Application Scenario · Military / Confidential Network / Confidential Terminal

Military / Confidential Network · Non-intrusive Remote O&M under Physical Isolation

For military, government confidential networks and confidential terminals, non-intrusive gateways deployed on private networks/intranets enable minute-level remote O&M and full operation audit under physical isolation.

Core solution for this scenario

APM-G220 Non-intrusive Smart Tuning GatewayTakes over the confidential-computer screen via HDMI and emulates keyboard and mouse via USB; privately deployed on a private network / intranet, with 4G not connected to the public network
Military / Confidential Network / Confidential Terminal scenario
Typical Customer Scenario

A military research institute keeps its confidential network physically isolated from the outside; dozens of test industrial PCs are distributed across 3 laboratory buildings. Each debugging session required test personnel to carry bulky monitors and operate machines one by one, taking half a day or more to walk between buildings and severely limiting progress. After deploying the G220, each industrial PC is connected non-intrusively, and all controlled-machine screens are operated remotely and centrally from the central server room. Debugging efficiency improved several-fold, physical isolation remained fully intact, and confidentiality compliance was satisfied.

I. Industry Pain Points

Typical challenges for Military / Confidential Network / Confidential Terminal in equipment O&M and data acquisition.

  • The core security principle of a confidential network is physical isolation — confidential computers cannot access external networks or install non-classified software, so all traditional remote-control solutions are unusable.
  • Confidential terminals are distributed across multiple secure areas; O&M requires approval and on-site escort to enter, so fault response heavily depends on physical presence.
  • Military and government units face high costs and limited staffing for on-site O&M personnel, making it hard to cover all terminals across the domain.
  • Operational activities lack digital audit means, placing heavy pressure on confidentiality management.

II. Solution

Build a "screen layer + protocol layer" dual-source data closed loop with the AIXOT non-intrusive gateway combination.

  • The APM-G220 captures the confidential-computer screen via HDMI and emulates keyboard and mouse via USB, connecting through Ethernet to the private network within the confidential zone and linking to an independently deployed private platform; the confidential computer is not networked, no software is installed, and no modifications are made.
  • In confidential scenarios, 4G does not connect to the public network; all communications are completed within the closed private network, ensuring isolation is not breached at the source.
  • Between the gateway and the confidential computer there are only two physical cables: HDMI one-way video and USB HID input — no network connection, no file-system access, no data-bus sharing.
  • Multi-level account permissions plus pre-operation secondary identity authentication; full logs and screenshot archiving make operations auditable, traceable and replayable.

III. Deployment Steps

An executable path from interface inventory to a standardized closed loop.

  • Inventory the video interfaces (HDMI/DVI/VGA) and USB keyboard-mouse channels of confidential terminals, and plan G220 deployment points
  • Deploy the remote-control platform on a standalone server within the confidential zone, with no Internet connection
  • Connect the gateway via Ethernet to the private network of the confidential zone and link to the private platform; 4G does not connect to the public network
  • Configure multi-level account permissions and secondary authentication; authorize before operation
  • Establish an O&M SOP of approval — access — remote operation — screen-recording archiving, with periodic replay audits

IV. System Integration & Data Connectivity

Standardized integration points with MES / SCADA / PLC / quality systems.

  • Integrate with the confidentiality management system: remote access requires approval, with least-privilege permissions
  • Integrate with the O&M audit system: full operation logs and screenshot records can be exported
  • Integrate with video security: remote operations are overlaid with on-site industrial-TV review
  • Integrate with the group platform: unified management of multiple secure areas, referencing the group multi-site solution

V. Value & Quantified Metrics

Measurable benefits delivered by the non-intrusive solution.

Hours → 5 minO&M Response
0Confidential-computer network changes
100%Operations auditable

VI. Deployment Boundaries & Compliance Red Lines

Compliance & applicable boundaries

Military and government confidential networks are strictly prohibited from connecting to public clouds; 4G must not connect to public networks; remote links must be confined to the private network / intranet within the confidential zone. The G220 applies only to confidential computers / terminals with video output and USB input; purely embedded devices without a display require separate evaluation.

VII. FAQ

Frequently asked questions for the Military / Confidential Network / Confidential Terminal scenario.

Can a confidential computer be networked for remote control?

No, and it is not permitted. The G220 takes over only physically via HDMI/USB; the confidential computer itself is not networked and no software is installed, and the link is closed within the confidential-zone private network.

Will physical isolation be compromised?

No. Between the gateway and the confidential computer there exist only two physical cables — HDMI one-way video and USB HID input — with no network connection, no file-system access, and no data-bus sharing.

How are operations audited?

Each session is fully screen-recorded; operation actions and screen changes are logged, enabling replay for accountability and satisfying confidentiality-management requirements.

How are cross-zone confidential terminals managed?

Deploy a private platform via the confidential-zone private network or VPN; all communications are completed within the closed private network, and 4G does not connect to the public network.

Related Scenarios & Products

Group Multi-Site

One platform to manage all site equipment

→ View Scenario

Data Center / Server Room

Out-of-band KVM centralized O&M

→ View Scenario

DCS / SCADA

Non-intrusive remote O&M for operator stations

→ View Scenario