Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

232 results about "Network isolation" patented technology

Isolation network. A network inserted in a circuit or transmission line to prevent interaction between circuits on each side of the insertion point.

Power disaster recovery system-oriented micropatch non-inductive deployment engine and resource scheduling method, system, equipment and medium

The invention relates to the technical field of power monitoring system network security and real-time micropatch hot deployment, and discloses a power disaster recovery system-oriented micropatch non-inductive deployment engine, a resource scheduling method, a system, equipment and a medium, and the method comprises the steps: capturing system events through a kernel eBPF probe, and carrying out feature extraction and model reasoning; generating and transmitting an encrypted scheduling token; loading and verifying a patch fragment by a patch agent, inserting a jump instruction through a kernel interface to redirect an execution stream, and maintaining multi-kernel cache consistency; fusing multi-source telemetry data to carry out fusing judgment, realizing network isolation and calling a key service to cancel a key; and collecting runtime indexes and performing trend prediction, triggering a recovery or rollback operation according to a result, and storing an operation result and data through a block chain. According to the method, through combination of deep fusion of multi-source heterogeneous data, dynamic reasoning of a knowledge graph and strategy optimization of reinforcement learning, efficient perception and defense of a complex attack scene of a digital power grid are realized.
Owner:GUIZHOU POWER GRID CO LTD

Power grid intrusion detection system based on artificial intelligence

The invention relates to the technical field of data processing, and discloses an artificial intelligence-based power grid intrusion detection system, which comprises a three-dimensional data cube construction module, a three-dimensional data cube feature extraction module, a feature fusion module, an attack probability prediction module, an attack credibility evaluation module and an intrusion protection module, aligning timestamps among the communication flow, the equipment state and the node topological relation of the power grid to generate a three-dimensional data cube of the power grid; abnormal node propagation characteristics and a flow time sequence mode are extracted; fusing the abnormal node propagation features and the time features of the flow time sequence mode through a cross-channel attention mechanism to obtain a fused feature vector; inputting the fusion feature vector into a full connection layer to obtain an attack probability; when the attack probability exceeds a preset threshold value, starting a sandbox verification process, and generating an attack credibility score; and issuing a network isolation and channel switching instruction based on the attack credibility score. The accuracy of power grid intrusion detection can be improved.
Owner:GUIZHOU POWER GRID CO LTD

Network isolation system supporting multi-dimensional auditing

The invention relates to the technical field of network security, and discloses a network isolation system supporting multi-dimensional auditing, which comprises an access control module, a security isolation module, an auditing analysis module and a management platform module, the access control module is used for carrying out identity verification and protocol legality verification on the access request; the security isolation module is connected with the access control module and is used for performing protocol stripping and content cleaning on the verified data stream; and the auditing analysis module is in bidirectional communication with the security isolation module and the management platform module, and is used for collecting multi-dimensional auditing data pieces of the network layer, the application layer and the user behavior layer. According to the method, the abnormal access behavior is detected in real time, when high-frequency unconventional port access is detected, a risk early warning mechanism is triggered, an alarm event is generated, and the management platform is linked to dynamically adjust an access strategy, so that quick response and active defense to potential attack behaviors are realized, and the recognition and blocking capabilities of the system to complex threats are improved.
Owner:ZHENGZHOU UNIV

Vision-based cross-network interaction method and system

The invention provides a vision-based cross-network interaction method and system, and relates to the technical field of intelligent interaction, and the method comprises the steps: obtaining a visual interaction sequence, constructing multi-modal feature representation, achieving cross-domain semantic alignment, deconstructing visual information into a hierarchical control instruction set, and transmitting the hierarchical control instruction set to a target network environment for execution after security classification. And a bidirectional mapping relation graph is constructed to realize incremental optimization. According to the method, semantic bridging between heterogeneous networks can be established, the cross-domain control precision is improved, and meanwhile safe interaction in a network isolation environment is guaranteed.
Owner:ZHONGTIAN ZHILING (BEIJING) TECH CO LTD

Article label anti-counterfeiting authentication method and system and computer equipment

The invention relates to an article label anti-counterfeiting authentication method and system and computer equipment. Comprising the following steps: reading first label information containing an identification area, a coding area and a password area through an external network base station to realize data preliminary verification and label authentication; and the second label information only containing the coding area is read by the intranet base station for re-verification, so that data multiple verification and anti-counterfeiting verification are provided for electronic label data interaction in a network isolation environment, information comprehensiveness and security are considered, the accuracy and reliability of target object identification are improved, and the user experience is improved. And meanwhile, data security is guaranteed through partition information management.
Owner:CHANGSHA YINGXIN SEMICONDUCTOR TECHNOLOGY CO LTD

Anode assembly workshop three-dimensional visual management system and method based on digital twinning

The invention discloses a digital twinning-based three-dimensional visual management system and a digital twinning-based three-dimensional visual management method for an anode assembly workshop. The system comprises a triple binding index module, a unified time axis alignment module, a view cone inverse solution positioning module, a safety linkage arrangement module and a resume playback module, and is provided with a process template library and a network isolation / main / standby module. Three-dimensional positioning and PTZ linkage of an AI / threshold event are realized by establishing mapping of a three-dimensional object, a camera and a PLC point location; the batch / bracket / station events, the PLC time sequence and the video slices are indexed in a unified mode; shadow verification, interlocking check, instruction issuing, read-back and video consistency confirmation and trace leaving are executed according to the process, and a safe closed loop from warning to disposal is formed. The method comprises the steps of access and calibration, triple binding, time axis alignment, event positioning and stream taking, linkage processing and resume filing. The positioning and handling efficiency can be improved, the misoperation risk is reduced, and cross-production-line reuse and tracing evidence obtaining are supported.
Owner:QINGTONGXIA ALUMINUM GRP

AI-powered cybersecurity system for regulatory compliance in energy distribution

A system for AI-supported cybersecurity and regulatory compliance in energy distribution networks, consisting of: a hardware-embedded data acquisition module configured to intercept, capture, and time-stamp operational data streams and to control data traffic from SCADA (Supervisory Control and Data Acquisition) systems, AMI (Advanced Metering Infrastructure) systems, and energy management systems (EMS) via multiple communication protocols without operational latency; an FPGA-based deep packet inspection unit coupled with the data acquisition module, wherein the FPGA firmware is configured to perform line rate filtering, protocol decomposition and metadata extraction of the acquired data and forwards preprocessed packet data to an AI processing unit; an AI processing unit consisting of a multi-core central processing unit (CPU), a dedicated AI accelerator selected from a graphics processing unit (GPU) or a tensor processing unit (TPU), and a volatile memory buffer; a response orchestration module that is communicatively coupled with network management devices and operations controllers, wherein the response orchestration module is configured to perform automated security and compliance remediation measures, including network isolation of compromised segments, enforcement of protocol encryption, and privilege revocation; and an immutable audit logging subsystem configured to record all detected events, compliance assessments, and corrective actions in a blockchain-based distributed ledger, with each log entry cryptographically anchored with a secure hash value and digitally signed with keys stored in a secure hardware enclave.
Owner:ALIF MUHAMMAD +11

Control method for under-voltage tripping and voltage detection closing for low-voltage switch

The invention discloses a control method for under-voltage tripping and voltage detection closing for a low-voltage switch, and relates to the technical field of power distribution automation. The problems of function separation, low detection precision, poor anti-interference capability and inconvenient maintenance in the prior art are solved. The method comprises the following steps: S1, acquiring a high-precision digital voltage through a voltage transformer, a voltage division network, an isolation amplifier and a 24-bit delta sigma ADC; s2, interference is suppressed by combining temperature compensation, FIR filtering, median filtering and an oversampling integration algorithm; s3, comparing the real-time voltage with a tripping / closing threshold value which can be configured online in parallel; s4 / S5, triggering a zero-crossing short pulse to drive opening / closing based on the threshold value and the time delay; s6, performing parallel fault monitoring, shielding misoperation and uploading fault data; according to the invention, the detection precision, the anti-interference capability and the operation and maintenance efficiency of the system are obviously improved.
Owner:PINGDINGSHAN PINGGAO-YASKAWA SWITCH APP CO LTD

Multi-tenant API key authentication and resource isolation system in containerized environment

The invention discloses a multi-tenant API key authentication and resource isolation system in a containerized environment, and relates to the field of containerized multi-tenant authentication. Comprising an authentication authorization layer, a resource management and control layer and a security isolation layer. The authentication authorization layer comprises a multi-tenant authentication engine, an API key verification sub-module, a tenant identity recognition sub-module, an authority cascade verification sub-module and a dynamic authority calculation sub-module. And the resource management and control layer comprises a resource quota manager, a dynamic quota allocation sub-module, a real-time use monitoring sub-module, a threshold alarm control sub-module and an elastic capacity expansion and contraction sub-module. The security isolation layer comprises a multi-dimensional isolation engine, a container network isolation sub-module, a storage space isolation sub-module, a process permission isolation sub-module and a system call filtering sub-module; deep fusion of API authentication and container resource control is realized, a dynamic resource quota management mechanism based on tenant identities is established, and fine-grained API authority control and resource use limitation are provided.
Owner:CHINA IND INTERNET RES INST

Multi-level data cleaning method for nuclear power industry

The invention belongs to the technical field of nuclear power data processing, and particularly relates to a multi-level data cleaning method for the nuclear power industry. Comprising a first hierarchy data importing and preprocessing layer, and the first hierarchy is a basic unit for nuclear power multi-hierarchy data cleaning; the second level carries out local processing layer data processing, and the data subjected to secondary cleaning is recompressed, feature codes are extracted, and then the data are transmitted to the third level; or directly forwarding the unprocessed original compressed data; the third hierarchy carries out data processing of the platform layer in the data; and the fourth level performs data processing of the data application layer, and is responsible for performing persistent storage on the data according to a standardized format after the data is subjected to full-process cleaning, compression, feature extraction and desensitization processing. The method has the beneficial effects that the method is specially customized for the nuclear power industry: special requirements of high confidentiality, network isolation, large data volume and the like of data in the nuclear power industry are fully considered, and a special cleaning and desensitization process is designed.
Owner:NUCLEAR POWER OPERATIONS RES INST (NPRI)

Cloud platform design method based on Docker container technology

The invention discloses a cloud platform design method based on a Docker container technology, and relates to the field of cloud computers. The method comprises the following steps: deploying a plurality of containerized target application services in a distributed management cluster, and respectively determining the number of container instances required by the plurality of target application services; for each target application service, distributing a plurality of container instances to different working nodes for operation according to a scheduling strategy and the number of the container instances; configuring a multi-level network isolation strategy for the plurality of target application services; constructing a label-based dynamic container instance scheduling strategy, and performing real-time scheduling on the container instances of the plurality of target application services through the dynamic container instance scheduling strategy; and copying the cluster management state among the plurality of management nodes in real time, and carrying out synchronization and regular backup on the application state of the running container instance, so that the running states of all nodes in the distributed management cluster are consistent. The method can improve the reliability of cloud platform design.
Owner:LIAONING PROVINCIAL COLLEGE OF COMM

Data transmission method and device between security domains, storage medium and electronic equipment

The invention discloses a data transmission method and device between security domains, a storage medium and electronic equipment. Relates to the field of data transmission, and the method comprises: in a front-end application of a first security domain, in response to an interaction request triggered by a user, generating a request message containing a unique identifier, and issuing the request message to a message queue service in the first security domain, the message queue service being used for a large model processing service in a second security domain, consuming the request message according to a pre-configured security access strategy, and writing response data of the large model into a shared cache service of a first security domain; and initiating a query request to the shared cache service to obtain response data corresponding to the interaction request from the shared cache service, and displaying the response data to the user through a user interface of the front-end application. The problem that data transmission efficiency is low when data transmission between security domains in a one-way network isolation environment is realized by depending on a manual or semi-automatic off-line ferry mode in the prior art is solved.
Owner:TRAVELSKY TECHNOLOGY LIMITED

Intranet data anti-leakage method based on zero trust and related device

The invention discloses an intranet data anti-leakage method based on zero trust and a related device, and belongs to the technical field of information technology and data security. The method comprises the following steps: identifying mainboard information of terminal equipment through a desk management module, limiting all unauthorized data external transmission paths, and only allowing internal white list software to be installed; an isolation wall of an intranet and an extranet is established through a network isolation module, only one network is allowed to exist at the same time, a client is deployed at a credit granting terminal and is bound with a credit granting account, and a gateway end verifies a user identity through a security center and gives a corresponding access right; the flow management and control module is used for limiting the intranet flow to only access the white list website; through an outgoing approval module, mail outgoing is allowed and file outgoing parameters are set only after approval is passed; and single management and control of an external transmission path of intranet data and blocking of a secret divulging behavior are realized. Through real-time control and safety supervision, file protection and leakage prevention of intranet data can be achieved, operation is convenient and fast, and applicability is achieved.
Owner:ZHUHAI TIANCHENG ADVANCED SEMICON TECH CO LTD

Time series data cross-gatekeeper two-way transmission method, device and equipment

The invention relates to the field of data transmission, and provides a time series data cross-gatekeeper two-way transmission method, device and equipment, and the method comprises the steps: configuring an Internet of Things database cluster and an isolation gatekeeper, and determining a configuration result; according to the configuration result, the sending end is started to package the time sequence data, a data packet containing redundancy check information is generated, and the redundancy check information comprises a double-length field and a check code; transmitting the packaged data packet to a receiving end through an isolation gatekeeper; after the receiving end receives the data packet, verifying the dual-length field and the check code, if the verification is passed, returning a success signal, otherwise, returning a failure signal; and if the sending end receives the failure signal, automatically retransmitting the data packet until a successful signal is received or a preset retry condition is met. The problem that in the prior art, cross-gatekeeper time sequence data transmission cannot meet the requirements for high safety and real-time performance at the same time is solved, and safe and reliable time sequence data two-way real-time transmission under the strict network isolation condition is achieved.
Owner:TIANMOU TECH (BEIJING) CO LTD +1

Whole-plant auxiliary network monitoring access processing method and system for IP conflict sub-control equipment

The invention relates to the technical field of industrial automation and control, and discloses a whole-plant auxiliary network monitoring access processing method and system for IP conflict sub-control equipment, and the method comprises the steps: accessing a data interface machine and a network switch into each independently operating electric precipitation upper computer of different sub-control systems; the monitoring data are read from the corresponding electric precipitation upper computer through the data interface machine; label name conversion is carried out on the monitoring data in the data interface machine, and the name duplication phenomenon of the monitoring data is eliminated; performing network isolation on conflicting IP addresses of the sub-control systems through a network switch to form an independent communication link; and uploading the monitoring data subjected to label conversion and network isolation to a database of the auxiliary network monitoring system to realize data integration of the sub-control system and the auxiliary network monitoring system. According to the method, adverse factors such as normal operation of the electric precipitation equipment in the implementation stage are overcome, and the purpose of accessing the electric precipitation monitoring data to the power plant auxiliary network monitoring system is safely achieved.
Owner:HUANENG PINGLIANG POWER GENERATION CO LTD

Automatic operation and maintenance method and system suitable for closed system

The invention provides an automatic operation and maintenance method and system suitable for a closed system. The technical problem that a traditional operation and maintenance scheme is difficult to apply due to network isolation and sample scarcity in closed environments such as finance and energy is solved. The method comprises the following steps: generating a unique and traceable migration identifier for all operation and maintenance data, models and reasoning results through a data and migration management module; quantitatively calculating a transferability score between the source domain and the target domain through a transferability evaluation module; an optimal model migration strategy is dynamically selected according to the mobility score, and efficient self-adaption of the model is achieved; closed-loop operation and maintenance are executed through a multi-agent cooperation system comprising detection, diagnosis and repair agents, and self-learning and self-optimization of the system are realized through small sample active learning and a knowledge base evolution mechanism. According to the method, rapid construction, continuous evolution and whole-process traceability of the artificial intelligence operation and maintenance capability in the closed system are realized, and the method has remarkable innovativeness and industrial application value.
Owner:CHINA ACADEMY OF INFORMATION & COMM

System for secure MCP-mediated tool use by AI agents and generative AI / LLM services in cloud-native distributed applications

A system (100) for the secure MCP-mediated use of tools by AI agents and generative AI / LLM services in cloud-native distributed applications, wherein the system (100) comprises: a KL agent interface (1) configured to receive natural language commands and application events from a variety of client applications and to generate appropriate tool call commands for one or more generative KL or Large Language Model (LLM) services; an MCP mediator service (2) that is configured to: (a) to convert the tool request requests into messages compatible with a model context protocol (MCP); and (b) to maintain the conversation context, including at least one of the following: user identity, tenant identity and application identity; a tool register (3) that stores a plurality of tool descriptions, each tool description defining at least a tool identifier, an input and output scheme, an endpoint location and allowed functions, wherein the tool register (3) is accessible to the MCP mediator service (2); a policy and security manager (4) configured to evaluate each MCP tool call against one or more security and access policies based on the conversation context and the corresponding tool description, and to issue a decision to allow, modify or block the tool call; a tool connector layer (5) comprising a plurality of tool adapters, each tool adapter being configured to communicate securely with a corresponding external tool, service or data source using credentials and permissions restricted according to the decision of the policy and security manager (4); an observation and audit manager (6) configured to record, for each tool call, at least a timestamp, the calling KL agent, the tool identifier, the policy decision, and a summary of the tool response, and to provide audit logs and metrics for monitoring and compliance purposes; and a cloud-native deployment controller (7) configured to provide the MCP mediator service (2), policy and security manager (4), tool connector layer (5) and observation and audit manager (6) as distributed microservices with network isolation between tenants in a cloud-native environment.
Owner:BHANDARWAR NILESH DNYANESHWAR REDMOND

Infrastructure and application management system based on cloud native technology

The invention discloses an infrastructure and application management system based on a cloud native technology, and the system comprises a command line tool which is used for carrying out the communication with a server through an MQTT protocol, and executing the cluster management operation; the multi-tenant private cloud cluster module is used for realizing resource isolation and quota management among tenants; the mirror image warehouse module is used for storing and managing application mirror images; the declarative management module is used for defining a resource expectation state through a YAML configuration file; the CI / CD assembly line module is used for automatically constructing, testing and deploying applications; the gateway resource scheduling module is responsible for load balancing and flow control; the user authorization and authentication module is used for realizing authority control based on an RBAC model; the security module comprises data encryption and network isolation; and the asset library management module is used for managing a program component and a platform library. By integrating a cloud native technology stack, a set of efficient, safe and extensible infrastructure and application management system is constructed, and the deployment efficiency and the operation and maintenance capability of enterprise-level applications are remarkably improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Secret transmission security management system for secret-related electronic files

The invention relates to the technical field of secret-related electronic file transmission and management, and discloses a secret-related electronic file secret transmission safety management system which comprises a safety management system. The security management system comprises a hardware security support layer, a distributed security storage layer, a file full life cycle security management layer, a user identity authentication and behavior auditing layer, a security auditing layer and an emergency response layer. The confidential electronic file secret transmission security management system integrates a trusted computing chip, security boot firmware, a physical unclonable function (PUF) and an optical isolation technology through a hardware security support layer, is different from a traditional system which only depends on software protection, constructs a trusted execution environment from a hardware bottom layer, guarantees the operation credibility by using the trusted computing chip, and improves the security of the confidential electronic file. The secure boot firmware blocks illegal program loading, the PUF endows the hardware with a unique uncounterfeited identity, and the optical isolation realizes physical level network isolation, so that threats such as hardware tampering and physical attacks are radically defended.
Owner:BEIJING AEROSPACE NETWORK TECHNOLOGY CO LTD

Industrial control safety cheating detection method and system based on container technology

The invention provides an industrial control security spoofing detection method and system based on a container technology, and relates to the technical field of industrial control network security, and the method comprises the steps: guiding an abnormal access request to a simulation service instance in a container environment, extracting an interactive operation to construct a multilayer directed graph, calculating a branch entropy value and a semantic deviation degree to form a feature vector, and carrying out the spoofing detection of the abnormal access request; and determining an attack stage based on the state transition matrix and the attack behavior knowledge base, controlling response data and implementing network isolation. The method can actively induce the attacker to expose the intention, accurately recognize the attack stage, and effectively protect the industrial control system from network attack.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Power industrial control terminal network isolation method and system based on process security label binding

The application discloses a kind of power industrial control terminal network isolation method and system based on process security label binding;Belong to the technical field of power system network security, its operating steps include: decoupling physical network resources into independent partitions and mapping to independent user-mode network protocol stack instances;Through the bottom flow direction rule, the in-bound traffic is accurately delivered to the corresponding partition;Identify process security label at the application layer, establish the forced mapping of process and specific protocol stack instance and link;Through the controlled shared memory channel, realize the safe data interaction between partitions.The application realizes strong logical isolation on unified hardware, through the forced binding of process identity and network link, reduces the privilege promotion and horizontal penetration risk caused by traditional protocol stack sharing, while limiting the scope of failure impact, without relying on external physical isolation equipment, significantly improves the endogenous security protection capability of industrial control system network boundary.
Owner:NARI INFORMATION & COMM TECH

Information management system, management device, and non-transitory computer-readable storage medium storing program

An information management system includes: a management system that manages management information; a print system that causes a printing device to print the management information acquired from the management system; and a management device that acquires the management information from scan data of a printed object with the management information printed thereon, and stores the acquired management information in a database on an isolated network isolated from an external network, and the print system causes the printing device to generate the printed object with identification information in accordance with a predetermined order rule printed thereon, and the management device acquires the identification information from the scan data of the printed object and gives a notification of a storage omission of the management information in the database, based on the acquired identification information.
Owner:SEIKO EPSON CORP

Storage cluster splitting method and apparatus, electronic device, and storage medium

This application discloses a method, apparatus, electronic device, and storage medium for splitting a storage cluster, relating to the field of computer technology, particularly to artificial intelligence fields such as cloud computing, distributed storage, and big data processing. The specific implementation scheme is as follows: The data path of the target resource in the original storage cluster is adjusted so that requests to access the target resource are sent to the target node in the original storage cluster; the target node is network isolated; the target node is restarted, and in response to the target node's target startup parameter being set to the target value, the target node is split from the original storage cluster as a new storage cluster; wherein, the target startup parameter is a parameter used to force a node to start as a new single-node cluster; the target node is removed from the original storage cluster, and the network isolation of the target node is lifted.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

A network isolation method, device, electronic device and storage medium for a cloud phone

The present disclosure provides a network isolation method, device, electronic device and storage medium for a cloud phone, and relates to the field of computer technology, in particular to the field of cloud services. The method is executed by a cloud phone management platform, and includes: obtaining a network isolation task for a target cloud device, querying a target isolation service, a target isolation script, a target configuration file template and a target isolation policy that match the target cloud device from a database; wherein the target cloud device includes a virtual machine for providing cloud phone business services; adding the target isolation policy to the target configuration file template to obtain a target configuration file; generating an isolation task script based on the target isolation service, the target isolation script and the target configuration file; and sending the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script.
Owner:HUNAN MC TECHNOLOGY CO LTD

Data offline protection method and system, electronic device and storage medium

The invention discloses a data offline protection method and system. The method comprises the steps that a first server backs up target data from a data source end according to a preset first network isolation strategy, and the target data serve as first backup data; at least one second server backs up the first backup data from the first server according to a preset second network isolation strategy to serve as second backup data, and the second server is in a physical isolation state after backup; wherein the first network is configured in a way that the first server only opens the data transmission with the data source end in a first set time period, and closes the data transmission with the data source end after the first backup data is backed up; the second network isolation strategy is configured to enable the second server to only open the data transmission with the first server in a second set time period, and close the data transmission with the first server after the second backup data is backed up. Unified management, calling of services among systems and function integration can be achieved, and the equipment cost is greatly reduced.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Data bidirectional synchronization method based on MongoDB and computer program product

The invention provides a MongoDB-based data bidirectional synchronization method, a computer program product, electronic equipment and a storage medium, and the method comprises the steps: obtaining first incremental data and second incremental data according to copy set service demands corresponding to a first MongoDB database and a second MongoDB database; respectively carrying out data ferrying on the first incremental data and the second incremental data; and respectively carrying out MongoDB database storage operation on the first incremental data after ferrying and the second incremental data after ferrying. By implementing the application, data synchronization can be realized without depending on message middleware, data intrusion is prevented, the primitiveness of the data is not damaged, network isolation is effectively traversed, and the transmission efficiency of the data is improved.
Owner:HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD +3

An access method, device, platform, equipment and medium of an intranet and extranet terminal

This invention provides a method, apparatus, platform, device, and medium for accessing internal and external network terminals. The internal and external network access platform is deployed with a software-defined boundary architecture, which includes a zero-trust system. The method includes: receiving communication connection requests from internal and external network terminals through the zero-trust system; responding to the communication connection requests by granting access permissions to the internet ports of the internal and external network terminals based on a door-knocking packet; establishing a communication connection with the internal and external network terminals based on the access permissions and receiving office business access requests from the internal and external network terminals; responding to the office business access requests, acquiring office data, and returning the office data to the workspace domain of the internal and external network terminals. The zero-trust strategy is implemented through the software-defined boundary architecture, utilizing internet port hiding technology to reduce internet exposure; and a zero-trust sandbox is used to provide security assurance by isolating internal and external network terminals in personal and workspaces, achieving internal and external network isolation during office work and maintenance.
Owner:CHINA TELECOM CORP LTD

Pressure stabilizing device of fire fighting water system of offshore unmanned platform

The utility model discloses a pressure stabilizing device of a fire fighting water system of an offshore unmanned platform, the pressure stabilizing device of the fire fighting water system of the offshore unmanned platform comprises a main pressure stabilizing pump and a standby pressure stabilizing pump, the main pressure stabilizing pump and the standby pressure stabilizing pump are both connected to a main pipe network, the main pipe network is provided with a pressure transmitter, and the pressure transmitter is connected with a control box. The control box is connected with the main stabilized pressure pump and the standby stabilized pressure pump so that the main stabilized pressure pump and the standby stabilized pressure pump can be switched for use, a main pipe network isolation valve is arranged on the main pipe network, and the main pipe network isolation valve needs to be closed when the main stabilized pressure pump and the standby stabilized pressure pump are switched for use. According to the pressure stabilizing device of the fire fighting water system of the offshore unmanned platform, the pressure transmitter is arranged on the main pipe network, the pressure transmitter detects the pressure of fire fighting water in the main pipe network and feeds back the pressure to the control box, the control box selects to open or close the main pressure stabilizing pump and the standby pressure stabilizing pump according to the pressure, automatic operation is achieved, remote control can be achieved, and the pressure stabilizing device is convenient to use. The system has the characteristics of high automation level and conformity with an unmanned platform.
Owner:OFFSHORE OIL ENG CO LTD

File transmission device and method under combination of physical and logic isolation networks

PendingCN121940157AMeet the requirements for isolated communicationConvenient and quick deploymentSecuring communicationExchange networkEngineering
The invention discloses a file transmission device and method under the combination of physical and logic isolation networks. The device comprises an all-in-one machine unit, the all-in-one machine unit comprises a gatekeeper front-end processor, an isolation module and a host machine; the host machine comprises a gatekeeper postposition machine, an isolation switching network channel and other logic isolation networks connected with the isolation switching network channel; the gatekeeper front-end processor receives the flow data transmitted by the isolation network; network isolation communication is carried out between the isolation module and the gatekeeper rear-end machine; the gatekeeper postposition machine and the isolation switching network channel internally form a network for TCP communication, the isolation switching network channel and other logic isolation networks directly communicate with the host machine through a shared memory, and the isolation switching network channel and the other logic isolation networks are in network isolation; the all-in-one machine has the beneficial effects that through the all-in-one machine unit provided by the invention, convenient and rapid implementation and deployment are realized, and the implementation cost is reduced; and the requirement of a physical isolation gatekeeper is met, and the requirement of internal network isolation communication is also met.
Owner:SHENZHEN LEAGSOFT TECH

Network knife switch based on physical isolation

A network knife switch based on physical isolation relates to the technical field of communication network maintenance, and comprises a bearing shell, a switching rotary knife switch and an on-off connector, and a rotary center shaft supported by a fixing frame is arranged in the length direction of the bearing shell and located at the center of the interior of the bearing shell. A plurality of groups of switching rotary knife switches are uniformly fixed in the length direction of the rotary middle shaft at intervals, and each group of switching rotary knife switches corresponds to one on-off connector; copper reeds are fixed in the trapezoidal clamping grooves of the on-off connectors, and any group of switching rotary knife switches comprise brake pads which are respectively positioned in the eight trapezoidal clamping grooves in the corresponding on-off connectors; the network switching device is simple in structure, reliable in performance and easy and convenient to operate, switching of different networks is achieved under the condition that the network isolation state is not affected, the risk of cross-network connection of the different networks is reduced, the difficulty of network maintenance is lowered, and the maintenance efficiency of an information system is improved.
Owner:CHINESE PEOPLES LIBERATION ARMY UNIT 96608