CN104301307B - A kind of internet security calls the system and method that Intranet is serviced - Google Patents

A kind of internet security calls the system and method that Intranet is serviced Download PDF

Info

Publication number
CN104301307B
CN104301307B CN201410482360.XA CN201410482360A CN104301307B CN 104301307 B CN104301307 B CN 104301307B CN 201410482360 A CN201410482360 A CN 201410482360A CN 104301307 B CN104301307 B CN 104301307B
Authority
CN
China
Prior art keywords
application server
server
quick response
response code
interior
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201410482360.XA
Other languages
Chinese (zh)
Other versions
CN104301307A (en
Inventor
张宏斌
顾贲
金渊
龚康莉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nanjing Feibo Data Technology Co ltd
Original Assignee
Jiangsu Fablesoft Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Jiangsu Fablesoft Co Ltd filed Critical Jiangsu Fablesoft Co Ltd
Priority to CN201410482360.XA priority Critical patent/CN104301307B/en
Publication of CN104301307A publication Critical patent/CN104301307A/en
Application granted granted Critical
Publication of CN104301307B publication Critical patent/CN104301307B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls

Abstract

The system and method that Intranet is serviced are called the present invention relates to a kind of internet security, including:The webserver, outer application server, interior application server, one-way optical gate, outer unidirectional Quick Response Code equipment, interior unidirectional Quick Response Code equipment, audit server, business system server, it is characterized in that, one-way optical gate is not use only in information exchange between the outer application server and interior application server, additionally use unidirectional Quick Response Code equipment and audit server, and audit server is only connected with unidirectional Quick Response Code equipment, complete physical isolation is realized with other equipment, it is ensured that audit server is not easily susceptible to attack.The call result of return is audited by audit server, the safety of call result has not only been ensured, the safe and reliable interaction of data message between inside and outside application server is also ensure that.The information exchange that the present invention is applied between enterprises and institutions and government offices' internal network and internet is shared.

Description

A kind of internet security calls the system and method that Intranet is serviced
Technical field
The present invention relates to Internet technology, more particularly to a kind of internet security calls system and the side of Intranet service Method, belongs to network safety filed.
Background technology
It is low between enterprises and institutions and government offices' internal network and internet with the continuous intensification of the level of informatization The shared demand of information exchange is carried out between level of confidentiality network and High Security Level network also increasingly strong.And it is continuous with these demands Increase, the security isolation of network and the secure exchange of data also turn into is increasingly worth concern.Increasingly increase to meet Long network security demand, the network security isolated product such as the fire wall that has successively been born, two-way isolation gap and one-way optical gate.
One-way optical gate is the unidirectional transmission property based on light, realizes physical light one way technique, thus for outer net and Intranet it Between data interaction provide the one-way data passage without feedback of the information.As shown in figure 1, existing internet calls what Intranet was serviced System includes:Interior application server, outer application server, one-way optical gate, the webserver, business system server, network clothes Business device is connected by internet with outer application server, and one-way optical gate is connected between outer application server and interior application server, interior Application server is connected with Intranet business system server, and the service call that outer application server receives webserver transmission please Ask, and be sent to interior application server;Interior application server performs service operations according to solicited message, and implementing result is transmitted To outer application server.One-way optical gate can preferably ensure the one-way transmission of network data information, but existing internet The system for calling Intranet to service, not to the service call result progress Independent Audit of return, it is impossible to ensure that what is returned calls knot Fruit it is safe and reliable.And in actual life, information bidirectional is there is between outer net (internet) and enterprises and institutions' Intranet Interactive application demand, how on the premise of information privacy is ensured, meets and two-way credible hand over safely is carried out between information Change the problem of be urgent need to resolve.In view of technical problem present in prior art, therefore, a kind of new safety of exigence every Above-mentioned technical problem is solved from mode.
The content of the invention
The present invention exactly calls Intranet service for technical problem present in prior art there is provided a kind of internet security System and method so that can be realized between internet and enterprises and institutions and government offices' internal network information exchange be total to Enjoy, while ensureing the safety of information in service invocation procedure.
To achieve these goals, the technical solution adopted by the present invention is that a kind of internet security calls what Intranet was serviced System, including:The webserver, outer application server, interior application server, one-way optical gate, unidirectional Quick Response Code equipment, audit clothes Business device, business system server, the webserver are connected by internet with outer application server, the outer application clothes On the one hand described one-way optical gate is connected between business device and interior application server, be on the other hand connected with the audit server and Two unidirectional Quick Response Code equipments, the audit server is only connected with two unidirectional Quick Response Code equipments, the interior application service Device is connected by Intranet with internal business systems server.The interior unidirectional Quick Response Code equipment is an ally inside the enemy's camp with server with examining The signal transmission apparatus between server is counted, the implementing result from interior application server is received, implementing result is converted into two dimension Then code passes through screen display;The outer unidirectional Quick Response Code equipment is passed as the signal between audit server and outer application server Transfer device, receives the data from audit server, and it is parsed, and the implementing result after most parsing at last is transmitted to outer Application server.So design not only ensure that the safety of service call result, while also compensate for using one-way optical gate when institute The defect audited without individual secure existed.The ingenious practicality of whole Technical Design, not only causes enterprises and institutions and country It can realize that information exchange is shared between machine-operated internal network and internet, and also ensure that information in service invocation procedure It is safe and reliable.
The method that internet security calls Intranet to service is realized using said system, is comprised the following steps:
Step one, the webserver sends service invocation request to the outer application server;
The service invocation request of reception is sent to the interior application server by step 2, the outer application server;
Step 3, the interior application server receives the service invocation request from the outer application server, performs clothes Business operation, and the implementing result of return is sent to the interior unidirectional Quick Response Code equipment;
Step 4, the interior unidirectional Quick Response Code equipment is handled the implementing result of reception, and passes through screen display;
Step 5, the audit server obtains the execution knot from the outer unidirectional Quick Response Code equipment by capture apparatus Really, and to it parse, the obtained implementing result of parsing audited, then by by the data conversion of audit into two dimension Code, finally by screen display;
Step 6, the outer unidirectional Quick Response Code equipment obtains the implementing result by auditing by capture apparatus, and it is entered Row processing
, it is sent to the outer application server;
Step 7, the outer application server receives the implementing result from the outer unidirectional Quick Response Code equipment, and will hold Row result returns to the webserver;
Step 8, the webserver receives the service call result returned.
As a modification of the present invention, the audit server is obtained through the interior unidirectional Quick Response Code by capture apparatus The implementing result of equipment processing, and is parsed to it, the implementing result that parsing is obtained is carried out information filtering, data check, Data deciphering etc. is operated, and then Quick Response Code will be converted into by the implementing result of audit, finally by screen display.
As a modification of the present invention, the interior application server is supported using soap protocol, http protocol, ODBC skills 3 kinds of modes of art select one or any combination form and business system server between carry out data interaction.It can so meet many Application scenario is planted, expands the use scope of system.
Relative to prior art, the features of the present invention and its effect are:The outer application server and interior application service Do not connect, and be attached using audit server and two unidirectional Quick Response Code equipments, institute only with one-way optical gate between device State audit server to be only connected with two unidirectional Quick Response Code equipments, complete physical isolation is realized with other equipment, it is ensured that examine Meter server is not easily susceptible to ensure that auditing result is safe and reliable while attack;Pass through tune of the audit server to return Audited with result, ensured the safety of call result.
Brief description of the drawings
Fig. 1 is the system structure diagram that internet calls that Intranet is serviced described in background technology.
Fig. 2 is the system structure diagram that internet proposed by the invention calls Intranet to service.
Fig. 3 calls the implementation process figure of the method for Intranet service for the internet security of the present invention.
Embodiment
In order to deepen the understanding of the present invention and understanding, the invention will be further described below in conjunction with the accompanying drawings and introduces.
Embodiment 1:As shown in Fig. 2 a kind of internet security calls the system that Intranet is serviced, including:It is the webserver, outer Application server, interior application server, one-way optical gate, outer unidirectional Quick Response Code equipment, interior unidirectional Quick Response Code equipment, auditing service Device, business system server, the webserver are connected by internet with outer application server, the outer application service On the one hand described one-way optical gate is connected between device and interior application server, the audit server and two are on the other hand connected with Platform unidirectional Quick Response Code equipment, the audit server is only connected with two unidirectional Quick Response Code equipments, the interior application server It is connected by Intranet with internal business systems server.Letter of the present invention between outer application server and interior application server One-way optical gate is not use only in breath interaction, unidirectional Quick Response Code equipment and audit server, and audit server is additionally used Only be connected with unidirectional Quick Response Code equipment, realize complete physical isolation with other equipment, it is ensured that audit server be difficult by To attack.The call result of return is audited by audit server, the safety of call result has not only been ensured, has also ensured The safe and reliable interaction of data message between inside and outside application server.
The outer application server, the service invocation request for receiving webserver transmission obtains specific request Information, is sent to interior application server;
The interior application server, the service invocation request for receiving outer application server transmission, specifically please be obtained Information is sought, service operations are performed, implementing result is returned;
The interior unidirectional Quick Response Code equipment, the implementing result for receiving interior application server transmission, and at it Reason;
The outer unidirectional Quick Response Code equipment, is handled for receiving the implementing result from audit server, and to it;
The one-way optical gate, for realizing the physical isolation of internet and Intranet, while realizing data from outer application service Device to interior application server one-way transmission;
The webserver, for sending service invocation request, receives the service call result returned;
The audit server, audits for the implementing result to return.
Set in addition, the interior unidirectional Quick Response Code equipment is an ally inside the enemy's camp with the signal transmission between server and audit server It is standby, the implementing result from interior application server is received, and implementing result is converted into Quick Response Code, then pass through screen display; The outer unidirectional Quick Response Code equipment is received from audit as the signal transmission apparatus between audit server and outer application server The data of server, and data are parsed, the implementing result after most parsing at last is transmitted to outer application server.So set Meter not only ensure that the safety of service call result, while existing when also compensate for using one-way optical gate examine without individual secure The defect of meter.
Embodiment 2:As shown in Fig. 2 as a modification of the present invention, the audit server is obtained through described interior unidirectional The implementing result of two-dimentional decoding apparatus processing, and it is parsed, information filtering, data are carried out to the implementing result that parsing is obtained Verification, Data Audit etc. are operated, and the implementing result by audit then are converted into Quick Response Code, and pass through screen display.Remaining Structure and advantage are identical with embodiment 1.
Embodiment 3:As shown in Fig. 2 as a modification of the present invention, the interior application server is supported using SOAP associations View, http protocol, 3 kinds of modes of ODBC technology select one or any combination form and business system server between carry out data friendship Mutually.Various application occasions can be so met, expand the use scope of system.Remaining structure and advantage and the complete phase of embodiment 1 Together.
As shown in figure 3, the implementation process that Intranet is serviced is called for internet security of the present invention, it is specific as follows:
S302, the webserver sends service invocation request to outer application server;
S304, outer application server receives the service invocation request that the webserver is sent, and obtains specific solicited message;
S306, outer application server is pre-processed and security strategy processing to solicited message;
Solicited message after processing is sent to interior application server by S308, outer application server;
S310, interior application server receives the service invocation request that outer application server is sent, and obtains specific request letter Breath;
S312, interior application server performs service operations according to solicited message, returns to implementing result;
The implementing result of return is sent to interior unidirectional Quick Response Code equipment by S314, interior application server;
S316, interior unidirectional Quick Response Code equipment receives the implementing result that interior application server is sent, and is handled;
The S316 is to the concrete processing procedure of implementing result:The implementing result that first interior application server is sent is changed Into Quick Response Code, then pass through screen display.
S318, audit server is obtained by capture apparatus and comes from interior unidirectional Quick Response Code equipment implementing result, and it is entered Row audit is handled;
The S318 is to the concrete processing procedure of implementing result:Implementing result first to acquisition is parsed, and right Parse obtained data and carry out the operation such as information filtering, data check, Data Audit, then by by the data conversion of audit into Quick Response Code, eventually through screen display.
S320, outer unidirectional Quick Response Code equipment obtains the data from audit server by capture apparatus, and is handled;
The concrete processing procedure to implementing result of the S320 is:Data first to acquisition are parsed, and then will Obtained data transfer is parsed into outer application server;
S322, outer application server receives the implementing result that outer unidirectional Quick Response Code equipment is sent, and is sent to network service Device;
S324, the webserver receives the implementing result that outer application server is returned.
At least one in technical characteristic described in embodiment 2,3 can also be combined to form new by the present invention with embodiment 1 Embodiment.
It should be noted that above-described embodiment, not for limiting protection scope of the present invention, in above-mentioned technical proposal On the basis of made equivalents or replacement each fall within the scope that the claims in the present invention are protected.

Claims (3)

1. a kind of internet security calls the system that Intranet is serviced, it is characterised in that system includes:The webserver, outer application Server, interior application server, one-way optical gate, outer unidirectional Quick Response Code equipment, interior unidirectional Quick Response Code equipment, audit server, industry Be engaged in system server, the webserver is connected by internet with outer application server, the outer application server and On the one hand described one-way optical gate is connected between interior application server, the audit server and two lists is on the other hand connected with To two-dimentional decoding apparatus, the audit server is only connected with two unidirectional Quick Response Code equipments, and the interior application server passes through Intranet is connected with internal business systems server;The interior unidirectional Quick Response Code equipment is received from the interior application server Implementing result, implementing result is converted into the form of Quick Response Code, then by screen display, and the outer unidirectional Quick Response Code equipment is led to Cross capture apparatus to obtain after the implementing result from audit server, first it is parsed, then will parse obtained execution As a result it is sent to outer application server;
The method that internet security calls Intranet to service is realized using said system, following steps are specifically included:
Step one, the webserver sends service invocation request to the outer application server;
The service invocation request of reception is sent to the interior application server by step 2, the outer application server;
Step 3, the interior application server receives the service invocation request from the outer application server, performs service behaviour Make, and the implementing result of return is sent to the interior unidirectional Quick Response Code equipment;
Step 4, the interior unidirectional Quick Response Code equipment is handled the implementing result of reception, and passes through screen display;
Step 5, the audit server receives the implementing result from the interior unidirectional Quick Response Code equipment by capture apparatus, It is parsed, then the implementing result that parsing is obtained is audited, the implementing result after audit is finally passed through into screen Display;
Step 6, the outer unidirectional Quick Response Code equipment is sent to the outer application to being handled by the implementing result of audit Server;
Step 7, the outer application server receives the implementing result from the outer unidirectional Quick Response Code equipment, and will perform knot Fruit returns to the webserver;
Step 8, the webserver receives the service call result returned.
2. a kind of internet security as claimed in claim 1 calls the system that Intranet is serviced, it is characterised in that the audit clothes Business device obtains the implementing result that the interior unidirectional Quick Response Code equipment is handled by capture apparatus, and implementing result is parsed, Then information filtering, data check, Data Audit are carried out to the implementing result after parsing to operate, the implementing result of audit will be passed through Quick Response Code is converted into, finally by screen display.
3. a kind of internet security as claimed in claim 1 calls the system that Intranet is serviced, it is characterised in that the interior application Server is supported to select the form and operation system of one or any combination using soap protocol, http protocol, 3 kinds of modes of ODBC technology Data interaction is carried out between server.
CN201410482360.XA 2014-09-22 2014-09-22 A kind of internet security calls the system and method that Intranet is serviced Active CN104301307B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410482360.XA CN104301307B (en) 2014-09-22 2014-09-22 A kind of internet security calls the system and method that Intranet is serviced

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410482360.XA CN104301307B (en) 2014-09-22 2014-09-22 A kind of internet security calls the system and method that Intranet is serviced

Publications (2)

Publication Number Publication Date
CN104301307A CN104301307A (en) 2015-01-21
CN104301307B true CN104301307B (en) 2017-11-03

Family

ID=52320875

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410482360.XA Active CN104301307B (en) 2014-09-22 2014-09-22 A kind of internet security calls the system and method that Intranet is serviced

Country Status (1)

Country Link
CN (1) CN104301307B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110891052A (en) * 2019-11-06 2020-03-17 北京吉威数源信息技术有限公司 Cross-network query system and method for spatial data of natural resources

Citations (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN201438702U (en) * 2009-03-20 2010-04-14 北京锐安科技有限公司 Unidirectional document transmission system
CN101764768A (en) * 2010-01-19 2010-06-30 北京锐安科技有限公司 Data security transmission system
US7805049B2 (en) * 2003-07-16 2010-09-28 Doron Handelman Devices and methods for all-optical processing and storage
CN202385106U (en) * 2011-12-15 2012-08-15 北京天行网安信息技术有限责任公司 Unidirectionally isolated optical gate
CN203166988U (en) * 2013-03-28 2013-08-28 施国君 Direct connection type unidirectional infrared physical isolation shutter
CN203482233U (en) * 2013-03-28 2014-03-12 施国君 Direct connection type unidirectional optical fiber physical isolation shutter
CN103714151A (en) * 2013-12-26 2014-04-09 北京锐安科技有限公司 One-way optical gate and method for carrying out data synchronizing between heterogeneous databases
CN203775214U (en) * 2014-04-09 2014-08-13 武汉科源安信科技有限公司 Infrared gate unidirectional data transmission machine
CN104301306A (en) * 2014-09-22 2015-01-21 江苏飞搏软件技术有限公司 System used for calling intranet services safely through Internet
CN103259781B (en) * 2013-04-07 2016-12-28 内蒙古华腾科技股份有限公司 Data transmission system based on image recognition

Patent Citations (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7805049B2 (en) * 2003-07-16 2010-09-28 Doron Handelman Devices and methods for all-optical processing and storage
CN201438702U (en) * 2009-03-20 2010-04-14 北京锐安科技有限公司 Unidirectional document transmission system
CN101764768A (en) * 2010-01-19 2010-06-30 北京锐安科技有限公司 Data security transmission system
CN202385106U (en) * 2011-12-15 2012-08-15 北京天行网安信息技术有限责任公司 Unidirectionally isolated optical gate
CN203166988U (en) * 2013-03-28 2013-08-28 施国君 Direct connection type unidirectional infrared physical isolation shutter
CN203482233U (en) * 2013-03-28 2014-03-12 施国君 Direct connection type unidirectional optical fiber physical isolation shutter
CN103259781B (en) * 2013-04-07 2016-12-28 内蒙古华腾科技股份有限公司 Data transmission system based on image recognition
CN103714151A (en) * 2013-12-26 2014-04-09 北京锐安科技有限公司 One-way optical gate and method for carrying out data synchronizing between heterogeneous databases
CN203775214U (en) * 2014-04-09 2014-08-13 武汉科源安信科技有限公司 Infrared gate unidirectional data transmission machine
CN104301306A (en) * 2014-09-22 2015-01-21 江苏飞搏软件技术有限公司 System used for calling intranet services safely through Internet

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
公安警务公开(对公网数据传输)项目边界接入;北京以利天诚科技有限公司;《URL:http://wenku.baidu.com/view/8034cd455f0e7cd184253672.html》;20140620;说明书第2页 *
单向传输光闸在"网上警局"网络解决方案;北京以利天诚科技有限公司;《URL: http://wenku.baidu.com/view/762e34e2a58da0116c17493c.html》;20140107;说明书第2页 *

Also Published As

Publication number Publication date
CN104301307A (en) 2015-01-21

Similar Documents

Publication Publication Date Title
CN104301306B (en) The system that a kind of internet security calls Intranet service
CN104125240A (en) Information external network, information internal network, and system and method for data interaction between internal network and external network
CN101764768A (en) Data security transmission system
WO2006014745A3 (en) Media enhanced gaming system
WO2015095597A8 (en) Devices and methods for improving web safety and deterrence of cyberbullying
CN105871657B (en) A kind of Network Data Control system and method based on Android platform
TW200715856A (en) System for video conference, proxy and method thereof
CL2012000868A1 (en) A method of providing access to an account maintained by a financial institution.
GB201201921D0 (en) An apparatus, method and computer system for reporting the impact of broadcasts
CN107239308A (en) A kind of calling function realization method and system of browser
WO2011155996A3 (en) Group messaging integration system, method and apparatus
CN106557820A (en) A kind of power transformation O&M standard operation mobile terminal platform
CN104301307B (en) A kind of internet security calls the system and method that Intranet is serviced
WO2013030166A3 (en) Method for transmitting video signals from an application on a server over an ip network to a client device
US11656608B2 (en) Rule-based communicating of equipment data from an industrial system to an analysis system using uni-directional interfaces
CN102917212A (en) 3G (The 3rd Generation Telecommunication) wireless video monitoring implementation method and 3G wireless video monitoring system based on RTP (Real Time Protocol) and RTSP (Real Time Streaming Protocol)
CN105635996A (en) Mobile phone short message receiving method of intelligent wearable equipment and server thereof
CN103516789B (en) From Office Network to the management method and system of the transmission data of production net
CN109347727A (en) A kind of social network information delivery system
CN109889369A (en) A kind of more net redundant data transmissions methods
CN202998321U (en) Security monitoring system and monitor
CN103402017A (en) Terminal and data processing method
WO2013043943A3 (en) Secure processing of confidential information on a network
CN103428201A (en) Multilink network information interaction method and system
CN202818347U (en) RTSP gateway equipment

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information

Address after: Bunning Technology Park No. 2 Yuhua Road in Yuhuatai District of Nanjing City, Jiangsu province 210012 4 floor, Room 405

Applicant after: JIANGSU FABLESOFT Co.,Ltd.

Address before: 210012 Yuhuatai City, Nanjing province tulip Road, No. C, building 4, building No., No. 401, No. 17

Applicant before: JIANGSU FEIBO SOFTWARE TECHNOLOGY Co.,Ltd.

CB02 Change of applicant information
GR01 Patent grant
GR01 Patent grant
TR01 Transfer of patent right

Effective date of registration: 20220811

Address after: Room 311, 3rd Floor, Block D, Hongtu Smart Technology Industrial Park, No. 68, Software Avenue, Yuhuatai District, Nanjing City, Jiangsu Province, 210012

Patentee after: Nanjing Feibo Data Technology Co.,Ltd.

Address before: Room 405, 4th floor, bonning Science Park, 2 Yuhua Avenue, Yuhuatai District, Nanjing City, Jiangsu Province, 210012

Patentee before: JIANGSU FABLESOFT Co.,Ltd.

TR01 Transfer of patent right
PE01 Entry into force of the registration of the contract for pledge of patent right

Denomination of invention: A System and Method of Internet Security Calling Intranet Services

Granted publication date: 20171103

Pledgee: Bank of Nanjing Co.,Ltd. Nanjing Chengnan sub branch

Pledgor: Nanjing Feibo Data Technology Co.,Ltd.

Registration number: Y2024980007216

PE01 Entry into force of the registration of the contract for pledge of patent right