Network Packet Transmission Method Based on SDN and Blockchain

By combining software-defined networks and blockchain technology, the problems of instability in data transmission and difficulty in attack detection in the industrial Internet are solved, and reliable transmission and secure detection of key data packets are achieved.

CN115941721BActive Publication Date: 2025-07-18GUILIN UNIV OF ELECTRONIC TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211312125.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-25
Publication Date
2025-07-18
Estimated Expiration
2042-10-25

AI Technical Summary

Technical Problem

There are data transmission stability problems and the loss of key data packets caused by advanced persistent threat attacks in the industrial Internet, which affects the security of industrial facilities.

Method used

The software-defined network technology is combined with blockchain technology, and key data packets are separated through the SDN processor, and the blockchain system assists in transmission and confirmation is used to realize reliable transmission and abnormal detection of data packets.

Benefits of technology

Ensure that critical data packets are not lost at normal speeds, and abnormal data packets can be detected and processed in a timely manner, improving the security and stability of the industrial Internet.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941721B_ABST
    Figure CN115941721B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of cyberspace security technology, and particularly to a method for transmitting network data packets based on SDN and blockchain. First, on the basis of the original industrial Internet devices directly connected to the Internet, an SDN processor is added, and the traditional network transmission method is used, combined with blockchain technology to assist in transmission, ensuring that the critical data packets transmitted by the industrial Internet devices can be transmitted at a normal speed without loss of critical data packets. At the same time, the blockchain is used to record the data and the transmission records of the critical data packets recorded on the SDN device, realizing the effective detection of abnormal data packets and assisting the administrator to timely handle security risks. The present invention combines software-defined network technology and blockchain technology, uses SDN to separate critical data packets, and is assisted by the blockchain system for transmission and confirmation, solving the technical problems of possible data loss and difficulty in detecting and tracing attack data packets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cyberspace security, and particularly to a method for transmitting network data packets based on SDN and blockchain. Background Art

[0002] With the development of industrial Internet and 5G technology, more and more industrial control devices are gradually connected to the Internet for convenient use, and the scenarios involve important industries and fields such as steel, energy, transportation, and water conservancy. Due to some scenarios, such as in-vehicle industrial devices, there are a large number of mobile usage situations, and problems such as unstable reception and loss of key data transmission may occur.

[0003] In addition, China has suffered a large number of cyberattacks all year round, and the industrial Internet contains a large number of key facilities. Therefore, the industrial Internet is also one of the key targets of advanced persistent threat (APT) attack organizations. APT attack organizations can maliciously control devices by forging key instructions of industrial Internet devices, thus seriously endangering Internet security and industrial construction, with a huge impact.

[0004] Currently, in the industrial Internet, there are problems of data transmission stability due to device movement or insufficient network coverage in complex environments. At the same time, there are also problems of abnormal instruction execution of industrial Internet devices caused by customized cyberattacks launched by APT attack organizations. These problems pose great potential hazards to the safe and stable operation of industrial Internet devices. Summary of the Invention

[0005] The purpose of the present invention is to provide a method for transmitting network data packets based on SDN and blockchain. By combining software-defined network technology and blockchain technology, using SDN to separate key data packets and assisting in transmission and confirmation through the blockchain system, the technical problems of possible data loss and difficulties in detecting and tracing attack data packets are solved.

[0006] To achieve the above purpose, the present invention provides a method for transmitting network data packets based on SDN and blockchain, including the following steps:

[0007] Step 1: The first SDN processor receives network data packets;

[0008] Step 2: The first SDN processor checks whether the current network data packet is a key data packet.

[0009] If not, it is directly sent through the existing network;

[0010] If so, it enters the additional processing stage;

[0011] Step 3: The additional processing stage includes Process 1, Process 2, and Process 3, where Process 1 and Process 2 are carried out simultaneously;

[0012] In Process 1, the first SDN processor communicates with the second SDN processor and prepares data for Process 3;

[0013] In Process 2, the blockchain system is used to assist in transmission and confirmation to complete the sending of critical data packets;

[0014] Process 3 is used to complete detection and traceability processing.

[0015] Among them, in the network data packet transmission method based on SDN and blockchain, an SDN processor is added on the basis of the original industrial Internet device directly connected to the Internet. The first SDN processor is the SDN processor at the current network exit, and the second SDN processor is the SDN processor at the peer network entrance.

[0016] Among them, the network data packets are sent by industrial Internet devices, and the critical data packets are instruction data packets for operating the status of industrial Internet devices, including functions such as device status change and upper limit value modification.

[0017] Among them, the specific process of Process 1 includes the following steps:

[0018] The first SDN processor directly sends the critical data packets through the network port connected to the normal network;

[0019] After receiving the critical data packets, the second SDN processor will first forward them to the target device;

[0020] After the second SDN processor finishes sending, it records the sent critical data packets for timely detection of network attack data streams in Process 3.

[0021] Among them, the specific process of Process 2 includes the following steps:

[0022] The first SDN processor adds a destination network label to the critical data packets and transmits them to the blockchain system;

[0023] The blockchain system synchronizes and processes the data;

[0024] The second SDN processor checks the sending status of the critical data packets and uses the blockchain system to notify the completion of the network data packet sending process.

[0025] Among them, during the process of the blockchain system synchronizing and processing the data, the blockchain nodes in the blockchain system need to package the data packets with the same target network label that are not processed currently to merge the data packet transmissions with the same destination network.

[0026] Among them, the process by which the second SDN processor checks the sending situation of critical data packets includes the following steps:

[0027] The second SDN processor checks whether the critical data packet has been sent in step 2.

[0028] If the critical data packet has not been sent in step 2, then send the current data packet and record the sending record.

[0029] If the critical data packet has been sent in step 2, then skip the sending.

[0030] Among them, the specific process of process 3 includes the following steps:

[0031] Regularly and comprehensively compare the sent data packets with the data packets required to be sent on the blockchain.

[0032] If it is not found that the sent data packets do not match the data packets required to be sent on the blockchain, then clear the cached data that has been matched and continue the comprehensive comparison.

[0033] If it is found that the sent data packets do not match the data packets required to be sent on the blockchain, then mark the sent data packets that are not recorded on the blockchain.

[0034] Report the situation of the critical data packets with anomalies to the administrator.

[0035] Carry out traceability based on the information of the critical data packets where anomalies occur.

[0036] Timely clear the cached data of the processed critical data packets for sending.

[0037] The present invention provides a method for transmitting network data packets based on SDN and blockchain. First, on the basis of the original industrial Internet devices directly connecting to the Internet, an SDN processor is added, and the traditional network transmission method is used, combined with the blockchain technology to assist in transmission, ensuring that the critical data packets transmitted by the industrial Internet devices can not only be transmitted at a normal speed but also ensure that the critical data packets are not lost. At the same time, using the blockchain to record data and the sending records of the critical data packets recorded on the SDN device, it is possible to effectively detect the data packets with anomalies and assist the administrator in timely handling of potential safety hazards. The present invention combines the software-defined network technology and the blockchain technology, separates the critical data packets using SDN, and transmits and confirms them with the assistance of the blockchain system, solving the technical problems of possible data loss and difficulties in detecting and tracing attack data packets. Brief Description of the Drawings

[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0039] Figure 1 It is a schematic flowchart of the network data packet transmission method based on SDN and blockchain of the present invention.

[0040] Figure 2 It is a schematic diagram of the security problems faced by the industrial Internet and the overall architecture solved by the present invention.

[0041] Figure 3 It is the overall network data packet transmission processing flowchart of the present invention.

[0042] Figure 4 It is the change flowchart of the data packet transmitted via the blockchain in the present invention. Specific embodiments

[0043] The following will describe in detail the embodiments of the present invention. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions from beginning to end. The embodiments described below by referring to the drawings are exemplary and are intended to explain the present invention, and should not be construed as a limitation to the present invention.

[0044] Please refer to Figure 1 , the present invention provides a network data packet transmission method based on SDN and blockchain, including the following steps:

[0045] S1: The first SDN processor receives the network data packet;

[0046] S2: The first SDN processor checks whether the current network data packet is a critical data packet.

[0047] If not, it is directly sent through the existing network;

[0048] If so, it enters the additional processing stage;

[0049] S3: The additional processing stage includes Process 1, Process 2 and Process 3, where Process 1 and Process 2 are carried out simultaneously;

[0050] In Process 1, the first SDN processor communicates with the second SDN processor and prepares data for Process 3;

[0051] In Process 2, the blockchain system is used to assist in transmission and confirmation to complete the sending of critical data packets;

[0052] Use process 3 to complete detection and traceability processing.

[0053] Furthermore, the present invention proposes a specific embodiment, which will be described below in conjunction with the accompanying drawings and specific implementation steps:

[0054] Please refer to Figures 2 to 4 , Figure 2 which is a schematic diagram of the security problems faced by the industrial Internet and the overall architecture solved by the present invention. Regarding the connection and communication methods of industrial Internet devices, and the data exchange methods through SDN and blockchain, as Figure 2 shown.

[0055] Specifically, on the basis of the original industrial Internet devices directly connecting to the Internet, the present invention adds an SDN processor. The SDN processor (processing device) is a network device. In the series mode, the SDN program can directly read, add, delete, and modify the data transmitted in the network cable. Compared with traditional network devices, such as routers and switches, the processing method of SDN is more flexible and can perform data processing without paying attention to the network topology structure. Therefore, based on the characteristics of SDN, the present invention combines blockchain technology to achieve ensuring the reliability of critical data transmission, forming a traceable operation log, and timely discovering network problems.

[0056] After transforming the existing industrial Internet communication architecture, it is necessary to design the processing flow and data conversion method of the blockchain and the SDN processor. The entire data transmission flowchart is as Figure 3 shown, and there are 3 process processing branches in the transmission process. The following will describe in detail according to the data packet flow process:

[0057] 0.1 First, after the network data packet is sent by the industrial Internet device, it reaches the SDN processor at the current network exit.

[0058] 0.2 The SDN processor will first check whether the data packet to be processed currently is a critical data packet used by the industrial Internet device (the industrial Internet critical data packet is an instruction data packet for operating the state of the industrial Internet device, and its functions include, for example, device state change, upper limit value modification, etc.).

[0059] 0.3 If the SDN processor determines according to the set rules that the current data packet is not a critical data packet, it will directly skip the additional processing stage and send it directly through the existing network.

[0060] 0.4 If the SDN processor determines that the current data packet is a critical data packet, it will start to enter the additional processing stage.

[0061] During the additional processing stage, due to problems such as the huge time consumption of data synchronization in the blockchain system, unnecessary delays will occur in the original data transmission of industrial Internet devices. Therefore, to solve this problem, the method in Process 1 is used to send the data in the industrial Internet first.

[0062] 1.1 In Process 1, the SDN directly sends the data packets through the network ports connected to the normal network.

[0063] 1.2 After the SDN processor at the other end receives the key data packets, it will first forward them to the target device.

[0064] 1.3 After the SDN processor at the other end finishes sending, it records the sent data packets for use in promptly detecting network attack data streams in Process 3.

[0065] 2. While Process 1 is in progress, Process 2 will also be carried out simultaneously.

[0066] 2.1 In Process 2, the program on the SDN processor analyzes the current key network data packets to extract the target network address information of the network packets.

[0067] 2.2 Subsequently, according to the extracted target network address information, the network label information corresponding to the target network address on the SDN processor is queried.

[0068] 2.3 After obtaining the network label information corresponding to the target network address, a storage pair of the target network label and the network data packet is generated in the temporary data structure (the structure is as shown in the data packet structure between SDN device 1 and blockchain node 1 in Figure 4 ).

[0069] 2.4 After that, the SDN device transmits the data packet storage pair with the destination network label added currently to the blockchain node.

[0070] 2.5 To solve the problem of the low throughput (TPS, transactions per second) of the blockchain, the blockchain node needs to pack the data packets with the same target network label that are not processed currently to merge the data packet transmissions with the same destination network, thereby reducing the consumption of throughput.

[0071] 2.6 Subsequently, when it reaches the time for regular synchronization with the blockchain, the blockchain node will transmit the packed data that has not been uploaded to the blockchain to the blockchain.

[0072] 2.7 Wait for the blockchain system to synchronize the data.

[0073] 2.8 Each blockchain node regularly checks whether there is data in the blockchain system that has not been processed in the network it manages.

[0074] 2.9 After the peer blockchain node (since the data packet will be distributed to each blockchain node before reaching the peer network, but only the receiving blockchain nodes within the jurisdiction will perform subsequent processing, so the receiving blockchain nodes are simply referred to as peer blockchain nodes, for example Figure 4 blockchain node 2) of

[0075] finds the data that has not been processed in its jurisdiction network, separates the unprocessed data into storage pairs with target network labels and network data packets.

[0076] 2.10 The peer blockchain node sends the storage pairs of the target network label and the network data packet to the peer SDN device.

[0077] 2.11 The SDN device needs to check whether the data packet has been sent in step [1.2].

[0078] 2.12 If the data packet has not been sent in step [1.2], then send the current data packet and record the sending record.

[0079] 2.13 If the data packet has been sent in step [1.2], then skip the sending.

[0080] 2.14 After the SDN finishes processing the data sending, it needs to notify the blockchain node to mark the currently sent key data packet as sent.

[0081] 3. To effectively detect and trace attack data packets in a timely manner, it is necessary to additionally use process 3 to carry out relevant detection work.

[0082] 3.1 First, the SDN device needs to make a comprehensive judgment regularly based on the records of the sent data packets combined with the data packets recorded on the blockchain.

[0083] 3.2 If no mismatch is found between the records of the sent data packets and the data packets to be sent on the blockchain, then clear the cached matched data and continue to execute [3.1].

[0084] 3.3 If a mismatch is found between the records of the sent data packets and the data packets to be sent on the blockchain, then mark the data packets that have been sent and are not recorded on the blockchain.

[0085] 3.4 Since the key data packets where anomalies occur are very likely to be data packets sent by the attacker, they need to be reported to the administrator for timely security defect repair.

[0086] 3.5 Trace and trace according to the key data packet information where the anomaly appears to solve the network boundary security hidden danger.

[0087] 3.6 Timely clean up the cache of the sent key data packets that have been processed on the SDN device to improve the processing efficiency of the SDN device for abnormal data packets.

[0088] After being classified and processed by the three processes described above, the initially sent network data packets can be classified and identified according to different categories.

[0089] By combining software-defined network technology and blockchain technology, the present invention solves the security hidden danger in the industrial Internet and brings the following advantages:

[0090] 1. The present invention combines the normal transmission method with blockchain technology to ensure that the key data packets transmitted by industrial Internet devices can be transmitted at a normal speed and the key data packets are not lost.

[0091] 2. The present invention uses the blockchain to record data and the key data packet sending records recorded on the SDN device to effectively detect the data packets where anomalies appear and can assist the administrator to timely handle security hidden dangers.

[0092] 3. The present invention can effectively help industrial Internet devices to work normally in Delay Tolerant Networks (DTN).

[0093] The above-disclosed is only a preferred embodiment of the present invention. Of course, the scope of the rights of the present invention cannot be limited by this. Those of ordinary skill in the art can understand all or part of the processes of implementing the above embodiments, and the equivalent changes made according to the claims of the present invention still fall within the scope covered by the invention.

Claims

1. A network data packet transmission method based on SDN and blockchain, characterized in that, It includes the following steps: Step 1: The first SDN processor receives network data packets; Step 2: The first SDN processor checks whether the current network data packet is a critical data packet. If not, it is directly sent through the existing network; If so, it enters the additional processing stage; Step 3: The additional processing stage includes Process 1, Process 2, and Process 3, where Process 1 and Process 2 are carried out simultaneously; The specific process of Process 1 includes the following steps: The first SDN processor directly sends the critical data packet through the network port connected to the normal network; After receiving the critical data packet, the second SDN processor first forwards it to the target device; After the second SDN processor finishes sending, it records the sent critical data packet for use in promptly detecting network attack data streams in Process 3; The specific process of Process 2 includes the following steps: The first SDN processor adds a destination network label to the critical data packet and transmits it to the blockchain system; The blockchain system synchronizes and processes the data; The second SDN processor checks the sending status of the critical data packet and uses the blockchain system to notify the completion of the network data packet sending process; The specific process of Process 3 includes the following steps: Regularly comprehensively compare the sent data packets with the data packets required to be sent on the blockchain; If no mismatch is found between the sent data packets and the data packets required to be sent on the blockchain, clear the cached data that has been matched and continue the comprehensive comparison; If a mismatch is found between the sent data packets and the data packets required to be sent on the blockchain, mark the sent data packets that are not recorded on the blockchain; Report the situation of the critical data packet with an anomaly to the administrator; Carry out traceability based on the information of the critical data packet with an anomaly; Timely clear the cached sent critical data packet that has been processed; In Process 1, the first SDN processor communicates with the second SDN processor and prepares data for Process 3; In Process 2, use the blockchain system to assist in transmission and confirmation to complete the sending of the critical data packet; Use Process 3 to complete detection and traceability processing.

2. The method for transmitting network data packets based on SDN and blockchain according to claim 1, characterized in that On the basis of the original industrial Internet device directly connecting to the Internet, an SDN processor is added to the method for transmitting network data packets based on SDN and blockchain, where the first SDN processor is the SDN processor at the current network exit, and the second SDN processor is the SDN processor at the peer network entrance.

3. The method for transmitting network data packets based on SDN and blockchain according to claim 1, characterized in that The network data packets are sent by industrial Internet devices, and the critical data packets are instruction data packets for operating the status of industrial Internet devices, including functions such as device status change and upper limit value modification.

4. The method for transmitting network data packets based on SDN and blockchain according to claim 1, characterized in that ​ In the process of blockchain system synchronization and data processing, blockchain nodes in the blockchain system need to package data packets with the same target network label that are currently unprocessed, in order to merge the data packet transmissions for the same destination network.

5. The method for transmitting network data packets based on SDN and blockchain according to claim 1, wherein: The process of the second SDN processor checking the sending situation of critical data packets includes the following steps: The second SDN processor checks whether the critical data packet has been sent in step 2. If the critical data packet has not been sent in step 2, the current data packet is sent and the sending record is recorded. If the critical data packet has been sent in step 2, the sending is skipped.

Citation Information

Patent Citations

  • Software defined opportunity network DDoS defense method based on block chain

    CN110113328A

  • Private blockchain network DDoS defense method based on software definition

    CN111614610A