A method, device, equipment, and medium for sending non-sensitive data via QUIC

By detecting the target transmission parameters in the QUIC protocol and selecting the preset QUIC protocol for non-encrypted data transmission, the CPU performance waste and security risks caused by the QUIC protocol in non-sensitive data transmission are solved, and efficient and secure data transmission is achieved.

CN115766902BActive Publication Date: 2025-05-23PURPLE MOUNTAIN LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211418172.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-14
Publication Date
2025-05-23
Estimated Expiration
2042-11-14

AI Technical Summary

Technical Problem

In non-sensitive data transmission scenarios, the transport layer encryption of the QUIC protocol leads to waste of CPU performance, and the lack of a fully trusted communication environment in the cloud environment increases security risks.

Method used

By detecting the target transmission parameters in the client and server connection request, if the parameter exists between both parties, the preset QUIC protocol is selected for non-encrypted data transmission, which improves transmission efficiency and reduces CPU performance consumption.

Benefits of technology

It realizes that without affecting security, reduces CPU performance consumption of non-sensitive data transmission, improves transmission efficiency, and ensures the security of data transmission in a cloud environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766902B_ABST
    Figure CN115766902B_ABST
Patent Text Reader

Abstract

The present application discloses a method, device, equipment, and medium for sending non-sensitive data via QUIC, which relates to the field of communication technology and is applied to a server, including: obtaining a connection request sent by a client, and detecting whether the connection request contains target transmission parameters; if it is detected that the connection request contains target transmission parameters and the server also has the target transmission parameters, then selecting a preset QUIC protocol; and transmitting non-sensitive data to the client based on the non-encrypted data transmission method in the preset QUIC protocol. By detecting the two parties connected by the connection request, determining whether to start the preset QUIC protocol transmission by detecting whether both contain target transmission parameters, and transmitting non-sensitive data in an unencrypted manner through the preset QUIC protocol, the transmission efficiency is improved, resources are saved, and security is ensured, while the original message transmission is not affected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular to a method, apparatus, device, and medium for sending non-sensitive data via QUIC. Background Art

[0002] QUIC (Quick UDP Internet Connection) is a transmission standard for secure channels. It is favored by http service providers due to its advantages such as user-mode protocol implementation and 0-RTT reconnection. In the current draft regulations, all QUIC messages and data must be encrypted, but in non-sensitive data transmission scenarios, data generally does not require transport layer encryption. For example, for certain video data, for videos that require copyright protection, service providers and applications generally encrypt and decrypt according to copyright protection policies. If QUIC encrypts and decrypts again, a lot of CPU will be wasted. Although the server can offload it to hardware, it is still a waste. It is necessary to develop hardware or buy special encryption services in the cloud. Moreover, if the client is a mobile phone or computer, it cannot be offloaded, which only wastes CPU and power. For live broadcast videos that pursue real-time performance and do not care about copyright protection and transmission protection, encryption not only wastes resources, but also reduces real-time performance, which is not cost-effective in any case.

[0003] In the prior art, in the IETF personal draft, draft-banks-quic-disable-encryption proposes scenarios and methods for non-encryption, and adds the transmission parameter disable_1rtt_encryption for the client and the server to negotiate whether encryption is not required. If both parties agree not to encrypt, data is transmitted without encryption. The handshake message still needs to be encrypted to prevent it from being maliciously tampered with by the middleman to be non-encrypted. But in addition to the handshake message, there are many control messages that will expose attack points, such as flow control messages. Malicious middlemen can tamper with flow control messages, resulting in abnormal message sending and receiving; for example, data messages can modify the flow ID to exhaust the available flow, resulting in the inability of normal communication parties to open new flows; for example, address migration, malicious middlemen can initiate address migration and pretend to be a normal communication party to send and receive messages. This is an unacceptable risk for data transmission. The draft draft-banks-quic-disable-encryption specifies that the applicable scenario is a completely trusted communication environment or the application has encrypted the application data. However, as cloud environments become more and more common, multi-tenancy has resulted in no completely trusted communication environment in the cloud. Even the east-west traffic in private clouds is not absolutely secure. For data that users have encrypted, the QUIC protocol part of the message is still very vulnerable to attacks.

[0004] In summary, how to achieve unencrypted non-sensitive data transmission to reduce the CPU performance consumed by non-sensitive data transmission and ensure the security of non-sensitive data transmission is a technical problem to be solved in this field. Summary of the invention

[0005] In view of this, the purpose of the present invention is to provide a method, device, equipment, and medium for sending non-sensitive data through QUIC, which can realize non-encrypted non-sensitive data transmission, so as to reduce the CPU performance consumed by non-sensitive data transmission and ensure the security of non-sensitive data transmission. The specific scheme is as follows:

[0006] In a first aspect, the present application discloses a method for sending non-sensitive data through QUIC, which is applied to a server, including:

[0007] Obtaining a connection request sent by a client, and detecting whether the connection request contains target transmission parameters;

[0008] If it is detected that the connection request has the target transmission parameters and the server also has the target transmission parameters, selecting the preset QUIC protocol;

[0009] Transmit non-sensitive data to the client based on the non-encrypted data transmission method in the preset QUIC protocol.

[0010] Optionally, the method for sending non-sensitive data through QUIC further includes:

[0011] A new type field for non-encrypted data transmission is added to the original QUIC protocol to generate the preset QUIC protocol.

[0012] Optionally, adding a type field for the non-encrypted data transmission mode to the original QUIC protocol to generate a preset QUIC protocol includes:

[0013] The type field used for non-encrypted data transmission, the Stream ID and the Offset Length in the Stream frame are encrypted respectively to generate a preset QUIC protocol.

[0014] Optionally, transmitting the non-sensitive data to the client in a non-encrypted data transmission manner based on the preset QUIC protocol includes:

[0015] The Stream ID and the Offset Length are encrypted based on a preset encryption algorithm; and the non-sensitive data are stored in the Stream frame in a non-encrypted manner, so that the non-sensitive data can be transmitted to the client by transmitting the Stream frame.

[0016] Optionally, after transmitting the non-sensitive data to the client in the non-encrypted data transmission mode in the preset QUIC protocol, the method further includes:

[0017] The mask is calculated by the client, and the Stream ID and the Offset Length are decrypted using the mask. If the decryption is successful, the non-sensitive data in the Stream frame is saved.

[0018] In a second aspect, the present application discloses a method for sending non-sensitive data through the QUIC protocol, which is applied to a client, including:

[0019] Sending a connection request to the server, so that the server detects whether the connection request includes a target transmission parameter, and the server is configured to select a corresponding preset QUIC protocol when detecting that the connection request contains the target transmission parameter and the server also contains the target transmission parameter;

[0020] Receive non-sensitive data sent by the server through the non-encrypted data transmission method in the preset QUIC protocol.

[0021] In a third aspect, the present application discloses a device for sending non-sensitive data via QUIC, which is applied to a server, including:

[0022] A parameter detection module is used to obtain a connection request sent by a client and detect whether the connection request contains a target transmission parameter;

[0023] A transmission start module, configured to select a preset QUIC protocol if it is detected that the connection request has the target transmission parameters and the server also has the target transmission parameters;

[0024] A data transmission module is used to transmit non-sensitive data to the client based on the non-encrypted data transmission method in the preset QUIC protocol.

[0025] In a fourth aspect, the present application discloses an electronic device, including:

[0026] Memory, used to store computer programs;

[0027] A processor is used to execute the computer program to implement the steps of the aforementioned disclosed method of sending non-sensitive data via QUIC.

[0028] In a fifth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the steps of the aforementioned method for sending non-sensitive data via QUIC.

[0029] It can be seen that the present application discloses a method for sending non-sensitive data via QUIC, which is applied to the server, including: obtaining a connection request sent by a client, and detecting whether the connection request contains a target transmission parameter; if it is detected that the connection request contains the target transmission parameter and the server also contains the target transmission parameter, then selecting the preset QUIC protocol; based on the non-encrypted data transmission method in the preset QUIC protocol, the non-sensitive data is transmitted to the client. It can be seen that the present application detects the two parties connected by the connection request to determine whether to start the preset QUIC protocol transmission by detecting whether both contain the target transmission parameters, and transmits non-sensitive data in an unencrypted manner through the preset QUIC protocol, thereby improving transmission efficiency, saving resources, and ensuring security, while not affecting the original message transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0031] Figure 1 A flow chart of a method for sending non-sensitive data via QUIC disclosed in this application;

[0032] Figure 2 A flowchart of a specific method for sending non-sensitive data via QUIC disclosed in this application;

[0033] Figure 3 A flowchart of another specific method for sending non-sensitive data via QUIC disclosed in this application;

[0034] Figure 4 This is a schematic diagram of the structure of a device for sending non-sensitive data via QUIC disclosed in this application;

[0035] Figure 5 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0036] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0037] In the prior art, in the IETF personal draft, draft-banks-quic-disable-encryption proposes scenarios and methods for non-encryption, and adds the transmission parameter disable_1rtt_encryption for the client and the server to negotiate whether encryption is not required. If both parties agree not to encrypt, data is transmitted without encryption. The handshake message still needs to be encrypted to prevent it from being maliciously tampered with by the middleman to be non-encrypted. But in addition to the handshake message, there are many control messages that will expose attack points, such as flow control messages. Malicious middlemen can tamper with flow control messages, resulting in abnormal message sending and receiving; for example, data messages can modify the flow ID to exhaust the available flow, resulting in the inability of normal communication parties to open new flows; for example, address migration, malicious middlemen can initiate address migration and pretend to be a normal communication party to send and receive messages. This is an unacceptable risk for data transmission. The draft draft-banks-quic-disable-encryption specifies that the applicable scenario is a completely trusted communication environment or the application has encrypted the application data. However, as cloud environments become more and more common, multi-tenancy has resulted in no completely trusted communication environment in the cloud. Even the east-west traffic in private clouds is not absolutely secure. For data that users have encrypted, the QUIC protocol part of the message is still very vulnerable to attacks.

[0038] To this end, this application proposes a solution for sending non-sensitive data through QUIC, which can realize unencrypted non-sensitive data transmission, so as to reduce the CPU performance consumed by non-sensitive data transmission and ensure the security of non-sensitive data transmission.

[0039] Reference Figure 1 As shown, an embodiment of the present invention discloses a method for sending non-sensitive data through QUIC, which is applied to a server, including:

[0040] Step S11: obtaining a connection request sent by the client, and detecting whether the connection request contains target transmission parameters.

[0041] In this embodiment, the QUIC protocol parameters are configured in advance. When the client establishes a connection request, in addition to configuring the normal transmission parameters of the QUIC protocol in the connection request, it is also necessary to add the target transmission parameters, that is, the transmission parameter big_data. Therefore, after the server receives the connection request sent by the client, the connection request is detected to detect whether there is a transmission parameter big_data in addition to the normal transmission parameters in the connection request. After obtaining the connection request sent by the client, it also includes: establishing a connection with the client through unique identification information and based on the connection request. It can be understood that the QUIC connection can be connected through unique identification information. In this way, it can be avoided that the same client and server are connected during the transmission process. If the connection is interrupted in the middle, a random number can be pre-set as the unique identification information to connect between the two.

[0042] Step S12: If it is detected that the connection request has the target transmission parameters and the server also has the target transmission parameters, the preset QUIC protocol transmission is selected.

[0043] In this embodiment, if it is detected that there is a target transmission parameter in the connection request sent by the client, and the server also has the target transmission parameter, it proves that the function of unencrypted video transmission can be used, that is, the preset QUIC protocol transmission can be immediately started; if it is detected that the connection request does not have the target transmission parameter and / or the server does not have the target transmission parameter, the original QUIC protocol is selected. It can be understood that due to the limitation of the preset target transmission parameter, if it is detected that the connection request does not have the target transmission parameter, but the client has the target transmission parameter, the preset QUIC protocol transmission is not started, and the original QUIC protocol transmission is still used, that is, encrypted transmission; if it is detected that the connection request has the target transmission parameter, but the client does not have the target transmission parameter, the preset QUIC protocol transmission is not started, and the original QUIC protocol transmission is still used. The same logic is also used when the server negotiates and executes the client. That is, only when both the client and the server have the transmission parameter big_data can the preset QUIC protocol be enabled to transmit non-sensitive data without encryption. Sensitive data is privacy data, and non-sensitive data is non-privacy data, such as video on demand data, social news, Internet public content, blockchain public chain transaction data, etc.

[0044] In this embodiment, a type field for non-encrypted data transmission is added to the original QUIC protocol to generate a preset QUIC protocol. It can be understood that the preset QUIC protocol is obtained by modifying the original QUIC protocol. Specifically, when the original QUIC protocol performs application data transmission, the entire Stream frame is encrypted for transmission. The Stream frame contains Stream ID (data stream identifier), Offset Length (offset length) and data, etc. If the entire Stream frame is encrypted for transmission, the data data therein is also encrypted for transmission. In the specific scenario of this embodiment, there is no need to encrypt the data data therein, so the non-sensitive data transmission of the preset QUIC protocol is through encrypted QUIC messages, but non-sensitive data is not encrypted. That is, when the preset QUIC protocol is enabled, correspondingly, when non-sensitive data is transmitted, the data frame header is encrypted, and the data data is not encrypted. That is, the Stream ID, Offset Length, and Length and other strings are encrypted, while the non-sensitive data to be transmitted is skipped. Because there is not much difference between 0-RTT and 1-RTT for transmitting large amounts of data, the non-sensitive data in this embodiment is only transmitted in 1-RTT packets, that is, in short headers. By adding a type field in the short header, the type field is used to indicate whether it is a designated large amount of data transmission that does not need to be encrypted. For example, the type field in the short header is modified as follows:

[0045] The first eight short headers in the draft are:

[0046] |0|1|S|R|R|K|P|P|

[0047] 0 (plain text): fixed value, indicating a short packet header.

[0048] 1 (plain text): fixed value, used for verification, must be 1, and will be discarded if it is 0.

[0049] S (plain text): spin bit, used for delay measurement.

[0050] RR (ciphertext): fixed value, must be 0, other values ​​are considered connection errors.

[0051] K (ciphertext): indicates whether the key is updated.

[0052] PP (ciphertext): packet number length.

[0053] This plan is amended to:

[0054] |0|1|S|T|T|K|P|P|

[0055] 0 (plain text): unchanged, fixed value, indicating a short packet header.

[0056] 1 (plain text): unchanged, fixed value, used for verification, must be 1, and discarded if 0.

[0057] S (plain text): unchanged, spin bit, used for delay measurement.

[0058] TT (ciphertext): modified from the RR bit, corresponding to the type bit of the long packet header, 00 is the original encrypted message, 01 is non-sensitive data, that is, a new data transmission method is added in this application, and the specific content is specified by the user. This embodiment takes video on demand data as an example, and other values ​​are regarded as connection errors.

[0059] K (ciphertext): indicates whether the key is updated. For non-sensitive data messages, this bit is 0. If a data packet with a value of 1 is received, it is considered a connection error.

[0060] PP (ciphertext): unchanged, packet number length.

[0061] Among them, after the short header is modified, the content of the message encrypted in the original mode does not change. After RR is changed to TT, when the TT character is still 00, the use of K for the encrypted data packet does not change, and does not affect the original message format, nor does it affect its transmission and packet processing. It can be understood that when the value of TT in the protocol is detected to be 01, the unencrypted transmission mode for non-sensitive data is turned on. When the value of TT in the protocol is detected to be 00, the original encrypted transmission mode is still used for non-sensitive data. When the type bit in the short header is detected to be 01, it indicates that the type bit is a non-sensitive data transmission mode, and the video-on-demand data is packaged and transmitted to the client. It should be noted that when the TT bit in the short header is 01, the internal message is a large number of unencrypted data messages specified in this embodiment, that is, QUIC does not encrypt the video-on-demand data, but the application itself may encrypt the video-on-demand data.

[0062] Step S13: Transmitting non-sensitive data to the client based on the non-encrypted data transmission method in the preset QUIC protocol.

[0063] In this embodiment, after determining that the method for transmitting non-sensitive data this time is to transmit through the preset QUIC protocol, the non-sensitive data is transmitted to the client through the selected preset QUIC protocol; it should be noted that since the transmission is carried out through the preset QUIC protocol, the process of transmitting the Stream frame is orderly and complete, thereby achieving reliable transmission of non-sensitive data.

[0064] It can be seen that the present application discloses a method for sending non-sensitive data via QUIC, which is applied to the server, including: obtaining a connection request sent by a client, and detecting whether the connection request contains a target transmission parameter; if it is detected that the connection request contains the target transmission parameter and the server also contains the target transmission parameter, then selecting the preset QUIC protocol; based on the non-encrypted data transmission method in the preset QUIC protocol, the non-sensitive data is transmitted to the client. It can be seen that the present application detects the two parties connected by the connection request to determine whether to start the preset QUIC protocol transmission by detecting whether both contain the target transmission parameters, and transmits non-sensitive data in an unencrypted manner through the preset QUIC protocol, thereby improving transmission efficiency, saving resources, and ensuring security, while not affecting the original message transmission.

[0065] Reference Figure 2 As shown, the embodiment of the present invention discloses a specific method for sending non-sensitive data through QUIC. Compared with the previous embodiment, this embodiment further illustrates and optimizes the technical solution. Specifically:

[0066] Step S21: Encrypt the Stream ID and Offset Length based on a preset encryption algorithm.

[0067] In this embodiment, a type field for non-encrypted data transmission is added to the original QUIC protocol, and the type field for non-encrypted data transmission, the Stream ID and the Offset Length in the Stream frame are encrypted to generate a preset QUIC protocol. It can be understood that the encryption process first obtains a random number, wherein the method of obtaining the random number is to determine by sampling a fixed number of bits of data, specifically, the sampling operation is performed from the preset position after the end of the Offset Length, and 136 bits are sampled, wherein, when the sampled Stream ID and Offset are less than 128 bits, a part of the non-sensitive data data is skipped, and sampling is performed from a fixed position, so that the sampled random number is a fixed random number, which is used to calculate the key during encryption and decryption, and the sampled random number is a bit data including Fin Bit (end bit), Stream ID length (data stream identification length), and Offset length. When the sampling length caused by skipping non-sensitive data data for sampling is less than the preset sampling length, the server needs to make up for it. When the client receives a frame that is less than the sampling length, it needs to be discarded.

[0068] In this embodiment, after obtaining the random number, a preset encryption algorithm is used to generate a mask. Specifically, the preset encryption algorithm can be used to calculate the short header key or the package key and the random number to generate a mask of the corresponding Stream frame, that is, the encryption key of the Stream frame, to complete the header encryption of the Stream frame. Among them, the preset encryption algorithm can specifically include but is not limited to: AES (Advanced Encryption Standard) algorithm, Chacha2.0 algorithm (stream symmetric encryption). The process of calculating the mask of the Stream frame is to first take a sample of a certain length, that is, a random number, and then use the preset encryption algorithm to generate the mask to obtain the mask.

[0069] Step S22: After selecting the preset QUIC protocol transmission, the non-sensitive data is stored in the Stream frame in an unencrypted manner, so that the non-sensitive data can be transmitted to the client by transmitting the Stream frame.

[0070] In this embodiment, after selecting the preset QUIC protocol transmission, the non-sensitive data is packaged and stored in the Stream frame, and the transmission of the non-sensitive data is completed by transmitting the Stream frame to the client; it should be noted that a data packet can have multiple frames. It can be understood that since the message described in this embodiment is generally used to transmit a large amount of data, it does not involve packet merging and frame merging. There is only one QUIC packet in a UDP packet, and a QUIC packet only contains one Stream frame, so the frame length field is not required, and the length continues until the end of the UDP packet. Because it is only used to transmit application data, the frame type field can also be omitted, so the OFF bit in the frame type is also not applicable, and the Stream ID and Offset Length are required. Only the FIN bit is retained to mark the end of the data in the stream. Generally speaking, the Stream ID Length occupies 3 bits, and after adding one, it indicates the length of the Stream ID; the Offset Length occupies 4 bits, indicating the length of the Offset. When the Length is 0, there is no Offset field.

[0071] Step S23: The client calculates the mask, and uses the mask to decrypt the Stream ID and the Offset Length. If the decryption is successful, the non-sensitive data in the Stream frame is saved.

[0072] In this embodiment, after receiving the Stream frame, the mask is calculated again, and the Stream ID and the Offset Length in the Stream frame header are decrypted using the calculated mask. If the decryption is successful, the non-sensitive data in the Stream frame can be obtained. If the decryption fails, the non-sensitive data in the Stream frame cannot be obtained. Therefore, if the client does not receive part of the Stream frame due to some factors, the server can judge that a certain Stream frame has not been successfully received by the client through the packet number and confirmation response information fed back by the client. Since each Stream frame has a packet number, and the order of the packet numbers is monotonically increasing according to the order of the data in the transmission process, therefore, after the client receives multiple Stream frames, the asynchronously arrived Stream frames are sorted again by the Offset obtained by successful decryption, and combined to form complete non-sensitive data. Among them, the Offset is the data offset, which represents the offset of the Stream frame in the entire data.

[0073] It can be seen that in this embodiment, since Stream ID and Offset are required when transmitting non-sensitive data, StreamID and Offset are protected using packet header protection or other algorithms to increase the possibility of preventing this part of the QUIC protocol from being hacked, and to increase the possibility of various risks caused by the non-sensitive data transmission process being exposed due to the QUIC protocol being hacked.

[0074] Reference Figure 3 As shown, the embodiment of the present invention also discloses a method for sending non-sensitive data through QUIC, which is applied to a client and includes:

[0075] Step S31: Sending a connection request to the server, so that the server detects whether the connection request contains a target transmission parameter, and the server is used to select a corresponding preset QUIC protocol when detecting that the connection request contains the target transmission parameter and the server also has the target transmission parameter;

[0076] Step S32: Receive non-sensitive data sent by the server through the non-encrypted data transmission method in the preset QUIC protocol.

[0077] For more detailed processing procedures in steps S31 and S32, please refer to the aforementioned disclosed embodiments, which will not be described in detail here.

[0078] It can be seen that the present application discloses a method for sending non-sensitive data via QUIC, which is applied to the server, including: obtaining a connection request sent by a client, and detecting whether the connection request contains a target transmission parameter; if it is detected that the connection request contains the target transmission parameter and the server also contains the target transmission parameter, then selecting the preset QUIC protocol; based on the non-encrypted data transmission method in the preset QUIC protocol, the non-sensitive data is transmitted to the client. It can be seen that the present application detects the two parties connected by the connection request to determine whether to start the preset QUIC protocol transmission by detecting whether both contain the target transmission parameters, and transmits non-sensitive data in an unencrypted manner through the preset QUIC protocol, thereby improving transmission efficiency, saving resources, and ensuring security, while not affecting the original message transmission.

[0079] Reference Figure 4 As shown, an embodiment of the present invention discloses a device for sending non-sensitive data through QUIC, which is applied to a server, including:

[0080] The parameter detection module 11 is used to obtain the connection request sent by the client and detect whether the connection request contains the target transmission parameter;

[0081] A transmission start module 12, configured to select a preset QUIC protocol transmission if it is detected that the connection request has the target transmission parameter and the server also has the target transmission parameter;

[0082] The data transmission module 13 is used to transmit non-sensitive data to the client based on the non-encrypted data transmission method in the preset QUIC protocol.

[0083] Among them, for more specific working processes of the above-mentioned modules, please refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.

[0084] It can be seen that the present application also discloses a device, and the specific method adopted in the device is the method for sending non-sensitive data through QUIC in the above embodiment, including: obtaining a connection request sent by the client, and detecting whether the connection request contains the target transmission parameters; if it is detected that the connection request contains the target transmission parameters and the server also contains the target transmission parameters, then selecting the preset QUIC protocol; based on the non-encrypted data transmission method in the preset QUIC protocol, the non-sensitive data is transmitted to the client. It can be seen that the device detects the two parties connected by the connection request to determine whether to start the preset QUIC protocol transmission by detecting whether both contain the target transmission parameters, and transmits non-sensitive data in an unencrypted manner through the preset QUIC protocol, thereby improving transmission efficiency, saving resources, and ensuring security, while not affecting the original message transmission.

[0085] Furthermore, the present application also discloses an electronic device. Figure 5 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.

[0086] Figure 5 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the method for sending non-sensitive data via QUIC disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0087] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0088] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0089] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0090] Among them, the operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20, so as to realize the operation and processing of the massive data 223 in the memory 22 by the processor 21, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the method of sending non-sensitive data through QUIC performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks. In addition to data transmitted from an external device received by the electronic device, the data 223 can also include data collected by its own input and output interface 25.

[0091] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the method for sending non-sensitive data via QUIC disclosed above is implemented. For the specific steps of the method, reference may be made to the corresponding contents disclosed in the aforementioned embodiments, and no further description will be given here.

[0092] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0093] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to the function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application. The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be directly implemented with a software module executed by a hardware or processor, or a combination of the two. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the technical field.

[0094] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0095] The above is a detailed introduction to the method, device, equipment and medium for sending non-sensitive data via QUIC provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A method for sending non-sensitive data over QUIC, It is characterized in that Applied to the server, including: Obtaining a connection request sent by a client, and detecting whether the connection request contains target transmission parameters; If it is detected that the connection request has the target transmission parameters and the server also has the target transmission parameters, selecting the preset QUIC protocol; Transmitting non-sensitive data to the client based on the non-encrypted data transmission method in the preset QUIC protocol; Wherein, if it is detected that the connection request has the target transmission parameter and the server also has the target transmission parameter, before selecting the preset QUIC protocol, it also includes: A new type field for non-encrypted data transmission is added to the original QUIC protocol to generate the preset QUIC protocol.

2. The method for sending non-sensitive data via QUIC according to claim 1, It is characterized in that After detecting whether the connection request includes the target transmission parameter, the method further includes: If it is detected that the connection request does not have the target transmission parameters and / or the server does not have the target transmission parameters, the original QUIC protocol is selected.

3. The method for sending non-sensitive data via QUIC according to claim 1, It is characterized in that The process of adding a type field for non-encrypted data transmission mode in the original QUIC protocol to generate a preset QUIC protocol also includes: The type field used for non-encrypted data transmission, the Stream ID and the OffsetLength in the Stream frame are encrypted respectively to generate a preset QUIC protocol.

4. The method for sending non-sensitive data via QUIC according to claim 3, It is characterized in that The transmitting of non-sensitive data to the client in a non-encrypted data transmission manner based on the preset QUIC protocol includes: The Stream ID and the Offset Length are encrypted based on a preset encryption algorithm; and the non-sensitive data are stored in the Stream frame in a non-encrypted manner, so that the non-sensitive data can be transmitted to the client by transmitting the Stream frame.

5. The method for sending non-sensitive data via QUIC according to claim 4, It is characterized in that After transmitting the non-sensitive data to the client in the non-encrypted data transmission mode in the preset QUIC protocol, the method further includes: The mask is calculated by the client, and the Stream ID and the Offset Length are decrypted using the mask. If the decryption is successful, the non-sensitive data in the Stream frame is saved.

6. A method for sending non-sensitive data over QUIC, It is characterized in that Applied to the client, including: Sending a connection request to the server, so that the server detects whether the connection request includes a target transmission parameter, and the server is configured to select a corresponding preset QUIC protocol when detecting that the connection request contains the target transmission parameter and the server also contains the target transmission parameter; Receiving non-sensitive data sent by the server through the non-encrypted data transmission method in the preset QUIC protocol; Before detecting that the connection request has the target transmission parameter and the server also has the target transmission parameter, selecting the corresponding preset QUIC protocol, the method further includes: A new type field for non-encrypted data transmission is added to the original QUIC protocol to generate the preset QUIC protocol.

7. A device for sending non-sensitive data via QUIC, It is characterized in that Applied to the server, including: A parameter detection module, used to obtain a connection request sent by a client and detect whether the connection request contains a target transmission parameter; A transmission start module, configured to select a preset QUIC protocol if it is detected that the connection request has the target transmission parameters and the server also has the target transmission parameters; A data transmission module, configured to transmit non-sensitive data to the client based on a non-encrypted data transmission method in the preset QUIC protocol; The device for sending non-sensitive data via QUIC is also used to add a type field for non-encrypted data transmission in the original QUIC protocol to generate a preset QUIC protocol.

8. An electronic device, It is characterized in that include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the steps of the method for sending non-sensitive data via QUIC as described in any one of claims 1 to 6.

9. A computer-readable storage medium, It is characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the steps of the method for sending non-sensitive data via QUIC as described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Communication method and system based on QUIC transmission protocol

    CN112738004A

  • QUIC data transmission method and device

    CN113114701A