A kind of data safety network gateway equipment with inherently safe defense function
Technical field
This utility model relates to the network equipment, particularly relates to a kind of data safety net with inherently safe defense function
Pass equipment.
Background technology
Along with the appearance of cloud computing (Cloud Computing), there is the biggest change, passes through in the application of computer network
Cloud computing system, though the most complicated calculating, as long as being sent a demand information to far-end by local computer by the Internet
Cloud computing system, cloud computing system will complete required calculating, and return the result on local computer.So, originally
Ground computer is with little need for what computing capability, and all of process all can be completed by the cloud computing system of far-end, calculating
Pressure moves on to the cloud computing system of far-end from local computer.Data safety network gateway system is equipment necessary to cloud computing, but
It is that existing data safety network gateway system exists following defect.Conventional data safety network gateway system does not has complete in view of vertical
Deep defensive design, various aspects only do one layer of defence, and any one single-point is once broken, and safety is immediately lost;And
And do not account for the linkage between modules safe design, fail the defence with level is designed cyclization ring phase
Button, acts in concert with each other.
One, unauthorized personnel can arbitrarily operate equipment, equipment may be caused maloperation by these human users, even
Encrypted card such as can be abused, caused user data to reveal by the core component in equipment.
Two, personnel's maloperation, machine is connect by other unrelated persons being not under the management of skilled operation maintenance personnel when
Touch and may produce some unexpected results, even the specialized machine room of top enterprise can not be completely secured the most not
This type of lower level error, such as machine can be occurred to be mispluged and to pull out netting twine.
Three, power-off service, computer circuit breaking almost loses everything protective capacities, this be one almost without asking that method is evaded
Topic, directly reads hard disk and obtains the data of computer and be that cost risk is high but the most certain rewarding means after power-off.
Four, marching into the arena maintenance, generally unique authentication when safeguarding of marching into the arena is exactly user password, and password is lost, and password is let out
Dew, the most just places the computer among risk, and password is directly safeguarded by people, and this also results in specific risk.And,
Operation maintenance personnel generally has too high authority, is generally responsible for the operation maintenance personnel safeguarding network and is responsible for safeguarding system personnel
Having same authority, partly leakage can cause whole System Privileges to be revealed, and therefore, safeguards and has only to username and password, exist
The possibility of Brute Force, easily by assault.
Five, easily destroyed by periphery malicious persons, such as, pull out netting twine or increase interception equipment;Number is revealed under specific event
According to, such as have a power failure.
In the prior art, there is the most all network equipments considering safety problem auspiciously.Such as, in prior art
Disclosing the self-desttruction equipment of a kind of electronic equipment in document 1 (CN104331675A), comprising: self-destruction triggers device, it is arranged
On the housing of electronic equipment, for illegally being opened or during broken shell at the housing of electronic equipment, trigger a self-destruction signal, and will
Its output performs device to self-destruction;Self-destruction performs device, and it is detecting that described self-destruction triggers the described self-destruction letter of device output
After number, utilize high voltage pulse that pin-saving chip and/or the data storage medium of described electronic equipment are carried out physical damage;Electricity
Pond electric power system: for powering for electronic equipment and described self-desttruction equipment.At the electronic equipment disclosed in prior art literature 1
In self-desttruction equipment, physics self-destruction can be carried out under specific abnormal conditions, and the electronic equipment after physics self-destruction becomes
Can not reuse, if wherein there is important data or file, then these data or file will be lost.
Therefore, use the self-desttruction equipment of this electronic equipment, for a user, although the problem of device data safety can be solved, but
It is that safety is built upon existing under the premise losing these data completely, for a user, either cost or wind
Danger is the highest.Secondly, the self-desttruction equipment of above-mentioned electronic equipment only only accounts for the housing of electronic equipment and is illegally opened or broken shell
Such abnormal conditions, do not consider other abnormal situation, and the situation that such as illegal identity accesses, for whole network
For system, do not form the security gateway system of hardware security defence design function all linked with one another, there is depth formula.
Utility model content
The purpose of this utility model is contemplated to make up above-mentioned defect of the prior art, it is provided that one has self peace
The data safety network gateway equipment of full defense function, in this has the data safety network gateway equipment of inherently safe defense function, if
Put multiple different safeguard procedures, thus form hardware security defence design function all linked with one another, there is depth formula.
The data safety network gateway equipment with inherently safe defense function that this utility model provides, including cabinet, simultaneously
Also including SoC chip, described SoC chip processes for data;Data safety network gateway device Host, is connected with described SoC chip
Connect;Unpacking sensor, is connected with described SoC chip, is used for detecting whether described cabinet is illegally opened;Alarm, with institute
State SoC chip to be connected, for detecting that described cabinet sends warning when illegally being opened at described unpacking sensor;And net
Network interface, is connected with described SoC chip, for being connected with external network.According to this, there is inherently safe defense function
Data safety network gateway equipment, it is possible to prevent cabinet from illegally being opened security gateway equipment.
The data safety network gateway equipment with inherently safe defense function that this utility model provides, including cabinet, simultaneously
Also including SoC chip, described SoC chip processes for data;Data safety network gateway device Host, is connected with described SoC chip
Connect;Network interface, is connected with described SoC chip, for being connected with external network;Network interface is locked, and arranges described network interface
On, it is connected with described SoC chip, for protecting the safety of described network interface;And alarm, with described SoC chip phase
Connect, for sending warning when described network interface lock is in abnormality.According to this, there are the data of inherently safe defense function
Security gateway equipment, it is possible to prevent network interface to be illegally used, thus protect the safety of gateway.
The data safety network gateway equipment with inherently safe defense function that this utility model provides, including cabinet, simultaneously
Also including SoC chip, described SoC chip processes for data;Data safety network gateway device Host, is connected with described SoC chip
Connect;USBKey, is connected with described SoC chip by USB interface, for authentication;Housing physical locks, is arranged on described number
According on the housing of security gateway equipment, it is connected with described SoC chip, for opening or locking at described data safety network gateway
The housing of equipment, in the case of by described USBKey by authentication, described housing physical locks is opened;Alarm, with
Described SoC chip is connected, for by described USBKey, by authentication, described housing physical locks is not unlocked
In the case of send warning;And network interface, it is connected with described SoC chip, for being connected with external network.According to this tool
There is the data safety network gateway equipment of inherently safe defense function, it is possible to prevent gateway housing from illegally being opened by physics, thus protect
The safety of gateway.
The data safety network gateway equipment with inherently safe defense function that this utility model provides, including cabinet, simultaneously
Also including SoC chip, described SoC chip processes for data;Data safety network gateway device Host, is connected with described SoC chip
Connect;USBKey, is connected with described SoC chip by USB interface, for authentication;Alarm, with described SoC chip phase
Connect, for sending warning in the case of described authentication is unsanctioned;And network interface, it is connected with described SoC chip
Connect, for being connected with external network.According to this, there is the data safety network gateway equipment of inherently safe defense function, it is possible to prevent
Gateway is cracked by undisclosed people, thus protects the safety of gateway.
The data safety network gateway equipment with inherently safe defense function that this utility model provides, including cabinet, simultaneously
Also including SoC chip, described SoC chip processes for data;Data safety network gateway device Host, is connected with described SoC chip
Connect;USBKey, is connected with described SoC chip by USB interface, for authentication;USBKey physical locks, described USBKey
Being arranged in described USBKey physical locks, described USBKey physical locks is connected with described SoC chip, is used for opening or pinning
Described USBKey, in the case of by described USBKey by authentication, described USBKey physical locks is opened;Alarm,
It is connected with described SoC chip, for sending warning in the case of described authentication is unsanctioned;And network interface, with
Described SoC chip is connected, for being connected with external network.According to this, there is the data safety net of inherently safe defense function
Pass equipment, utilizes physical locks and USBKey simultaneously, it is possible to uses physical locks and the double protection of authentication, thus protects gateway
Safety.
Preferably, described unpacking sensor is multiple;It is highly preferred that described unpacking sensor is 4, it is separately positioned on institute
State on four angles of cabinet;Preferably, described network interface is arranged on described cabinet, the described SoC chip when inserting netting twine
Control described network interface lock auto lock;Preferably, when extracting netting twine from network interface, described SoC chip is to described
USBKey verifies, after being verified, described network interface lock is opened, and otherwise, described SoC chip controls described alarm and sends report
Alert;Preferably, when described alarm work, described SoC chip triggers the cipher card in institute's data safety network gateway equipment and enters
Self-destruction program, wipes the key of storage in described cipher card;Preferably, also including power supply unit, said supply unit is with described
SoC chip is connected with the main frame of described data safety network gateway equipment, and said supply unit includes external power source, and with described
Main battery that external power source is connected and reserve battery;Preferably, when described external power source power-off, use main battery or standby
Described SoC chip is powered by battery;It is highly preferred that the exception in the state of described SoC chip record network interface and equipment
Operation Log, uploads and backups in far-end server.
The utility model has the advantage of: provide a set of hardware security providing the depth formula that multicompartment links layer by layer
Defence design, is designed to all linked with one another by hardware safety protection layer by layer, even if a certain layer defense mechanism is broken, more internal layer
Defense mechanism can trigger immediately and play a role.Outermost layer dual factors physical protection is broken through by violence, then in interior one layer of equipment
In core encrypted card, key meeting self-destruction, can send warning to corresponding personnel, even if whole process external power source is broken after self-destruction
Electricity also has battery backup and powers, and all abnormal operations can be uploaded to far-end server, it is simple to follow the trail of.So defending layer
Under the design that layer triggers, can preferably ensure the inherently safe of data safety network gateway equipment, especially key safety, thus enter one
The data safety of step protection user.
Accompanying drawing explanation
Fig. 1 is the structure chart of data safety network gateway equipment of the present utility model;
Fig. 2 is the structure chart of power supply unit of the present utility model;
Detailed description of the invention
Fig. 1 shows a kind of data safety network gateway equipment of the present utility model, and including cabinet 8, this data safety network gateway sets
For also including: SoC chip (System-on-a-Chip: system level chip) 1, described SoC chip 1 processes for data;Data
Security gateway equipment main frame 2, is connected with described SoC chip 1;Unpacking sensor 3, is connected with described SoC chip 1, is used for
Detect whether described cabinet 8 is illegally opened;Alarm 4, is connected with described SoC chip 1, at described data safety net
Pass equipment sends warning when being in unsafe condition;USBKey 6, is connected with described SoC chip 1 by USB interface 7, is used for
Authentication;Network interface 10, is connected with described SoC chip 1, for being connected with external network;Network interface lock 11, arranges institute
State on network interface 10, be connected with described SoC chip 1, for protecting the safety of described network interface 10;Power supply unit 9, with
Described SoC chip 1 is connected with data security gateway equipment main frame 2;Housing physical locks (the main lock 5 corresponding in accompanying drawing 1), if
Put on the housing of data safety network gateway equipment, be connected with SoC chip 1, for opening or locking at data safety network gateway
The housing of equipment, in the case of by USBKey 1 by authentication, housing physical locks 5 is opened;USBKey physical locks is (right
Should be in the physical locks 8 in accompanying drawing 1), USBKey is arranged in USBKey physical locks 8, and USBKey physical locks 8 is connected with SoC chip 1
Connecing, be used for opening or pin USBKey 1, in the case of by USBKey1 by authentication, USBKey physical locks 1 is opened
Open.
For ensureing the safety of cabinet 8, described unpacking sensor 3 is multiple, and in general, described unpacking sensor 3 is set to 4
Individual, it is separately positioned on four angles of described cabinet 8, when violence is opened from four angles of cabinet 8, it will send warning.Report
Alert mode does not limits, and in this utility model, can be to send note, mail or telephone call to corresponding personnel, or directly
Use acoustic-optic alarm, notify corresponding personnel's emergent management.
Sensor 3 of unpacking can use pressure transducer in this utility model, detects cabinet pressure anomaly, if cabinet
The pressure born exceedes certain threshold value and has been judged as people just at violence unlatching cabinet, thus is judged as that cabinet is the most non-
Method is opened.
The physical locks 5 being connected with described SoC chip 1 that described data safety network gateway equipment includes, is used for protecting cabinet 8
Safety.When opening described physical locks 5, described USBKey 6 is verified by described SoC chip 1, allows to beat after being verified
Opening described physical locks 5, otherwise, described SoC chip 1 controls alarm 4 and sends warning.Warning illegally can be opened with above-mentioned cabinet
The exception sent when opening is identical, or can also use other type of alarm.
In other words, in this utility model, just can open when only USBKey 6 accesses and when having physical locks 5 key
Open cabinet 8 and carry out plant maintenance, otherwise can trigger key self-destruction flow process.This physical locks 5 is physical locks, needs to have key simultaneously
And USBKey 6 could open, lacking one, open can not.
Additionally, the USBKey physical locks 8 being connected with described SoC chip 1 that described data safety network gateway equipment includes, use
Safety in protection USBKey6.When opening described USBKey physical locks 8, described USBKey 6 is carried out by described SoC chip 1
Checking, allows to open described USBKey physical locks 8 after being verified, otherwise, described SoC chip 1 controls alarm 4 and sends report
Alert.The exception that warning sends when illegally can be opened with above-mentioned cabinet is identical, or can also use other type of alarm.
In this utility model, as long as under being judged as that described data safety network gateway equipment is in the hole, such as, by opening
Case sensor 3 detects that (illegally unblanking) is unblanked in violence, or when USBKey physical locks 8 or main lock 5 illegally to be opened, institute
State SoC chip 1 and just trigger key self-destruction logic, firstly generate array random number and key storage region is carried out random writing, cover
Lid falls the data in key storage region, repeated multiple times, it is ensured that data are irrecoverable, then performs cipher key initialization.
Data safety network gateway equipment after key self-destruction logical process can also reuse itself, but will lose
Lose original key arranged, enter by regenerating key or the key recovery backed up before, just can reuse number
According to security gateway equipment.Owing to data safety network gateway equipment physical function is not lost, the most for a user, need not be again
Purchasing data safety network gateway equipment, in data safety network gateway equipment, other user data or the file of storage are not the most lost
Losing, for a user, either cost or risk are all minimum.
Described network interface 10 is arranged on described cabinet 8, and after inserting netting twine, described SoC chip 1 controls described network interface
Lock 11 shell fragment automatic springs, netting twine head is locked.
When extracting netting twine from network interface 10, described USBKey 6 is verified by described SoC chip 1, and checking is logical
The most described network interface is locked 11 shell fragments and is automatically opened up, and netting twine can normally be extracted;Otherwise, strength is extracted netting twine or directly blocks netting twine
During suspension, described SoC chip 1 controls alarm 4 and sends warning.
For preferably safeguarding equipment, described SoC chip 1 records the abnormal operation in the state of network interface 10 and equipment
Daily record, uploads in real time and backups in far-end server.Far-end server can be Cloud Server etc..
Fig. 2 shows the structure of power supply unit 9, and it includes external power source 12, and is connected with described external power source 12
Main battery 14 and reserve battery 13.External power source 12 usually civil power by the power supply after transformator transformation, generally 12V,
The power supply of 5A.Main battery 14 and reserve battery 13 are charged by external power source 12, when external power source power-off, use main battery 14 or
Described SoC chip 1 is powered by reserve battery 13, it is ensured that the safety of cabinet 8, the most when power is off, unpack sensor 3, alarm 4,
Physical locks 5 etc. are in running order, only just can open cabinet after being verified, otherwise report to the police, it is ensured that cabinet 8 is in power-off
Safety under state.The mode reported to the police can be to send note or telephone call to corresponding personnel, notifies that corresponding personnel promptly locate
Reason.
In this utility model, it is not required that include in data safety network gateway equipment simultaneously simultaneously based on unpacking sensor 3,
The safe depth defense measure of USBKey6, main lock 5 and physical locks 8 etc., can be only possess any one in them or
All.
It is obvious to a person skilled in the art that this utility model is not limited to the details of above-mentioned one exemplary embodiment, and
And in the case of without departing substantially from spirit or essential attributes of the present utility model, it is possible to realize this practicality in other specific forms new
Type.Therefore, no matter from the point of view of which point, all should regard embodiment as exemplary, and be nonrestrictive, this practicality is new
The scope of type is limited by claims rather than described above, it is intended that by the containing of equivalency in claim that fall
All changes in justice and scope are included in this utility model.Should not be considered as any reference in claim limiting
Involved claim.