A kind of enterprise instant communication system and method based on safety isolation network gate
Technical field
The present invention relates to a kind of instant communicating system and method, more particularly, to a kind of enterprise based on safety isolation network gate
Instant communicating system and method.
Background technology
The IT construction of present Chinese Enterprise has no longer been a blank sheet of paper, with information technology and the change of management, it is desirable to
The IT system of enterprise is increasingly abundanter, more and more complete.Improved in current Enterprise IT System under complete basis, enterprise pair
The safety of IT system is also increasingly paid attention to, it follows therefore that being that enterprise can realize enterprise by safety isolation network gate technology
The security assurance information of IT system, it is not allow that safety isolation network gate technology has a most significant feature on isolation technology
The foundation of TCP sessions.
Developed into Internet era instantly in enterprise's IT construction, the daily communication collaborative demand of enterprises is increasingly vigorous.
Enterprise wishes to realize that the communication of inside cooperates with by enterprise-level instant messaging (IM) product.By enterprise-level IM products IT systems
System is extended to mobile device (Mobile) again from the fixed equipment (PC) in office.So that the effect neck of enterprise's IT information systems
Domain is amplified, and the office of IT information systems is no longer influenced by the constraint in place, is also no longer influenced by the constraint of equipment.Enterprise staff can
Using mobile device (Mobile), IT information systems are quickly handled when needing, so that the business of enterprise is faster
Speed meets with a response, the final whole work efficiency for improving enterprise.
But conflict as described above, the internet demand of enterprise has with the security assurance information technology of enterprise, enterprise-level IM productions
Product are dependent on TCP session technologies, but have isolation in safety isolation network gate Technique on T CP sessions, do not allow to establish TCP sessions.Cause
This has the enterprise of safety isolation network gate technology under such a scenario, and it is current to improve often to land enterprise-level IM products
The internet IT construction of enterprise.
The content of the invention
It is an object of the present invention to overcome the above-mentioned drawbacks of the prior art and provide one kind is based on security isolation
The enterprise instant communication system and method for gateway.
The purpose of the present invention can be achieved through the following technical solutions:
A kind of enterprise instant communication system based on safety isolation network gate, the system are used to establish in corporate intranet and outer net
Outer net mobile client instant messaging, described corporate intranet connects described outer net by safety isolation network gate, described
Corporate intranet include Intranet instant communication server, the system also includes being used to HTTP transmitting data and TCP session numbers
According to the outer net instant messaging adapter and Intranet instant messaging adapter mutually changed, described outer net instant messaging adapter
It is arranged on outer net, described outer net mobile client, which connects through outer net instant messaging adapter and is connected to safety isolation network gate, to be entered
And corporate intranet is connected, described Intranet instant messaging adapter is arranged in corporate intranet, described safety isolation network gate, interior
Net instant messaging adapter and Intranet instant communication server are in turn connected to form Intranet communication line;
When carrying out instant messaging:
Outer net instant messaging adapter establishes HTTP transmission communications with safety isolation network gate, while outer net instant messaging is adapted to
Device establishes TCP transmission communication with outer net mobile client, and outer net instant messaging adapter carries out HTTP transmission data and TCP sessions
The conversion of data;Intranet instant messaging adapter establishes HTTP transmission communications, while Intranet instant messaging with safety isolation network gate
Adapter establishes TCP transmission communication with Intranet instant communication server, and Intranet instant messaging adapter carries out HTTP transmission data
With the conversion of TCP session datas;Thus the instant messaging of corporate intranet and outer net is completed.
Desktop end client is provided with described corporate intranet, described desktop end client is connected to Intranet instant messaging
Server simultaneously establishes TCP transmission communication with Intranet instant communication server.
Intranet mobile client is provided with described corporate intranet, the Intranet mobile client is connected to Intranet IMU
Inquiry server simultaneously establishes TCP transmission communication with Intranet instant communication server.
A kind of means of communication of the enterprise instant communication system based on safety isolation network gate, this method comprise the following steps:
(1) judge whether outer net mobile client has data-pushing to corporate intranet, if then performing step (2), otherwise
Perform step (3);
(2) outer net instant messaging adapter carries out the conversion that TCP session datas transmit data to HTTP, while Intranet is instant
Communications adapter carries out conversion of the HTTP transmission data to TCP session datas, and Intranet instant communication server completes outer net movement
The reception of client push data, return to step (1) circulation perform;
(3) judge whether Intranet instant communication server has data-pushing to outer net mobile client, if then performing step
Suddenly (4), otherwise return to step (1) circulation perform;
(4) Intranet instant messaging adapter carry out TCP session datas to HTTP transmit data to conversion, while outer net is
When communications adapter carry out conversion of the HTTP transmission data to TCP session datas, outer net mobile client completes Intranet IMU
The reception of adapter propelling data is interrogated, return to step (1) circulation performs.
Step (2) is specially:
(21) data that outer net mobile client will push are pushed to outer net instant messaging by TCP transmission mode and are adapted to
Device;
(22) outer net instant messaging adapter receives the TCP session numbers of outer net mobile client push by TCP sessions
According to;
(23) TCP session datas are converted to HTTP by HTTP transport protocol and transmit number by outer net instant messaging adapter
According to, and then HTTP transmission data are forwarded to corporate intranet by outer net instant messaging adapter through safety isolation network gate;
(24) Intranet instant messaging adapter by the HTTP of reception transmission data be converted to TCP session datas and be pushed to
Intranet instant communication server, Intranet instant communication server complete the reception of outer net mobile client propelling data, return to step
Suddenly (1) circulation performs.
Step (4) is specially:
(41) data that Intranet instant communication server will push are pushed to Intranet instant messaging by TCP transmission mode
Adapter;
(42) Intranet instant messaging adapter receives the TCP meetings of Intranet instant communication server push by TCP sessions
Talk about data;
(43) TCP session datas are converted to HTTP by HTTP transport protocol and transmit number by Intranet instant messaging adapter
According to, and then HTTP is transmitted data and is forwarded to outer net instant messaging adaptation through safety isolation network gate by Intranet instant messaging adapter
Device;
(44) outer net instant messaging adapter by the HTTP of reception transmission data be converted to TCP session datas and be pushed to
Outer net mobile client, outer net mobile client complete the reception of Intranet instant communication server propelling data, return to step (1)
Circulation performs.
Compared with prior art, the invention has the advantages that:
The present invention sets outer net instant messaging adapter and Intranet instant messaging adapter, realize communication data conversion and
Transmission, the long link that the outer net mobile client outside safety isolation network gate has obtained TCP sessions is supported, so as to be
When ability to communicate, ensured the promptness of instant messaging, TCP meetings also obtained in the Intranet instant communication server of corporate intranet
The long link of words supports, by the duplex nature timely processing instant communication data of TCP sessions, and safety isolation network gate
Safety is still ensured, data biography is carried out mutually by HTTP (HTTP) between corporate intranet and outer net
Pass, the information security of enterprise, which remains unchanged, to be under the control of gateway, is entered without breaking safety isolation network gate, the safety of business data
Still it is under the protection of safety isolation network gate, obtains the ability characteristics of Internet enterprises instant messaging, so that enterprise
The processing of the instant messaging ability, information system of industry has been extended to internet and safely controllable.
Brief description of the drawings
Fig. 1 is the structured flowchart of the enterprise instant communication system of the invention based on safety isolation network gate.
Fig. 2 is the flow chart of the means of communication of the enterprise instant communication system of the invention based on safety isolation network gate.
In figure, 1 is outer net mobile client, and 2 be outer net instant messaging adapter, and 3 be safety isolation network gate, and 4 be Intranet
Instant messaging adapter, 5 be Intranet instant communication server, and 6 be desktop end client, and 7 be Intranet mobile client.
Embodiment
The present invention is described in detail with specific embodiment below in conjunction with the accompanying drawings.
Embodiment
As shown in figure 1, a kind of enterprise instant communication system based on safety isolation network gate, the system is used to establish in enterprise
Net and the instant messaging of the outer net mobile client 1 in outer net, corporate intranet connect outer net, enterprise by safety isolation network gate 3
Intranet includes Intranet instant communication server 5, and the system also includes being used to HTTP transmitting data and TCP session datas are mutual
The outer net instant messaging adapter 2 and Intranet instant messaging adapter 4 of conversion, outer net instant messaging adapter 2 are arranged on outer
Net, outer net mobile client 1 connect through outer net instant messaging adapter 2 and are connected to safety isolation network gate 3 and then connect enterprise
Intranet, Intranet instant messaging adapter 4 are arranged in corporate intranet, safety isolation network gate 3, the and of Intranet instant messaging adapter 4
Intranet instant communication server 5 is in turn connected to form Intranet communication line;
When carrying out instant messaging:
Outer net instant messaging adapter 2 establishes HTTP transmission communications with safety isolation network gate 3, while outer net instant messaging is fitted
Orchestration 2 and outer net mobile client 1 establish TCP transmission communication, outer net instant messaging adapter 2 carry out HTTP transmission data with
The conversion of TCP session datas;Intranet instant messaging adapter 4 establishes HTTP transmission communications, while Intranet with safety isolation network gate 3
Instant messaging adapter 4 establishes TCP transmission communication with Intranet instant communication server 5, and Intranet instant messaging adapter 4 is carried out
HTTP transmits data and the conversion of TCP session datas;Thus the instant messaging of corporate intranet and outer net is completed.
Desktop end client 6 is provided with corporate intranet, desktop end client 6 is connected to Intranet instant communication server 5 simultaneously
TCP transmission communication is established with Intranet instant communication server 5.Intranet mobile client 7, the Intranet are additionally provided with corporate intranet
Mobile client 7 is connected to Intranet instant communication server 5 and establishes TCP transmission communication with Intranet instant communication server 5.Table
Face end client 6 and Intranet mobile client 7 establish TCP sessions with Intranet instant communication server 5 and realize instant messaging.
A kind of means of communication of the enterprise instant communication system based on safety isolation network gate 3, this method comprise the following steps:
(1) judge whether outer net mobile client 1 has data-pushing to corporate intranet, if then performing step (2), otherwise
Perform step (3);
(2) outer net instant messaging adapter 2 carries out the conversion that TCP session datas transmit data to HTTP, while Intranet is
When communications adapter 4 carry out conversion of the HTTP transmission data to TCP session datas, Intranet instant communication server 5 completes outer net
The reception of the propelling data of mobile client 1, return to step (1) circulation perform;
(3) judge whether Intranet instant communication server 5 has data-pushing to outer net mobile client 1, if then performing
Step (4), otherwise return to step (1) circulation perform;
(4) Intranet instant messaging adapter 4 carry out TCP session datas to HTTP transmit data to conversion, while outer net
Instant messaging adapter 2 carries out conversion of the HTTP transmission data to TCP session datas, and outer net mobile client 1 completes Intranet and is
When the propelling data of communications adapter 4 reception, return to step (1) circulation perform.
Step (2) is specially:
(201) data that outer net mobile client 1 will push are pushed to outer net instant messaging by TCP transmission mode and fitted
Orchestration 2;
(202) outer net instant messaging adapter 2 receives the TCP sessions of the push of outer net mobile client 1 by TCP sessions
Data;
(203) TCP session datas are converted to HTTP by HTTP transport protocol and transmit number by outer net instant messaging adapter 2
According to and by HTTP transmission data corporate intranet (i.e. revolution in outer net instant messaging adapter 2 is forwarded to through safety isolation network gate 3
According to);
(204) Intranet instant messaging adapter 4 receives HTTP transmission data;
(205) the HTTP transmission data of reception are converted to TCP session datas and are pushed to by Intranet instant messaging adapter 4
To Intranet instant communication server 5;
(206) Intranet instant communication server 5 completes the reception of the propelling data of outer net mobile client 1, return to step (1)
Circulation performs.
Step (4) is specially:
(401) data that Intranet instant communication server 5 will push are pushed to Intranet IMU by TCP transmission mode
Interrogate adapter 4;
(402) Intranet instant messaging adapter 4 receives the TCP of the push of Intranet instant communication server 5 by TCP sessions
Session data;
(403) TCP session datas are converted to HTTP by HTTP transport protocol and transmit number by Intranet instant messaging adapter 4
According to, and then HTTP is transmitted data and is forwarded to outer net instant messaging adaptation through safety isolation network gate 3 by Intranet instant messaging adapter 4
Device 2;
(404) the HTTP transmission data that outer net instant messaging adapter 2 receives;
(405) the HTTP transmission data of reception are converted to TCP session datas and are pushed to by outer net instant messaging adapter 2
To outer net mobile client 1;
(406) outer net mobile client 1 completes the reception of the propelling data of Intranet instant communication server 5, return to step (1)
Circulation performs.
The HTTP (HTTP) that is allowed by the technology of safety isolation network gate 3 realizes enterprise-level instant messaging
(IM).An instant messaging adapter is all established on the Intranet processing unit and outer net processing unit of safety isolation network gate 3.Outside
Net instant messaging adapter 2 (outer net IM adapters) is outside the secure isolated network of safety isolation network gate 3, with outer net mobile client
TCP session links are established at end 1, and the instant communication data of the duplex nature progress outer net mobile client 1 of link is grown by TCP
Transmitting-receiving, but during data are inwardly transmitted, then Intranet instant messaging is transferred to by HTTP (HTTP)
Adapter 4 (Intranet IM adapters).Intranet instant messaging adapter 4 is responsible for collecting the HTTP data of outer net adapter, but passes through
TCP conversational modes, pass data to Intranet instant communication server.Therefore, the outer net movement outside safety isolation network gate 3
The long link that client 1 has obtained TCP sessions is supported, so as to obtain instant messaging ability, has ensured the timely of instant messaging
Property, the long link that TCP sessions have also been obtained in the Intranet instant communication server 5 of corporate intranet is supported, passes through the complete of TCP sessions
Duplex nature timely processing instant communication data, and the safety of safety isolation network gate 3 still ensured, corporate intranet and
Data transfer is carried out mutually by HTTP (HTTP) between outer net, the information security of enterprise remains unchanged in gateway
Under control.