Data tampering protection method and system in Ethernet data transmission

By dynamically adjusting the bit rate during Ethernet data transmission and performing data integrity verification in the router's DNS cache, the problem of data transmission being easily tampered with due to long transmission time is solved, achieving efficient and secure data transmission.

CN120602412BActive Publication Date: 2025-10-03GUANGZHOU WEIXUN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511093500.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-10-03
Estimated Expiration
2045-08-06

AI Technical Summary

Technical Problem

In Ethernet data transmission, data transmission time is too long and can be easily intercepted and tampered by intruders, and existing technologies are difficult to effectively protect against it.

Method used

The switch obtains data packet information, dynamically adjusts the code stream speed, optimizes data transmission time based on network bandwidth parameters, and performs data integrity verification in the router DNS cache, using symmetric encryption and public key encryption technology to ensure data security.

Benefits of technology

Effectively shorten data transmission time, reduce the risk of data interception and tampering, and improve data transmission efficiency and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602412B_ABST
    Figure CN120602412B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network communications technology, and more particularly to a method and system for protecting data from tampering in Ethernet data transmission. The method comprises: obtaining information about a data packet to be sent from a current host via a current switch, determining its transmission distance and current bit rate, and calculating an estimated transmission time; if the estimated time exceeds a preset threshold, obtaining the switch's network bandwidth parameters, determining a maximum bit rate as a target bit rate, and recalculating the transmission time; if the recalculated time is less than the threshold, sending the data packet to a target host via a target switch; otherwise, taking other security measures. This method shortens transmission time by dynamically adjusting the bit rate, reducing the risk of data interception and tampering, and simultaneously improving transmission efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network communication technology, and in particular to a method and system for protecting data from tampering in Ethernet data transmission. Background Art

[0002] Ethernet, a widely used wired local area network (LAN) technology, offers significant advantages in data transmission speed, stability, and compatibility. However, as network scale and data transmission volume increase, Ethernet faces increasing security threats during data transmission. In particular, when data transmission takes too long, packets remain in the network for an increased period of time, providing intruders with more opportunities to intercept and tamper with data.

[0003] The above content is only used to assist in understanding the technical solution of the present invention and does not constitute an admission that the above content is prior art. Summary of the Invention

[0004] The main purpose of the present invention is to provide a data tampering protection method and system in Ethernet data transmission, aiming to solve the technical problem that in the existing Ethernet data transmission process, if the data transmission time is too long, it is easy for intruders to intercept the data and then tamper with the data.

[0005] To achieve the above object, the present invention provides a method for protecting data from tampering in Ethernet data transmission, the method comprising:

[0006] Obtain data information of the data packet to be sent by the current host through the current switch;

[0007] Determining the transmission distance of the data packet to be sent and the current code stream speed corresponding to the data packet according to the data information of the data packet to be sent, wherein the transmission distance of the data packet to be sent is the distance between the current host sending end and the target host receiving end;

[0008] Determining an estimated transmission time of the data packet based on the transmission distance of the data packet to be sent and the current bit rate, and obtaining a network bandwidth parameter of the current switch when the estimated transmission time of the data packet is greater than a preset time threshold;

[0009] Determining a target bitrate of the data packet to be sent according to the network bandwidth parameter, wherein the target bitrate is the maximum bitrate of the data packet to be sent, and re-determining an estimated data packet transmission time based on the target bitrate and the transmission distance of the data packet to be sent;

[0010] If the re-determined estimated transmission time of the data packet is less than the preset time threshold, the data packet to be sent is sent to the target host through the target switch.

[0011] Optionally, after re-determining the estimated transmission time of the data packet based on the target bitrate and the transmission distance of the data packet to be sent, the method further includes:

[0012] If the re-determined estimated transmission time of the data packet is greater than a preset time threshold, caching the data packet to be sent in the router DNS cache, and verifying the data integrity of the data packet to be sent through the router DNS cache;

[0013] After the verification is passed, the data packet to be sent is sent to the target host through the target switch; if the verification fails, a verification error code is sent to the current host through the current switch.

[0014] Optionally, if the re-determined estimated transmission time of the data packet is less than a preset time threshold, sending the to-be-sent data packet to the target host through the target switch includes:

[0015] If the re-determined estimated transmission time of the data packet is less than the preset time threshold, determining the importance score of the data packet to be sent;

[0016] When the importance score is greater than a first preset score threshold, the data packet to be sent is read in a blocking mode, the data packet to be sent is cached in a router DNS cache, and the data integrity of the data packet to be sent is verified by the router DNS cache. After the verification passes, the data packet to be sent is sent to the target host through the target switch;

[0017] When the importance score is less than a first preset score threshold, the data packet to be sent is read in a non-blocking mode, and the data packet to be sent is sent to the target host through the target switch.

[0018] Optionally, if the re-determined estimated transmission time of the data packet is less than a preset time threshold, sending the to-be-sent data packet to the target host through the target switch includes:

[0019] If the re-determined estimated transmission time of the data packet is less than the preset time threshold, dividing the data packet to be sent into a plurality of sub-data packets with a sending time sequence, wherein different sub-data packets correspond to different importance scores;

[0020] Determining a sub-packet with an importance score greater than a second preset score threshold as a first sub-packet, reading the first sub-packet in a blocking mode, caching the first sub-packet in a router DNS cache, and verifying data integrity of the first sub-packet using the router DNS cache. After the data integrity is verified, sending the first sub-packet to a target host via a target switch;

[0021] Determine a sub-packet with an importance score less than a second preset score threshold as a second sub-packet, read the second sub-packet in a non-blocking mode, and send the second sub-packet to a target host through a target switch.

[0022] Optionally, determining the target bitrate of the data packet to be sent according to the network bandwidth parameter includes:

[0023] determining a maximum allowable data transmission distance according to the network bandwidth parameter, and if the transmission distance of the data packet to be sent is greater than the maximum allowable data transmission distance, determining a target bit rate of the data packet to be sent according to the maximum allowable data transmission distance;

[0024] Correspondingly, the target bit rate is the maximum bit rate of the data packet to be sent at the maximum allowable data transmission distance.

[0025] Optionally, after determining the maximum allowable data transmission distance according to the network bandwidth parameter, the method further includes:

[0026] If the transmission distance of the data packet to be sent is less than the maximum allowable data transmission distance, the maximum bit rate of the network bandwidth parameter is determined as the target bit rate of the data packet to be sent.

[0027] Optionally, caching the data packet to be sent in a router DNS cache, and verifying the data integrity of the data packet to be sent through the router DNS cache, includes:

[0028] Determine whether the current host and the target host are in the same network segment;

[0029] If the packets are in the same network segment, the packets to be sent are cached in the DNS cache of the router in the same network segment, and the data integrity of the packets to be sent is verified by the DNS cache of the router;

[0030] If they are in different network segments, the data packet to be sent is sent to the cloud server or the local server through the router, and the cloud server sends the data packet to be sent through the wide area network or the local server sends the data packet to the router DNS cache through the local area network, and the data integrity of the data packet to be sent is verified through the router DNS cache.

[0031] Optionally, the verifying the data integrity of the data packet to be sent by the router DNS cache includes:

[0032] Encrypting a certain segment of data in the data packet to be sent or encrypting a hash value of a certain segment of data through the current switch to form a message digest as an authenticator and entering it into the data packet to be sent;

[0033] The router DNS cache uses symmetric encryption and public key encryption technology to parse the authentication code in the data packet to be sent. If the parsing fails, it is determined that the data packet to be sent is abnormal and stops sending it to the target switch. After the parsing is completed, the target switch obtains the complete decrypted data packet to be sent.

[0034] Optionally, the file in the data packet to be sent includes: source IP, source MAC address, source port number, destination IP, destination MAC address, destination port number and network segment protocol number.

[0035] In addition, to achieve the above-mentioned purpose, the present invention also provides a data tampering protection system in Ethernet data transmission, the system includes a data tampering protection device in Ethernet data transmission, the device includes: a memory, a processor and a data tampering protection program in Ethernet data transmission stored on the memory and runnable on the processor, the data tampering protection program in Ethernet data transmission is configured to implement the steps of the data tampering protection method in Ethernet data transmission as described in any one of the above.

[0036] The present invention provides a data tampering protection method and system for Ethernet data transmission, the method comprising: obtaining data information of a data packet to be sent from a current host through a current switch; determining a transmission distance of the data packet to be sent and a current bit rate corresponding to the data packet based on the data information of the data packet to be sent, wherein the transmission distance of the data packet to be sent is the distance between a transmitting end of the current host and a receiving end of a target host; determining an estimated data packet transmission time based on the transmission distance of the data packet to be sent and the current bit rate, and obtaining network bandwidth parameters of the current switch when the estimated data packet transmission time is greater than a preset time threshold; determining a target bit rate of the data packet to be sent based on the network bandwidth parameters, wherein the target bit rate is the maximum bit rate of the data packet to be sent; re-determining the estimated data packet transmission time based on the target bit rate and the transmission distance of the data packet to be sent; and if the re-determined estimated data packet transmission time is less than the preset time threshold, sending the data packet to be sent to the target host through the target switch. The present invention effectively shortens data transmission time by dynamically adjusting the bit rate of the data packet, reduces the risk of data interception and tampering, and improves data transmission efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1It is a structural diagram of a data tampering protection device in Ethernet data transmission in a hardware operating environment involved in an embodiment of the present invention;

[0038] Figure 2 A flow chart of an embodiment of a method for protecting data from tampering in Ethernet data transmission according to the present invention;

[0039] Figure 3 Schematic diagram of the framework of an embodiment of a data tampering protection system in Ethernet data transmission according to the present invention.

[0040] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0041] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0042] Reference Figure 1 , Figure 1 This is a structural diagram of a data tampering protection device in Ethernet data transmission in a hardware operating environment involved in an embodiment of the present invention.

[0043] like Figure 1 As shown, the data tamper protection device for Ethernet data transmission may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen. Optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. In the present invention, the wired interface of the user interface 1003 may be a USB interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 1005 may be a high-speed random access memory (RAM) or a non-volatile memory (NVM), such as a disk drive. The memory 1005 may also be a storage device independent of the processor 1001.

[0044] Those skilled in the art will understand that Figure 1 The structure shown in the figure does not constitute a limitation on the data tampering protection device in Ethernet data transmission, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0045] like Figure 1 As shown, the memory 1005 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a data tampering protection program in Ethernet data transmission.

[0046] exist Figure 1 In the data tampering protection device for Ethernet data transmission shown, the network interface 1004 is mainly used to connect to the background server and communicate data with the background server; the user interface 1003 is mainly used to connect to peripheral devices; the data tampering protection device for Ethernet data transmission calls the data tampering protection program for Ethernet data transmission stored in the memory 1005 through the processor 1001, and executes the data tampering protection method for Ethernet data transmission provided by the embodiment of the present invention.

[0047] Based on the above hardware structure, an embodiment of a data tampering protection method in Ethernet data transmission of the present invention is proposed.

[0048] Reference Figure 2 , Figure 2 1 is a flow chart of an embodiment of a method for protecting data from tampering in Ethernet data transmission according to the present invention. In this embodiment, the method for protecting data from tampering in Ethernet data transmission includes the following steps:

[0049] S10: Obtain data information of the data packet to be sent by the current host through the current switch.

[0050] It should be noted that the executor of this embodiment can be a data tampering protection device in Ethernet data transmission, which can realize functions such as obtaining data packet information, calculating transmission distance and bit rate, adjusting target bit rate, and controlling the forwarding of data packets, or other electronic devices that can realize the above functions. This embodiment does not limit this.

[0051] It should be noted that the current switch refers to the switch device responsible for forwarding data packets in the network, located between the current host and the target host. It is an intermediate node in data transmission, capable of capturing and processing data packets passing through it. The current host refers to the network device that is sending a data packet, such as a computer or server. It is the source of the data packet. The pending data packet refers to the data unit that the current host is about to send over the network. It may include the source address, destination address, data content, and checksum information. Acquiring data information involves the switch monitoring the data packets sent by the current host and extracting key information from them. This key information may include the source address, destination address, packet size, protocol type, and timestamp. The source address refers to the IP address or MAC address of the current host, and the destination address refers to the IP address or MAC address of the target host. The packet size refers to the length or number of bytes of the packet, the protocol type, such as TCP or UDP, and the timestamp is the time the packet was sent. Specifically, the switch captures the data packets through port mirroring or deep packet inspection. The extracted data information can be stored in the switch's cache for subsequent use.

[0052] S20: Determine the transmission distance of the data packet to be sent and the current code stream speed corresponding to the data packet according to the data information of the data packet to be sent, wherein the transmission distance of the data packet to be sent is the distance between the current host sending end and the target host receiving end.

[0053] It should be noted that transmission distance refers to the length of the network path between the current host's sender and the destination host's receiver. Distance can be physical or logical. Physical distances can be measured in kilometers, while logical distances can be measured in hops, which refers to the number of switches or routers a packet passes through. Current data rate refers to the rate at which data packets are transmitted in the current network environment, typically measured in bits per second (bps). It reflects the current network's bandwidth utilization and transmission efficiency. Determining transmission distance involves querying the routing table using the destination address (such as the IP address) to obtain path information from the current host to the destination. Hop count or physical distance can be calculated using a network topology map or routing protocols (such as OSPF and BGP). If the network supports geolocation, physical distance can be estimated using GPS or IP geolocation. Determining current data rate involves using the switch's traffic monitoring function to obtain the current data packet transmission rate. Network performance monitoring tools (such as SNMP and NetFlow) can be used to query current network bandwidth utilization. Actual transmission rate can be calculated based on packet size and timestamp. Specifically, you can use routing protocols or network management tools (such as Ping and Traceroute) to determine the transmission distance, and obtain the current bit rate through the switch's traffic statistics function or network monitoring tools.

[0054] S30: determining an estimated data packet transmission time based on the transmission distance of the data packet to be sent and the current code stream speed, and obtaining a network bandwidth parameter of the current switch when the estimated data packet transmission time is greater than a preset time threshold.

[0055] It should be noted that the estimated packet transmission time refers to the estimated time required for a packet to be sent from the current host to the destination host. It is calculated based on the transmission distance and the current data rate. The preset time threshold is the maximum allowable transmission time. If the estimated packet transmission time exceeds this threshold, the transmission time is considered excessive, potentially affecting data security or efficiency. The network bandwidth parameter refers to the current available bandwidth of the switch, including total bandwidth, used bandwidth, and remaining bandwidth. It is an important basis for adjusting the data rate.

[0056] Specifically, the estimated transmission time is equal to the transmission distance divided by the current bitrate. The transmission distance can be a physical distance (e.g., kilometers) or a logical distance (e.g., number of hops). The current bitrate can be obtained through the switch's traffic monitoring function. If the estimated transmission time is less than or equal to the preset time threshold, the data transmission time is within an acceptable range and no adjustment is required. If the estimated transmission time is greater than the preset time threshold, the data transmission time is too long, potentially increasing the risk of data interception or tampering and requiring further optimization. To obtain the current switch's network bandwidth parameters, specifically query the current network bandwidth usage through the switch's management interface. The parameters obtained may include total bandwidth, used bandwidth, and remaining bandwidth. The total bandwidth is the switch's maximum available bandwidth, the used bandwidth is the bandwidth currently in use on the network, and the remaining bandwidth is the total bandwidth minus the used bandwidth.

[0057] In this step, the estimated transmission time is calculated to evaluate the data packet's transmission efficiency in the current network environment and determine whether there are any delays or performance bottlenecks. If the estimated transmission time is too long, the data packet will be exposed to the network for a longer period of time, potentially being intercepted or tampered with. Obtaining network bandwidth parameters provides a basis for subsequent optimization of the data stream speed, shortening transmission time and reducing security risks. Secondly, obtaining network bandwidth parameters provides information on current network bandwidth usage, providing data support for dynamic adjustment of the data stream speed and ensuring efficient use of network resources. Real-time monitoring and adjustment ensure that data packets reach the destination host within a reasonable time, improving the reliability and stability of data transmission.

[0058] S40: Determine a target bitrate of the data packet to be sent according to the network bandwidth parameter, where the target bitrate is the maximum bitrate of the data packet to be sent, and re-determine an estimated data packet transmission time based on the target bitrate and the transmission distance of the data packet to be sent.

[0059] S50: If the re-determined estimated transmission time of the data packet is less than the preset time threshold, the to-be-sent data packet is sent to the target host via the target switch.

[0060] It should be noted that the target bitrate refers to the optimized transmission rate of the data packets to be sent. It is the maximum bitrate calculated based on network bandwidth parameters. The maximum bitrate refers to the highest achievable transmission rate for the data packets to be sent under the current network environment, subject to the available bandwidth. Recalculating the estimated transmission time for a data packet refers to recalculating the estimated time required for the data packet to be sent from the current host to the target host based on the target bitrate and transmission distance. Specifically, if the recalculated estimated transmission time is less than or equal to a preset time threshold, the data transmission time is within an acceptable range, and the data packet can be sent. If the recalculated estimated transmission time is greater than the preset time threshold, the transmission time is still too long even after adjusting the bitrate, and further optimization of the network configuration or reduction of the data packet size can be considered. If the recalculated estimated transmission time meets the requirements, the target switch forwards the data packet to the target host. During the transmission process, the target switch can control the packet forwarding rate based on the target bitrate to ensure data transmission efficiency. By determining the target bitrate, network bandwidth utilization is maximized, data transmission efficiency is improved, and recalculating the estimated transmission time ensures that the data packet reaches the target host within a reasonable time, reducing the risk of data interception or tampering.

[0061] The present embodiment provides a data tampering protection method in Ethernet data transmission, the method comprising: obtaining data information of a data packet to be sent by a current host through a current switch; determining a transmission distance of the data packet to be sent and a current bit rate corresponding to the data packet based on the data information of the data packet to be sent, wherein the transmission distance of the data packet to be sent is the distance between the current host sending end and the target host receiving end; determining an estimated data packet transmission time based on the transmission distance of the data packet to be sent and the current bit rate, and when the estimated data packet transmission time is greater than a preset time threshold, obtaining a network bandwidth parameter of the current switch; determining a target bit rate of the data packet to be sent based on the network bandwidth parameter, wherein the target bit rate is the maximum bit rate of the data packet to be sent, and re-determining the estimated data packet transmission time based on the target bit rate and the transmission distance of the data packet to be sent; if the re-determined estimated data packet transmission time is less than the preset time threshold, sending the data packet to be sent to the target host through the target switch. The present invention effectively shortens data transmission time, reduces the risk of data interception and tampering, and improves data transmission efficiency by dynamically adjusting the bit rate of the data packet.

[0062] Furthermore, after re-determining the estimated transmission time of the data packet based on the target bit rate and the transmission distance of the data packet to be sent, the method further includes:

[0063] If the re-determined estimated transmission time of the data packet is greater than a preset time threshold, caching the data packet to be sent in the router DNS cache, and verifying the data integrity of the data packet to be sent through the router DNS cache;

[0064] After the verification is passed, the data packet to be sent is sent to the target host through the target switch; if the verification fails, a verification error code is sent to the current host through the current switch.

[0065] It should be noted that the router DNS cache refers to the cache area within the router used to temporarily store DNS query results or data packets. In this embodiment, it is used to cache data packets to be transmitted for data integrity verification. Data integrity verification is the process of checking for tampering or corruption during transmission using a checksum algorithm (such as CRC, MD5, SHA, etc.). The verification error code is an error message sent to the current host when data integrity verification fails, indicating that the data packet may have been tampered with or corrupted.

[0066] Specifically, if the re-determined estimated transmission time for a packet exceeds a preset time threshold, the router temporarily stores the packet in the DNS cache. The router then uses a checksum algorithm (such as CRC, MD5, or SHA) to verify the integrity of the cached packet. This verification process may include calculating a checksum (such as a hash value) for the packet and comparing the calculated checksum with the checksum carried in the packet. If the two match, the packet is intact; if they do not, the packet may have been tampered with or corrupted. If the data integrity verification passes, the router sends the packet to the target switch, which forwards the packet to the target host. If the data integrity verification fails, the router sends a verification error code to the current host via the current switch. The verification error code may include the error type, such as packet tampering or corruption, and recommended remediation measures, such as resending the packet. Data integrity verification ensures that the packet has not been tampered with or corrupted during transmission, improving data transmission reliability. When the estimated transmission time is too long, the caching and verification mechanisms prevent the direct transmission of potentially unsafe packets, mitigating security risks.

[0067] The step of caching the data packet to be sent in a router DNS cache and verifying the data integrity of the data packet to be sent through the router DNS cache includes:

[0068] Determine whether the current host and the target host are in the same network segment;

[0069] If the packets are in the same network segment, the packets to be sent are cached in the DNS cache of the router in the same network segment, and the data integrity of the packets to be sent is verified by the DNS cache of the router;

[0070] If they are in different network segments, the data packet to be sent is sent to the cloud server or the local server through the router, and the cloud server sends the data packet to be sent through the wide area network or the local server sends the data packet to the router DNS cache through the local area network, and the data integrity of the data packet to be sent is verified through the router DNS cache.

[0071] It should be noted that the same network segment means that the IP addresses of the current host and the target host are in the same subnet, and they can communicate directly through the local area network (LAN) without forwarding through a router. Different network segments means that the IP addresses of the current host and the target host are not in the same subnet, and cross-segment communication requires a router or gateway. A cloud server refers to a remote server deployed in the cloud, which is used to handle data packet transmission and verification across network segments. A local server refers to a server deployed in the local network, which is used to handle data packet transmission and verification within the local area network. A wide area network (WAN) refers to a network with a wide coverage area, used to connect network devices in different geographical locations. A local area network (LAN) refers to a network with a smaller coverage area, typically used to connect network devices in the same geographical location.

[0072] Specifically, the current host and the target host's IP address and subnet mask are compared to determine whether they are in the same subnet. If so, they belong to the same network segment; otherwise, they belong to different network segments. If they are in the same network segment, the to-be-sent packet is cached in the router's DNS cache on the same network segment. The router's DNS cache verifies the packet's data integrity, such as by calculating a hash value and comparing it with the checksum in the packet. If verification succeeds, the router forwards the packet to the target host. If verification fails, a verification error code is sent to the current host. If they are in different network segments, the to-be-sent packet is sent to a cloud server or a local server via the router. The cloud server receives the packet over the wide area network (WAN) and sends it to the router's DNS cache on the target network segment. The local server receives the packet over the local area network (LAN) and sends it to the router's DNS cache on the target network segment. The router's DNS cache verifies the packet's data integrity. If verification succeeds, the router forwards the packet to the target host. If verification fails, a verification error code is sent to the current host. Based on whether the current host and the target host are on the same network segment, the most appropriate transmission path (LAN or WAN) is selected to improve data transmission efficiency. The router's DNS cache verifies the integrity of the data packet to ensure that the data has not been tampered with or damaged during transmission. Then, cloud servers or local servers handle cross-segment data packet transmission, ensuring that data reaches the target host securely and efficiently.

[0073] Furthermore, the verifying the data integrity of the data packet to be sent by the router DNS cache includes:

[0074] Encrypting a certain segment of data in the data packet to be sent or encrypting a hash value of a certain segment of data through the current switch to form a message digest as an authenticator and entering it into the data packet to be sent;

[0075] The router DNS cache uses symmetric encryption and public key encryption technology to parse the authentication code in the data packet to be sent. If the parsing fails, it is determined that the data packet to be sent is abnormal and stops sending it to the target switch. After the parsing is completed, the target switch obtains the complete decrypted data packet to be sent.

[0076] It should be noted that a message digest is a fixed-length string generated by performing a hash operation (such as MD5 or SHA-256) on a segment of data in a data packet. It is used to verify data integrity. An authenticator is a verification identifier generated by encrypting a message digest or a segment of data, used to ensure that data has not been tampered with during transmission. Symmetric cryptography, such as AES and DES, uses the same key for encryption and decryption. It boasts high encryption speed and is suitable for encrypting large amounts of data. Public-key cryptography, such as RSA and ECC, uses different keys for encryption and decryption. It offers high security and is suitable for key exchange and digital signatures. Parsing involves decrypting the authenticator using a decryption algorithm to verify its consistency with the original data. Anomaly detection involves determining that a data packet may have been tampered with or damaged if the authenticator cannot be decrypted or is inconsistent with the original data during parsing.

[0077] Specifically, the current switch performs a hash operation on a segment of data in a data packet to generate a message digest. It then encrypts the message digest using symmetric or public-key cryptography to generate an authenticator, which is then included in the data packet to be sent. After receiving the data packet, the router's DNS cache extracts the authenticator, decrypts it using symmetric or public-key cryptography to obtain the original message digest, hashes the same data in the data packet to generate a new message digest, and compares the decrypted message digest with the newly generated message digest. If the authenticator cannot be parsed, such as decryption failure or inconsistent message digests, the packet is considered abnormal. The router's DNS cache stops sending the packet to the target switch, logs the abnormality, and sends a verification error code to the current host, indicating that the packet may have been tampered with or corrupted. If the parsing is successful and the message digests are consistent, the packet is considered intact and the router's DNS cache sends the packet to the target switch. The target switch receives the decrypted, complete data packet to be sent and forwards it to the target host. This authenticator mechanism ensures that the data packet has not been tampered with or corrupted during transmission, improving data transmission reliability. The authenticator is encrypted and parsed using symmetric and public key cryptography to prevent malicious data tampering or forgery. During the parsing process, packet anomalies are quickly detected, preventing unsafe packets from being forwarded to the target host. Combining symmetric and public key cryptography, it balances encryption speed and security, adapting to the needs of various scenarios. A verification mechanism ensures that only complete and secure packets are forwarded, improving overall network reliability.

[0078] The data packet to be sent includes: source IP, source MAC address, source port number, destination IP, destination MAC address, destination port number and network segment protocol number.

[0079] Furthermore, if the re-determined estimated transmission time of the data packet is less than a preset time threshold, sending the to-be-sent data packet to the target host through the target switch includes:

[0080] If the re-determined estimated transmission time of the data packet is less than the preset time threshold, determining the importance score of the data packet to be sent;

[0081] When the importance score is greater than a first preset score threshold, the data packet to be sent is read in a blocking mode, the data packet to be sent is cached in a router DNS cache, and the data integrity of the data packet to be sent is verified by the router DNS cache. After the verification passes, the data packet to be sent is sent to the target host through the target switch;

[0082] When the importance score is less than a first preset score threshold, the data packet to be sent is read in a non-blocking mode, and the data packet to be sent is sent to the target host through the target switch.

[0083] It should be noted that the importance score refers to a quantitative score of the importance of a data packet based on factors such as its content, purpose, and priority. The higher the score, the more important the data packet. The first preset score threshold refers to a pre-set importance score threshold used to determine whether a data packet requires additional integrity verification and cache processing. Blocking mode means that when reading a data packet, the system will wait until the data packet is completely read and verified before proceeding with subsequent operations. This mode is suitable for high-priority or high-importance data packets. Non-blocking mode means that when reading a data packet, the system will not wait for the data packet to be completely read, but will proceed directly with subsequent operations. This mode is suitable for low-priority or low-importance data packets.

[0084] Specifically, a packet's importance score is calculated based on factors such as its content, purpose, and priority. Scoring criteria may include packet type (e.g., control data, user data, management data), packet priority (e.g., high, medium, low), and packet security requirements, such as whether encryption or authentication is required. If the importance score is greater than a first preset threshold, the packet is read in blocking mode to ensure complete reading. The packet is then cached in the router's DNS cache. Data integrity is verified in the router's DNS cache. If verification passes, the target switch sends the packet to the target host. If verification fails, a verification error code is sent to the current host. If the importance score is less than the first preset threshold, the packet is read in non-blocking mode and subsequent operations are performed directly. The target switch sends the packet to the target host without buffering or verification. Based on the packet's importance score, blocking or non-blocking mode is dynamically selected to optimize system resource allocation. High-importance packets are cached and verified to ensure their integrity and security. Low-importance packets are treated in non-blocking mode to reduce processing time and improve transmission efficiency. Dynamically adjust processing methods based on packet importance to meet the needs of different scenarios. By differentiating the processing methods for high-priority and low-priority data packets, unnecessary caching and verification operations are reduced, reducing network load.

[0085] In another embodiment, if the re-determined estimated transmission time of the data packet is less than a preset time threshold, sending the to-be-sent data packet to the target host through the target switch includes:

[0086] If the re-determined estimated transmission time of the data packet is less than the preset time threshold, dividing the data packet to be sent into a plurality of sub-data packets with a sending time sequence, wherein different sub-data packets correspond to different importance scores;

[0087] Determining a sub-packet with an importance score greater than a second preset score threshold as a first sub-packet, reading the first sub-packet in a blocking mode, caching the first sub-packet in a router DNS cache, and verifying data integrity of the first sub-packet using the router DNS cache. After the data integrity is verified, sending the first sub-packet to a target host via a target switch;

[0088] Determine a sub-packet with an importance score less than a second preset score threshold as a second sub-packet, read the second sub-packet in a non-blocking mode, and send the second sub-packet to a target host through a target switch.

[0089] It should be noted that sub-packets refer to multiple smaller data units divided into a data packet to be sent according to certain rules (such as content type and priority). Each sub-packet can be sent and processed independently. The sending sequence refers to the order in which sub-packets are sent, which can be determined based on their importance score or priority. The importance score is a quantitative assessment of the importance of a sub-packet based on factors such as its content, purpose, and priority. A higher score indicates a more important sub-packet. The second preset scoring threshold is a pre-set importance score threshold used to distinguish between high- and low-importance sub-packets. Blocking mode means that when reading a sub-packet, the system waits until the sub-packet is completely read and verified before proceeding with subsequent operations. This mode is suitable for high-importance sub-packets. Non-blocking mode means that when reading a sub-packet, the system does not wait for the sub-packet to be completely read, but proceeds directly with subsequent operations. This mode is suitable for low-importance sub-packets.

[0090] Specifically, the data packet to be sent is divided into multiple sub-packets based on content type, priority, and other criteria. Each sub-packet is assigned an importance score, and its transmission sequence is determined. If the importance score of a sub-packet exceeds a second preset score threshold, it is marked as the first sub-packet. The first sub-packet is read in blocking mode to ensure complete reading. The first sub-packet is cached in the router's DNS cache. The router's DNS cache verifies the data integrity of the first sub-packet. If the verification passes, the target switch sends the first sub-packet to the target host. If the verification fails, a verification error code is sent to the current host. If the importance score of the sub-packet is less than the second preset score threshold, it is marked as the second sub-packet. The second sub-packet is read in non-blocking mode, and subsequent operations are performed directly. The target switch sends the second sub-packet to the target host without buffering or verification. By dividing the sub-packets and distinguishing their processing methods, the data transmission process is optimized and overall efficiency is improved. High-importance sub-packets are cached and verified to ensure their integrity and security. Low-importance sub-packets are processed in non-blocking mode to reduce processing time and improve transmission efficiency. The processing method is dynamically adjusted based on the importance of the sub-packets to meet the needs of different scenarios. By distinguishing between high- and low-importance sub-packets, unnecessary caching and verification operations are reduced, lowering network load. During data transmission, both high- and low-importance data can be processed simultaneously, meeting the needs of complex scenarios.

[0091] For example, the importance score of sub-packet A is 85, which is greater than the second preset score threshold of 70. Sub-packet A is marked as the first sub-packet. Sub-packet A is read in blocking mode and cached in the router DNS cache. The router DNS cache verifies the integrity of sub-packet A. After the verification is passed, the target switch sends sub-packet A to the target host. The importance score of sub-packet B is 60, which is less than the second preset score threshold of 70. Sub-packet B is marked as the second sub-packet. Sub-packet B is read in non-blocking mode. The target switch sends sub-packet B to the target host without caching and verification. Through this implementation, the system can dynamically adjust the processing method according to the importance of the sub-packet, ensuring the integrity and security of high-importance data while improving the transmission efficiency of low-importance data.

[0092] In addition, in this embodiment, determining the target bitrate of the data packet to be sent according to the network bandwidth parameter includes:

[0093] determining a maximum allowable data transmission distance according to the network bandwidth parameter, and if the transmission distance of the data packet to be sent is greater than the maximum allowable data transmission distance, determining a target bit rate of the data packet to be sent according to the maximum allowable data transmission distance;

[0094] Correspondingly, the target bit rate is the maximum bit rate of the data packet to be sent at the maximum allowable data transmission distance.

[0095] It should be noted that the maximum allowable data transmission distance refers to the maximum physical distance over which a data packet can be stably transmitted within a given network bandwidth. This distance is dependent on factors such as network bandwidth, signal attenuation, and noise interference. The target bitrate refers to the bitrate that a data packet needs to achieve during transmission, expressed in bitrates (bps), such as 500 Kbps or 2 Mbps. The maximum bitrate refers to the highest bitrate that a data packet can achieve within the maximum allowable data transmission distance.

[0096] Specifically, the maximum allowable data transmission distance is calculated based on network bandwidth parameters, taking into account factors such as signal attenuation and noise interference. For example, if the network bandwidth is 100 Mbps and signal attenuation is minimal, the maximum allowable data transmission distance may be 100 km. The transmission distance of the data packet to be sent is compared with the maximum allowable data transmission distance. If the transmission distance exceeds the maximum allowable data transmission distance, the next step is performed; otherwise, the target bitrate is determined directly based on the network bandwidth parameters. Based on the maximum allowable data transmission distance, the maximum bitrate of the data packet to be sent at that distance is calculated. The target bitrate is set to this maximum bitrate to ensure stable data transmission. The target bitrate is dynamically adjusted based on the network bandwidth parameters and transmission distance to ensure stable data transmission. For longer transmission distances, the target bitrate can be lowered to minimize the impact of signal attenuation and noise interference on data transmission. For shorter transmission distances, network bandwidth can be fully utilized to improve data transmission efficiency. The target bitrate is dynamically adjusted based on changes in network bandwidth and transmission distance to meet the needs of different scenarios. By properly setting the target bitrate, data packets can be ensured to reach the receiving end completely and accurately.

[0097] Furthermore, after determining the maximum allowable data transmission distance according to the network bandwidth parameter, the method further includes:

[0098] If the transmission distance of the data packet to be sent is less than the maximum allowable data transmission distance, the maximum bit rate of the network bandwidth parameter is determined as the target bit rate of the data packet to be sent.

[0099] It's important to note that when transmission distances are short, network signal attenuation and noise interference are minimal, allowing network bandwidth resources to be fully utilized. Setting the target bitrate to the maximum bitrate maximizes data transmission efficiency, avoids wasting bandwidth resources, shortens data transmission time, and mitigates the risk of interception and tampering during data transmission.

[0100] In addition, refer to Figure 3 An embodiment of the present invention further proposes a data tampering protection system in Ethernet data transmission, the system including a data tampering protection device in Ethernet data transmission, the device including: a memory, a processor, and a data tampering protection program in Ethernet data transmission stored in the memory and executable on the processor, the data tampering protection program in Ethernet data transmission being configured to implement the steps of the data tampering protection method in Ethernet data transmission as described in any one of the above.

[0101] Other embodiments or specific implementations of the data tampering protection system in Ethernet data transmission of the present invention can refer to the above-mentioned method embodiments and will not be repeated here.

[0102] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0103] The serial numbers of the embodiments of the present invention are for descriptive purposes only and do not represent superiority or inferiority of the embodiments. In a unit claim that enumerates several means, several of these means may be embodied by the same item of hardware. The use of the terms first, second, and third, etc., does not denote any order; these terms should be interpreted as designations.

[0104] Through the above description of the embodiments, those skilled in the art will clearly understand that the above-mentioned embodiments and methods can be implemented using software plus the necessary general hardware platform. Of course, hardware can also be used, but in many cases, the former is a more preferred embodiment. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as a read-only memory image (ROM) / random access memory (RAM), a magnetic disk, or an optical disk) and includes a number of instructions for enabling an end-user device (such as a mobile phone, computer, server, air conditioner, or network user device, etc.) to execute the methods described in various embodiments of the present invention.

[0105] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A data tampering protection method in Ethernet data transmission, characterized in that: The method comprises: Obtain data information of the data packet to be sent by the current host through the current switch; Determining the transmission distance of the data packet to be sent and the current code stream speed corresponding to the data packet according to the data information of the data packet to be sent, wherein the transmission distance of the data packet to be sent is the distance between the current host sending end and the target host receiving end; Determining an estimated transmission time of the data packet based on the transmission distance of the data packet to be sent and the current bit rate, and obtaining a network bandwidth parameter of the current switch when the estimated transmission time of the data packet is greater than a preset time threshold; Determining a target bitrate of the data packet to be sent according to the network bandwidth parameter, wherein the target bitrate is the maximum bitrate of the data packet to be sent, and re-determining an estimated data packet transmission time based on the target bitrate and the transmission distance of the data packet to be sent; If the re-determined estimated transmission time of the data packet is less than the preset time threshold, the data packet to be sent is sent to the target host through the target switch.

2. The data tampering protection method in Ethernet data transmission according to claim 1, characterized in that: After re-determining the estimated transmission time of the data packet based on the target bit rate and the transmission distance of the data packet to be sent, the method further includes: If the re-determined estimated transmission time of the data packet is greater than a preset time threshold, caching the data packet to be sent in the router DNS cache, and verifying the data integrity of the data packet to be sent through the router DNS cache; After the verification is passed, the data packet to be sent is sent to the target host through the target switch; if the verification fails, a verification error code is sent to the current host through the current switch.

3. The data tampering protection method in Ethernet data transmission according to claim 1, characterized in that: If the re-determined estimated transmission time of the data packet is less than the preset time threshold, sending the to-be-sent data packet to the target host through the target switch includes: If the re-determined estimated transmission time of the data packet is less than the preset time threshold, determining the importance score of the data packet to be sent; When the importance score is greater than a first preset score threshold, the data packet to be sent is read in a blocking mode, the data packet to be sent is cached in a router DNS cache, and the data integrity of the data packet to be sent is verified by the router DNS cache. After the verification passes, the data packet to be sent is sent to the target host through the target switch; When the importance score is less than a first preset score threshold, the data packet to be sent is read in a non-blocking mode, and the data packet to be sent is sent to the target host through the target switch.

4. The data tampering protection method in Ethernet data transmission according to claim 1, characterized in that: If the re-determined estimated transmission time of the data packet is less than the preset time threshold, sending the to-be-sent data packet to the target host through the target switch includes: If the re-determined estimated transmission time of the data packet is less than the preset time threshold, dividing the data packet to be sent into a plurality of sub-data packets with a sending time sequence, wherein different sub-data packets correspond to different importance scores; Determining a sub-packet with an importance score greater than a second preset score threshold as a first sub-packet, reading the first sub-packet in a blocking mode, caching the first sub-packet in a router DNS cache, and verifying data integrity of the first sub-packet using the router DNS cache. After the data integrity is verified, sending the first sub-packet to a target host via a target switch; Determine a sub-packet with an importance score less than a second preset score threshold as a second sub-packet, read the second sub-packet in a non-blocking mode, and send the second sub-packet to a target host through a target switch.

5. The data tampering protection method in Ethernet data transmission according to claim 1, characterized in that: The determining the target stream speed of the data packet to be sent according to the network bandwidth parameter includes: determining a maximum allowable data transmission distance according to the network bandwidth parameter, and if the transmission distance of the data packet to be sent is greater than the maximum allowable data transmission distance, determining a target bit rate of the data packet to be sent according to the maximum allowable data transmission distance; Correspondingly, the target bit rate is the maximum bit rate of the data packet to be sent at the maximum allowable data transmission distance.

6. The data tampering protection method in Ethernet data transmission according to claim 5, characterized in that: After determining the maximum allowable data transmission distance according to the network bandwidth parameter, the method further includes: If the transmission distance of the data packet to be sent is less than the maximum allowable data transmission distance, the maximum bit rate of the network bandwidth parameter is determined as the target bit rate of the data packet to be sent.

7. The data tampering protection method in Ethernet data transmission according to claim 2, characterized in that: The step of caching the data packet to be sent in the router DNS cache and verifying the data integrity of the data packet to be sent through the router DNS cache includes: Determine whether the current host and the target host are in the same network segment; If the packets are in the same network segment, the packets to be sent are cached in the DNS cache of the router in the same network segment, and the data integrity of the packets to be sent is verified by the DNS cache of the router; If they are in different network segments, the data packet to be sent is sent to the cloud server or the local server through the router, and the cloud server sends the data packet to be sent through the wide area network or the local server sends the data packet to the router DNS cache through the local area network, and the data integrity of the data packet to be sent is verified through the router DNS cache.

8. The data tampering protection method in Ethernet data transmission according to claim 2, characterized in that: The verifying the data integrity of the data packet to be sent by the router DNS cache includes: Encrypting a certain segment of data in the data packet to be sent or encrypting a hash value of a certain segment of data through the current switch to form a message digest as an authenticator and entering it into the data packet to be sent; The router DNS cache uses symmetric encryption and public key encryption technology to parse the authentication code in the data packet to be sent. If the parsing fails, it is determined that the data packet to be sent is abnormal and stops sending it to the target switch. After the parsing is completed, the target switch obtains the complete decrypted data packet to be sent.

9. The data tampering protection method in Ethernet data transmission according to any one of claims 1 to 8, characterized in that: The data packet to be sent includes: source IP, source MAC address, source port number, destination IP, destination MAC address, destination port number and network segment protocol number.

10. A data tampering protection system in Ethernet data transmission, characterized in that: The system includes a data tampering protection device in Ethernet data transmission, and the device includes: a memory, a processor, and a data tampering protection program in Ethernet data transmission stored on the memory and executable on the processor, wherein the data tampering protection program in Ethernet data transmission is configured to implement the steps of the data tampering protection method in Ethernet data transmission according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Method, device and system of code rate self-adaptive control in wireless transmission

    CN103096084A

  • Ethernet data transmission method and system and Ethernet equipment

    CN116886629A