CN115242422B - Data intercommunication processing method and device and informationized management system - Google Patents

Data intercommunication processing method and device and informationized management system Download PDF

Info

Publication number
CN115242422B
CN115242422B CN202210535944.3A CN202210535944A CN115242422B CN 115242422 B CN115242422 B CN 115242422B CN 202210535944 A CN202210535944 A CN 202210535944A CN 115242422 B CN115242422 B CN 115242422B
Authority
CN
China
Prior art keywords
network environment
target
file
data
sharing system
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202210535944.3A
Other languages
Chinese (zh)
Other versions
CN115242422A (en
Inventor
梁伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba China Co Ltd
Original Assignee
Alibaba China Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba China Co Ltd filed Critical Alibaba China Co Ltd
Priority to CN202210535944.3A priority Critical patent/CN115242422B/en
Publication of CN115242422A publication Critical patent/CN115242422A/en
Application granted granted Critical
Publication of CN115242422B publication Critical patent/CN115242422B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0209Architectural arrangements, e.g. perimeter networks or demilitarized zones
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/06Protocols specially adapted for file transfer, e.g. file transfer protocol [FTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/03Protocol definition or specification 
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/22Parsing or analysis of headers

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)

Abstract

The embodiment of the application discloses a data intercommunication processing method, a device and an informationized management system, wherein the informationized management system comprises: a first information management subsystem operating in a first network environment, and a second information management subsystem operating in a second network environment; the first network environment and the second network environment are isolated through hardware equipment; a target file sharing system is deployed in the first network environment and the second network environment; the first network environment and the second network environment are also provided with data intercommunication service terminals, which are used for converting target data into target files after generating the target data needing to be interacted across the network environments, and uploading the target files to the target file system; on the receiving side, the target file is received through the target file sharing system. By the embodiment of the application, the data intercommunication between the internal network and the external network can be realized more efficiently.

Description

Data intercommunication processing method and device and informationized management system
Technical Field
The present invention relates to the field of information processing technologies in cross-network environments, and in particular, to a data intercommunication processing method, device, and information management system.
Background
Along with the popularization and application of the information technology, the informatization work of some organizations has the characteristics of high development speed, wide coverage range, quick updating and upgrading and high working efficiency, and the reinforced informatization construction not only can improve the modern office level and enhance the resource sharing, but also can provide powerful technical support for the organization management system construction.
During the informative construction, the organization may need to cooperate with third party technology developers. However, since some sensitive information is often involved in the organization system, an internal private network (for short, an intranet) is usually deployed, and the intranet and an external network (i.e., a public network) are separated by a device such as a physical isolation gatekeeper. For example, in an organization system, computers that process internally sensitive information operate as independent private networks, physically isolated from external networks that process other non-sensitive data, and so forth. The private network operation mode ensures the information security and confidentiality to the maximum extent, and brings a series of problems and inconvenience for informationized construction projects cooperated with third parties.
For example, an organization often has a demand for on-line release of some merchandise that requires auction, and for this demand, a informatization management system is built together with a developer of the merchandise information service system. The information management system may be partially operated in an intranet and partially operated in an extranet, and may have a requirement for data transmission between the two parts, for example, commodities which are generated in the intranet of the information management system and need to be auctioned need to be sent to the extranet part for on-shelf processing, and the like. However, due to the existence of the physically isolated gatekeeper device in the intranet, internet technology cannot directly provide the organization with the above services.
In the prior art, in order to realize data intercommunication between the internal network and the external network, special approval is usually required to be carried out to related departments, and after approval is passed, physical network gate equipment can be opened to realize data intercommunication between the internal network and the external network. However, this approval process may be complex and inefficient to implement.
Therefore, how to implement the data intercommunication between the internal and external networks more efficiently becomes a technical problem that needs to be solved by those skilled in the art.
Disclosure of Invention
The application provides a data intercommunication processing method, a data intercommunication processing device and an informationized management system, which can realize the intercommunication of internal and external network data more efficiently.
The application provides the following scheme:
an information-based management system is provided, which comprises a management server,
the information management system includes: a first information management subsystem operating in a first network environment, and a second information management subsystem operating in a second network environment; the first network environment and the second network environment are isolated through hardware equipment;
the first network environment and the second network environment are provided with target file sharing systems, and the target file systems are as follows: a file sharing system which can realize intercommunication between the first network environment and the second network environment by opening the isolation;
The first network environment and the second network environment are also provided with a data intercommunication server;
the data intercommunication server is used for converting target data into a target file after one of the first information management subsystem or the second information management subsystem generates the target data needing to be interacted across the network environment, and uploading the target file to the target file system; and on a receiving side, receiving the target file through the target file sharing system, analyzing the target file through the protocol, and restoring the target file into the target data so as to provide the target data for the other one of the first information management subsystem and the second information management subsystem for processing.
A data interworking processing method, comprising:
determining target data to be interacted between the first network environment and the second network environment across the network environments; the first network environment and the second network environment are isolated through hardware equipment;
converting the target data into a target file according to a preset protocol;
uploading the target file to a target file sharing system, wherein the target file sharing system is as follows: and the file sharing system which is isolated and can realize intercommunication between the first network environment and the second network environment is opened, so that the target file is received at a receiving side in a mode of monitoring the target file sharing system, and the target file is analyzed through the protocol and then restored into the target data.
The step of converting the target data into the target file according to a preset protocol comprises the following steps:
and generating the file name of the target file according to the file naming rule configured in the protocol.
The file name comprises a network environment identifier for executing uploading operation, so that when a receiving side monitors that a new file is generated in the file sharing system, whether the file is the current network environment or the file uploaded in the opposite network environment is judged through the network environment identifier in the file name, and whether downloading processing is carried out is determined according to a judging result.
The file name comprises data number information, so that the receiving side can utilize the data number information to carry out integrity check on the restored data after restoring the target file into the target data.
The file name comprises a data type identifier, so that a receiving side can provide the data type identifier for a corresponding module to process after restoring the target file into the target data.
The uploading the target file to a target file sharing system comprises the following steps:
uploading the target file to a target file sharing system through a target account, and receiving the target file in a mode that the target file sharing system is detected through the target account;
The target account number is an account number which is registered in the target file sharing system in advance.
Wherein the target data includes: target data which is generated by one of a first informatization management subsystem running in the first network environment or a second informatization management subsystem running in the second network environment and needs to be interacted across the network environments.
Wherein the target data includes: commodity information that is interacted across network environments, and/or a variety of information generated on information distribution and transaction links, is required between a first network environment and a second network environment.
Wherein the target data includes: message or instruction class data is needed for cross-network environment interactions between the first network environment and the second network environment.
A method of data interworking, comprising:
detecting a target file sharing system, wherein the target file system is communicated with the first network environment and the second network environment through isolation formed by hardware equipment so as to realize intercommunication between the first network environment and the second network environment;
if a new target file appears in the target file sharing system, downloading the target file from the target file sharing system, wherein the target file is generated after converting target data needing to be interacted between a first network environment and a second network environment in a cross-network environment according to a preset protocol, and storing the target data in the target file sharing system;
And analyzing the target file through the protocol, and then restoring the target file into the target data so as to process the target data.
A data interworking processing apparatus comprising:
a target data determining unit, configured to determine target data that needs to interact across network environments between a first network environment and a second network environment; the first network environment and the second network environment are isolated through hardware equipment;
the file conversion unit is used for converting the target data into a target file according to a preset protocol;
the file uploading unit is used for uploading the target file to a target file sharing system, and the target file sharing system is: and the file sharing system which is isolated and can realize intercommunication between the first network environment and the second network environment is opened, so that the target file is received at a receiving side in a mode of detecting the target file sharing system, and the target file is analyzed through the protocol and then restored into the target data.
A data interworking apparatus comprising:
the detection unit is used for detecting a target file sharing system, wherein the target file sharing system is communicated with the first network environment and the second network environment through isolation formed by hardware equipment so as to realize intercommunication between the first network environment and the second network environment;
The file acquisition unit is used for downloading and acquiring the target file from the target file sharing system if a newly added target file appears in the target file sharing system, wherein the target file is generated after converting target data needing to be interacted between a first network environment and a second network environment in a cross-network environment according to a preset protocol and is stored in the target file sharing system;
and the data conversion unit is used for analyzing the target file through the protocol and then restoring the target file into the target data so as to process the target data.
A computer readable storage medium having stored thereon a computer program which when executed by a processor performs the steps of the method of any of the preceding claims.
An electronic device, comprising:
one or more processors; and
a memory associated with the one or more processors, the memory for storing program instructions that, when read for execution by the one or more processors, perform the steps of the method of any of the preceding claims.
According to a specific embodiment provided by the application, the application discloses the following technical effects:
According to the method and the device for implementing the data communication between the first network environment and the second network environment, in the information management system crossing the network environments, target data of interaction between the first network environment and the second network environment is required, and under the condition that isolation is conducted between the first network environment and the second network environment through hardware equipment, if a target file sharing system is deployed in the first network environment and the second network environment, and isolation between networks is achieved through the target file sharing system, intercommunication between the first network environment and the second network environment can be achieved, and a data intercommunication server can be provided in the first network environment and the second network environment. On the transmitting side, the target data can be converted into a target file according to a certain protocol through the data intercommunication server, and then the target file is uploaded to a target file sharing system. And the data intercommunication server of the receiving side can receive the target file by monitoring the target file sharing system, and analyze the target file by the protocol and restore the target file into target data. Therefore, the intercommunication capability of the internal and external networks of the file sharing system can be endowed to the informationized management system crossing the network environment, so that the data intercommunication of the informationized management system between the internal and external networks is realized under the condition that additional approval is not needed.
Of course, not all of the above-described advantages need be achieved at the same time in practicing any one of the products of the present application.
Drawings
In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings that are needed in the embodiments will be briefly described below, and it is obvious that the drawings in the following description are only some embodiments of the present application, and that other drawings can be obtained according to these drawings without inventive effort for a person skilled in the art.
FIG. 1 is a schematic diagram of an information management system provided in an embodiment of the present application;
FIG. 2 is a flow chart of a first method provided by an embodiment of the present application;
FIG. 3 is a flow chart of a second method provided by an embodiment of the present application;
FIG. 4 is a schematic diagram of a first apparatus provided in an embodiment of the present application;
FIG. 5 is a schematic diagram of a second apparatus provided in an embodiment of the present application;
fig. 6 is a schematic diagram of an electronic device provided in an embodiment of the present application.
Detailed Description
The following description of the embodiments of the present application will be made clearly and fully with reference to the accompanying drawings, in which it is evident that the embodiments described are only some, but not all, of the embodiments of the present application. All other embodiments obtained by a person of ordinary skill in the art based on the embodiments in the present application are within the scope of the protection of the present application.
In the embodiment of the application, for the informatization management system running across the network environment, a new solution is provided for avoiding the intercommunication of the internal and external network data by additionally carrying out the internal and external network examination and approval. Specifically, in the process of implementing the application, the inventor of the application finds that a file sharing system may be deployed inside some organizations to meet the different-place office requirements of personnel in the organizations, where the file sharing system may be a software product similar to a "cloud disk" or a "network disk", and unlike a common "cloud disk" or a "network disk", the file sharing system may be accessed through an external network (i.e. the internet or a public network) or an internal network of the organizations (whereas a common "cloud disk" or a "network disk" may only be accessed through an external network). This is because, when a specific file sharing system is deployed, isolation between the internal and external networks is already opened, and interworking between the internal and external networks can be achieved. Thus, if a user in an organization needs to be able to process some files after going home or going out to the outside, a specific file can be uploaded to the file sharing system in an intranet, and after going out to the outside, the user can check the specific file by logging in the file sharing system, can also download the file to the local for checking, and so on.
That is, the above-mentioned file sharing system capable of achieving interworking between the intranet and the extranet may have been deployed in the intranet environment of the organization, but in the prior art, such a file sharing system is generally provided for users to use in a scene such as a foreign office. In the embodiment of the application, the file sharing system can be used for realizing the intercommunication of the internal network and the external network of the information management system crossing the network environment. Specifically, the file sharing system can be deployed in an external network environment where the specific information management system is located, so that the internal and external network intercommunication capability of the file sharing system can be endowed to the information management system crossing the network environment, and the data intercommunication between the internal and external networks can be realized without additional approval for the information management system. Meanwhile, in the information management system of the cross-network environment, data to be transmitted from the intranet to the extranet comprises commodity information and the like to be auctioned, and the information is not sensitive or confidential, so that the data which can be transmitted to the extranet is determined after being allowed by an organization, and the problem of data security does not exist.
Specific embodiments provided in the embodiments of the present application are described in detail below.
Example 1
First, this embodiment provides an information management system, referring to fig. 1, which may include: a first information management subsystem 101 operating in a first network environment, and a second information management subsystem 102 operating in a second network environment; the first network environment and the second network environment are isolated through hardware equipment;
a target file sharing system 103 is deployed between the first network environment and the second network environment, where the target file system is: a file sharing system which can realize intercommunication between the first network environment and the second network environment by opening the isolation;
the first network environment and the second network environment are also provided with a data intercommunication server 104;
the data interworking server 104 is configured to, after generating target data that needs to be interacted across a network environment by one of the first information management subsystem or the second information management subsystem, convert the target data into a target file, and upload the target file to the target file system; and on a receiving side, receiving the target file through the target file sharing system, analyzing the target file through the protocol, and restoring the target file into the target data so as to provide the target data for the other one of the first information management subsystem and the second information management subsystem for processing.
The first network environment and the second network environment may be an intranet and an extranet (i.e., the internet, the public network, etc.) inside the organization, respectively, and may be isolated by a device such as a gatekeeper. Among them, the so-called gatekeeper is called a security isolation gatekeeper. The safety isolation gatekeeper is a network safety device which cuts off the link layer connection between networks on a circuit by special hardware with various control functions and can perform safe and moderate application data exchange between networks. That is, after the gatekeeper device is deployed, a physical data barrier may be formed between the internal and external networks, and further, the use of wireless networks within a particular organization is not allowed, and the use of any network devices for data transmission is not allowed.
For an information management system across network environments, the information management system needs to be divided into two parts, including a first information management subsystem running in a first network environment and a second information management subsystem running in a second network environment. In addition, in a specific operation process, data interaction is often required between the first informatization management subsystem and the second informatization management subsystem. Thus, in the embodiment of the present application, the target data specifically needed to perform the cross-network environment interaction between the first network environment and the second network environment may include: target data which is generated by one of a first informatization management subsystem running in the first network environment or a second informatization management subsystem running in the second network environment and needs to be interacted across the network environments.
For example, assuming that the first network environment is an intranet environment of an organization, and the second network environment is an extranet environment, the specific information management system may be a system related to intelligent "auction", that is, the first information management subsystem may collect information about commodities that need to participate in the "auction" and then send the information to the second information management subsystem, where the second information management subsystem performs processing such as issuing of the commodities in the associated commodity information service system. Then, in the links of specific information release, transaction and the like of the merchandise information service system, some information may be generated, including information of the buyer user, order information, logistics information and the like, and may need to be returned to the first informationized management subsystem through the second informationized management subsystem, so that confirmation of purchasing qualification of the buyer user, confirmation of order information and the like on the organization side may be caused. In addition, some messages, instructions, etc. may also need to be interacted with between the first information management subsystem and the second information management subsystem. Such as a message confirming the purchasing qualification of the buyer user, etc. In summary, in the process of informatization management, data intercommunication needs to be implemented between the first informatization management subsystem and the second informatization management subsystem. However, since the first information management subsystem and the second information management subsystem operate in the first network environment and the second network environment respectively, and physical devices such as a gatekeeper exist between the first network environment and the second network environment for isolation, in the prior art, if data intercommunication between the first information management subsystem and the second information management subsystem is to be realized, a layer-by-layer approval is required to be performed to related departments to obtain permission to open the gatekeeper device. However, the approval process may be complicated, and may require a long time to wait, and may even fail.
In order to avoid the above-mentioned approval process, in the embodiment of the present application, the capability of intercommunication of internal and external network data of a file sharing system deployed in an internal network environment of an organization is given to an informationized management system crossing the network environment, so as to implement intercommunication of internal and external network data in the informationized management system. The file sharing system firstly opens devices such as a gateway, so that intercommunication between the internal network and the external network (namely, between the first network environment and the second network environment) can be realized, that is, files can be uploaded from the internal network environment and accessed or downloaded in the external network environment, or files can be uploaded from the external network environment and accessed or downloaded in the internal network environment, and the like. Therefore, in order to achieve the above objective, in the embodiment of the present application, the same file sharing system as that in the intranet environment may be deployed in the extranet environment where the information management system is located, that is, assuming that a certain software is installed in the intranet environment where the first information management subsystem is deployed to implement the file sharing system, the software may also be installed in the extranet environment where the second information management subsystem is deployed, so as to implement data communication between the first information management subsystem and the second information management subsystem.
However, in the prior art, a user in an organization needs to manually upload a specific file to a file sharing system and manually download the file, and in an application scenario of an informatization management system of a cross-network environment, in order to exert the advantage of informatization, the informatization management system can automatically trigger specific file uploading and downloading processing. However, in the information management system, information processing is generally performed in the data dimension, and the file sharing system performs information processing in the file dimension. For example, in an information management system inside an organization, a plurality of pieces of commodity information to be distributed to an external network may be generated, and the like, which cannot be directly stored in a file sharing system (in which information can be stored only in units of files).
Therefore, in the embodiment of the present application, a data interworking server may be provided in the first network environment and the second network environment, where the data interworking server is used to convert data that needs to be interacted across the network environment, which is generated in a specific first informatization management subsystem or a second informatization management subsystem, into a file according to a certain protocol, and then upload the file to a specific file sharing system. In addition, when a receiver (one of the first information management subsystem and the second information management subsystem generates specific data and becomes a sender, the other is the receiver, and the identities of the sender and the receiver are specific and can be interchanged), whether the file in the file sharing system is updated or not can be judged by detecting the mode of the file sharing system in real time or at fixed time, if the file is updated, whether the updated file is from the current network environment or the network environment of the other party can be judged, if the updated file is from the current network environment or the network environment of the other party, the corresponding file can be downloaded, and then the corresponding file is converted into data according to a corresponding protocol, and the data is processed by the specific information management system.
Specifically, for a specific data intercommunication server, the capabilities of data analysis, data uploading/downloading, monitoring and the like can be realized mainly through script and other modes. The target data to be uploaded can be converted into files through the data analysis module, and files downloaded from the file sharing system can be converted back into the original data. The data uploading/downloading module can be used for uploading or downloading specific files to the file sharing system, and the monitoring module is mainly used for monitoring whether the file sharing system generates new files.
In order to realize conversion from data to files and vice versa, a specific conversion protocol may be formulated in advance, so that a specific data analysis module may convert target data to be interacted into files in the preset protocol, and then may restore the files downloaded from the file sharing system into specific data according to the protocol.
The specific process of converting the data into the file may involve the generation of a file name and the generation of specific file contents. Here, regarding specific data such as target information and order information, specific data field names, data values, etc. may be converted into contents in the file; regarding data of the type of message, instruction, etc., when converted into a file, the specific file content may be empty, which message, which instruction, etc. are embodied by the file name.
In addition, since the data interworking servers are deployed in the first network environment and the second network environment, and both the data interworking servers can upload files to the file sharing file system or download files from the file sharing file system, the files uploaded by the first network environment side and the files uploaded by the second network environment side may exist in the sharing file system. The files uploaded by the user do not need to be downloaded, and only the files uploaded by the user do not need to be downloaded. Thus, when the file name is specifically generated, the network environment identifier for generating specific data may be added to the file name, for example, "intranet", "extranet" or the like may be included. Thus, when the specific data intercommunication server monitors a new file from the file sharing system, the specific data intercommunication server can determine whether the file is uploaded by the network environment where the specific data intercommunication server is located or the file uploaded by the network environment of the other party according to the network environment identification.
In addition, a specific data type identifier may be included in the file name, so that the receiving party can identify the corresponding data type according to the specific file name, and further, the corresponding data type can be processed by different data modules. For example, "target information," "order information," and the like may be included.
Furthermore, specific data number information can be embodied in the file name, that is, in the process of converting the target data into the file, multiple pieces of data may be converted into the same file, and in the process of data intercommunication, the situations of data loss and the like may be caused, so that the specific data number information can be embodied in the file name, and after the specific data is analyzed and restored from the specific file by the receiver, the integrity of the data can be checked according to the data number information in the file name. For example, the file name of a certain file may be: the intranet (tag information) (150), that is, the file is uploaded by the intranet by being known by the file name, the specific data type is tag information, 150 pieces of data in total, and the like.
After converting the target data into a file, the specific file may be uploaded to the file sharing system by the upload/download module. In a specific implementation, the specific file sharing system may be an account-based private system, for example, a certain corporate register a certain account in the shared file system and upload a certain file to the file sharing system by using the account, so that when the corporate downloads a file on the external network, the corporate also needs to log in the file sharing system through the account in the external network, so that the specific file can be viewed. Therefore, in the embodiment of the present application, in order to implement a specific file uploading/downloading operation, a user such as a user inside an organization may apply for an account in the file sharing system in advance, and then provide the account to a developer of the information management system, so that the developer may write the account information into a specific data intercommunication server. Thus, the data interworking server can be performed in a state of logging in to the file sharing system through the account number, regardless of the uploading or downloading of the file. For example, if it is necessary to send certain data from the intranet to the extranet, after the data is converted into a file, the file may be uploaded to the file sharing system in a state that the interworking server on the intranet side logs in to the file sharing system through the account number applied in advance. Correspondingly, the intercommunication server side of the external network side can monitor the file change condition in the file sharing system under the state of logging in the file sharing system through the same account number.
In the process of monitoring the file change condition of the file sharing system by the data intercommunication server, if a new file is found under the current account, the data is proved to be needed to be interacted between the intranet and the extranet. However, as described above, since the specific newly added file may be uploaded in the network environment where the current data interworking server is located, it may also be uploaded in the network environment of the other party; that is, it is assumed that a certain file is uploaded on the intranet side, and since the data interworking servers of the intranet and the extranet are both monitoring, the data interworking servers of the intranet side and the extranet can both monitor the newly uploaded file, but only the data interworking server of the extranet side needs to download the file. Therefore, when a new file is specifically monitored to be generated in the file sharing system, the generation source of the file can be determined, and then whether to download is determined. Specifically, as described above, if the file name carries the network environment identifier for generating the specific file, the above-mentioned determination may be made according to the network environment identifier in the file name, and so on.
After the specific file is downloaded, the file can be analyzed by the data analysis module by utilizing a specific protocol, so that the file is restored into specific data. After specific data is restored, if the file name also comprises data number information, the integrity of the analyzed data can be checked according to the information. In addition, if the file name also comprises data type information, the analyzed data can be provided for a corresponding module in the informationized management subsystem under the current network environment for processing.
In summary, according to the embodiment of the present application, in an information management system crossing network environments, target data of interaction between a first network environment and a second network environment is required, and in the case where isolation is performed between the first network environment and the second network environment by hardware devices, if a target file sharing system is deployed in the first network environment and the second network environment, and the target file sharing system has opened isolation between networks, the interworking between the first network environment and the second network environment can be implemented, a data interworking server may be provided in the first network environment and the second network environment. On the transmitting side, the target data can be converted into a target file according to a certain protocol through the data intercommunication server, and then the target file is uploaded to a target file sharing system. And the data intercommunication server of the receiving side can receive the target file by monitoring the target file sharing system, and analyze the target file by the protocol and restore the target file into target data. Therefore, the intercommunication capability of the internal and external networks of the file sharing system can be endowed to the informationized management system crossing the network environment, so that the data intercommunication of the informationized management system between the internal and external networks is realized under the condition that additional approval is not needed.
The scheme for realizing the data intercommunication between the internal network and the external network of the informationized management system is provided under the condition that additional approval is not needed. In practical application, the scheme can have various specific application scenes, for example, a specific intranet can be an internal network of an organization, and a specific informatization management system can be an informatization management system commonly constructed by a commodity information service provider and the organization, and is mainly used for realizing informatization management in the process of on-line selling of 'auction items'. The information management system can be divided into a part for running and organizing an intranet and a part for running on an extranet, and some data interaction is needed between the two parts. For example, the organization intranet section needs to transmit information of newly generated "auction items" to the extranet section for distribution, the extranet section needs to transmit information of consumer users who perform purchasing operations to the organization intranet section for confirmation of purchasing qualifications, etc., and so on. In the process, the intranet part of the informationized management system can provide the information of the 'auction items' for the data intercommunication server side of the intranet part, and the server side converts the information to be transmitted into files and uploads the files to the file sharing system of the intranet of the organization. Correspondingly, the data intercommunication server side of the external network part can monitor the file from the file sharing system, restore the information of the file, and then perform processing such as release in the commodity information service system. Similarly, when the consumer user browses to the issued information through the commodity information service system and generates a purchase request, the information management system of the external network part can also convert the user information into a file through the data intercommunication service end of the external network part, upload the file to the file sharing system, receive the file through the data intercommunication service end of the internal network part, and provide the file to relevant personnel or programs in the organization to confirm the purchase qualification and the like of the consumer user, and the like.
Example two
The second embodiment corresponds to the first embodiment, and from the perspective of the data interworking server on the transmitting side, a data interworking processing method is provided, referring to fig. 2, and the method may include:
s201: determining target data to be interacted between the first network environment and the second network environment across the network environments; the first network environment and the second network environment are isolated through hardware equipment;
s202: converting the target data into a target file according to a preset protocol;
s203: uploading the target file to a target file sharing system, wherein the target file sharing system is as follows: and the file sharing system which is isolated and can realize intercommunication between the first network environment and the second network environment is opened, so that the target file is received at a receiving side in a mode of detecting the target file sharing system, and the target file is analyzed through the protocol and then restored into the target data.
In the process of converting the target data into the target file, the file name of the target file can be generated according to the file naming rule configured in the protocol.
Specifically, the file name may include a network environment identifier for performing an uploading operation, so that when the receiving side monitors that a new file is generated in the file sharing system, whether the file is the current network environment or the file uploaded in the opposite network environment is determined according to the network environment identifier in the file name, and whether to perform downloading processing is determined according to a determination result.
Or, the file name may further include data number information, so that after the receiving side restores the target file to the target data, the receiving side performs integrity check on the restored data by using the data number information.
In addition, the file name can also include a data type identifier, so that the receiving side can provide the corresponding module with the data type identifier for processing after restoring the target file into the target data.
Specifically, when uploading the target file to a target file sharing system, uploading the target file to the target file sharing system through a target account, and further receiving the target file in a mode that the target account detects the target file sharing system; the target account number is an account number which is registered in the target file sharing system in advance.
In practical applications, the target data may include: target data which is generated by one of a first informatization management subsystem running in the first network environment or a second informatization management subsystem running in the second network environment and needs to be interacted across the network environments. Of course, in practical applications, other data that needs to be interacted between the first network environment and the second network environment may also be used.
Specifically, the target data may include: commodity information that is interacted across network environments, and/or a variety of information generated on information distribution and transaction links, is required between a first network environment and a second network environment. Alternatively, the target data may further include: message or instruction class data is needed for cross-network environment interactions between the first network environment and the second network environment.
Example III
The third embodiment also corresponds to the first embodiment, and from the perspective of the data interworking server on the receiving side, a data interworking method is provided, and referring to fig. 3, the method may include:
s301: detecting a target file sharing system, wherein the target file system is communicated with the first network environment and the second network environment through isolation formed by hardware equipment so as to realize intercommunication between the first network environment and the second network environment;
S302: if a new target file appears in the target file sharing system, downloading the target file from the target file sharing system, wherein the target file is generated after converting target data needing to be interacted between a first network environment and a second network environment in a cross-network environment according to a preset protocol, and storing the target data in the target file sharing system;
s303: and analyzing the target file through the protocol, and converting the target file into the target data so as to process the target data.
For the parts of the second and third embodiments, which are not described in detail, reference may be made to the description of the first embodiment and other parts of the present specification, and the details are not repeated here.
It should be noted that, in the embodiments of the present application, the use of user data may be involved, and in practical applications, user specific personal data may be used in the schemes described herein within the scope allowed by applicable legal regulations in the country where the applicable legal regulations are met (for example, the user explicitly agrees to the user to actually notify the user, etc.).
Corresponding to the embodiment, the embodiment of the application also provides a data intercommunication processing device, referring to fig. 4, the device may include:
A target data determining unit 401, configured to determine target data that needs to perform cross-network environment interaction between the first network environment and the second network environment; the first network environment and the second network environment are isolated through hardware equipment;
a file conversion unit 402, configured to convert the target data into a target file according to a preset protocol;
a file uploading unit 403, configured to upload the target file to a target file sharing system, where the target file sharing system is: and the file sharing system which is isolated and can realize intercommunication between the first network environment and the second network environment is opened, so that the target file is received at a receiving side in a mode of detecting the target file sharing system, and the target file is analyzed through the protocol and then is converted into the target data.
Specifically, the file conversion unit may specifically be configured to:
and generating the file name of the target file according to the file naming rule configured in the protocol.
The file name may include a network environment identifier for performing an uploading operation, so that when the receiving side monitors that a new file is generated in the file sharing system, whether the file is a current network environment or an uploaded file in a counterpart network environment is determined through the network environment identifier in the file name, and whether to perform downloading processing is determined according to a determination result.
Or, the file name may further include data number information, so that after the receiving side restores the target file to the target data, the receiving side performs integrity check on the restored data by using the data number information.
Or the file name can also comprise a data type identifier, so that the receiving side can provide the corresponding module with the data type identifier for processing after restoring the target file into the target data.
Specifically, the file uploading unit may specifically be used for:
uploading the target file to a target file sharing system through a target account, and receiving the target file in a mode that the target file sharing system is detected through the target account;
the target account number is an account number which is registered in the target file sharing system in advance.
Wherein the target data includes: target data which is generated by one of a first informatization management subsystem running in the first network environment or a second informatization management subsystem running in the second network environment and needs to be interacted across the network environments.
Specifically, the target data may include: commodity information that is interacted across network environments, and/or a variety of information generated on information distribution and transaction links, is required between a first network environment and a second network environment.
In addition, the target data may further include: message or instruction class data is needed for cross-network environment interactions between the first network environment and the second network environment.
Corresponding to the embodiment, the embodiment of the application also provides a data intercommunication device, referring to fig. 5, the device may include:
a detection unit 501, configured to detect a target file sharing system, where the target file sharing system has opened an isolation formed by a hardware device between a first network environment and a second network environment, so as to implement interworking between the first network environment and the second network environment;
a file obtaining unit 502, configured to download, from the target file sharing system, a target file if a new target file appears in the target file sharing system, where the target file is generated by converting target data that needs to perform cross-network environment interaction between the first network environment and the second network environment according to a preset protocol, and store the converted target data in the target file sharing system;
and the data conversion unit 503 is configured to parse the target file through the protocol and convert the parsed target file into the target data, so as to process the target data.
In addition, the embodiment of the application further provides a computer readable storage medium, on which a computer program is stored, which when executed by a processor, implements the steps of the method of any one of the foregoing method embodiments.
And an electronic device comprising:
one or more processors; and
a memory associated with the one or more processors for storing program instructions that, when read for execution by the one or more processors, perform the steps of the method of any of the preceding method embodiments.
Fig. 6 illustrates an architecture of an electronic device, which may include a processor 610, a video display adapter 611, a disk drive 612, an input/output interface 613, a network interface 614, and a memory 620, to name a few. The processor 610, video display adapter 611, disk drive 612, input/output interface 613, network interface 614, and memory 620 may be communicatively coupled via a communications bus 630.
The processor 610 may be implemented by a general-purpose CPU (Central Processing Unit, processor), microprocessor, application specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, etc. for executing relevant programs to implement the technical solutions provided herein.
The Memory 620 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory ), a static storage device, a dynamic storage device, or the like. The memory 620 may store an operating system 621 for controlling the operation of the electronic device 600, and a Basic Input Output System (BIOS) for controlling the low-level operation of the electronic device 600. In addition, a web browser 623, a data storage management system 624, a data interworking processing system 625, and the like may also be stored. The data interworking processing system 625 may be an application program that specifically implements the operations of the foregoing steps in the embodiments of the present application. In general, when the technical solutions provided in the present application are implemented in software or firmware, relevant program codes are stored in the memory 620 and invoked by the processor 610 to be executed.
The input/output interface 613 is used to connect with an input/output module to realize information input and output. The input/output module may be configured as a component in a device (not shown) or may be external to the device to provide corresponding functionality. Wherein the input devices may include a keyboard, mouse, touch screen, microphone, various types of sensors, etc., and the output devices may include a display, speaker, vibrator, indicator lights, etc.
The network interface 614 is used to connect communication modules (not shown) to enable communication interactions of the device with other devices. The communication module may implement communication through a wired manner (such as USB, network cable, etc.), or may implement communication through a wireless manner (such as mobile network, WIFI, bluetooth, etc.).
Bus 630 includes a path to transfer information between components of the device (e.g., processor 610, video display adapter 611, disk drive 612, input/output interface 613, network interface 614, and memory 620).
It should be noted that although the above devices illustrate only the processor 610, video display adapter 611, disk drive 612, input/output interface 613, network interface 614, memory 620, bus 630, etc., the device may include other components necessary to achieve proper operation in an implementation. Furthermore, it will be understood by those skilled in the art that the above-described apparatus may include only the components necessary to implement the present application, and not all the components shown in the drawings.
From the above description of embodiments, it will be apparent to those skilled in the art that the present application may be implemented in software plus a necessary general purpose hardware platform. Based on such understanding, the technical solutions of the present application may be embodied essentially or in a part contributing to the prior art in the form of a software product, which may be stored in a storage medium, such as a ROM/RAM, a magnetic disk, an optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to perform the methods described in the embodiments or some parts of the embodiments of the present application.
In this specification, each embodiment is described in a progressive manner, and identical and similar parts of each embodiment are all referred to each other, and each embodiment mainly describes differences from other embodiments. In particular, for a system or system embodiment, since it is substantially similar to a method embodiment, the description is relatively simple, with reference to the description of the method embodiment being made in part. The systems and system embodiments described above are merely illustrative, wherein the elements illustrated as separate elements may or may not be physically separate, and the elements shown as elements may or may not be physical elements, may be located in one place, or may be distributed over a plurality of network elements. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art will understand and implement the present invention without undue burden.
The data intercommunication processing method, device and information management system provided by the application are described in detail, and specific examples are applied to the description of the principle and implementation of the application, and the description of the above examples is only used for helping to understand the method and core ideas of the application; also, as will occur to those of ordinary skill in the art, many modifications are possible in view of the teachings of the present application, both in the detailed description and the scope of its applications. In view of the foregoing, this description should not be construed as limiting the application.

Claims (10)

1. An informationized management system is characterized in that,
the information management system includes: a first information management subsystem operating in a first network environment, and a second information management subsystem operating in a second network environment; the first network environment and the second network environment are isolated through hardware equipment;
the first network environment and the second network environment are provided with target file sharing systems, and the target file sharing systems are as follows: a file sharing system which can realize intercommunication between the first network environment and the second network environment by opening the isolation;
the first network environment and the second network environment are also provided with a data intercommunication server;
the data intercommunication service end is used for converting target data into a target file according to a preset protocol after one party in the first information management subsystem or the second information management subsystem generates the target data needing to be interacted across network environments, and generating the file name of the target file according to a file naming rule configured in the protocol; uploading the target file to the target file sharing system through a target account; on a receiving side, receiving the target file from the target file sharing system through the target account number, analyzing the target file through the protocol, and restoring the target file into the target data so as to provide the target data for the other one of the first information management subsystem and the second information management subsystem for processing; the target account is an account which is registered in the target file sharing system in advance;
The file name comprises a network environment identifier for executing uploading operation, so that when a receiving side monitors that a new file is generated in the file sharing system, whether the file is the current network environment or the file uploaded in the opposite network environment is judged through the network environment identifier in the file name, and whether downloading processing is carried out is determined according to a judging result.
2. A data interworking processing method, comprising:
determining target data to be interacted between the first network environment and the second network environment across the network environments; the first network environment and the second network environment are isolated through hardware equipment;
converting the target data into a target file according to a preset protocol, and generating a file name of the target file according to a file naming rule configured in the protocol;
uploading the target file to a target file sharing system through a target account, wherein the target file sharing system is as follows: the file sharing system which is isolated and can realize intercommunication between the first network environment and the second network environment is opened, so that the target file is received by a receiving side in a mode of monitoring the target file sharing system through the target account, and the target file is analyzed through the protocol and then restored into the target data so as to process the target data; the target account is an account which is registered in the target file sharing system in advance;
The file name comprises a network environment identifier for executing uploading operation, so that when a receiving side monitors that a new file is generated in the file sharing system, whether the file is the current network environment or the file uploaded in the opposite network environment is judged through the network environment identifier in the file name, and whether downloading processing is carried out is determined according to a judging result.
3. The method of claim 2, wherein the step of determining the position of the substrate comprises,
the file name comprises data number information, so that the receiving side can utilize the data number information to carry out integrity check on the restored data after restoring the target file into the target data.
4. The method of claim 2, wherein the step of determining the position of the substrate comprises,
the file name comprises a data type identifier, so that a receiving side can provide the data type identifier for a corresponding module for processing after restoring the target file into the target data.
5. The method according to claim 2 to 4, wherein,
the target data includes: target data which is generated by one of a first informatization management subsystem running in the first network environment or a second informatization management subsystem running in the second network environment and needs to be interacted across the network environments.
6. The method of claim 5, wherein the step of determining the position of the probe is performed,
the target data includes: commodity information that is interacted across network environments, and/or a variety of information generated on information distribution and transaction links, is required between a first network environment and a second network environment.
7. The method of claim 5, wherein the step of determining the position of the probe is performed,
the target data includes: message or instruction class data is needed for cross-network environment interactions between the first network environment and the second network environment.
8. A method of data interworking, comprising:
detecting a target file sharing system through a target account, wherein the target file sharing system is communicated with the first network environment and the second network environment through isolation formed by hardware equipment so as to realize intercommunication between the first network environment and the second network environment; the target account is an account which is registered in the target file sharing system in advance;
if a new target file appears in the target file sharing system, downloading the target file from the target file sharing system, wherein the target file is generated after converting target data needing to be interacted between a first network environment and a second network environment in a cross-network environment according to a preset protocol, and storing the target data in the target file sharing system; the target file is also associated with a file name generated according to a file naming rule configured in the protocol, wherein the file name comprises a network environment identifier for executing uploading operation, so that when a receiving side monitors that a new file is generated in the file sharing system, whether the file is a current network environment or a file uploaded in a counterpart network environment is judged through the network environment identifier in the file name, and whether downloading processing is carried out is determined according to a judging result;
And analyzing the target file through the protocol, and then restoring the target file into the target data so as to process the target data.
9. A computer readable storage medium, on which a computer program is stored, characterized in that the program, when being executed by a processor, implements the steps of the method according to any of claims 2 to 8.
10. An electronic device, comprising:
one or more processors; and
a memory associated with the one or more processors for storing program instructions that, when read for execution by the one or more processors, perform the steps of the method of any of claims 2 to 8.
CN202210535944.3A 2022-05-17 2022-05-17 Data intercommunication processing method and device and informationized management system Active CN115242422B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202210535944.3A CN115242422B (en) 2022-05-17 2022-05-17 Data intercommunication processing method and device and informationized management system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202210535944.3A CN115242422B (en) 2022-05-17 2022-05-17 Data intercommunication processing method and device and informationized management system

Publications (2)

Publication Number Publication Date
CN115242422A CN115242422A (en) 2022-10-25
CN115242422B true CN115242422B (en) 2024-01-02

Family

ID=83667773

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202210535944.3A Active CN115242422B (en) 2022-05-17 2022-05-17 Data intercommunication processing method and device and informationized management system

Country Status (1)

Country Link
CN (1) CN115242422B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117675418B (en) * 2024-02-02 2024-05-10 吉林省建兴智能科技有限公司 Data transmission system and method based on non-physical medium intrusion prevention

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108881158A (en) * 2018-05-04 2018-11-23 北京明朝万达科技股份有限公司 Data interaction system and method
CN109729053A (en) * 2017-10-31 2019-05-07 北京国双科技有限公司 The exchange method and device of data between intranet and extranet
CN112583918A (en) * 2020-12-11 2021-03-30 广州润普网络科技有限公司 Intranet and extranet document interaction system, method and storage medium
CN113382012A (en) * 2021-06-18 2021-09-10 广州中爆数字信息科技股份有限公司 Internal and external network data exchange method, device, equipment and storage medium
CN113704781A (en) * 2021-07-23 2021-11-26 平安银行股份有限公司 File secure transmission method and device, electronic equipment and computer storage medium
CN114124929A (en) * 2021-09-29 2022-03-01 奇安信科技集团股份有限公司 Cross-network data processing method and device

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9118636B2 (en) * 2008-05-12 2015-08-25 Nbcuniversal Media, Llc Data transfer control system and method
CN103812882B (en) * 2012-11-06 2018-01-30 腾讯科技(深圳)有限公司 A kind of method and system of file transmission
US20210224091A1 (en) * 2020-01-17 2021-07-22 Microsoft Technology Licensing, Llc Sharable link for remote computing resource access

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109729053A (en) * 2017-10-31 2019-05-07 北京国双科技有限公司 The exchange method and device of data between intranet and extranet
CN108881158A (en) * 2018-05-04 2018-11-23 北京明朝万达科技股份有限公司 Data interaction system and method
CN112583918A (en) * 2020-12-11 2021-03-30 广州润普网络科技有限公司 Intranet and extranet document interaction system, method and storage medium
CN113382012A (en) * 2021-06-18 2021-09-10 广州中爆数字信息科技股份有限公司 Internal and external network data exchange method, device, equipment and storage medium
CN113704781A (en) * 2021-07-23 2021-11-26 平安银行股份有限公司 File secure transmission method and device, electronic equipment and computer storage medium
CN114124929A (en) * 2021-09-29 2022-03-01 奇安信科技集团股份有限公司 Cross-network data processing method and device

Also Published As

Publication number Publication date
CN115242422A (en) 2022-10-25

Similar Documents

Publication Publication Date Title
EP1872227B1 (en) System and method of testing wireless component applications
CN112115190B (en) Method, device and system for converting interface message
CN111177617A (en) Web direct operation and maintenance method and device based on operation and maintenance management system and electronic equipment
CN111177112A (en) Database blocking method and device based on operation and maintenance management system and electronic equipment
US10152400B2 (en) Method and system for dynamically unblocking customers in critical workflows by pushing community contributed solutions just-in-time when an error is encountered
CN113449022A (en) Method and device for processing service request
CN115242422B (en) Data intercommunication processing method and device and informationized management system
CN114726650B (en) Task request processing method and device, electronic equipment and computer readable medium
CN110324209B (en) Micro-service system monitoring method and device, electronic equipment and computer readable medium
CN111966653A (en) Data processing method, device, server and storage medium for micro-service call link
CN114416169A (en) Data processing method, medium, device and computing equipment based on micro front end
CN114371888A (en) Method and device for hot updating of log collection plug-in, electronic equipment and readable medium
CN112015383A (en) Login method and device
CN110275701B (en) Data processing method, device, medium and computing equipment
CN111526039A (en) Electronic equipment opening method and device, electronic equipment and computer readable medium
CN111835804A (en) Method, device and system for data transmission between internal network and external network
CN113141613B (en) Communication channel detection method and device and electronic equipment
CN110875832A (en) Abnormal service monitoring method, device and system and computer readable storage medium
CN112783903B (en) Method and device for generating update log
CN110278133B (en) Checking method, device, computing equipment and medium executed by server
CN114296985A (en) Global exception handling method and platform in large-scale micro-service cluster scene
CN112905970A (en) Authority verification method and device, computer readable storage medium and electronic equipment
CN113326060A (en) Service request processing method, device and system and service configuration method and device
CN113704079A (en) Interface testing method and device based on Protobuf
CN111949472A (en) Method and device for recording application logs

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant