Method and system for secure switching and transmission of data streams in communication networks

By monitoring the data stream of the communication network gateway nodes to transmit time domain attribute information, identifying and avoiding abnormal gateway nodes, and redetermining the data transmission path, the delay and reliability problems of data flow switching transmission in the communication network are solved, and efficient data flow security switching is achieved.

CN118540154BActive Publication Date: 2025-08-22SICHUAN ZHIHE NEW ENERGY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410918923.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-10
Publication Date
2025-08-22
Estimated Expiration
2044-07-10

AI Technical Summary

Technical Problem

The prior art cannot efficiently and quickly bypass the abnormal gateway node for data flow switching transmission in the communication network, resulting in delay distortion and reliability of data flow transmission.

Method used

Listen to the time domain attribute information of the data stream transmission of the gateway nodes within the communication network, identify the abnormal gateway nodes, and redetermine the data transmission path to avoid the abnormal nodes, ensuring safe switching of the data flow.

Benefits of technology

It improves the data streaming transmission quality of the communication network, avoids the delay distortion of data streaming transmission, and enhances the reliability and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118540154B_ABST
    Figure CN118540154B_ABST
Patent Text Reader

Abstract

The present invention provides a data stream security switching transmission method and system for a communication network, which monitors the data stream transmission time domain attribute information of each gateway node within the communication network to determine the time distribution characteristic information of a suspicious data transmission event at each gateway node; identifies abnormal gateway nodes based on the time distribution characteristic information of the gateway nodes and the channel allocation time attribute information of all corresponding connected terminals, thereby identifying a faulty data transmission path within the communication network; monitors the actual data transmission path of a target terminal connected to the communication network and compares it with the faulty data transmission path to determine whether the target terminal is in a data transmission security state; and re-determines the data transmission path based on the transmission end point of the actual data transmission path and all gateway nodes under all the faulty data transmission paths, thereby performing a data stream transmission switching operation on the target terminal, avoiding the influence of the abnormal gateway node and improving the data stream transmission quality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a method and system for securely switching and transmitting data streams in a communication network. Background Art

[0002] Communication networks can provide data transmission channels for a large number of terminals, such as smartphones and portable computers. Data streams emitted by these terminals can be quickly and stably transmitted to their respective endpoints after passing through different gateway nodes within the communication network. In actual communication network operations, gateway nodes inevitably face problems such as data saturation or intrusion. This can result in insufficient bandwidth for the corresponding gateway node to transmit additional data streams, or the gateway node being hijacked, leading to security risks such as data leakage and illegal tampering, reducing the reliability and security of data stream transmission within the communication network. Currently, to ensure the normal transmission of data streams, if an abnormality is detected in a gateway node, the corresponding gateway node is blocked to prohibit further data transmission. This method can effectively prevent abnormal gateway nodes from interfering with the normal operation of the entire communication network, but it does not provide a solution for subsequently bypassing abnormal gateway nodes for efficient and rapid data transmission. This reduces the timeliness and reliability of data stream switching within the communication network, degrades the overall data stream transmission quality of the communication network, and is prone to problems such as data stream transmission delay and distortion. Summary of the Invention

[0003] In response to the defects of the prior art, the present invention provides a method and system for secure switching and transmission of data streams in a communication network, which monitors the data stream transmission time domain attribute information of each gateway node within the communication network, thereby determining the time distribution characteristic information of a suspicious data transmission event occurring at each gateway node, and performing preliminary data transmission status screening on the gateway nodes; based on the time distribution characteristic information of the gateway nodes and the channel allocation time attribute information of all corresponding connected terminals, the method and system identify abnormal gateway nodes, thereby identifying faulty data transmission paths within the communication network, and providing a reference basis for subsequent data stream switching and transmission; monitors the actual data transmission path of the target terminal connected to the communication network, and compares it with the faulty data transmission path to determine whether the target terminal is in a data transmission safety state, and determine the data stream switching and transmission requirements of the target terminal; and also redetermines the data transmission path based on the transmission end point of the actual data transmission path and all gateway nodes under all faulty data transmission paths, thereby performing data stream transmission switching operations on the target terminal, effectively avoiding the influence of abnormal gateway nodes, improving the data stream transmission quality of the communication network, and avoiding problems such as data stream transmission delay and distortion.

[0004] The present invention provides a method for securely switching and transmitting data streams in a communication network, comprising the following steps:

[0005] Step S1: monitor all gateway nodes within the communication network to obtain data flow transmission time domain attribute information of each gateway node; based on the data flow transmission time domain attribute information, determine the time distribution characteristic information of the suspicious data transmission event occurring at the gateway node;

[0006] Step S2, based on the time distribution characteristic information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals, determining whether the gateway node is an abnormal gateway node; based on the location distribution attribute information of all abnormal gateway nodes in the communication network, identifying all faulty data transmission paths in the communication network;

[0007] Step S3: monitoring the target terminal connected to the communication network to obtain the actual data transmission path of the target terminal; comparing the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission safety state;

[0008] Step S4, when the target terminal is not currently in a data transmission safety state, the data transmission path of the target terminal is re-determined based on the transmission end point of the actual data transmission path and all gateway nodes under all faulty data transmission paths; and based on the re-determined data transmission path, a data stream transmission switching operation is performed on the target terminal.

[0009] In one embodiment disclosed in the present application, in step S1, all gateway nodes within the communication network are monitored to obtain data stream transmission time domain attribute information of each gateway node; based on the data stream transmission time domain attribute information, time distribution characteristic information of a suspicious data transmission event occurring at the gateway node is determined, including:

[0010] Based on the network link distance between all gateway nodes within the communication network and the communication server, all gateway nodes are divided into several gateway node areas, and each gateway node area is independently monitored to obtain data flow transmission change information of all gateway nodes under each gateway node area; the data flow transmission change information is analyzed to obtain the change rate of the data flow transmission fluctuation amplitude of the gateway node over time, which is used as the data transmission time domain attribute information;

[0011] Based on the rate of change of the data traffic transmission fluctuation amplitude over time, determine the maximum continuous time during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node exceeds the preset rate of change; if the maximum continuous time is greater than the preset time threshold, determine that a suspicious data transmission event has occurred at the gateway node; otherwise, determine that no suspicious data transmission event has occurred at the gateway node; and use the distribution information of all durations during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node where the suspicious data transmission event has occurred exceeds the preset rate of change as the time distribution characteristic information of the occurrence of the suspicious data transmission event.

[0012] In one embodiment disclosed in the present application, in step S2, based on the time distribution characteristic information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals, determining whether the gateway node is an abnormal gateway node; based on the location distribution attribute information of all abnormal gateway nodes within the communication network, identifying all faulty data transmission paths within the communication network, including:

[0013] Obtaining information on the time interval allocation of the data transmission channel allowed to all terminals connected to the gateway node where the suspicious data transmission event occurs, and using this information as the channel allocation time attribute information; comparing the time distribution characteristic information corresponding to the gateway node with the channel allocation time attribute information to obtain the time proportion of the time zone in which the suspicious data transmission event occurs when each connected terminal is allowed to use the data transmission channel; if the time proportions corresponding to terminals exceeding a preset number of proportions all exceed a preset time proportion threshold, determining that the gateway node is an abnormal gateway node; otherwise, determining that the gateway node is not an abnormal gateway node;

[0014] Based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a fault data transmission path distribution map corresponding to the communication network is generated; wherein, the fault data transmission path distribution map includes the communication link distribution information corresponding to each of the fault data transmission paths within the communication network.

[0015] In one embodiment disclosed in the present application, in step S3, monitoring a target terminal connected to the communication network to obtain an actual data transmission path of the target terminal; and comparing the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission security state includes:

[0016] Based on the identity information of the target terminal accessing the communication network, performing targeted monitoring on the target terminal to obtain a transmission destination of data transmission by the target terminal, thereby determining the shortest data transmission path between the target terminal and the transmission destination, and using the shortest data transmission path as the actual data transmission path;

[0017] The actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined; if the gateway node overlap rate exceeds a preset overlap rate threshold, it is determined whether the communication link distance between the abnormal gateway nodes within the actual data transmission path exceeds a preset distance threshold; if so, it is determined that the target terminal is not currently in a data transmission safety state; if not, it is determined that the target terminal is currently in a data transmission safety state.

[0018] In one embodiment disclosed in the present application, in step S4, when the target terminal is not currently in a data transmission safety state, the data transmission path of the target terminal is re-determined based on the transmission endpoint of the actual data transmission path and all gateway nodes under all failed data transmission paths; and based on the re-determined data transmission path, a data stream transmission switching operation is performed on the target terminal, including:

[0019] When the target terminal is not currently in a data transmission safety state, determining the location information of all gateway nodes under all non-faulty data transmission paths within the communication network based on the location information of all gateway nodes under the faulty data transmission path within the communication network; and re-determining the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network;

[0020] Based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted by the target terminal is divided into a plurality of data packets, and all the data packets are grouped into a data packet queue before performing a data stream transmission switching operation.

[0021] The present invention also provides a data stream secure switching transmission system for a communication network, comprising:

[0022] The gateway node monitoring module is used to monitor all gateway nodes in the communication network and obtain the time domain attribute information of the data stream transmission of each gateway node;

[0023] a data transmission time characteristic determination module, configured to determine time distribution characteristic information of a suspicious data transmission event occurring at the gateway node based on the data stream transmission time domain attribute information;

[0024] an abnormal gateway node identification module, configured to determine whether the gateway node is an abnormal gateway node based on the time distribution characteristic information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals;

[0025] A faulty data transmission path identification module, configured to identify all faulty data transmission paths within the communication network based on location distribution attribute information of all abnormal gateway nodes within the communication network;

[0026] A target terminal monitoring module is used to monitor the target terminal connected to the communication network and obtain the actual data transmission path of the target terminal;

[0027] a data transmission security state judgment module, configured to compare the actual data transmission path with all faulty data transmission paths to judge whether the target terminal is currently in a data transmission security state;

[0028] a data transmission path redetermining module, configured to, when the target terminal is not currently in a data transmission safety state, redetermine the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and all gateway nodes under all failed data transmission paths;

[0029] The data stream transmission switching module is used to perform a data stream transmission switching operation on the target terminal based on the re-determined data transmission path.

[0030] In one embodiment disclosed in the present application, the gateway node monitoring module is used to monitor all gateway nodes within the communication network to obtain the data stream transmission time domain attribute information of all gateway nodes, including:

[0031] Based on the network link distance between all gateway nodes within the communication network and the communication server, all gateway nodes are divided into several gateway node areas, and each gateway node area is independently monitored to obtain data flow transmission change information of all gateway nodes under each gateway node area; the data flow transmission change information is analyzed to obtain the change rate of the data flow transmission fluctuation amplitude of the gateway node over time, which is used as the data transmission time domain attribute information;

[0032] The data transmission time feature determination module is configured to determine time distribution feature information of a suspicious data transmission event occurring at the gateway node based on the data stream transmission time domain attribute information, including:

[0033] Based on the rate of change of the data traffic transmission fluctuation amplitude over time, determine the maximum continuous time during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node exceeds the preset rate of change; if the maximum continuous time is greater than the preset time threshold, determine that a suspicious data transmission event has occurred at the gateway node; otherwise, determine that no suspicious data transmission event has occurred at the gateway node; and use the distribution information of all durations during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node where the suspicious data transmission event has occurred exceeds the preset rate of change as the time distribution characteristic information of the occurrence of the suspicious data transmission event.

[0034] In one embodiment disclosed in the present application, the abnormal gateway node identification module is configured to determine whether the gateway node is an abnormal gateway node based on the time distribution feature information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals, including:

[0035] Obtaining information on the time interval allocation of the data transmission channel allowed to all terminals connected to the gateway node where the suspicious data transmission event occurs, and using this information as the channel allocation time attribute information; comparing the time distribution characteristic information corresponding to the gateway node with the channel allocation time attribute information to obtain the time proportion of the time zone in which the suspicious data transmission event occurs when each connected terminal is allowed to use the data transmission channel; if the time proportions corresponding to terminals exceeding a preset number of proportions all exceed a preset time proportion threshold, determining that the gateway node is an abnormal gateway node; otherwise, determining that the gateway node is not an abnormal gateway node;

[0036] The faulty data transmission path identification module is used to identify all faulty data transmission paths within the communication network based on the location distribution attribute information of all abnormal gateway nodes within the communication network, including:

[0037] Based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a fault data transmission path distribution map corresponding to the communication network is generated; wherein, the fault data transmission path distribution map includes the communication link distribution information corresponding to each of the fault data transmission paths within the communication network.

[0038] In one embodiment disclosed in the present application, the target terminal monitoring module is configured to monitor a target terminal accessing the communication network to obtain an actual data transmission path of the target terminal, including:

[0039] Based on the identity information of the target terminal accessing the communication network, performing targeted monitoring on the target terminal to obtain a transmission destination of data transmission by the target terminal, thereby determining the shortest data transmission path between the target terminal and the transmission destination, and using the shortest data transmission path as the actual data transmission path;

[0040] The data transmission security status judgment module is configured to compare the actual data transmission path with all faulty data transmission paths to judge whether the target terminal is currently in a data transmission security state, including:

[0041] The actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined; if the gateway node overlap rate exceeds a preset overlap rate threshold, it is determined whether the communication link distance between the abnormal gateway nodes within the actual data transmission path exceeds a preset distance threshold; if so, it is determined that the target terminal is not currently in a data transmission safety state; if not, it is determined that the target terminal is currently in a data transmission safety state.

[0042] In one embodiment disclosed in the present application, the data transmission path redetermining module is configured to, when the target terminal is not currently in a data transmission safety state, redetermine the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and all gateway nodes under all failed data transmission paths, including:

[0043] When the target terminal is not currently in a data transmission safety state, determining the location information of all gateway nodes under all non-faulty data transmission paths within the communication network based on the location information of all gateway nodes under the faulty data transmission path within the communication network; and re-determining the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network;

[0044] The data stream transmission switching module is configured to perform a data stream transmission switching operation on the target terminal based on the re-determined data transmission path, including:

[0045] Based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted by the target terminal is divided into a plurality of data packets, and all the data packets are grouped into a data packet queue before performing a data stream transmission switching operation.

[0046] Compared with the existing technology, the data stream security switching transmission method and system of the communication network monitors the data stream transmission time domain attribute information of each gateway node in the communication network, thereby determining the time distribution characteristic information of the suspicious data transmission event of each gateway node, and performing preliminary data transmission status screening of the gateway node; based on the time distribution characteristic information of the gateway node and the channel allocation time attribute information of all the corresponding connected terminals, the abnormal gateway nodes are identified, thereby identifying the faulty data transmission path in the communication network, providing a reference basis for subsequent data stream switching transmission; the actual data transmission path of the target terminal connected to the communication network is monitored and compared with the faulty data transmission path to determine whether the target terminal is in a data transmission security state and determine the data stream switching transmission requirements of the target terminal; the data transmission path is also re-determined based on the transmission end point of the actual data transmission path and all gateway nodes under all the faulty data transmission paths, thereby performing data stream transmission switching operations on the target terminal, effectively avoiding the influence of abnormal gateway nodes, improving the data stream transmission quality of the communication network, and avoiding problems such as data stream transmission delay and distortion.

[0047] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.

[0048] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0050] Figure 1 A schematic flow chart of a method for securely switching and transmitting data streams in a communication network provided by the present invention.

[0051] Figure 2 This is a schematic diagram of the framework of the data stream secure switching transmission system for the communication network provided by the present invention. DETAILED DESCRIPTION

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0053] See Figure 1 , is a flow chart of a method for securely switching and transmitting data streams in a communication network provided by an embodiment of the present invention. The method for securely switching and transmitting data streams in a communication network includes:

[0054] Step S1: monitor all gateway nodes within the communication network to obtain data flow transmission time domain attribute information of each gateway node; based on the data flow transmission time domain attribute information, determine the time distribution characteristic information of the suspicious data transmission event of the gateway node;

[0055] Step S2: determining whether the gateway node is an abnormal gateway node based on the time distribution characteristic information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals; and identifying all faulty data transmission paths within the communication network based on the location distribution attribute information of all abnormal gateway nodes within the communication network;

[0056] Step S3: monitoring the target terminal connected to the communication network to obtain the actual data transmission path of the target terminal; comparing the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission safety state;

[0057] Step S4, when the target terminal is not currently in a data transmission safety state, the data transmission path of the target terminal is re-determined based on the transmission end point of the actual data transmission path and all gateway nodes under all faulty data transmission paths; and based on the re-determined data transmission path, the data stream transmission switching operation is performed on the target terminal.

[0058] The beneficial effects of the above technical solution are as follows: the data stream security switching transmission method of the communication network monitors the data stream transmission time domain attribute information of each gateway node within the communication network, thereby determining the time distribution characteristic information of a suspicious data transmission event at each gateway node, and performing preliminary data transmission status screening on the gateway node; based on the time distribution characteristic information of the gateway node and the channel allocation time attribute information of all corresponding connected terminals, the abnormal gateway node is identified, thereby identifying the faulty data transmission path within the communication network, providing a reference basis for subsequent data stream switching transmission; the actual data transmission path of the target terminal connected to the communication network is monitored and compared with the faulty data transmission path to determine whether the target terminal is in a data transmission security state and determine the data stream switching transmission requirements of the target terminal; the data transmission path is re-determined based on the transmission end point of the actual data transmission path and all gateway nodes under all faulty data transmission paths, thereby performing data stream transmission switching operations on the target terminal, effectively avoiding the influence of abnormal gateway nodes, improving the data stream transmission quality of the communication network, and avoiding problems such as data stream transmission delay and distortion.

[0059] Preferably, in step S1, all gateway nodes within the communication network are monitored to obtain data flow transmission time domain attribute information of each gateway node; based on the data flow transmission time domain attribute information, time distribution characteristic information of a suspicious data transmission event occurring at the gateway node is determined, including:

[0060] Based on the network link distance between all gateway nodes in the communication network and the communication server, all gateway nodes are divided into several gateway node areas. Each gateway node area is independently monitored to obtain the data flow transmission change information of all gateway nodes under each gateway node area. This data flow transmission change information is analyzed to obtain the change rate of the data flow transmission fluctuation amplitude of the gateway node over time, which is used as the time domain attribute information of the data transmission;

[0061] Based on the rate of change of the data traffic transmission fluctuation amplitude over time, determine the maximum continuous time during which the data traffic transmission fluctuation amplitude change rate of the gateway node exceeds the preset change rate; if the maximum continuous time is greater than the preset time threshold, determine that a suspicious data transmission event has occurred at the gateway node; otherwise, determine that no suspicious data transmission event has occurred at the gateway node; and use the distribution information of all durations during which the data traffic transmission fluctuation amplitude change rate of the gateway node where the suspicious data transmission event occurs exceeds the preset change rate as the time distribution characteristic information of the occurrence of the suspicious data transmission event.

[0062] The beneficial effects of the above technical solution are as follows: the communication network contains a large number of gateway nodes, each of which works independently as a data transmission intermediary. Terminals such as smartphones or portable computers access the corresponding gateway nodes to use the communication network for data flow transmission and interaction. The communication network is also equipped with a communication server, which is used to control and manage all gateway nodes under the communication network. The communication network contains a large number of gateway nodes. If all gateway nodes are monitored separately, it will consume a large amount of monitoring computing resources and the real-time monitoring cannot be guaranteed. To this end, based on the network link distance between all gateway nodes in the communication network and the communication server, all gateway nodes are divided into several gateway node areas, so that the network link distance between each gateway node area and the communication server is within a corresponding distance interval. Then, each gateway node area is monitored independently to obtain the data flow transmission change information of all gateway nodes under each gateway node area. In this way, it is possible to achieve fast real-time monitoring of all gateway nodes without having to monitor all gateway nodes separately, and accurately determine the changes in the data flow transmission volume of each gateway node. The data traffic transmission change information is then analyzed to obtain the rate of change of the data traffic transmission fluctuation amplitude of the gateway node over time, that is, the rate of change of the data traffic transmission fluctuation of the gateway node, thereby quantitatively characterizing the degree of fluctuation of the data traffic passing through the gateway node during data transmission. Furthermore, based on the rate of change of the data traffic transmission fluctuation amplitude over time, the maximum continuous time during which the data traffic transmission fluctuation amplitude change rate of the gateway node exceeds a preset change rate is determined. If the maximum continuous time is greater than a preset time threshold, it is determined that a suspicious data transmission event has occurred at the gateway node. This allows screening of gateway nodes whose data traffic fluctuates significantly for a long period of time during data transmission, thereby accurately locating and identifying gateway nodes that are affected by traffic attacks and affect normal data transmission. The distribution information of all durations during which the data traffic transmission fluctuation amplitude change rate of the gateway node experiencing the suspicious data transmission event exceeds the preset change rate is used as the time distribution characteristic information of the suspicious data transmission event. This allows accurate and comprehensive characterization of the time distribution pattern of the suspicious data transmission event occurring at the gateway node.

[0063] Preferably, in step S2, based on the time distribution characteristic information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals, determining whether the gateway node is an abnormal gateway node; based on the location distribution attribute information of all abnormal gateway nodes in the communication network, identifying all faulty data transmission paths in the communication network, including:

[0064] Obtain information on the time interval allocation of the data transmission channel allowed to all terminals connected to the gateway node where the suspicious data transmission event occurs, and use this information as the time attribute information of the channel allocation; compare the time distribution characteristic information corresponding to the gateway node with the channel allocation time attribute information to obtain the time proportion of the time zone in which the suspicious data transmission event occurs in which each terminal connected is allowed to use the data transmission channel; if the time proportion corresponding to more than a preset number of terminals exceeds a preset time proportion threshold, then determine that the gateway node is an abnormal gateway node; otherwise, determine that the gateway node is not an abnormal gateway node;

[0065] Based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a fault data transmission path distribution map corresponding to the communication network is generated; wherein, the fault data transmission path distribution map includes the communication link distribution information corresponding to all the fault data transmission paths within the communication network.

[0066] The beneficial effect of the above technical solution is that the gateway node of the communication network may be connected to multiple terminals at the same time or need to transmit data streams sent by multiple terminals. In order to ensure that all terminals and the data streams they send can equally obtain the right to use the corresponding gateway node, the communication server of the communication network will allocate the use time intervals for all terminals connected to the gateway node, that is, determine the time intervals in which all the corresponding connected terminals are allowed to use the gateway node for data stream transmission, thereby obtaining the corresponding channel allocation time attribute information, and realizing the time division multiplexing attribute determination of all terminals for the gateway node. Then, the time distribution feature information corresponding to the gateway node is compared with the channel allocation time attribute information to obtain the time proportion of suspicious data transmission events occurring in the time zone where each connected terminal is allowed to use the data transmission channel. The time proportion refers to the duration of the suspicious data transmission event occurring within the duration period corresponding to the data transmission channel allowed to be used by each terminal. The larger the time proportion, the higher the probability of data transmission anomalies occurring during the data transmission process of the corresponding terminal through the gateway node. If the time proportions corresponding to the terminals exceeding the preset number of proportions all exceed the preset time proportion threshold, the gateway node is judged to be an abnormal gateway node, so that the abnormal gateway node can be accurately located. In addition, based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a distribution map of the faulty data transmission paths corresponding to the communication network is generated, thereby globally representing the distribution of all faulty data transmission paths within the communication network, and providing an accurate reference basis for the subsequent redetermination of the data transmission path to avoid all abnormal gateway nodes.

[0067] Preferably, in step S3, monitoring the target terminal connected to the communication network to obtain the actual data transmission path of the target terminal; comparing the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission safety state includes:

[0068] Based on the identity information of the target terminal accessing the communication network, a targeted monitoring is performed on the target terminal to obtain a transmission destination of the data transmission by the target terminal, thereby determining the shortest data transmission path between the target terminal and the transmission destination, and using the shortest data transmission path as the actual data transmission path;

[0069] The actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined; if the gateway node overlap rate exceeds the preset overlap rate threshold, it is determined whether the communication link distance between the abnormal gateway nodes within the actual data transmission path exceeds the preset distance threshold; if so, it is determined that the target terminal is not currently in a data transmission safety state; if not, it is determined that the target terminal is currently in a data transmission safety state.

[0070] The beneficial effect of the above technical solution is that when a target terminal connected to the communication network initiates a data transmission task, it is necessary to predetermine the original actual data transmission path of the target terminal, thereby providing a path reference for subsequent judgment of whether the actual data transmission path is safe or not. To this end, based on the identity information of the target terminal connected to the communication network, the target terminal is monitored in a targeted manner to obtain the transmission destination of the target terminal for data transmission, and the shortest data transmission path between the target terminal and the transmission destination is determined. In this way, the actual data transmission path can be prioritized to achieve the optimal data transmission mode between the target terminal and the transmission destination. In addition, the actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined. The gateway node overlap rate refers to the repetition rate between the gateway nodes included in the actual data transmission path and the gateway nodes included in all faulty data transmission paths. The larger the gateway node overlap rate, the greater the probability that the actual data transmission path and the faulty data transmission path share the same gateway node, and the greater the probability that the actual data transmission path will experience data transmission anomalies. By comparing the threshold value of the gateway node overlap rate, it is accurately determined whether the target terminal is currently in a data transmission security state, thereby providing a benchmark for whether the data transmission path of the target terminal needs to be re-determined.

[0071] Preferably, in step S4, when the target terminal is not currently in a data transmission safety state, the data transmission path of the target terminal is re-determined based on the transmission endpoint of the actual data transmission path and all gateway nodes under all failed data transmission paths; and based on the re-determined data transmission path, a data stream transmission switching operation is performed on the target terminal, including:

[0072] When the target terminal is not currently in a data transmission safety state, determining the location information of all gateway nodes under all non-faulty data transmission paths within the communication network based on the location information of all gateway nodes under the faulty data transmission path within the communication network; and re-determining the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network;

[0073] Based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted to the target terminal is divided into several data packets, and all the data packets are grouped into a data packet queue before performing a data stream transmission switching operation.

[0074] The beneficial effect of the above technical solution is: when the target terminal is not currently in a data transmission safety state, it indicates that the target terminal cannot guarantee normal and timely transmission of data when using the actual data transmission path for data transmission. At this time, based on the location information of all gateway nodes under the faulty data transmission path within the communication network, the location information of all gateway nodes under all non-faulty data transmission paths within the communication network is determined, that is, all gateway nodes within the communication network except the gateway nodes under the faulty data transmission path are screened and located, and then based on the transmission end point of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network, the data transmission path of the target terminal is re-determined, wherein the re-determination of the data transmission path of the target terminal can be achieved based on the principle of the shortest data transmission path formed between the transmission end point and all gateway nodes under all non-faulty data transmission paths. It belongs to the conventional technical means in this field and will not be introduced in detail here. In addition, based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted by the target terminal is divided into several data packets, so that each data packet obtained by the division matches the available bandwidth of the gateway node, avoiding the problem of data transmission congestion in the process of transmitting data packets along the re-determined data transmission path, and then all data packets are grouped into data packet queues and data stream transmission switching operations are performed, thereby improving the data stream transmission quality of the communication network and avoiding problems such as data stream transmission delay and distortion.

[0075] See Figure 2, is a schematic diagram of a framework of a data stream secure switching transmission system for a communication network provided by an embodiment of the present invention. The data stream secure switching transmission system for a communication network includes:

[0076] The gateway node monitoring module is used to monitor all gateway nodes in the communication network and obtain the time domain attribute information of the data stream transmission of each gateway node;

[0077] A data transmission time feature determination module is used to determine time distribution feature information of a suspicious data transmission event occurring at the gateway node based on the data stream transmission time domain attribute information;

[0078] An abnormal gateway node identification module is used to determine whether the gateway node is an abnormal gateway node based on the time distribution feature information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals;

[0079] A faulty data transmission path identification module is used to identify all faulty data transmission paths within the communication network based on the location distribution attribute information of all abnormal gateway nodes within the communication network;

[0080] A target terminal monitoring module is used to monitor the target terminal connected to the communication network and obtain the actual data transmission path of the target terminal;

[0081] A data transmission security status judgment module is used to compare the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission security state;

[0082] A data transmission path redetermining module is used to, when the target terminal is not currently in a data transmission safety state, redetermine the data transmission path of the target terminal based on the transmission end point of the actual data transmission path and all gateway nodes under all failed data transmission paths;

[0083] The data stream transmission switching module is used to perform a data stream transmission switching operation on the target terminal based on the re-determined data transmission path.

[0084] The beneficial effects of the above technical solution are as follows: the data stream security switching transmission system of the communication network monitors the data stream transmission time domain attribute information of each gateway node within the communication network, thereby determining the time distribution characteristic information of a suspicious data transmission event at each gateway node, and performing preliminary data transmission status screening on the gateway node; based on the time distribution characteristic information of the gateway node and the channel allocation time attribute information of all corresponding connected terminals, the abnormal gateway node is identified, thereby identifying the faulty data transmission path within the communication network, providing a reference basis for subsequent data stream switching transmission; the actual data transmission path of the target terminal connected to the communication network is monitored and compared with the faulty data transmission path to determine whether the target terminal is in a data transmission security state and determine the data stream switching transmission requirements of the target terminal; the data transmission path is re-determined based on the transmission end point of the actual data transmission path and all gateway nodes under all faulty data transmission paths, thereby performing data stream transmission switching operations on the target terminal, effectively avoiding the influence of abnormal gateway nodes, improving the data stream transmission quality of the communication network, and avoiding problems such as data stream transmission delay and distortion.

[0085] Preferably, the gateway node monitoring module is used to monitor all gateway nodes within the communication network to obtain the data stream transmission time domain attribute information of all gateway nodes, including:

[0086] Based on the network link distance between all gateway nodes in the communication network and the communication server, all gateway nodes are divided into several gateway node areas. Each gateway node area is independently monitored to obtain the data flow transmission change information of all gateway nodes under each gateway node area. This data flow transmission change information is analyzed to obtain the change rate of the data flow transmission fluctuation amplitude of the gateway node over time, which is used as the time domain attribute information of the data transmission;

[0087] The data transmission time feature determination module is used to determine the time distribution feature information of the suspicious data transmission event at the gateway node based on the data stream transmission time domain attribute information, including:

[0088] Based on the rate of change of the data traffic transmission fluctuation amplitude over time, determine the maximum continuous time during which the data traffic transmission fluctuation amplitude change rate of the gateway node exceeds the preset change rate; if the maximum continuous time is greater than the preset time threshold, determine that a suspicious data transmission event has occurred at the gateway node; otherwise, determine that no suspicious data transmission event has occurred at the gateway node; and use the distribution information of all durations during which the data traffic transmission fluctuation amplitude change rate of the gateway node where the suspicious data transmission event occurs exceeds the preset change rate as the time distribution characteristic information of the occurrence of the suspicious data transmission event.

[0089] The beneficial effects of the above technical solution are as follows: the communication network contains a large number of gateway nodes, each of which works independently as a data transmission intermediary. Terminals such as smartphones or portable computers access the corresponding gateway nodes to use the communication network for data flow transmission and interaction. The communication network is also equipped with a communication server, which is used to control and manage all gateway nodes under the communication network. The communication network contains a large number of gateway nodes. If all gateway nodes are monitored separately, it will consume a large amount of monitoring computing resources and the real-time monitoring cannot be guaranteed. To this end, based on the network link distance between all gateway nodes in the communication network and the communication server, all gateway nodes are divided into several gateway node areas, so that the network link distance between each gateway node area and the communication server is within a corresponding distance interval. Then, each gateway node area is monitored independently to obtain the data flow transmission change information of all gateway nodes under each gateway node area. In this way, it is possible to achieve fast real-time monitoring of all gateway nodes without having to monitor all gateway nodes separately, and accurately determine the changes in the data flow transmission volume of each gateway node. The data traffic transmission change information is then analyzed to obtain the rate of change of the data traffic transmission fluctuation amplitude of the gateway node over time, that is, the rate of change of the data traffic transmission fluctuation of the gateway node, thereby quantitatively characterizing the degree of fluctuation of the data traffic passing through the gateway node during data transmission. Furthermore, based on the rate of change of the data traffic transmission fluctuation amplitude over time, the maximum continuous time during which the data traffic transmission fluctuation amplitude change rate of the gateway node exceeds a preset change rate is determined. If the maximum continuous time is greater than a preset time threshold, it is determined that a suspicious data transmission event has occurred at the gateway node. This allows screening of gateway nodes whose data traffic fluctuates significantly for a long period of time during data transmission, thereby accurately locating and identifying gateway nodes that are affected by traffic attacks and affect normal data transmission. The distribution information of all durations during which the data traffic transmission fluctuation amplitude change rate of the gateway node experiencing the suspicious data transmission event exceeds the preset change rate is used as the time distribution characteristic information of the suspicious data transmission event. This allows accurate and comprehensive characterization of the time distribution pattern of the suspicious data transmission event occurring at the gateway node.

[0090] Preferably, the abnormal gateway node identification module is used to determine whether the gateway node is an abnormal gateway node based on the time distribution feature information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals, including:

[0091] Obtain information on the time interval allocation of the data transmission channel allowed to all terminals connected to the gateway node where the suspicious data transmission event occurs, and use this information as the time attribute information of the channel allocation; compare the time distribution characteristic information corresponding to the gateway node with the channel allocation time attribute information to obtain the time proportion of the time zone in which the suspicious data transmission event occurs in which each terminal connected is allowed to use the data transmission channel; if the time proportion corresponding to more than a preset number of terminals exceeds a preset time proportion threshold, then determine that the gateway node is an abnormal gateway node; otherwise, determine that the gateway node is not an abnormal gateway node;

[0092] The faulty data transmission path identification module is used to identify all faulty data transmission paths within the communication network based on the location distribution attribute information of all abnormal gateway nodes within the communication network, including:

[0093] Based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a fault data transmission path distribution map corresponding to the communication network is generated; wherein, the fault data transmission path distribution map includes the communication link distribution information corresponding to all the fault data transmission paths within the communication network.

[0094] The beneficial effect of the above technical solution is that the gateway node of the communication network may be connected to multiple terminals at the same time or need to transmit data streams sent by multiple terminals. In order to ensure that all terminals and the data streams they send can equally obtain the right to use the corresponding gateway node, the communication server of the communication network will allocate the use time intervals for all terminals connected to the gateway node, that is, determine the time intervals in which all the corresponding connected terminals are allowed to use the gateway node for data stream transmission, thereby obtaining the corresponding channel allocation time attribute information, and realizing the time division multiplexing attribute determination of all terminals for the gateway node. Then, the time distribution feature information corresponding to the gateway node is compared with the channel allocation time attribute information to obtain the time proportion of suspicious data transmission events occurring in the time zone where each connected terminal is allowed to use the data transmission channel. The time proportion refers to the duration of the suspicious data transmission event occurring within the duration period corresponding to the data transmission channel allowed to be used by each terminal. The larger the time proportion, the higher the probability of data transmission anomalies occurring during the data transmission process of the corresponding terminal through the gateway node. If the time proportions corresponding to the terminals exceeding the preset number of proportions all exceed the preset time proportion threshold, the gateway node is judged to be an abnormal gateway node, so that the abnormal gateway node can be accurately located. In addition, based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a distribution map of the faulty data transmission paths corresponding to the communication network is generated, thereby globally representing the distribution of all faulty data transmission paths within the communication network, and providing an accurate reference basis for the subsequent redetermination of the data transmission path to avoid all abnormal gateway nodes.

[0095] Preferably, the target terminal monitoring module is used to monitor the target terminal accessing the communication network to obtain the actual data transmission path of the target terminal, including:

[0096] Based on the identity information of the target terminal accessing the communication network, a targeted monitoring is performed on the target terminal to obtain a transmission destination of the data transmission by the target terminal, thereby determining the shortest data transmission path between the target terminal and the transmission destination, and using the shortest data transmission path as the actual data transmission path;

[0097] The data transmission security status judgment module is used to compare the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission security state, including:

[0098] The actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined; if the gateway node overlap rate exceeds the preset overlap rate threshold, it is determined whether the communication link distance between the abnormal gateway nodes within the actual data transmission path exceeds the preset distance threshold; if so, it is determined that the target terminal is not currently in a data transmission safety state; if not, it is determined that the target terminal is currently in a data transmission safety state.

[0099] The beneficial effect of the above technical solution is that when a target terminal connected to the communication network initiates a data transmission task, it is necessary to predetermine the original actual data transmission path of the target terminal, thereby providing a path reference for subsequent judgment of whether the actual data transmission path is safe or not. To this end, based on the identity information of the target terminal connected to the communication network, the target terminal is monitored in a targeted manner to obtain the transmission destination of the target terminal for data transmission, and the shortest data transmission path between the target terminal and the transmission destination is determined. In this way, the actual data transmission path can be prioritized to achieve the optimal data transmission mode between the target terminal and the transmission destination. In addition, the actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined. The gateway node overlap rate refers to the repetition rate between the gateway nodes included in the actual data transmission path and the gateway nodes included in all faulty data transmission paths. The larger the gateway node overlap rate, the greater the probability that the actual data transmission path and the faulty data transmission path share the same gateway node, and the greater the probability that the actual data transmission path will experience data transmission anomalies. By comparing the threshold value of the gateway node overlap rate, it is accurately determined whether the target terminal is currently in a data transmission security state, thereby providing a benchmark for whether the data transmission path of the target terminal needs to be re-determined.

[0100] Preferably, the data transmission path redetermining module is configured to, when the target terminal is not currently in a data transmission safety state, redetermine the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and all gateway nodes under all failed data transmission paths, including:

[0101] When the target terminal is not currently in a data transmission safety state, determining the location information of all gateway nodes under all non-faulty data transmission paths within the communication network based on the location information of all gateway nodes under the faulty data transmission path within the communication network; and re-determining the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network;

[0102] The data stream transmission switching module is configured to perform a data stream transmission switching operation on the target terminal based on the re-determined data transmission path, including:

[0103] Based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted to the target terminal is divided into several data packets, and all the data packets are grouped into a data packet queue before performing a data stream transmission switching operation.

[0104] The beneficial effect of the above technical solution is: when the target terminal is not currently in a data transmission safety state, it indicates that the target terminal cannot guarantee normal and timely transmission of data when using the actual data transmission path for data transmission. At this time, based on the location information of all gateway nodes under the faulty data transmission path within the communication network, the location information of all gateway nodes under all non-faulty data transmission paths within the communication network is determined, that is, all gateway nodes within the communication network except the gateway nodes under the faulty data transmission path are screened and located, and then based on the transmission end point of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network, the data transmission path of the target terminal is re-determined, wherein the re-determination of the data transmission path of the target terminal can be achieved based on the principle of the shortest data transmission path formed between the transmission end point and all gateway nodes under all non-faulty data transmission paths. It belongs to the conventional technical means in this field and will not be introduced in detail here. In addition, based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted by the target terminal is divided into several data packets, so that each data packet obtained by the division matches the available bandwidth of the gateway node, avoiding the problem of data transmission congestion in the process of transmitting data packets along the re-determined data transmission path, and then all data packets are grouped into data packet queues and data stream transmission switching operations are performed, thereby improving the data stream transmission quality of the communication network and avoiding problems such as data stream transmission delay and distortion.

[0105] From the contents of the above embodiments, it can be seen that the data stream security switching transmission method and system of the communication network monitors the data stream transmission time domain attribute information of each gateway node within the communication network, thereby determining the time distribution characteristic information of each gateway node when a suspicious data transmission event occurs, and performing preliminary data transmission status screening on the gateway node; based on the time distribution characteristic information of the gateway node and the channel allocation time attribute information of all corresponding connected terminals, the abnormal gateway node is identified, thereby identifying the faulty data transmission path within the communication network, providing a reference basis for subsequent data stream switching transmission; the actual data transmission path of the target terminal connected to the communication network is monitored and compared with the faulty data transmission path to determine whether the target terminal is in a data transmission security state and determine the data stream switching transmission requirements of the target terminal; the data transmission path is also re-determined based on the transmission end point of the actual data transmission path and all gateway nodes under all faulty data transmission paths, thereby performing data stream transmission switching operations on the target terminal, effectively avoiding the influence of abnormal gateway nodes, improving the data stream transmission quality of the communication network, and avoiding problems such as data stream transmission delay and distortion.

[0106] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A method for securely switching and transmitting data streams in a communication network, characterized in that: It includes the following steps: Step S1: monitor all gateway nodes within the communication network to obtain data flow transmission time domain attribute information of each gateway node; based on the data flow transmission time domain attribute information, determine the time distribution characteristic information of the suspicious data transmission event occurring at the gateway node; Step S2, judging whether the gateway node is an abnormal gateway node based on the time distribution characteristic information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals; Identifying all faulty data transmission paths within the communication network based on location distribution attribute information of all abnormal gateway nodes within the communication network; Step S3, monitoring the target terminal connected to the communication network to obtain the actual data transmission path of the target terminal; Comparing the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission safety state; Step S4: when the target terminal is not currently in a data transmission safety state, re-determine the data transmission path of the target terminal based on the transmission end point of the actual data transmission path and all gateway nodes under all failed data transmission paths; and performing a data stream transmission switching operation on the target terminal based on the re-determined data transmission path; Wherein, the step S1 specifically includes: Based on the network link distance between all gateway nodes within the communication network and the communication server, all gateway nodes are divided into several gateway node areas, and each gateway node area is independently monitored to obtain data flow transmission change information of all gateway nodes under each gateway node area; the data flow transmission change information is analyzed to obtain the change rate of the data flow transmission fluctuation amplitude of the gateway node over time, which is used as the data transmission time domain attribute information; Based on the rate of change of the data traffic transmission fluctuation amplitude over time, determining the maximum continuous time during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node exceeds a preset rate of change; if the maximum continuous time is greater than a preset time threshold, determining that a suspicious data transmission event has occurred at the gateway node; otherwise, determining that no suspicious data transmission event has occurred at the gateway node; and using the distribution information of all durations during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node where the suspicious data transmission event occurred exceeds the preset rate of change as the time distribution characteristic information of the occurrence of the suspicious data transmission event; The step S2 specifically includes: Obtain the time interval allocation information of the gateway node where the suspicious data transmission event occurs and allow all terminals connected to it to use the data transmission channel, and use this as the channel allocation time attribute information; compare the time distribution feature information corresponding to the gateway node with the channel allocation time attribute information to obtain the time proportion of the time zone in which the suspicious data transmission event occurs for each connected terminal that is allowed to use the data transmission channel; if the time proportion corresponding to terminals exceeding a preset number of proportions exceeds a preset time proportion threshold, then determine that the gateway node is an abnormal gateway node; otherwise, determine that the gateway node is not an abnormal gateway node.

2. The method for securely switching and transmitting data streams in a communication network according to claim 1, wherein: The step S2 further includes: Based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a fault data transmission path distribution map corresponding to the communication network is generated; wherein, the fault data transmission path distribution map includes the communication link distribution information corresponding to each of the fault data transmission paths within the communication network.

3. The method for securely switching and transmitting data streams in a communication network according to claim 1, wherein: In step S3, monitoring the target terminal connected to the communication network is performed to obtain the actual data transmission path of the target terminal; Comparing the actual data transmission path with all faulty data transmission paths to determine whether the target terminal is currently in a data transmission safety state includes: Based on the identity information of the target terminal accessing the communication network, performing targeted monitoring on the target terminal to obtain a transmission destination of data transmission by the target terminal, thereby determining the shortest data transmission path between the target terminal and the transmission destination, and using the shortest data transmission path as the actual data transmission path; The actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined; if the gateway node overlap rate exceeds a preset overlap rate threshold, it is determined whether the communication link distance between the abnormal gateway nodes within the actual data transmission path exceeds a preset distance threshold; if so, it is determined that the target terminal is not currently in a data transmission safety state; if not, it is determined that the target terminal is currently in a data transmission safety state.

4. The method for securely switching and transmitting data streams in a communication network according to claim 1, wherein: In step S4, when the target terminal is not currently in a data transmission safety state, the data transmission path of the target terminal is re-determined based on the transmission endpoint of the actual data transmission path and all gateway nodes under all faulty data transmission paths; and performing a data stream transmission switching operation on the target terminal based on the re-determined data transmission path, including: When the target terminal is not currently in a data transmission safety state, determining the location information of all gateway nodes under all non-faulty data transmission paths within the communication network based on the location information of all gateway nodes under the faulty data transmission path within the communication network; and re-determining the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network; Based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted by the target terminal is divided into a plurality of data packets, and all the data packets are grouped into a data packet queue before performing a data stream transmission switching operation.

5. A data stream secure switching transmission system for a communication network, characterized in that: include: The gateway node monitoring module is used to monitor all gateway nodes in the communication network and obtain the time domain attribute information of the data stream transmission of each gateway node; a data transmission time characteristic determination module, configured to determine time distribution characteristic information of a suspicious data transmission event occurring at the gateway node based on the data stream transmission time domain attribute information; an abnormal gateway node identification module, configured to determine whether the gateway node is an abnormal gateway node based on the time distribution characteristic information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals; A faulty data transmission path identification module, configured to identify all faulty data transmission paths within the communication network based on location distribution attribute information of all abnormal gateway nodes within the communication network; A target terminal monitoring module is used to monitor the target terminal connected to the communication network and obtain the actual data transmission path of the target terminal; a data transmission security state judgment module, configured to compare the actual data transmission path with all faulty data transmission paths to judge whether the target terminal is currently in a data transmission security state; a data transmission path redetermining module, configured to, when the target terminal is not currently in a data transmission safety state, redetermine the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and all gateway nodes under all failed data transmission paths; a data stream transmission switching module, configured to perform a data stream transmission switching operation on the target terminal based on the re-determined data transmission path; The gateway node monitoring module is used to monitor all gateway nodes within the communication network to obtain the data flow transmission time domain attribute information of all gateway nodes, including: Based on the network link distance between all gateway nodes within the communication network and the communication server, all gateway nodes are divided into several gateway node areas, and each gateway node area is independently monitored to obtain data flow transmission change information of all gateway nodes under each gateway node area; the data flow transmission change information is analyzed to obtain the change rate of the data flow transmission fluctuation amplitude of the gateway node over time, which is used as the data transmission time domain attribute information; The data transmission time feature determination module is configured to determine time distribution feature information of a suspicious data transmission event occurring at the gateway node based on the data stream transmission time domain attribute information, including: Based on the rate of change of the data traffic transmission fluctuation amplitude over time, determining the maximum continuous time during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node exceeds a preset rate of change; if the maximum continuous time is greater than a preset time threshold, determining that a suspicious data transmission event has occurred at the gateway node; otherwise, determining that no suspicious data transmission event has occurred at the gateway node; and using the distribution information of all durations during which the rate of change of the data traffic transmission fluctuation amplitude of the gateway node where the suspicious data transmission event occurred exceeds the preset rate of change as the time distribution characteristic information of the occurrence of the suspicious data transmission event; The abnormal gateway node identification module is used to determine whether the gateway node is an abnormal gateway node based on the time distribution feature information corresponding to the gateway node and the channel allocation time attribute information of all corresponding connected terminals, including: Obtain the time interval allocation information of the gateway node where the suspicious data transmission event occurs and allow all terminals connected to it to use the data transmission channel, and use this as the channel allocation time attribute information; compare the time distribution feature information corresponding to the gateway node with the channel allocation time attribute information to obtain the time proportion of the time zone in which the suspicious data transmission event occurs for each connected terminal that is allowed to use the data transmission channel; if the time proportion corresponding to terminals exceeding a preset number of proportions exceeds a preset time proportion threshold, then determine that the gateway node is an abnormal gateway node; otherwise, determine that the gateway node is not an abnormal gateway node.

6. The data stream secure switching transmission system for a communication network according to claim 5, wherein: The faulty data transmission path identification module is used to identify all faulty data transmission paths within the communication network based on the location distribution attribute information of all abnormal gateway nodes within the communication network, including: Based on the network location distribution information of all abnormal gateway nodes within the communication network and the connection permission information between each abnormal gateway node and other gateway nodes, a fault data transmission path distribution map corresponding to the communication network is generated; wherein, the fault data transmission path distribution map includes the communication link distribution information corresponding to each of the fault data transmission paths within the communication network.

7. The data stream secure switching transmission system for a communication network according to claim 5, wherein: The target terminal monitoring module is configured to monitor a target terminal connected to the communication network to obtain an actual data transmission path of the target terminal, including: Based on the identity information of the target terminal accessing the communication network, performing targeted monitoring on the target terminal to obtain a transmission destination of data transmission by the target terminal, thereby determining the shortest data transmission path between the target terminal and the transmission destination, and using the shortest data transmission path as the actual data transmission path; The data transmission security status judgment module is configured to compare the actual data transmission path with all faulty data transmission paths to judge whether the target terminal is currently in a data transmission security state, including: The actual data transmission path is compared with all faulty data transmission paths, and the gateway node overlap rate between the actual data transmission path and all faulty data transmission paths is determined; if the gateway node overlap rate exceeds a preset overlap rate threshold, it is determined whether the communication link distance between the abnormal gateway nodes within the actual data transmission path exceeds a preset distance threshold; if so, it is determined that the target terminal is not currently in a data transmission safety state; if not, it is determined that the target terminal is currently in a data transmission safety state.

8. The data stream secure switching transmission system for a communication network according to claim 5, wherein: The data transmission path redetermining module is configured to, when the target terminal is not currently in a data transmission safety state, redetermine the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and all gateway nodes under all faulty data transmission paths, including: When the target terminal is not currently in a data transmission safety state, determining the location information of all gateway nodes under all non-faulty data transmission paths within the communication network based on the location information of all gateway nodes under the faulty data transmission path within the communication network; and re-determining the data transmission path of the target terminal based on the transmission endpoint of the actual data transmission path and the location information of all gateway nodes under all non-faulty data transmission paths within the communication network; The data stream transmission switching module is configured to perform a data stream transmission switching operation on the target terminal based on the re-determined data transmission path, including: Based on the available bandwidth information of all gateway nodes under the re-determined data transmission path, the data to be transmitted by the target terminal is divided into a plurality of data packets, and all the data packets are grouped into a data packet queue before performing a data stream transmission switching operation.

Citation Information

Patent Citations

  • Network load balancing method and device based on link and equipment states

    CN116232977A

  • Real-time attack tracing method and system based on machine learning

    CN118158002A