Terminal communication security management and control method and system in multi-network scenarios
By monitoring the running properties of terminal applications to generate message clusters and identifying the link characteristics of available networks, the problem of terminal communication interruption in multi-network scenarios is solved, and the security and reliability of the terminal's external communications are improved.
Patent Information
- Application Number
- CN202411442895.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-16
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2044-10-16
AI Technical Summary
In the existing technology, terminals cannot effectively utilize the data transmission advantages of different networks in multi-network scenarios, resulting in increased message sending time, communication interruption, and failure to meet the needs of efficient and accurate task processing.
Monitor the running attribute information of all applications under the terminal, generate external communication message clusters, and distribute them to the corresponding communication channels, identify the link gateway feature information of the available network, determine the message transmission security attributes, and automatically select the matching network connection status to ensure that each communication channel obtains equal network connection rights.
It improves the security and reliability of external communications of terminals in multi-network scenarios, ensures that each message cluster receives optimal transmission processing, and fully utilizes the data transmission advantages of different networks.
Smart Images

Figure CN119421185B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to a method and system for terminal communication security management and control in multi-network scenarios. Background Art
[0002] In order to avoid data transmission crosstalk, existing terminals such as smart phones are only allowed to connect to a single network at the same time, so that all messages of the terminal can only be sent and transmitted through a single link in a single network during operation. When there are a large number of applications inside the terminal that need to exchange messages with the outside world, all messages can only be arranged according to the corresponding rules to generate a corresponding message queue, and then all messages in the message queue are sent and transmitted one by one in sequence. This will increase the time consumption of message sending. Once the network link currently connected to the terminal fails, the message transmission of the message queue will be interrupted, which will not only increase the time cost of the terminal's message communication, but also delay the task processing progress of the application program inside the terminal, and cannot meet the terminal's needs for efficient and accurate task processing. At present, it is necessary to convert the stable and efficient transmission of messages for the terminal in multi-network scenarios to ensure that the terminal can fully utilize the data transmission advantages of different networks and maximize the security and reliability of the terminal's external communications. Summary of the Invention
[0003] In response to the defects of the existing technology, the present invention provides a terminal communication security management and control method and system in a multi-network scenario, which monitors the operating attribute information of all applications under the terminal to determine the external communication process of each application, and generates a number of corresponding external communication messages, and performs timely and targeted processing on the external communication needs of different applications; divides all external communication messages into a number of message clusters and assigns them to corresponding communication channels, realizes differentiated transmission of different message clusters, and ensures that each message cluster can obtain optimal transmission processing; searches and identifies all available networks that the terminal can connect to, traces and identifies each available network, obtains the link gateway feature information of each available network, thereby determining the message transmission security attribute information of each available network, and accurately determines the operational security of the available network in different message transmission scenarios, thereby selecting a matching network for the communication channel that currently needs to connect to the network, and automatically changes the network connection status of the communication channel that currently needs to connect to the network, ensuring that each communication channel can obtain equal network connection rights, making full use of the data transmission advantages of different networks, and improving the external communication security and reliability of the terminal.
[0004] The present invention provides a terminal communication security management and control method in a multi-network scenario, comprising the following steps:
[0005] Step S1: monitor all applications under the terminal to obtain the running attribute information of each application; based on the running attribute information, determine the external communication process of each application, and generate a number of external communication messages corresponding to each application;
[0006] Step 2: Based on the message attribute information of all external communication messages, all external communication messages are divided into a number of message clusters; based on the working status of all communication channels under the terminal, all message clusters are respectively assigned to corresponding communication channels;
[0007] Step S3: Perform a multi-network signal search on the environment where the terminal is located to identify all available networks to which the terminal can connect; retroactively identify all available networks to obtain link gateway feature information of each available network; and determine message transmission security attribute information of the available networks based on the link gateway feature information.
[0008] Step S4: Identify the message receiving status of all communication channels and determine the network connection order of all communication channels; select a matching network for the communication channel that currently needs to connect to the external network based on the message transmission security attribute information; and automatically change the network connection status of the communication channel that currently needs to connect to the external network based on the message sending attribute information of the communication channel that currently needs to connect to the external network.
[0009] In one embodiment disclosed in the present application, in step S1, all applications under the terminal are monitored to obtain the operation attribute information of each of the applications; based on the operation attribute information, the external communication processes of each of the applications are determined, thereby generating a number of external communication messages corresponding to each of the applications, including:
[0010] Based on the program running log of the terminal, all applications in the foreground startup state are determined; based on the port addresses of all applications in the foreground startup state, all applications are monitored to obtain task processing process attribute information of each application; wherein the task processing process attribute information includes attribute information of all processes that the application needs to execute during the task processing process;
[0011] Based on the task processing process attribute information, an execution data packet and an execution time of the external communication process of the application are determined; based on the execution data packet and the execution time, a plurality of external communication messages corresponding to the application are generated.
[0012] In one embodiment disclosed in the present application, in step S2, all external communication messages are divided into a plurality of message clusters based on message attribute information of all external communication messages; and all message clusters are assigned to corresponding communication channels based on the working status of all communication channels under the terminal, including:
[0013] Identify the target terminals of all external communication messages to obtain identity attribute information of the target terminals of all external communication messages; and group all external communication messages to be sent to the same target terminal into the same message cluster based on the identity attribute information;
[0014] The working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel; the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are allocated to corresponding communication channels.
[0015] In one embodiment disclosed in the present application, in step S3, a multi-network signal search is performed on the environment where the terminal is located to identify all available networks to which the terminal can connect; all available networks are retroactively identified to obtain link gateway feature information of each available network; and based on the link gateway feature information, message transmission security attribute information of the available network is determined, including:
[0016] Performing a multi-network signal search in the environment where the terminal is located to obtain signal strength change information of all network signals in the environment within a preset time interval; determining the signal stability of each of all networks in the environment based on the signal strength change information; and identifying all available networks to which the terminal can connect based on the signal stability;
[0017] Perform link gateway tracing and identification on each available network to obtain the location information of all gateways included in all links under each available network; based on the location information of all gateways, retrieve and analyze the historical message transmission records of all gateways to obtain the message transmission packet loss attribute information of all gateways during the historical message transmission process; then, based on the message transmission packet loss attribute information, determine the message transmission integrity of each available network, and use this as the message transmission security attribute information; wherein, the message transmission integrity includes the message transmission integrity corresponding to the message transmission to each target terminal through the available network.
[0018] In one embodiment disclosed in the present application, in step S4, message receiving status of all communication channels is identified to determine the network connection order of all communication channels; based on the message transmission security attribute information, a matching network is selected for the communication channel that currently needs to connect to the network; and based on the message sending attribute information of the communication channel that currently needs to connect to the network, the network connection status of the communication channel that currently needs to connect to the network is automatically changed, including:
[0019] Identify the message data receiving status of each communication channel and predict the time when the message data volume allocated to each communication channel reaches the upper limit of its own allowed receiving data volume; determine the network connection order of all communication channels based on the order of the corresponding occurrence times from earliest to latest;
[0020] Based on the message transmission security attribute information contained in the available network, the message transmission completeness corresponding to the message transmission to each target terminal and the target terminal to which the communication channel that currently needs to connect to the external network needs to transmit the message, a matching network is selected for the communication channel that currently needs to connect to the external network; and based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed.
[0021] The present invention also provides a terminal communication security management and control system in a multi-network scenario, including:
[0022] The terminal monitoring module is used to monitor all applications under the terminal and obtain the running attribute information of all applications;
[0023] An external communication message generation module, configured to determine the external communication processes of all the applications based on the operation attribute information, and thereby generate a plurality of external communication messages corresponding to all the applications;
[0024] A message cluster division module is used to divide all external communication messages into several message clusters based on the message attribute information of all external communication messages;
[0025] A message cluster allocation module is used to allocate all message clusters to corresponding communication channels based on the working status of all communication channels under the terminal;
[0026] An available network identification module, configured to search for multiple network signals in the environment where the terminal is located and identify all available networks to which the terminal can connect;
[0027] A message transmission security attribute determination module is used to retroactively identify all available networks and obtain link gateway characteristic information of each available network; based on the link gateway characteristic information, determine the message transmission security attribute information of the available network;
[0028] A network connection sequence determination module is used to identify the message receiving status of all communication channels and determine the network connection sequence of all communication channels;
[0029] The network connection execution and change module is used to select a matching network for the communication channel that currently needs to connect to the external network based on the message transmission security attribute information; and automatically change the network connection status of the communication channel that currently needs to connect to the external network based on the message sending attribute information of the communication channel that currently needs to connect to the external network.
[0030] In one embodiment disclosed in the present application, the terminal monitoring module is used to monitor all applications under the terminal and obtain the running attribute information of each application, including:
[0031] Based on the program running log of the terminal, all applications in the foreground startup state are determined; based on the port addresses of all applications in the foreground startup state, all applications are monitored to obtain task processing process attribute information of each application; wherein the task processing process attribute information includes attribute information of all processes that the application needs to execute during the task processing process;
[0032] The external communication message generation module is used to determine the external communication processes of all applications based on the operation attribute information, and thereby generate a number of external communication messages corresponding to all applications, including:
[0033] Based on the task processing process attribute information, an execution data packet and an execution time of the external communication process of the application are determined; based on the execution data packet and the execution time, a plurality of external communication messages corresponding to the application are generated.
[0034] In one embodiment disclosed in the present application, the message cluster division module is configured to divide all external communication messages into a number of message clusters based on message attribute information of all external communication messages, including:
[0035] Identify the target terminals of all external communication messages to obtain identity attribute information of the target terminals of all external communication messages; and group all external communication messages to be sent to the same target terminal into the same message cluster based on the identity attribute information;
[0036] The message cluster allocation module is configured to allocate all message clusters to corresponding communication channels based on the working status of all communication channels under the terminal, including:
[0037] The working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel; the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are allocated to corresponding communication channels.
[0038] In one embodiment disclosed in the present application, the available network identification module is configured to perform a multi-network signal search in the environment where the terminal is located and identify all available networks to which the terminal can connect, including:
[0039] Performing a multi-network signal search in the environment where the terminal is located to obtain signal strength change information of all network signals in the environment within a preset time interval; determining the signal stability of each of all networks in the environment based on the signal strength change information; and identifying all available networks to which the terminal can connect based on the signal stability;
[0040] The message transmission security attribute determination module is configured to retroactively identify all available networks and obtain link gateway characteristic information of each of the available networks; and determine the message transmission security attribute information of the available networks based on the link gateway characteristic information, including:
[0041] Perform link gateway tracing and identification on each available network to obtain the location information of all gateways included in all links under each available network; based on the location information of all gateways, retrieve and analyze the historical message transmission records of all gateways to obtain the message transmission packet loss attribute information of all gateways during the historical message transmission process; then, based on the message transmission packet loss attribute information, determine the message transmission integrity of each available network, and use this as the message transmission security attribute information; wherein, the message transmission integrity includes the message transmission integrity corresponding to the message transmission to each target terminal through the available network.
[0042] In one embodiment disclosed in the present application, the network connection sequence determination module is configured to identify the message receiving status of all communication channels and determine the network connection sequence of all communication channels, including:
[0043] Identify the message data receiving status of each communication channel and predict the time when the message data volume allocated to each communication channel reaches the upper limit of its own allowed receiving data volume; determine the network connection order of all communication channels based on the order of the corresponding occurrence times from earliest to latest;
[0044] The network connection execution and change module is configured to select a matching network for the communication channel currently requiring external connection based on the message transmission security attribute information; and automatically change the network connection status of the communication channel currently requiring external connection based on the message transmission attribute information of the communication channel currently requiring external connection, including:
[0045] Based on the message transmission security attribute information contained in the available network, the message transmission completeness corresponding to the message transmission to each target terminal and the target terminal to which the communication channel that currently needs to connect to the external network needs to transmit the message, a matching network is selected for the communication channel that currently needs to connect to the external network; and based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed.
[0046] Compared with the existing technology, the terminal communication security management method and system in the multi-network scenario monitors the operating attribute information of all applications under the terminal to determine the external communication process of each application, and generates a number of corresponding external communication messages, and timely and targetedly processes the external communication needs of different applications; divides all external communication messages into a number of message clusters and assigns them to corresponding communication channels to achieve differentiated transmission of different message clusters, ensuring that each message cluster can obtain the best transmission processing; searches and identifies all available networks that the terminal can connect to, traces and identifies each available network, and obtains the link gateway feature information of each available network to determine the message transmission security attribute information of each available network, and accurately determines the operational security of the available network in different message transmission scenarios, so as to select a matching network for the communication channel that currently needs to connect to the network, and automatically changes the network connection status of the communication channel that currently needs to connect to the network, ensuring that each communication channel can obtain equal network connection rights, making full use of the data transmission advantages of different networks, and improving the external communication security and reliability of the terminal.
[0047] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.
[0048] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0050] Figure 1 A schematic diagram of the process of the terminal communication security management and control method in a multi-network scenario provided by the present invention;
[0051] Figure 2 This is a schematic diagram of the framework of the terminal communication security management and control system in a multi-network scenario provided by the present invention. DETAILED DESCRIPTION
[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0053] See Figure 1 , which is a flow chart of a terminal communication security management method in a multi-network scenario provided by an embodiment of the present invention. The terminal communication security management method in a multi-network scenario includes:
[0054] Step S1: monitor all applications under the terminal to obtain the running attribute information of each application; based on the running attribute information, determine the external communication process of each application, and generate a number of external communication messages corresponding to each application;
[0055] Step 2: Based on the message attribute information of all external communication messages, all external communication messages are divided into several message clusters; based on the working status of all communication channels under the terminal, all message clusters are respectively assigned to corresponding communication channels;
[0056] Step S3: Perform a multi-network signal search on the environment where the terminal is located to identify all available networks to which the terminal can connect; perform retroactive identification on all available networks to obtain link gateway characteristic information of each available network; and determine message transmission security attribute information of the available network based on the link gateway characteristic information.
[0057] Step S4, message receiving state identification is performed on all communication channels to determine the network connection sequence of all communication channels; based on the message transmission security attribute information, a matching network is selected for the communication channel currently requiring external network connection; and based on the message sending attribute information of the communication channel currently requiring external network connection, the network connection state of the communication channel currently requiring external network connection is automatically changed.
[0058] The terminal communication security management method in the multi-network scenario listens to the running attribute information of all application programs under the terminal, determines the external communication process of each application program, and generates a plurality of external communication messages corresponding thereto, so as to timely and directionally process the external communication demand of different application programs; all external communication messages are divided into a plurality of message clusters and distributed to corresponding communication channels, so as to realize differentiated transmission of different message clusters and ensure that each message cluster can obtain optimal transmission processing; all available networks that the terminal can connect are searched and identified, each available network is traced and identified to obtain the link gateway characteristic information of each available network, so as to determine the message transmission security attribute information of each available network, accurately determine the operation security of the available network in different message transmission scenarios, select a matching network for the communication channel currently requiring external network connection, and automatically change the network connection state of the communication channel currently requiring external network connection, so as to ensure that each communication channel can obtain equal network connection permission, fully utilize the data transmission advantages of different networks, and improve the external communication security and reliability of the terminal.
[0059] Preferably, in the step S1, all application programs under the terminal are listened to to obtain the running attribute information of all application programs; based on the running attribute information, the external communication process of each application program is determined to generate a plurality of external communication messages corresponding to each application program, including:
[0060] Based on the program running log of the terminal, all application programs in the foreground startup state are determined; based on the port address of all application programs in the foreground startup state, all application programs are listened to to obtain the task processing process attribute information of all application programs; wherein the task processing process attribute information includes all process attribute information required to be executed by the application program in the task processing process;
[0061] Based on the task processing process attribute information, the execution data packet and execution time of the external communication process of the application program are determined; based on the execution data packet and the execution time, a plurality of external communication messages corresponding to the application program are generated.
[0062] In the above technical solution, terminals such as smartphones or tablets are installed with applications of different types and functions. Each application may need to communicate and interact with other external terminals during operation. At this time, it is necessary to send and transmit external communication messages from the application. In order to ensure that all applications in the terminal can obtain timely external communication message transmission, it is necessary to identify the task processing process of each application during operation. Specifically, the terminal's program operation log is analyzed to obtain all applications in the foreground startup state, and the applications currently in the corresponding task processing state are calibrated and identified; then, based on the port address of the application in the foreground startup state, the application is monitored to obtain the application's task processing process attribute information, thereby characterizing all process state attributes that the application needs to execute during the task processing process, which facilitates accurate identification of external communication needs during the operation of all processes under the application. In addition, based on the attribute information of the task processing process, the execution data packet and execution time of the external communication process of the application are determined, so that the execution time interval of the external communication process of the application included in the task processing process and the data packet that needs to be processed are marked and identified; then, based on the execution data packet and execution time of the external communication process of the application, a number of external communication messages corresponding to the application during its operation are generated, so that the external communication messages required by the application can be generated in a timely and accurate manner, thereby improving the operating efficiency and reliability of the application.
[0063] Preferably, in step S2, all external communication messages are divided into a number of message clusters based on the message attribute information of all external communication messages; and all message clusters are assigned to corresponding communication channels based on the working status of all communication channels under the terminal, including:
[0064] Identify the target terminals of all external communication messages to obtain the identity attribute information of the target terminals of all external communication messages; based on the identity attribute information, group all external communication messages that need to be sent to the same target terminal into the same message cluster;
[0065] The working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel; the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are allocated to the corresponding communication channels.
[0066] In the above technical solution, different external communication messages generated by the application during the task processing process may need to be sent and transmitted to different external target terminals. In this way, the network links passed by different external communication messages during the sending and transmission process are not the same. In order to facilitate the centralized and unified sending and transmission of external communication messages that need to be sent and transmitted to the same target terminal, the sending target terminals of all external communication messages are identified, and the identity attribute information of the sending target terminals of all external communication messages is obtained, and all external communication messages that need to be sent to the same target terminal are divided into the same message cluster. In this way, all external communication messages under the same message cluster need to be sent and transmitted to the same target terminal in the outside world, and all external communication messages under the same message cluster can be sent and transmitted through the same network link. In addition, the working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel, that is, the communication bandwidth value allowed to be used by each communication channel is determined, and the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are respectively allocated to corresponding communication channels, so that message clusters with larger message data volume can be allocated to communication channels with larger communication bandwidth, ensuring that all message clusters can obtain communication channels that match their own data volume, improving the sending and transmission efficiency of message clusters, and avoiding the sending and transmission congestion of message clusters.
[0067] Preferably, in step S3, a multi-network signal search is performed on the environment where the terminal is located to identify all available networks to which the terminal can connect; all available networks are retroactively identified to obtain link gateway feature information of each available network; based on the link gateway feature information, message transmission security attribute information of the available network is determined, including:
[0068] Performing a multi-network signal search for the terminal's environment to obtain signal strength change information for all network signals in the environment within a preset time interval; determining the signal stability of each of the networks in the environment based on the signal strength change information; and identifying all available networks to which the terminal can connect based on the signal stability;
[0069] Perform link gateway tracing and identification on each available network to obtain the location information of all gateways included in all links under each available network; based on the location information of all gateways, retrieve and analyze the historical message transmission records of all gateways to obtain the message transmission packet loss attribute information of all gateways during the historical message transmission process; then, based on the message transmission packet loss attribute information, determine the message transmission integrity of each available network, and use this as the message transmission security attribute information; wherein, the message transmission integrity includes the message transmission integrity corresponding to the message transmission to each target terminal through the available network.
[0070] In the above technical solution, the terminal's environment may contain multiple different types of network signals, and different network signals correspond to different types of networks. In order for the terminal to obtain connection permissions to different networks, a multi-network signal search is performed on the terminal's environment to obtain signal strength change information for all network signals in the environment within a preset time interval. Based on this signal strength change information, the average signal strength and signal strength drift rate of each network in the environment are determined, thereby determining the signal stability of each network. Generally speaking, the greater the average signal strength and / or the smaller the signal strength drift rate, the higher the corresponding signal stability. The signal stability of all networks is then compared with a preset stability threshold. When the signal stability exceeds the preset stability threshold, the corresponding network is determined as an available network to which the terminal can connect. Link gateway tracing is also performed on each available network to obtain the location information of all gateways included in all links under each available network. Based on this, the historical message transmission records of all gateways are retrieved and analyzed to obtain the message transmission packet loss attribute information of each gateway during the historical message transmission process; wherein the message transmission packet loss attribute information may include, but is not limited to, the message transmission packet loss rate and / or the message transmission packet loss frequency of each gateway during the historical message transmission process. Based on the attribute information of message transmission packet loss, the message transmission integrity of each available network is determined. This is a conventional technical means in this field and will not be introduced in detail here. This can provide a reliable basis for the subsequent matching connection between communication channels and networks.
[0071] Preferably, in step S4, the message receiving status of all communication channels is identified to determine the network connection order of all communication channels; based on the message transmission security attribute information, a matching network is selected for the communication channel that currently needs to connect to the network; and based on the message sending attribute information of the communication channel that currently needs to connect to the network, the network connection status of the communication channel that currently needs to connect to the network is automatically changed, including:
[0072] Identify the message data receiving status of each communication channel and predict the time when the message data volume allocated to each communication channel reaches the upper limit of its own allowed receiving data volume; determine the network connection order of all communication channels based on the order of the corresponding occurrence times from earliest to latest;
[0073] Based on the message transmission security attribute information contained in the available network, the message transmission integrity corresponding to each target terminal and the target terminal to which the communication channel that currently needs to connect to the external network needs to transmit the message, a matching network is selected for the communication channel that currently needs to connect to the external network; and based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed.
[0074] In the above technical solution, the message data volume receiving state of each communication channel is identified, and the time when the message data volume allocated to each communication channel reaches the upper limit of the data volume allowed to be received is predicted. When the message data volume allocated to the communication channel reaches the upper limit of the data volume allowed to be received, it indicates that the communication channel has reached the message receiving saturation state, and at this time, the message received by the communication channel needs to be sent out for transmission. Then, based on the order of the occurrence time corresponding to all communication channels from early to late, the network connection order of all communication channels is determined to ensure that all communication channels can equally and promptly send out the messages they have received. In addition, based on the message transmission security attribute information contained in the available network, the message transmission integrity corresponding to each target terminal and the target terminal to which the communication channel currently needs to connect to the network needs to transmit the message, a matching network is selected for the communication channel currently needing to connect to the network, thereby ensuring that each communication channel can obtain equal network connection rights and fully utilize the data transmission advantages of different networks. In addition, based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed. That is to say, if the actual duration of the network connection of the communication channel that currently needs to connect to the external network exceeds its corresponding estimated time, the connection between the communication channel and the corresponding network is automatically disconnected, so that the corresponding network can be connected to other communication channels, thereby avoiding a communication channel occupying the same network for a long time, resulting in other communication channels being unable to obtain equal connection rights to the corresponding network.
[0075] See Figure 2 , is a schematic diagram of the framework of a terminal communication security management and control system in a multi-network scenario provided by an embodiment of the present invention. The terminal communication security management and control system in a multi-network scenario includes:
[0076] The terminal monitoring module is used to monitor all applications under the terminal and obtain the running attribute information of all applications;
[0077] An external communication message generation module is used to determine the external communication processes of all applications based on the running attribute information, and thereby generate a number of external communication messages corresponding to all applications;
[0078] A message cluster division module is used to divide all external communication messages into several message clusters based on the message attribute information of all external communication messages;
[0079] A message cluster allocation module is used to allocate all message clusters to corresponding communication channels based on the working status of all communication channels under the terminal;
[0080] An available network identification module is used to search for multiple network signals in the environment where the terminal is located and identify all available networks to which the terminal can connect;
[0081] A message transmission security attribute determination module is used to retroactively identify all available networks and obtain link gateway characteristic information of each available network; based on the link gateway characteristic information, determine the message transmission security attribute information of the available network;
[0082] A network connection sequence determination module is used to identify the message receiving status of all communication channels and determine the network connection sequence of all communication channels;
[0083] The network connection execution and change module is used to select a matching network for the communication channel that currently needs to connect to the external network based on the security attribute information transmitted by the message; and automatically change the network connection status of the communication channel that currently needs to connect to the external network based on the message sending attribute information of the communication channel that currently needs to connect to the external network.
[0084] The terminal communication security management and control system in this multi-network scenario monitors the operating attribute information of all applications under the terminal to determine the external communication process of each application, and generates a number of corresponding external communication messages to promptly and directionally process the external communication needs of different applications; divides all external communication messages into a number of message clusters and assigns them to corresponding communication channels to achieve differentiated transmission of different message clusters, ensuring that each message cluster can obtain the best transmission processing; searches and identifies all available networks that the terminal can connect to, traces and identifies each available network, and obtains the link gateway feature information of each available network to determine the message transmission security attribute information of each available network, accurately determines the operational security of the available network in different message transmission scenarios, selects a matching network for the communication channel that currently needs to connect to the network, and automatically changes the network connection status of the communication channel that currently needs to connect to the network, ensuring that each communication channel can obtain equal network connection rights, making full use of the data transmission advantages of different networks, and improving the external communication security and reliability of the terminal.
[0085] Preferably, the terminal monitoring module is used to monitor all applications under the terminal and obtain the running attribute information of all applications, including:
[0086] Based on the terminal's program running log, all applications in the foreground startup state are identified; based on the port addresses of all applications in the foreground startup state, all applications are monitored to obtain task processing process attribute information of each application; wherein the task processing process attribute information includes attribute information of all processes that the application needs to execute during the task processing process;
[0087] The external communication message generation module is used to determine the external communication processes of all applications based on the operation attribute information, and thereby generate a number of external communication messages corresponding to all applications, including:
[0088] Based on the attribute information of the task processing process, an execution data packet and an execution time of the external communication process of the application are determined; based on the execution data packet and the execution time, a plurality of external communication messages corresponding to the application are generated.
[0089] In the above technical solution, terminals such as smartphones or tablets are installed with applications of different types and functions. Each application may need to communicate and interact with other external terminals during operation. At this time, it is necessary to send and transmit external communication messages from the application. In order to ensure that all applications in the terminal can obtain timely external communication message transmission, it is necessary to identify the task processing process of each application during operation. Specifically, the terminal's program operation log is analyzed to obtain all applications in the foreground startup state, and the applications currently in the corresponding task processing state are calibrated and identified; then, based on the port address of the application in the foreground startup state, the application is monitored to obtain the application's task processing process attribute information, thereby characterizing all process state attributes that the application needs to execute during the task processing process, which facilitates accurate identification of external communication needs during the operation of all processes under the application. In addition, based on the attribute information of the task processing process, the execution data packet and execution time of the external communication process of the application are determined, so that the execution time interval of the external communication process of the application included in the task processing process and the data packet that needs to be processed are marked and identified; then, based on the execution data packet and execution time of the external communication process of the application, a number of external communication messages corresponding to the application during its operation are generated, so that the external communication messages required by the application can be generated in a timely and accurate manner, thereby improving the operating efficiency and reliability of the application.
[0090] Preferably, the message cluster division module is used to divide all external communication messages into several message clusters based on message attribute information of all external communication messages, including:
[0091] Identify the target terminals of all external communication messages to obtain the identity attribute information of the target terminals of all external communication messages; based on the identity attribute information, group all external communication messages that need to be sent to the same target terminal into the same message cluster;
[0092] The message cluster allocation module is used to allocate all message clusters to corresponding communication channels based on the working status of all communication channels under the terminal, including:
[0093] The working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel; the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are allocated to the corresponding communication channels.
[0094] In the above technical solution, different external communication messages generated by the application during the task processing process may need to be sent and transmitted to different external target terminals. In this way, the network links passed by different external communication messages during the sending and transmission process are not the same. In order to facilitate the centralized and unified sending and transmission of external communication messages that need to be sent and transmitted to the same target terminal, the sending target terminals of all external communication messages are identified, and the identity attribute information of the sending target terminals of all external communication messages is obtained, and all external communication messages that need to be sent to the same target terminal are divided into the same message cluster. In this way, all external communication messages under the same message cluster need to be sent and transmitted to the same target terminal in the outside world, and all external communication messages under the same message cluster can be sent and transmitted through the same network link. In addition, the working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel, that is, the communication bandwidth value allowed to be used by each communication channel is determined, and the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are respectively allocated to corresponding communication channels, so that message clusters with larger message data volume can be allocated to communication channels with larger communication bandwidth, ensuring that all message clusters can obtain communication channels that match their own data volume, improving the sending and transmission efficiency of message clusters, and avoiding the sending and transmission congestion of message clusters.
[0095] Preferably, the available network identification module is configured to perform a multi-network signal search in the environment where the terminal is located and identify all available networks to which the terminal can connect, including:
[0096] The terminal is in the environment carries out multi-network signal search, obtains all network signals existing in the environment in the preset time interval range signal strength change information;Based on the signal strength change information, determine the signal stability of all networks existing in the environment respectively;Based on the signal stability, identify all available networks that the terminal can connect;
[0097] The message transmission security attribute determination module is used for tracing and identifying all available networks respectively, obtaining the link gateway feature information of each available network;Based on the link gateway feature information, determine the message transmission security attribute information of the available network, including:
[0098] Each available network is respectively identified by link gateway tracing, obtaining the location information of all gateways contained by all links under each available network;Based on the location information of all gateways, call and analyze the historical message transmission record of each gateway, obtain the message transmission packet loss occurrence attribute information of each gateway in the historical message transmission process;Again based on the message transmission packet loss occurrence attribute information, determine the message transmission integrity of each available network, which is used as the message transmission security attribute information;Wherein, the message transmission integrity includes the message transmission integrity of each target terminal through the available network.
[0099] In the above technical solution, the terminal is in an environment space where multiple different types of network signals can exist, and different network signals correspond to connecting different types of networks. In order to enable the terminal to obtain the connection permission of different networks, the terminal performs a multi-network signal search on the environment to obtain signal strength change information of all network signals existing in the environment within a preset time interval range, and based on the signal strength change information, determines the signal average strength and signal strength drift rate of each network existing in the environment, thereby determining the signal stability of each network. Generally speaking, the greater the signal average strength and / or the smaller the signal strength drift rate, the higher the corresponding signal stability. Then, the signal stability of all networks is compared with a preset stability threshold. When the signal stability exceeds the preset stability threshold, the corresponding network is determined as an available network that the terminal can connect to. In addition, link gateway tracing identification is performed on each available network respectively to obtain the location information of all gateways contained in all links under each available network. The historical message transmission records of all gateways are retrieved and analyzed based on this to obtain the message transmission packet loss occurrence attribute information of each gateway in the historical message transmission process. The message transmission packet loss occurrence attribute information can include, but is not limited to, the message transmission packet loss rate and / or the message transmission packet loss occurrence frequency of each gateway in the historical message transmission process. Based on the message transmission packet loss occurrence attribute information, the message transmission integrity of each available network is determined, which is a conventional technical means in the art and will not be described in detail here. This can provide a reliable basis for subsequent matching connection of communication channels and networks.
[0100] Preferably, the network connection sequence determination module is configured to identify the message receiving state of all communication channels, and determine the network connection sequence of all communication channels, including:
[0101] The message data volume receiving state of each communication channel is identified, and the occurrence time when the message data volume allocated to each communication channel reaches the upper limit of the allowed receiving data volume of itself is predicted. Based on the sequence from early to late of the occurrence time corresponding to all communication channels, the network connection sequence of all communication channels is determined.
[0102] The network connection execution and change module is configured to select a matching network for the communication channel that currently needs to connect to an external network based on the message transmission security attribute information, and automatically change the network connection state of the communication channel that currently needs to connect to an external network based on the message sending attribute information of the communication channel that currently needs to connect to an external network, including:
[0103] Based on the message transmission security attribute information contained in the available network, the message transmission integrity corresponding to each target terminal and the target terminal to which the communication channel that currently needs to connect to the external network needs to transmit the message, a matching network is selected for the communication channel that currently needs to connect to the external network; and based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed.
[0104] In the above technical solution, the message data volume receiving state of each communication channel is identified, and the time when the message data volume allocated to each communication channel reaches the upper limit of the data volume allowed to be received is predicted. When the message data volume allocated to the communication channel reaches the upper limit of the data volume allowed to be received, it indicates that the communication channel has reached the message receiving saturation state, and at this time, the message received by the communication channel needs to be sent out for transmission. Then, based on the order of the occurrence time corresponding to all communication channels from early to late, the network connection order of all communication channels is determined to ensure that all communication channels can equally and promptly send out the messages they have received. In addition, based on the message transmission security attribute information contained in the available network, the message transmission integrity corresponding to each target terminal and the target terminal to which the communication channel currently needs to connect to the network needs to transmit the message, a matching network is selected for the communication channel currently needing to connect to the network, thereby ensuring that each communication channel can obtain equal network connection rights and fully utilize the data transmission advantages of different networks. In addition, based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed. That is to say, if the actual duration of the network connection of the communication channel that currently needs to connect to the external network exceeds its corresponding estimated time, the connection between the communication channel and the corresponding network is automatically disconnected, so that the corresponding network can be connected to other communication channels, thereby avoiding a communication channel occupying the same network for a long time, resulting in other communication channels being unable to obtain equal connection rights to the corresponding network.
[0105] From the contents of the above embodiments, it can be seen that the terminal communication security management method and system in the multi-network scenario monitors the operating attribute information of all applications under the terminal, thereby determining the external communication process of each application, and generating corresponding external communication messages, and timely and targeted processing of the external communication needs of different applications; all external communication messages are divided into several message clusters and assigned to corresponding communication channels to achieve differentiated transmission of different message clusters, ensuring that each message cluster can obtain optimal transmission processing; search and identify all available networks that the terminal can connect to, trace back and identify each available network, and obtain the link gateway feature information of each available network, thereby determining the message transmission security attribute information of each available network, and accurately determining the operational security of the available network in different message transmission scenarios, thereby selecting a matching network for the communication channel that currently needs to connect to the network, and automatically changing the network connection status of the communication channel that currently needs to connect to the network, ensuring that each communication channel can obtain equal network connection rights, making full use of the data transmission advantages of different networks, and improving the external communication security and reliability of the terminal.
[0106] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A terminal communication security management and control method in a multi-network scenario, characterized in that: It includes the following steps: Step S1: monitor all applications under the terminal to obtain the running attribute information of each application; based on the running attribute information, determine the external communication process of each application, and generate a number of external communication messages corresponding to each application; Step S2: dividing all external communication messages into a number of message clusters based on message attribute information of all external communication messages; and assigning all message clusters to corresponding communication channels based on the working status of all communication channels under the terminal; Step S3, performing a multi-network signal search on the environment where the terminal is located to identify all available networks to which the terminal can connect; All available networks are retroactively identified to obtain the link gateway feature information of each available network; Determining message transmission security attribute information of the available network based on the link gateway characteristic information includes: Performing a multi-network signal search in the environment where the terminal is located to obtain signal strength change information of all network signals in the environment within a preset time interval; determining the signal stability of each of all networks in the environment based on the signal strength change information; and identifying all available networks to which the terminal can connect based on the signal stability; Perform link gateway tracing and identification on each available network to obtain the location information of all gateways included in all links under each available network; based on the location information of all gateways, retrieve and analyze the historical message transmission records of all gateways to obtain the message transmission packet loss attribute information of each gateway during the historical message transmission process; then, based on the message transmission packet loss attribute information, determine the message transmission integrity of each available network, and use this as the message transmission security attribute information; wherein, the message transmission integrity includes the message transmission integrity corresponding to the message transmission to each target terminal via the available network; Step S4, identifying the message receiving status of all communication channels and determining the network connection order of all communication channels; selecting a matching network for the communication channel that currently needs to connect to the network based on the message transmission security attribute information; and automatically changing the network connection status of the communication channel that currently needs to connect to the network based on the message sending attribute information of the communication channel that currently needs to connect to the network, which includes: Identify the message data receiving status of each communication channel and predict the time when the message data volume allocated to each communication channel reaches the upper limit of its own allowed receiving data volume; determine the network connection order of all communication channels based on the order of the corresponding occurrence times from earliest to latest; Based on the message transmission security attribute information contained in the available network, the message transmission completeness corresponding to the message transmission to each target terminal and the target terminal to which the communication channel that currently needs to connect to the external network needs to transmit the message, a matching network is selected for the communication channel that currently needs to connect to the external network; and based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed.
2. The terminal communication security management and control method in a multi-network scenario according to claim 1, characterized in that: In step S1, all applications under the terminal are monitored to obtain the running attribute information of each application; Based on the running attribute information, the external communication processes of all the applications are determined, thereby generating a number of external communication messages corresponding to all the applications, including: Based on the program running log of the terminal, all applications in the foreground startup state are determined; based on the port addresses of all applications in the foreground startup state, all applications are monitored to obtain task processing process attribute information of each application; wherein the task processing process attribute information includes attribute information of all processes that the application needs to execute during the task processing process; Based on the task processing process attribute information, an execution data packet and an execution time of the external communication process of the application are determined; based on the execution data packet and the execution time, a plurality of external communication messages corresponding to the application are generated.
3. The terminal communication security management and control method in a multi-network scenario according to claim 1, characterized in that: In the step S2, all external communication messages are divided into a number of message clusters based on the message attribute information of all external communication messages; Based on the working status of all communication channels under the terminal, all message clusters are assigned to corresponding communication channels, including: Identify the target terminals of all external communication messages to obtain identity attribute information of the target terminals of all external communication messages; and group all external communication messages to be sent to the same target terminal into the same message cluster based on the identity attribute information; The working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel; the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are allocated to corresponding communication channels.
4. The terminal communication security management and control system in multi-network scenarios is characterized by: include: The terminal monitoring module is used to monitor all applications under the terminal and obtain the running attribute information of all applications; An external communication message generation module, configured to determine the external communication processes of all the applications based on the operation attribute information, and thereby generate a plurality of external communication messages corresponding to all the applications; A message cluster division module is used to divide all external communication messages into several message clusters based on the message attribute information of all external communication messages; A message cluster allocation module is used to allocate all message clusters to corresponding communication channels based on the working status of all communication channels under the terminal; An available network identification module is used to search for multiple network signals in the environment where the terminal is located and identify all available networks to which the terminal can connect, including: Performing a multi-network signal search in the environment where the terminal is located to obtain signal strength change information of all network signals in the environment within a preset time interval; determining the signal stability of each of all networks in the environment based on the signal strength change information; and identifying all available networks to which the terminal can connect based on the signal stability; A message transmission security attribute determination module is configured to retroactively identify all available networks and obtain link gateway characteristic information of each available network; based on the link gateway characteristic information, determine the message transmission security attribute information of the available network, including: Perform link gateway tracing and identification on each available network to obtain the location information of all gateways included in all links under each available network; based on the location information of all gateways, retrieve and analyze the historical message transmission records of all gateways to obtain the message transmission packet loss attribute information of each gateway during the historical message transmission process; then, based on the message transmission packet loss attribute information, determine the message transmission integrity of each available network, and use this as the message transmission security attribute information; wherein, the message transmission integrity includes the message transmission integrity corresponding to the message transmission to each target terminal via the available network; The network connection sequence determination module is used to identify the message receiving status of all communication channels and determine the network connection sequence of all communication channels, which includes: Identify the message data receiving status of each communication channel and predict the time when the message data volume allocated to each communication channel reaches the upper limit of its own allowed receiving data volume; determine the network connection order of all communication channels based on the order of the corresponding occurrence times from earliest to latest; The network connection execution and change module is used to select a matching network for the communication channel that currently needs to connect to the external network based on the message transmission security attribute information; and automatically change the network connection status of the communication channel that currently needs to connect to the external network based on the message transmission attribute information of the communication channel that currently needs to connect to the external network, which includes: Based on the message transmission security attribute information contained in the available network, the message transmission completeness corresponding to the message transmission to each target terminal and the target terminal to which the communication channel that currently needs to connect to the external network needs to transmit the message, a matching network is selected for the communication channel that currently needs to connect to the external network; and based on the estimated time required to complete the message sending of the communication channel that currently needs to connect to the external network, the network connection status duration of the communication channel that currently needs to connect to the external network is automatically changed.
5. The terminal communication security management and control system in a multi-network scenario according to claim 4, characterized in that: The terminal monitoring module is used to monitor all applications under the terminal and obtain the running attribute information of all applications, including: Based on the program running log of the terminal, all applications in the foreground startup state are determined; based on the port addresses of all applications in the foreground startup state, all applications are monitored to obtain task processing process attribute information of each application; wherein the task processing process attribute information includes attribute information of all processes that the application needs to execute during the task processing process; The external communication message generation module is used to determine the external communication processes of all applications based on the operation attribute information, and thereby generate a number of external communication messages corresponding to all applications, including: Based on the task processing process attribute information, an execution data packet and an execution time of the external communication process of the application are determined; based on the execution data packet and the execution time, a plurality of external communication messages corresponding to the application are generated.
6. The terminal communication security management and control system in a multi-network scenario according to claim 4, characterized in that: The message cluster division module is used to divide all external communication messages into several message clusters based on the message attribute information of all external communication messages, including: Identify the target terminals of all external communication messages to obtain identity attribute information of the target terminals of all external communication messages; and group all external communication messages to be sent to the same target terminal into the same message cluster based on the identity attribute information; The message cluster allocation module is configured to allocate all message clusters to corresponding communication channels based on the working status of all communication channels under the terminal, including: The working status of all communication channels under the terminal is identified to obtain the communication bandwidth allocated to each communication channel; the communication bandwidth allocated to each communication channel is compared with the maximum message data volume of each message cluster, and all message clusters are allocated to corresponding communication channels.
Citation Information
Patent Citations
Multi-bearer data transmission method and device
CN105338569A
Network connection method and network connection apparatus of intelligent terminal
CN107484172A