A data transmission device and method based on protocol obfuscation rule camouflage
Through client camouflage and proxy server group obfuscation rule camouflage, combined with encryption technology, the problem that existing encrypted data transmission protocols are easy to analyze is solved, and multi-dimensional security of data transmission is achieved.
Patent Information
- Application Number
- CN202210628239.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-02
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2042-06-02
AI Technical Summary
The access addresses, data packet structures, and traffic characteristics of existing encrypted data transmission protocols are fixed or follow certain patterns, which can be easily analyzed by criminals, leading to security risks of information leakage.
A data transmission device based on protocol obfuscation rules is used to generate a random network request address through client disguise, and a proxy server group is used to perform data analysis and multi-frequency bit traffic disguise to obfuscate the actual data transmission path. Asymmetric encryption and symmetric encryption are combined to improve security.
It achieves multi-dimensional security for data transmission, prevents illegal tracking and analysis, and ensures the identity, location and data security of data transmitters.
Smart Images

Figure CN114866220B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and in particular to a data transmission device and method based on protocol obfuscation rule camouflage. Background Art
[0002] With the continuous advancement of science and technology, a wide variety of applications have emerged on the Internet, resulting in the traffic used for data transmission on the Internet becoming complex and diverse. Using the Internet to transmit files / data has become an indispensable part of people's work and life. However, the data security protection that can be achieved by the currently widely used network transmission protocols is limited. Therefore, they are only suitable for ordinary digital office work and cannot meet the security protection requirements for data transmission between some confidential units and / or personnel in the country. At present, network application protocols have transitioned from traditional protocols such as HTTP, FTP, SMTP, and POP3 to protocols such as HTTPS, SSL, and VoIP. The existing HTTPS, SSL, and VoIP encrypted transmission protocols essentially use technical means such as key encryption of communication data, data integrity verification, and two-way authentication to ensure the security of data transmission.
[0003] However, in existing technologies, the structure, flow rate, and access address of data packets in data transmission channels are fixed and regular, and the data in these data transmission channels is not mixed with data traffic from other applications. Therefore, these data packets can be easily analyzed and / or located by some criminals, posing a security risk of information leakage. Therefore, it is necessary to improve the shortcomings of existing technologies.
[0004] In addition, on the one hand, there are differences in understanding among those skilled in the art; on the other hand, the applicant studied a large number of documents and patents when making the present invention, but due to space limitations, not all details and contents are listed in detail. However, this does not mean that the present invention does not have the characteristics of these prior arts. On the contrary, the present invention already has all the characteristics of the prior art, and the applicant reserves the right to add relevant prior art to the background technology. Summary of the Invention
[0005] When data is transmitted between clients and servers using the existing HTTPS protocol, the transmission of encrypted data relies on HTTPS, SSL, and the encrypted transmission protocol. However, if the encrypted data's access network address, packet structure, and traffic volume are fixed or patterned, the encrypted data can be easily deciphered by unauthorized actors. Once the encrypted data is analyzed and deciphered, it could pose a significant security risk to data transmission channels between nationally classified units, departments, or individuals, creating the risk of information leakage. The consequences of a data leak are disastrous.
[0006] In view of the shortcomings of the prior art, the present invention provides a data transmission device based on protocol obfuscation rules. The data transmission device at least includes a client, a proxy server group and a target server.
[0007] The client can disguise the data to be transmitted based on the obfuscation protocol and form the first data.
[0008] The client can utilize a combination of multiple algorithms to randomly change the access address of the data to be transmitted (such as a disguised network request address generated by the client) to ensure the randomness of the access address of the data to be transmitted.
[0009] The proxy server group is composed of multiple proxy servers. The proxy server can parse the first data according to the obfuscation protocol to obtain the real network request address corresponding to the data to be transmitted in the first data. At the same time, the client can also use relevant scripts to disguise the data to be transmitted into a data packet with the same or similar structure as the data packet of other applications, and the data to be transmitted interacts with the proxy server at irregular intervals to form the illusion of multi-frequency bit traffic disguised transmission, while the real data to be transmitted is hidden in batches in the above-mentioned disguised data packets, so that the real data to be transmitted is randomly forwarded to the proxy server group, thereby confusing criminals, preventing the data to be transmitted from being tracked and analyzed, and ultimately achieving the technical effect of ensuring the security of the data to be transmitted in multiple dimensions.
[0010] The target server can obtain the first data forwarded by the proxy server.
[0011] When the proxy server is capable of forwarding the first data to a target server corresponding to the real network request address based on the real network request address, the target server is capable of parsing the first data forwarded by the proxy server based on the obfuscation protocol and obtaining the data to be transmitted from the first data, thereby at least achieving protection of the data to be transmitted.
[0012] The present invention adopts a multi-node traffic obfuscation operation, that is, the client forwards the first data to the proxy server corresponding to the request address of the camouflaged network in the proxy server group based on the request address of the camouflaged network randomly generated by the obfuscation protocol, so as to ensure that the proxy server accessed by the first data / data to be transmitted is random each time, thereby achieving the structure and traffic rate of the data packet of the first data / data to be transmitted, the application data filled in the data to be transmitted (such as the filling data packet) and the address of the proxy server accessed by the data to be transmitted (such as the camouflaged network request address) are all random, and the real network request address corresponding to the data to be transmitted is hidden by the camouflaged network request address, ultimately achieving absolute obfuscation of the data to be transmitted and improving the security of data transmission.
[0013] In short, through the above configuration method, that is, through secondary packaging of the original https encrypted transmission protocol, adding multiple server nodes (such as a proxy server group), random filling of the data to be transmitted and / or multi-frequency Bit traffic disguised transmission and other technical means, the traffic, frequency, packet structure, etc. generated in the process of transmitting the data to be transmitted are irregular. The multiple server nodes will confuse criminals, making it impossible for criminals to find the real target server corresponding to the data to be transmitted. Ultimately, through the above multiple strategies, the data to be transmitted can be prevented from being analyzed by criminals and leaked, and the identity security, location security and data security of the data transmitter can be ensured from multiple dimensions.
[0014] According to a preferred embodiment, the obfuscation protocol includes at least a method for disguising the data to be transmitted and / or a method for switching the data transmission channel between the client, the proxy server, and the target server for transmitting the data to be transmitted. By obfuscating the data to be transmitted within the data transmission channel through the above methods, protection of the data to be transmitted is achieved.
[0015] According to a preferred embodiment, the first data includes at least data to be transmitted, a disguised network request address and an identifier, the disguised network request address corresponding to the real network request address in the data to be transmitted is generated by the client based on the obfuscation protocol, and the identifier is used to identify the disguise algorithm used by the client in the process of generating the disguised network request address, wherein the client can send the first data to at least one proxy server in the proxy server group corresponding to the disguised network request address based on the disguised network request address.
[0016] According to a preferred embodiment, the method for disguising data to be transmitted includes:
[0017] The client generates the disguised network request address by using the disguise algorithm to hide the real network request address corresponding to the data to be transmitted;
[0018] The client combines the data to be transmitted, the disguised network request address, and an identifier corresponding to the disguise algorithm into the first data.
[0019] According to a preferred embodiment, the method for disguising data to be transmitted further includes:
[0020] The client randomly fills the information to be transmitted in the data to be transmitted and / or transmits it in disguise of multiple-frequency bit traffic, thereby confusing the data to be transmitted and preventing it from being deciphered by lawless elements.
[0021] According to a preferred embodiment, the step of randomly filling the information to be transmitted in the data to be transmitted by the client includes:
[0022] Determining whether the data to be transmitted meets a triggering condition for triggering random filling;
[0023] Randomly dividing the information to be transmitted into a plurality of sub-data packets;
[0024] Generate padding data packets that need to be filled;
[0025] Randomly mixing the filling data packet into the plurality of sub-data packets;
[0026] The sub-data packets containing the padding data packet are sent to the proxy server or the target server in batches.
[0027] According to a preferred embodiment, the step of the client performing disguised transmission of the information to be transmitted in the data to be transmitted using multiple bit flows includes:
[0028] Determining whether the data to be transmitted meets the triggering condition for triggering disguised transmission of multi-frequency bit traffic;
[0029] Parse the target application's data packet format;
[0030] Disguising the information to be transmitted as a data packet of the target application based on the format of the data packet of the target application;
[0031] The disguised data to be transmitted is sent to the proxy server or the target server.
[0032] According to a preferred embodiment, when the target server has obtained the data to be transmitted, the target server can send second data to the proxy server, wherein the second data at least includes return data corresponding to the data to be transmitted in the first data, and the proxy server can obtain the second data and disguise the second data as third data based on the obfuscation protocol.
[0033] The present invention also provides a data transmission method based on protocol obfuscation rule camouflage. The method comprises:
[0034] The client disguises the data to be transmitted based on the obfuscation protocol and forms the first data;
[0035] The proxy server parses the first data according to the obfuscation protocol to obtain a real network request address corresponding to the first data and the data to be transmitted;
[0036] The target server obtains the first data forwarded by the proxy server.
[0037] According to a preferred embodiment, the method further comprises:
[0038] The proxy server forwards the first data to a target server corresponding to the real network request address based on the real network request address;
[0039] The target server parses the first data sent by the proxy server based on the obfuscation protocol, and obtains the data to be transmitted from the first data, so as to at least protect the data to be transmitted. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 This is a simplified schematic diagram of module connection relationships of a preferred embodiment provided by the present invention.
[0041] Reference Signs List
[0042] 1: Client 2: Proxy server group 3: Target server;
[0043] 200: Proxy server. DETAILED DESCRIPTION
[0044] The following is a detailed description with reference to the accompanying drawings.
[0045] Figure 1 A data transmission device based on protocol obfuscation rules is shown. The data transmission device at least includes a client 1, a proxy server group 2 and a target server 3.
[0046] The client 1 is configured to disguise the data to be transmitted based on the obfuscation protocol and form the first data.
[0047] The proxy server group 2 is composed of multiple proxy servers 200. The proxy server 200 can obtain the first data sent by the client 1. The proxy server 200 is configured to parse the first data according to the obfuscation protocol to obtain the real network request address corresponding to the data to be transmitted in the first data.
[0048] The target server 3 can obtain the first data forwarded by the proxy server 200 .
[0049] In the case where the proxy server 200 is able to forward the first data to the target server 3 corresponding to the real network request address based on the real network request address, the target server 3 is configured to be able to parse the first data forwarded by the proxy server 200 based on the obfuscation protocol, and obtain the data to be transmitted from the first data, so as to at least achieve protection of the data to be transmitted.
[0050] According to a preferred embodiment, the obfuscation protocol includes at least a method for disguising the data to be transmitted and / or a method for switching the data transmission channel between the client 1, the proxy server 200, and the target server 3. The obfuscation protocol obfuscates the data to be transmitted within the data transmission channel through the above methods, thereby protecting the data to be transmitted.
[0051] Since the security of the data transmission channel between the client 1 and the target server 3 is not high enough, the present invention proposes a rule for protecting the data to be transmitted in the data transmission channel, namely, an obfuscation protocol.
[0052] The purpose of switching the data transmission channel by the obfuscation protocol is to use the disguised network request address generated by the obfuscation protocol to forward the data to be transmitted to the target server 3 through the proxy server 200 corresponding to the randomly generated disguised network request address. In other words, the data to be transmitted is transmitted and obfuscated through multiple nodes (such as proxy server group 2). Proxy server group 2 includes multiple proxy servers 200, and the data to be transmitted can be forwarded to the target server 3 by any proxy server 200 in proxy server group 2. Therefore, the data transmission channel between client 1 and target server 3 can be changed arbitrarily, thereby ultimately achieving the data transmission channel of the data to be transmitted without any regularity, thereby achieving protection of the data to be transmitted.
[0053] The obfuscation protocol can also include an encryption method for performing secondary encryption on the data to be transmitted / first data. The encryption method can be an asymmetric encryption and / or a symmetric encryption algorithm.
[0054] The data in the data transmission channel at least includes data to be transmitted.
[0055] The data in the data transmission channel may also include first data.
[0056] According to a preferred embodiment, the first data includes at least the data to be transmitted, a disguised network request address, and an identifier. The disguised network request address corresponding to the actual network request address in the data to be transmitted is generated by client 1 based on an obfuscation protocol, and the identifier is used to identify the disguise algorithm used by client 1 in generating the disguised network request address. Client 1 can send the first data based on the disguised network request address to at least one proxy server 200 in proxy server group 2 corresponding to the disguised network request address.
[0057] The data to be transmitted at least includes a real network request address, which is the address of the target server 3 to which the data to be transmitted needs to be sent.
[0058] The data to be transmitted may also include but is not limited to: one or more of the following data: ciphertext returned based on the real network request address (such as HTTPS network request), CA digital certificate signature public key, identity information, random number, quantum key and information to be transmitted.
[0059] The disguised network request address is an address corresponding to any proxy server 200 that is randomly generated by the client 1 by disguising the real network request address in the data to be transmitted.
[0060] The types of information to be transmitted can be added or deleted according to the actual application scenario.
[0061] For example, the data to be transmitted may include information to be transmitted and a real network request address; in this case, the first data includes information to be transmitted, the real network request address, and a disguised network request address.
[0062] The client 1 , the proxy server 200 and the target server 3 can all transmit the data to be transmitted based on the HTTPS protocol and the obfuscation protocol.
[0063] According to a preferred embodiment, the method for disguising data to be transmitted includes:
[0064] Client 1 generates a disguised network request address through a disguise algorithm to hide the real network request address corresponding to the data to be transmitted;
[0065] The client 1 combines the data to be transmitted, the disguised network request address, and the identifier corresponding to the disguise algorithm into first data.
[0066] Preferably, both the proxy server 200 and the target server 3 can disguise the real network request address in the data to be transmitted based on the obfuscation protocol.
[0067] To ensure efficient data transmission, the HTTPS protocol uses symmetric encryption for all data transmissions after successful certificate verification. That is, the HTTPS protocol only uses asymmetric encryption during the certificate verification phase. If a criminal (such as a hacker) intercepts the data being transmitted during this process, the data is likely to be deciphered within a certain period of time, as the keys used in symmetric encryption are pseudo-random numbers and computer technology is currently undergoing rapid development.
[0068] Therefore, the present invention performs asymmetric encryption on the data to be transmitted after it has already been symmetrically encrypted. This operation not only does not significantly affect the efficiency of data transmission, but also greatly improves the security of data transmission. That is, even if criminals (such as hackers) intercept the symmetrically and asymmetrically encrypted data to be transmitted, they will not be able to decrypt the data to be transmitted.
[0069] Before the client 1 sends the data to be transmitted to the proxy server 200, the client 1 first encrypts the data to be transmitted using asymmetric encryption and symmetric encryption algorithms, and then the client 1 rewrites the real network request address in the data to be transmitted to disguise / hide the real network request address, and generates a disguised network request address.
[0070] The disguised network request address is randomly generated by client 1 using a disguise algorithm.
[0071] The above cloaking algorithms have specific identifiers in the obfuscation protocol.
[0072] Particularly preferably, the first data can further include: an identifier of a camouflage algorithm used by the client 1 to camouflage the data to be transmitted at that time.
[0073] The identifier can be one or more characters such as numbers and letters.
[0074] For example, if the identifier is "A", it means that the camouflage algorithm used by client 1 to camouflage the data to be transmitted is the first camouflage algorithm; if the identifier is "B", it means that the camouflage algorithm used by client 1 to camouflage the data to be transmitted is the second camouflage algorithm, and so on.
[0075] The camouflage algorithm can be flexibly selected based on the needs of the actual application scenario. The camouflage algorithm can be a message digest algorithm, a secure hash algorithm, a message authentication code algorithm, a segmentation algorithm, a parallel splicing algorithm, etc. When the camouflage request of the sender of the information to be transmitted, client 1, is camouflaged using the camouflage algorithm and sent to a server in the server group 2, server 2 finds the camouflage algorithm used by the corresponding sender of the information to be transmitted, client 1, based on the camouflage algorithm identifier contained in the first camouflage data. Then, based on the camouflage algorithm, the real address of the receiver of the information to be transmitted, client 1, is parsed. Then, server 2 sends the first camouflage data to the corresponding receiver of the information to be transmitted, client 1, based on the parsed real address of the receiver of the information to be transmitted.
[0076] For example, when there is only one target server 3, the disguised network request address indicates that the first data is forwarded to the target server 3 via a proxy server 200 in the proxy server group 2; when there are more than one target servers 3, the disguised network request address indicates which proxy server 200 the first data is forwarded to which target server 3.
[0077] The client 1 disguises the real network request address in the data to be transmitted by rewriting the interface of the network request.
[0078] The client 1 sends the first data to the proxy server 200 corresponding to the disguised network request address based on the disguised network request address. The proxy server 200 corresponding to the disguised network request address can parse the first data based on the obfuscation protocol to obtain the real network request address corresponding to the data to be transmitted.
[0079] For example, the address of the target server 3 corresponding to a certain data to be transmitted (ie, the real network request address) is www.cloudfront.com. The disguised network request address can be any one or more of the disguised addresses such as a.com, b.net, and c.org.
[0080] After the proxy server 200 corresponding to the disguised network request address in the proxy server group 2 receives the first data sent by the client 1, the proxy server 200 can obtain the identifier in the first data based on the obfuscation protocol, and use the identifier to parse the disguise algorithm used by the client 1 corresponding to the first data. Then, based on the disguise algorithm, it can parse the first data (such as the disguised network request address in the first data) to determine the real network request address corresponding to the data to be transmitted. Afterwards, the one or more proxy servers 200 forward the first data in batches to the target server 3 corresponding to the real network request address based on the real network request address corresponding to the data to be transmitted.
[0081] Preferably, the proxy server 200 and the target server 3 may be servers of the same model.
[0082] Preferably, the work responsibilities of the proxy server 200 and the target server 3 can be switched. For example, the target server 3 can serve as a proxy server 200 in the proxy server group 2; and a proxy server 200 in the proxy server group 2 can also serve as the target server 3.
[0083] Through the above configuration, the client 1 can use multiple algorithms to disguise the real network request address in the data to be transmitted, and can add a disguised network request address randomly generated by the disguise algorithm to the first data, thereby ensuring the randomness of the proxy server 200 / target server 3 accessed by the client 1, and at the same time preventing the data to be transmitted from being analyzed by criminals to obtain the real network request address corresponding to the data to be transmitted and the target server 3 corresponding to the real network request address; at the same time, the client 1 and the proxy server 200 can both disguise the real network request address in the data to be transmitted based on the obfuscation protocol, and forward the first data to the target server 3 corresponding to the real network request address via the proxy server 200 corresponding to the disguised network request address through the randomly generated disguised network request address, so as to hide the real network request address of the data to be transmitted and prevent the leakage of the data to be transmitted.
[0084] In the prior art, the access address of the data transmitted by the client 1 is often fixed. However, in the present invention, the data to be transmitted sent by the client 1 is transmitted to the target server 3 via any one or more proxy servers 200 in the proxy server group 2. Since the first data corresponding to the data to be transmitted can be forwarded to the target server 3 corresponding to the actual network request address via a random proxy server 200, the data transmission channel used to transmit the data to be transmitted is not fixed. In other words, the data transmission channel in the present invention is irregular, thereby preventing criminals from obtaining the data to be transmitted (such as the actual network request address) or obtaining related information about the data to be transmitted from the fixed data transmission channel.
[0085] When there is only one proxy server 200, although the transmission path of the data to be transmitted cannot be randomly changed, the traffic camouflage and random packet filling methods can still be applied to the data to be transmitted by the client 1, the proxy server 200 and the target server 3 to protect the data to be transmitted.
[0086] According to a preferred embodiment, the method for disguising data to be transmitted further includes:
[0087] The client 1 randomly fills the information to be transmitted in the data to be transmitted and / or transmits the data in disguise of multiple-frequency bit traffic, so as to confuse the data to be transmitted and prevent it from being deciphered by criminals.
[0088] Client 1 can use scripts to disguise the data being transmitted as packets with a different structure (e.g., packets from video or music applications) and interact with proxy server 200 at irregular intervals to create the illusion of multiple bits being transmitted. Furthermore, client 1 can randomly mix data from other applications into the data being transmitted. Specifically, after the data being transmitted is divided into multiple sub-packets, client 1 hides these sub-packets in batches within packets from other applications. These packets are then transmitted in segments to proxy server 200 or target server 3, thereby obfuscating the data being transmitted and preventing it from being deciphered by unauthorized parties.
[0089] The existing technology does not mix the data to be transmitted with the data traffic of other applications during the transmission of the data to be transmitted, and the structure and flow rate of the data to be transmitted during the transmission process are also regular. Therefore, the data to be transmitted can be easily analyzed by criminals to find the relevant patterns of the data to be transmitted, resulting in the leakage of the data to be transmitted. The present invention uses an obfuscation protocol, that is, randomly padding the information to be transmitted in the data to be transmitted and / or disguising the transmission of multiple bit flows, so that the structure and flow rate of the data to be transmitted during the transmission process are irregular, thereby achieving obfuscation of the data to be transmitted and preventing the data to be transmitted from being deciphered by criminals.
[0090] According to a preferred embodiment, the step of randomly filling the information to be transmitted in the data to be transmitted by the client 1 includes:
[0091] S11: Determine whether the data to be transmitted meets the triggering condition for triggering random filling;
[0092] S12: randomly dividing the information to be transmitted into multiple sub-data packets;
[0093] S13: Generate a padding data packet that needs to be filled;
[0094] S14: randomly mixing the filling data packet into the multiple sub-data packets;
[0095] S15: Sending multiple sub-data packets including the padding data packet to the proxy server 200 or the target server 3 in batches.
[0096] S11: Client 1 determines whether the data to be transmitted meets the triggering conditions for triggering random filling. The triggering conditions can be flexibly set according to the actual application scenario. For example, client 1 can add a specific trigger identifier to the data to be transmitted. If client 1 identifies the data to be transmitted and finds that the above trigger identifier is included in the first data, then the above data to be transmitted is identified by client 1 as data to be transmitted that meets the triggering conditions for triggering random filling; if client 1 identifies the data to be transmitted and finds that the above trigger identifier is not included in the first data, then the above data to be transmitted is identified by client 1 as data to be transmitted that does not meet the triggering conditions for triggering random filling.
[0097] The triggering conditions mentioned above may be randomly generated by a corresponding algorithm, that is, the random packet filling and transmission operation of the client 1 on the data to be transmitted is random.
[0098] S12: randomly dividing the information to be transmitted into a plurality of sub-data packets. By setting this way, the size and number of the sub-data packets can be made irregular.
[0099] S13: Generate a padding data packet to be filled. If client 1 analyzes the data to be transmitted and determines that the data to be transmitted meets the preset trigger conditions, client 1 generates a padding data packet to be filled with the data to be transmitted / first data according to a corresponding algorithm. The padding data packet can have a structure identical or similar to that of other applications (such as video, music, etc.). The identical or similar structure refers to the same or similar characteristics of the data packets, such as structure, flow rate, and frequency.
[0100] S14: Randomly mix the padding data packet into the multiple sub-data packets. The number of padding data packets filled between two sub-data packets is random.
[0101] S15: Send the sub-data packets containing the padding data packet to the proxy server 200 or the target server 3 in batches. The time at which the client 1 sends the sub-data packets containing the padding data packet to the proxy server 200 or the target server 3 may also be random.
[0102] Preferably, the proxy server 200 or the target server 3 can receive the multiple sub-data packets in a segmented manner, so as to reassemble the multiple sub-data packets into the first data.
[0103] Through the above configuration, the real data to be transmitted is randomly mixed into the data packets of other applications, and the first data is forwarded in batches to one or more proxy servers 200 at irregular intervals (for example, the sending time of the first data is also randomly set by a random algorithm), so that the structure of the data packet and the flow rate of the transmitted first data are irregular, thereby achieving the purpose of confusing criminals.
[0104] According to a preferred embodiment, the step of the client 1 performing camouflaged transmission of the information to be transmitted in the data to be transmitted with multiple bit flows includes:
[0105] S21: Determine whether the data to be transmitted meets the triggering condition for triggering multi-frequency bit traffic disguised transmission;
[0106] S22: parsing the format of the data packet of the target application;
[0107] S23: Disguising the information to be transmitted as a data packet of the target application based on the format of the data packet of the target application;
[0108] S24: Send the disguised data to be transmitted to the proxy server 200 or the target server 3.
[0109] S21: Client 1 determines whether the data to be transmitted at that time meets the triggering conditions for triggering Bit traffic disguised transmission. The triggering conditions can be set manually according to the actual application scenario. For example, client 1 can add a specific trigger identifier to the data to be transmitted. If client 1 identifies the data to be transmitted and finds that the first data contains the above-mentioned trigger identifier, then the above-mentioned data to be transmitted is identified by client 1 as the data to be transmitted that meets the triggering conditions for disguised transmission using Bit traffic; if client 1 identifies the data to be transmitted and finds that the first data does not contain the above-mentioned trigger identifier, then the above-mentioned data to be transmitted is identified by client 1 as the data to be transmitted that does not meet the triggering conditions for disguised transmission using Bit traffic.
[0110] The triggering condition can be randomly generated by a corresponding algorithm, that is, the operation of the client 1 to perform bit traffic disguised transmission on the data to be transmitted is random.
[0111] The client 1 / proxy server 200 / target server 3 can disguise the traffic of the data packets to be transmitted by using methods such as traffic filling, traffic normalization and traffic masking.
[0112] The client 1 / proxy server 200 / target server 3 may also disguise the traffic of the data packets to be transmitted by methods such as rerouting, adding junk packets, dropping packets, including merging, packet fragmentation, packet disorder, flow mixing, flow segmentation and flow merging.
[0113] Particularly preferably, the method adopted by the client 1 / proxy server 200 / target server 3 of the present invention to disguise the data to be transmitted is to disguise the encrypted data to be transmitted into a data packet with the same or similar format / structure as the data packet of other applications (such as video, music and other applications).
[0114] For example, client 1 needs to disguise the data to be transmitted into the format of the data packet of the target application (such as a music application). Client 1 can first parse the format / structure of the data packet of the target application, and then disguise the data to be transmitted into the format / structure of the data packet of the music application, so that criminals cannot identify the disguised data to be transmitted, and ultimately achieve the purpose of confusing data eavesdroppers.
[0115] Through the above configuration, when the client 1 / proxy server 200 / target server 3 transmits the data to be transmitted or the first data, the encrypted data packet of the data to be transmitted or the first data is disguised as a data packet with the same / similar structure as other applications, and / or the encrypted data packet of the data to be transmitted or the first data is hidden in the data packet of other applications, and then forwarded to the proxy server 200 in batches, so as to confuse data eavesdroppers.
[0116] According to a preferred embodiment, when the target server 3 has obtained the data to be transmitted, the target server 3 can send second data to the proxy server 200. The second data includes at least the return data corresponding to the data to be transmitted in the first data. The proxy server 200 can obtain the second data and disguise the second data as third data based on the obfuscation protocol.
[0117] Preferably, the data to be transmitted is used to request second data from the target server 3 .
[0118] The third data at least includes return data corresponding to the data to be transmitted.
[0119] In response to the data to be transmitted, the target server 3 can send return data corresponding to the first data to the proxy server 200 .
[0120] The target server 3 can also disguise the returned data based on the obfuscation protocol to generate second data.
[0121] The proxy server 200 can obtain the second data and disguise the second data as third data based on the obfuscation protocol.
[0122] The third data can be transmitted to the client 1 by the proxy server 200 .
[0123] Preferably, the second data may also include but is not limited to: CA digital certificate signature public key, identity information, random number, quantum key and identifier of the disguise algorithm used by the target server 3 this time, etc.
[0124] Preferably, the data to be transmitted is used to request second data from the target server 3 .
[0125] Preferably, the target server 3 can also encrypt the second data in an asymmetric encryption manner and a symmetric encryption manner.
[0126] The third data at least includes return data corresponding to the data to be transmitted in the first data.
[0127] Preferably, the third data may also include but is not limited to: CA digital certificate signature public key, identity information, random number, quantum key, identifier of the camouflage algorithm used by the proxy server 200 this time, etc.
[0128] The disguise and transmission process of the second data and the third data is the same as that of the first data, so the disguise and transmission process of the second data and the third data will not be described in detail here.
[0129] The present invention also provides a data transmission method based on protocol obfuscation rule camouflage. The method includes:
[0130] The client 1 disguises the data to be transmitted based on the obfuscation protocol and forms the first data;
[0131] The proxy server 200 parses the first data according to the obfuscation protocol to obtain a real network request address corresponding to the data to be transmitted in the first data;
[0132] The target server 3 obtains the first data forwarded by the proxy server 200 .
[0133] According to a preferred embodiment, the method further comprises:
[0134] The proxy server 200 forwards the first data to the target server 3 corresponding to the real network request address based on the real network request address.
[0135] The target server 3 parses the first data sent by the proxy server 200 based on the obfuscation protocol, and obtains the data to be transmitted from the first data, so as to at least achieve protection of the data to be transmitted.
[0136] It should be noted that the above-mentioned specific embodiments are exemplary, and those skilled in the art can come up with various solutions inspired by the disclosure of the present invention, and these solutions also fall within the scope of the disclosure of the present invention and fall within the scope of protection of the present invention. Those skilled in the art should understand that the present invention specification and its drawings are illustrative and do not constitute a limitation on the claims. The scope of protection of the present invention is defined by the claims and their equivalents. The present invention specification contains multiple inventive concepts, such as "preferably", "according to a preferred embodiment" or "optionally", which means that the corresponding paragraph discloses an independent concept, and the applicant reserves the right to file a divisional application based on each inventive concept.
Claims
1. A data transmission device based on protocol obfuscation rules, characterized in that: At least: A client (1) is configured to disguise the data to be transmitted based on an obfuscation protocol and form first data; a proxy server group (2), composed of a plurality of proxy servers (200), wherein the proxy servers (200) are configured to parse the first data according to the obfuscation protocol to obtain a real network request address in the first data corresponding to the data to be transmitted; A target server (3) is capable of acquiring the first data forwarded by the proxy server (200); Wherein, when any one or more of the proxy servers (200) in the proxy server group (2) can forward the first data in batches to the target server (3) corresponding to the real network request address based on the real network request address, the data transmission channel between the client (1) and the target server (3) is arbitrarily changed, The target server (3) is configured to parse the first data forwarded by the proxy server (200) based on the obfuscation protocol and obtain the data to be transmitted from the first data, so as to at least protect the data to be transmitted.
2. The device according to claim 1, characterized in that The obfuscation protocol at least includes a method for disguising the data to be transmitted and / or a method for switching a data transmission channel for transmitting the data to be transmitted between the client (1), the proxy server (200) and the target server (3), so as to obfuscate the data to be transmitted in the data transmission channel by the method and thereby protect the data to be transmitted.
3. The device according to claim 1 or 2, characterized in that The first data at least includes data to be transmitted, a disguised network request address and an identifier, wherein the disguised network request address corresponding to the real network request address in the data to be transmitted is generated by the client (1) based on the obfuscation protocol, and the identifier is used to identify the disguise algorithm used by the client (1) in the process of generating the disguised network request address, wherein the client (1) can send the first data to at least one proxy server (200) in the proxy server group (2) corresponding to the disguised network request address based on the disguised network request address.
4. The device according to claim 3, characterized in that The method for disguising data to be transmitted includes: The client (1) generates the disguised network request address through the disguise algorithm to hide the real network request address corresponding to the data to be transmitted; The client (1) combines the data to be transmitted, the disguised network request address, and the identifier corresponding to the disguise algorithm into the first data.
5. The device according to claim 4, characterized in that The method for disguising the data to be transmitted further includes: The client (1) randomly fills the information to be transmitted in the data to be transmitted and / or transmits it in a multi-frequency bit flow disguised manner, so as to confuse the data to be transmitted and prevent it from being deciphered by criminals.
6. The device according to claim 5, characterized in that The step of randomly filling the information to be transmitted in the data to be transmitted by the client (1) comprises: Determining whether the data to be transmitted meets a triggering condition for triggering random filling; Randomly dividing the information to be transmitted into a plurality of sub-data packets; Generate padding data packets that need to be filled; Randomly mixing the filling data packet into the plurality of sub-data packets; The sub-data packets containing the padding data packets are sent to the proxy server (200) or the target server (3) in batches.
7. The device according to claim 5, characterized in that The step of the client (1) performing multi-frequency bit flow disguised transmission on the information to be transmitted in the data to be transmitted comprises: Determine whether the data to be transmitted meets the triggering condition for triggering multi-frequency bit traffic disguised transmission; Parse the target application's data packet format; Disguising the information to be transmitted as a data packet of the target application based on the format of the data packet of the target application; The disguised data to be transmitted is sent to the proxy server (200) or the target server (3).
8. The device according to claim 7, characterized in that When the target server (3) has obtained the data to be transmitted, the target server (3) can send second data to the proxy server (200), wherein the second data at least includes return data corresponding to the data to be transmitted in the first data, and the proxy server (200) can obtain the second data and disguise the second data as third data based on the obfuscation protocol.
9. A data transmission method based on protocol obfuscation rule camouflage, characterized in that: The method comprises: The client (1) disguises the data to be transmitted based on the obfuscation protocol and forms first data; Any one or more proxy servers (200) in the proxy server group (2) parses the first data according to the obfuscation protocol to obtain a real network request address in the first data corresponding to the data to be transmitted; The target server (3) obtains the first data forwarded by the proxy server (200) in batches, and the data transmission channel between the client (1) and the target server (3) is changed arbitrarily.
10. The method according to claim 9, characterized in that The method further comprises: The proxy server (200) forwards the first data to a target server (3) corresponding to the real network request address based on the real network request address; The target server (3) parses the first data sent by the proxy server (200) based on the obfuscation protocol, and obtains the data to be transmitted from the first data, so as to at least protect the data to be transmitted.
Citation Information
Patent Citations
Video data processing method, device and system
CN103686198A