Cross-domain security data interaction method, device and system based on dynamic multi-channel and intelligent verification, and computer equipment

By using dynamic multi-channel and intelligent verification methods between internal and external networks, dynamically allocating data shards and performing real-time verification, the problem of low intelligence in data exchange in internal and external networks is solved, and efficient and secure data interaction is achieved.

CN120200819APending Publication Date: 2025-06-24CHINA SOUTHERN POWER GRID INTERNET SERVICE CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510396003.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the process of digital transformation, data exchange between internal and external networks have the problem of low intelligence in data transmission, especially in data exchange between different security domains or different networks.

Method used

A cross-domain secure data interaction method based on dynamic multi-channel and intelligent verification is adopted. By obtaining network status data of each available transmission channel between internal and external networks, the transmission priority score is determined, data sharding is dynamically allocated using reinforcement learning algorithms, and data filtering and integrity verification are performed through the hardware filtering engine and shard-level verification engine in the isolation domain.

Benefits of technology

It improves the intelligence of data transmission during the data interaction between internal and external networks, realizes load balancing and disaster recovery switching, reduces data delay, and improves the overall efficiency and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200819A_ABST
    Figure CN120200819A_ABST
Patent Text Reader

Abstract

The invention relates to a cross-network domain security data interaction method and device based on dynamic multi-channel and intelligent verification, computer equipment, a computer readable storage medium and a computer program product, and is applied to an external network domain. The method comprises the following steps: acquiring network state data of each available transmission channel between an internal network and an external network, and determining a transmission priority score of each available transmission channel so as to screen out a main transmission channel and a standby transmission channel; dynamically distributing to-be-transmitted data fragments to the main transmission channel and the standby transmission channel through a reinforcement learning algorithm; transmitting the data fragments distributed to the main transmission channel and the standby transmission channel to an isolation domain; the isolation domain is used for filtering the received data fragments through a hardware filtering engine and sending the filtered data fragments to the internal network domain; the internal network domain is used for verifying the integrity of the data fragments according to the fragment hash values corresponding to the data fragments. By adopting the method, the intelligence of data transmission in the internal and external network interaction process can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a cross-network domain secure data interaction method, device, system, computer device, computer-readable storage medium, and computer program product based on dynamic multi-channels and intelligent verification. Background Art

[0002] Generally, in order to protect the security of important data and application systems, a method of coexisting multiple networks is commonly adopted. However, in the process of digital transformation, the most direct problem usually faced is how to enable application systems in different networks and different security domains to achieve information exchange and sharing, that is, how to share and exchange data in different domains.

[0003] In the process of data sharing and exchange, exchanges between different security domains or different networks are usually faced, including data exchanges between internal and external networks and between different confidentiality levels. In related technologies, the interaction between internal and external networks depends on fixed lines, with limited bandwidth and vulnerable to network fluctuations, resulting in low intelligence in data transmission during the interaction between internal and external networks.

[0004] Therefore, in related technologies, there is a problem of low intelligence in data transmission during the interaction between internal and external networks. Summary of the Invention

[0005] Based on this, in view of the above technical problems, it is necessary to provide a cross-network domain secure data interaction method, system, device, computer device, computer-readable storage medium, and computer program product based on dynamic multi-channels and intelligent verification, which can improve the intelligence of data transmission during the interaction between internal and external networks.

[0006] In a first aspect, the present application provides a cross-network domain secure data interaction method based on dynamic multi-channels and intelligent verification, which is applied to an external network domain and includes:

[0007] Obtain network status data of each available transmission channel between the internal and external networks;

[0008] Determine the transmission priority scores of each available transmission channel according to the network status data of each available transmission channel, so as to screen out the main transmission channel and the backup transmission channel;

[0009] Dynamically allocate the data slices to be transmitted to the main transmission channel and the backup transmission channel through a reinforcement learning algorithm; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay;

[0010] Transmit the data slices allocated to the main transmission channel and the backup transmission channel to the isolation domain;

[0011] Among them, the isolation domain is used to filter the received data shards through a hardware filtering engine and send the filtered data shards to the intranet domain; the intranet domain is used to verify the integrity of the received data shards according to the shard hash values corresponding to the received data shards.

[0012] In one embodiment, there are multiple pieces of network status data. According to the network status data of each available transmission channel, the transmission priority scores of each available transmission channel are determined to screen out the main transmission channel and the backup transmission channel, including:

[0013] For any available transmission channel, obtain the weight information corresponding to each piece of network status data of the any available transmission channel;

[0014] According to the weight information corresponding to each piece of network status data, adjust each piece of network status data to obtain each adjusted network status data;

[0015] Obtain the sum among each adjusted network status data to obtain the transmission priority score of the any available transmission channel.

[0016] In one embodiment, the weight information includes a weight coefficient, the network status data includes the currently measured bandwidth, the data packet loss rate, and the network latency. According to the weight information corresponding to each piece of network status data, adjusting each piece of network status data to obtain each adjusted network status data includes:

[0017] Obtain the product of the first ratio and the weight coefficient corresponding to the currently measured bandwidth to obtain the adjusted currently measured bandwidth; the first ratio is the ratio between the currently measured bandwidth and the theoretical maximum bandwidth of the any available transmission channel;

[0018] Obtain the product of the target difference and the weight coefficient corresponding to the data packet loss rate to obtain the adjusted data packet loss rate; the target difference is the difference between 1 and the data packet loss rate;

[0019] Obtain the product of the second ratio and the weight coefficient corresponding to the network latency to obtain the adjusted network latency; the second ratio is the ratio between 1 and the network latency.

[0020] In one embodiment, the step of transmitting the data shards allocated to the main transmission channel and the backup transmission channel to the isolation domain includes:

[0021] Encode the data shards allocated to the main transmission channel through a forward error correction coding technique to generate redundant data shards;

[0022] Overlay the redundant data shards onto the primary transmission channel, and transmit the data shards of the primary transmission channel and the backup transmission channel to the isolation domain.

[0023] In one embodiment, the method further includes:

[0024] Obtain the original data to be transmitted to the intranet domain;

[0025] Compress the original data to obtain compressed data;

[0026] Perform sharding on the compressed data to obtain the data shards to be transmitted, and attach a lightweight blockchain-style hash chain to the data shards to be transmitted.

[0027] In a second aspect, the present application further provides a cross-network domain secure data interaction system based on dynamic multi-channels and intelligent verification, including: a dynamic channel scheduler deployed in the external network domain, a secure ferry middle layer deployed in the isolation domain, and a shard-level verification engine deployed in the internal network domain;

[0028] The dynamic channel scheduler is configured to obtain the network status data of each available transmission channel between the internal and external networks;

[0029] The dynamic channel scheduler is configured to determine the transmission priority scores of each available transmission channel according to the network status data of each available transmission channel, so as to screen out the primary transmission channel and the backup transmission channel;

[0030] The dynamic channel scheduler is configured to dynamically allocate the data shards to be transmitted to the primary transmission channel and the backup transmission channel through a reinforcement learning algorithm; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay;

[0031] The dynamic channel scheduler is configured to transmit the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain;

[0032] The secure ferry middle layer is configured to filter the received data shards through a hardware filtering engine and send the filtered data shards to the internal network domain;

[0033] The shard-level verification engine is configured to verify the integrity of the received data shards according to the shard hash values corresponding to the received data shards.

[0034] In a third aspect, the present application further provides a cross-network domain secure data interaction device applied to the external network domain, including:

[0035] An acquisition module, configured to obtain the network status data of each available transmission channel between the internal and external networks;

[0036] A determination module, configured to determine the transmission priority scores of the available transmission channels according to the network status data of the available transmission channels, so as to screen out the primary transmission channel and the backup transmission channel;

[0037] An allocation module, configured to dynamically allocate the data shards to be transmitted to the primary transmission channel and the backup transmission channel through a reinforcement learning algorithm; the optimization objective of the reinforcement learning algorithm is to minimize the overall transmission delay;

[0038] A transmission module, configured to transmit the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain;

[0039] Wherein, the isolation domain is configured to filter the received data shards through a hardware filtering engine and send the filtered data shards to the internal network domain; the internal network domain is configured to verify the integrity of the received data shards according to the shard hash values corresponding to the received data shards.

[0040] In a fourth aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.

[0041] In a fifth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0042] In a sixth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0043] The above cross-network domain secure data interaction method, system, device, computer device, computer-readable storage medium and computer program product based on dynamic multi-channel and intelligent verification are applied to the external network domain. By obtaining the network status data of each available transmission channel between the internal and external networks; according to the network status data of each available transmission channel, determining the transmission priority scores of each available transmission channel to screen out the primary transmission channel and the backup transmission channel; through a reinforcement learning algorithm, dynamically allocating the data shards to be transmitted to the primary transmission channel and the backup transmission channel; the optimization objective of the reinforcement learning algorithm is to minimize the overall transmission delay; transmitting the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain; the isolation domain is configured to filter the received data shards through a hardware filtering engine and send the filtered data shards to the internal network domain; the internal network domain is configured to verify the integrity of the received data shards according to the shard hash values corresponding to the received data shards.

[0044] In this way, by monitoring the network status of available transmission channels between the internal and external networks, the transmission priorities of each available transmission channel can be more accurately evaluated, so as to screen out the main transmission channel and the backup transmission channel. Then, through a reinforcement learning algorithm with the optimization goal of minimizing the overall transmission delay, the data slices to be transmitted are dynamically allocated to the main transmission channel and the backup transmission channel, realizing load balancing and disaster recovery switching, reducing data latency, and improving the intelligence of data transmission in the process of data interaction between the internal and external networks. Further, the data slices allocated to the main transmission channel and the backup transmission channel are transmitted to the isolation domain. The isolation domain is used to filter the received data slices through a hardware filtering engine and send the filtered data slices to the internal network domain. The internal network domain is used to verify the integrity of the received data slices one by one according to the slice hash values corresponding to the received data slices, without waiting to verify after receiving the complete data, avoiding the problem of full retransmission when data errors occur, reducing the time-consuming of data transmission, improving the verification efficiency, and thus effectively improving the intelligence of data transmission in the process of data interaction between the internal and external networks. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0046] Figure 1 It is a schematic flowchart of a cross-network domain secure data interaction method based on dynamic multi-channels and intelligent verification in one embodiment;

[0047] Figure 2 It is a schematic flowchart of a cross-network domain secure data interaction method based on dynamic multi-channels and intelligent verification in another embodiment;

[0048] Figure 3 It is a system framework diagram of a cross-network domain secure data interaction system based on dynamic multi-channels and intelligent verification in one embodiment;

[0049] Figure 4 It is a network topology diagram of a cross-network domain secure data interaction system based on dynamic multi-channels and intelligent verification in one embodiment;

[0050] Figure 5 It is a structural block diagram of a cross-network domain secure data interaction device based on dynamic multi-channels and intelligent verification in one embodiment;

[0051] Figure 6 It is an internal structure diagram of a computer device in one embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0053] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are only examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0054] In one embodiment, as Figure 1 shown, a cross-network domain secure data interaction method based on dynamic multi-channels and intelligent verification is provided, which is applied to the external network domain. In this embodiment, the method is illustrated by taking the method applied to a computer device deployed in the external network domain. It can be understood that the computer device can be a terminal device, and the terminal device may include but is not limited to: devices such as smart phones, tablet computers, portable personal computers, etc. The type of the terminal device is not limited in the embodiments of the present application and is hereby explained. Optionally, the computer device can be a server, and the server can be an independent physical server or a server cluster or distributed system composed of multiple physical servers. The computer device can also be a system including a terminal and a server, and realizes the cross-network domain secure data interaction method based on dynamic multi-channels and intelligent verification through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:

[0055] Step S110, obtain the network state data of each available transmission channel between the internal and external networks.

[0056] Among them, the available transmission channel refers to a channel that can be used for data transmission between the internal and external networks, including but not limited to channels such as TCP (Transmission Control Protocol) / UDP (User Datagram Protocol) / 5G dedicated line, etc.

[0057] Among them, the network state data may refer to data used to characterize the network state, including but not limited to at least one of the measured bandwidth, data packet loss rate, and network latency of the current channel.

[0058] In a specific implementation, a computer device in the external network domain can obtain the network status data of each available transmission channel between the internal and external networks. Specifically, each available transmission channel between the internal and external networks can be monitored according to preset network status monitoring metrics to obtain the network status data. The network status monitoring metrics include, but are not limited to, at least one of the measured bandwidth, data packet loss rate, and network latency.

[0059] Step S120: Determine the transmission priority scores of each available transmission channel according to the network status data of each available transmission channel, so as to screen out the primary transmission channel and the backup transmission channel.

[0060] Among them, the transmission priority score is used to evaluate the transmission priority of the available transmission channel. The higher the transmission priority score, the higher the corresponding transmission priority. That is, the transmission priority score is positively correlated with the transmission priority.

[0061] Among them, the primary transmission channel can refer to the available transmission channel with the highest transmission priority score, and the backup transmission channel can be the available transmission channel with the second highest transmission priority score.

[0062] In a specific implementation, the computer device can determine the transmission priority scores of each available transmission channel according to the network status data of each available transmission channel, and thus can screen out the primary transmission channel and the backup transmission channel according to the transmission priority scores of each available transmission channel.

[0063] Among them, in the process of determining the transmission priority score, the computer device can input the network status data of each available transmission channel into a pre-trained transmission priority scoring model, and the pre-trained transmission priority scoring model outputs the transmission priority scores of each available transmission channel based on the network status data.

[0064] For example, in practical applications, an LSTM (Long Short-Term Memory) neural network can be used to predict the channel delay and packet loss rate within the next 10 ms. The input features include network status data: historical bandwidth (1 s window), TCP retransmission rate, timestamp jitter, and queue depth; the output result: the transmission priority scores (0 - 100 points) of each channel.

[0065] Step S130: Dynamically allocate the data shards to be transmitted to the primary transmission channel and the backup transmission channel through a reinforcement learning algorithm.

[0066] Among them, the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay.

[0067] Among them, the data shards to be transmitted refer to the data shards obtained by intelligently sharding the data to be transmitted from the external network domain to the internal network domain.

[0068] In a specific implementation, when a computer device dynamically allocates data shards to be transmitted to a primary transmission channel and a backup transmission channel through a reinforcement learning algorithm, a Q-learning reinforcement learning model can be used to decide the transmission path of the data shards to be transmitted. The objective function is to minimize the end-to-end delay, so as to optimize the mapping relationship between the data shards to be transmitted and the available transmission channels based on the Q-learning algorithm, and determine whether to allocate the data shards to be transmitted to the primary transmission channel or the backup transmission channel. The size of the data shards is dynamically adjusted according to the channel MTU (Maximum Transmission Unit) (256B - 4KB) to make full use of the transmission capacity of each channel, avoid additional splitting and recombination of data packets in the channel due to over-large shards, which increases the transmission delay; and also avoid over-small shards, which results in excessive protocol overhead.

[0069] Among them, in the process of adopting the Q-learning algorithm, the state can be composed of multiple factors, such as the current bandwidth, delay, queue length of each channel, and the number and size of the shards that have not been allocated yet, etc., to reflect the real-time status of the current network and the progress of data transmission. The agent can make decisions based on these states.

[0070] The action can refer to which available transmission channel to allocate a data shard for transmission. In this embodiment, there are 2 available transmission channels (primary transmission channel or backup transmission channel) to choose from, so the size of the action space in each state is 2.

[0071] In this embodiment, the design goal of the reward function of the Q-learning algorithm is to minimize the overall transmission delay. The reward can be defined as the negative of the transmission delay, that is, after each transmission is completed, the smaller the delay, the greater the reward. For example, if the delay of a data shard through a certain available transmission channel is t, then the reward r = -t. The goal of the agent is to indirectly achieve the purpose of minimizing the overall transmission delay by continuously learning and choosing actions that can obtain the maximum cumulative reward.

[0072] The agent selects an action a in each state s, transmits the data shard to be transmitted through the selected available transmission channel, then calculates the reward r according to the delay information feedback by the environment, and updates the Q value. The Q value update formula is Q(s, a) ← (1 - α)Q(s, a) + α[r + γmaxa′Q(s′, a′)], where α is the learning rate, γ is the discount factor, and s′ is the next state transferred to after executing the action a.

[0073] By continuously interacting with the environment, the Q-learning algorithm gradually learns which available transmission channel to allocate data shards to in different network states to achieve the minimum transmission delay. As the learning progresses, the agent can dynamically adjust the mapping relationship between the data shards to be transmitted and the available transmission channels according to the real-time network conditions, thereby minimizing the overall transmission delay.

[0074] Step S140: Transmit the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain.

[0075] Among them, each data shard is attached with a lightweight blockchain-style hash chain (Merkle Tree structure), enabling the receiving end to verify the integrity piece by piece.

[0076] Specifically, during the process of sharding the data to be transmitted, a lightweight blockchain-style hash chain (Merkle Tree structure) can be attached to each data shard. Specifically, the sender generates a CRC32 checksum for each data shard and writes the shard hash value into the Merkle tree; the shard header of the data shard includes: CRC32 checksum, shard generation timestamp, and Merkle tree node hash.

[0077] Among them, the isolation domain is used to filter the received data shards through a hardware filtering engine and send the filtered data shards to the intranet domain.

[0078] Among them, the isolation domain is provided with a one-way optical gate enhanced ferry system: a physically isolated buffer area is deployed between the external network and the internal network, and the data flows unidirectionally after format cleaning, content filtering, and virus scanning.

[0079] Among them, the intranet domain is used to verify the integrity of the received data shards according to the shard hash values corresponding to the received data shards.

[0080] In specific implementation, the computer device can transmit the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain through multi-channel aggregation technology. The isolation domain is used to filter the received data shards through a hardware filtering engine and send the filtered data shards to the intranet domain; the intranet domain is used to verify the integrity of the received data shards according to the shard hash values corresponding to the received data shards.

[0081] Specifically, the intranet domain (i.e., the receiving end) verifies immediately when the data shards arrive. The incorrect shards trigger local retransmission instead of overall retransmission. In practical applications, the intranet domain can verify the CRC32 and the hash chain in parallel. The failed shards trigger local retransmission, and the verification records of all data shards are written into the consortium chain. All verification records are put on the chain to ensure that the process cannot be tampered with.

[0082] Among them, during the data transmission between the internal and external networks, a differential incremental transmission algorithm is adopted: only the changed data blocks are synchronized, and the second-level incremental update is realized by combining the version number comparison to reduce the redundant data transmission. Specifically, the rsync algorithm is used to identify the data differences, determine the changed data blocks, and only transmit the changed data blocks (the block size is adjustable). The version number format is: timestamp_hash prefix.

[0083] In the above cross-network domain secure data interaction method based on dynamic multi-channels and intelligent verification, when applied to the external network domain, the network status data of each available transmission channel between the internal and external networks is obtained; according to the network status data of each available transmission channel, the transmission priority scores of each available transmission channel are determined to screen out the primary transmission channel and the backup transmission channel; through the reinforcement learning algorithm, the data slices to be transmitted are dynamically allocated to the primary transmission channel and the backup transmission channel; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay; the data slices allocated to the primary transmission channel and the backup transmission channel are transmitted to the isolation domain; the isolation domain is used to filter the received data slices through the hardware filtering engine and send the filtered data slices to the internal network domain; the internal network domain is used to verify the integrity of the received data slices according to the slice hash values corresponding to the received data slices.

[0084] In this way, by monitoring the network status of the available transmission channels between the internal and external networks, the transmission priorities of each available transmission channel can be more accurately evaluated, so as to screen out the primary transmission channel and the backup transmission channel. Through the reinforcement learning algorithm with the optimization goal of minimizing the overall transmission delay, the data slices to be transmitted are dynamically allocated to the primary transmission channel and the backup transmission channel, realizing load balancing and disaster recovery switching, reducing data latency, and improving the data transmission intelligence in the data interaction process between the internal and external networks; further, the data slices allocated to the primary transmission channel and the backup transmission channel are transmitted to the isolation domain; the isolation domain is used to filter the received data slices through the hardware filtering engine and send the filtered data slices to the internal network domain; the internal network domain is used to verify the integrity of each received data slice one by one according to the slice hash value corresponding to the received data slice, without waiting to verify after receiving the complete data, avoiding the problem of full-scale retransmission when data errors occur, reducing the time-consuming of data transmission, improving the verification efficiency, and thus effectively improving the data transmission intelligence in the data interaction process between the internal and external networks.

[0085] In one embodiment, there are multiple pieces of network status data. According to the network status data of each available transmission channel, the transmission priority scores of each available transmission channel are determined to screen out the primary transmission channel and the backup transmission channel, including: for any available transmission channel, obtaining the weight information corresponding to each piece of network status data of any available transmission channel; adjusting each piece of network status data according to the weight information corresponding to each piece of network status data to obtain each adjusted network status data; obtaining the sum of the adjusted network status data to obtain the transmission priority score of any available transmission channel.

[0086] Among them, the multiple pieces of network status data may include the currently measured bandwidth, the data packet loss rate, and the network latency.

[0087] In a specific implementation, when the computer device determines the transmission priority scores of each available transmission channel according to the network status data of each available transmission channel to screen out the primary transmission channel and the backup transmission channel, for any available transmission channel, the weight information corresponding to each piece of network status data of the available transmission channel can be obtained, and each piece of network status data is adjusted according to the weight information corresponding to each piece of network status data to obtain each adjusted network status data; then, the sum of the adjusted network status data is obtained to obtain the transmission priority score of the available transmission channel.

[0088] Among them, the weight information includes weight coefficients. When the computer device adjusts each piece of network status data according to the weight information corresponding to each piece of network status data to obtain each adjusted network status data, the product of the first ratio and the weight coefficient corresponding to the currently measured bandwidth can be obtained to obtain the adjusted currently measured bandwidth; the first ratio is the ratio between the currently measured bandwidth and the theoretical maximum bandwidth of any available transmission channel; the product of the target difference and the weight coefficient corresponding to the data packet loss rate is obtained to obtain the adjusted data packet loss rate; the target difference is the difference between 1 and the data packet loss rate; the product of the second ratio and the weight coefficient corresponding to the network latency is obtained to obtain the adjusted network latency; the second ratio is the ratio between 1 and the network latency.

[0089] In this way, for the available transmission channel, by obtaining the sum of the adjusted currently measured bandwidth, the adjusted data packet loss rate, and the adjusted network latency corresponding to the available transmission channel, the transmission priority score corresponding to the available transmission channel is obtained.

[0090] In practical applications, the currently measured bandwidth, the data packet loss rate, and the network latency corresponding to the available transmission channel can be input into a pre-configured transmission priority scoring formula, and the transmission priority scoring formula can be expressed as:

[0091] Score = α * (BWcurrent / BWmax) + β * (1 - LossRate) + γ * (1 / Latency);

[0092] Among them, Score represents the transmission priority score, and the other variables are defined as shown in Table 1 below:

[0093] Table 1 Variable Definitions:

[0094] Among them, the weight coefficients can be dynamically optimized through gradient descent.

[0095] Among them, BWcurrent / BWmax is the first ratio, which can also be named the bandwidth utilization term.

[0096] The bandwidth utilization term is used to measure the actual usage efficiency of the channel bandwidth. The closer the value is to 1, the more fully the bandwidth is utilized. For example: if the measured bandwidth is 800 Mbps and the theoretical bandwidth is 1 Gbps, the score for this item is 0.8.

[0097] Among them, 1 - LossRate is the target difference, which can also be named the packet loss rate term. The lower the packet loss rate, the higher the score. For example: when the packet loss rate is 2% (0.02), the score for this item is 0.98.

[0098] Among them, 1 / Latency is the second ratio, which can also be named the latency term. The lower the latency, the higher the score. For example: when the latency is 5 ms, the score for this item is 1 / 5 = 0.2; when the latency is 2 ms, the score is 1 / 2 = 0.5.

[0099] Among them, the weight coefficients (α, β, γ) are used to balance the importance of bandwidth, packet loss rate, and latency in the score. Default settings: α = 0.4 (higher bandwidth weight, suitable for throughput - sensitive scenarios); β = 0.3 (packet loss rate is of secondary importance, affecting data integrity); γ = 0.3 (same latency weight, suitable for scenarios with high real - time requirements).

[0100] Dynamic adjustment of weight coefficients:

[0101] Optimize the weights through the Gradient Descent method. The goal is to minimize the overall transmission latency and maximize the success rate. For example: if a certain channel frequently experiences packet loss resulting in retransmission, the system automatically reduces the β weight and increases the α or γ weight.

[0102] For example:

[0103] Suppose the measured parameters of a certain 5G channel are as follows:

[0104] BWcurrent = 900 Mbps, BWmax = 1 Gbps;

[0105] LossRate = 0.01 (1% packet loss);

[0106] Latency = 8 ms;

[0107] Weights: α = 0.4, β = 0.3, γ = 0.3;

[0108] The formula for calculating Score is:

[0109] α * (BWcurrent / BWmax) + β * (1 - LossRate) + γ * (1 / Latency);

[0110] Calculation:

[0111] Score = 0.4 * 900 / 1000 + 0.3 * (1 - 0.01) + 0.3 * 1 / 8

[0112] = 0.4 * 0.9 + 0.3 * 0.99 + 0.3 * 0.125 = 0.36 + 0.297 + 0.0375 = 0.6945.

[0113] Application scenario of the formula:

[0114] Channel selection: Select the channel with the highest Score as the main transmission channel.

[0115] Redundant backup: If the Score of the main transmission channel is lower than the threshold (e.g., 0.6), automatically switch to the backup transmission channel.

[0116] Network optimization: Dynamically adjust the weight coefficients in real-time to adapt to different service requirements (e.g., video streams focus on bandwidth, and financial transactions focus on latency).

[0117] This scoring model is based on multi-attribute decision analysis (MCDA) and comprehensively evaluates multiple performance indicators through linear weighted aggregation. Its advantages are:

[0118] 1. Interpretability: Intuitively reflects the impact of each indicator on the channel quality.

[0119] 2. Flexibility: The weight coefficients can be dynamically adjusted according to service requirements.

[0120] 3. Scalability: More indicators (such as jitter, cost) can be added to form an extended formula:

[0121] Score = (where n is ∑i = 1) wi * f(xi);

[0122] where wi is the weight and f(xi) is the normalization function.

[0123] In one embodiment, transmitting the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain includes: encoding the data shards allocated to the primary transmission channel through forward error correction coding technology to generate redundant data shards; superimposing the redundant data shards on the primary transmission channel, and transmitting the data shards of the primary transmission channel and the backup transmission channel to the isolation domain.

[0124] In a specific implementation, in the process of transmitting the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain through multi-channel aggregation technology, the data shards allocated to the primary transmission channel can be encoded through forward error correction coding technology to generate redundant data shards; the redundant data shards are superimposed on the primary transmission channel, and the data shards of the primary transmission channel and the backup transmission channel are transmitted to the isolation domain.

[0125] In practical applications, redundant data shards can be superimposed on the primary transmission channel (such as a 5G dedicated line), and Reed-Solomon forward error correction coding (FEC) is adopted with an adjustable redundancy (default 20%). The receiving end (intranet domain) quickly recovers the lost shards through matrix decoding, avoiding the RTT (Round-Trip Time) waiting of traditional TCP retransmission.

[0126] In this way, redundant transmission is superimposed on the primary transmission channel, and fast packet loss recovery is achieved through forward error correction coding (FEC), which can avoid retransmission delay.

[0127] In one embodiment, the method further includes: obtaining the original data to be transmitted to the intranet domain; compressing the original data to obtain compressed data; performing sharding processing on the compressed data to obtain the data shards to be transmitted, and attaching a lightweight blockchain-style hash chain to the data shards to be transmitted.

[0128] In a specific implementation, before the step of dynamically allocating the data shards to be transmitted to the primary transmission channel and the backup transmission channel, the computer device can obtain the original data to be transmitted to the intranet domain; compress the original data to obtain compressed data; perform sharding processing on the compressed data to obtain the data shards to be transmitted, and attach a lightweight blockchain-style hash chain to the data shards to be transmitted.

[0129] Among them, edge computing nodes can be deployed near the boundary between the internal and external networks to pre-execute preprocessing such as data compression (LZ4 / Snappy algorithm) and protocol conversion (JSON-binary). Build a topology-aware routing engine: combine SDN (Software Defined Network) to dynamically plan the shortest path, bypass network congestion nodes, ensure the optimal transmission path, and solve the problem that static routing strategies in related technologies cannot perceive network state changes in real time, and sudden traffic is prone to cause congestion.

[0130] Specifically, data compression can be performed in real time using the LZ4 algorithm, with a compression ratio of 50-70%, an increase in latency of <0.5 ms, and protocol conversion: converting JSON / XML to a binary format (such as Protocol Buffers), reducing the volume by 40-60%.

[0131] When the topology-aware routing engine selects a transmission path, it can combine with the SDN (Software Defined Network Controller) controller to collect the network-wide topology information, use the Dijkstra algorithm to calculate the shortest path, and dynamically avoid congested nodes. The path switching decision time is <5 ms.

[0132] In another embodiment, as Figure 2 shown, a flowchart of a cross-network domain secure data interaction method based on dynamic multi-channel and intelligent verification is provided, including the following steps:

[0133] Step S202, obtain the original data to be transmitted to the internal network domain.

[0134] Step S204, compress the original data to obtain compressed data.

[0135] Step S206, perform fragmentation processing on the compressed data to obtain data fragments to be transmitted, and attach a lightweight blockchain-style hash chain to the data fragments to be transmitted.

[0136] Step S208, obtain the network status data of each available transmission channel between the internal and external networks.

[0137] Step S210, for any available transmission channel, obtain the weight information corresponding to each network status data of any available transmission channel.

[0138] Step S212, adjust each network status data according to the weight information corresponding to each network status data to obtain each adjusted network status data.

[0139] Step S214, obtain the sum of the adjusted network status data to obtain the transmission priority score of any available transmission channel, so as to screen out the main transmission channel and the backup transmission channel.

[0140] Step S216, dynamically allocate the data fragments to be transmitted to the main transmission channel and the backup transmission channel through a reinforcement learning algorithm.

[0141] Step S218, perform encoding processing on the data fragments allocated to the main transmission channel through forward error correction coding technology to generate redundant data fragments.

[0142] Step S220: Stack the redundant data shards onto the primary transmission channel, and transmit the data shards of the primary transmission channel and the backup transmission channel to the isolation domain.

[0143] It should be noted that the specific limitations of the above steps can be referred to the specific limitations of a cross-network domain secure data interaction method based on dynamic multi-channels and intelligent verification in the above text.

[0144] In one embodiment, a cross-network domain secure data interaction system based on dynamic multi-channels and intelligent verification is provided. The system includes: a dynamic channel scheduler deployed in the external network domain, a secure ferry middle layer deployed in the isolation domain, and a shard-level verification engine deployed in the internal network domain.

[0145] The dynamic channel scheduler is used to obtain the network status data of each available transmission channel between the internal and external networks; the dynamic channel scheduler is also used to determine the transmission priority scores of each available transmission channel according to the network status data of each available transmission channel, so as to screen out the primary transmission channel and the backup transmission channel; the dynamic channel scheduler is also used to dynamically allocate the data shards to be transmitted to the primary transmission channel and the backup transmission channel through a reinforcement learning algorithm; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay; the dynamic channel scheduler is also used to transmit the data shards allocated to the primary transmission channel and the backup transmission channel to the isolation domain.

[0146] The secure ferry middle layer is used to filter the received data shards through a hardware filtering engine and send the filtered data shards to the internal network domain.

[0147] The shard-level verification engine is used to verify the integrity of the received data shards according to the shard hash values corresponding to the received data shards.

[0148] Among them, for the secure ferry middle layer, a one-way optical gate enhanced ferry system is designed: a physically isolated buffer area is deployed between the external network and the internal network, and the data flows unidirectionally after format cleaning, content filtering, and virus scanning.

[0149] Among them, the secure ferry middle layer implements dynamic token authentication: a one-time key is generated for each transmission, and end-to-end encryption is achieved in combination with the national cryptography algorithm (SM4 / SM9), and the key is distributed through an independent secure channel. Exemplarily, a temporary key pair can be generated based on the national cryptography SM9 algorithm, the token validity period is a single transmission cycle, and it is automatically destroyed after expiration. The key life cycle is bound to the transmission session, and the token format is: Token = Base64(SM9_Encrypt(SessionID || Timestamp || Nonce)).

[0150] Among them, the secure ferry intermediate layer enables real-time zero-trust access control: micro-segmentation policies based on user / device fingerprints to minimize data transfer permissions.

[0151] Furthermore, during the process of the secure ferry intermediate layer filtering the received data shards through the hardware filtering engine, the following filtering methods can be adopted:

[0152] a. FPGA (Field Programmable Gate Array) realizes regular expression matching (such as filtering SQL (Structured Query Language) injection statements) and AI model inference (sensitive image recognition), with a processing speed of 10 Gbps.

[0153] b. Regular expression engine: supports more than 2000 rules (such as SQL injection, XSS (Cross-Site Scripting) attack characteristics), adopts NFA (Nondeterministic Finite Automaton) parallel matching, and the processing speed ≥ 10 Gbps.

[0154] c. AI model inference engine: deploys a lightweight CNN (Convolutional Neural Network) model (for example, a compressed version of ResNet-18) for image sensitive content recognition (such as screenshots of classified documents), with an inference latency < 2 ms.

[0155] For the convenience of those skilled in the art to understand, Figure 3 a system framework diagram of a cross-domain secure data interaction system based on dynamic multi-channels and intelligent verification is provided. The descriptions of the core modules in this system framework diagram are shown in Table 2 as follows:

[0156] Table 2 Descriptions of the core modules of the system

[0157]

[0158] Furthermore, Figure 4 a network topology diagram of a cross-domain secure data interaction system based on dynamic multi-channels and intelligent verification is provided. The descriptions of the core modules of this network topology diagram are shown in Table 3 as follows:

[0159] Table 3 Descriptions of the core modules of the system

[0160]

[0161] In an application embodiment, taking the scenarios of financial high-frequency trading and securities market quotation synchronization as examples:

[0162] Requirement:

[0163] The cross-exchange order data synchronization delay ≤ 3ms, and the packet loss rate < 0.001%.

[0164] Implementation process:

[0165] a. The external network market data (100,000 pieces per second) is compressed by the edge node (LZ4 compression rate 65%) and sliced into 1KB data blocks.

[0166] b. The dynamic scheduler selects 5G dedicated line (main transmission channel) and SD-WAN (backup transmission channel), and the allocation ratio is 8:2.

[0167] c. The secure ferry layer filters illegal fields (such as abnormal price values), and the FPGA processing delay is 0.1ms.

[0168] d. The internal network aggregation node repairs 0.005% of the packet loss through FEC, and the Merkle tree verification takes 0.3ms.

[0169] Expected result:

[0170] The end-to-end delay is 2.8ms, and the data integrity rate is 99.9995%.

[0171] In another application embodiment, taking the cross-network approval, image, and file transfer (full-scenario) scenarios as an example:

[0172] Requirement:

[0173] 1. Security: The declaration materials contain sensitive information, and it is necessary to ensure anti-theft and anti-tampering during the transmission process, meeting the requirements of Class III information security protection;

[0174] 2. Real-time performance: The approval process needs to synchronize the status across the network (such as pre-approval passed → internal network review → result feedback), and the end-to-end delay ≤ 500ms;

[0175] 3. Compliance: The data needs to be automatically desensitized, and the logs need to be fully audited.

[0176] Implementation process:

[0177] 1. External network declaration end:

[0178] Users submit application materials through the platform for the external network declaration end to obtain the original data to be transmitted, and the edge preprocessing node performs the following operations:

[0179] Format standardization: Convert unstructured files into a unified format, reducing the volume by 30%;

[0180] Sensitive field identification: Extract keyword fields through an NLP (Natural Language Processing) model and perform partial desensitization;

[0181] Intelligent sharding: Shard by 1KB, and attach a desensitization mark and digital watermark to each shard (to prevent screenshot leakage).

[0182] 2. Dynamic channel transmission:

[0183] The dynamic scheduler selects the optimal channel combination according to the external network load status (such as peak morning hours):

[0184] Main transmission channel: External network dedicated line (bandwidth guaranteed at 100Mbps), carrying 90% of the shards;

[0185] Standby transmission channel: 5G-VPN slice (with QoS (Quality of Service) priority), carrying the remaining 10% of the shards;

[0186] Enable FEC redundancy (redundancy rate of 10%) to prevent the approval process from being interrupted due to network jitter.

[0187] 3. Secure ferry middle layer:

[0188] Hardware filtering engine:

[0189] The FPGA implements secondary verification of sensitive content, and the rules include:

[0190] Prohibit the transmission of documents containing the words "confidential" or "top secret";

[0191] Intercept un-desensitized complete sensitive data.

[0192] The AI model detects whether the scanned document has been tampered with by PS (based on GAN (Generative Adversarial Networks) anomaly detection), with an accuracy rate ≥ 99%.

[0193] Dynamic token authentication:

[0194] Generate a one-time token (SM9 algorithm) for each declaration, bind the user IP + device fingerprint, and the validity period is a single session (≤ 5 minutes).

[0195] 4. Intranet approval terminal:

[0196] Execute at the edge aggregation node:

[0197] Data recombination: Based on the Merkle tree, quickly verify the integrity of the shards, and abnormal shards trigger retransmission within seconds;

[0198] Log chain - up: Approval operation records (such as "Initial review passed", "Rejected for modification") are written into the consortium chain, and the nodes include approval units at all levels.

[0199] Result feedback: The approval result is returned to the external network through a reverse optical gate (only allowing HTTP 200 responses), with a delay ≤ 300 ms.

[0200] Expected result:

[0201] Automatically desensitize sensitive fields through the ferry layer to meet the compliance requirements of Class - III information security protection.

[0202] Technical index verification:

[0203] 1. Security compliance:

[0204] The desensitization rate of sensitive fields is 100%, and the interception of unauthorized file transfers is ≥ 99.9 times / day;

[0205] Pass the Class - III information security protection certification and meet the security specifications.

[0206] 2. Performance:

[0207] End - to - end delay: Material upload (200 ms) + Approval status feedback (150 ms) = 350 ms;

[0208] Peak throughput: Support 1000 concurrent declarations (10 MB materials per user), with a total bandwidth occupancy ≤ 800 Mbps.

[0209] 3. Audit and traceability:

[0210] The blockchain evidence preservation includes shard hashes, approval operations, and timestamps, supporting the accurate restoration of the transmission process during auditing.

[0211] Performance indicators:

[0212] The transmission delay is reduced by 50 - 80% (compared with the traditional network gate solution), and the minimum can reach the 1 - ms level;

[0213] The bandwidth utilization rate ≥ 95%, and the effective throughput after multi - channel aggregation is increased by 3 - 5 times;

[0214] The automatic repair rate of shard loss ≥ 99.9%, and the data integrity rate ≥ 99.999%.

[0215] End - to - end delay: Material upload (200 ms)+Approval status feedback (150 ms) = 350 ms;

[0216] Peak throughput: Support 1000 concurrent declarations (10 MB materials per user), with a total bandwidth occupancy ≤ 800 Mbps.

[0217] Security indicators:

[0218] Resist common attacks such as SQL injection / XSS (interception rate 100%);

[0219] Support the compliance requirements of Class III / IV information security protection, meet security specifications. The risk of key leakage is reduced by 90%;

[0220] Blockchain evidence preservation ensures non-repudiation of operations, and the audit traceability granularity reaches the shard level;

[0221] The desensitization rate of sensitive fields is 100%, and unauthorized file transfers are intercepted ≥99.9 times / day.

[0222] Audit traceability:

[0223] Blockchain evidence preservation includes shard hashes, approval operations, and timestamps, supporting accurate restoration of the transmission process during audits.

[0224] Scalability:

[0225] Edge nodes support horizontal scaling, and a single cluster can handle millions of concurrent connections;

[0226] The SDN architecture supports flexible access to new transmission protocols.

[0227] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.

[0228] Based on the same inventive concept, the embodiments of the present application also provide a cross-network domain secure data interaction device based on dynamic multi-channel and intelligent verification for implementing the above-mentioned cross-network domain secure data interaction method based on dynamic multi-channel and intelligent verification. The implementation solutions provided by this device to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the cross-network domain secure data interaction device based on dynamic multi-channel and intelligent verification provided below can refer to the limitations on the cross-network domain secure data interaction method based on dynamic multi-channel and intelligent verification in the above text, and will not be repeated here.

[0229] In an exemplary embodiment, as Figure 5As shown, a cross-network domain secure data interaction device based on dynamic multi-channels and intelligent verification is provided, which is applied to the external network domain and includes: an acquisition module 510, a determination module 520, an allocation module 530, and a transmission module 540, where:

[0230] The acquisition module 510 is used to acquire the network status data of each available transmission channel between the internal and external networks.

[0231] The determination module 520 is used to determine the transmission priority scores of each of the available transmission channels according to the network status data of each of the available transmission channels, so as to screen out the main transmission channel and the backup transmission channel.

[0232] The allocation module 530 is used to dynamically allocate the data slices to be transmitted to the main transmission channel and the backup transmission channel through a reinforcement learning algorithm; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay.

[0233] The transmission module 540 is used to transmit the data slices allocated to the main transmission channel and the backup transmission channel to the isolation domain;

[0234] Among them, the isolation domain is used to filter the received data slices through a hardware filtering engine and send the filtered data slices to the internal network domain; the internal network domain is used to verify the integrity of the received data slices according to the slice hash values corresponding to the received data slices.

[0235] In one embodiment, there are multiple pieces of the network status data. The determination module 520 is specifically configured to, for any available transmission channel, acquire the weight information corresponding to each of the network status data of the any available transmission channel; adjust each of the network status data according to the weight information corresponding to each of the network status data to obtain each adjusted network status data; acquire the sum among each of the adjusted network status data to obtain the transmission priority score of the any available transmission channel.

[0236] In one embodiment, the weight information includes a weight coefficient. The network status data includes the currently measured bandwidth, the data packet loss rate, and the network delay. The determination module 520 is specifically configured to acquire the product of the first ratio and the weight coefficient corresponding to the currently measured bandwidth to obtain the adjusted currently measured bandwidth; the first ratio is the ratio between the currently measured bandwidth and the theoretical maximum bandwidth of the any available transmission channel; acquire the product of the target difference and the weight coefficient corresponding to the data packet loss rate to obtain the adjusted data packet loss rate; the target difference is the difference between 1 and the data packet loss rate; acquire the product of the second ratio and the weight coefficient corresponding to the network delay to obtain the adjusted network delay; the second ratio is the ratio between 1 and the network delay.

[0237] In one embodiment, the allocation module 530 is specifically configured to encode the data shards allocated to the main transmission channel through forward error correction coding technology to generate redundant data shards; superimpose the redundant data shards on the main transmission channel, and transmit the data shards of the main transmission channel and the standby transmission channel to the isolation domain.

[0238] In one embodiment, the device further includes a preprocessing module, configured to obtain the original data to be transmitted to the intranet domain; compress the original data to obtain compressed data; perform sharding processing on the compressed data to obtain the data shards to be transmitted, and attach a lightweight blockchain-style hash chain to the data shards to be transmitted.

[0239] Each module in the above cross-network domain secure data interaction device based on dynamic multi-channel and intelligent verification can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0240] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 6 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through the system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data shard data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a cross-network domain secure data interaction method based on dynamic multi-channel and intelligent verification.

[0241] Those skilled in the art can understand, Figure 6The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0242] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0243] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0244] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0245] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0246] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0247] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in the present application.

[0248] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A cross-domain secure data interaction method based on dynamic multi-channel and intelligent verification, characterized in that: Applied to an external network domain, the method includes: Obtain network status data of each available transmission channel between the internal and external networks; Determine the transmission priority score of each of the available transmission channels according to the network status data of each of the available transmission channels, so as to screen out a main transmission channel and a backup transmission channel; The data fragments to be transmitted are dynamically allocated to the primary transmission channel and the backup transmission channel by a reinforcement learning algorithm; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay; Transmitting the data slices allocated to the primary transmission channel and the backup transmission channel to the isolation domain; Among them, the isolation domain is used to filter the received data fragments through the hardware filtering engine, and send the filtered data fragments to the intranet domain; the intranet domain is used to verify the integrity of the received data fragments according to the fragment hash values ​​corresponding to the received data fragments.

2. The method according to claim 1, characterized in that The network status data has a plurality of items, and according to the network status data of each of the available transmission channels, a transmission priority score of each of the available transmission channels is determined to screen out a main transmission channel and a backup transmission channel, including: For any available transmission channel, obtaining weight information corresponding to each of the network status data of the any available transmission channel; According to the weight information corresponding to each of the network status data, each of the network status data is adjusted to obtain each adjusted network status data; The sum of the adjusted network status data is obtained to obtain a transmission priority score of any available transmission channel.

3. The method according to claim 2, characterized in that The weight information includes a weight coefficient, the network status data includes a currently measured bandwidth, a data packet loss rate, and a network delay, and the network status data are adjusted according to the weight information corresponding to each of the network status data to obtain each adjusted network status data, including: Obtaining the product of the first ratio and the weight coefficient corresponding to the current measured bandwidth to obtain the adjusted current measured bandwidth; the first ratio is the ratio between the current measured bandwidth and the theoretical maximum bandwidth of any available transmission channel; Obtaining the product of the target difference and the weight coefficient corresponding to the data packet loss rate to obtain the adjusted data packet loss rate; the target difference is the difference between 1 and the data packet loss rate; Obtain the product of a second ratio and a weight coefficient corresponding to the network delay to obtain an adjusted network delay; the second ratio is a ratio between 1 and the network delay.

4. The method according to claim 1, characterized in that The step of transmitting the data slices allocated to the primary transmission channel and the backup transmission channel to the isolation domain includes: The data slices allocated to the main transmission channel are encoded by forward error correction coding technology to generate redundant data slices; The redundant data slices are superimposed on the main transmission channel, and the data slices of the main transmission channel and the backup transmission channel are transmitted to the isolation domain.

5. The method according to claim 1, characterized in that The method further comprises: Acquiring original data to be transmitted to the intranet domain; Compressing the original data to obtain compressed data; The compressed data is sliced ​​to obtain the data slices to be transmitted, and a lightweight blockchain-style hash chain is attached to the data slices to be transmitted.

6. A cross-domain secure data interaction system based on dynamic multi-channel and intelligent verification, characterized in that: The system includes: a dynamic channel scheduler deployed in the external network domain, a secure ferry middle layer deployed in the isolation domain, and a shard-level verification engine deployed in the internal network domain; The dynamic channel scheduler is used to obtain network status data of each available transmission channel between the internal and external networks; The dynamic channel scheduler is used to determine the transmission priority score of each of the available transmission channels according to the network status data of each of the available transmission channels, so as to screen out the main transmission channel and the backup transmission channel; The dynamic channel scheduler is used to dynamically allocate the data fragments to be transmitted to the main transmission channel and the backup transmission channel through a reinforcement learning algorithm; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay; The dynamic channel scheduler is used to transmit the data slices allocated to the main transmission channel and the backup transmission channel to the isolation domain; The secure ferrying middle layer is used to filter the received data fragments through the hardware filtering engine and send the filtered data fragments to the intranet domain; The shard-level verification engine is used to verify the integrity of the received data shards based on the shard hash values ​​corresponding to the received data shards.

7. A cross-domain secure data interaction device based on dynamic multi-channel and intelligent verification, characterized in that: Applied to an external network domain, the device comprises: An acquisition module is used to obtain network status data of each available transmission channel between the internal and external networks; A determination module, configured to determine a transmission priority score of each of the available transmission channels according to the network status data of each of the available transmission channels, so as to screen out a main transmission channel and a backup transmission channel; An allocation module, configured to dynamically allocate the data fragments to be transmitted to the primary transmission channel and the backup transmission channel by using a reinforcement learning algorithm; the optimization goal of the reinforcement learning algorithm is to minimize the overall transmission delay; A transmission module, used for transmitting the data slices allocated to the primary transmission channel and the backup transmission channel to the isolation domain; Among them, the isolation domain is used to filter the received data fragments through the hardware filtering engine, and send the filtered data fragments to the intranet domain; the intranet domain is used to verify the integrity of the received data fragments according to the fragment hash values ​​corresponding to the received data fragments.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Cited By

  • Computer remote control method and system

    CN120750641A

  • Large model agent unified security agent method and system based on zero-trust architecture

    CN122160184A

  • A Unified Security Agent Method and System for Large-Scale Intelligent Agents Based on Zero-Trust Architecture

    CN122160184B