Movatterモバイル変換


[0]ホーム

URL:


CN103020546A - Intelligent physical isolation secure data exchange equipment and method - Google Patents

Intelligent physical isolation secure data exchange equipment and method
Download PDF

Info

Publication number
CN103020546A
CN103020546ACN2012105534148ACN201210553414ACN103020546ACN 103020546 ACN103020546 ACN 103020546ACN 2012105534148 ACN2012105534148 ACN 2012105534148ACN 201210553414 ACN201210553414 ACN 201210553414ACN 103020546 ACN103020546 ACN 103020546A
Authority
CN
China
Prior art keywords
data
transmission interface
controller
usb
usb transmission
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2012105534148A
Other languages
Chinese (zh)
Inventor
不公告发明人
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
GAUNGZHOU HUABIAO TECHNOLOGY DEVELOPMENT CO LTD
Original Assignee
GAUNGZHOU HUABIAO TECHNOLOGY DEVELOPMENT CO LTD
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by GAUNGZHOU HUABIAO TECHNOLOGY DEVELOPMENT CO LTDfiledCriticalGAUNGZHOU HUABIAO TECHNOLOGY DEVELOPMENT CO LTD
Priority to CN2012105534148ApriorityCriticalpatent/CN103020546A/en
Publication of CN103020546ApublicationCriticalpatent/CN103020546A/en
Pendinglegal-statusCriticalCurrent

Links

Images

Landscapes

Abstract

The invention discloses intelligent physical isolation secure data exchange equipment and an intelligent physical isolation secure data exchange method. The equipment comprises a first universal serial bus (USB) transmission interface, a second USB transmission interface, a controller and a storage medium, wherein the controller is only connected with the first USB transmission interface or the second USB transmission interface in a certain data transmission time; and the storage medium is connected with the controller. The method comprises the following steps of: respectively connecting two hosts by the two USB interfaces; selecting one host for performing data transmission; disconnecting the connection after completing data transmission; and selecting the other host for performing data transmission. Therefore, the secure data exchange of the two hosts is realized. By the data exchange equipment provided by the invention, the secure data exchange between an inside network and an outside network is realized in a mode of simulating artificially plugging-unplugging a USB flash disk by adopting an intelligent control technology, the security of the data exchange of the inside network and the outside network is ensured; the work efficiency is improved; the accuracy and the security of the data exchange are also improved; and secure information working environment is provided for the user.

Description

Intelligent physical isolation safe switch and method
Technical field
The present invention relates to a kind of switch and method, especially a kind of intelligent physical isolation safe switch and method.Belong to the data transfer of computer security fields.
Background technology
The fast development of computer technology, for the masses' work and life brought a lot of facilities, the especially development of Internet technology has thoroughly changed our life and behavioural habits.Develop into now, manage business on the computing machine by based on the mathematical operation of unit, cloud computing and the cloud service that file processing is transformed into Internet-based, extension of network progressively is formed on worldwide information sharing and business processing to external network internally.But, when offering convenience, information sharing also brings the risk of information leakage, intranet and extranet are connected when carrying out exchanges data, also brought the management test of information security, particularly in network attack and virus all in the very frequent and severe situation, if do not have safety precaution mechanism or strict Safety Management Measures, professional normal operation all is difficult to guarantee.
As everyone knows, according to relevant information safety management regulations, in some special industries or unit, maintaining secrecy and the referred very high status of safety of information do not allowed least bit mishap, and this point embodies the most obviously in the government affairs service.For example, China widelys popularize online government affairs with Improving Government work efficiency and masses' service satisfaction, it is convenient for the masses that governments at all levels unit all releases the government affairs service network, the front end of government affairs service network must be built at internet platform, masses' ability free access, but in order to guarantee data security, the operation system of units concerned can not directly externally connect again, the unit's of having to be erected at Intranet.Therefore, data just occur and how to exchange and guarantee a safe difficult problem at intranet and extranet.
It is reported that traditional safe isolation method mainly is to adopt gateway, but gateway but can't be realized physical isolation truly, has equally certain potential safety hazard.Accomplish safety isolation truly, must accomplish absolute physical isolation, make and do not carry out data by network communication mode between the intranet and extranet and directly exchange, thereby reduce the potential safety hazard that information leakage causes.Therefore, the most traditional mode is exactly to insert the outer net computer by tangible media such as artificial use USB flash disks, and data are copied into media such as USB flash disks, then extracts and inserts the Intranet computer again, copies into the Intranet computer just copying into the data of USB flash disk.But, although this kind manual method has realized the physical isolation of absolute sense, but still be difficult to thoroughly get rid of the potential safety hazard of intranet and extranet exchanges data, and adopt manual mode of operation's cost larger, inefficiency, make easily operating personnel tired and cause the appearance of misoperation, but also easily by the premeditated incorrect data of transmission of people and virus, bring information security hidden danger.So, need a kind of novel inner-external network data safety switching equipment.
Summary of the invention
The objective of the invention is provides a kind of security that can guarantee the intranet and extranet exchanges data in order to solve the defective of above-mentioned prior art, the intelligent physical isolation safe switch that can increase work efficiency again.
Another object of the present invention is to provide a kind of intelligent physical isolation safe method for interchanging data.
Purpose of the present invention can reach by taking following technical scheme:
Intelligent physical isolation safe switch is characterized in that: described switch comprises
Two are separated physically, connect two main frames of intranet and extranet respectively and make main frame carry out a USB transmission interface and the 2nd USB transmission interface of data transmission;
Be used for switching a USB transmission interface and the 2nd USB transmission interface and the controller of setting data transmission period;
And the storage medium that is used for two main frame the transmission of datas of storage intranet and extranet;
Described controller only is connected with a USB transmission interface or the 2nd USB transmission interface in the period in a certain data transmission, and described storage medium is connected with controller.
As a kind of preferred version, comprise also that for to the power supply of data switching equipment energising, the signal lamp device that is used for showing the display of two host data transmission informations of intranet and extranet and is used to indicate the switch state described power supply is connected with controller with display and is connected.
As a kind of preferred version, described signal lamp device comprises power lamp, first data transmission signal lamp and the second data transfer signal lamp, described power lamp is connected with power supply, described first data transmission signal lamp be connected the data transfer signal lamp and be connected with the 2nd USB transmission interface with a USB transmission interface respectively.
As a kind of preferred version, described first data transmission signal lamp and the second data transfer signal lamp lay respectively at a side of a USB transmission interface and the 2nd USB transmission interface.
As a kind of preferred version, a described USB transmission interface is PC or server with two main frames of intranet and extranet that the 2nd USB transmission interface connects respectively.
As a kind of preferred version, described storage medium is solid state hard disc, TF card, SD card or USB flash disk.
Another object of the present invention can reach by taking following technical scheme:
Intelligent physical isolation safe method for interchanging data is characterized in that may further comprise the steps:
1) after the energising of data interaction equipment, the USB transmission interface on the equipment and the 2nd USB transmission interface are connected respectively No. 1 main frame and No. 2 main frames;
2) set data transmission after the period at controller, set up being connected of controller and a USB transmission interface, No. 1 main frame is started working;
3) at this moment, No. 1 main frame is by the controller access storage medium, and a USB transmission interface receives the transmission of data of No. 1 main frame, and deposits data in storage medium;
4) after No. 1 main frame is finished data transmission, disconnect request to the controller transmitting apparatus, controller is received the physical connection that disconnects after the off device request between No. 1 main frame and the storage medium, sets up simultaneously being connected of controller and the 2nd USB transmission interface, and No. 2 main frame is started working;
5) No. 2 main frames obtain starting working after the event that equipment switches, by the controller access storage medium, the 2nd USB transmission interface is given No. 2 main frames with the data transmission of depositing No. 1 main frame in the storage medium, receives simultaneously the transmission of data of No. 2 main frames, and deposits data in storage medium;
6) after No. 2 main frames are finished data transmission, disconnect request to the controller transmitting apparatus, controller is received the physical connection that disconnects after the off device request between No. 2 main frames and the storage medium, set up simultaneously being connected of controller and a USB transmission interface, No. 1 main frame restarts work, read the data of storage medium and data are write storage medium, namely realize the secure data exchange between No. 1 main frame and No. 2 main frames.
As a kind of preferred version, the event that described No. 1 main frame and No. 2 main frame transmission off device requests and the equipment that obtains switch is finished by the SDK kit.
The present invention has following beneficial effect with respect to prior art:
1, switch of the present invention adopts hardware physical isolation pattern to carry out exchanges data, adopt two USB interface to be connected with two PCs or server respectively, rather than adopt traditional netting twine to connect, the communication of after controller disconnects, also just breaking, can reduce the probability of being attacked by network program comparatively speaking, can come the physical segregation state of facilities for observation whether normal by two data transfer signal lamps that connect USB interface in addition.
2, switch of the present invention is to simulate the mode of manually carrying out the plug USB flash disk to carry out data physics importing exchange, adopt intelligent control technology to realize the secure exchange of intranet and extranet data, in the security that has guaranteed the intranet and extranet exchanges data, receiving port and data output in data can be judged data's consistency by intelligent means, thereby the data that guarantee exchange are accurate and needs, improved work efficiency, reduce because the error that manually-operated brings, can also save cost of human resources, solve the request for utilization of carrying out the secure data exchange between the network.
3, the solution of the pure physics of the more employings of switch of the present invention, by adopting controller to switch USB interface in the mode of similar relay, guarantee that an end line disconnects, another circuit just can be opened, accomplished physical isolation truly, make the exchanges data between the intranet and extranet avoid to a great extent traditional network communication mode the problem of information leakage to occur easily, guaranteed data security.
4, switch of the present invention can solve the safety problem of carrying out exchanges data between the intranet and extranet, also greatly improved simultaneously the poor efficiency of tradition by artificial plug USB flash disk or handover network, judge by the front and back data's consistency, can improve the accuracy of exchanges data, the information work environment of enjoying a safety for the user provides support.
Description of drawings
Fig. 1 is the theory diagram of switch of the present invention.
Fig. 2 is the exchanges data process flow diagram of switch of the present invention.
Embodiment
Embodiment 1:
As shown in Figure 1, the switch of present embodiment comprises a USB transmission interface 1 and the 2nd USB transmission interface 2,controller 3, storage medium 4,power supply 5,display 6 and signal lamp device, describedcontroller 3 only is connected with a USB transmission interface 1 or the 2nd USB transmission interface 2 in the period in a certain data transmission, and described storage medium 4, describedpower supply 5 are connected with display and are connected withcontroller 3 respectively.Described signal lamp device comprises power lamp 7, first datatransmission signal lamp 8 and the second data transfer signal lamp 9, described power lamp 7 is connected withpower supply 5, described first datatransmission signal lamp 8 be connected data transfer signal lamp 9 and be connected with the 2nd USB transmission interface 2 with a USB transmission interface 1 respectively.
In the present embodiment, a described USB transmission interface 1 connects respectively two main frames of intranet and extranet with the 2nd USB transmission interface 2, select wherein by changeable described two the USB transmission interfaces ofcontroller 3 that a main frame carries out data transmission, described two main frames are PC or server.Described storage medium 4 is solid state hard disc, TF card, SD card or USB flash disk.Described power lamp 7 is when lamp is bright, and the expression switch is switched on, in normal operation; Described first datatransmission signal lamp 8 and the second data transfer signal lamp 9 lay respectively at a side of a USB transmission interface 1 and the 2nd USB transmission interface 2, the data transfer signal lamp represents that when lamp is bright the USB transmission interface works, because described two USB transmission interfaces can not be worked simultaneously, so the bright situation of lamp can not appear in data transfer signal lamp simultaneously, come the physical segregation state of observed data switching equipment whether normal with this.
As depicted in figs. 1 and 2, the data exchange process of present embodiment is as follows:
1) after the energising of data interaction equipment, the USB transmission interface 1 on the equipment and the 2nd USB transmission interface 2 are connected respectively No. 1 main frame and No. 2 main frames, wherein, No. 1 main frame is the outer net main frame, and No. 2 main frames are intranet host;
2) set data transmission after the period atcontroller 3, set up being connected ofcontroller 3 and a USB transmission interface 1, No. 1 main frame is started working;
3) at this moment, No. 1 main frame passes through the transmission of data that controller 3 access storage media 4, the one USB transmission interfaces 1 receive No. 1 main frame, and deposits data in storage medium 4;
4) after No. 1 main frame is finished data transmission, disconnect request by the SDK kit to controller 3 transmitting apparatus,controller 3 is received the physical connection that disconnects after the off device request between No. 1 main frame and the storage medium 4, set up simultaneously being connected ofcontroller 3 and the 2nd USB transmission interface 2, No. 2 main frame is started working;
5) No. 2 main frames obtain starting working after the event that equipment switches by the SDK kit, bycontroller 3 access storage media 4, the 2nd USB transmission interface 2 is given No. 2 main frames with the data transmission of No. 1 main frame of depositing in the storage medium 4, receive simultaneously the transmission of data of No. 2 main frames, and deposit data in storage medium 4;
6) after No. 2 main frames are finished data transmission, disconnect request by the SDK kit to controller 3 transmitting apparatus,controller 3 is received the physical connection that disconnects after the off device request between No. 2 main frames and the storage medium 4, set up simultaneously being connected ofcontroller 3 and a USB transmission interface 1, No. 1 main frame obtains restarting work after the event that equipment switches by the SDK kit, read the data of storage medium 4 and data are write storage medium 4, namely realize the secure data exchange between No. 1 main frame and No. 2 main frames.
In the above-mentioned data exchange process, can utilize 6 pairs of current main frames of communicating by letter of display to judge bycontroller 3.
The above; it only is the preferred embodiment of the invention; but protection scope of the present invention is not limited to this; anyly be familiar with those skilled in the art in scope disclosed in this invention; be equal to replacement or change according to technical scheme of the present invention and inventive concept thereof, all belonged to protection scope of the present invention.

Claims (8)

CN2012105534148A2012-12-182012-12-18Intelligent physical isolation secure data exchange equipment and methodPendingCN103020546A (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN2012105534148ACN103020546A (en)2012-12-182012-12-18Intelligent physical isolation secure data exchange equipment and method

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN2012105534148ACN103020546A (en)2012-12-182012-12-18Intelligent physical isolation secure data exchange equipment and method

Publications (1)

Publication NumberPublication Date
CN103020546Atrue CN103020546A (en)2013-04-03

Family

ID=47969140

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN2012105534148APendingCN103020546A (en)2012-12-182012-12-18Intelligent physical isolation secure data exchange equipment and method

Country Status (1)

CountryLink
CN (1)CN103020546A (en)

Cited By (14)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN103581174A (en)*2013-10-152014-02-12国家电网公司Information interaction device for handset and server
CN104216848A (en)*2013-05-292014-12-17鸿富锦精密电子(天津)有限公司 motherboard
CN104601598A (en)*2015-02-092015-05-06中国兵器工业集团第五三研究所Device and method for automatically achieving unidirectional transmission of data between intranet and internet by physical isolation
CN104615552A (en)*2014-12-292015-05-13浪潮(北京)电子信息产业有限公司Safe transmission method and system
CN105635161A (en)*2016-01-122016-06-01浪潮(北京)电子信息产业有限公司Data transmission method and system
CN107018139A (en)*2017-04-242017-08-04宁波永耀信息科技有限公司Data duplex mutually passes automation equipment between a kind of separation net based on mobile memory medium
CN108199849A (en)*2018-01-042018-06-22北京中电华大电子设计有限责任公司The USBkey equipment safeties attacking system and method for a kind of real time data acquisition
CN110138707A (en)*2018-02-022019-08-16阿里巴巴集团控股有限公司Method, client, application and the electronic equipment of data interaction
WO2020087782A1 (en)*2018-10-292020-05-07北京博衍思创信息科技有限公司External terminal protection device and protection system for data traffic control
CN111654512A (en)*2020-08-062020-09-11北京赛宁网安科技有限公司USB flash disk ferry attack environment simulation device and method applied to network target range
KR20210003934A (en)*2018-10-292021-01-12베이징 비욘드인포 테크놀로지 씨오., 엘티디. Data forwarding control method and system based on hardware control logic
CN114500763A (en)*2021-12-312022-05-13珠海奔图电子有限公司 Data transmission control device, method and system for image forming apparatus
CN114638023A (en)*2020-12-162022-06-17军理科学技术研究院(南京)有限公司Computer USB interface isolation method and device
RU2822994C2 (en)*2018-10-292024-07-17Бейджин Бейондинфо Текнолоджи Ко., Лтд.Method for managing data movement based on hardware control logic node and system for implementing the method

Citations (3)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20060184784A1 (en)*2005-02-162006-08-17Yosi ShaniMethod for secure transference of data
US20100211705A1 (en)*2006-10-062010-08-19Fabien AlcouffeSecured system for transferring data between two equipments
CN203039718U (en)*2012-12-182013-07-03广州市华标科技发展有限公司Intelligent physical isolation secure data exchange equipment

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20060184784A1 (en)*2005-02-162006-08-17Yosi ShaniMethod for secure transference of data
US20100211705A1 (en)*2006-10-062010-08-19Fabien AlcouffeSecured system for transferring data between two equipments
CN203039718U (en)*2012-12-182013-07-03广州市华标科技发展有限公司Intelligent physical isolation secure data exchange equipment

Cited By (21)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN104216848A (en)*2013-05-292014-12-17鸿富锦精密电子(天津)有限公司 motherboard
CN104216848B (en)*2013-05-292017-04-05赛恩倍吉科技顾问(深圳)有限公司Mainboard
CN103581174A (en)*2013-10-152014-02-12国家电网公司Information interaction device for handset and server
CN104615552A (en)*2014-12-292015-05-13浪潮(北京)电子信息产业有限公司Safe transmission method and system
CN104601598A (en)*2015-02-092015-05-06中国兵器工业集团第五三研究所Device and method for automatically achieving unidirectional transmission of data between intranet and internet by physical isolation
CN105635161A (en)*2016-01-122016-06-01浪潮(北京)电子信息产业有限公司Data transmission method and system
CN107018139A (en)*2017-04-242017-08-04宁波永耀信息科技有限公司Data duplex mutually passes automation equipment between a kind of separation net based on mobile memory medium
CN108199849B (en)*2018-01-042021-01-05北京中电华大电子设计有限责任公司USBKey equipment security attack system and method for real-time data acquisition
CN108199849A (en)*2018-01-042018-06-22北京中电华大电子设计有限责任公司The USBkey equipment safeties attacking system and method for a kind of real time data acquisition
CN110138707A (en)*2018-02-022019-08-16阿里巴巴集团控股有限公司Method, client, application and the electronic equipment of data interaction
CN110138707B (en)*2018-02-022022-08-02阿里巴巴集团控股有限公司Data interaction method, client, application and electronic equipment
US11170133B2 (en)2018-10-292021-11-09Beijing Beyondinfo Technology Co., Ltd.External terminal protection device and protection system for data flow control
KR20210003934A (en)*2018-10-292021-01-12베이징 비욘드인포 테크놀로지 씨오., 엘티디. Data forwarding control method and system based on hardware control logic
US10931641B1 (en)*2018-10-292021-02-23Beijing Beyondinfo Technology Co., Ltd.Hardware control logic based data forwarding control method and system
KR102313544B1 (en)2018-10-292021-10-15베이징 비욘드인포 테크놀로지 씨오., 엘티디. Data forwarding control method and system based on hardware control logic
EP3876121A4 (en)*2018-10-292022-06-08Beijing Beyondinfo Technology Co., Ltd.Data forwarding control method and system based on hardware control logic
WO2020087782A1 (en)*2018-10-292020-05-07北京博衍思创信息科技有限公司External terminal protection device and protection system for data traffic control
RU2822994C2 (en)*2018-10-292024-07-17Бейджин Бейондинфо Текнолоджи Ко., Лтд.Method for managing data movement based on hardware control logic node and system for implementing the method
CN111654512A (en)*2020-08-062020-09-11北京赛宁网安科技有限公司USB flash disk ferry attack environment simulation device and method applied to network target range
CN114638023A (en)*2020-12-162022-06-17军理科学技术研究院(南京)有限公司Computer USB interface isolation method and device
CN114500763A (en)*2021-12-312022-05-13珠海奔图电子有限公司 Data transmission control device, method and system for image forming apparatus

Similar Documents

PublicationPublication DateTitle
CN103020546A (en)Intelligent physical isolation secure data exchange equipment and method
TW472185B (en)System and method for hot insertion of computer-related add-on cards
CN1312602C (en)Applied management system, managing apparatus, managing method and management program
US9423956B2 (en)Emulating a stretched storage device using a shared storage device
CN107343041B (en)Accurate poverty alleviation management system and method based on cloud computing
CN109800188A (en)Method for electrically above and below a kind of server hard disk back plane power supply structure and long-range control hard disk
CN106850286A (en)The baseboard management controller of baseboard management controller and NE management disk on veneer
US9442811B2 (en)Emulating a stretched storage device using a shared replicated storage device
CN202939611U (en)Internal and external network physical isolation computer host machine
CN102662803A (en)Double-controlled double-active redundancy equipment
CN202887163U (en)Switching device of internal and external network physical isolation computer
CN109462495A (en)A kind of ship hardware and communication system detection system and method
CN108551476A (en)A kind of control method and system for realizing file transmission
CN102354261A (en)Remote control system for power supply switches of machine room servers
CN104993598A (en)Intelligent substation centralized backup measuring and control device
CN203039718U (en)Intelligent physical isolation secure data exchange equipment
CN104951528B (en)A kind of method and terminal of Data Migration
CN108780350A (en)Power collapse and clock wakeup for hardware management of memory management units and distributed virtual memory networks
CN204597988U (en)The AFDX terminal test equipment of Based PC PCI interface
CN113867203A (en) Control system and method for flywheel array
CN203966117U (en)Sequential type USB link isolation transponder
CN204719748U (en)The intelligent management system of extensive USB device
CN202424768U (en)Network safety isolator
CN202006812U (en)Computer interlock control system with two-out-of-three structure
CN116775353A (en)Method and device for repairing failed disk, electronic equipment and readable storage medium

Legal Events

DateCodeTitleDescription
C06Publication
PB01Publication
C10Entry into substantive examination
SE01Entry into force of request for substantive examination
C12Rejection of a patent application after its publication
RJ01Rejection of invention patent application after publication

Application publication date:20130403


[8]ページ先頭

©2009-2025 Movatter.jp