Inner net computer is carried out the method and apparatus of security protection
Technical field
The present invention relates to computer data security protective method and equipment thereof, prevent that particularly method that computer data leaks and data sheet thereof are to the equipment that imports.
Background technology
Government and the enterprises and institutions data more than 80% leave in the internal network with electronic format now; the renewal of various movable storage devices is also more and more faster simultaneously; sensitive information, secret data and archives material are stored in the move media; a large amount of secret papers and data become magnetic medium; be stored in the unshielded mobile memory medium; if let go unchecked, abuse mobile memory medium arbitrarily and will bring incalculable damage.Repeatedly the mobile memory medium that the takes place case of divulging a secret, steal secret information has brought immeasurable loss for country and enterprises and institutions in recent years.
On the other hand, inner net computer can the phenomenon of illegal external connection of inner net computer occur by getting online without being tethered to a cable, and this also can make intranet data leak.
Therefore, for relating computer provides effectively, the data transmission solution is most important reliably.
Summary of the invention
An object of the present invention is to provide the method that prevents that computer data from leaking.
Another object of the present invention provides a kind ofly carries out the equipment of the unidirectional importing of data in the method preventing that computer data from leaking.
One aspect of the present invention is utilized one-way transmission, is the bridge of Data transmission between USB memory device and the computing machine, guarantee data by quick, correct be transferred to computing machine in, guaranteed that effectively any data in the computing machine do not leak.
The method that prevents that computer data from leaking of the present invention may further comprise the steps:
A) computer real-time detects the USB device of inserting USB interface, in case determine that the USB device that is detected is the equipment of easily divulging a secret, just forbids the USB device of being inserted immediately;
B) the USB memory device is inserted USB interface of computer via unidirectional introducing equipment, the data that described USB memory device can only be stored to described computing machine one-way transmission via described data unidirectional introducing equipment.
Said method can prevent that the equipment of easily divulging a secret from obtaining the data of Computer Storage by the USN interface of computing machine.Simultaneously, can also send the data of the equipment of easily divulging a secret to computing machine by uniaxially, thereby realize the physical isolation of computing machine to the device orientation of easily divulging a secret.
Wherein in described steps A) in, when COMPUTER DETECTION to described USB device is equipment outside data unidirectional introducing equipment, USB mouse, the USB keyboard, determine that then the USB device that is detected is the equipment of easily divulging a secret.
Wherein at described step B) in, described data unidirectional introducing equipment by following steps with the data sheet stored in the described USB device to being transferred to described computing machine:
At first from described USB memory device, read the file directory of the file of its stored;
According to file directory, selection will send to the specified file of computing machine;
Data to described specified file are encoded;
The one-way transmission coded data;
Coded data to described one-way transmission is decoded, and obtains the data of described specified file;
Data with specified file send computing machine to then.
Wherein utilize light transmitting device one-way transmission coded data, comprising:
Optical transmission module carries out the electric light conversion with encoded data signal, is transformed into the light data-signal, then via the optical fiber one-way transmission;
Optical Receivers will carry out opto-electronic conversion via described light transmission fiber data-signal, be reduced into described encoded data signal.
Said method can also comprise:
Of the present inventionly preventing that the computer data equipment of carrying out the unidirectional importing of data in the method that leaks from comprising:
Connect the USB memory device, specify the file of storing in the described USB memory device, and specified file is carried out the USB receiving element that data send;
The data of described USB receiving element transmission are carried out the one-way transmission apparatus of one-way transmission; And
Receive the data of described one-way transmission apparatus transmission, and send it to the USB transmitting element of computing machine.
Wherein said USB receiving element comprises: detect the detection module that the USB memory device inserts automatically; Inquire about the file of storing in the USB memory device that is inserted, thereby obtain the enquiry module of file directory information; Select specified file to be sent according to file directory information, and send the plurality of keys of command adapted thereto; According to the transmission instruction that button sent, send the sending module of the data of described specified file; And inquire about, select, instruct the display that shows.
Wherein said one-way transmission apparatus can be one of light, electric one-way transmission apparatus.
Wherein said one-way transmission apparatus comprises: the scrambler that the data that described USB receiving element is sent are carried out digital coding; And the optical transmitter that described scrambler encoded data signal is converted to light signal and carries out the light transmission; Transmit the optical fiber of described light signal; Reception is via the light signal of described Optical Fiber Transmission and convert thereof into electric signal, thereby obtains the photoreceiver of encoded data signal; And the demoder that the coded data of described photoreceiver output is decoded.
Described USB receiving element and/or data encoder are made of single-chip microcomputer or programmable logic device (PLD), and one of both or both have a buffer area that the data that sent is carried out buffer memory; And
Described USB transmitting element and/or data decoder are made of single-chip microcomputer or programmable logic device (PLD), and one of both or both have a buffer area that the data that received is carried out buffer memory.
Utilize said method of the present invention and equipment can realize following technique effect:
All USB interface, USB device are monitored accurately and effectively, guaranteed that other any USB device except that unidirectional transmission equipment and USB mouse, USB keyboard all are not allowed to use, thereby cut off by the leak channel of computer data of USB device.
Below in conjunction with accompanying drawing principle of the present invention, details are elaborated.
Description of drawings
Fig. 1 realizes that first kind of the present invention prevents the leak process flow diagram of method of computer data;
Fig. 2 is the synoptic diagram that shows the data unidirectional introducing equipment of carrying out the inventive method;
Fig. 3 is the synoptic diagram that the USB receiving element of data unidirectional introducing equipment of the present invention is carried out detection, inquiry, assigned operation;
Fig. 4 is the synoptic diagram that the USB receiving element of data unidirectional introducing equipment of the present invention sends specified file.
Embodiment
The alleged easily equipment of divulging a secret of the present invention is meant can be exported and/or the downloading computer data, thereby the USB device that might cause computer data to divulge a secret, the easily equipment of divulging a secret of the present invention includes but not limited to: portable hard drive, USB flash disk, MP3, MP4, digital camera, printer etc. are in interior USB device.
The method that prevents that computer data from leaking of the present invention may further comprise the steps:
A) computer real-time detects the USB device of inserting USB interface, in case determine that the USB device that is detected is the equipment of easily divulging a secret, just forbids the USB device of being inserted immediately; Steps A of the present invention) can avoid utilizing the incident of USB device downloading computer data to take place.
B) the USB memory device is inserted USB interface of computer via unidirectional introducing equipment, the data that described USB memory device can only be stored to described computing machine one-way transmission via described data unidirectional introducing equipment.Owing to utilize the one-way transmission technology, therefore step B of the present invention) data of storing in the USB memory device can be sent to computing machine, prevent from again the data of computing machine are downloaded in the USB memory device simultaneously.
At above-mentioned steps A) in, when COMPUTER DETECTION to described USB device is equipment outside data unidirectional introducing equipment or USB mouse or the USB keyboard, determine that then the USB device that is detected is the equipment of easily divulging a secret.Computing machine can detect details such as the hardware ID that software (as USBTrace) detects USB device by USB, determine thus whether USB device is one of data unidirectional introducing equipment, USB mouse, USB keyboard, if not wherein any one, judge that then this USB device is the equipment of easily divulging a secret.
At above-mentioned steps B) in, described data unidirectional introducing equipment by following steps with the data sheet stored in the described USB device to being transferred to described computing machine:
At first from described USB memory device, read the file directory of the file of its stored; According to file directory, selection will send to the specified file of computing machine, promptly specify the file that will send to computing machine; Data to described specified file are encoded; The one-way transmission coded data; Coded data to described one-way transmission is decoded, and obtains the data of described specified file; Data with specified file send computing machine to then.
The present invention can utilize the light one-way transmission apparatus to realize the one-way transmission of coded data, and this generally includes: optical transmission module carries out the electric light conversion with encoded data signal, is transformed into the light data-signal, then via the optical fiber one-way transmission; Optical Receivers will carry out opto-electronic conversion via described light transmission fiber data-signal, be reduced into described encoded data signal.
Fig. 1 has shown and has realized that first kind of the present invention prevents the leak process flow diagram of method of computer data that at first computer real-time detects the USB device of inserting the computing machine USB interface; Judge that then the USB device of being inserted is USB mouse or keyboard or data unidirectional introducing equipment, if judgement is not among USB mouse or keyboard or the data unidirectional introducing equipment any, the USB device inserted of forbidding then is USB mouse or keyboard then allows to use USB mouse or keyboard if judge; If judge it is the data unidirectional introducing equipments, then allow the data unidirectional introducing equipment to send the data of USB device storage to computing machine.
Second kind of method that prevents that computer data from leaking of the present invention may further comprise the steps:
A) computer real-time detects the USB device of inserting USB interface, in case determine that the USB device that is detected is the equipment of easily divulging a secret, just forbids the USB device of being inserted immediately;
B) the USB memory device is inserted USB interface of computer via unidirectional introducing equipment, the data that described USB memory device can only be stored to described computing machine one-way transmission via described data unidirectional introducing equipment;
Fig. 2 has shown the equipment of carrying out the data one-way transmission in above-mentioned two kinds of methods of the present invention, utilizes solid box to show the structure of present device among the figure.As shown in Figure 3, the equipment of execution data one-way transmission of the present invention comprises:
Connect USB memory device 1, specify the file of storing in the described USB memory device 1, and specified file is carried out the USB receiving element 2 that data send; This USB receiving element 2 can be single-chip microcomputer or the microcomputer with USB socket, the USB memory device that it can find to insert at any time, it is inquired about, and carries out specified file and send the processing of specified file.
The data of described USB receiving element 2 transmissions are carried out the one-way transmission apparatus 3 of one-way transmission; This one-way transmission apparatus can be one of sound, light, electric one-way transmission apparatus.
Receive the data of described one-way transmission apparatus 3 transmission, and send it to the USB transmitting element 4 of computing machine 5.
USB receiving element 2 can comprise: detect the detection module that the USB memory device inserts automatically; Inquire about the file of storing in the USB memory device that is inserted, thereby obtain the enquiry module of file directory information; Select specified file to be sent according to file directory information, and send the plurality of keys of command adapted thereto; According to the transmission instruction that button sent, send the sending module of the data of described specified file; And inquire about, select, instruct the display that shows.
Fig. 3 has shown detection, inquiry, the assigned operation of USB receiving element.When the USB memory device was connected to unidirectional introducing equipment, USB receiving element (as single-chip microcomputer Tx MCU) can make an immediate response, and shows user interface by liquid crystal display.File system on the Tx MCU can be inquired about the file in the USB device after responding USB device, return its fileinfo.Check catalogues at different levels by the operation response of button, on liquid crystal, show simultaneously.LCD screen adopts the resolution of 256*64, can show four lines, maximum 16 Chinese characters of every row.Button comprises "enter" key" (enter a sub-directory, or select), Exit key (being withdrawn into upper directory), Up key (scrolling up), down key (rolling) and Cancel key (cancelling) downwards.LCD screen and button are used, and can check bibliographic structure, locating file, select files, send file or cancel transmission.
Fig. 4 has shown the specified file transmit operation of USB receiving element.When the user selectes the file (for example specified file among the figure) that will send, by the key response operation information such as storage first address of file are delivered to Tx MCU, after handling, MCU by data bus fileinfo and content are sent to subordinate's data processing module (data cache module for example again, so that the metadata cache of 2K Byte is provided), the same help that be unable to do without file system in this process.In transport process, the user still can interrupt transmitting by the response of button, and MCU can tell subordinate's module to abandon this time sending by operation response.
When utilize select files on the unidirectional transmission equipment and send by "enter" key" after, terminal application software ejects the address that dialog box prompting user select File is preserved automatically, determine destination address after file begin transmission, and with progress bar prompting current data transmission progress.Unless the user presses the Cancel key and stops data transmission procedure on unidirectional introducing equipment, otherwise data transmission carries out finishing until whole file transmission always.
Referring to Fig. 2, one-way transmission apparatus 3 comprises again: the scrambler 31 that the data that described USB receiving element 2 is sent are carried out digital coding; Described scrambler encoded data signal is converted to light signal and carry out the optical transmitter 32 that light sends; Transmit the optical fiber 33 of described light signal; Reception is via the light signal of described Optical Fiber Transmission and convert thereof into electric signal, thereby obtains the photoreceiver 34 of encoded data signal; And the demoder 35 that the coded data of described photoreceiver output is decoded.
USB receiving element 2 and/or data encoder 31 can be made of single-chip microcomputer or programmable logic device (PLD), one of both or both have the buffer area that the data that sent is carried out buffer memory, thereby set up the data buffer between USB receiving element 2 and optical transmitter 32; And
USB transmitting element 4 and/or data decoder 35 can be made of single-chip microcomputer or programmable logic device (PLD), one of both or both have the buffer area that the data that received is carried out buffer memory, thereby set up the data buffer between USB transmitting element 4 and photoreceiver 34.
The present invention has following characteristics:
1, all USB interfaces, USB device are monitored accurately and effectively, guaranteed that other any USB devices except unidirectional transmission equipment and USB mouse, USB keyboard all are not allowed to use.
2, utilize the light unidirectional transmission property to guarantee the one-way transmission of data. In unidirectional this characteristic of utilizing light in the equipment of pouring into, realized that data can only be sent on the computer by unidirectional introducing equipment from the USB memory device, any data on the computer can not oppositely return.
3, realized file system at the USB receiver, can obtain the document directory structure of the USB memory device of connection, and pass to display module and shown by LCD screen, by LCD screen and button can check the document directory structure of USB memory device and voluntarily the select target file send.
4, at the USB receiver between the light delivery module, and light delivery module has guaranteed speed and the efficient of transfer of data to the data buffer zone that hardware between the USB transmitter (for example in USB receiver and USB transmitting element) is realized 2K Byte.
5, in the data one-way transmission, carry out data encoding and data decode, thereby guaranteed the correctness of transfer of data.
Although above the present invention is had been described in detail, the invention is not restricted to this, those skilled in the art of the present technique can carry out various modifications according to principle of the present invention. Therefore, all modifications of doing according to the principle of the invention all should be understood to fall into protection scope of the present invention.