|
Embody the policy requirements of security isolation and finite connection fully,
Inspur Information Security Business Department understands deeply the policy requirements of the state on the security isolation system depending on the achievements of many years’ research in the security isolation and the support of the related departments of the state, puts the policy requirements into the development of the product depending on the profound technology foundation, puts forwards the products adopting mapping GAP technology firstly and forms the solution in China. Mapping GAP technology adopts pure data exchange among the chips. The access is controlled by the special hardware which guarantees that there is no network access between the interior and exterior networks at any time point and embodies fully the policy requirements of “security isolation, finite connection” of the state fully.
Provide higher security through channel control
Inspur VTInfo security isolation gatekeeper puts forward the channel control concept firstly and assures the validity of data check through controlling the flow of the data by the chip. Traditional gatekeeper facilities do not have the highly reliable special hardware and provide the security isolation through adopting interior and exterior systems visiting the hard disk at different times. As the hard disk is read and write device and it is hard to control the flow of the data from the hardware, data flow reliability, information intrusion, and check validity cannot be assured. All of the isolation exchange cards inside the Inspur VTInfo security isolation gatekeeper are researched, developed and manufactured by the Inspur Information Security Business Department which can control data flow through the chip and thus has higher security comparing with the traditional gatekeeper.
Provide better confidentiality through content check
Inspur VTInfo security isolation gatekeeper integrates the document security classification identification mark module of State Secrecy Bureau and the check module of the highly-efficient content and can check the security classification and data content sent from the interior network to the exterior network to avoid the leakage to a large extent and thus provide not only safe communication means but also better confidentiality.
Use the special operation system and provide stronger safety platform support.
The operation system used inside the Inspur VTInfo security isolation gatekeeper is an independently developed and reinforced operating platform which provides more secure reinforced safety operation than open operation system.
Internationally leading exchange speed
Inspur VTInfo security isolation gatekeeper firstly raises the 100M isolation exchange system speed over 80Mbps and the exchange speed among the isolation cards over 1G, the isolation concept product introducing the gigabit network for the first time. Compared with the internationally outstanding 120Mbps transfer speed, Inspur Information Safety Business Department raises the transfer speed into the 360Mbps firstly through the internationally leading mapping GAP technology, caters for the gigabit solution, and protects the faster construction of informatization in China.
Working state and application binding
Inspur VTInfo security isolation gatekeeper binds the working state of the system and user application by adopting the time-sharing mode and assures the safety of the unsupported system through hardware control.
Product function
Each Inspur VTInfo security isolation gatekeeper uses high-speed data isolation exchange card researched and developed independently based on the mapping GAP technology to guarantee the operation of the system with high security and confidentiality. Transparent protocol conversion In order to reach the limited connection of data under safety isolation, Inspur VTInfo security isolation gatekeeper provides the transparent protocol conversion for the application layer data to increase the security of the exchange of data of the system. The protocol conversion process is transparent to the user, and is stable and reliable without the management of user.
Data filtering and transmission of application layer
Inspur VTInfo security isolation gatekeeper provides the application layer data filtering and transmission function to support the main stream application layer protocol, including; HTTP protocol FTP protocol SMTP protocol POP3 protocol DNS protocol Data mapping protocol File transport protocol
And the ever-expanding application layer protocols
Seurity classification mark (optional) and content check
Inspur TVInfo security isolation gatekeeper integration has the security identification mark checking system designated by the State Secrecy Bureau and the high-speed content checking system.
Authentication and authorization of user
Inspur TVInfo security isolation gatekeeper provides various user authentication modes including certificate(optional)and OTP authentication and executes the user authentication through functional mode and application binding function.
AntiVirus (optional)
Inspur TVInfo security isolation gatekeeper integration has the AntiVirus module(optional). The antivirus library can be upgraded through the network and GUI management configuration interface.
IDS
Inspur TVInfo security isolation gatekeeper integration has the preliminary level IDS which can provide the fundamental Intrusion Detection function for unit without intrusion detection system.
Management configuration
Inspur TVInfo security isolation gatekeeper can conduct management configuration through GUI, CONSOLE and LCD. The GUI management configuration can provide the independent network interface to assure higher security. The management configuration needs identification authentication of the system.
Log analysis
Inspur TVInfo security isolation gatekeeper provides perfect log analysis tools which can inquire and maintain the log through the GUI mode. The log analysis needs the identification authentication of the system. The log supports import and export.
Reach the single-way and two-way channel control through special isolation exchange card.
Single-way work mode can be selected, i.e. building one data channel between the interior system and exterior system through chip detection and chip interlocking mechanism, and transferring only the data from the exterior network to the interior network to control the channel completely through the control of data flow direction.
|