Data bandwidth guarantee and encryption transmission system based on tunnel technology
By performing policy matching and bandwidth metering before tunnel encapsulation, identifying the original length and performing intelligent access control, the problem of bandwidth loss in tunnel encryption technology is solved, and the priority transmission of high-value services and the data transmission effect with both security and stability are achieved.
Patent Information
- Application Number
- CN202511123043.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-10-14
AI Technical Summary
In existing technologies, when tunnel encryption technology is combined with a bandwidth guarantee mechanism, the actual available bandwidth of users is damaged, metering is inaccurate, and fair bandwidth guarantee and differentiated service quality control cannot be achieved.
By performing policy matching and bandwidth metering before tunnel encapsulation, identifying the original length, and combining the service priority and network resource status of the message, dynamic intelligent admission control is carried out to ensure that only high-value services are transmitted first when the network is congested, and data encryption and tunnel encapsulation are performed on this basis.
It achieves the precise fulfillment of bandwidth promised to users, ensures the priority protection of high-value services in complex network environments, and improves service quality and data transmission security.
Smart Images

Figure CN120785639A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data transmission, and more specifically, to a data bandwidth guarantee and encryption transmission system based on tunneling technology. Background Art
[0002] With the rapid development of information technology and the ubiquity of the internet, networks have become an indispensable infrastructure for modern society. Enterprises and individual users are increasingly demanding network communications, demanding not only high speeds but also stringent requirements for data transmission security and quality of service. To protect sensitive information, such as commercial secrets and personal privacy, from theft or tampering when transmitted over public networks like the internet, tunneling technology, particularly encrypted tunneling (such as IPsecVPN), has become widely used. This technology encrypts the original data packet and encapsulates it within a new IP header for transmission, creating a logically secure channel over an insecure network, effectively ensuring data confidentiality and integrity.
[0003] However, existing technologies have encountered difficult technical challenges in combining tunnel encryption technology with bandwidth guarantee mechanisms. Typically, network devices implement bandwidth control or rate limiting (i.e., QoS policies) on data flows just before a packet leaves the physical interface. For services requiring tunnel transmission, this means the original packet has already been encrypted and tunnel-encapsulated, significantly increasing its overall length due to the addition of overhead such as the tunnel header and encryption protocol header (such as the ESP header). Service providers or network administrators use this encapsulated packet length to perform bandwidth metering and rate limiting. This directly leads to inaccurate bandwidth metering for users and a failure to guarantee the actual service bandwidth purchased. For example, a user may purchase a 100Mbps bandwidth service and expect to transmit their original service data at that rate. However, due to the tunnel encapsulation overhead (which may account for 10%-20%), the actual effective service data throughput may be far less than 100Mbps, as the tunnel overhead itself consumes the purchased bandwidth. This rate limiting approach based on encapsulated packet length is unfair to users and fails to achieve refined management of network resources.
[0004] Therefore, a data bandwidth guarantee and encryption transmission system based on tunnel technology is desired. Summary of the Invention
[0005] In order to solve the above technical problems, the present application is proposed. The embodiments of the present application provide a data bandwidth guarantee and encryption transmission system based on tunnel technology.
[0006] According to one aspect of the present application, a data bandwidth guarantee and encryption transmission system based on tunneling technology is provided, which includes: a policy matching module, configured to perform policy matching on the received original message to obtain a classified message and message metadata, wherein the message metadata includes an original length; a bandwidth metering and admission control module, configured to perform bandwidth metering and admission control based on the original length of the classified messages based on the message metadata to obtain admission messages; A data encryption module, configured to encrypt the access message based on a tunnel policy to obtain a security payload; a tunnel encapsulation module, configured to perform tunnel encapsulation on the security payload and the header information of the admission message to obtain a final tunnel message; The message delivery module is used to deliver the final tunnel message to the sending queue of the physical interface.
[0007] Compared to existing technologies, the tunnel-based data bandwidth guarantee and encrypted transmission system provided in this application restructures the data processing flow, moving the key decision point for bandwidth metering and admission control from after tunnel encapsulation to before encapsulation, thereby decoupling the two major functions of security encryption and bandwidth guarantee. Specifically, an intelligent pre-processing module performs policy matching before packets enter the tunnel encapsulation process to identify target traffic and accurately capture its original length, excluding any tunnel overhead. Based on this original length, the system not only provides fair and accurate bandwidth metering, addressing the issue of actual bandwidth loss for users due to tunnel encapsulation overhead, but also makes dynamic, probabilistic, intelligent admission decisions based on the packet's service priority and current network resource status, thereby prioritizing high-value services during network congestion. Ultimately, only packets that pass this precise and intelligent screening are sent for encryption and encapsulation. This architecture of precise metering followed by secure encapsulation transforms traditional passive traffic limiting into proactive, refined resource scheduling, ensuring accurate delivery of promised bandwidth to users and improving service quality while ensuring data transmission security. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0009] Figure 1 4 is a system block diagram of a data bandwidth guarantee and encryption transmission system based on tunnel technology according to an embodiment of the present application.
[0010] Figure 2Schematic diagram of data flow of a data bandwidth guarantee and encryption transmission system based on tunnel technology according to an embodiment of the present application.
[0011] Figure 3 This is a block diagram of a policy matching module in a data bandwidth guarantee and encryption transmission system based on tunnel technology according to an embodiment of the present application.
[0012] Figure 4 This is a block diagram of a bandwidth metering and admission control module in a data bandwidth guarantee and encryption transmission system based on tunneling technology according to an embodiment of the present application. DETAILED DESCRIPTION
[0013] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.
[0014] As used in this application and the claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not intended to refer to the singular but may include the plural. Generally speaking, the terms "comprises" and "include" only indicate the inclusion of the steps and elements specifically identified, and these steps and elements do not constitute an exclusive list. A method or apparatus may also include other steps or elements.
[0015] Although the present application makes various references to certain modules in the system according to embodiments of the present application, any number of different modules can be used and run on the user terminal and / or server. The modules are illustrative only, and different aspects of the system and method can use different modules.
[0016] Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, the various steps may be processed in reverse order or simultaneously, as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0017] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.
[0018] In tunnel encryption scenarios, bandwidth control is usually performed after packet encapsulation, causing the tunnel protocol's own overhead to occupy the bandwidth purchased by users, resulting in unfair metering. At the same time, the rigid access mechanism cannot distinguish business priorities, making it difficult to ensure the service quality of critical applications during network congestion.
[0019] To address the above technical issues, the technical solution of this application proposes a data bandwidth assurance and encrypted transmission system based on tunneling technology, implementing an architecture that prioritizes intelligent admission followed by secure encapsulation. Specifically, the system first intercepts the original message at the forefront of the processing flow, identifies traffic requiring tunneling through policy matching, and immediately extracts its original, unmodified length as key metadata. Subsequently, the system does not directly encapsulate the message, but instead enters a core intelligent admission control phase. In this phase, the system no longer simply makes a binary judgment based on token bucket sufficiency. Instead, it comprehensively evaluates the message's service priority (such as the DSCP value) and the current health of network resources to calculate a dynamic admission score, which is converted into a probabilistic admission permit. Only when a message has a sufficiently high admission probability based on its value and passes the final resource verification based on its original length is it officially allowed to pass. Finally, these carefully screened admitted messages are submitted to subsequent modules to complete the standard encryption and tunnel encapsulation process. In this way, this solution not only fundamentally guarantees the accuracy and fairness of bandwidth metering, but also, by introducing a dynamic decision-making mechanism based on business value, prioritizes critical services in complex network environments, seamlessly integrating secure transmission with refined service quality control.
[0020] In the technical solution of the present application, a data bandwidth guarantee and encryption transmission system based on tunnel technology is proposed. Figure 1 4 is a system block diagram of a data bandwidth guarantee and encryption transmission system based on tunnel technology according to an embodiment of the present application. Figure 2 Schematic diagram of data flow in a data bandwidth guarantee and encrypted transmission system based on tunnel technology according to an embodiment of the present application. Figure 1 and Figure 2 As shown, according to an embodiment of the present application, a data bandwidth guarantee and encryption transmission system 100 based on tunnel technology includes: a policy matching module 110, which is used to perform policy matching on the received original message to obtain a classified message and message metadata, wherein the message metadata includes the original length; a bandwidth metering and admission control module 120, which is used to perform bandwidth metering and admission control based on the original length of the classified message based on the message metadata to obtain an admission message; a data encryption module 130, which is used to encrypt the admission message based on the tunnel policy to obtain a security payload; a tunnel encapsulation module 140, which is used to tunnel encapsulate the security payload and the header information of the admission message to obtain a final tunnel message; and a message delivery module 150, which is used to deliver the final tunnel message to the sending queue of the physical interface.
[0021] In the tunneling-based data bandwidth guarantee and encrypted transmission system 100, the policy matching module 110 is used to perform policy matching on the received original message to obtain a classified message and message metadata, including the original length. It should be understood that, in the initial stage of data processing, the system cannot predict whether an incoming IP message requires tunnel encapsulation, nor can it know its original, unmodified size. This results in a lack of necessary pre-conditional information for subsequent bandwidth measurement and policy execution. Therefore, in the technical solution of the present application, policy matching is performed on the received original message to obtain a classified message and message metadata, including the original length. This establishes a clear data foundation and processing basis for subsequent accurate bandwidth measurement and differentiated quality of service assurance. This ensures that the system solidifies and transmits the key original attributes of the message before performing any operations that change the message size, laying the foundation for fair billing and intelligent admission control based on the original length.
[0022] Figure 3 FIG is a block diagram of a policy matching module in a data bandwidth guarantee and encryption transmission system based on tunnel technology according to an embodiment of the present application. Figure 3 As shown, in an embodiment of the present application, the policy matching module 110 includes: a message header tuple extraction unit 111, used to extract a message header tuple from the original message; a policy rule query unit 112, used to use the message header tuple as a query key to query a policy rule library preconfigured in the device, and output the matching policy rule in response to a successful search, and designate the original message as a classified message; a data reading unit 113, used to read the original length from the original message and extract the user identifier from the matching policy rule in response to the matching policy rule being tunnel encapsulation; an encapsulation unit 114, used to encapsulate the user identifier and the original length as the message metadata.
[0023] Specifically, in one example of this application, the policy matching and message metadata generation process proceeds as follows: A gateway device deployed at the egress of an enterprise network receives an original message originating from an internal R&D employee (IP address 192.168.1.100) destined for a core server at headquarters (IP address 10.10.30.5). First, a message header tuple extraction unit parses the original message's IP header, extracting key information such as the source IP address, destination IP address, and protocol number, to form a message header tuple. Subsequently, a policy rule query unit uses this message header tuple as a query key to search the device's preconfigured policy rule base. This rule base contains a rule specifying that all traffic from the 192.168.1.0 / 24 network segment to the 10.10.30.0 / 24 network segment must be tunneled and associated with the user identifier R&D_Group. Since the query successfully matches, the original message is immediately designated as a classified message. Next, the data reading unit, in response to the matching rule's tunnel encapsulation instruction, reads the original length (e.g., 512 bytes) from the classified message's IP header and extracts the user identifier, R&D_Group, from the matching policy rule. Finally, the encapsulation unit encapsulates the obtained original length (512 bytes) and user identifier, R&D_Group, into a structured message metadata object, associates it with the classified message, and delivers it to the subsequent bandwidth metering and admission control module. If the original message's destination is a public Internet address and the policy rule base search fails, the message is directly sent to the device's standard IP forwarding table query and forwarding engine for standard public network forwarding.
[0024] In particular, in response to an unsuccessful search, the original message is sent to the device's standard IP forwarding table query and forwarding engine; or, in response to the matched policy rule being a default forwarding, the original message is sent to the device's standard IP forwarding table query and forwarding engine. That is, in a specific example of the present application, in a network device, in order to ensure the integrity and robustness of the processing logic, a clear and efficient processing path must be provided for messages that do not meet specific policy conditions. These two processing mechanisms together constitute the default or bypass channel for the special processing flow described in this solution, ensuring that the device can not only serve as a dedicated tunnel gateway, but also seamlessly assume the role of a standard router.
[0025] Specifically, the first case, that is, in response to an unsuccessful lookup, the original message is sent to the device's standard IP forwarding table query and forwarding engine, which is the standard procedure for handling the vast majority of ordinary traffic. For example, when an employee in the R&D department visits a public Internet website, the destination IP address of the original message they send is a public network address. When the policy rule query unit searches in the policy rule library, it cannot find any rules that match the public network address because the library only configures tunnel policies for specific internal servers or partner networks. In the event of a search failure, the system determines that the message does not require tunnel encapsulation and subsequent bandwidth guarantee processing, and then directly hands it over to the device's built-in quasi-IP forwarding table query and forwarding engine. The engine will perform a regular routing lookup, find the exit to the Internet based on the longest prefix match principle, and forward the message.
[0026] The second scenario, where the original packet is sent to the device's standard IP forwarding table query and forwarding engine in response to a matching policy rule indicating default forwarding, offers a more flexible and granular management approach. This allows network administrators to explicitly exempt certain traffic from tunneling. For example, an administrator might set a broad policy requiring all traffic from the R&D department destined for the headquarters server network segment to be tunneled. However, to conserve resources, the administrator could also configure a more specific, higher-priority rule specifying default forwarding for access to one of the non-confidential servers used for software releases. When a packet precisely matches this default forwarding rule, even if the lookup is successful, the system treats it the same as unsuccessful packets and sends it directly to the standard IP forwarding table query and forwarding engine for normal routing. These two mechanisms complement each other, ensuring that only traffic truly requiring security and bandwidth control undergoes policy matching and subsequent data processing.
[0027] In the tunnel technology-based data bandwidth guarantee and encrypted transmission system 100, the bandwidth metering and admission control module 120 performs original length-based bandwidth metering and admission control on the classified packets based on the packet metadata to obtain admitted packets. It should be understood that, since the traditional bandwidth control mechanism can only make rigid decisions based on the size of the encapsulated packets, it not only leads to unfair metering of user bandwidth, but also cannot distinguish between service values when network resources are scarce, making it difficult to guarantee the quality of service of critical applications. Therefore, in the technical solution of the present application, the original length-based bandwidth metering and admission control is further performed on the classified packets based on the packet metadata to obtain admitted packets, so as to upgrade the single rate limit to a dynamic admission system that combines fair metering and intelligent decision-making. In this way, the user's paid bandwidth can be accurately realized, while high-value services are prioritized in limited resources, ultimately achieving differentiated service guarantee with both security and performance.
[0028] Figure 4 A block diagram of a bandwidth metering and admission control module in a tunnel technology-based data bandwidth guarantee and encrypted transmission system according to an embodiment of the present application. As shown in Figure 4 In the embodiment of the present application, the bandwidth metering and admission control module 120 includes: a packet utility and resource health joint evaluation unit 121 for jointly evaluating the packet metadata, the classified packets, and the token bucket state to obtain an admission score; an admission decision probability calculation unit 122 for performing probabilistic admission decision based on a logistic function on the admission score to obtain an admission probability; and a random sample admission unit 123 for performing random sample admission and token consumption evaluation on the classified packets to obtain the admitted packets.
[0029] Specifically, since the original bandwidth metering mechanism has defects in admission control, its decision logic is too rigid and lacks awareness of service value. When the token is sufficient, the mechanism makes a simple binary decision and releases all size-compliant packets indiscriminately. This processing method ignores the real-time tightness of network resources and cannot distinguish between high-priority critical service packets and low-priority ordinary data packets. In the critical state where network resources tend to be saturated, this homogenized processing strategy is likely to cause important service transmission quality to be squeezed by non-critical services, thus failing to achieve true quality of service guarantee.
[0030] In response to the above defects, a dynamic and business-aware probabilistic admission control mechanism is designed. The first step of this mechanism is the joint evaluation of message utility and resource health. It should be understood that an intelligent admission decision should not rely solely on the single dimension of message size, but must comprehensively consider the business value of the message itself and the abundance of current network resources. In this way, a comprehensive score is generated for each message to be processed that can fully reflect its admission value. Based on this, the DSCP (Differentiated Services Code Point) value and original length and other features of the message are first extracted, and combined with the weights preset by the network administrator, it is calculated by the following formula: in, is the preset weight vector, is the message feature vector, is the current number of tokens, is the token bucket capacity, and More specifically, the message utility and resource health joint evaluation unit is configured to: extract a differential services code point value from the classified message; combine the differential services code point value and the original length of the message metadata to obtain a message feature vector ; Based on the message feature vector, calculate the basic utility ; Based on the token bucket status, calculate the resource health ; Based on the resource health and the basic utility, calculate the admission score In this way, the system no longer outputs a simple yes or no judgment, but instead produces an admission score that combines the intrinsic priority of the message and the real-time health of the token bucket.
[0031] The second step of this mechanism is a probabilistic admission decision based on the logistic function. Considering that the admission score generated in the previous step is a raw score with a variable numerical range, it is not convenient to use it directly for admission decisions. Therefore, it is necessary to map this raw score to a standardized scale with intuitive physical meaning, so that the score can be smoothly converted into an admission probability between 0 and 1.
[0032] In the embodiment of the present application, the classic Logistic function is used to complete the conversion, and the formula can be expressed as: in, is the decision threshold, is the steepness factor of the curve. It cleverly constructs a soft decision boundary, the probability of admission of a packet with high score will tend to 1, while the probability of a packet with low score will tend to 0. This S-shaped probability curve elegantly realizes the smooth transition from absolute pass to absolute rejection, completely changing the rigid decision mode of the original mechanism.
[0033] The third step of the mechanism is random sampling admission and token consumption. Accordingly, after obtaining the admission probability , the system needs a specific execution mechanism to put this probability into practice. That is, the abstract probability must be converted into the final disposal action for the current packet. The purpose of execution is to decide the fate of the packet through a random sampling, while ensuring that the macro behavior of the system strictly conforms to the expectation defined by the probability, and taking physical resources as the final hard constraint.
[0034] The system makes a final decision according to the following conditions, which are expressed as: wherein, is the original length, is a random number uniformly distributed in the interval [0, 1]. More specifically, the random sample admission unit is configured to: generate a random number uniformly distributed in the interval [0, 1] ; in response to the random number being less than the admission probability and the current number of tokens of the token bucket state being greater than or equal to the original length , determine the classified packet as an admitted packet. Accordingly, it makes a final admission or discard decision under the guidance of probability, and accurately deducts the corresponding tokens when admitted, binding the probability model with the real resource consumption behavior. This random process containing hard resource check not only guarantees the flexibility and intelligence of the decision, but also safeguards the bottom line of non-overdraft of bandwidth control, finally outputting the admitted packet allowed to pass or executing the discard operation.
[0035] In summary, bandwidth access control has fundamentally evolved from a static, passive access control system to a dynamic, proactive intelligent scheduling system. Its core technical purpose is to overcome the problem of QoS failure caused by the original mechanism's inability to identify business differences and perceive resource pressure when facing a complex network environment. By introducing a joint evaluation based on message utility and resource health, combined with a probabilistic flexible decision-making model, this mechanism can effectively distinguish between high-value and low-value businesses, and give priority to protecting the data flow of critical applications when the network is congested, thereby significantly improving the utilization efficiency and value of limited bandwidth resources. Ultimately, it provides users with a more stable, reliable and differentiated high-quality network service experience without sacrificing data encryption security.
[0036] In the above-mentioned data bandwidth guarantee and encrypted transmission system 100 based on tunnel technology, the data encryption module 130 is used to encrypt the access message based on the tunnel strategy to obtain a security payload. It should be understood that since the previous steps have ensured the access qualification of the message and the fairness of bandwidth consumption, the data content of the message itself still exists in plain text, which is extremely susceptible to eavesdropping and tampering when transmitted through the public network, and cannot meet the basic requirements of secure communication. Therefore, in the technical solution of the present application, the access message is further encrypted based on the tunnel strategy to obtain a security payload, thereby applying core security protection to the data that has been approved for transmission. In this way, the confidentiality and integrity of user data can be guaranteed without affecting the determined bandwidth control strategy, so that the entire transmission system has both performance and security.
[0037] Specifically, in this embodiment of the present application, the data encryption module is configured to: search for an encryption algorithm and key based on the tunnel policy; extract payload data from the access message; and encrypt the payload data based on the encryption algorithm and key to obtain the secure payload. Specifically, the data encryption process is precisely executed according to the pre-set security policy. Specifically, a 512-byte message originating from the R&D department, previously determined to be accessible, is fed into the data encryption module. The module first searches for the associated security association based on the tunnel policy to which it belongs, namely the IPsec tunnel policy connecting the R&D department to the core server at headquarters. This security association explicitly defines the encryption algorithm used for this session as AES-256 and the corresponding encryption key. The module then strips the IP header from the access message and extracts all subsequent payload data. Finally, the module invokes the encryption engine, using the AES-256 algorithm and key obtained from the security association, to perform an encryption operation on the extracted payload data. The result is a ciphertext data block of the same length as the original payload, but with its contents completely obfuscated. This encrypted ciphertext data block is defined as a security payload and is ready for the subsequent tunnel encapsulation step.
[0038] In the above-mentioned data bandwidth guarantee and encrypted transmission system 100 based on tunnel technology, the tunnel encapsulation module 140 is used to perform tunnel encapsulation on the header information of the security payload and the access message to obtain the final tunnel message. It should be understood that since the previous step has converted the plaintext payload into a security payload, the security payload is still separated from the header information of the original message, and the header of the original message contains an internal private network address and cannot be routed on the public network. Therefore, in the technical solution of the present application, the security payload and the header information of the access message are further tunnel encapsulated to obtain the final tunnel message, so as to integrate the encrypted data with the original routing information and put a new shell that can be addressed on the public network. In this way, a final data packet with a complete structure, security, reliability and public routing can be generated, completing the last link of the entire secure transmission process.
[0039] Specifically, in an embodiment of the present application, the tunnel encapsulation module is used to: use the access message as an internal message; replace the payload data in the internal message with the security payload to obtain an updated internal message; generate a tunnel header based on the tunnel type; add the tunnel header before the updated internal message to obtain encapsulated data; and add an external IP header to the front end of the encapsulated data to obtain the final tunnel message.
[0040] Specifically, the original incoming message (containing the header with source IP address 192.168.1.100 and destination IP address 10.10.30.5, as well as the plaintext payload) is first logically treated as an internal message to be protected. The module then performs a core replacement operation: replacing the original plaintext payload within this internal message with the security payload generated in the previous step. This operation results in an updated internal message with the structure: [Original IP Header] + [Security Payload]. This entity retains the original routing information header, but its data content is now securely protected.
[0041] Next, based on the IPsec tunnel policy for the current session, a corresponding tunnel header, the ESP (Encapsulating Security Payload) header, is generated. This ESP header contains key information, such as the security parameter index. It serves as the glue and identifier between the old and new packets, instructing the receiving end how to process the encrypted data packet.
[0042] Next, the tunnel header (i.e., ESP header) generated in the previous step is appended to the front of the updated inner message generated in the first step. This operation forms an intermediate entity, the encapsulated data. Its structure is: [ESP header] + [updated inner message], which, when expanded, becomes [ESP header] [original IP header] [security payload].
[0043] Finally, to enable this inner packet to be transmitted over the public internet, the module generates a new outer IP header. The source address of this outer IP header is the public IP address of the local gateway device, and the destination address is the public IP address of the gateway on the headquarters server's network. This outer IP header is appended to the front of the encapsulated data. This completes the final tunnel message, a structured, hierarchical, and publicly routable packet. Its final structure is: [outer IP header][ESP header][original IP header][security payload]. This message is then delivered to the physical interface's transmit queue, ready for dispatch to its destination.
[0044] In the above-mentioned data bandwidth guarantee and encrypted transmission system 100 based on tunnel technology, the message delivery module 150 is used to deliver the final tunnel message to the sending queue of the physical interface. It should be understood that since all the previous steps have successfully converted the original message into a final tunnel message with a complete structure, encrypted content and public network routing capability, the message has reached its final form at the logical processing level. Therefore, in the technical solution of the present application, the final tunnel message is further delivered to the sending queue of the physical interface to complete the final handover from logical processing to physical transmission. In this way, it can be ensured that the message that has undergone a series of intelligent decision-making and security processing can be truly sent out, so that all the technical effects of the present invention can be finally realized in actual network communications.
[0045] Specifically, in one specific example of this application, the final tunnel message generated by the tunnel encapsulation module, whose external IP header points to the public network address of the headquarters gateway, is passed to the device's core forwarding engine. Based on the message's external destination IP address, the engine queries the device's global routing table and determines that the message must be sent from the physical interface connected to the internet service provider (e.g., GigabitEthernet0 / 0 / 1). The final tunnel message is then placed into the transmit queue associated with this physical interface. This transmit queue is a first-in, first-out buffer managed by the interface driver that temporarily stores packets to be sent. Finally, the network interface card hardware of this physical interface continuously removes messages from its transmit queue, serializes them into electrical or optical signals, and sends them out via physical media (such as optical fiber or Ethernet cable), starting their transmission journey across the public network.
[0046] In summary, the tunneling-based data bandwidth guarantee and encrypted transmission system described in the embodiments of the present application is described. By restructuring the data processing flow, it shifts the key decision point for bandwidth metering and admission control from after tunnel encapsulation to before encapsulation, thereby decoupling the two major functions of security encryption and bandwidth guarantee. Specifically, an intelligent pre-processing module performs policy matching before packets enter the tunnel encapsulation process to identify target traffic and accurately capture its original length, excluding any tunnel overhead. Based on this original length, the system not only provides fair and accurate bandwidth metering, addressing the issue of users' actual available bandwidth being compromised due to tunnel encapsulation overhead, but also makes dynamic, probabilistic, intelligent admission decisions based on the packet's service priority and the current state of network resources, thereby prioritizing the communication quality of high-value services during network congestion. Ultimately, only packets that pass this precise and intelligent screening are sent for encryption and encapsulation. This architecture of precise metering followed by secure encapsulation transforms traditional passive traffic limiting into proactive, refined resource scheduling, ensuring accurate delivery of promised bandwidth to users and improving service quality while ensuring data transmission security.
[0047] While various embodiments of the present disclosure have been described above, the above descriptions are illustrative, non-exhaustive, and not intended to be limiting of the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical applications, or improvements to existing technologies, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A data bandwidth guarantee and encryption transmission system based on tunnel technology, characterized in that: include: a policy matching module, configured to perform policy matching on the received original message to obtain a classified message and message metadata, wherein the message metadata includes an original length; a bandwidth metering and admission control module, configured to perform bandwidth metering and admission control based on the original length of the classified messages based on the message metadata to obtain admission messages; A data encryption module, configured to encrypt the access message based on a tunnel policy to obtain a security payload; a tunnel encapsulation module, configured to perform tunnel encapsulation on the security payload and the header information of the admission message to obtain a final tunnel message; The message delivery module is used to deliver the final tunnel message to the sending queue of the physical interface.
2. The data bandwidth guarantee and encryption transmission system based on tunnel technology according to claim 1 is characterized in that: The strategy matching module includes: A message header tuple extraction unit, configured to extract a message header tuple from the original message; a policy rule query unit, configured to query a policy rule library preconfigured in the device using the message header tuple as a query key, output a matching policy rule in response to a successful query, and designate the original message as a classified message; a data reading unit, configured to, in response to the matched policy rule being tunnel encapsulation, read the original length from the original message and extract a user identifier from the matched policy rule; An encapsulation unit is configured to encapsulate the user identifier and the original length into the message metadata.
3. The data bandwidth guarantee and encryption transmission system based on tunnel technology according to claim 2 is characterized in that: In response to an unsuccessful search, sending the original message to a standard IP forwarding table query and forwarding engine of the device; or In response to the matched policy rule being default forwarding, the original message is sent to the standard IP forwarding table query and forwarding engine of the device.
4. The data bandwidth guarantee and encryption transmission system based on tunnel technology according to claim 1 is characterized in that: The bandwidth metering and admission control module includes: A message utility and resource health joint evaluation unit, which is used to perform a joint evaluation of message utility and resource health on message metadata, classified messages, and token bucket status to obtain an admission score; an admission decision probability calculation unit, configured to perform a probabilistic admission decision on the admission score based on a logistic function to obtain an admission probability; The random sample admission unit is used to perform random sample admission and token consumption evaluation on the classified messages to obtain the admission messages.
5. The data bandwidth guarantee and encryption transmission system based on tunnel technology according to claim 4 is characterized in that: The message utility and resource health joint evaluation unit is used to: extracting a Differentiated Services Code Point value from the classified message; Combining the differentiated services code point value and the original length of the message metadata to obtain a message feature vector; Calculating a basic utility based on the message feature vector; Calculating resource health based on the token bucket status; The admission score is calculated based on the resource health and the basic utility.
6. The data bandwidth guarantee and encryption transmission system based on tunnel technology according to claim 4 is characterized in that: The random sample admission unit is used to: Generates random numbers uniformly distributed in the interval [0,1]; In response to the random number being smaller than the admission probability and the current number of tokens in the token bucket state being greater than or equal to the original length, the classified message is determined as an admission message.
7. The data bandwidth guarantee and encryption transmission system based on tunnel technology according to claim 1 is characterized in that: The data encryption module is used to: Find encryption algorithms and keys based on tunnel policies; extracting payload data from the admission message; The payload data is encrypted based on the encryption algorithm and the key to obtain the secure payload.
8. The data bandwidth guarantee and encryption transmission system based on tunnel technology according to claim 1 is characterized in that: The tunnel encapsulation module is used to: Using the admission message as an internal message; replacing the payload data in the internal message with the security payload to obtain an updated internal message; Generate a tunnel header based on the tunnel type; Adding the tunnel header before the updated internal message to obtain encapsulated data; An external IP header is added to the front end of the encapsulated data to obtain the final tunnel message.
Citation Information
Cited By
Electronic waybill submission system and method applied to dangerous cargo road transportation
CN121436845A
An electronic waybill submission system and method applied to dangerous goods road transport
CN121436845B