Intelligent physical isolation safe switch and methodTechnical field
The present invention relates to a kind of switch and method, especially a kind of intelligent physical isolation safe switch and method.Belong to the data transfer of computer security fields.
Background technology
The fast development of computer technology, for the masses' work and life brought a lot of facilities, the especially development of Internet technology has thoroughly changed our life and behavioural habits.Develop into now, manage business on the computing machine by based on the mathematical operation of unit, cloud computing and the cloud service that file processing is transformed into Internet-based, extension of network progressively is formed on worldwide information sharing and business processing to external network internally.But, when offering convenience, information sharing also brings the risk of information leakage, intranet and extranet are connected when carrying out exchanges data, also brought the management test of information security, particularly in network attack and virus all in the very frequent and severe situation, if do not have safety precaution mechanism or strict Safety Management Measures, professional normal operation all is difficult to guarantee.
As everyone knows, according to relevant information safety management regulations, in some special industries or unit, maintaining secrecy and the referred very high status of safety of information do not allowed least bit mishap, and this point embodies the most obviously in the government affairs service.For example, China widelys popularize online government affairs with Improving Government work efficiency and masses' service satisfaction, it is convenient for the masses that governments at all levels unit all releases the government affairs service network, the front end of government affairs service network must be built at internet platform, masses' ability free access, but in order to guarantee data security, the operation system of units concerned can not directly externally connect again, the unit's of having to be erected at Intranet.Therefore, data just occur and how to exchange and guarantee a safe difficult problem at intranet and extranet.
It is reported that traditional safe isolation method mainly is to adopt gateway, but gateway but can't be realized physical isolation truly, has equally certain potential safety hazard.Accomplish safety isolation truly, must accomplish absolute physical isolation, make and do not carry out data by network communication mode between the intranet and extranet and directly exchange, thereby reduce the potential safety hazard that information leakage causes.Therefore, the most traditional mode is exactly to insert the outer net computer by tangible media such as artificial use USB flash disks, and data are copied into media such as USB flash disks, then extracts and inserts the Intranet computer again, copies into the Intranet computer just copying into the data of USB flash disk.But, although this kind manual method has realized the physical isolation of absolute sense, but still be difficult to thoroughly get rid of the potential safety hazard of intranet and extranet exchanges data, and adopt manual mode of operation's cost larger, inefficiency, make easily operating personnel tired and cause the appearance of misoperation, but also easily by the premeditated incorrect data of transmission of people and virus, bring information security hidden danger.So, need a kind of novel inner-external network data safety switching equipment.
Summary of the invention
The objective of the invention is provides a kind of security that can guarantee the intranet and extranet exchanges data in order to solve the defective of above-mentioned prior art, the intelligent physical isolation safe switch that can increase work efficiency again.
Another object of the present invention is to provide a kind of intelligent physical isolation safe method for interchanging data.
Purpose of the present invention can reach by taking following technical scheme:
Intelligent physical isolation safe switch is characterized in that: described switch comprises
Two are separated physically, connect two main frames of intranet and extranet respectively and make main frame carry out a USB transmission interface and the 2nd USB transmission interface of data transmission;
Be used for switching a USB transmission interface and the 2nd USB transmission interface and the controller of setting data transmission period;
And the storage medium that is used for two main frame the transmission of datas of storage intranet and extranet;
Described controller only is connected with a USB transmission interface or the 2nd USB transmission interface in the period in a certain data transmission, and described storage medium is connected with controller.
As a kind of preferred version, comprise also that for to the power supply of data switching equipment energising, the signal lamp device that is used for showing the display of two host data transmission informations of intranet and extranet and is used to indicate the switch state described power supply is connected with controller with display and is connected.
As a kind of preferred version, described signal lamp device comprises power lamp, first data transmission signal lamp and the second data transfer signal lamp, described power lamp is connected with power supply, described first data transmission signal lamp be connected the data transfer signal lamp and be connected with the 2nd USB transmission interface with a USB transmission interface respectively.
As a kind of preferred version, described first data transmission signal lamp and the second data transfer signal lamp lay respectively at a side of a USB transmission interface and the 2nd USB transmission interface.
As a kind of preferred version, a described USB transmission interface is PC or server with two main frames of intranet and extranet that the 2nd USB transmission interface connects respectively.
As a kind of preferred version, described storage medium is solid state hard disc, TF card, SD card or USB flash disk.
Another object of the present invention can reach by taking following technical scheme:
Intelligent physical isolation safe method for interchanging data is characterized in that may further comprise the steps:
1) after the energising of data interaction equipment, the USB transmission interface on the equipment and the 2nd USB transmission interface are connected respectively No. 1 main frame and No. 2 main frames;
2) set data transmission after the period at controller, set up being connected of controller and a USB transmission interface, No. 1 main frame is started working;
3) at this moment, No. 1 main frame is by the controller access storage medium, and a USB transmission interface receives the transmission of data of No. 1 main frame, and deposits data in storage medium;
4) after No. 1 main frame is finished data transmission, disconnect request to the controller transmitting apparatus, controller is received the physical connection that disconnects after the off device request between No. 1 main frame and the storage medium, sets up simultaneously being connected of controller and the 2nd USB transmission interface, and No. 2 main frame is started working;
5) No. 2 main frames obtain starting working after the event that equipment switches, by the controller access storage medium, the 2nd USB transmission interface is given No. 2 main frames with the data transmission of depositing No. 1 main frame in the storage medium, receives simultaneously the transmission of data of No. 2 main frames, and deposits data in storage medium;
6) after No. 2 main frames are finished data transmission, disconnect request to the controller transmitting apparatus, controller is received the physical connection that disconnects after the off device request between No. 2 main frames and the storage medium, set up simultaneously being connected of controller and a USB transmission interface, No. 1 main frame restarts work, read the data of storage medium and data are write storage medium, namely realize the secure data exchange between No. 1 main frame and No. 2 main frames.
As a kind of preferred version, the event that described No. 1 main frame and No. 2 main frame transmission off device requests and the equipment that obtains switch is finished by the SDK kit.
The present invention has following beneficial effect with respect to prior art:
1, switch of the present invention adopts hardware physical isolation pattern to carry out exchanges data, adopt two USB interface to be connected with two PCs or server respectively, rather than adopt traditional netting twine to connect, the communication of after controller disconnects, also just breaking, can reduce the probability of being attacked by network program comparatively speaking, can come the physical segregation state of facilities for observation whether normal by two data transfer signal lamps that connect USB interface in addition.
2, switch of the present invention is to simulate the mode of manually carrying out the plug USB flash disk to carry out data physics importing exchange, adopt intelligent control technology to realize the secure exchange of intranet and extranet data, in the security that has guaranteed the intranet and extranet exchanges data, receiving port and data output in data can be judged data's consistency by intelligent means, thereby the data that guarantee exchange are accurate and needs, improved work efficiency, reduce because the error that manually-operated brings, can also save cost of human resources, solve the request for utilization of carrying out the secure data exchange between the network.
3, the solution of the pure physics of the more employings of switch of the present invention, by adopting controller to switch USB interface in the mode of similar relay, guarantee that an end line disconnects, another circuit just can be opened, accomplished physical isolation truly, make the exchanges data between the intranet and extranet avoid to a great extent traditional network communication mode the problem of information leakage to occur easily, guaranteed data security.
4, switch of the present invention can solve the safety problem of carrying out exchanges data between the intranet and extranet, also greatly improved simultaneously the poor efficiency of tradition by artificial plug USB flash disk or handover network, judge by the front and back data's consistency, can improve the accuracy of exchanges data, the information work environment of enjoying a safety for the user provides support.
Description of drawings
Fig. 1 is the theory diagram of switch of the present invention.
Fig. 2 is the exchanges data process flow diagram of switch of the present invention.
Embodiment
Embodiment 1:
As shown in Figure 1, the switch of present embodiment comprises a USB transmission interface 1 and the 2nd USB transmission interface 2,controller 3, storage medium 4,power supply 5,display 6 and signal lamp device, describedcontroller 3 only is connected with a USB transmission interface 1 or the 2nd USB transmission interface 2 in the period in a certain data transmission, and described storage medium 4, describedpower supply 5 are connected with display and are connected withcontroller 3 respectively.Described signal lamp device comprises power lamp 7, first datatransmission signal lamp 8 and the second data transfer signal lamp 9, described power lamp 7 is connected withpower supply 5, described first datatransmission signal lamp 8 be connected data transfer signal lamp 9 and be connected with the 2nd USB transmission interface 2 with a USB transmission interface 1 respectively.
In the present embodiment, a described USB transmission interface 1 connects respectively two main frames of intranet and extranet with the 2nd USB transmission interface 2, select wherein by changeable described two the USB transmission interfaces ofcontroller 3 that a main frame carries out data transmission, described two main frames are PC or server.Described storage medium 4 is solid state hard disc, TF card, SD card or USB flash disk.Described power lamp 7 is when lamp is bright, and the expression switch is switched on, in normal operation; Described first datatransmission signal lamp 8 and the second data transfer signal lamp 9 lay respectively at a side of a USB transmission interface 1 and the 2nd USB transmission interface 2, the data transfer signal lamp represents that when lamp is bright the USB transmission interface works, because described two USB transmission interfaces can not be worked simultaneously, so the bright situation of lamp can not appear in data transfer signal lamp simultaneously, come the physical segregation state of observed data switching equipment whether normal with this.
As depicted in figs. 1 and 2, the data exchange process of present embodiment is as follows:
1) after the energising of data interaction equipment, the USB transmission interface 1 on the equipment and the 2nd USB transmission interface 2 are connected respectively No. 1 main frame and No. 2 main frames, wherein, No. 1 main frame is the outer net main frame, and No. 2 main frames are intranet host;
2) set data transmission after the period atcontroller 3, set up being connected ofcontroller 3 and a USB transmission interface 1, No. 1 main frame is started working;
3) at this moment, No. 1 main frame passes through the transmission of data that controller 3 access storage media 4, the one USB transmission interfaces 1 receive No. 1 main frame, and deposits data in storage medium 4;
4) after No. 1 main frame is finished data transmission, disconnect request by the SDK kit to controller 3 transmitting apparatus,controller 3 is received the physical connection that disconnects after the off device request between No. 1 main frame and the storage medium 4, set up simultaneously being connected ofcontroller 3 and the 2nd USB transmission interface 2, No. 2 main frame is started working;
5) No. 2 main frames obtain starting working after the event that equipment switches by the SDK kit, bycontroller 3 access storage media 4, the 2nd USB transmission interface 2 is given No. 2 main frames with the data transmission of No. 1 main frame of depositing in the storage medium 4, receive simultaneously the transmission of data of No. 2 main frames, and deposit data in storage medium 4;
6) after No. 2 main frames are finished data transmission, disconnect request by the SDK kit to controller 3 transmitting apparatus,controller 3 is received the physical connection that disconnects after the off device request between No. 2 main frames and the storage medium 4, set up simultaneously being connected ofcontroller 3 and a USB transmission interface 1, No. 1 main frame obtains restarting work after the event that equipment switches by the SDK kit, read the data of storage medium 4 and data are write storage medium 4, namely realize the secure data exchange between No. 1 main frame and No. 2 main frames.
In the above-mentioned data exchange process, can utilize 6 pairs of current main frames of communicating by letter of display to judge bycontroller 3.
The above; it only is the preferred embodiment of the invention; but protection scope of the present invention is not limited to this; anyly be familiar with those skilled in the art in scope disclosed in this invention; be equal to replacement or change according to technical scheme of the present invention and inventive concept thereof, all belonged to protection scope of the present invention.