A data transmission system and method based on security authentication and control

By using an IP-free firewall unit to perform random feature sampling and security level assessment before data transmission in an IoT environment, the problems of low data transmission efficiency and high hardware cost in existing technologies are solved, achieving efficient and secure data transmission.

CN120342755BActive Publication Date: 2025-11-25SYM TECH (GUANGDONG) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510675201.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-11-25
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

Existing technologies cannot effectively perform security authentication before data transmission in the Internet of Things (IoT) environment, resulting in low data transmission efficiency and the inability to match the optimal transmission channel for different devices and data attributes. Furthermore, traditional firewall mechanisms in the IoE environment suffer from high hardware costs, high latency, and inability to be updated in real time.

Method used

By employing an IP-free firewall unit to establish a pre-communication link with the data sender before data transmission, determining the data interaction channel through random feature sampling, and matching different communication protocols and transmission channels according to the security level, data security authentication is moved forward.

Benefits of technology

It improves data transmission efficiency, reduces hardware costs, ensures real-time performance and security, adapts to diverse devices and data attributes in the IoE environment, and avoids the shortcomings of traditional firewall mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342755B_ABST
    Figure CN120342755B_ABST
Patent Text Reader

Abstract

The application provides a data transmission system and method based on security authentication and control, and belongs to the technical field of data security authentication and control. The system comprises a data sending end and a data receiving end. When the data receiving end receives a data sending request, a non-IP firewall unit is started to establish a pre-communication link with the data sending end. The non-IP firewall unit sends a random sampling instruction to the data sending end. Based on the data sample features obtained by random feature sampling, the non-IP firewall unit determines the current data interaction channel of the data receiving end and the data sending end. Based on the current data interaction channel, the data sending end transmits data to the data receiving end. The application also provides a centralized management mode of distributed security access control. The application is based on centralized management of a management center, and further moves the data security authentication to before the start of data transmission. Different transmission channels are matched according to different security authentication results, so that the data transmission efficiency can be improved under the condition of ensuring the terminal security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security authentication and control technology, and particularly relates to a data transmission system and method based on security authentication and control, a computer-readable storage medium for implementing the method, a computer program product, and an electronic device. Background Technology

[0002] With the rapid popularization of the Internet of Things (IoT), the concept of the Internet of Everything (IoE) has been proposed. IoE connects various devices to the network through various communication technologies such as Wi-Fi, Bluetooth, Zigbee, and 5G; it collects and processes data from the physical world using sensors and actuators, enabling remote control of devices; and it utilizes cloud computing and edge computing technologies to store and analyze massive amounts of data, providing support for decision-making. While the Internet of Everything improves the efficiency of production and daily life, creating new business models and employment opportunities, it also brings challenges such as data security and privacy protection, device compatibility, and interoperability.

[0003] Most current IoT security measures are implemented through software, such as setting up software firewalls and encrypted transmission over dedicated lines. To address this, the Chinese authorized invention patent "A Distributed Information Network Security Protection Method, System and its Readable Storage Medium" (authorization announcement number CN116566682B) transfers security rules from other non-IP hardware firewalls to the current non-IP hardware firewall based on pre-configured network architecture, enabling it to provide temporary security protection.

[0004] However, the relevant technologies can only begin security authentication and analysis when the data actually arrives, impacting data transmission efficiency as the data stream continues to be generated. Furthermore, in an IoE environment, device types and data attributes vary widely, requiring different data transmission protocols and security control levels. The firewall technologies employed can only screen for potential risks; when no risk exists or the risk level differs, they fail to match the optimal data transmission channel, further reducing data transmission efficiency. Additionally, when multiple execution units (including data transmission devices and firewall units) exist, how to centrally configure and control different secure access policies is also a technical problem that needs to be solved. Summary of the Invention

[0005] To address the aforementioned technical problems, this invention proposes a data transmission system and method based on security authentication and control in an IoE environment, a computer-readable storage medium for implementing the method, a computer program product, and an electronic device.

[0006] In a first aspect of the invention, a data transmission system based on security authentication and control is proposed, the system comprising at least one data transmitter and at least one data receiver;

[0007] The data receiving end is configured with an IP-free firewall unit;

[0008] When the data receiving end receives a data sending request, the IP-free firewall unit is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end;

[0009] The IP-free firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link. The sampling instruction is used to randomly sample features of the dataset to be sent by the data sending end.

[0010] Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiver and the data sender.

[0011] Based on the current data interaction channel, the data sending end transmits data to the data receiving end.

[0012] The data sample features include first data sample features and second data sample features;

[0013] The first data sample features are obtained by the data sending end through random feature sampling of the dataset to be sent based on the sampling instruction;

[0014] The second data sample features are obtained by the IP-free firewall unit through random feature sampling of the dataset to be sent based on the sampling instruction.

[0015] In practical applications, this invention can also be centrally managed through a management center and communicated using physical network ports.

[0016] Therefore, the data transmission system based on security authentication and control described in the first aspect can also be implemented based on a distributed terminal firewall framework, the system including an execution unit group and a management center group;

[0017] The execution unit group includes multiple execution units, and each execution unit includes a networking and deployment module and an access control module;

[0018] The management center group includes a security operation and maintenance management module, a status monitoring management module, and a policy configuration management module;

[0019] The security operation and maintenance management module includes a traffic log unit, a traffic statistics unit, a traffic analysis unit, an alarm handling unit, and a report unit;

[0020] The status monitoring and management module includes a central operation status unit, an execution unit deployment status unit, an execution unit operation status unit, a terminal connection status management unit, and a terminal IP / MAC management unit.

[0021] The policy configuration management module includes a policy management unit, a remote management unit, a batch management unit, a distribution management unit, and a dynamic port opening unit;

[0022] In practical applications, each protected terminal device (including data sender / receiver) is connected to the physical port of the switch device through each corresponding execution unit under the distributed terminal firewall framework. It is then centrally managed by the management center based on the distributed terminal firewall framework, and the testing process is recorded at the same time.

[0023] In a second aspect of the invention, a data transmission method based on security authentication and control is proposed, the method being applied to at least one data receiving end, the method comprising the following steps:

[0024] When a data transmission request is received, the IP-free firewall unit of the data receiving end is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end.

[0025] The IP-free firewall unit sends a sampling instruction to the data sending end based on the pre-communication link. The sampling instruction is used to perform random feature sampling on the dataset to be sent by the data sending end.

[0026] Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiver and the data sender.

[0027] Based on the current data interaction channel, the data sending end transmits data to the data receiving end.

[0028] During the process of the data sending end transmitting data to the data receiving end based on the current data interaction channel, the IP-free firewall unit continuously sends sampling instructions to the data sending end based on the pre-communication link in order to continuously perform random feature sampling on the dataset to be sent by the data sending end.

[0029] Based on the data sample features obtained through continuous random feature sampling, the IP-free firewall unit determines whether the data receiver and the data sender maintain the current data interaction channel or change the current data interaction channel.

[0030] The IP-free firewall unit is pre-configured with multiple data interaction channels, each corresponding to a different security assessment level and communication protocol.

[0031] The IP-free firewall unit, based on the data sample characteristics obtained by the random feature sampling, evaluates the security level and applicable communication protocol of the dataset to be sent by the data sender, and then determines the current data interaction channel between the data receiver and the data sender.

[0032] The IP-free firewall unit is a detachable IP-free hardware firewall unit.

[0033] In a third aspect of the present invention, a data transmission method based on security authentication and control in an IoE environment is proposed. The method is applied to at least one data sending end and includes the following steps:

[0034] Identify at least one data receiving end and send a data transmission request to the data receiving end;

[0035] Random feature sampling is performed on the first dataset to be sent, and the features of the first data sample obtained by random feature sampling are sent to the data receiving end;

[0036] Based on the data interaction channel invoked by the data receiving end, the first dataset to be sent is transmitted to the data receiving end;

[0037] Furthermore, while transmitting the first dataset to be sent, a second dataset to be sent is prepared.

[0038] The method further includes:

[0039] After sending a data transmission request to the data receiving end, the data receiving end establishes a pre-communication link with the data sending end. Based on the pre-communication link, the data receiving end sends the random feature sampling instruction to the data sending end. The random feature sampling instruction is used to instruct the data sending end to perform random feature sampling on the first dataset to be sent.

[0040] After sending a data transmission request to the data receiving end, the data receiving end establishes a pre-communication link with the data sending end. Based on the pre-communication link, the data receiving end performs random feature sampling on the first dataset to be sent to obtain the features of the second data sample.

[0041] The data receiving end determines the data interaction channel invoked by the data receiving end based on the features of the first data sample and the features of the second data sample.

[0042] In a fourth aspect of the invention, a computer-readable storage medium is also provided for storing computer instructions that, when executed on an electronic device, cause the electronic device to perform all or part of the steps of the aforementioned data transmission method based on security authentication and control.

[0043] In a fifth aspect of the invention, a computer device is also provided, the computer device including a processor and a memory, the memory for storing instructions, and the processor for calling the instructions in the memory to cause the computer device to execute the aforementioned data transmission method based on security authentication and control.

[0044] In a sixth aspect of the invention, a computer program product is also provided, the product comprising a computer program, which, when executed, implements all or part of the steps of the aforementioned data transmission method based on security authentication and control.

[0045] In the technical solution of this invention, when the data receiving end receives a data transmission request in an IoE environment, it activates the IP-free firewall unit, enabling the IP-free firewall unit to establish a pre-communication link with the data sending end. The IP-free firewall unit sends a random sampling command to the data sending end based on the pre-communication link. Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end. Based on the current data interaction channel, the data sending end transmits data to the data receiving end. This invention moves data security authentication to before data transmission begins and matches different transmission channels for different security authentication results, thereby improving data transmission efficiency while ensuring terminal security.

[0046] Further advantages of the present invention will be further detailed in the Specific Embodiments section in conjunction with the accompanying drawings. Attached Figure Description

[0047] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 This is a scenario architecture diagram of a data transmission system based on security authentication and control according to an embodiment of the present invention;

[0049] Figure 2 This is a schematic diagram of the main flow of a data transmission method based on security authentication and control according to an embodiment of the present invention;

[0050] Figure 3 This is a schematic diagram of the main flow of a data transmission method based on security authentication and control according to another preferred embodiment of the present invention;

[0051] Figure 4This is a schematic diagram illustrating the principle of determining the current data interaction channel between the data receiving end and the data sending end in an embodiment of the method of the present invention;

[0052] Figure 5 This is a schematic diagram of a product embodiment based on the technical solution of the present invention, which is centrally managed by a management center and communicates using a physical network port. Detailed Implementation

[0053] In the specific embodiments of this application, if the embodiments of the relevant technical solutions involve user-related data, then when the embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0054] See Figure 1 , Figure 1 This is a scenario architecture diagram of a data transmission system based on security authentication and control, according to an embodiment of the present invention.

[0055] exist Figure 1 The diagram shows multiple data receivers, multiple data senders, and multiple IP-free firewall unit modules.

[0056] It's understandable that the concepts of data receiver and data sender are relative; a data receiver can also be a data sender. In practical applications, especially in an IoT environment, a data receiver and data sender can be any IoT device capable of generating data and having the ability to send and receive data.

[0057] For a given IoT device, when it generates data and needs to send it out, it is called a "data sender"; and when it prepares to receive data from another IoT device, it transforms into a "data receiver." Of course, for an IoT device, "receiving data" and "sending data" can occur sequentially or simultaneously. This invention focuses on the data transmission process between a "data sender" and a "data receiver."

[0058] In various embodiments of the present invention, "data," "information," and "message" can all serve as transmission objects between a "data sender" and a "data receiver," and their types include any combination of plain text, hyperlinks, images, voice, video, operation instructions, etc. For ease of description, they are all referred to as "data."

[0059] exist Figure 1In this embodiment, each IoT device can be configured with a detachable (pluggable) and readily switchable (activated / dormant) IP-free firewall unit module. Preferably, the IP-free firewall unit is a detachable IP-free hardware firewall unit.

[0060] When an IoT device acts as a data receiver, its corresponding IP-free firewall module is enabled; when it acts as a data sender, its corresponding IP-free firewall module is disabled (removed or put into hibernation) to achieve energy saving.

[0061] When the data receiving end receives a data sending request, the IP-free firewall unit is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end;

[0062] The IP-free firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link. The sampling instruction is used to randomly sample features of the dataset to be sent by the data sending end.

[0063] Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiver and the data sender.

[0064] Based on the current data interaction channel, the data sending end transmits data to the data receiving end.

[0065] As can be seen, this invention moves data security authentication to before data transmission begins. Specifically, when the data receiving end receives a data transmission request, it first activates the IP-free firewall unit, enabling the IP-free firewall unit to establish a pre-communication link with the data sending end;

[0066] The establishment of a "pre-communication link" is not for transmitting actual data. At this point, for the data receiving end, since the security attributes of the data to be received are unclear, directly opening the receiving channel poses a certain system risk.

[0067] In existing technologies, a firewall or filtering module is typically used as a front-end to process and intercept incoming data before accepting or rejecting it, depending on the situation. This can achieve a certain level of security in typical data transmission processes.

[0068] However, in the IoT scenario, a large number of IoT devices connect to the network via different protocols or interfaces, including Wi-Fi, Bluetooth, Zigbee, 5G, and infrared. By collecting data from multiple sources, near-field or remote control of devices and data visualization analysis are achieved. The data generated, in most scenarios, targets physically meaningful objects (any combination of plain text, hyperlinks, images, voice, video, and operation commands). These objects exhibit very obvious and regular characteristics (e.g., temporal characteristics, periodic characteristics, and data range variation characteristics). Operation commands, such as remote control operations and near-field communication operations, also have corresponding characteristics, and these commands are pre-configured. The large number of IoT devices connected to the network themselves constitute a security mesh. Data transmission and reception should be continuous and uninterrupted for most of the time.

[0069] In this scenario, the main risks to data transmission come from sudden network attacks, such as abnormal traffic injection, data attacks from remote off-grid devices, and disturbances from abnormal near-field devices. If a security control mechanism is still used, where incoming data is first processed and intercepted by the firewall or filter before being accepted or rejected as appropriate, the negative impacts include:

[0070] (1) Interruption of normal IoE data transmission and transmission causes a large delay in the control of grid devices within the IoT area, which is unacceptable in some application scenarios that require real-time performance or have low latency tolerance.

[0071] (2) Traditional firewall mechanisms may fail in response to risk characteristics such as “abnormal traffic injection, data attacks from remote off-grid devices, and disturbances from near-field abnormal devices”, while the filtering rules of the filtering module need to be pre-configured and cannot be updated in real time.

[0072] (3) An additional intermediate storage medium is required to temporarily receive the data to be filtered. For simple one-to-one transmission, the increased hardware cost is acceptable (can be denoted as O(1)); however, for N IoT devices in an IoE scenario, the increased hardware cost will increase dramatically (i.e., ...).

[0073] (4) Traditional firewalls and filtering mechanisms generally perform uniform filtering after discovering risk characteristics, without providing different levels of processing channels for different situations.

[0074] To address the above problems, the technical solution of the present invention is to first activate the IP-free firewall unit, thereby establishing a pre-communication link between the IP-free firewall unit and the data sending end. Then, the IP-free firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link. The sampling instruction is used to perform random feature sampling on the dataset to be sent by the data sending end.

[0075] As mentioned earlier, in the IoE scenario, the risks to data transmission mainly come from sudden network attacks, such as abnormal traffic injection, data attacks from remote off-grid devices, and disturbances from near-field abnormal devices. Although these risks are unpredictable, their characteristics are inevitably hidden in the dataset to be sent, and the location of this hiding place is random. Furthermore, unlike existing technologies that generate, send, and detect data simultaneously, in this embodiment of the invention, the data sender must determine at least one data receiver only after the dataset to be sent is ready, and then send a data transmission request to the data receiver. This data transmission request carries information such as the size of the dataset to be sent, its generation time (time range), data format, and data storage location.

[0076] At this point, the dataset to be sent is set to an unmodifiable (read-only) state. Therefore, if risk feature injection occurs, it can only happen during the data generation stage and is unavoidable (because the risk feature has already been integrated with the dataset itself into an unmodifiable read-only state).

[0077] In order to detect whether the dataset to be sent has risky characteristics, based on the randomness of its injection, the IP-free firewall unit sends a random sampling instruction to the data sender through the pre-communication link. The sampling instruction is used to randomly sample the features of the dataset to be sent by the data sender.

[0078] Specifically, the random sampling instruction is implemented based on a random sampling function. The random sampling function determines multiple sampling positions and sampling ranges based on information such as the size of the dataset to be sent, the generation time (time range), the data format, and the data storage location, thereby obtaining multiple data sample features.

[0079] Data sample characteristics include the completeness of the sampled data, the continuity of data between adjacent sampling points, and the size of the sampled unit data, etc.; they may also include the characteristics of abnormal risk points obtained from sampling, such as using regular expressions to match risk keywords, warning codes, alarm data formats, etc. from the sampling range.

[0080] Of course, different sampling functions can obtain different sampling characteristics, and those skilled in the art can pre-set different sampling functions based on different data to be transmitted.

[0081] Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit can assess the security level of the dataset to be sent by the data sender and the applicable communication protocol.

[0082] Preferably, the IP-free firewall unit is pre-configured with multiple data interaction channels, each corresponding to a different security assessment level and communication protocol.

[0083] For example, security levels can be pre-defined as low, medium, and high, or quantified into levels 0-5. Applicable communication protocols include synchronous / asynchronous communication protocols, hyperlink text communication protocols, publish-subscribe protocols, application-layer open-source protocols, and full-duplex communication protocols.

[0084] Taking low, medium, and high as examples, when no risk features are found in the data sample features obtained based on the random feature sampling, such as multiple sample data being complete and continuous, and not matching risk keywords, warning codes, alarm data formats, etc., the security level of the dataset to be sent by the data sending end is evaluated as low.

[0085] When, based on the features of the data samples obtained by the random feature sampling, it is found that multiple sampled data are complete and continuous, but risk keywords, warning codes, alarm data formats, etc. are matched in some positions, the security level of the dataset to be sent by the data sending end is assessed as medium.

[0086] When the data sample features obtained based on the random feature sampling are found to be incomplete or discontinuous (meaning that injections exist at multiple different locations), the security level of the dataset to be sent by the data sending end is assessed as high.

[0087] When the security level is low, depending on the device type of the data sender and the data generation method, you can choose application layer open source protocols, full-duplex communication protocols, etc.

[0088] Preferably, the application layer open-source protocol can be AMQP, which ensures fast and latency-free data transmission; the full-duplex communication protocol can be a WebSocket-based protocol, enabling full-duplex communication over a single TCP connection, overcoming the limitations of HTTP's stateless and unidirectional communication. It performs exceptionally well in real-time interactive scenarios.

[0089] When the security level is low, if the HTTP state is stable, you can also choose asynchronous communication protocols, hyperlink text communication protocols, etc.

[0090] When the security level is medium, a synchronous communication protocol is preferred. In this case, the data to be transmitted itself carries a certain risk. Therefore, using a synchronous communication protocol ensures that after a subset of data segments without security risks is successfully sent and receives an acknowledgment response from the receiving end, the next subset of data segments can be sent. This synchronous response method ensures continuous data transmission as much as possible, while also enabling the timely identification and rejection of data segments with security risks (excluding them from the data transmission process).

[0091] When the security level is high, a publish-subscribe protocol such as MQTT is preferred. For example, communication between smart home devices, such as smart light bulbs and sensors, can use the MQTT protocol to transmit data.

[0092] Under the "publish-subscribe" protocol, the publisher is responsible for publishing (producing, sending) data, and the consumer is responsible for consuming (receiving) data. The consumer pre-registers the types of message data it is interested in and only responds to message data of these registered types.

[0093] By using a publish-subscribe protocol, even if the data to be sent is risky, these risky instructions are not registered (subscribed) by the subscriber (consumer) implementation. Therefore, the relevant instructions will not be executed and will not affect the security of the system or device. As for normal instructions, since they are pre-registered, they can also be executed normally without interrupting the normal transmission of the data stream.

[0094] Once the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end, the data sending end can transmit data to the data receiving end based on the current data interaction channel.

[0095] In other words, this invention not only moves data security authentication to before data transmission begins, but also matches different transmission channels for different security authentication results, which can improve data transmission efficiency while ensuring terminal security.

[0096] Furthermore, the data sample characteristics obtained by random feature sampling on which the above security assessment is based can be obtained by either the data sending end or the data receiving end.

[0097] Preferably, in order to avoid "pseudo-random" sampling in the event of data receiver hijacking, the random sampling process is jointly executed by the data sender and the data receiver to achieve random supervision.

[0098] Specifically, the data sample features include first data sample features and second data sample features;

[0099] The first data sample features are obtained by the data sending end through random feature sampling of the dataset to be sent based on the sampling instruction;

[0100] The second data sample features are obtained by the IP-free firewall unit through random feature sampling of the dataset to be sent based on the sampling instruction.

[0101] At this time, the IP-free firewall unit evaluates the first security level and applicable first communication protocol of the dataset to be sent by the data sender based on the first data sample characteristics; at the same time, it evaluates the second security level and applicable second communication protocol of the dataset to be sent by the data sender based on the second data sample characteristics.

[0102] When there is a contradiction (inconsistency) between the first security level and the applicable first communication protocol, the second security level and the applicable second communication protocol are used, and the current data interaction channel between the data receiving end and the data sending end is determined.

[0103] In practical applications, this invention can also be centrally managed through a management center and communicated using physical network ports.

[0104] therefore, Figure 1 The data transmission system based on security authentication and control can also be implemented based on a distributed terminal firewall framework.

[0105] At this point, the system can implement a distributed firewall architecture for execution unit networking configuration policies based on a centralized management mode.

[0106] Specifically, the system also includes an execution unit group and a management center group; the execution unit group includes multiple execution units, and each execution unit includes a networking and deployment module and an access control module;

[0107] The management center group includes a security operation and maintenance management module, a status monitoring management module, and a policy configuration management module;

[0108] The security operation and maintenance management module includes a traffic log unit, a traffic statistics unit, a traffic analysis unit, an alarm handling unit, and a report unit;

[0109] The status monitoring and management module includes a central operation status unit, an execution unit deployment status unit, an execution unit operation status unit, a terminal connection status management unit, and a terminal IP / MAC management unit.

[0110] The policy configuration management module includes a policy management unit, a remote management unit, a batch management unit, a distribution management unit, and a dynamic port opening unit;

[0111] In practical applications, each protected terminal device (including data sender / receiver) is connected to the physical port of the switch device through each corresponding execution unit under the distributed terminal firewall framework. It is then centrally managed by the management center based on the distributed terminal firewall framework, and the test process is recorded. A unified management center can be used to implement the control framework for terminal device protection under the distributed firewall framework with multiple execution units.

[0112] The following section details the basic working principle of the product form resulting from this invention in practical applications.

[0113] In specific deployment, the product formed by the technical solution of this invention is mainly composed of a unified management center that controls multiple distributed IP-free firewall units.

[0114] The management center needs to implement network access control. Execution units need to be networked with the management center to be managed by it, including executing policies and access control policies issued by the management center.

[0115] In a preferred embodiment, the management center can directly communicate with the IP-free execution unit (IP-free hardware firewall unit) and issue deployment instructions. After intercepting the deployment instructions, the execution unit parses out the IP address characteristics of the management center; thus, the execution unit can establish a communication association with the management center based on the IP address characteristics, that is, maintain a direct connection with the management center.

[0116] Typically, the protected terminal devices use DHCP networks, resulting in their IP addresses being constantly changing. Using IP addresses as identifiers makes it impossible to match managed objects.

[0117] Therefore, as another preferred embodiment, when the management center issues relevant deployment policies to the protected terminal devices, it further uses the MAC code of the terminal devices as a feature code to ensure that the management center can determine the identity of the protected terminal devices and thus continue to implement the relevant deployment policies for network access control.

[0118] Implementation examples of network access control-based deployment strategies can effectively protect the security of related protected devices (including data senders / receivers and execution units).

[0119] As a more specific example, in an IoE environment, the protected devices could be smart light poles equipped with cameras and their voice control devices. Under normal data transmission conditions, these protected devices are "unprotected," posing a significant security risk. Based on the centralized management center control embodiment of this invention, the management center can issue corresponding network access control policies to the execution unit to perform secure access control, thereby improving the security of the protected terminal devices.

[0120] Having explained the principles of the system implementation example, the following... Figures 2-5 Different implementations of the method embodiments are introduced.

[0121] Figure 2 The diagram illustrates the main flow of a data transmission method based on security authentication and control according to an embodiment of the present invention.

[0122] Figure 2 The method, described from the perspective of the data receiving end, mainly includes the following steps:

[0123] When a data transmission request is received, the IP-free firewall unit of the data receiving end is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end.

[0124] The IP-free firewall unit sends a sampling instruction to the data sending end based on the pre-communication link. The sampling instruction is used to perform random feature sampling on the dataset to be sent by the data sending end.

[0125] Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiver and the data sender.

[0126] Based on the current data interaction channel, the data sending end transmits data to the data receiving end.

[0127] Preferably, the IP-free firewall unit is pre-configured with multiple data interaction channels, each corresponding to a different security assessment level and communication protocol;

[0128] The IP-free firewall unit, based on the data sample characteristics obtained by the random feature sampling, evaluates the security level and applicable communication protocol of the dataset to be sent by the data sender, and then determines the current data interaction channel between the data receiver and the data sender.

[0129] When the security level is low, depending on the device type of the data sender and the data generation method, you can choose application layer open source protocols, full-duplex communication protocols, etc.

[0130] Preferably, the application layer open-source protocol can be AMQP, which ensures fast and latency-free data transmission; the full-duplex communication protocol can be a WebSocket-based protocol, enabling full-duplex communication over a single TCP connection, overcoming the limitations of HTTP's stateless and unidirectional communication. It performs exceptionally well in real-time interactive scenarios.

[0131] When the security level is low, if the HTTP state is stable, you can also choose asynchronous communication protocols, hyperlink text communication protocols, etc.

[0132] When the security level is medium, a synchronous communication protocol is preferred. In this case, the data to be transmitted itself carries a certain risk. Therefore, using a synchronous communication protocol ensures that after a subset of data segments without security risks is successfully sent and receives an acknowledgment response from the receiving end, the next subset of data segments can be sent. This synchronous response method ensures continuous data transmission as much as possible while also enabling timely identification of data segments with security risks.

[0133] When the security level is high, a publish-subscribe protocol such as MQTT is preferred. For example, communication between smart home devices, such as smart light bulbs and sensors, can use the MQTT protocol to transmit data.

[0134] During the process of the data sending end transmitting data to the data receiving end based on the current data interaction channel, the IP-free firewall unit continuously sends sampling instructions to the data sending end based on the pre-communication link in order to continuously perform random feature sampling on the dataset to be sent by the data sending end.

[0135] Based on the data sample features obtained through continuous random feature sampling, the IP-free firewall unit determines whether the data receiver and the data sender maintain the current data interaction channel or change the current data interaction channel.

[0136] As can be seen, the data sending end can only determine at least one data receiving end after preparing the current dataset to be sent each time, and then send a data transmission request to the data receiving end. The data transmission request carries information such as the size of the dataset to be sent, the generation time (time range), the data format, and the data storage location.

[0137] Then, the data to be transmitted is sent based on the IP-free firewall unit; at the same time, the data sender continues to prepare the next dataset to be sent, repeating the above process.

[0138] Specifically, Figure 3 This diagram illustrates the main flow of a data transmission method based on security authentication and control according to another preferred embodiment of the present invention.

[0139] exist Figure 3Taking the first and second datasets to be sent sequentially as an example, the relevant steps are as follows: Figure 3 (Step numbers omitted)

[0140] S1: The data sender prepares the first dataset to be sent;

[0141] S2: The data sender sends a data transmission request to the data receiver;

[0142] S3: The data receiving end enables the IP-free firewall unit, so that the IP-free firewall unit establishes a pre-communication link with the data sending end;

[0143] S4: The IP-free firewall unit sends a sampling instruction to the data sending end based on the pre-communication link;

[0144] S5: Based on the random sampling instruction, random feature sampling is performed on the first dataset to be sent to obtain data sample features;

[0145] S6: The IP-free firewall unit determines the current data interaction channel between the data receiver and the data sender based on the characteristics of the data sample;

[0146] S7: Based on the current data interaction channel, while the data sending end transmits data to the data receiving end, the data sending end prepares a second dataset to be sent.

[0147] S8: The IP-free firewall unit sends a sampling instruction to the data sending end based on the pre-communication link;

[0148] S9: Based on the random sampling instruction, perform random feature sampling on the second dataset to be sent to obtain data sample features, then proceed to step S6.

[0149] Understandably, the data sending end will continuously generate the first dataset, the second dataset, ..., the Nth dataset. Each time a dataset is generated, its transmission process follows the aforementioned steps; that is, the method can be a cyclical process used to sequentially process and transmit the first dataset, the second dataset, ..., the i-th dataset... The data exchange channel for each dataset needs to be redefined based on the characteristics of the randomly sampled data. The sampling function used for each resampling changes, and the sampling parameters are dynamically updated (for example, the random sampling function determines multiple sampling positions and sampling ranges based on the size of the dataset to be sent, the generation time (time range), the data format, the data storage location, etc.) to avoid "pseudo-random" phenomena.

[0150] Figure 4 This is a schematic diagram illustrating the principle of determining the current data interaction channel between the data receiving end and the data sending end in an embodiment of the method of the present invention.

[0151] The main focus was on further optimizing the sampling process, including the following methods:

[0152] The IP-free firewall unit establishes a pre-communication link with the data sender;

[0153] The IP-free firewall unit sends a sampling command to the data sender based on the pre-communication link;

[0154] The data sending end performs random feature sampling on the dataset to be sent based on the sampling instruction to obtain the first data sample feature; the data receiving end performs random feature sampling on the dataset to be sent based on the sampling instruction to obtain the second data sample feature.

[0155] At this time, the IP-free firewall unit evaluates the first security level and applicable first communication protocol of the dataset to be sent by the data sender based on the first data sample characteristics; at the same time, it evaluates the second security level and applicable second communication protocol of the dataset to be sent by the data sender based on the second data sample characteristics.

[0156] When there is a contradiction (inconsistency) between the first security level and the applicable first communication protocol, the second security level and the applicable second communication protocol are used, and the current data interaction channel between the data receiving end and the data sending end is determined.

[0157] When the method embodiment is described from the perspective of the data sending end, the specific implementation steps include:

[0158] Identify at least one data receiving end and send a data transmission request to the data receiving end;

[0159] Random feature sampling is performed on the first dataset to be sent, and the features of the first data sample obtained by random feature sampling are sent to the data receiving end;

[0160] Based on the data interaction channel invoked by the data receiving end, the first dataset to be sent is transmitted to the data receiving end;

[0161] Furthermore, while transmitting the first dataset to be sent, a second dataset to be sent is prepared.

[0162] After sending a data transmission request to the data receiving end, the data receiving end establishes a pre-communication link with the data sending end. Based on the pre-communication link, the data receiving end sends the random feature sampling instruction to the data sending end. The random feature sampling instruction is used to instruct the data sending end to perform random feature sampling on the first dataset to be sent.

[0163] The data receiving end performs random feature sampling on the first dataset to be sent based on the pre-communication link to obtain the features of the second data sample.

[0164] The data receiving end determines the data interaction channel invoked by the data receiving end based on the features of the first data sample and the features of the second data sample.

[0165] In practical applications, this invention requires centralized management based on a management center and communication via physical network ports. Figure 5 This diagram illustrates a product embodiment based on the technical solution of the present invention, which is centrally managed by a management center and communicates using a physical network port.

[0166] The management center centrally manages the multiple data receiving ends, multiple data sending ends, and multiple IP-free firewall unit modules, and uses physical network ports for related communication.

[0167] As can be seen, the improved technical solution described above has at least the following advantages compared to existing technologies:

[0168] (1) In most data transmission processes, normal IoE data transmission and sending do not need to be interrupted, ensuring real-time performance, minimizing latency, and meeting the application requirements of some low latency tolerance IoE scenarios.

[0169] (2) There is no need to configure an intermediate storage medium, reducing hardware deployment costs;

[0170] (3) By moving data security authentication to before data transmission begins and matching different transmission channels for different security authentication results, data transmission efficiency can be improved while ensuring terminal security.

[0171] (4) Implementation examples of network access control-based deployment strategies can effectively protect the security of related protected devices (including data sender / receiver and execution unit).

[0172] Other technologies, principles, algorithms, or models not elaborated in detail in this application can be found in the prior art.

[0173] In summary, in the technical solution of this invention, when the data receiving end receives a data transmission request, it activates the IP-free firewall unit, enabling the IP-free firewall unit to establish a pre-communication link with the data sending end. The IP-free firewall unit then sends a random sampling command to the data sending end based on the pre-communication link. Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end. Based on the current data interaction channel, the data sending end transmits data to the data receiving end. This invention moves data security authentication to before data transmission begins and matches different transmission channels for different security authentication results, thereby improving data transmission efficiency while ensuring terminal security.

[0174] In the foregoing embodiments section, the present invention provides multiple embodiments, each of which can constitute an independent technical solution and may contribute to the prior art, and solve corresponding technical problems. However, it should be noted that different embodiments can be combined with each other without violating logic; at the same time, each embodiment can solve at least one technical problem, but it is not required that each individual embodiment solve multiple or all technical problems.

[0175] The foregoing has shown and described the method embodiments and systems of the present invention, but it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A data transmission method based on security authentication and control, the method being applied to at least one data receiving end, characterized in that, The method includes the following steps: When a data transmission request is received, the IP-free firewall unit of the data receiving end is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end. The IP-free firewall unit sends a sampling instruction to the data sending end based on the pre-communication link. The sampling instruction is used to perform random feature sampling on the dataset to be sent by the data sending end. The IP-free firewall unit, based on the data sample characteristics obtained by the random feature sampling, evaluates the security level and applicable communication protocol of the dataset to be sent by the data sender, and then determines the current data interaction channel between the data receiver and the data sender. Based on the current data interaction channel, the data sending end transmits data to the data receiving end.

2. The data transmission method based on security authentication and control as described in claim 1, characterized in that, During the process of the data sending end transmitting data to the data receiving end based on the current data interaction channel, the IP-free firewall unit continuously sends sampling instructions to the data sending end based on the pre-communication link in order to continuously perform random feature sampling on the dataset to be sent by the data sending end. Based on the data sample features obtained through continuous random feature sampling, the IP-free firewall unit determines whether the data receiver and the data sender maintain the current data interaction channel or change the current data interaction channel.

3. The data transmission method based on security authentication and control as described in claim 1, characterized in that, The IP-free firewall unit is pre-configured with multiple data interaction channels, each corresponding to a different security assessment level and communication protocol.

4. The data transmission method based on security authentication and control as described in claim 1, characterized in that, The IP-free firewall unit is a detachable IP-free hardware firewall unit.

5. A data transmission method based on security authentication and control, the method being applied to at least one data transmitting end, characterized in that, The method includes the following steps: Identify at least one data receiving end and send a data transmission request to the data receiving end. The data receiving end establishes a pre-communication link with the data sending end. The data receiving end sends a random feature sampling instruction to the data sending end based on the pre-communication link. The random feature sampling instruction is used to instruct the data sending end to perform random feature sampling on the first dataset to be sent to obtain the first data sample features. The first data sample features obtained by random feature sampling are sent to the data receiving end; The data receiving end performs random feature sampling on the first dataset to be sent based on the pre-communication link to obtain the features of the second data sample. The data receiving end determines the data interaction channel to be invoked based on the characteristics of the first data sample and the characteristics of the second data sample. Based on the data interaction channel determined by the data receiving end, the first dataset to be sent is transmitted to the data receiving end; Furthermore, while transmitting the first dataset to be sent, a second dataset to be sent is prepared.

6. The data transmission method based on security authentication and control as described in claim 5, characterized in that, After sending a data transmission request to the data receiving end, the IP-free firewall unit of the data receiving end is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end.

7. The data transmission method based on security authentication and control as described in claim 6, characterized in that, The IP-free firewall unit is pre-configured with multiple data interaction channels, each corresponding to a different security assessment level and communication protocol. The IP-free firewall unit evaluates the first security level and applicable first communication protocol of the dataset to be sent by the data sender based on the characteristics of the first data sample; and evaluates the second security level and applicable second communication protocol of the dataset to be sent by the data sender based on the characteristics of the second data sample. When there is a conflict between the first security level and the applicable first communication protocol, the second security level and the applicable second communication protocol are used, and the current data interaction channel between the data receiving end and the data sending end is determined.

8. A data transmission system based on security authentication and control, the system comprising at least one data transmitter and at least one data receiver, characterized in that: The data receiving end is configured with an IP-free firewall unit; When the data receiving end receives a data sending request, the IP-free firewall unit is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end; The IP-free firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link. The sampling instruction is used to randomly sample features of the dataset to be sent by the data sending end. The IP-free firewall unit, based on the data sample characteristics obtained by the random feature sampling, evaluates the security level and applicable communication protocol of the dataset to be sent by the data sender, and then determines the current data interaction channel between the data receiver and the data sender. Based on the current data interaction channel, the data sending end transmits data to the data receiving end.

9. A data transmission system based on security authentication and control as described in claim 8, characterized in that: The data sample features include first data sample features and second data sample features; The first data sample features are obtained by the data sending end through random feature sampling of the dataset to be sent based on the sampling instruction; The second data sample features are obtained by the IP-free firewall unit through random feature sampling of the dataset to be sent based on the sampling instruction; The IP-free firewall unit is pre-configured with multiple data interaction channels, each corresponding to a different security assessment level and communication protocol. The IP-free firewall unit evaluates the first security level and applicable first communication protocol of the dataset to be sent by the data sender based on the characteristics of the first data sample; and evaluates the second security level and applicable second communication protocol of the dataset to be sent by the data sender based on the characteristics of the second data sample. When there is a conflict between the first security level and the applicable first communication protocol, the second security level and the applicable second communication protocol are used, and the current data interaction channel between the data receiving end and the data sending end is determined.

10. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by the processor, it implements the steps of the data transmission method based on security authentication and control as described in any one of claims 1 to 4 or 5-7.

Citation Information

Patent Citations

  • A distributed information network security protection method, system, and its readable storage medium.

    CN116566682B

  • Network traffic security detection method, apparatus and device, and readable storage medium

    CN117061373A