control mainboard and a kind of internal and external network data security one-way transmission system as described in embodiment one;Wherein, control mainboard is fixed in casing interior.

[0042] Further, double-row network interface is provided on the outside of casing, to facilitate with internal network host and external network host are connected, specifically, in the double-row network interface, one row is used to connect external network host, another row is used to connect internal network host;Wherein, each row network interface includes multiple network interfaces, and each network interface can connect a host computer.

[0043] Although the specific embodiments of the utility model have been described above with reference to the drawings, it is not a limitation on the protection scope of the utility model, and those skilled in the art should understand that various modifications or deformations made by the skilled in the art without creative labor on the basis of the technical scheme of the utility model are still within the protection scope of the utility model.

Claims

1. An internal and external network data security one-way transmission system, characterized by, The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks.

2. The system of claim 1, wherein, The application relates to a one-way data transmission system for internal and external networks.

3. The system of claim 1, wherein the system further comprises a network address translator (NAT) device, and the NAT device is configured to: receive the first packet from the first network device; and transmit the first packet to the second network device. The application relates to a one-way data transmission system for internal and external networks.

4. The system of claim 1, wherein, The application relates to a one-way data transmission system for internal and external networks.

5. The system of claim 4, wherein, The application relates to a one-way data transmission system for internal and external networks.

6. The system of claim 1, wherein, The data storage module is a database acceleration card, model number is The database acceleration card is connected with the first processor through a PCIE interface, and the database acceleration card is integrated with a network interface card connected with an external network host through a network interface.

7. An apparatus for one-way transmission of data between an intranet and an extranet, characterized by The application relates to a one-way data transmission system for internal and external networks.

8. The apparatus according to claim 7, wherein the apparatus is characterized by: The application relates to a one-way data transmission system for internal and external networks.

9. The apparatus of claim 8, wherein the apparatus is configured to: The application relates to a one-way data transmission system for internal and external networks.

10. The apparatus of claim 9, wherein the apparatus is configured to: The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external networks. The application relates to a one-way data transmission system for internal and external