Traffic transmission method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202311182374.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-13
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2043-09-13
AI Technical Summary
[0005]本申请提供一种流量传输方法、装置、电子设备及存储介质,用以解决现有的流量传输方法存在流程固化、灵活性不足,无法满足不同加密需求的问题
[0050]本申请提供的流量传输方法、装置、电子设备及存储介质,应用于流量传输系统,通过获取加密流量的加密需求标识,加密需求标识根据加密流量的传输信息和加密需求信息设置,传输信息表征加密流量的待传输节点,加密需求信息表征对待传输节点的加密方式;根据加密需求标识,确定加密流量的流转信道、以及流转信道的加密算法,其中,流转信道包括第一节点和第二节点,第一节点为第二节点的上一传输节点;根据加密算法,对流转信道中的第一节点和第二节点进行加密,得到加密流转信道;根据加密流转信道,对加密流量进行传输的手段,可以通过获取加密流量的加密需求标识,并通过加密需求标识,确定待传输节点、以及待传输节点的加密方式,因此可以确定用户的加密需求,从而可以在加密流量传输时,对用于加密流量传输的流转信道进行加密,并使用加密后的流转信道对加密流量进行传输,因此,可以在不同加密场景下,根据加密需求标识来选择不同的加密算法,从而提高了流量传输过程中选择加密方式的灵活性,更有利地防止攻击者利用加密流量为载体实施攻击,提高了流量传输的安全性,同时,因为采取信道加密的方式,对流转信道上的所有待传输节点进行加密,而不是采用信源加密的方式,打破了原有的固化传输流程,优化了交互协议流程,因此可以解决数据流量安全传输效率低的问题,实现了保障流量在流转过程中的安全,满足用户不同加密需求的效果。
Smart Images

Figure CN117201409B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, electronic device and storage medium for transmitting data traffic. Background Technology
[0002] With the development of the network and the increase in data volume, data security has become increasingly important. Therefore, in view of the current status of network data security protection, it is of great significance to improve the security capabilities of data flow and ensure the security of traffic transmission.
[0003] Currently, network interaction processes are all executed according to standard protocol interaction processes, and there are also fixed patterns for establishing trust, identifying a certain node or platform as a fixed trusted point as the basis for traffic transmission.
[0004] However, existing traffic transmission methods suffer from rigid processes and insufficient flexibility, failing to meet diverse encryption requirements. Summary of the Invention
[0005] This application provides a traffic transmission method, apparatus, electronic device, and storage medium to solve the problems of existing traffic transmission methods having rigid processes, insufficient flexibility, and inability to meet different encryption requirements.
[0006] In a first aspect, this application provides a traffic transmission method applied to a traffic transmission system, comprising:
[0007] Obtain the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier is set according to the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted in the encrypted traffic, and the encryption requirement information represents the encryption method of the node to be transmitted.
[0008] Based on the encryption requirement identifier, the transfer channel of the encrypted traffic and the encryption algorithm of the transfer channel are determined. The transfer channel includes a first node and a second node, and the first node is the previous transmission node of the second node.
[0009] Based on the encryption algorithm, the first and second nodes in the transfer channel are encrypted to obtain the encrypted transfer channel;
[0010] Encrypted traffic is transmitted based on the encrypted flow channel.
[0011] In this application, the encryption requirement identifier for obtaining encrypted traffic includes:
[0012] Acquire data traffic and the nodes from which the data traffic is to be transmitted;
[0013] If there are no abnormalities in the node to which the data traffic is to be transmitted, then the data traffic is determined to be the initial target traffic;
[0014] If the initial target traffic meets the baseline requirement, then the initial target traffic is determined as the target traffic. The baseline requirement represents the amount of data required for the encrypted traffic to complete the target service.
[0015] In response to a user's request to encrypt the target traffic, the system determines that the target traffic is encrypted and obtains the transmission information and encryption requirement information of the encrypted traffic.
[0016] Based on the transmission information and encryption requirement information, the encrypted traffic is marked to obtain the encryption requirement identifier of the encrypted traffic.
[0017] In this application, after obtaining the data traffic and the node to which the data traffic is to be transmitted, the method further includes:
[0018] If the node to which the data traffic is to be transmitted is abnormal, the data traffic is identified as the first abnormal traffic and a backup encrypted transfer channel is determined.
[0019] Use the backup encrypted transfer channel as the transfer channel for encrypted traffic, and re-execute the steps of obtaining data traffic and the node to be transmitted for data traffic.
[0020] In this application, if the initial target traffic meets the baseline value requirement, then the initial target traffic is determined to be the target traffic, including:
[0021] Determine the packets of the initial target traffic, the unformatted data in the packets, and the baseline value requirements;
[0022] Compare the baseline values with the unformatted data to obtain the comparison results;
[0023] If the comparison results indicate that the unformatted data meets the baseline requirements, then the initial target flow is determined to meet the baseline requirements, and the initial target flow is determined to be the target flow.
[0024] In this application, after comparing baseline values and unformatted data to obtain the comparison results, the method further includes:
[0025] If the comparison results indicate that the unformatted data does not meet the baseline value requirements, then the initial target flow is determined to be the second abnormal flow that does not meet the baseline value requirements;
[0026] Based on the second abnormal traffic, the transmission process of encrypted traffic is stopped.
[0027] In this application, before encrypting the first and second nodes in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel, the method further includes:
[0028] Based on the encryption requirements, the key is stored in the first node and the second node. The key is the key corresponding to the encryption algorithm.
[0029] Adjust the first and second nodes to be initial trusted nodes;
[0030] After adjusting the first node and the second node to be initial trusted nodes, control the first node to initiate an authentication request to the second node at a first preset time and a preset frequency, and obtain the first authentication result;
[0031] The second node is controlled to initiate an authentication request to the first node at a second preset time and a preset frequency, and a second authentication result is obtained.
[0032] Based on the first authentication result and the second authentication result, the first node and the second node are determined to be trusted nodes, so as to execute the step of encrypting the first node and the second node in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel.
[0033] In this application, the method also includes:
[0034] If the first authentication result indicates that the second node did not respond to the first node's authentication request, then the second node is determined to be an untrusted node in an abnormal state.
[0035] After determining that the second node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the second node is taken offline.
[0036] If the second authentication result indicates that the first node did not respond to the second node's authentication request, then the first node is an untrusted node in an abnormal state.
[0037] After determining that the first node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the first node is taken offline.
[0038] In this application, the method also includes:
[0039] When encrypted traffic is transmitted to the first node, the first node stops sending authentication requests to the second node;
[0040] When encrypted traffic is transmitted to the second node, the second node stops sending authentication requests to the first node.
[0041] Secondly, this application provides a flow transmission device, comprising:
[0042] The acquisition module is used to acquire the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier is set according to the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted in the encrypted traffic, and the encryption requirement information represents the encryption method of the node to be transmitted.
[0043] The determination module is used to determine the transfer channel of the encrypted traffic and the encryption algorithm of the transfer channel based on the encryption requirement identifier. The transfer channel includes a first node and a second node, and the first node is the previous transmission node of the second node.
[0044] Obtaining the module: Based on the encryption algorithm, encrypt the first and second nodes in the transfer channel to obtain the encrypted transfer channel;
[0045] Transmission module: Transmits encrypted traffic according to the encrypted flow channel.
[0046] Thirdly, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;
[0047] The memory stores the instructions that the computer executes;
[0048] The processor executes computer execution instructions stored in memory to implement the method of this application.
[0049] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method of this application.
[0050] The traffic transmission method, apparatus, electronic device, and storage medium provided in this application are applied to a traffic transmission system. They involve obtaining an encryption requirement identifier for encrypted traffic, which is set based on the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted in the encrypted traffic, and the encryption requirement information represents the encryption method for the node to be transmitted. Based on the encryption requirement identifier, a transfer channel for the encrypted traffic and an encryption algorithm for the transfer channel are determined. The transfer channel includes a first node and a second node, with the first node being the previous transmission node of the second node. The encryption algorithm is used to encrypt the first node and the second node in the transfer channel to obtain an encrypted transfer channel. The means of transmitting encrypted traffic using the encrypted transfer channel can be achieved by obtaining the encryption requirement identifier of the encrypted traffic and, through the encryption requirement identifier, determining the node to be transmitted and the encryption method for the node to be transmitted. The point-to-point encryption method allows for the determination of user encryption requirements. This enables encryption of the transfer channel used for encrypted traffic transmission, and the encrypted transfer channel is then used to transmit the encrypted traffic. Therefore, different encryption algorithms can be selected based on encryption requirements in different encryption scenarios, improving the flexibility of encryption method selection during traffic transmission and effectively preventing attackers from using encrypted traffic as a carrier for attacks, thus enhancing traffic transmission security. Furthermore, because channel encryption is used to encrypt all nodes to be transmitted on the transfer channel, rather than source encryption, it breaks the original fixed transmission process and optimizes the interaction protocol process. Therefore, it solves the problem of low efficiency in secure data traffic transmission, ensuring the security of traffic during the transfer process and meeting the diverse encryption needs of users. Attached Figure Description
[0051] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0052] Figure 1 A flowchart illustrating the traffic transmission method provided in an embodiment of this application;
[0053] Figure 2 A flowchart illustrating another traffic transmission method provided in an embodiment of this application;
[0054] Figure 3 A schematic diagram illustrating a scenario for the traffic transmission method provided in an embodiment of this application;
[0055] Figure 4 This is a schematic diagram of the structure of the traffic transmission device provided in the embodiments of this application;
[0056] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0057] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation
[0058] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0059] In existing technologies, network interactions are performed according to standard protocol interaction procedures, and the establishment of trusted nodes or trusted platforms is also fixed during the process. Therefore, this traffic transmission method lacks flexibility and cannot meet different encryption requirements.
[0060] To address the aforementioned problems, this application provides a traffic transmission method that involves obtaining an encryption requirement identifier for encrypted traffic. This identifier is set based on the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted in the encrypted traffic, and the encryption requirement information represents the encryption method for the node to be transmitted. Based on the encryption requirement identifier, a transfer channel and an encryption algorithm for the transfer channel are determined. The transfer channel includes a first node and a second node, where the first node is the previous transmission node of the second node. The first and second nodes in the transfer channel are encrypted according to the encryption algorithm to obtain an encrypted transfer channel. The encrypted traffic is then transmitted using the encrypted transfer channel. Because the encryption requirement identifier is set, the encrypted traffic can be transmitted through encryption... The encryption requirement identifier determines the node to be transmitted and the encryption method of the node, as well as the transit channel and encryption algorithm of the transit channel. This allows for encryption of the first and second nodes of the transit channel. The encryption method of the node to be transmitted can be a combination of multiple algorithms, thus improving the flexibility of the traffic transmission method. Furthermore, by encrypting the first and second nodes, an encrypted transit channel is obtained. Channel encryption prevents attackers from using encrypted traffic as a carrier for attacks. The encrypted traffic is transmitted according to the encrypted transit channel, rather than using source encryption, thereby improving the efficiency of secure data transmission and ensuring the security of the traffic transit channel. This achieves the effect of meeting different encryption needs of users.
[0061] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0062] The execution entity of the traffic transmission method, apparatus, electronic device, and storage medium provided in this application embodiment can be a server. The server can be a computer, mobile phone, tablet, or other device. This embodiment does not impose any particular limitation on the implementation method of the execution entity, as long as the execution entity can obtain the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier is set according to the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted in the encrypted traffic, and the encryption requirement information represents the encryption method of the node to be transmitted. Based on the encryption requirement identifier, the flow channel of the encrypted traffic and the encryption algorithm of the flow channel are determined. The flow channel includes a first node and a second node, where the first node is the previous transmission node of the second node. According to the encryption algorithm, the first node and the second node in the flow channel are encrypted to obtain the encrypted flow channel. The encrypted traffic can then be transmitted according to the encrypted flow channel.
[0063] Encryption refers to the method of using encryption algorithms to process plaintext information into ciphertext that cannot be recognized. Encryption usually uses encryption algorithms, which can include national commercial cryptographic algorithms and international algorithms. National commercial cryptographic algorithms can refer to national cryptographic algorithms, which are cryptographic algorithm standards and their application specifications recognized and published by the State Cryptography Administration. International algorithms can refer to cryptographic algorithms published by foreign security agencies.
[0064] Figure 1 This is a flowchart illustrating the traffic transmission method provided in an embodiment of this application. The execution entity of this traffic transmission method can be a server, such as... Figure 1 As shown, the traffic transmission method may include:
[0065] S101. Obtain the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier is set according to the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted in the encrypted traffic, and the encryption requirement information represents the encryption method of the node to be transmitted.
[0066] Encrypted traffic can refer to data traffic that users choose to encrypt and protect during transmission based on their own needs. Users can also determine whether data traffic is publicly available or needs to be encrypted based on the importance of the data traffic to be transmitted.
[0067] The encryption requirement identifier can refer to the algorithm identifier corresponding to the encryption algorithm selected by the user based on their own needs. The user can indicate that the data traffic to be transmitted is of great importance and needs to be encrypted for transmission, and then select an encryption algorithm to protect the encrypted traffic. The algorithm identifier can be composed of the cryptographic algorithm identifier corresponding to the encryption algorithm category and the identifier corresponding to the specific cryptographic algorithm. Among them, the national commercial cryptographic algorithm identifier is 1, and the international algorithm identifier is 0.
[0068] Transmission information can refer to the nodes to be transmitted in encrypted traffic. For traffic that requires encryption, the management and monitoring platform can receive the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier represents the nodes to be transmitted in the encrypted traffic and the encryption method of the nodes to be transmitted. Therefore, it can determine the flow channel of the encrypted traffic, identify all nodes to be transmitted on the flow channel, including the destination address, and obtain the transmission information.
[0069] The destination address can refer to the IP address that receives the traffic.
[0070] The node to be transmitted can refer to a communication network endpoint. Communication network endpoints are connected to other communication network endpoints through physical or logical connections to form a transfer channel. Data is sent, received, or forwarded through the transfer channel. All communication network endpoints are interconnected with the management and monitoring platform.
[0071] Encryption requirement information can refer to the encryption methods of all nodes on the transmission channel triggered by encryption requirements. The encryption method can be a combination of multiple encryption algorithms. These multiple encryption algorithms are set in advance. Users can generate an identifier by selecting the corresponding tag of the algorithm according to their own needs. This allows the management and monitoring platform to select the corresponding encryption algorithm based on the encryption requirement identifier, thereby obtaining the encryption requirement information.
[0072] In this embodiment of the application, obtaining the encryption requirement identifier of the encrypted traffic includes:
[0073] Acquire data traffic and the nodes from which the data traffic is to be transmitted;
[0074] If there are no abnormalities in the node to which the data traffic is to be transmitted, then the data traffic is determined to be the initial target traffic;
[0075] If the initial target traffic meets the baseline requirement, then the initial target traffic is determined as the target traffic. The baseline requirement represents the amount of data required for the encrypted traffic to complete the target service.
[0076] In response to a user's request to encrypt the target traffic, the system determines that the target traffic is encrypted and obtains the transmission information and encryption requirement information of the encrypted traffic.
[0077] Based on the transmission information and encryption requirement information, the encrypted traffic is marked to obtain the encryption requirement identifier of the encrypted traffic.
[0078] Among them, the absence of abnormalities in the nodes to be transmitted for data traffic can refer to comparing the data flow direction determined by the nodes to be transmitted based on the data traffic transmission information with the traffic transmission destination address pre-stored by the user in the management and monitoring platform. If they are the same, it is determined that there are no abnormalities in the nodes to be transmitted for data traffic.
[0079] The baseline value can refer to the actual size of a certain business data portion that a user needs to complete based on their own requirements. The user's own requirements can refer to the traffic transmission needs of the user's target business. The target business can refer to the communication business that the user expects to complete. The data packet of the business includes a fixed format part and a data part. The fixed format part can refer to the packet header and segment offset, and the data part can refer to the business data volume. The size of the business data volume is usually within a fixed range, that is, the size of the business data volume that can be carried is fixed. Therefore, this fixed range is set as the baseline value, stored in the management and monitoring platform, and compared with the initial target traffic to obtain the comparison result.
[0080] If the initial target traffic meets the baseline requirement, it means comparing the packet size of the initial target traffic with the baseline value within the set fixed range. If the packet size of the initial target traffic is within the set fixed range, then the initial target traffic is determined to meet the baseline requirement.
[0081] The baseline value requirement characterizes the data volume requirement for encrypted traffic to complete the target service. It can refer to whether the data packet size of the encrypted traffic is within the data volume range of the target service. If it is, it means that the target service can be completed and the encrypted traffic meets the data volume requirement of the target service, that is, it meets the baseline value requirement.
[0082] The encryption request operation refers to the user determining whether the target traffic is encrypted based on its importance. If so, an encryption requirement identifier is added to the encrypted traffic before it is transmitted, and an encryption request is sent to the management and monitoring platform. After receiving the encryption request, the management and monitoring platform obtains the encryption requirement identifier of the encrypted traffic and completes the encrypted traffic transmission process.
[0083] Based on the transmission information and encryption requirement information, the encrypted traffic is marked to obtain the encryption requirement identifier of the encrypted traffic. This identifier can refer to the encryption method of the transmission node and the node to be transmitted, as well as the specific encryption algorithm, which is determined based on the transmission information and encryption requirement information. The encryption requirement identifier consists of the cryptographic algorithm identifier corresponding to the encryption algorithm category and the identifier corresponding to the specific cryptographic algorithm, and the identifier is loaded into the header of the traffic data packet.
[0084] The steps regarding the encryption requirement identifier, which consists of the cryptographic algorithm identifier corresponding to the encryption algorithm category and the identifier corresponding to the specific cryptographic algorithm, are illustrated below: For example, if the encrypted traffic uses the national commercial cryptographic algorithm identifier, the identifier is 1. The specific national cryptographic algorithm can refer to ZUC (Zu Chongzhi Algorithm), SM2 (Elliptic Curve Public Key Cryptography), SM3 (Hash Algorithm), SM4 (Symmetric Algorithm), or SM9 (Identifier Cryptography). The identifiers corresponding to the specific national cryptographic algorithms are 0, 2, 3, 4, and 9. When transmitting the encryption request to the management and monitoring platform, these identifiers are represented as 10, 12, 13, 14, and 19, and the identifiers are loaded into the traffic data packet header. This allows the monitoring and management platform to obtain the encryption requirement identifier of the encrypted traffic upon receiving the encryption request, thus completing the encrypted traffic transmission process.
[0085] In this embodiment of the application, after obtaining the data traffic and the node to which the data traffic is to be transmitted, the method further includes:
[0086] If the node to which the data traffic is to be transmitted is abnormal, the data traffic is identified as the first abnormal traffic and a backup encrypted transfer channel is determined.
[0087] Use the backup encrypted transfer channel as the transfer channel for encrypted traffic, and re-execute the steps of obtaining data traffic and the node to be transmitted for data traffic.
[0088] Among them, abnormal transmission node can refer to the data flow direction determined by the transmission node based on the data traffic transmission information being different from the user's expected traffic transmission destination address, including incorrect destination IP address of data traffic, violation, lack of IP registration information, etc.
[0089] A transfer channel can refer to the channel through which traffic flows during transmission, while an encrypted transfer channel can refer to a transfer channel in which the nodes to be transmitted have enabled encryption algorithms.
[0090] A backup encrypted transfer channel can refer to an encrypted transfer channel with the same destination address as the encrypted transfer channel but with a different node to be transmitted on the channel. The management and monitoring platform will switch the node to be transmitted based on the destination address and re-initiate the broadcast channel.
[0091] In this embodiment of the application, if the initial target traffic meets the baseline value requirement, then the initial target traffic is determined to be the target traffic, including:
[0092] Determine the packets of the initial target traffic, the unformatted data in the packets, and the baseline value requirements;
[0093] Compare the baseline values with the unformatted data to obtain the comparison results;
[0094] If the comparison results indicate that the unformatted data meets the baseline requirements, then the initial target flow is determined to meet the baseline requirements, and the initial target flow is determined to be the target flow.
[0095] The initial target traffic data packet can refer to the basic unit of traffic transmission. The data packet includes a fixed format part and a data part. The fixed format part can refer to the packet header and segment offset, while the data part can refer to the unformatted data. The unformatted data can refer to the actual data part transmitted by the data packet, i.e., the payload.
[0096] Regarding the comparison of baseline requirements and unformatted data, the comparison results are obtained. If the comparison results indicate that the unformatted data meets the baseline requirements, then the initial target traffic is determined to meet the baseline requirements, and the initial target traffic is determined to be the target traffic. For example, the data packet for completing a certain service requested by the user is usually 4 bytes in size, with a fluctuation of 1 byte. The baseline requirement is 3 to 5 bytes. The unformatted data in the traffic data packet is 4 bytes in size, which meets the baseline requirements. Therefore, the initial target traffic is determined to be the target traffic.
[0097] In this embodiment of the application, after comparing the baseline value requirements and unformatted data to obtain the comparison result, the method further includes:
[0098] If the comparison results indicate that the unformatted data does not meet the baseline value requirements, then the initial target flow is determined to be the second abnormal flow that does not meet the baseline value requirements;
[0099] Based on the second abnormal traffic, the transmission process of encrypted traffic is stopped.
[0100] If the comparison result indicates that the non-formatted data does not meet the baseline value requirement, then the initial target traffic is determined to not meet the baseline value requirement and is identified as the second abnormal traffic. Based on the second abnormal traffic, the transmission process of the encrypted traffic is stopped. For example, the data packet for completing a certain service requested by the user is usually 4 bytes in size, with a fluctuation of 1 byte. The baseline value requirement is 3 to 5 bytes. However, the size of the non-formatted data in the traffic data packet is 10 bytes, which far exceeds the baseline value requirement. Therefore, the initial target traffic is determined to be the second abnormal traffic, and the transmission process of the encrypted traffic is stopped.
[0101] S102. Based on the encryption requirement identifier, determine the transfer channel of the encrypted traffic and the encryption algorithm of the transfer channel, wherein the transfer channel includes a first node and a second node, and the first node is the previous transmission node of the second node.
[0102] Here, the first node can refer to the first node through which encrypted traffic passes during transmission on the encrypted transfer channel. The second node can refer to the second node through which encrypted traffic passes during transmission on the encrypted transfer channel.
[0103] In this embodiment of the application, before encrypting the first node and the second node in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel, the method further includes:
[0104] Based on the encryption requirements, the key is stored in the first node and the second node. The key is the key corresponding to the encryption algorithm.
[0105] Adjust the first and second nodes to be initial trusted nodes;
[0106] After adjusting the first node and the second node to be initial trusted nodes, control the first node to initiate an authentication request to the second node at a first preset time and a preset frequency, and obtain the first authentication result;
[0107] The second node is controlled to initiate an authentication request to the first node at a second preset time and a preset frequency, and a second authentication result is obtained.
[0108] Based on the first authentication result and the second authentication result, the first node and the second node are determined to be trusted nodes, so as to execute the step of encrypting the first node and the second node in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel.
[0109] Here, the key can refer to a parameter input into an algorithm that converts plaintext to ciphertext or ciphertext to plaintext.
[0110] Initial trusted nodes refer to all nodes in the flow channel that can support all encryption algorithms initiated by encrypted traffic and store keys, and can encrypt or decrypt encrypted traffic. These nodes are regarded as initial trusted nodes in order to complete the subsequent authentication and verification of the initial trusted nodes.
[0111] The first preset time can refer to a certain moment before the encrypted traffic transmission is encrypted by the first node, the second preset time can refer to another moment before the encrypted traffic transmission is encrypted by the first node, and the preset frequency can refer to any frequency.
[0112] Regarding the steps of controlling the first node to initiate authentication requests to the second node at a first preset time and a preset frequency after adjusting the first node and the second node as initial trusted nodes, and obtaining the first authentication result; and controlling the second node to initiate authentication requests to the first node at a second preset time and a preset frequency, and obtaining the second authentication result, an example is as follows: For instance, if traffic is transmitted encrypted through the first node and the second node at 10:00 AM, then the first node will initiate authentication requests to the second node every five minutes starting at 8:00 AM to obtain the first authentication result, and the second node will initiate authentication requests to the first node at the same frequency starting at 9:00 AM to obtain the second authentication result.
[0113] An authentication request can refer to a request initiated by a first node to a second node at a preset time and frequency to verify the trustworthiness of the nodes. Authentication includes mutual authentication of the certificates of the first and second nodes, certificate validity period, a list of algorithms that the node can use, and the status of any other nodes. Among these, a node certificate can refer to the node's identity credentials. A node can generate and store keys from its certificate. The list of algorithms that a node can use can refer to the encryption algorithms initiated corresponding to the keys stored by the node. The status of any other nodes can refer to whether the first and second nodes can normally receive and respond to the authentication request. A response can refer to the first and second nodes sending authentication requests to each other after receiving the authentication request. If the status of receiving and sending authentication requests is normal, the trustworthiness verification of the node is completed. If the status of receiving and sending authentication requests is abnormal, it indicates that the node is an untrusted node.
[0114] In this embodiment of the application, the method further includes:
[0115] If the first authentication result indicates that the second node did not respond to the first node's authentication request, then the second node is determined to be an untrusted node in an abnormal state.
[0116] After determining that the second node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the second node is taken offline.
[0117] If the second authentication result indicates that the first node did not respond to the second node's authentication request, then the first node is an untrusted node in an abnormal state.
[0118] After determining that the first node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the first node is taken offline.
[0119] Among them, untrusted nodes can refer to nodes that do not have certificates, whose certificates have expired, or whose stored keys cannot support the encryption algorithm initiated. When the first node initiates an authentication request to the second node, if it does not receive a response from the second node to the first node, it indicates that the second node is an untrusted node and is identified as an abnormal node.
[0120] Offline processing refers to the process where, after receiving the authentication result, the management and monitoring platform confirms that a node is an abnormal node, and then removes the abnormal node from the transmission channel to prevent traffic from being transmitted on the abnormal node in subsequent steps.
[0121] If the first authentication result indicates that the second node did not respond to the first node's authentication request, then the second node is an untrusted node and is determined to be an abnormal node. After the second node is determined to be an abnormal node, an alarm message is output to the management and monitoring platform in the traffic transmission system, and the second node is taken offline. For example, the first node initiates an authentication request to the second node. The second node receives the authentication request but does not respond to the first node. Since the first node does not receive a response from the second node, the management and monitoring platform receives the authentication result, determines that the second node is an abnormal node, issues an alarm for the abnormal node, and removes the second node to prevent traffic from being transmitted on the abnormal node in subsequent steps.
[0122] In this embodiment of the application, the method further includes:
[0123] When encrypted traffic is transmitted to the first node, the first node stops sending authentication requests to the second node;
[0124] When encrypted traffic is transmitted to the second node, the second node stops sending authentication requests to the first node.
[0125] Specifically, when encrypted traffic is transmitted to the first node, the first node stops sending authentication requests to the second node. This can mean that the second node initiates an authentication request to the first node, the first node receives the request and responds to the second node with the authentication request, obtains the second authentication result, and completes the authentication process. This determines that the first node is a trusted node, thus ensuring the trustworthiness of the first node. Therefore, the traffic can be encrypted at the first node. Consequently, when encrypted traffic is transmitted to the first node, the first node can stop sending authentication requests to the second node.
[0126] S103. According to the encryption algorithm, the first node and the second node in the transfer channel are encrypted to obtain the encrypted transfer channel.
[0127] The encrypted transfer channel refers to the transmission channel composed of encrypted nodes obtained by encrypting the first and second nodes. All data traffic establishes an encrypted transfer channel when flowing through the nodes. It has the characteristics of high efficiency in establishing the encrypted transfer channel. Furthermore, the encryption of nodes in the encrypted transfer channel can adopt the superposition of different encryption algorithms, thus ensuring the security of the data.
[0128] S104. Transmit encrypted traffic according to the encrypted flow channel.
[0129] Transmitting encrypted traffic can refer to encrypting traffic that has been confirmed to be free of abnormalities through the aforementioned steps, by passing it through the first and second nodes on the encrypted transfer channel.
[0130] After the traffic is encrypted by the first and second nodes on the encrypted transfer channel, it is transmitted from the second node to the destination IP address, thus completing the traffic transmission process.
[0131] The traffic transmission method provided in this application determines the transmission channel and encryption algorithm of the encrypted traffic based on the encryption requirements of the encrypted traffic. It stores the key corresponding to the encryption algorithm in a first node and a second node. The first node initiates an authentication request to the second node at a first preset time and a preset frequency. The second node receives the authentication request and responds to the first node. The second node then sends an authentication request to the first node at a second preset time and a preset frequency. The first node receives the authentication request and responds to the second node, thus determining the first and second nodes as trusted nodes. Encryption is then performed on the first and second nodes in the transmission channel to obtain an encrypted transmission channel. Finally, the encrypted traffic is transmitted. This eliminates the need for authentication of the first and second nodes by the management and monitoring platform, avoiding excessive permissions on the platform and resulting in high load and management chaos. It optimizes the processing capacity of the management and monitoring platform. Furthermore, by using any node as a trusted node and other arbitrary nodes as verification objects, continuous mutual authentication is performed until the traffic transmission passes through the nodes, enhancing the security and trustworthiness of the nodes and strengthening network security defenses.
[0132] Figure 2 A flowchart illustrating another traffic transmission method provided in this application embodiment is shown below. Figure 2 As shown, the method may include:
[0133] S201. Upon receiving data traffic, check whether the basic information of the traffic is correct, whether the destination IP is correct and compliant, and whether it has IP registration information.
[0134] If the destination IP address is abnormal, it is considered abnormal traffic.
[0135] S202. If the destination IP address is correct, check the packet weight.
[0136] S203. Based on the actual business situation and the size of the data packets generated by the actual business, a baseline value is defined. The value of the flexible field of data traffic is compared with the baseline value. If the data packet size is not abnormal, it is considered normal traffic.
[0137] The flexible field part can refer to the data part, that is, the size of the business data volume.
[0138] If the size of a data packet is significantly larger or smaller than the baseline value, it is considered abnormal traffic.
[0139] S204. Normal traffic is divided into encrypted traffic and unencrypted traffic depending on whether it needs to be transmitted encrypted.
[0140] Here, encryption refers to channel encryption, which includes data that has been encrypted by the source. However, this does not affect the continued implementation of the method. For traffic that does not require encryption, the data traffic can be transferred directly using the conventional method.
[0141] S205. For traffic that requires encryption, an encryption requirement identifier will be added before it flows to the next node. At the same time, a message indicating that encryption is required will be sent to the headquarters network security management and monitoring platform. The platform will then broadcast the message to all nodes related to the traffic to enable encryption until the traffic reaches its destination IP.
[0142] Among them, the encryption requirement identifier can indicate that the traffic can select an encryption algorithm according to its own needs and generate an encryption requirement identifier corresponding to the encryption algorithm.
[0143] S206. Each node can act as a trusted node, initiating authentication requests to other nodes at a certain frequency. The authentication results are transmitted back to the network security management and monitoring platform, allowing the platform to keep track of node movements at all times and promptly handle any abnormal nodes, such as forcibly taking them offline.
[0144] In this process, node 1 is selected as a trusted node. It randomly sends verification requests to any other node every 5 minutes. These requests include mutual authentication of certificates, certificate validity period, a list of algorithms that the node can use, and the status of any other node. Similarly, node 2 can also send authentication requests as a trusted node, but it needs to be scheduled at a certain frequency to avoid the authentication requests sent by the previous node. For example, if node 1's time is 8:00 AM, then node 2's time can be set to 9:00 AM or later to ensure that nodes can send mobile trusted authentication requests at off-peak times.
[0145] The network security management and monitoring platform includes a broadcast channel management module, a mobile trusted management module, and a security situation monitoring module. The broadcast channel management module mainly handles functions related to broadcast channel encryption, including the establishment of broadcast channels and the broadcasting of cryptographic algorithms. The mobile trusted management module mainly manages the security of each routing node, including mutual authentication between nodes (including key attributes such as certificate version, protocol, and validity period), node algorithms, and authentication result management. The authentication results are mainly used as the data source for security situation monitoring. The security monitoring platform mainly monitors and displays the status of node authentication results, and can provide timely warnings for abnormal nodes, thereby improving system maintenance efficiency.
[0146] Another traffic transmission method provided in this application adopts different processing methods for traffic demand in different scenarios, utilizes the concept of broadcast encryption, establishes a public channel as the basis, reduces the interactive negotiation process, generalizes the concept of trust, takes the trust of any node as the basis, and combines dynamic monitoring and management methods to strengthen trust management and realize the trusted transmission of traffic through full routing. On the other hand, it takes data traffic as the monitoring object, monitors key characteristics such as data packet weight and traffic data flow direction, and identifies abnormal traffic, thus ensuring the security of traffic during the flow process.
[0147] Figure 3 This is a schematic diagram of a traffic transmission method provided in an embodiment of this application, such as... Figure 3 As shown, this scenario can be a traffic transmission system, which may include:
[0148] Upon receiving a data stream, the encryption requirement is determined. Unencrypted traffic without encryption requirements will not be discussed here. For encrypted traffic with encryption requirements, the network security management and monitoring platform initiates channel encryption simultaneously on all nodes to be transmitted on broadcast channel 1 (to destination A), broadcast channel 2 (to destination B), and broadcast channel 3 (to destination C) according to the encryption requirements of the data stream. Broadcast channel 1 uses the SM4 encryption algorithm, broadcast channel 2 uses the SM3 encryption algorithm, and broadcast channel 3 uses the SM2 encryption algorithm.
[0149] Figure 4 This is a schematic diagram of the structure of the traffic transmission device provided in an embodiment of this application. Figure 4 As shown, the traffic transmission device 40 includes: an acquisition module 401, a determination module 402, a obtaining module 403, and a transmission module 404. Wherein:
[0150] The acquisition module 401 is used to acquire the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier is set according to the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted in the encrypted traffic, and the encryption requirement information represents the encryption method of the node to be transmitted.
[0151] The determination module 402 is used to determine the transfer channel of the encrypted traffic and the encryption algorithm of the transfer channel according to the encryption requirement identifier. The transfer channel includes a first node and a second node, and the first node is the previous transmission node of the second node.
[0152] Module 403 is used to encrypt the first and second nodes in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel;
[0153] The transmission module 404 is used to transmit encrypted traffic according to the encrypted flow channel.
[0154] In this embodiment of the application, the acquisition module 401 can also be specifically used for:
[0155] Acquire data traffic and the nodes from which the data traffic is to be transmitted;
[0156] If there are no abnormalities in the node to which the data traffic is to be transmitted, then the data traffic is determined to be the initial target traffic;
[0157] If the initial target traffic meets the baseline requirement, then the initial target traffic is determined as the target traffic. The baseline requirement represents the amount of data required for the encrypted traffic to complete the target service.
[0158] In response to a user's request to encrypt the target traffic, the system determines that the target traffic is encrypted and obtains the transmission information and encryption requirement information of the encrypted traffic.
[0159] Based on the transmission information and encryption requirement information, the encrypted traffic is marked to obtain the encryption requirement identifier of the encrypted traffic.
[0160] In this embodiment of the application, the determining module 402 can also be specifically used for:
[0161] If the node to which the data traffic is to be transmitted is abnormal, the data traffic is identified as the first abnormal traffic and a backup encrypted transfer channel is determined.
[0162] Use the backup encrypted transfer channel as the transfer channel for encrypted traffic, and re-execute the steps of obtaining data traffic and the node to be transmitted for data traffic.
[0163] In this embodiment of the application, the determining module 402 can also be specifically used for:
[0164] Determine the packets of the initial target traffic, the unformatted data in the packets, and the baseline value requirements;
[0165] Compare the baseline values with the unformatted data to obtain the comparison results;
[0166] If the comparison results indicate that the unformatted data meets the baseline requirements, then the initial target flow is determined to meet the baseline requirements, and the initial target flow is determined to be the target flow.
[0167] In this embodiment of the application, the determining module 402 can also be specifically used for:
[0168] If the comparison results indicate that the unformatted data does not meet the baseline value requirements, then the initial target flow is determined to be the second abnormal flow that does not meet the baseline value requirements;
[0169] Based on the second abnormal traffic, the transmission process of encrypted traffic is stopped.
[0170] In this embodiment of the application, the determining module 402 can also be specifically used for:
[0171] Based on the encryption requirements, the key is stored in the first node and the second node. The key is the key corresponding to the encryption algorithm.
[0172] Adjust the first and second nodes to be the initial trusted nodes;
[0173] After adjusting the first node and the second node to be initial trusted nodes, control the first node to initiate an authentication request to the second node at a first preset time and a preset frequency, and obtain the first authentication result;
[0174] The second node is controlled to initiate an authentication request to the first node at a second preset time and a preset frequency, and a second authentication result is obtained.
[0175] Based on the first authentication result and the second authentication result, the first node and the second node are determined to be trusted nodes, so as to execute the step of encrypting the first node and the second node in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel.
[0176] In this embodiment of the application, the determining module 402 can also be specifically used for:
[0177] If the first authentication result indicates that the second node did not respond to the first node's authentication request, then the second node is determined to be an untrusted node in an abnormal state.
[0178] After determining that the second node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the second node is taken offline.
[0179] If the second authentication result indicates that the first node did not respond to the second node's authentication request, then the first node is an untrusted node in an abnormal state.
[0180] After determining that the first node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the first node is taken offline.
[0181] In this embodiment of the application, the determining module 402 can also be specifically used for:
[0182] When encrypted traffic is transmitted to the first node, the first node stops sending authentication requests to the second node;
[0183] When encrypted traffic is transmitted to the second node, the second node stops sending authentication requests to the first node.
[0184] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 5 As shown, the electronic device 50 includes:
[0185] The electronic device 50 may include a processor 501 with one or more processing cores, a memory 502 with one or more computer-readable storage media, a communication component 503, and other components. The processor 501, memory 502, and communication component 503 are connected via a bus 504.
[0186] In the specific implementation process, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to execute the above-mentioned traffic transmission method.
[0187] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0188] In the above Figure 5 In the illustrated embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0189] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0190] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0191] In some embodiments, a computer program product is also provided, including a computer program or instructions that, when executed by a processor, implement the steps in any of the above-described traffic transmission methods.
[0192] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0193] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0194] Therefore, embodiments of this application provide a computer-readable storage medium storing a plurality of instructions that can be loaded by a processor to execute steps in any of the traffic transmission methods provided in embodiments of this application.
[0195] The storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0196] According to one aspect of this application, a computer program product or computer program is provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium.
[0197] Since the instructions stored in the storage medium can execute the steps of any of the traffic transmission methods provided in the embodiments of this application, the beneficial effects that any of the traffic transmission methods provided in the embodiments of this application can achieve can be realized. For details, please refer to the previous embodiments, which will not be repeated here.
[0198] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0199] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for transmitting traffic, characterized in that, Applied to a traffic transmission system, the method includes: Obtain the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier is set according to the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted by the encrypted traffic, and the encryption requirement information represents the encryption method for the node to be transmitted. Based on the encryption requirement identifier, the transfer channel of the encrypted traffic and the encryption algorithm of the transfer channel are determined, wherein the transfer channel includes a first node and a second node, and the first node is the previous transmission node of the second node; According to the encryption algorithm, the first node and the second node in the transfer channel are encrypted to obtain an encrypted transfer channel; The encrypted traffic is transmitted according to the encrypted transfer channel.
2. The method according to claim 1, characterized in that, The encryption requirement identifier for obtaining encrypted traffic includes: Obtain the data traffic and the node to which the data traffic is to be transmitted; If the node to which the data traffic is to be transmitted is normal, then the data traffic is determined to be the initial target traffic; If the initial target traffic meets the baseline value requirement, then the initial target traffic is determined to be the target traffic, and the baseline value requirement represents the amount of data required for the encrypted traffic to complete the target service; In response to a user's encryption request for the target traffic, the target traffic is identified as the encrypted traffic, and the transmission information and encryption requirement information of the encrypted traffic are obtained. Based on the transmission information and the encryption requirement information, the encrypted traffic is marked to obtain the encryption requirement identifier of the encrypted traffic.
3. The method according to claim 2, characterized in that, After acquiring the data traffic and the node to which the data traffic is to be transmitted, the method further includes: If the node to which the data traffic is to be transmitted is abnormal, the data traffic is determined to be the first abnormal traffic and a backup encrypted transfer channel is determined. The backup encrypted transfer channel is used as the transfer channel for the encrypted traffic, and the steps of obtaining the data traffic and the node to be transmitted for the data traffic are re-executed.
4. The method according to claim 2, characterized in that, The step of determining the initial target traffic as target traffic if the initial target traffic meets the baseline value requirement includes: Determine the data packets of the initial target traffic, the unformatted data in the data packets, and the baseline value requirements; The baseline value requirement and the unformatted data are compared to obtain the comparison result; If the comparison result indicates that the unformatted data meets the baseline value requirement, then the initial target traffic is determined to meet the baseline value requirement, and the initial target traffic is determined to be the target traffic.
5. The method according to claim 4, characterized in that, After comparing the baseline value requirement and the unformatted data to obtain the comparison result, the method further includes: If the comparison result indicates that the unformatted data does not meet the baseline value requirement, then the initial target traffic is determined to be a second abnormal traffic that does not meet the baseline value requirement; Based on the second abnormal traffic, the transmission process of the encrypted traffic is stopped.
6. The method according to claim 1, characterized in that, Before encrypting the first node and the second node in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel, the method further includes: Based on the encryption requirement information, a key is stored in the first node and the second node, and the key is a key corresponding to the encryption algorithm; Adjust the first node and the second node to be initial trusted nodes; After adjusting the first node and the second node as initial trusted nodes, the first node is controlled to initiate an authentication request to the second node at a first preset time and a preset frequency to obtain a first authentication result. The second node is controlled to initiate an authentication request to the first node at a second preset time and a preset frequency, and a second authentication result is obtained. Based on the first authentication result and the second authentication result, the first node and the second node are determined to be trusted nodes, so as to execute the step of encrypting the first node and the second node in the transfer channel according to the encryption algorithm to obtain the encrypted transfer channel.
7. The method according to claim 6, characterized in that, The method further includes: If the first authentication result indicates that the second node did not respond to the authentication request of the first node, then the second node is determined to be an untrusted node in an abnormal state; After determining that the second node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the second node is taken offline. If the second authentication result indicates that the first node did not respond to the second node's authentication request, then the first node is an untrusted node in an abnormal state; After determining that the first node is an untrusted node in an abnormal state, an alarm message is sent to the management and monitoring platform in the traffic transmission system, and the first node is taken offline.
8. The method according to claim 6, characterized in that, The method further includes: When the encrypted traffic is transmitted to the first node, the first node stops sending authentication requests to the second node; When the encrypted traffic is transmitted to the second node, the second node stops sending authentication requests to the first node.
9. A flow transmission device, characterized in that, include: The acquisition module is used to acquire the encryption requirement identifier of the encrypted traffic. The encryption requirement identifier is set according to the transmission information and encryption requirement information of the encrypted traffic. The transmission information represents the node to be transmitted by the encrypted traffic, and the encryption requirement information represents the encryption method for the node to be transmitted. The determination module is used to determine the transfer channel of the encrypted traffic and the encryption algorithm of the transfer channel based on the encryption requirement identifier, wherein the transfer channel includes a first node and a second node, and the first node is the previous transmission node of the second node; Obtaining module: According to the encryption algorithm, encrypt the first node and the second node in the transfer channel to obtain the encrypted transfer channel; Transmission module: Transmits the encrypted traffic according to the encrypted streaming channel.
10. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the traffic transmission method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Data transmission method and device, electronic equipment and storage medium
CN111131245A
Multiplexing security tunnels
US20190306116A1