End-to-End Encryption Network Data Synchronization Method, Apparatus, Electronic Device, and Storage Medium

By performing two-layer encryption processing and routing tag forwarding on data nodes in an end-to-end encryption network, the problem that data transmission paths can be perceived is solved, and the security and integrity of data transmission are achieved.

CN116112207BActive Publication Date: 2025-07-11BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211478391.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-23
Publication Date
2025-07-11
Estimated Expiration
2042-11-23

AI Technical Summary

Technical Problem

The existing data synchronization method During the data transmission process, the data transmission path can be perceived, resulting in a high risk of data leakage.

Method used

The data nodes in the end-to-end encryption network are used for two-layer encryption processing, including encryption between the data source node and the destination node and the encryption between adjacent data forwarding nodes, and data forwarding is carried out through routing tags to prevent the complete path from being leaked.

Benefits of technology

Improves security during data synchronization, making the data transmission path unaware, ensuring the integrity and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116112207B_ABST
    Figure CN116112207B_ABST
Patent Text Reader

Abstract

The present application provides an end-to-end encrypted network data synchronization method, apparatus, electronic device, and storage medium. Among them, the end-to-end encrypted network data synchronization method includes: the data nodes in the end-to-end encrypted network include ordinary nodes and system nodes. The method includes: receiving status information reported by ordinary nodes, where the status information includes the reporting time, data operation type, node identifier, and path encoding; creating a data synchronization index for the ordinary nodes based on the reporting time, data operation type, node identifier, and path encoding; when receiving node data sent by ordinary nodes, associating the data synchronization index with the node data, and other steps. The present application can prevent the data transmission path during the data synchronization process from being perceived on the premise of realizing data synchronization, thereby improving data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technologies, and in particular, to an end-to-end encrypted network data synchronization method, apparatus, electronic device, and storage medium. Background Art

[0002] Currently, in the existing data synchronization method, during the data synchronization process, data can be encrypted at each data node to improve data security.

[0003] However, the existing data synchronization method still has the following disadvantages: that is, the data transmission path during the data synchronization process can be perceived, resulting in the leakage of the data transmission path. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide an end-to-end encrypted network data synchronization method, apparatus, electronic device, and storage medium, so as to prevent the data transmission path during the data synchronization process from being perceived on the premise of realizing data synchronization, thereby improving data security.

[0005] In a first aspect, the present invention provides an end-to-end encrypted network data synchronization method. The data nodes in the end-to-end encrypted network include ordinary nodes and system nodes. The method is applied to the system node and includes:

[0006] Receiving status information reported by an ordinary node, where the status information includes a reporting time, a data operation type, a node identifier, and a path encoding;

[0007] Creating a data synchronization index for the ordinary node based on the reporting time, the data operation type, the node identifier, and the path encoding;

[0008] When receiving node data sent by an ordinary node, associating the data synchronization index with the node data;

[0009] When receiving a data synchronization request sent by another system node in the end-to-end encrypted network, determining the data to be synchronized based on the synchronization timestamp and the data synchronization index carried in the data synchronization request;

[0010] Sending the synchronized data to another system node in the end-to-end encrypted network, and updating the maximum timestamp in the local synchronization list based on the synchronization timestamp.

[0011] In the first aspect of the present application, since the data synchronization method is applied to an end-to-end encrypted network, during the synchronization process of node data, two-layer encryption processing can be performed, thereby improving the security of node data. Among them, one layer of encryption processing in the two-layer encryption is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encrypted network, the data forwarding node completes data forwarding based on the routing label. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing label, but cannot perceive the complete path. In this way, the complete synchronization path can be prevented from being leaked through the routing label.

[0012] In another aspect, by receiving the status information reported by the ordinary node, the data synchronization index of the ordinary node can be created based on the reporting time, data operation type, node identifier, and path encoding. Then, when receiving the node data sent by the ordinary node, the data synchronization index can be associated with the node data. Further, when receiving the data synchronization request sent by another system node in the end-to-end encrypted network, the data to be synchronized can be determined based on the synchronization timestamp and data synchronization index carried in the data synchronization request, so as to send the synchronized data to another system node in the end-to-end encrypted network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time, and the data synchronization index is associated with the node data, in this way, the synchronization of data can be complete and orderly according to the timestamp, without requiring the system time of all nodes in the network to be absolutely consistent.

[0013] In an alternative embodiment, the method further includes:

[0014] Receiving a synchronization path query request sent by an ordinary node, determining the synchronization path based on the link connection information of the ordinary node and the load information of multiple ordinary nodes in the cluster, and sending the synchronization path to the ordinary node, so that the ordinary node sends node data to the system node based on the synchronization path.

[0015] In the above alternative embodiment, the system node can provide a synchronization path query service to the ordinary node based on the load balancing strategy.

[0016] In an alternative embodiment, the data node in the end-to-end encrypted network determines a plurality of available system nodes through the system nodes known to itself returned by the adjacent data nodes.

[0017] In the above alternative embodiment, the data node in the end-to-end encrypted network can obtain a plurality of available system nodes through the system nodes known to itself returned by the adjacent data nodes.

[0018] In an alternative embodiment, the method further includes:

[0019] When the system node serves as a temporary service node, a fixed service node is allocated to the ordinary node based on the load data of other system nodes in the end-to-end encrypted network, where the ordinary node selects a system node from several available system nodes as the temporary service node.

[0020] In the above optional implementation manner, the system node can re-allocate the fixed service node to the ordinary node based on the load balancing policy.

[0021] In a second aspect, the present invention provides a data synchronization device for an end-to-end encrypted network. The data nodes in the end-to-end encrypted network include ordinary nodes and system nodes. The device is applied to the system node and includes:

[0022] A first receiving module, configured to receive the status information reported by the ordinary node, where the status information includes the reporting time, the data operation type, the node identifier, and the path encoding;

[0023] A creating module, configured to create a data synchronization index of the ordinary node based on the reporting time, the data operation type, the node identifier, and the path encoding;

[0024] A mapping module, configured to associate the data synchronization index with the node data when receiving the node data sent by the ordinary node;

[0025] A determining module, configured to determine the data to be synchronized based on the synchronization timestamp and the data synchronization index carried in the data synchronization request when receiving a data synchronization request sent by another system node in the end-to-end encrypted network;

[0026] A data synchronization module, configured to send the synchronization data to another system node in the end-to-end encrypted network and update the maximum timestamp in the local synchronization list based on the synchronization timestamp.

[0027] The device according to the second aspect of the present application can receive the status information reported by ordinary nodes by executing the method for synchronizing network data based on end-to-end encryption. Furthermore, it can create a data synchronization index for ordinary nodes based on the reporting time, data operation type, node identifier, and path encoding. Then, when receiving the node data sent by an ordinary node, it can associate the data synchronization index with the node data. Subsequently, when receiving a data synchronization request sent by another system node in the end-to-end encryption network, it can determine the data to be synchronized based on the synchronization timestamp and data synchronization index carried in the data synchronization request, thereby sending the synchronized data to another system node in the end-to-end encryption network and updating the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time and the data synchronization index is associated with the node data, in this way, the synchronization of data can be complete and orderly according to the timestamp, without requiring the system times of all nodes in the network to be absolutely consistent.

[0028] On the other hand, since the data synchronization method is applied to the end-to-end encryption network, during the synchronization process of node data, it can undergo two-layer encryption processing, which can further improve the security of node data. Among them, one layer of the two-layer encryption processing is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encryption network, the data forwarding nodes complete data forwarding based on routing labels. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing label, but cannot perceive the complete path. In this way, the complete synchronization path can be prevented from being leaked through the routing label.

[0029] In an alternative embodiment, the device further includes:

[0030] A second receiving module, configured to receive a synchronization path query request sent by an ordinary node, determine a synchronization path based on the link connection information of the ordinary node and the load information of multiple ordinary nodes in the cluster, and send the synchronization path to the ordinary node, so that the ordinary node sends node data to the system node based on the synchronization path.

[0031] In the above alternative embodiment, the system node can provide a synchronization path query service to ordinary nodes based on a load balancing strategy.

[0032] In an alternative embodiment, the data nodes in the end-to-end encryption network determine a plurality of available system nodes through the system nodes known to themselves returned by adjacent data nodes.

[0033] In the above alternative embodiment, the data nodes in the end-to-end encryption network can obtain a plurality of available system nodes through the system nodes known to themselves returned by adjacent data nodes.

[0034] In an alternative embodiment, the apparatus further includes:

[0035] A distribution module, configured to, when the system node acts as a temporary service node, allocate a fixed service node for the ordinary node based on the load data of other system nodes in the end-to-end encrypted network, where the ordinary node selects a system node from several available system nodes as the temporary service node.

[0036] In the above alternative embodiment, the system node can re-allocate a fixed service node for the ordinary node based on the load balancing policy.

[0037] In a third aspect, the present invention provides an electronic device, including:

[0038] A processor; and

[0039] A memory, configured to store machine-readable instructions, which, when executed by the processor, execute the end-to-end encrypted network data synchronization method according to any one of the foregoing embodiments.

[0040] The electronic device in the third aspect of the present application can receive the status information reported by the ordinary node by executing the end-to-end encrypted network data synchronization method, and then can create a data synchronization index for the ordinary node based on the reporting time, data operation type, node identifier, and path encoding. Further, when receiving the node data sent by the ordinary node, the data synchronization index can be associated with the node data. Further, when receiving a data synchronization request sent by another system node in the end-to-end encrypted network, the data to be synchronized can be determined based on the synchronization timestamp and the data synchronization index carried in the data synchronization request, so as to send the synchronized data to another system node in the end-to-end encrypted network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time, and the data synchronization index is associated with the node data, in this way, the synchronization of the data can be complete and orderly according to the timestamp, without requiring the system times of all nodes in the network to be absolutely consistent.

[0041] On the other hand, since the data synchronization method is applied to the end-to-end encrypted network, during the synchronization process of the node data, two-layer encryption processing can be performed, which can improve the security of the node data. Among them, one layer of the two-layer encryption processing is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encrypted network, the data forwarding node completes data forwarding based on the routing label. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing label, and cannot perceive the complete path. In this way, the complete synchronization path can be prevented from being leaked through the routing label.

[0042] In a fourth aspect, the present invention provides a storage medium storing a computer program, and the computer program is executed by a processor to perform the end-to-end encrypted network data synchronization method according to any one of the foregoing embodiments.

[0043] By executing the end-to-end encrypted network data synchronization method, the storage medium according to the fourth aspect of the present application can receive the status information reported by ordinary nodes, and then can create a data synchronization index for the ordinary nodes based on the reporting time, data operation type, node identifier, and path encoding. Further, when receiving the node data sent by an ordinary node, the data synchronization index can be associated with the node data. Further, when receiving a data synchronization request sent by another system node in the end-to-end encrypted network, the data to be synchronized can be determined based on the synchronization timestamp and data synchronization index carried in the data synchronization request, so as to send the synchronized data to another system node in the end-to-end encrypted network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time, and the data synchronization index is associated with the node data, in this way, the synchronization of data can be complete and orderly according to the timestamp, without requiring the system times of all nodes in the network to be absolutely consistent.

[0044] On the other hand, since the data synchronization method is applied to the end-to-end encrypted network, during the synchronization process of node data, two-layer encryption processing can be performed, which can improve the security of node data. Among them, one layer of encryption processing in the two-layer encryption processing is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encrypted network, the data forwarding nodes complete data forwarding based on routing labels. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing label, but cannot perceive the complete path. In this way, the complete synchronization path can be prevented from being leaked through the routing label. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0046] Figure 1 is a schematic flowchart of an end-to-end encrypted network data synchronization method disclosed in an embodiment of the present application;

[0047] Figure 2 is a schematic deployment topology diagram of a secure communication system provided by an embodiment of the present application;

[0048] Figure 3 It is a schematic diagram of an end-to-end encryption method disclosed in an embodiment of the present application;

[0049] Figure 4 It is a schematic diagram showing the association between a data synchronization index and node data disclosed in an embodiment of the present application;

[0050] Figure 5 It is a schematic structural diagram of a data synchronization device based on an end-to-end encrypted network disclosed in an embodiment of the present application

[0051] Figure 6 It is a schematic structural diagram of an electronic device disclosed in an embodiment of the present application. Detailed implementation manners

[0052] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0053] Embodiment 1

[0054] Please refer to Figure 1 , Figure 1 It is a schematic flowchart of a data synchronization method based on an end-to-end encrypted network disclosed in an embodiment of the present application. Among them, the data nodes in the end-to-end encrypted network include ordinary nodes and system nodes, and this method is applied to system nodes. As Figure 1 shown, the method in the embodiment of the present application includes the following steps:

[0055] 101. Receive the status information reported by the ordinary node, where the status information includes the reporting time, data operation type, node identifier, and path encoding;

[0056] 102. Create a data synchronization index for the ordinary node based on the reporting time, data operation type, node identifier, and path encoding;

[0057] 103. When receiving the node data sent by the ordinary node, associate the data synchronization index with the node data;

[0058] 104. When receiving a data synchronization request sent by another system node in the end-to-end encrypted network, determine the data to be synchronized based on the synchronization timestamp and data synchronization index carried in the data synchronization request;

[0059] 105. Send the synchronized data to another system node in the end-to-end encrypted network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp.

[0060] In the embodiments of the present application, since the data synchronization method is applied to an end-to-end encrypted network, during the synchronization process of node data, two-layer encryption processing can be performed, thereby improving the security of node data. Among them, one layer of the two-layer encryption processing is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encrypted network, the data forwarding nodes complete data forwarding based on routing tags. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing tag, but cannot perceive the complete path. In this way, the complete synchronization path can be prevented from being leaked through the routing tag.

[0061] On the other hand, by receiving the status information reported by ordinary nodes, a data synchronization index of ordinary nodes can be created based on the reporting time, data operation type, node identifier, and path encoding. Then, when receiving the node data sent by ordinary nodes, the data synchronization index can be associated with the node data. Further, when receiving a data synchronization request sent by another system node in the end-to-end encrypted network, the data to be synchronized can be determined based on the synchronization timestamp and data synchronization index carried in the data synchronization request, so as to send the synchronized data to another system node in the end-to-end encrypted network and update the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time and the data synchronization index is associated with the node data, in this way, the synchronization of data can be complete and orderly according to the timestamp, without the need for the system time of all nodes in the network to be absolutely consistent.

[0062] In the embodiments of the present application, specifically, please refer to Figure 2 , Figure 2 which is a schematic diagram of the deployment topology of a secure communication system provided by the embodiments of the present application. As Figure 2 shown, the secure communication system includes three system nodes S and several ordinary nodes ( Figure 2 represented by circles without S in Figure 2 ). Among them, end-to-end encryption is used for data communication between each ordinary node. Therefore,

[0063] Further, the end-to-end encryption method means that during the data transmission process, the data to be transmitted undergoes two layers of encryption. One layer of encryption is to encrypt the data to be transmitted using the session key negotiated between the data source node and the destination node. Since only the data source node and the destination node know the key negotiation in this encryption step, after the data to be transmitted is encrypted by this layer, the data forwarding node cannot decrypt the encrypted data to be transmitted because it does not know the key negotiation. Thus, the data forwarding node cannot disclose the specific content of the data to be transmitted. The other layer of encryption is the encryption between two adjacent nodes. As an example, please refer to Figure 3 , Figure 3 which is a schematic diagram of an end-to-end encryption method disclosed in an embodiment of the present application. As Figure 3 shown, when data node A needs to transmit data msg to data node C through data node B, data node A and data node C negotiate the session key AC. Then, based on the session key AC, session key AB, and session key BC, the data msg is encrypted. Among them, when each node joins the network, it negotiates the session secret key with its adjacent nodes, that is, the session key AB and the session key BC can be negotiated when the node joins the network. In this way, when the data msg is transmitted from data node A to data node B, it is encrypted by the session key AC and the session key AB, and when the data msg is transmitted from data node B to data node C, it is encrypted by the session key AC and the session key BC.

[0064] In an embodiment of the present application, specifically, the specific method for data nodes in the end-to-end encryption network to negotiate session keys is as follows: The data node generates its own private key based on the system random number generator and uses the elliptic curve algorithm to generate its own public key. Then, the private key and the public key are used as parameters of the ECDHE key negotiation algorithm, and then the session key is negotiated with other data nodes based on the ECDHE key negotiation algorithm. Regarding the ECDHE key negotiation algorithm, please refer to the prior art, and this embodiment of the present application will not elaborate on it.

[0065] In an embodiment of the present application, further, when a data node applies to access the end-to-end encryption network, it can also use the public key as the input parameter of the Hash algorithm, so as to obtain an IPv6 virtual address based on the Hash algorithm. This IPv6 virtual address is used as the identity identifier of the data node in the end-to-end encryption network. Among them, due to the one-way irreversible feature of the Hash algorithm, the public key cannot be obtained reversely through the IPv6 virtual address, so the identity identifier cannot be forged based on the public key.

[0066] It should be noted that the difference between system nodes and ordinary nodes is that system nodes can provide services required for multiple ordinary nodes to implement the data synchronization process, such as data transmission path query services. On the other hand, in some scenarios, system nodes can be regarded as ordinary nodes based on demand, that is, end-to-end encryption can be used.

[0067] In the embodiment of the present application, for step 102, the data structure obtained by associating the data synchronization index with the node data is as follows: Figure 4 As shown, Figure 4 Schematic diagram of the association between a data synchronization index and node data disclosed in the embodiment of the present application. Figure 4 As shown, Time indicates the reporting time, and Date_id indicates the node identifier, where the node identifier can be the IPv6 virtual address of the data node. Accordingly, the node data Date_1, Date_2, and Date_n are used as the values ​​of the fields Index_1, Index_2, and Index_n under the index column.

[0068] In the embodiment of the present application, for step 105, the maximum timestamp in the local synchronization list is used to indicate the time of the most recent synchronization of the system node. For example, assuming that the system node was last synchronized at 6 o'clock, 6 o'clock is the maximum timestamp. Accordingly, when the system node needs to request other systems to synchronize data, 6 o'clock is sent as the synchronization timestamp to other system nodes, so that other system nodes synchronize data after 6 o'clock to it.

[0069] In an optional implementation manner, the method of the embodiment of the present application further includes the following steps:

[0070] Receive a synchronization path query request sent by an ordinary node, determine a synchronization path based on the link connection information of the ordinary node and the load information of multiple ordinary nodes in the cluster, and send the synchronization path to the ordinary node, so that the ordinary node sends node data to the system node based on the synchronization path.

[0071] In the above optional implementation manner, the system node can provide a synchronous path query service to ordinary nodes based on a load balancing strategy.

[0072] In an optional implementation, a data node in the end-to-end encryption network determines a number of available system nodes through its own known system nodes returned by adjacent data nodes.

[0073] In the above optional implementation, the data nodes in the end-to-end encryption network can obtain several available system nodes through their own known system nodes returned by adjacent data nodes.

[0074] In the above optional implementation, the data nodes in the end-to-end encrypted network can be the overall system nodes or ordinary nodes of the network. For example, the system nodes can discover other system nodes through the above method and obtain the load data of other system nodes.

[0075] In an optional implementation, the method of the embodiment of the present application further includes the following steps:

[0076] When the system node acts as a temporary service node, based on the load data of other system nodes in the end-to-end encrypted network, allocate a fixed service node for the ordinary node, where the ordinary node selects one system node from several available system nodes as the temporary service node.

[0077] In the above optional implementation, the system node can re-allocate a fixed service node for the ordinary node based on the load balancing strategy.

[0078] In the above optional implementation, as an example, assume there are system node A, system node B, and system node C. Among them, the ordinary node selects system node C as the temporary service node in the early stage. After a period of time, system node C learns from the link connection information reported by the ordinary node that the ordinary node can also connect to system node A and system node B, and based on the load data of system node A and the load of system node B, it can be known that the load of system node A is lower than the load of system node B. At this time, system node A can be used as the fixed service node of the ordinary node, so that the ordinary node reports corresponding data and requests services to system node A subsequently.

[0079] Embodiment 2

[0080] Please refer to Figure 5 , Figure 5 is a schematic structural diagram of an end-to-end encrypted network data synchronization device disclosed in an embodiment of the present application. The data nodes in the end-to-end encrypted network include ordinary nodes and system nodes, and this device is applied to system nodes. As Figure 5 shown, the device of the embodiment of the present application includes the following functional modules:

[0081] The first receiving module 201 is configured to receive the status information reported by the ordinary node, where the status information includes the reporting time, data operation type, node identifier, and path encoding;

[0082] The creating module 202 is configured to create a data synchronization index of the ordinary node based on the reporting time, data operation type, node identifier, and path encoding;

[0083] The mapping module 203 is configured to associate the data synchronization index with the node data when receiving the node data sent by the ordinary node;

[0084] A determination module 204, configured to determine data to be synchronized based on a synchronization timestamp and a data synchronization index carried in a data synchronization request when receiving a data synchronization request sent by another system node in an end-to-end encrypted network;

[0085] A data synchronization module 205, configured to send synchronized data to another system node in the end-to-end encrypted network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp.

[0086] By executing the end-to-end encrypted network data synchronization method, the device according to an embodiment of the present application can receive status information reported by ordinary nodes, and then can create a data synchronization index for the ordinary nodes based on the reporting time, data operation type, node identifier, and path encoding. Furthermore, when receiving node data sent by an ordinary node, the device can associate the data synchronization index with the node data. Moreover, when receiving a data synchronization request sent by another system node in the end-to-end encrypted network, the device can determine the data to be synchronized based on the synchronization timestamp and the data synchronization index carried in the data synchronization request, so as to send the synchronized data to another system node in the end-to-end encrypted network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time and the data synchronization index is associated with the node data, the synchronization of data can be complete and orderly according to the timestamp, without requiring the system times of all nodes in the network to be absolutely consistent.

[0087] On the other hand, since the data synchronization method is applied to an end-to-end encrypted network, during the synchronization process of node data, two-layer encryption processing can be performed, which can improve the security of node data. Among them, one layer of the two-layer encryption processing is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encrypted network, the data forwarding nodes complete data forwarding based on routing labels. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing label, but cannot perceive the complete path. In this way, the disclosure can prevent the complete synchronization path from being leaked through the routing label.

[0088] In an optional embodiment, the device according to an embodiment of the present application further includes the following functional modules:

[0089] A second receiving module, configured to receive a synchronization path query request sent by an ordinary node, determine a synchronization path based on the link connection information of the ordinary node and the load information of multiple ordinary nodes in the cluster, and send the synchronization path to the ordinary node, so that the ordinary node sends node data to the system node based on the synchronization path.

[0090] In the above optional embodiment, the system node can provide a synchronization path query service to the ordinary node based on a load balancing policy.

[0091] In an optional embodiment, a data node in an end-to-end encrypted network determines a number of available system nodes through the system nodes known to itself returned by adjacent data nodes.

[0092] In the above optional embodiment, a data node in an end-to-end encrypted network can obtain a number of available system nodes through the system nodes known to itself returned by adjacent data nodes.

[0093] In an optional embodiment, the device of the embodiment of the present application further includes the following functional modules:

[0094] An allocation module, configured to, when the system node is used as a temporary service node, allocate a fixed service node for the ordinary node based on the load data of other system nodes in the end-to-end encrypted network, where the ordinary node selects a system node from a number of available system nodes as the temporary service node.

[0095] In the above optional embodiment, the system node can re-allocate a fixed service node for the ordinary node based on a load balancing policy.

[0096] Embodiment III

[0097] Please refer to Figure 6 , Figure 6 which is a schematic structural diagram of an electronic device disclosed in the embodiment of the present application. As Figure 6 shown, the electronic device of the embodiment of the present application includes:

[0098] A processor 301; and

[0099] A memory 302, configured to store machine-readable instructions, which, when executed by the processor 301, execute the end-to-end encrypted network data synchronization method according to any one of the foregoing embodiments.

[0100] By executing the method for synchronizing network data based on end-to-end encryption, the electronic device according to the embodiment of the present application can receive the status information reported by ordinary nodes, and then can create a data synchronization index for the ordinary nodes based on the reporting time, data operation type, node identifier, and path encoding. Further, when receiving the node data sent by an ordinary node, the data synchronization index can be associated with the node data. Further, when receiving a data synchronization request sent by another system node in the end-to-end encryption network, the data to be synchronized can be determined based on the synchronization timestamp and the data synchronization index carried in the data synchronization request, so as to send the synchronized data to another system node in the end-to-end encryption network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time, and the data synchronization index is associated with the node data, in this way, the synchronization of data can be complete and orderly according to the timestamp, without the need for the system times of all nodes in the network to be absolutely consistent.

[0101] On the other hand, since the data synchronization method is applied to the end-to-end encryption network, during the synchronization process of node data, two-layer encryption processing can be performed, which can further improve the security of node data. Among them, one layer of encryption processing in the two-layer encryption processing is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encryption network, the data forwarding nodes complete data forwarding based on routing tags. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing tag, but cannot perceive the complete path. In this way, the complete synchronization path can be prevented from being leaked through the routing tag.

[0102] Embodiment 4

[0103] The embodiment of the present application provides a storage medium storing a computer program, and the computer program is executed by a processor to perform the method for synchronizing network data based on end-to-end encryption as described in any one of the foregoing embodiments.

[0104] By executing the method for synchronizing network data based on end-to-end encryption, the storage medium according to the embodiment of the present application can receive the status information reported by ordinary nodes, and then can create a data synchronization index for the ordinary nodes based on the reporting time, data operation type, node identifier, and path encoding. Further, when receiving the node data sent by an ordinary node, it can associate the data synchronization index with the node data. Further, when receiving a data synchronization request sent by another system node in the end-to-end encryption network, it can determine the data to be synchronized based on the synchronization timestamp carried in the data synchronization request and the data synchronization index, so as to send the synchronized data to another system node in the end-to-end encryption network, and update the maximum timestamp in the local synchronization list based on the synchronization timestamp. In the above process, since the data synchronization index can be created based on the reporting time, and the data synchronization index is associated with the node data, in this way, the synchronization of data can be complete and orderly according to the timestamp, without the need for the system times of all nodes in the network to be absolutely consistent.

[0105] On the other hand, since the data synchronization method is applied to the end-to-end encryption network, during the synchronization process of node data, two-layer encryption processing can be performed, which can improve the security of node data. Among them, one layer of encryption processing in the two-layer encryption is the encryption between the data source node and the destination node, and the other layer is the encryption between two adjacent data forwarding nodes. Further, in the end-to-end encryption network, the data forwarding nodes complete data forwarding based on routing labels. Among them, each data forwarding node can only know where the data comes from and where the data needs to be sent based on the routing label, and cannot perceive the complete path. In this way, the complete synchronization path can be prevented from being leaked through the routing label.

[0106] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical or other form.

[0107] In addition, the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0108] Furthermore, in each embodiment of the present application, each functional module can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0109] It should be noted that if a function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0110] In this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0111] The above are only the embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. An end-to-end encrypted network data synchronization method, characterized in that The data nodes in the end-to-end encrypted network include ordinary nodes and system nodes. The method is applied to the system nodes and includes: Receiving status information reported by ordinary nodes, where the status information includes the reporting time, data operation type, node identifier, and path encoding; Creating a data synchronization index for the ordinary nodes based on the reporting time, the data operation type, the node identifier, and the path encoding; When receiving node data sent by the ordinary nodes, associating the data synchronization index with the node data; When receiving a data synchronization request sent by another system node in the end-to-end encrypted network, determining the data to be synchronized based on the synchronization timestamp carried in the data synchronization request and the data synchronization index; Sending the synchronized data to another system node in the end-to-end encrypted network and updating the maximum timestamp in the local synchronization list based on the synchronization timestamp.

2. The method according to claim 1, wherein The method further includes: Receiving a synchronization path query request sent by the ordinary nodes, determining a synchronization path based on the link connection information of the ordinary nodes and the load information of multiple ordinary nodes in the cluster, and sending the synchronization path to the ordinary nodes so that the ordinary nodes send the node data to the system nodes based on the synchronization path.

3. The method according to claim 1, wherein The data nodes in the end-to-end encrypted network determine a number of available system nodes through the system nodes known to themselves returned by adjacent data nodes.

4. The method according to claim 3, wherein The method further includes: When the system node serves as a temporary service node, allocating a fixed service node for the ordinary nodes based on the load data of other system nodes in the end-to-end encrypted network, where the ordinary nodes select one of the available system nodes as the temporary service node.

5. An end-to-end encrypted network data synchronization device, characterized in that, The data nodes in the end-to-end encrypted network include ordinary nodes and system nodes. The device is applied to the system nodes and includes: A first receiving module for receiving status information reported by ordinary nodes, where the status information includes the reporting time, data operation type, node identifier, and path encoding; A creating module for creating a data synchronization index for the ordinary nodes based on the reporting time, the data operation type, the node identifier, and the path encoding; A mapping module for associating the data synchronization index with the node data when receiving node data sent by the ordinary nodes; A determining module for determining the data to be synchronized based on the synchronization timestamp carried in the data synchronization request and the data synchronization index when receiving a data synchronization request sent by another system node in the end-to-end encrypted network; A data synchronization module for sending the synchronized data to another system node in the end-to-end encrypted network and updating the maximum timestamp in the local synchronization list based on the synchronization timestamp.

6. The device according to claim 5, characterized in that, The device further includes: A second receiving module, configured to receive the synchronization path query request sent by the ordinary node, determine a synchronization path based on the link connection information of the ordinary node and the load information of multiple ordinary nodes in the cluster, and send the synchronization path to the ordinary node, so that the ordinary node sends the node data to the system node based on the synchronization path.

7. The device according to claim 5, characterized in that The data nodes in the end-to-end encrypted network determine several available system nodes through the system nodes known to themselves returned by adjacent data nodes.

8. The device according to claim 7, wherein The apparatus further includes: An allocation module, configured to, when the system node serves as a temporary service node, allocate a fixed service node for the ordinary node based on the load data of other system nodes in the end-to-end encrypted network, where the ordinary node selects one system node from several available system nodes as the temporary service node.

9. An electronic device, characterized in that, Comprising: A processor; And A memory, configured to store machine-readable instructions, which, when executed by the processor, execute the end-to-end encrypted network data synchronization method according to any one of claims 1-4.

10. A storage medium, characterized in that, The storage medium stores a computer program, and the computer program is executed by a processor to perform the end-to-end encrypted network data synchronization method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Short message encryption communication method based on dynamic timestamp and national secret algorithm

    CN113015111A

  • Data transmission method and device for anonymous communication, electronic equipment and storage medium

    CN114338127A