Data isolation device based on non-network mode, and method and system thereof

2014 
The invention provides a data isolation device based on a non-network mode, and an isolation method and an isolation system thereof. The data isolation device comprises an intranet host, an extranet host, and an isolated communication module. The intranet host and the extranet host are loaded with a network protocol stack, and respectively maintain a TCP proxy client module and a TCP proxy server module. A TCP connection socket1 is established and data forwarding is carried out between the TCP proxy server module and a service data packet client. A TCP connection socket2 is established and data forwarding is carried out between the TCP proxy client module and a service data packet server. The isolated communication module uses a proprietary protocol. The TCP header and following message headers of a service data packet are removed. Only pure service data load forwarding is carried out. Four-layer isolated subsystem communication between inner-end and outer-end hosts is realized on the whole, all network attacks except proprietary-protocol-based internal attacks are effectively prevented, and high network data exchange efficiency is ensured on the premise of physical isolation between the internal network and the external network.
    • Correction
    • Source
    • Cite
    • Save
    • Machine Reading By IdeaReader
    0
    References
    0
    Citations
    NaN
    KQI
    []