Military / Confidential Network · Non-intrusive Remote O&M under Physical Isolation
For military, government confidential networks and confidential terminals, non-intrusive gateways deployed on private networks/intranets enable minute-level remote O&M and full operation audit under physical isolation.
Core solution for this scenario

A military research institute keeps its confidential network physically isolated from the outside; dozens of test industrial PCs are distributed across 3 laboratory buildings. Each debugging session required test personnel to carry bulky monitors and operate machines one by one, taking half a day or more to walk between buildings and severely limiting progress. After deploying the G220, each industrial PC is connected non-intrusively, and all controlled-machine screens are operated remotely and centrally from the central server room. Debugging efficiency improved several-fold, physical isolation remained fully intact, and confidentiality compliance was satisfied.
I. Industry Pain Points
Typical challenges for Military / Confidential Network / Confidential Terminal in equipment O&M and data acquisition.
- The core security principle of a confidential network is physical isolation — confidential computers cannot access external networks or install non-classified software, so all traditional remote-control solutions are unusable.
- Confidential terminals are distributed across multiple secure areas; O&M requires approval and on-site escort to enter, so fault response heavily depends on physical presence.
- Military and government units face high costs and limited staffing for on-site O&M personnel, making it hard to cover all terminals across the domain.
- Operational activities lack digital audit means, placing heavy pressure on confidentiality management.
II. Solution
Build a "screen layer + protocol layer" dual-source data closed loop with the AIXOT non-intrusive gateway combination.
- The APM-G220 captures the confidential-computer screen via HDMI and emulates keyboard and mouse via USB, connecting through Ethernet to the private network within the confidential zone and linking to an independently deployed private platform; the confidential computer is not networked, no software is installed, and no modifications are made.
- In confidential scenarios, 4G does not connect to the public network; all communications are completed within the closed private network, ensuring isolation is not breached at the source.
- Between the gateway and the confidential computer there are only two physical cables: HDMI one-way video and USB HID input — no network connection, no file-system access, no data-bus sharing.
- Multi-level account permissions plus pre-operation secondary identity authentication; full logs and screenshot archiving make operations auditable, traceable and replayable.
III. Deployment Steps
An executable path from interface inventory to a standardized closed loop.
- Inventory the video interfaces (HDMI/DVI/VGA) and USB keyboard-mouse channels of confidential terminals, and plan G220 deployment points
- Deploy the remote-control platform on a standalone server within the confidential zone, with no Internet connection
- Connect the gateway via Ethernet to the private network of the confidential zone and link to the private platform; 4G does not connect to the public network
- Configure multi-level account permissions and secondary authentication; authorize before operation
- Establish an O&M SOP of approval — access — remote operation — screen-recording archiving, with periodic replay audits
IV. System Integration & Data Connectivity
Standardized integration points with MES / SCADA / PLC / quality systems.
- Integrate with the confidentiality management system: remote access requires approval, with least-privilege permissions
- Integrate with the O&M audit system: full operation logs and screenshot records can be exported
- Integrate with video security: remote operations are overlaid with on-site industrial-TV review
- Integrate with the group platform: unified management of multiple secure areas, referencing the group multi-site solution
V. Value & Quantified Metrics
Measurable benefits delivered by the non-intrusive solution.
VI. Deployment Boundaries & Compliance Red Lines
Compliance & applicable boundaries
Military and government confidential networks are strictly prohibited from connecting to public clouds; 4G must not connect to public networks; remote links must be confined to the private network / intranet within the confidential zone. The G220 applies only to confidential computers / terminals with video output and USB input; purely embedded devices without a display require separate evaluation.
VII. FAQ
Frequently asked questions for the Military / Confidential Network / Confidential Terminal scenario.
Can a confidential computer be networked for remote control?
No, and it is not permitted. The G220 takes over only physically via HDMI/USB; the confidential computer itself is not networked and no software is installed, and the link is closed within the confidential-zone private network.
Will physical isolation be compromised?
No. Between the gateway and the confidential computer there exist only two physical cables — HDMI one-way video and USB HID input — with no network connection, no file-system access, and no data-bus sharing.
How are operations audited?
Each session is fully screen-recorded; operation actions and screen changes are logged, enabling replay for accountability and satisfying confidentiality-management requirements.
How are cross-zone confidential terminals managed?
Deploy a private platform via the confidential-zone private network or VPN; all communications are completed within the closed private network, and 4G does not connect to the public network.