A method for setting up a content delivery network based on anonymous communication

By introducing anonymous transmission links and the Tor network into the CDN, the problem of user privacy protection in the CDN is solved. This achieves improved anonymity and security while reducing link latency, thereby enhancing the security and performance of the CDN.

CN119728176BActive Publication Date: 2025-10-31CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411762834.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-03
Publication Date
2025-10-31
Estimated Expiration
2044-12-03

AI Technical Summary

Technical Problem

Existing content delivery networks (CDNs) fail to effectively protect users' identity and location privacy during transmission, especially in scenarios where anonymity is highly required. Furthermore, malicious nodes in the Tor network may exploit anonymity to engage in malicious activities.

Method used

Anonymous transmission links are introduced into the CDN architecture. The optimal transmission path is selected through location exposure evaluation, and anonymous transmission links are established. Relay nodes in the Tor network are used for data encryption and decryption to ensure that user identity and location information are not leaked.

Benefits of technology

It effectively hides user identity and location information, improves CDN security and performance, reduces link latency, lowers the risk of privacy leaks and attacks, and provides a more secure access experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728176B_ABST
    Figure CN119728176B_ABST
Patent Text Reader

Abstract

This disclosure provides a method for setting up a content delivery network based on anonymous communication, aiming to enhance anonymity and security while reducing link latency. The method includes: receiving a push / pull stream request from a client; determining a transmission path corresponding to the push / pull stream request based on the transmission parameters corresponding to the request; determining an anonymous transmission link between adjacent nodes of the transmission path; the anonymous transmission link being determined after orientation and exposure evaluation; and anonymously transmitting the data corresponding to the push / pull stream request through the transmission path and the anonymous transmission link between adjacent nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of content delivery network technology, and in particular to a method for setting up a content delivery network based on anonymous communication. Background Technology

[0002] Content Delivery Networks (CDNs) can effectively improve website access speed and stability, reduce the load on the origin server, enhance website security, and lower website costs. However, there is currently no solution to protect the anonymity of CDNs, which may expose user identity information and location during transmission, especially in scenarios with high privacy requirements such as government agencies, enterprises, and the military.

[0003] Tor (The Onion Router) is a tool and network protocol for anonymizing network communication. It is designed to ensure anonymity and privacy in network communication. When using Tor for anonymous communication, on the one hand, the more Tor clients running, the more users are hidden among the relay nodes, making the Tor network faster and more secure; on the other hand, as the number of Tor relays increases, malicious nodes can join the Tor network and take advantage of its anonymity to engage in malicious or even illegal activities.

[0004] Therefore, how to enhance anonymity and security while reducing link latency is an urgent problem to be solved. Summary of the Invention

[0005] To overcome the problems existing in related technologies, this disclosure provides a method for setting up a content delivery network based on anonymous communication. The technical solution of this disclosure is as follows:

[0006] According to a first aspect of the present disclosure, a method for setting up a content delivery network based on anonymous communication is provided, comprising:

[0007] Receive push and pull requests for data streams from clients;

[0008] The transmission path corresponding to the push-pull stream request is determined based on the transmission parameters corresponding to the push-pull stream request.

[0009] Anonymous transmission links are determined between adjacent nodes of the transmission path; these anonymous transmission links are determined after azimuth exposure evaluation.

[0010] The data corresponding to the push-pull stream request is transmitted anonymously through the transmission path and the anonymous transmission links between adjacent nodes of the transmission path.

[0011] Optionally, determining anonymous transmission links between adjacent nodes of the transmission path includes:

[0012] Obtain the relay node list; the relay node list includes multiple relay nodes;

[0013] Select an entry node, intermediate node, and exit node from the list of relay nodes; the entry node is a relay node carrying an entry tag, and the exit node is a relay node carrying an exit tag.

[0014] Based on the azimuth exposure rate of the entrance node, the azimuth exposure of the entrance node is evaluated to obtain the exposure evaluation result;

[0015] If the exposure assessment result is greater than or equal to the exposure rate threshold, and if the number of times the entry node is selected is less than or equal to the number of times it is selected, the entry node is discarded, and an entry node is re-selected from the relay nodes carrying the entry tag in the relay node list for azimuth exposure assessment.

[0016] If the exposure evaluation result is less than the exposure rate threshold, and / or if the number of times the entry node is selected is greater than the selection number threshold, the entry node is retained, and the anonymous transmission link determined by the entry node, the intermediate node, and the exit node is established.

[0017] Optionally, when the push-pull stream request is a pull stream request and is in the send request phase, or when the push-pull stream request is a push stream request, the transmission data corresponding to the push-pull stream request is anonymously transmitted through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path, including:

[0018] At the sending node in the adjacent nodes of the transmission path, the transmitted data is encrypted; the transmitted data is pull request content or a pushed data stream.

[0019] The encrypted transmission data is decrypted and transmitted layer by layer through each relay node of the anonymous transmission link until the decrypted transmission data is transmitted to the receiving node in the adjacent node of the transmission path at the last relay node.

[0020] Optionally, at the sending node in the adjacent nodes of the transmission path, the transmitted data is encrypted, including:

[0021] Determine the relay node corresponding to the anonymous transmission link between adjacent nodes of the transmission path;

[0022] The transmitted data is encrypted layer by layer using the session key corresponding to each relay node, in order from the furthest to the nearest relay node.

[0023] The encrypted transmission data is decrypted and transmitted layer by layer through each relay node of the anonymous transmission link, including:

[0024] For each relay node in the anonymous transmission link, after receiving the encrypted transmission data transmitted by the previous hop node, it uses its own corresponding session key to decrypt the encrypted transmission data and then transmits the decrypted transmission data to the next hop node.

[0025] Wherein, the previous hop node is the sending node or the relay node, and the next hop node is the receiving node or the relay node.

[0026] Optionally, when the push-pull stream request is a pull stream request and is in the response request phase, the transmission data corresponding to the push-pull stream request is anonymously transmitted through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path, including:

[0027] Through each hop relay node of the anonymous transmission link, the transmission data sent by the receiving node in the adjacent nodes of the transmission path is encrypted layer by layer during transmission.

[0028] The encrypted transmission data is transmitted to the sending node in the adjacent node of the transmission path at the last hop relay node.

[0029] The sending node and the receiving node are determined during the sending request phase of the streaming request.

[0030] Optionally, the transmitted data sent by the receiving node in the adjacent nodes of the transmission path is encrypted layer by layer through each hop relay node of the anonymous transmission link, including:

[0031] For each relay node in the anonymous transmission link, after receiving the transmission data transmitted by the previous hop node, its own corresponding session key encrypts the transmission data and transmits the encrypted transmission data to the next hop node.

[0032] The previous hop node is the receiving node or relay node, and the next hop node is the sending node or relay node.

[0033] Optionally, when the push-pull stream request is a push stream request, the transmission path corresponding to the push-pull stream request is determined based on the transmission parameters corresponding to the push-pull stream request, including:

[0034] Identify the first target edge node;

[0035] The data stream is authenticated based on the first target edge node, and the first target center node is determined according to the authentication result. The data stream is the data stream pushed by the push request.

[0036] Based on the first target edge node and the first target center node, the first transmission path corresponding to the push request is obtained.

[0037] Optionally, when the push-pull stream request is a pull stream request, the transmission path corresponding to the push-pull stream request is determined based on the transmission parameters corresponding to the push-pull stream request, including:

[0038] Based on the transmission parameters corresponding to the push / pull stream request, the transmission protocol and provision method corresponding to the data stream pulled by the pull stream request are determined; the transmission protocol includes a first transmission protocol and a second transmission protocol; the second transmission protocol indicates that the data stream is transmitted in the form of slices; the provision method includes origin server provision and client push stream provision;

[0039] The transmission path corresponding to the push / pull stream request is determined based on the transmission protocol and the provision method.

[0040] Optionally, when the transmission protocol is the first transmission protocol, determining the transmission path corresponding to the push / pull stream request based on the transmission protocol and the provision method includes:

[0041] When the provision method is provided by the source station, a second transmission path is determined, the second transmission path including: a second target edge node, a second target parent node, a second target center node, and the source station;

[0042] In the case where the provision method is client-side push streaming, a third transmission path is determined, which includes: a third target edge node, a third target parent node, and a third target center node.

[0043] Optionally, when the transmission protocol is the second transmission protocol, determining the transmission path corresponding to the push / pull stream request based on the transmission protocol and the provision method includes:

[0044] When the provision method is provided by the source station, determine the transmission protocol of the data stream provided by the source station;

[0045] When the source station provides the data stream using the second transmission protocol, a fourth transmission path is determined, the fourth transmission path including a fourth target edge node, a fourth target parent node, a fourth target center node, and the source station; the access terminal server of the fourth target center node is used to obtain the data stream from the source station and transmit the data stream to the gateway of the fourth target center node.

[0046] When the source station provides the data stream using the first transmission protocol, a fifth transmission path is determined, the fifth transmission path including a fifth target edge node, a fifth target parent node, a fifth target center node, and the source station; the gateway of the fifth target center node is used to obtain the data stream from the source station and to slice the data stream;

[0047] In the case where the provision method is client-side push streaming, a sixth transmission path is determined, which includes a sixth target edge node, a sixth target parent node, and a sixth target center node; the gateway of the sixth target center node is used to slice the data stream.

[0048] According to a second aspect of the present disclosure, an apparatus for setting up a content delivery network based on anonymous communication is provided, comprising:

[0049] The receiving module is used to receive push and pull requests for data streams from clients;

[0050] The first determining module is used to determine the transmission path corresponding to the push-pull stream request based on the transmission parameters corresponding to the push-pull stream request.

[0051] The second determining module is used to determine an anonymous transmission link between adjacent nodes of the transmission path; the anonymous transmission link is determined after azimuth exposure evaluation.

[0052] The transmission module is used to anonymously transmit the transmission data corresponding to the push-pull stream request through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path.

[0053] According to a third aspect of the present disclosure, an electronic device is provided, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, it implements the steps of the content delivery network setup method based on anonymous communication as described in the first aspect.

[0054] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of the content delivery network establishment method based on anonymous communication as described in the first aspect.

[0055] According to a fifth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the content delivery network construction method based on anonymous communication described in the first aspect.

[0056] This disclosure introduces anonymous transmission links into the CDN architecture. This method effectively hides user identity and location information, especially in scenarios with high privacy requirements. It not only improves CDN performance but also provides users with a more secure access experience. Based on the transmission parameters of push and pull stream requests, the optimal transmission path is determined, and an anonymous transmission link is established between adjacent nodes based on a link selection mechanism using orientation exposure evaluation. This effectively avoids malicious nodes, reduces the risk of privacy leaks and attacks, and thus improves overall communication security. While ensuring anonymity and security, it effectively reduces link latency and improves data transmission efficiency. Attached Figure Description

[0057] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings used in the description of the embodiments of this disclosure will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0058] Figure 1 This is a schematic diagram illustrating the steps of a content delivery network setup method based on anonymous communication, as shown in an embodiment of this disclosure.

[0059] Figure 2 This is a schematic diagram of a jet propulsion system as shown in an embodiment of this disclosure;

[0060] Figure 3 This is a schematic diagram of a pull stream frame shown in an embodiment of the present disclosure;

[0061] Figure 4 This is another schematic diagram of a pull stream installation shown in an embodiment of this disclosure;

[0062] Figure 5 This is a schematic diagram of an overall setup shown in an embodiment of this disclosure;

[0063] Figure 6 This is a schematic diagram of an adaptive link selection process based on exposure rate, as shown in an embodiment of this disclosure;

[0064] Figure 7 This is a schematic diagram illustrating an internal data transmission process between adjacent nodes in a transmission path, as shown in an embodiment of this disclosure.

[0065] Figure 8 This is a block diagram illustrating a content delivery network setup device based on anonymous communication, as shown in an embodiment of this disclosure.

[0066] Figure 9 This is a schematic diagram of an electronic device shown in an embodiment of this disclosure. Detailed Implementation

[0067] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0068] The terms "first," "second," etc., used in this disclosure and in the claims are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this disclosure can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0069] To facilitate understanding, the technical terms used in this disclosure will be explained first.

[0070] CDN: CDN fully utilizes multiple servers in physical space to distribute and store various resources needed by users, enabling users to obtain the resources they need stably and conveniently from the nearest server. It solves the distance and bandwidth problems caused by a large number of users accessing remote resources, allowing users to download from the nearest CDN server, reducing routing steps, increasing download speed, and shortening transmission time to improve user experience.

[0071] Tor consists of a directory server, an Onion Router (OR), and an Onion Proxy (OP). Users can communicate anonymously on the Internet through Tor.

[0072] OR is a layered encryption service, also known as a "scalable ingress router," that allows users to protect their network data in terms of anonymity and privacy.

[0073] OP: A Tor user runs an OP on their local machine. The OP periodically communicates with other Tor users, thus forming a virtual circuit in the Tor network.

[0074] The CDN processing flow is as follows:

[0075] (1) When a user requests resources from a CDN, the CDN node will take into account factors such as the geographical location and network of the request and select the node closest to the user to improve the efficiency of resource access.

[0076] (2) When a CDN node receives a request, it first checks whether the node has the resource required by the user. If it does, it returns the resource to the user directly; otherwise, it continues to make a request to the upper-level origin server.

[0077] (3) When a CDN node requests resources from the origin server, the origin server will transmit the resources to the CDN node. When the CDN node receives the resources returned by the origin server, it will cache the resources on its own server and return the resources to the user.

[0078] (4) When the resources of the origin site change, the CDN will automatically update the resources in the cache to ensure that users get the latest resources.

[0079] Therefore, CDNs can effectively improve website access speed and stability, reduce the load on the origin server, enhance website security, and lower website costs. However, currently, there is no solution for anonymity protection within CDNs. In industries with extremely high anonymity requirements, such as the military, government, and finance, it is essential to focus not only on improving access speed but also on ensuring privacy and anonymity.

[0080] Tor, an anonymous communication system, allows users to communicate anonymously on the Internet. Originally designed for military use, Tor aims to ensure anonymity and privacy in network communications. Its low latency, directory services, and ease of configuration have made it popular among users and researchers in the field of anonymous communication. It is a tool and network protocol for anonymizing network communication. By adding the current node to the Tor network and establishing multiple layers of encryption and tunnel routing during transmission, it hides the user's real identity and location information. User communication traffic passes through multiple relays and undergoes random routing, making it more difficult to trace the user's origin and destination, thus achieving anonymity.

[0081] In industries with high anonymity requirements, such as the military, government, and finance, Tor is a secure and convenient solution.

[0082] However, as the number of Tor relays increases, malicious nodes can join the Tor network and engage in malicious or even illegal activities by taking advantage of the Tor network's anonymity. Therefore, there are certain problems with building a CDN architecture on the Tor network.

[0083] To address the aforementioned technical problems, this disclosure proposes a method for establishing a content delivery network based on anonymous communication. This method enhances anonymity and security while reducing link latency.

[0084] To achieve anonymous transmission in a CDN system, the CDN system architecture needs to be built on a Tor network. The nodes in the entire CDN system are divided into three categories: edge nodes, parent nodes (zones), and central nodes (nations).

[0085] Edge nodes serve as the entry point for interaction with clients, undertaking authentication and matching functions throughout the entire chain.

[0086] Parent nodes are used to alleviate the pressure on the central machine and improve distribution capabilities under a large number of requests.

[0087] The central node is used for complex task processing, and its specific functions are as follows:

[0088] 1. Media Processing: Covers multiple functions such as transcoding, recording, screenshotting, content review, time-shift playback, and delayed playback. It works closely with professional transcoding equipment to ensure high-quality presentation and processing of media content.

[0089] 2. Stream Name Optimization: Since specific streaming processing requirements may not be directly achieved based on the stream name in user request parameters, especially when transcoding and delayed playback are involved, the central node will intelligently rewrite the stream name to adapt to different processing logic.

[0090] 3. Streaming priority management: When faced with repeated streaming, the central node can automatically cover high-priority streams according to preset priority rules to ensure the priority transmission of critical content.

[0091] 4. HLS Slicing Service: For HLS streaming requests, if the origin server cannot provide readily available slice files, the central node will automatically perform slicing operations to ensure continuous playback and efficient caching of the HLS stream. Building a CDN architecture within the Tor network requires connecting all layers of nodes and client nodes to the Tor network; if necessary, the origin server should also be connected to the Tor network.

[0092] To integrate the CDN gateway architecture into the Tor network, all nodes at each level and client nodes need to be connected to the Tor network. If necessary, the origin server should also be connected to the Tor network to ensure that all nodes within the architecture are in an anonymous network, thereby achieving anonymous and secure information transmission.

[0093] Figure 1 This is a schematic diagram illustrating the steps of a content delivery network (CDN) setup method based on anonymous communication, as shown in an embodiment of this disclosure. Figure 1 As shown, the method may specifically include the following steps:

[0094] Step S11: Receive push and pull requests from the client for the data stream.

[0095] A CDN gateway listens for push / pull streaming requests from clients on a designated network interface or port. These requests contain information about the data stream the user wishes to transmit. Upon receiving a request, the CDN gateway verifies its format and completeness to ensure it is a valid push / pull streaming request. Only after confirming a valid request will subsequent operations be performed. A CDN gateway can also be a live streaming CDN gateway.

[0096] Step S12: Determine the transmission path corresponding to the push-pull stream request based on the transmission parameters corresponding to the push-pull stream request.

[0097] The received push / pull stream requests are parsed to extract relevant transmission parameters, including data type, transmission rate, and latency requirements. Based on the parsed transmission parameters, the optimal transmission path is determined.

[0098] Step S13: Determine anonymous transmission links between adjacent nodes of the transmission path; the anonymous transmission links are determined after azimuth exposure evaluation.

[0099] Secure anonymous transmission links are established between adjacent nodes along the selected transmission path. A directional exposure assessment can be performed on each relay node in the anonymous transmission link to calculate the exposure rate of each node, identify potential malicious nodes, and thus ensure that the selected anonymous transmission link can effectively avoid malicious nodes.

[0100] Step S14: Anonymously transmit the transmission data corresponding to the push-pull stream request through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path.

[0101] By establishing anonymous transmission links between adjacent nodes in the transmission path, anonymous transmission of data corresponding to push and pull stream requests can be achieved.

[0102] By employing embodiments of this disclosure, potential malicious nodes can be effectively identified and avoided through directional exposure assessment, ensuring data anonymity during transmission and protecting user identity information from leakage. Based on the client's push / pull streaming requests and relevant transmission parameters, the system can intelligently select the optimal transmission path, improving data transmission efficiency and reducing latency. By establishing anonymous transmission links between adjacent nodes along the transmission path, the system can effectively reduce the risk of user privacy leakage and ensure data security during transmission.

[0103] In one optional embodiment, when the push-pull stream request is a push stream request, determining the transmission path corresponding to the push-pull stream request based on the transmission parameters corresponding to the push-pull stream request includes: determining a first target edge node; authenticating the data stream based on the first target edge node, and determining a first target center node based on the authentication result, wherein the data stream is the data stream pushed by the push stream request; and obtaining a first transmission path corresponding to the push stream request based on the first target edge node and the first target center node.

[0104] First, a push stream request is received from the client. This request contains the data stream information the user wishes to push, along with relevant transmission parameters. The received push stream request can be parsed to extract necessary parameters, including the data stream type, push stream target, bandwidth requirements, and other information. The push stream request can be based on the RTMP protocol.

[0105] The push streaming request transmission path adopts a two-layer model, which means that the data stream transmission mainly takes place between two layers: edge nodes and central nodes. Edge nodes are the entry points for direct interaction with the client, while central nodes are responsible for more complex data processing and storage.

[0106] Therefore, the push request will be transmitted through the first target center node and the first target edge node.

[0107] Based on the request parameters and network topology, a suitable first target edge node can be determined. This node should have sufficient bandwidth and processing power to receive push data. The node status of this first target edge node can be monitored to ensure that it is available under the current network conditions and can effectively handle push requests from clients.

[0108] At the first target edge node, the pushed data stream is authenticated to ensure that only authorized users can push the stream. Authentication can be implemented in various ways, such as using a username and password, or a push key.

[0109] Based on the authentication result, the system determines whether the push request is authorized. If authentication fails, the system will reject the push request and send a corresponding error message to the client. If authentication succeeds, the system will determine a suitable first target central node based on the status of the first target edge node and network conditions. The first target central node is responsible for processing and distributing these data streams, which may involve transcoding, storage, and other operations.

[0110] Based on the identified first target edge node and first target center node, the system constructs the first transmission path corresponding to the push request. This first transmission path connects the client, edge node, and center node, ensuring smooth data transmission. While constructing the path, the system can optimize the path based on real-time network conditions, selecting a better link to improve transmission efficiency.

[0111] The determined first transmission path information is fed back to the client, informing it of the processing status of the push request and the transmission path of the data stream. After confirming the transmission path, the client can begin pushing the data stream to the first target edge node, and then the data stream will be transmitted to the first target center node for further processing.

[0112] Additionally, if the central node is configured with active media tasks, such as a task that triggers transcoding upon receiving the streaming data, then the central node will interact with the transcoding machine. The transcoding machine's role is to convert the pushed audio and video streams into different formats or resolutions to adapt to different playback requirements and network conditions.

[0113] Figure 2 This is a schematic diagram of a power delivery system installation according to an embodiment of this disclosure. Figure 2 As shown, CDN is set up on the Tor network. The client pushes the data stream to the edge node, and then the edge node forwards it to the central node. After receiving the data stream, the central node, if it is configured with an active media task, will interact with the transcoding machine to process the pushed data stream.

[0114] By employing embodiments of this disclosure, the transmission path is determined based on the transmission parameters of the streaming request, enabling real-time response to network conditions. It allows for the selection of optimal edge and central nodes based on current network conditions and load, thereby improving data transmission efficiency and stability. After determining the edge node, authentication of the data stream based on that node effectively prevents unauthorized access and data leakage, thus enhancing the overall system security. The system allows for flexible adjustment of the transmission path according to different streaming requests and transmission parameters, adapting to diverse business needs and network environments. This flexibility enables the system to better serve various scenarios and user requirements.

[0115] In one optional embodiment, when the push-pull stream request is a pull stream request, determining the transmission path corresponding to the push-pull stream request based on the transmission parameters corresponding to the push-pull stream request includes: determining the transmission protocol and provisioning method corresponding to the data stream pulled by the pull stream request based on the transmission parameters corresponding to the push-pull stream request; the transmission protocol includes a first transmission protocol and a second transmission protocol; the second transmission protocol indicates that the data stream is transmitted in the form of slices; the provisioning method includes origin server provisioning and client push stream provisioning; and determining the transmission path corresponding to the push-pull stream request based on the transmission protocol and the provisioning method.

[0116] The client sends a stream pull request to the CDN gateway, containing the target stream information and related transmission parameters. The system parses the transmission parameters in the stream pull request to determine the transmission protocol and delivery method.

[0117] The transmission protocol includes a first transmission protocol and a second transmission protocol.

[0118] The primary transmission protocol can be either FLV (Flash Video) or RTMP (Real-Time Messaging Protocol). FLV is suitable for web-based video-on-demand and live streaming. RTMP is designed for real-time data transmission and offers lower latency.

[0119] The second transport protocol could be HLS (HTTP Live Streaming). HLS achieves streaming media transmission by breaking the entire video stream into a series of small HTTP file segments. Each segment describes a short period of the video stream, and the client downloads and plays these segments sequentially, thus enabling real-time streaming. Therefore, when a stream request is made based on the HLS protocol, the data stream is transmitted in fragments.

[0120] The supply methods include origin server provision and client-side streaming. If it is origin server provision, a transmission path needs to be established to the origin server to obtain the target data stream from the origin server; if it is client-side streaming, a transmission path needs to be established to the central node, which is the central node corresponding to the client-side streaming, to obtain the target data stream from the central node.

[0121] Using embodiments of this disclosure, the system can dynamically construct transmission paths based on transmission protocols and delivery methods. This dynamic path construction mechanism can respond to network changes in real time, optimize the quality of streaming media transmission, and ensure that users can obtain a good viewing experience in different network environments. By optimizing transmission paths and protocol selection, the system can significantly reduce latency, improve the smoothness of streaming media playback, and reduce buffering, thereby enhancing the overall viewing experience for users. It can adapt to different streaming media needs, supports multiple transmission protocols and delivery methods, giving the system good scalability and allowing it to be adjusted and optimized as technology advances and user needs change.

[0122] In one optional embodiment, when the transmission protocol is a first transmission protocol, determining the transmission path corresponding to the push / pull stream request according to the transmission protocol and the provision method includes: when the provision method is provided by the origin station, determining a second transmission path, the second transmission path including: a second target edge node, a second target parent node, a second target center node, and the origin station; and when the provision method is provided by client push streaming, determining a third transmission path, the third transmission path including: a third target edge node, a third target parent node, and a third target center node.

[0123] The system parses the streaming request and confirms that the transport protocol used is the primary transport protocol, such as RTMP or FLV. It then determines whether the streaming is provided by the origin server or by the client pushing the stream.

[0124] If the data is provided by the origin server, it indicates that the current mode is origin-back mode. A suitable second target edge node is selected; the second target parent node is determined, which coordinates the data flow across multiple edge nodes; a second target center node is selected; the address and access method of the origin server are determined to obtain the target data flow from the origin server. A second transmission path is established through the second target edge node, second target parent node, second target center node, and origin server.

[0125] When the streaming method is client-side push streaming, it indicates that the current mode is push-pull streaming. Clients other than the one initiating the pull request actively push the live stream to a central node of the CDN. A suitable third-target edge node is selected; the third-target parent node is determined, which coordinates the data streams across multiple edge nodes; the central node corresponding to the client's push request is identified and designated as the third-target central node. The third-target central node already has the data stream corresponding to the pull request, so it can directly obtain the data stream from the third-target central node. A third transmission path is established through the third-target edge node, the third-target parent node, and the third-target central node.

[0126] In addition, if the client initiates a streaming request that requires media transcoding, the central node will interact with the transcoding machine to process the data stream and transmit the processed data stream to the client.

[0127] Figure 3 This is a schematic diagram of a pull-stream installation according to an embodiment of this disclosure. Figure 3 As shown, when a CDN is deployed on the Tor network, and the streaming request is initiated based on RTMP / FLV, there are two different transmission paths depending on how the data stream is provided. When the data stream is provided by the origin server, when a client requests a live stream, the streaming request initiated based on FLV / RTMP is sent to the edge node, then back to the origin from the parent node, then back to the origin from the central node, the central node then retrieves the stream from the origin server, and then it is transmitted step-by-step through the CDN network to the edge nodes, finally reaching the client. When the data stream is provided by the client pushing the stream, when a client requests a live stream, the streaming request initiated based on FLV / RTMP is sent to the edge node, then back to the origin from the parent node, then back to the origin from the central node, the central node retrieves the data stream, and then it is transmitted step-by-step through the CDN network to the edge nodes, finally reaching the client. Additionally, if the client has media task requirements, after the central node obtains the data stream, it will interact with the transcoding machine to process the data stream before transmitting the processed data stream step-by-step to the client.

[0128] Using embodiments of this disclosure, the system can dynamically select appropriate transmission paths based on different provisioning methods. This flexibility ensures that the CDN can efficiently process streaming media requests under varying network conditions and business requirements. By selecting appropriate edge nodes, parent nodes, and central nodes, the system can optimize resource utilization and reduce unnecessary data transmission and latency. Support for multiple streaming media transmission modes (such as origin pull mode and push-pull streaming mode) enables the CDN to adapt to different business scenarios and customer needs, enhancing system applicability. In push-pull streaming mode, the third-party target central node can directly acquire existing data streams, reducing data transmission latency and ensuring users can receive live content in real time.

[0129] In one optional embodiment, when the transmission protocol is a second transmission protocol, determining the transmission path corresponding to the push / pull stream request based on the transmission protocol and the provision method includes: when the provision method is provided by the origin station, determining the transmission protocol of the data stream provided by the origin station; when the origin station provides the data stream using the second transmission protocol, determining a fourth transmission path, the fourth transmission path including a fourth target edge node, a fourth target parent node, a fourth target center node, and the origin station; the access terminal server of the fourth target center node is used to obtain the data stream from the origin station and transmit the data stream to the gateway of the fourth target center node; when the origin station provides the data stream using a first transmission protocol, determining a fifth transmission path, the fifth transmission path including a fifth target edge node, a fifth target parent node, a fifth target center node, and the origin station; the gateway of the fifth target center node is used to obtain the data stream from the origin station and slice the data stream; when the provision method is client push streaming, determining a sixth transmission path, the sixth transmission path including a sixth target edge node, a sixth target parent node, and a sixth target center node; the gateway of the sixth target center node is used to slice the data stream.

[0130] Confirm whether the data stream is provided by the origin server or by the client pushing the stream.

[0131] When the data stream is provided by the origin server, the fourth target edge node is determined based on the current network status and load. The fourth target edge node is responsible for receiving users' pull requests. The fourth target parent node is determined. The fourth target parent node is responsible for coordinating the data streams of multiple edge nodes to ensure efficient data stream transmission. The fourth target center node is determined. The fourth target center node is responsible for obtaining the data stream from the origin server and processing it.

[0132] Since the current pull request is initiated based on the second transport protocol, the node's ATS (Access Terminal Server) will be used when transmitting the data stream through the CDN node. The ATS is responsible for caching and forwarding data to reduce the access pressure on the upstream server.

[0133] When the source server provides the data stream, it can provide the data stream based on the RTMP / FLV protocol or the HLS protocol. Depending on which transport protocol the source server uses to provide the data stream, two transmission paths will occur.

[0134] When the origin server provides the data stream using a second transport protocol, i.e., based on the HLS protocol, the origin server will cut the video content into a series of small segments. These segments are provided to downstream servers via the HLS protocol. The central node's ATS will be used, which will send a request to the origin server to obtain the segment files of the data stream, and then transmit the segment files to the central node's gateway.

[0135] Therefore, when the origin server provides the data stream using the second transport protocol, the data transmission flow of the fourth transport path is as follows: The request is sent from the client, undergoes initial processing by the fourth target edge node nginx, and is then forwarded to the fourth target edge node ATS for caching and forwarding. Subsequently, the request continues to be passed through the hierarchy of the fourth target parent node gateway nginx and the fourth target parent node ATS. Finally, the request arrives at the fourth target central node gateway nginx. Here, the fourth target central node gateway nginx will first attempt to obtain the HLS slice from the directly connected fourth target central node ATS. If the required slice is not cached in the fourth target central node ATS, a back-to-origin mechanism will be triggered, and the fourth target central node ATS will directly request and obtain the HLS slice file from the origin server.

[0136] When the origin server provides the data stream using the first transmission protocol, i.e., based on the RTMP / FLV protocol, the origin server will not cut the video content into a series of small segments. Therefore, the central node needs to segment the data stream. Using the central node's gateway nginx, after obtaining the data stream from the origin server, the central node segments the data stream to facilitate caching and on-demand transmission, and then transmits the segments to the downstream server.

[0137] Therefore, when the origin server provides the data stream using the first transmission protocol, the data transmission flow of the fifth transmission path is as follows: the request is sent from the client, and after initial processing by the fifth target edge node nginx, it is forwarded to the fifth target edge node ATS for caching and forwarding; subsequently, the request continues to be passed through the hierarchy of the fifth target parent node gateway nginx and the fifth target parent node ATS; finally, the request arrives at the fifth target central node gateway nginx, and the fifth target central node nginx actively pulls the RTMP / FLV stream from the origin server. After receiving the stream, the fifth target central node nginx will slice it into small pieces, and the sliced ​​files are stored on the central node's disk for subsequent distribution and access; when the fifth target parent node ATS returns to the fifth target central node nginx, it obtains the data stream fragments from the fifth target central node nginx.

[0138] When a client initiates a pull request based on the HLS protocol to obtain a data stream pushed by another client, the gateway nginx of the central node corresponding to the client's push request will slice the data stream to meet the requirement of the pull request to obtain a fragmented data stream. These sliced ​​video files are then stored on the central node's disk for subsequent distribution and playback. In this case, the data stream no longer needs to be obtained from the origin server, but only from the central node. Therefore, it can be determined that the sixth target edge node, the sixth target parent node, and the sixth target central node are included. The sixth target central node is the central node that receives the data stream pushed by another client, and its gateway slices the pushed data stream.

[0139] Therefore, when the client pushes the data stream, the data transmission process of the sixth transmission path is as follows: the request is sent from the client, and after initial processing by the sixth target edge node nginx, it is forwarded to the sixth target edge node ATS for caching and forwarding; subsequently, the request continues to be passed through the hierarchy of the sixth target parent node gateway nginx and the sixth target parent node ATS; finally, the request arrives at the sixth target central node gateway nginx, where the sixth target central node nginx slices the pushed data stream into small pieces, and the sliced ​​files are stored on the central node's disk for subsequent distribution and access; when the sixth target parent node ATS returns to the sixth target central node nginx, it obtains the data stream slices from the sixth target central node nginx.

[0140] Figure 4 This is a schematic diagram of another pull-stream installation shown in an embodiment of this disclosure. According to... Figure 4As shown, when a CDN is deployed on the Tor network and the streaming request is initiated based on HLS, there are three different transmission paths. These three paths share a common, unified process: When the client pulls the data stream via the HLS protocol, its origin pull path sequentially passes through the edge node gateway Nginx server, the edge node ATS server, the parent node gateway Nginx server, and the parent node ATS server, finally reaching the central node gateway Nginx server. When the data stream is provided by the client-pushed stream, the central node gateway Nginx server slices the data stream and persists it to the central disk. The parent node ATS server directly retrieves the data stream slices from the central node gateway Nginx server. When the data stream is provided by the origin server using the HLS protocol, the central node gateway Nginx server retrieves the data stream slices from the central node gateway ATS server, which is responsible for directly obtaining the HLS slice files from the origin server. When the data stream is provided by the origin server using the RTMP / FLV protocol, the central node gateway Nginx server obtains the RTMP / FLV data stream from the origin server, slices the data stream, and writes it to the central disk. The parent node ATS server directly retrieves the data stream slices from the origin server via the central node gateway Nginx server.

[0141] In addition, if the client initiates a streaming request that requires media transcoding, the central node will interact with the transcoding machine to process the data stream and transmit the processed data stream to the client.

[0142] Using embodiments of this disclosure, the system can dynamically determine the optimal transmission path based on the data stream provision method and transmission protocol. This flexibility ensures that the data stream can be transmitted to the client in the most efficient way under different scenarios and conditions. It also supports multiple transmission protocols such as RTMP / FLV and HLS to meet the needs of different application scenarios; for scenarios requiring high real-time performance, the RTMP / FLV protocol can be selected; for scenarios requiring broader compatibility and lower latency, the HLS protocol can be selected. By dividing the system into multiple layers, such as edge nodes, parent nodes, and central nodes, and introducing ATS for caching and forwarding, the system achieves good scalability and stability.

[0143] Figure 5 This is a schematic diagram of an overall structure shown in an embodiment of this disclosure. Figure 5As shown, the actual CDN system architecture model is not singular, depending on customer needs and business acquisition methods. Nodes accessing the Tor network need to support various setup scenarios, specifically, setup scenarios where push-pull stream requests are push requests, push-pull stream requests are pull requests and the transport protocol is the first transport protocol, and push-pull stream requests are pull requests and the transport protocol is the second transport protocol.

[0144] A CDN system architecture based on the Tor network can realize business scenarios such as FLV / RTMP streaming, HLS streaming, and RTMP streaming. It can overcome the current lack of privacy protection for anonymity in CDNs.

[0145] When organizations such as governments, enterprises, and the military actually use CDN, connecting user nodes and CDN nodes to the Tor network allows for both nearby and stable access to the necessary resources while ensuring anonymity. For the participation of important personnel, their identity information can be hidden, thus extending the anonymity of the CDN.

[0146] When transmitting data corresponding to a push-pull stream request using the corresponding transmission path, the transmission between adjacent nodes of the transmission path is implemented using anonymous transmission links.

[0147] In one optional embodiment, determining an anonymous transmission link between adjacent nodes of the transmission path includes: obtaining a relay node list; the relay node list includes multiple relay nodes; selecting an entry node, an intermediate node, and an exit node from the relay node list; the entry node is a relay node carrying an entry tag, and the exit node is a relay node carrying an exit tag; performing an azimuth exposure assessment on the entry node based on its azimuth exposure rate to obtain an exposure assessment result; if the exposure assessment result is greater than or equal to an exposure rate threshold, and if the number of times the entry node is selected is less than or equal to a selection count threshold, discarding the entry node and re-selecting an entry node from the relay node list carrying an entry tag for azimuth exposure assessment; if the exposure assessment result is less than an exposure rate threshold, and / or if the number of times the entry node is selected is greater than a selection count threshold, retaining the entry node, and using the anonymous transmission link determined by the entry node, the intermediate node, and the exit node.

[0148] Extract currently available relay node information to form a list containing multiple relay nodes. This list includes relay nodes carrying ingress tags and relay nodes carrying egress tags.

[0149] In Tor network communication, information transmission between any two nodes involves three hops: an entry node, an intermediate node, and an exit node, before finally reaching the destination machine. These three nodes form an anonymous transmission link. The entry node is selected from among the relay nodes carrying entry tags, the exit node is selected from among the relay nodes carrying exit tags, and the intermediate nodes are relay nodes that do not carry either entry or exit tags.

[0150] From a performance optimization perspective, current location-aware link selection algorithms, such as Astoria, intelligently prioritize shorter communication paths based on geographic location information, significantly reducing communication latency. However, these algorithms may inadvertently leak client location information. In the Tor network, an environment that highly values ​​anonymity, this information leakage is particularly sensitive. Furthermore, the presence of malicious nodes also poses a significant challenge to Tor's anonymity protection mechanisms, as exposing location information compromises Tor's anonymity. To defend against attackers compromising Tor's anonymity, this paper re-analyzes potential attack scenarios arising from malicious nodes in different link locations, and proposes practical solutions to mitigate malicious attacks.

[0151] Based on Tor's mechanism, triple proxy ensures that no matter which relay node is hijacked, neither the source nor the destination address can be known simultaneously, thus achieving anonymity. According to the link selection algorithm, each relay can only be selected once, and no two relays can belong to the same family, so the probability of a malicious node deploying to the three-hop network is extremely low. Therefore, the directional exposure rate of the entry node can be used to approximate the directional exposure rate of the entire anonymous transmission link.

[0152] The following evaluation model can be used to evaluate the azimuth exposure of the entry node:

[0153] Pr[as=ase:ase←A(BG(PSA,φ,gcn))]-δe≤eℇ•Pr[1 / ASE]

[0154] Where E represents all relays with ingress labels on the Tor network, and for the ingress node e∈E selected in the link selection, the position of the ingress node ase∈ASE, ASE represents the set of AS to which all ingress nodes belong, a malicious node is defined as BG(PSA,φ,gcn), the link selection algorithm is PSA, and δe is the directional exposure rate of the ingress node.

[0155] Pr[as=ase:ase←A(BG(PSA,φ,gcn))] represents the probability that link selection algorithm A selects a specific ingress node e (located at position ase) given a malicious node BG (defined by the PSA algorithm, parameters φ, and gcn). eℇ is a constant or coefficient used to adjust or quantify the uncertainty or error range of the prediction. Pr[1 / ASE] represents the reciprocal of the probability of randomly selecting a position from all possible ingress node positions (the set of ASE).

[0156] The above evaluation model means that, considering malicious nodes (BG), the probability predicted for the location of ingress node e by link selection algorithm A, minus the azimuth exposure rate δe of that node, should be less than or equal to a threshold given by the product of a constant eℇ and the average probability of all ingress node locations. This evaluation model is used to assess the performance of link selection algorithms in protecting location privacy.

[0157] The value corresponding to Pr[as=ase:ase←A(BG(PSA,φ,gcn))]-δe is used as the exposure evaluation result. eℇ•Pr[1 / ASE] is used as the exposure rate threshold.

[0158] If the exposure assessment result of the entry node is greater than or equal to the exposure rate threshold, it means that the currently selected entry node may not be safe. It can be discarded and a safer route can be selected instead.

[0159] When selecting an ingress node, the number of selections must also be considered. Allowing a certain number of selections in link selection can strike a balance between security and efficiency.

[0160] If the exposure assessment result is greater than or equal to the exposure rate threshold, and if the number of times the entry node is selected is less than or equal to the number of selections threshold, the currently selected entry node is discarded, and a new entry node is selected from the relay nodes carrying the entry tag in the relay node list and an azimuth exposure assessment is performed.

[0161] If the exposure evaluation result is less than the exposure rate threshold, and / or if the number of times the entry node is selected is greater than the selection number threshold, the entry node is retained, and the anonymous transmission link determined by the entry node, the intermediate node, and the exit node is established.

[0162] Figure 6 This is a schematic diagram illustrating an adaptive link selection process based on exposure rate, as shown in an embodiment of this disclosure. According to... Figure 6As shown, an anonymous transmission path is selected, and the exposure evaluation result is determined according to the evaluation model; it is determined whether the exposure evaluation result is greater than or equal to the exposure rate threshold; if the exposure evaluation result is less than the exposure rate threshold, an anonymous transmission path is determined; if the exposure evaluation result is greater than or equal to the exposure rate threshold, it is further determined whether the number of selections is greater than the number of selections threshold; if the number of selections is less than or equal to the number of selections threshold, an anonymous transmission path is reselected; if the number of selections is greater than the number of selections threshold, an anonymous transmission path is determined.

[0163] When communication occurs between service nodes in a live streaming CDN architecture, an adaptive anonymity transmission link selection mechanism based on location exposure rate can improve anonymity, minimize the risk of malicious nodes, and reduce potential attacks. The core mechanism uses a location exposure evaluation model to predict the location exposure rate of anonymous transmission links by assessing the location exposure rate of the entry node. Then, it dynamically selects anonymity transmission links with higher anonymity based on an exposure rate threshold. This ensures the security and anonymity of the CDN system, making it better suited for applications involving important and confidential information, such as those in the military and government sectors.

[0164] By employing embodiments of this disclosure, the anonymity performance of an entry node in the network can be effectively determined by evaluating its directional exposure rate. The embodiments introduce a dual judgment mechanism of selection count threshold and exposure rate threshold, making the link selection process more flexible and adaptive. By evaluating the directional exposure rate of relay nodes and limiting the number of selections, potential malicious nodes can be effectively avoided, thereby improving the security of the entire anonymous transmission link and reducing the risk of attack.

[0165] In one optional embodiment, when the push-pull stream request is a pull stream request and is in the send request phase, or when the push-pull stream request is a push stream request, the transmission data corresponding to the push-pull stream request is anonymously transmitted through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path, including:

[0166] At the sending node in the adjacent nodes of the transmission path, the transmitted data is encrypted; the transmitted data is pull request content or push data stream; through each hop relay node of the anonymous transmission link, the encrypted transmitted data is decrypted and transmitted layer by layer until the decrypted transmitted data is transmitted to the receiving node in the adjacent nodes of the transmission path at the last hop relay node.

[0167] Select appropriate entry, intermediate, and exit nodes from the list of relay nodes. The entry, intermediate, and exit nodes form an effective anonymous transmission link.

[0168] At the sending node, the data to be transmitted is encrypted. Encryption algorithms such as AES and RSA can be used to ensure data security. The session key of the relay node in the anonymous transmission link can also be used to encrypt the pull request content or the pushed data stream, forming encrypted data packets.

[0169] The first relay node in the anonymous transmission link receives the encrypted data and performs a layer of decryption using the corresponding key. The decrypted data continues to travel along the anonymous transmission link, undergoing a layer of decryption at each relay node using its corresponding key. Finally, the last-hop relay node performs a layer of decryption on the encrypted data packet, obtaining the decrypted transmission data, which is then transmitted to the receiving node in the adjacent nodes of the transmission path.

[0170] The embodiments of this disclosure encrypt the transmitted data at the sending node to ensure that the data is not stolen or tampered with by unauthorized third parties during transmission. By using an anonymous transmission link, the true identity and location of the sending end are hidden, protecting user privacy and meeting the needs of application scenarios requiring anonymous transmission. Through layer-by-layer decryption at each relay node, the risk of single point of failure is effectively reduced, as each relay node can only decrypt the portion of data it is responsible for, further enhancing data transmission security. Whether it's a pull stream request or a push stream request, the system can use the same encryption and decryption processing strategy, demonstrating good flexibility and adaptability.

[0171] In one optional embodiment, at the sending node among the adjacent nodes of the transmission path, the transmitted data is encrypted, including: determining the relay node corresponding to the anonymous transmission link between the adjacent nodes of the transmission path; encrypting the transmitted data layer by layer using the session key corresponding to the relay node in order from farthest to nearest; and decrypting and transmitting the encrypted transmitted data layer by layer through each hop relay node of the anonymous transmission link, including: for each relay node in the anonymous transmission link, after receiving the encrypted transmitted data transmitted by the previous hop node, decrypting the encrypted transmitted data layer by layer using its own corresponding session key, and transmitting the decrypted transmitted data to the next hop node; wherein the previous hop node is the sending node or the relay node, and the next hop node is the receiving node or the relay node.

[0172] Once a valid anonymous transmission link is established, the relay nodes within that link can be identified using identifiers and other information. Each relay node includes an exit node, intermediate nodes, and an entry node. The entry node is the node that continues data transmission with the sending node; from a data transmission perspective, the entry node is the node closest to the sending node. The exit node is the node that continues data transmission with the receiving node; from a data transmission perspective, the exit node is the node furthest from the sending node.

[0173] After identifying the relay nodes, the system needs to obtain the session key corresponding to each relay node. The session key is used for encryption and decryption operations when transmitting data on the anonymous transmission link.

[0174] Encryption is performed layer by layer from the nearest relay node. Specifically, the steps are as follows: First, the transmitted data is encrypted using the session key of the exit node, forming the innermost encrypted data. Then, the encrypted data obtained in the previous step is encrypted a second time using the session key of the intermediate node, forming the intermediate encrypted data. Finally, the intermediate encrypted data is encrypted a final time using the session key of the entry node, forming the outermost encrypted data, thus creating the final encrypted data packet.

[0175] The sending node transmits the final encrypted data packet to the ingress node. The ingress node decrypts the encrypted data using its corresponding session key to obtain the intermediate layer encrypted data. It then transmits the decrypted intermediate layer encrypted data to the intermediate node.

[0176] The intermediate node receives the intermediate layer encrypted data from the ingress node. It decrypts the intermediate layer encrypted data using its own corresponding session key to obtain the innermost layer encrypted data, and then transmits the innermost layer encrypted data to the egress node.

[0177] The exit node receives the innermost encrypted data from the intermediate node. It decrypts the innermost encrypted data using its own session key to obtain the decrypted transmission data, which is the original data sent by the client. The decrypted original data is then transmitted in plaintext to the receiving node.

[0178] After receiving plaintext data, the receiving node performs the corresponding processing. If it is a pull request, the receiving node transmits the data stream to the client. If it is a push request, the receiving node stores or forwards the data stream to the target server.

[0179] By employing embodiments of this disclosure, data security during transmission can be ensured by encrypting the transmitted data at the sending node in adjacent nodes along the transmission path. The layer-by-layer encryption method ensures that each relay node can only decrypt data at its corresponding encryption level, thus preventing the acquisition of the complete content of the entire data packet. This encryption method effectively prevents unauthorized third parties from intercepting and parsing data during transmission, thereby improving the overall security of data transmission.

[0180] If it's a streaming request, the system will transmit the data stream to the client after receiving the request. The anonymous transmission link is also used during the transmission of the data stream to the client, and the transmitted data stream also needs to be encrypted and decrypted.

[0181] In one optional embodiment, when the push-pull stream request is a pull stream request and is in the response request phase, the transmission data corresponding to the push-pull stream request is anonymously transmitted through the anonymous transmission link between the transmission path and the adjacent nodes of the transmission path. This includes: encrypting the transmission data sent by the receiving node in the adjacent nodes of the transmission path layer by layer through each hop relay node of the anonymous transmission link; until the encrypted transmission data is transmitted to the sending node in the adjacent nodes of the transmission path at the last hop relay node; wherein the sending node and the receiving node are determined during the sending request phase of the pull stream request.

[0182] The data stream corresponding to the pull request is returned to the client via the transmission path, using anonymous transmission links between each pair of adjacent nodes in the transmission path. Each pair of adjacent nodes in the transmission path is defined as the sending node and the receiving node.

[0183] During the request sending phase of a streaming request, the sending and receiving nodes are determined among two adjacent nodes. The sending node is the one logically closer to the client, and the receiving node is the one logically closer to the data source or streaming media server. During the response request phase, the node closer to the client is again designated as the sending node, and the node closer to the data source or streaming media server is designated as the receiving node.

[0184] An anonymous transmission link consists of three relay nodes: an exit node, an intermediate node, and an entry node.

[0185] During the transmission of the data stream using the transmission path, the data is encrypted at each relay node before being transmitted to the next hop node. At the final hop relay node, the received data is encrypted again before being transmitted to the sending node.

[0186] In the embodiments of this disclosure, encryption is applied at each relay node during the data return process to ensure that the data is not stolen or tampered with during transmission. By encrypting the returned data, the true identity information between the target server and the client is hidden, protecting user privacy and reducing the risk of being monitored.

[0187] In one optional embodiment, the transmission data sent by the receiving node in the adjacent nodes of the transmission path is encrypted layer by layer through each relay node of the anonymous transmission link. This includes: for each relay node in the anonymous transmission link, after receiving the transmission data transmitted by the previous hop node, the relay node encrypts the transmission data with its own corresponding session key, and transmits the encrypted transmission data to the next hop node; wherein the previous hop node is the receiving node or the relay node, and the next hop node is the sending node or the relay node.

[0188] An anonymous transmission link consists of three relay nodes: an exit node, an intermediate node, and an entry node.

[0189] The data transmission between the egress node and the receiver node is in plaintext. After receiving the data stream from the receiver node, the egress node uses its own session key to perform a first layer of encryption on the transmitted data, forming the innermost encrypted data. The egress node then transmits the innermost encrypted data to the intermediate node.

[0190] After receiving the innermost encrypted data, the intermediate node uses its corresponding session key to perform a second layer of encryption on the innermost encrypted data, forming the intermediate encrypted data. The intermediate node then transmits the intermediate encrypted data to the entry node.

[0191] After receiving the intermediate layer encrypted data, the ingress node uses its corresponding session key to perform a third layer of encryption on the intermediate layer encrypted data, resulting in the innermost layer encrypted data, which is the final encrypted data packet. This final encrypted data packet is then transmitted to the receiving node.

[0192] After receiving the data stream that has been encrypted through three layers, the receiving node can use the corresponding session key to decrypt the final encrypted data packet and obtain the data stream sent by the receiving node.

[0193] In the embodiments of this disclosure, during data transmission, each relay node uses its own corresponding session key to encrypt the received data, and each relay node possesses a unique session key, which further enhances the security of data transmission. Each relay node encrypts and forwards the received data, ensuring that the data is processed and acknowledged at each hop, reducing the risk of data loss or corruption.

[0194] Figure 7 This is a schematic diagram illustrating an internal data transmission process between adjacent nodes in a transmission path, as shown in an embodiment of this disclosure. Figure 7 Taking the specific communication process between the client and the CDN edge node server in the Tor network as an example, the communication process of other nodes in the CDN in the Tor network can be found in [reference needed]. Figure 7 The workflow. According to... Figure 7 As shown,

[0195] Step 1: The user launches the Tor client, which first sends a request to the directory server in the Tor network. The directory server then sends the client a list of all available relay nodes on the current Tor network and their corresponding public keys. The process of the client sending the request to the directory server, and the process of the directory server returning the list of relay nodes and their corresponding public keys to the client, are encrypted. The public key list includes the session key information for each relay node.

[0196] Step 2: The client determines the anonymous transmission link based on the relay list information. The list of relay nodes provides relay nodes identified as Guard and Exit. The random routing algorithm selects the entry node from the relay nodes identified as Guard and the exit node from the relay nodes identified as Exit, according to the node identification information. The probability of random selection is determined by the weight of the bandwidth reported by the relay node in the total bandwidth. The weight represents the location exposure assessment result of the relay node.

[0197] Step 3: After selecting three relay nodes, the client obtains the session key information of each of the three relay nodes. At the same time, it establishes an anonymous transmission link containing these relay nodes based on their IP addresses and other identity information. The anonymous transmission link is used to encrypt the transmitted data.

[0198] Step 4: The client sends a request to the target server, encrypting the request content layer by layer using an onion-wrapped encryption mechanism. The target server is the CDN edge node server. Layer-by-layer encryption means that each layer encrypts the content based on the previous layer. The encryption order is as follows: from farthest to nearest, the request content is encrypted sequentially using the session keys corresponding to the three hop nodes. The encrypted request content is then transmitted through an anonymous transmission link.

[0199] In an anonymous transmission link, relay nodes decrypt the encrypted request content layer by layer sequentially. Specifically, upon receiving data, the ingress node uses its session key to decrypt the outermost layer and obtain the next-hop node information; the ingress node forwards the decrypted data to intermediate nodes; the intermediate nodes use their corresponding session keys to perform intermediate-level decryption and forward it to the egress node; finally, the egress node performs the innermost-level decryption to obtain the plaintext request content and transmits it to the target server. Only the transmission connection between the egress node and the target server is unencrypted.

[0200] Step 5: The target server receives the original request information data, replies to the user, and during the return process, the reply is encrypted using the session key corresponding to the relay node at each relay node, and finally the encrypted information is returned to the client, completing a complete communication.

[0201] Figure 8 This is a block diagram illustrating a content delivery network (CDN) setup device based on anonymous communication, as shown in an embodiment of this disclosure. Figure 8 As shown, the device includes:

[0202] The receiving module 810 is used to receive push and pull requests for data streams from the client;

[0203] The first determining module 820 is used to determine the transmission path corresponding to the push-pull stream request based on the transmission parameters corresponding to the push-pull stream request.

[0204] The second determining module 830 is used to determine an anonymous transmission link between adjacent nodes of the transmission path; the anonymous transmission link is determined after azimuth exposure evaluation.

[0205] The transmission module 840 is used to anonymously transmit the transmission data corresponding to the push-pull stream request through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path.

[0206] This disclosure also provides an electronic device, with reference to... Figure 9 , Figure 9 This is a schematic diagram of an electronic device according to an embodiment of this disclosure. For example... Figure 9 As shown, the electronic device 900 includes a memory 910 and a processor 920. The memory 910 and the processor 920 are connected via a bus for communication. The memory 910 stores a computer program that can run on the processor 920, thereby implementing the steps in the content delivery network construction method based on anonymous communication disclosed in this embodiment.

[0207] This disclosure also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the steps in the method for setting up a content delivery network based on anonymous communication disclosed in this disclosure.

[0208] This disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the steps in the content delivery network construction method based on anonymous communication disclosed in this disclosure.

[0209] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0210] Those skilled in the art will understand that the embodiments disclosed herein can be provided as methods, apparatus, or computer program products. Therefore, the embodiments disclosed herein can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the embodiments disclosed herein can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0211] This disclosure describes embodiments of methods, apparatus, electronic devices, and computer program products according to embodiments of this disclosure with reference to flowchart illustrations and / or block diagrams. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0212] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0213] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0214] Although some embodiments of the present disclosure have been described, those skilled in the art, upon learning the basic inventive concept, can make further changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the present disclosure.

[0215] The above provides a detailed description of a content distribution network setup method based on anonymous communication provided by this disclosure. Specific examples have been used to illustrate the principles and implementation methods of this disclosure. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this disclosure. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this disclosure. Therefore, the content of this specification should not be construed as a limitation of this disclosure.

Claims

1. A method for setting up a content delivery network based on anonymous communication, characterized in that, include: Receive push and pull requests from clients for data streams; The transmission path corresponding to the push-pull stream request is determined based on the transmission parameters corresponding to the push-pull stream request. Anonymous transmission links are determined between adjacent nodes of the transmission path; these anonymous transmission links are determined after azimuth exposure evaluation. The data corresponding to the push-pull stream request is transmitted anonymously through the transmission path and the anonymous transmission links between adjacent nodes of the transmission path.

2. The method according to claim 1, characterized in that, Determining anonymous transmission links between adjacent nodes in the transmission path includes: Obtain the relay node list; the relay node list includes multiple relay nodes; Select an entry node, intermediate node, and exit node from the list of relay nodes; the entry node is a relay node carrying an entry tag, and the exit node is a relay node carrying an exit tag. Based on the azimuth exposure rate of the entrance node, the azimuth exposure of the entrance node is evaluated to obtain the exposure evaluation result; If the exposure assessment result is greater than or equal to the exposure rate threshold, and if the number of times the entry node is selected is less than or equal to the number of times it is selected, the entry node is discarded, and an entry node is re-selected from the relay nodes carrying the entry tag in the relay node list for azimuth exposure assessment. If the exposure evaluation result is less than the exposure rate threshold, and / or if the number of times the entry node is selected is greater than the selection number threshold, the entry node is retained, and the anonymous transmission link determined by the entry node, the intermediate node, and the exit node is established.

3. The method according to claim 1, characterized in that, When the push-pull stream request is a pull stream request and is in the send request phase, or when the push-pull stream request is a push stream request, the transmission data corresponding to the push-pull stream request is anonymously transmitted through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path, including: At the sending node in the adjacent nodes of the transmission path, the transmitted data is encrypted; the transmitted data is pull request content or a pushed data stream. The encrypted transmission data is decrypted and transmitted layer by layer through each relay node of the anonymous transmission link until the decrypted transmission data is transmitted to the receiving node in the adjacent node of the transmission path at the last relay node.

4. The method according to claim 3, characterized in that, At the sending node in the adjacent nodes of the transmission path, the transmitted data is encrypted, including: Determine the relay node corresponding to the anonymous transmission link between adjacent nodes of the transmission path; The transmitted data is encrypted layer by layer using the session key corresponding to each relay node, in order from the furthest to the nearest relay node. The encrypted transmission data is decrypted and transmitted layer by layer through each relay node of the anonymous transmission link, including: For each relay node in the anonymous transmission link, after receiving the encrypted transmission data transmitted by the previous hop node, it uses its own corresponding session key to decrypt the encrypted transmission data and then transmits the decrypted transmission data to the next hop node. Wherein, the previous hop node is the sending node or the relay node, and the next hop node is the receiving node or the relay node.

5. The method according to claim 1, characterized in that, When the push-pull stream request is a pull stream request and is in the response request phase, the transmission data corresponding to the push-pull stream request is anonymously transmitted through the transmission path and the anonymous transmission link between adjacent nodes of the transmission path, including: Through each hop relay node of the anonymous transmission link, the transmission data sent by the receiving node in the adjacent node of the transmission path is encrypted layer by layer during transmission. The encrypted transmission data is transmitted to the sending node in the adjacent node of the transmission path at the last hop relay node. The sending node and the receiving node are determined during the sending request phase of the streaming request.

6. The method according to claim 5, characterized in that, Through each hop relay node of the anonymous transmission link, the transmitted data sent by the receiving node in the adjacent nodes of the transmission path is encrypted layer by layer, including: For each relay node in the anonymous transmission link, after receiving the transmission data transmitted by the previous hop node, its own corresponding session key encrypts the transmission data and transmits the encrypted transmission data to the next hop node. The previous hop node is the receiving node or relay node, and the next hop node is the sending node or relay node.

7. The method according to claim 1, characterized in that, When the push / pull stream request is a push stream request, the transmission path corresponding to the push / pull stream request is determined based on the transmission parameters corresponding to the push / pull stream request, including: Identify the first target edge node; The data stream is authenticated based on the first target edge node, and the first target center node is determined according to the authentication result. The data stream is the data stream pushed by the push request. Based on the first target edge node and the first target center node, the first transmission path corresponding to the push request is obtained.

8. The method according to claim 1, characterized in that, When the push-pull stream request is a pull stream request, the transmission path corresponding to the push-pull stream request is determined based on the transmission parameters corresponding to the push-pull stream request, including: Based on the transmission parameters corresponding to the push / pull stream request, the transmission protocol and provision method corresponding to the data stream pulled by the pull stream request are determined; the transmission protocol includes a first transmission protocol and a second transmission protocol; the second transmission protocol indicates that the data stream is transmitted in the form of slices; the provision method includes origin server provision and client push stream provision; The transmission path corresponding to the push / pull stream request is determined based on the transmission protocol and the provision method.

9. The method according to claim 8, characterized in that, When the transmission protocol is the first transmission protocol, determining the transmission path corresponding to the push / pull stream request based on the transmission protocol and the provision method includes: When the provision method is provided by the source station, a second transmission path is determined, the second transmission path including: a second target edge node, a second target parent node, a second target center node, and the source station; In the case where the provision method is client-side push streaming, a third transmission path is determined, which includes: a third target edge node, a third target parent node, and a third target center node.

10. The method according to claim 8, characterized in that, When the transmission protocol is the second transmission protocol, determining the transmission path corresponding to the push / pull stream request based on the transmission protocol and the provision method includes: When the provision method is provided by the source station, determine the transmission protocol of the data stream provided by the source station; When the source station provides the data stream using the second transmission protocol, a fourth transmission path is determined, the fourth transmission path including a fourth target edge node, a fourth target parent node, a fourth target center node, and the source station; the access terminal server of the fourth target center node is used to obtain the data stream from the source station and transmit the data stream to the gateway of the fourth target center node. When the source station provides the data stream using the first transmission protocol, a fifth transmission path is determined, the fifth transmission path including a fifth target edge node, a fifth target parent node, a fifth target center node, and the source station; the gateway of the fifth target center node is used to obtain the data stream from the source station and to slice the data stream; In the case where the provision method is client-side push streaming, a sixth transmission path is determined, which includes a sixth target edge node, a sixth target parent node, and a sixth target center node; the gateway of the sixth target center node is used to slice the data stream.

Citation Information

Patent Citations

  • Content distribution IP hiding method and system based on dynamic proxy chain

    CN114143073A

  • Systems And Methods for Providing Network Diversification and Secure Communications

    US20220078174A1