A data security transmission method and system for IDC

By adopting a comprehensive evaluation method based on sensitive information rule base and access behavior in the IDC environment, sensitive level hierarchy and dynamic adjustment of data packets to be transmitted, and packet segmentation and encryption are combined with real-time bandwidth and encryption resources, the problem of poor security and transmission efficiency in the existing technology is solved, and efficient and secure data transmission is achieved.

CN119766577BActive Publication Date: 2025-06-06PACIFIC BUSINESS SOLUTIONS (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510251633.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-06-06
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

In Internet Data Center (IDC), existing data security transmission methods are difficult to take into account security and transmission efficiency in large-scale data flows, especially in high concurrency scenarios, resulting in performance bottlenecks. At the same time, existing encryption policies cannot distinguish data sensitivity, resulting in wasted computing resources and lack a dynamic adjustment mechanism based on access behavior.

Method used

A data security transmission method and system for IDC is proposed. Through the acquisition module, the sensitive information rule base is predefined, and the access situation of the data packets to be transmitted is analyzed. The hierarchical module performs sensitive hierarchy and adjustment. The division module divides data packets according to the real-time bandwidth and sensitive hierarchy. The encryption module adopts encryption methods of different levels and generates camouflage data packets through the transmission module.

Benefits of technology

This method can match appropriate encryption methods according to the importance of data, reduce waste of computing resources, improve transmission efficiency, improve system security and stability, and is suitable for IDC data centers in high concurrency environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766577B_ABST
    Figure CN119766577B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data transmission, and discloses a data security transmission method and system for IDC, wherein the system comprises: a collection module, configured to predefine a sensitive information rule base, and screen data packets to be transmitted according to the sensitive information rule base; analyze the access situation of the data packets to be transmitted; a classification module, configured to determine the sensitive information location index and calculate the final sensitivity level of the data packets to be transmitted; a division module, configured to divide the data packets to be transmitted according to the final sensitivity level and the real-time remaining bandwidth to obtain a plurality of sub-data packets; an encryption module, configured to configure encryption resources for the sub-data packets according to the final sensitivity level for encryption; and a transmission module, configured to determine whether to generate a disguised data packet according to the size of the final sensitivity level, and transmit it. The present invention can ensure data security while maximizing the efficiency of data transmission through sensitive information classification and dynamic adjustment based on access behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and in particular to a data security transmission method and system for IDC. Background Art

[0002] The secure data transmission process in Internet data centers (IDCs) usually involves large-scale data flows. To ensure data security, traditional high-security methods usually use strong encryption algorithms such as AES-256, RSA-4096, and SM4. However, these algorithms significantly increase CPU load and affect data transmission efficiency, especially in high-concurrency scenarios, leading to performance bottlenecks.

[0003] In addition, data flows in IDC environments have different data sensitivities. Some data (such as public information and cached data) have lower security requirements, while some highly sensitive data (such as user privacy and financial transaction data) require stronger security protection. However, existing encryption strategies often adopt a one-size-fits-all approach, using the same encryption strength regardless of the sensitivity of the data, resulting in a waste of computing resources and reduced transmission efficiency. Therefore, existing methods still have the following shortcomings: they cannot distinguish data sensitivity, resulting in a waste of computing resources; they lack a dynamic adjustment mechanism based on access behavior, making it difficult to accurately match encryption strategies; and the generation strategy of disguised data packets is single, and only disguises through random filling, without combining actual access patterns.

[0004] In summary, there is an urgent need for an IDC data transmission strategy that can improve data transmission efficiency while ensuring security. Summary of the invention

[0005] In view of this, the present invention proposes a data security transmission method and system for IDC, aiming to solve the problem of low balance between security and transmission efficiency in the case of large-scale data flow in the current technology.

[0006] On the one hand, the present invention proposes a data security transmission system for IDC, comprising: a collection module, configured to predefine a sensitive information rule base, and filter data packets to be transmitted according to the sensitive information rule base. Analyze the access situation of the data packets to be transmitted, wherein the access situation includes the access frequency of the data packets to be transmitted, the access user type, the access period and the access method.

[0007] The classification module is configured to classify the sensitivity level of the data packet to be transmitted and determine the sensitive information location index based on the sensitive information rule base and the size of the data packet to be transmitted. Based on the access situation of the data packet to be transmitted, the sensitivity level of the data packet to be transmitted is adjusted to obtain the final sensitivity level of the data packet to be transmitted.

[0008] The division module is configured to obtain the real-time remaining bandwidth, and divide the data packet to be transmitted into a plurality of sub-data packets according to the final sensitivity level and the real-time remaining bandwidth.

[0009] The encryption module is used to configure encryption resources for the sub-data packet for encryption according to the final sensitivity level.

[0010] The transmission module is configured to obtain the final sensitivity level, and when the final sensitivity level is greater than or equal to a preset level threshold, generate a disguised data packet according to the data packet to be transmitted, and send the disguised data packet and the encrypted sub-data packets to the receiving end in sequence.

[0011] Furthermore, when the acquisition module screens and analyzes the data packets to be transmitted, it includes: matching the data packets to be transmitted according to the keywords in the sensitive information rule base, and when the data packets to be transmitted do not successfully match any of the keywords in the sensitive information rule base, adding a first-class label to the data packets to be transmitted and recording them as first-class data packets, and the first-class data packets are directly moved to the transmission module. When the data packets to be transmitted successfully match any of the keywords in the sensitive information rule base, adding a second-class label to the data packets to be transmitted and recording them as second-class data packets.

[0012] When analyzing the access situation of the data packets to be transmitted, the data packets to be transmitted without a type of label are selected.

[0013] Furthermore, the classification module obtains the final sensitivity level of the data packet to be transmitted, including: setting the sensitivity level of a type of data packet as an initial sensitivity level, and using the initial sensitivity level as the final sensitivity level.

[0014] The second type of data packets are graded according to their sensitivity levels, and the sensitivity levels are determined by satisfying the following relationship.

[0015]

[0016] in, For sensitivity level, is the initial sensitivity level, is the total number of paragraphs in the current data packet, is the number of successfully matched paragraphs in the current data packet. is the number of successful matches, is the sensitivity coefficient corresponding to the i-th keyword in the sensitive information rule base, The size of the current data packet to be transmitted. , and is the data content weight coefficient.

[0017] When the sensitivity level of the data packet to be transmitted is adjusted, the access situation of the data packet to be transmitted is obtained, and the final sensitivity level is calculated based on the access situation.

[0018] .

[0019] in, The final sensitivity level, is the access frequency, To access the user type value, is the access mode value, is the time decay rate, is the current time, The creation time of the data packet to be transmitted. When the access user types are administrator access, ordinary user access, and external user access, The values ​​are -1, 0, and 1. When the access modes are normal access, batch download, and API remote call, The values ​​are 0, 5, and 8 respectively. , , , is the access behavior weight coefficient.

[0020] Furthermore, when the division module divides the data packet to be transmitted, it includes: obtaining a sensitive information location index, determining the starting position and the ending position of the sensitive information according to the sensitive information location index, calculating the center point of the sensitive information, and using the center point as a cutting point to obtain a plurality of first sub-data packets.

[0021] The real-time remaining bandwidth is obtained, a partition threshold is preset and recorded as R, and a partition judgment factor is calculated according to the real-time remaining bandwidth and the current first sub-data packet. The partition judgment factor is calculated and obtained through the following relationship: .

[0022] in, To divide the judgment factor, is the size of the first sub-packet, The real-time remaining bandwidth.

[0023] When r≥R, the first sub-data packet is split twice to obtain a plurality of second sub-data packets.

[0024] Further, when the first sub-packet is further split to obtain the second sub-packet, the number of the second sub-packets is indivual.

[0025] Furthermore, when the encryption module encrypts the sub-data packet, it includes: pre-setting a first level threshold and a second level threshold, and the first level threshold is smaller than the second level threshold, the first level threshold and the second level threshold divide the sensitivity level from low to high into a first level interval, a second level interval and a third level interval, and according to the final sensitivity level corresponding to the sub-data packet before division, the first level threshold and the second level threshold are compared respectively, the sub-data packet is divided into the corresponding level interval and the encryption method is determined.

[0026] When the sub-data packet is located in the first level interval, a preset lightweight encryption is performed.

[0027] When the sub-data packet is located in the second level interval, a preset standard level encryption is performed.

[0028] When the sub-data packet is located in the third level interval, a preset multi-level encryption is performed.

[0029] Furthermore, after the encryption method is determined, the real-time available resources are obtained and the estimated resources required for encryption are calculated, and all the sub-data packets to be encrypted are sorted according to the real-time available resources, the estimated resources required for encryption and the final sensitivity level, and encryption is started in sequence.

[0030] When the sub-data packets are sorted, each sub-data packet is given a priority, and the sub-data packets are sorted in sequence according to the size of the priority, and the priority satisfies the following relationship.

[0031] .

[0032] in, is the priority value of the ith sub-packet, is the size of the ith sub-packet, is the estimated encryption resource required for the i-th sub-packet, is the final sensitivity level of the ith sub-packet, is the time decay rate, is the current time, is the creation time of the data packet to be transmitted before the i-th sub-data packet is divided, For real-time available resources, , , are the priority weight coefficients respectively.

[0033] Further, the level threshold of the transmission module during transmission is the second level threshold.

[0034] The disguised data packet and the data packet to be transmitted use the same source IP and port number and the same encryption method.

[0035] Furthermore, the transmission module is also configured to obtain the sequence number sent by the receiving end, compare the sequence number with the sequence number stored by the sending end, determine the packet loss rate of the data packet to be transmitted, and adjust the second level threshold according to the packet loss rate. The adjusted second level threshold is expressed as follows.

[0036] .

[0037] .

[0038] in, is the adjusted second level threshold, is the second level threshold, is the packet loss rate, Indicates the adjustment sensitivity coefficient, 1≤h≤2.

[0039] Compared with the prior art, the beneficial effect of the present invention is that the present invention adopts a comprehensive evaluation method based on a sensitive information rule base and access behavior to classify the sensitivity level of the data packets to be transmitted, and dynamically adjust the sensitivity level. Compared with the traditional method of using the same encryption strength for all data, the scheme can match the appropriate encryption method according to the importance of the data, reduce the waste of computing resources, and improve the transmission efficiency. By analyzing the access situation of the data packet to be transmitted (access frequency, user type, access method, etc.), the present invention can dynamically adjust the sensitivity level of the data. For example, external user access or API remote call will increase the sensitivity level of the data, while administrator access will not significantly affect the sensitivity level. This can effectively prevent potential sensitive information leakage and improve system security. The present invention splits the data packet according to the real-time remaining bandwidth and the data sensitivity level, ensuring that high-priority data can be transmitted within a reasonable bandwidth range and preventing low-priority data from occupying too much transmission resources. Compared with the fixed-size data packet splitting method, the scheme can be optimized according to the actual network situation to improve the overall transmission efficiency. The present invention adopts three different levels of encryption methods, namely lightweight encryption, standard encryption, and multi-level encryption, to ensure that data with lower sensitivity does not occupy too many computing resources, and highly sensitive data obtains stronger security protection. This can not only ensure transmission security, but also improve overall transmission performance and avoid performance bottlenecks caused by excessive CPU load. In addition, the present invention improves the stability and reliability of data transmission by real-time monitoring of packet loss rate and dynamically adjusting encryption strength. By calculating real-time available resources, estimating the resources required for encryption, and combining the sensitivity level of the data packet, the sorting of encryption tasks is optimized, the encryption efficiency of priority data is improved, system resources are optimally utilized, and unnecessary computing overhead is reduced. The strategy of the present invention can adaptively adjust various parameters (such as sensitivity level, encryption method, bandwidth division, etc.) in a high-concurrency environment to ensure that the system can carry large-scale data traffic while maintaining high security and transmission efficiency. It is particularly suitable for high-traffic environments such as IDC data centers.

[0040] On the other hand, the data security transmission method for IDC proposed by the present invention includes: S1: pre-defining a sensitive information rule base, and filtering the data packets to be transmitted according to the sensitive information rule base. Analyzing the access situation of the data packets to be transmitted, the access situation includes the access frequency of the data packets to be transmitted, the access user type, the access period and the access method.

[0041] S2: Based on the sensitive information rule base and the size of the data packet to be transmitted, the data packet to be transmitted is graded for sensitivity and the sensitive information location index is determined. Based on the access situation of the data packet to be transmitted, the sensitivity level of the data packet to be transmitted is adjusted to obtain the final sensitivity level of the data packet to be transmitted.

[0042] S3: Acquire the real-time remaining bandwidth, and divide the data packet to be transmitted into a plurality of sub-data packets according to the final sensitivity level and the real-time remaining bandwidth.

[0043] S4: Allocate encryption resources for the sub-data packet for encryption according to the final sensitivity level.

[0044] S5: Obtain the final sensitivity level. When the final sensitivity level is greater than or equal to a preset level threshold, generate a disguised data packet according to the data packet to be transmitted, and send the disguised data packet and the encrypted sub-data packets to the receiving end in sequence.

[0045] It is understandable that the above-mentioned data security transmission method and system for IDC have the same beneficial effects, which will not be described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] By reading the detailed description of the preferred embodiment below, various other advantages and benefits will become clear to those of ordinary skill in the art. The accompanying drawings are only used for the purpose of illustrating the preferred embodiment and are not considered to be limitations of the present invention. In addition, the same reference symbols are used to represent the same components throughout the accompanying drawings.

[0047] Figure 1 This is a functional framework diagram of a data security transmission system for IDC provided in an embodiment of the present invention.

[0048] Figure 2 The present invention provides a flowchart of a data security transmission method for IDC according to an embodiment of the present invention. DETAILED DESCRIPTION

[0049] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that, in the absence of conflict, the embodiments of the present invention and the features described in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0050] See also Figure 1 As shown, an embodiment of the present invention provides a data security transmission system for IDC, including: a collection module, configured to predefine a sensitive information rule base, and filter data packets to be transmitted according to the sensitive information rule base. Analyze the access situation of the data packets to be transmitted, and the access situation includes the access frequency of the data packets to be transmitted, the access user type, the access period and the access method.

[0051] The classification module is configured to classify the sensitivity level of the data packet to be transmitted and determine the sensitive information location index based on the sensitive information rule base and the size of the data packet to be transmitted. Based on the access situation of the data packet to be transmitted, the sensitivity level of the data packet to be transmitted is adjusted to obtain the final sensitivity level of the data packet to be transmitted.

[0052] The division module is configured to obtain the real-time remaining bandwidth, and divide the data packet to be transmitted into a plurality of sub-data packets according to the final sensitivity level and the real-time remaining bandwidth.

[0053] The encryption module is used to configure encryption resources for sub-data packets for encryption according to the final sensitivity level.

[0054] The transmission module is configured to obtain a final sensitivity level. When the final sensitivity level is greater than or equal to a preset level threshold, a disguised data packet is generated according to the data packet to be transmitted, and the disguised data packet and the encrypted sub-data packets are sent to the receiving end in sequence.

[0055] It is understandable that by screening and grading the data packets to be transmitted through the sensitive information rule base, the sensitivity levels of different data can be distinguished, and the same encryption strategy can be avoided for all data, thereby reducing the waste of computing resources and improving transmission efficiency. The acquisition module analyzes the access status of the data packet (including access frequency, user type, access period and access method), so that the system can dynamically adjust the sensitivity level of the data according to the actual access behavior and enhance the accuracy of the security strategy. The real-time remaining bandwidth is obtained through the division module, and the division method of the data packet is dynamically adjusted according to the data sensitivity level, so as to optimize the transmission efficiency of the data stream and reduce the network load pressure in high concurrency scenarios. The encryption module dynamically matches the encryption resources according to the final sensitivity level of the data packet, and adopts encryption methods of different strengths (lightweight, standard, and multiple levels) to reduce the computing cost and improve the encryption efficiency while ensuring data security. When highly sensitive data is transmitted, the system generates a disguised data packet, making it difficult for attackers to distinguish the real data, improving data security, and enhancing the ability to defend against malicious attacks (such as traffic analysis attacks). By comprehensively considering data sensitivity, access behavior, bandwidth status and encryption resource allocation, the system improves data transmission efficiency while ensuring data security, making large-scale data flow management in IDC environments more efficient and reliable.

[0056] Furthermore, when the acquisition module screens and analyzes the data packets to be transmitted, it includes: matching the data packets to be transmitted according to the keywords in the sensitive information rule base, and when the data packets to be transmitted do not successfully match any of the keywords in the sensitive information rule base, adding a first-class label to the data packets to be transmitted, recording them as first-class data packets, and directly moving the first-class data packets to the transmission module. When the data packets to be transmitted successfully match any of the keywords in the sensitive information rule base, adding a second-class label to the data packets to be transmitted, recording them as second-class data packets.

[0057] When analyzing the access situation of the data packets to be transmitted, the data packets to be transmitted without a type of label are selected.

[0058] It can be understood that by performing keyword matching on the data packets to be transmitted through the sensitive information rule base, preliminary screening of the data is achieved, and ordinary data packets (i.e., Class A data packets) that do not contain sensitive information are directly moved to the transmission module without the need for additional encryption or complex processing, thereby reducing the system computing overhead and improving the efficiency of data transmission.

[0059] For Class II data packets that match sensitive information, the system further performs access behavior analysis to ensure that only data that may pose a real security risk is deeply processed. This approach effectively reduces unnecessary computing resource consumption and enables the system to focus on the security protection of high-risk data.

[0060] In addition, access behavior analysis only targets packets to be transmitted that do not carry a class of labels, that is, only packets that may involve sensitive information are analyzed, avoiding redundant analysis of non-sensitive data and further improving the operating efficiency of the system. This screening mechanism can accurately focus on highly sensitive data, improve the pertinence of data security policies, and maintain the overall efficient operation of the system.

[0061] Furthermore, the classification module obtains the final sensitivity level of the data packets to be transmitted, including: setting the sensitivity level of a type of data packets as the initial sensitivity level, and using the initial sensitivity level as the final sensitivity level.

[0062] The sensitivity level of the second category data packets is classified by satisfying the following relationship.

[0063]

[0064] in, For sensitivity level, is the initial sensitivity level, is the total number of paragraphs in the current data packet, is the number of successfully matched paragraphs in the current data packet. is the number of successful matches, is the sensitivity coefficient corresponding to the i-th keyword in the sensitive information rule base, The size of the current data packet to be transmitted. , and is the data content weight coefficient.

[0065] When the sensitivity level of the data packet to be transmitted is adjusted, the access situation of the data packet to be transmitted is obtained, and the final sensitivity level is calculated based on the access situation.

[0066] .

[0067] in, The final sensitivity level, is the access frequency, To access the user type value, is the access mode value, is the time decay rate, is the current time, The creation time of the data packet to be transmitted. When the access user types are administrator access, ordinary user access, and external user access, The values ​​are -1, 0, and 1. When the access modes are normal access, batch download, and API remote call, The values ​​are 0, 5, and 8 respectively. , , , is the access behavior weight coefficient.

[0068] It can be understood that by directly setting an initial sensitivity level for a type of data packet and using it as the final sensitivity level, unnecessary complex calculations on non-sensitive data are avoided, thereby improving system operating efficiency and reducing the consumption of computing resources.

[0069] For Category II data packets, comprehensive calculations are performed based on the matching degree of sensitive information, the number of matches, and the importance of matching keywords, making the classification of sensitivity levels more refined and dynamic. Compared with the traditional fixed threshold method, this method can more accurately reflect the sensitivity of data packets, thereby providing more effective security strategies.

[0070] Adjusting the sensitivity level based on the access situation of the data packet can dynamically reflect the security risks of the data in the actual use process. For example, high-risk access behaviors such as external user access, batch downloads, or API remote calls will significantly increase the sensitivity level of the data packet, while administrator access or low-frequency access by ordinary users will not increase the sensitivity level. This adaptive adjustment mechanism enables the system to perceive the security status of the data in real time, prevent potential data leakage risks, and avoid excessive encryption or restrictions on low-risk data, thereby improving the flexibility and practicality of the system.

[0071] The introduction of a time decay factor gradually weakens the impact of historical access records on the current sensitivity level, ensuring that the system can adapt to changes in data usage in a timely manner and avoid the problem of long-term stored sensitive data having a sensitivity level that is too high or too low due to historical access, thereby optimizing security management strategies and making data protection more reasonable and efficient.

[0072] It should be noted that in the data content weight coefficient, Indicates the impact of the ratio of the number of successfully matched paragraphs to the total number of paragraphs in the data packet on the final sensitivity level. Indicates the impact of the average sensitivity coefficient of sensitive keywords on the final sensitivity level. Indicates the impact of the size of the current data packet to be transmitted on the final sensitivity level. , and The larger it is, the more sensitive the impact will be. , and The sum of the data represents the sensitivity of the data itself to the final sensitivity level.

[0073] Access behavior weight coefficient , , , It indicates the sensitivity of the impact of the access situation on the final sensitivity level.

[0074] The data content weight coefficient and the access behavior weight coefficient are adjustable constant values.

[0075] Furthermore, when the division module divides the data packet to be transmitted, it includes: obtaining the sensitive information position index, determining the starting position and the ending position of the sensitive information according to the sensitive information position index, calculating the center point of the sensitive information, using the center point as the cutting point, and obtaining several first sub-data packets.

[0076] The real-time remaining bandwidth is obtained, a partition threshold is preset and recorded as R, and a partition judgment factor is calculated based on the real-time remaining bandwidth and the current first sub-packet. The partition judgment factor is calculated and obtained through the following relationship: .

[0077] in, To divide the judgment factor, is the size of the first sub-packet, The real-time remaining bandwidth.

[0078] When r≥R, the current first sub-data packet is split twice to obtain a plurality of second sub-data packets.

[0079] First, by determining the sensitive information location index, the area containing sensitive information in the data packet can be accurately located, and the data packet can be divided using the center point of the sensitive information as the cutting point. This method ensures that sensitive data will not be truncated at the data packet boundary, thereby reducing the risk of sensitive information being exposed during transmission and improving data security.

[0080] Secondly, by dividing and adjusting the real-time remaining bandwidth, the size of the data packet can dynamically adapt to the current network conditions. The introduction of the division judgment factor enables the system to reduce unnecessary division when the bandwidth is sufficient, reduce the number of data packets, and improve transmission efficiency. When the bandwidth is tight, the data packet is further divided to avoid network congestion caused by large data packets. This adaptive division mechanism can improve the stability and efficiency of data transmission, so that the system can maintain good performance in different network environments.

[0081] In addition, the secondary splitting strategy ensures reasonable granularity control of data packets. When the split judgment factor exceeds the set threshold, the sub-packets are further split to make them more adaptable to bandwidth conditions, avoiding large data packets occupying too much bandwidth resources and affecting the overall transmission quality. This hierarchical splitting mechanism improves the flexibility of data packet scheduling, ensuring that high-priority data can be transmitted faster, while reducing the impact of congestion on other services.

[0082] Overall, this solution takes into account data security, network adaptability and transmission efficiency by combining sensitive information location indexing with dynamic bandwidth adaptation. It can be widely used in data security transmission scenarios, especially in environments with strict protection requirements for sensitive information, such as finance, medical care, government affairs and other fields.

[0083] Further, when the current first sub-packet is further split to obtain the second sub-packet, the number of the second sub-packets is indivual.

[0084] It should be noted that the sub-data packet refers to the first sub-data packet and the second sub-data packet generated by dividing the data packet to be transmitted by the dividing module.

[0085] Furthermore, when the encryption module encrypts a sub-data packet, it includes: pre-setting a first level threshold and a second level threshold, and the first level threshold is smaller than the second level threshold, the first level threshold and the second level threshold divide the sensitivity level from low to high into a first level interval, a second level interval and a third level interval, and comparing the final sensitivity level corresponding to the sub-data packet before division with the first level threshold and the second level threshold respectively, dividing the sub-data packet into corresponding level intervals and determining the encryption method.

[0086] When the sub-data packet is located in the first level interval, a preset lightweight encryption is performed.

[0087] When the sub-data packet is located in the second level interval, a preset standard level encryption is performed.

[0088] When the sub-data packet is located in the third level interval, a preset multi-level encryption is performed.

[0089] It should be noted that the first level interval range is (-∞, first level threshold]. The second level interval range is (first level threshold, second level threshold). The third level interval range is (second level threshold, +∞).

[0090] It can be understood that the above content divides the sensitivity level into three encryption levels by setting the first level threshold and the second level threshold, and can match the most suitable encryption strategy according to the sensitivity of the sub-packet to ensure the balance between security and performance. Compared with the traditional unified encryption scheme, this method can reduce the encryption calculation overhead of non-sensitive data while ensuring the high security of sensitive data, thereby improving the overall efficiency of data transmission.

[0091] Secondly, different levels of encryption methods match different security requirements. Among them: lightweight encryption in the first level range is suitable for low-sensitivity data, which can reduce the computational burden of encryption and decryption and improve system throughput.

[0092] The standard encryption level in the second level range provides moderate security and is suitable for ordinary sensitive data, ensuring that data is not easily tampered with or stolen during transmission.

[0093] The third-level multi-level encryption is suitable for highly sensitive data and uses stronger encryption algorithms or multi-layer encryption mechanisms to prevent malicious attacks or data leaks and ensure data security.

[0094] In addition, the encryption scheme can adaptively perform hierarchical encryption based on data sensitivity, ensuring that highly sensitive data receives a higher level of protection while avoiding unnecessary encryption overhead, reducing data transmission delays, and improving the real-time performance of the system.

[0095] It should be noted that lightweight encryption is an encryption method with low resource consumption and high computational efficiency. AES-128 or RC4 is preferred in this embodiment. Standard-level encryption provides a relatively moderate encryption strength, and AES-256 or RSA is preferred in this embodiment. Multi-level encryption protects data by encrypting multiple times, using different encryption algorithms and longer keys to ensure that the data is difficult to decrypt even when attacked. In this embodiment, it is preferred that AES encryption is combined with RSA encryption or that AES is used for symmetric encryption first, and then RSA is used for public key encryption.

[0096] Furthermore, after the encryption method is determined, the real-time available resources are obtained and the estimated resources required for encryption are calculated. According to the real-time available resources, the estimated resources required for encryption and the final sensitivity level, all sub-data packets to be encrypted are sorted and encryption is started in sequence.

[0097] When sorting sub-data packets, each sub-data packet is given a priority, and they are sorted in descending order of priority, and the priorities satisfy the following relationship.

[0098] .

[0099] in, is the priority value of the ith sub-packet, is the size of the ith sub-packet, is the estimated encryption resource required for the i-th sub-packet, is the final sensitivity level of the ith sub-packet, is the time decay rate, 0< ≤1, is the current time, is the creation time of the data packet to be transmitted before the i-th sub-data packet is divided, For real-time available resources, , , are the priority weight coefficients respectively.

[0100] It is understandable that by obtaining available resources in real time and calculating the estimated resources required for encryption, the system computing resources can be reasonably scheduled to avoid blocking the encryption process or degrading system performance due to insufficient resources. This method ensures efficient use of computing power, making the data encryption process smoother, reducing potential processing delays, and improving overall transmission efficiency.

[0101] Secondly, all sub-packets to be encrypted are sorted based on priority to ensure that sensitive data is encrypted and transmitted first, thereby improving the security of sensitive data. The priority calculation formula comprehensively considers the size, sensitivity level, creation time and required resources of the sub-packet, so that when resources are limited, the secure transmission of highly sensitive data is prioritized, while low-sensitivity data can be appropriately delayed to optimize system load balancing.

[0102] In addition, the priority strategy is dynamically adaptive and can adjust data priorities over time to avoid long-term high-sensitivity data that cannot be encrypted and transmitted in time due to low priority. The strategy can adapt to different business scenarios, such as finance, medical care, and government data transmission, to ensure that high-risk data can receive the highest level of security, while optimizing the allocation of computing resources and improving encryption and transmission efficiency.

[0103] , , They are priority weight coefficients, which are adjustable constant values. In high-security environments (such as finance, medical and other industries), they can be increased. , making encryption and transmission of highly sensitive data a higher priority.

[0104] In applications with high real-time requirements (such as video streaming and remote control), the , increase , , to ensure the timeliness of data transmission.

[0105] Further, the level threshold of the transmission module during transmission is a second level threshold.

[0106] The spoofed data packet uses the same source IP and port number as the data packet to be transmitted and uses the same encryption method.

[0107] It is understandable that by using the same source IP and port number for disguised data packets and data packets to be transmitted, it is possible to effectively confuse attackers from identifying real data packets. During network transmission, attackers usually locate high-value data by monitoring specific IP and port traffic characteristics. This method makes it difficult for attackers to easily distinguish between real data packets and disguised data packets, thereby enhancing the data's ability to resist interception and improving transmission security. Disguised data packets and data packets to be transmitted use the same encryption method, further enhancing the disguise effect. Since the characteristics of encrypted data (such as data length, encryption mode, etc.) may be distinguishable to a certain extent for traffic analysis, a unified encryption method can reduce the risk of being identified by traffic analysis tools, making it more difficult for attackers to classify data through encryption characteristics, thereby improving data security and concealment.

[0108] Furthermore, the transmission module is also configured to obtain the sequence number sent by the receiving end, compare the sequence number with the sequence number stored by the sending end, determine the packet loss rate of the data packet to be transmitted, and adjust the second level threshold according to the packet loss rate. The adjusted second level threshold is expressed as follows.

[0109] .

[0110] .

[0111] in, is the adjusted second level threshold, is the second level threshold, is the packet loss rate, Indicates the adjustment sensitivity coefficient, 1≤h≤2.

[0112] It is understandable that adjusting the second level threshold according to the packet loss rate can enable the transmission system to make adaptive adjustments according to changes in the network environment. When the packet loss rate is high, the system will adjust the threshold to ensure that sensitive data with higher priority can be better protected. This ensures a reasonable balance between the sensitivity and security of data during transmission.

[0113] By adjusting the second level threshold, you can optimize the balance between security and performance. When the network conditions are poor (such as high packet loss rate), the system can automatically improve security and enhance data encryption and protection. When the network is stable (low packet loss rate), the threshold can be appropriately lowered to improve data transmission efficiency and system responsiveness.

[0114] As the packet loss rate fluctuates, the system can automatically adjust its strategy to not only ensure data security, but also improve efficiency when the packet loss rate is low. This allows the system to better adapt to different network conditions and avoid excessive burden on network resources when packet loss is high. By adjusting the second-level threshold, the system can flexibly respond to different transmission needs and conditions, avoid unchanging security settings, and improve the efficiency and stability of overall data transmission.

[0115] When the packet loss rate is high, the system may increase the protection of sensitive data to prevent data from being attacked or leaked in the case of poor network quality. By properly adjusting the sensitivity threshold, the system can reasonably protect sensitive information according to the actual transmission quality and improve the security of the system in a harsh network environment.

[0116] Encryption protection mechanism: The threshold adjustment mechanism can ensure that the system protects data through different levels of encryption under different packet loss rates, thereby realizing a dynamic and efficient security protection strategy.

[0117] When the packet loss rate is low, the system reduces the security encryption strength, thereby saving encryption calculations and bandwidth consumption. When the packet loss rate is high, the system automatically increases the protection level to avoid security vulnerabilities caused by packet loss and reduce data retransmission or loss caused by packet loss.

[0118] See also Figure 2 As shown, the embodiment of the present invention provides a data security transmission method for IDC, including: S1: pre-defining a sensitive information rule base, filtering the data packet to be transmitted according to the sensitive information rule base. Analyzing the access situation of the data packet to be transmitted, the access situation includes the access frequency of the data packet to be transmitted, the access user type, the access period and the access method.

[0119] S2: Based on the sensitive information rule base and the size of the data packet to be transmitted, the data packet to be transmitted is graded for sensitivity and the sensitive information location index is determined. Based on the access situation of the data packet to be transmitted, the sensitivity level of the data packet to be transmitted is adjusted to obtain the final sensitivity level of the data packet to be transmitted.

[0120] S3: Obtain the real-time remaining bandwidth, and divide the data packet to be transmitted into several sub-data packets according to the final sensitivity level and the real-time remaining bandwidth.

[0121] S4: Configure encryption resources for the sub-packets for encryption according to the final sensitivity level.

[0122] S5: Obtain the final sensitivity level. When the final sensitivity level is greater than or equal to the preset level threshold, generate a disguised data packet according to the data packet to be transmitted, and send the disguised data packet and the encrypted sub-data packets to the receiving end in sequence.

[0123] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A data security transmission system for IDC, characterized in that: include: The collection module is configured to predefine a sensitive information rule base and filter the data packets to be transmitted according to the sensitive information rule base; Analyze the access situation of the data packet to be transmitted, wherein the access situation includes the access frequency of the data packet to be transmitted, the type of access user, the access period and the access method; A classification module is configured to classify the sensitivity level of the data packet to be transmitted and determine the sensitive information location index based on the sensitive information rule base and the size of the data packet to be transmitted; Based on the access situation of the data packet to be transmitted, adjusting the sensitivity level of the data packet to be transmitted to obtain a final sensitivity level of the data packet to be transmitted; A division module is configured to obtain the real-time remaining bandwidth, and divide the data packet to be transmitted into a plurality of sub-data packets according to the final sensitivity level and the real-time remaining bandwidth; An encryption module, configured to configure encryption resources for the sub-data packet for encryption according to the final sensitivity level; The transmission module is configured to obtain the final sensitivity level, and when the final sensitivity level is greater than or equal to a preset level threshold, generate a disguised data packet according to the data packet to be transmitted, and send the disguised data packet and the encrypted sub-data packets to the receiving end in sequence.

2. The data security transmission system for IDC according to claim 1, characterized in that: When the acquisition module screens and analyzes the data packets to be transmitted, it includes: Match the data packet to be transmitted according to the keywords in the sensitive information rule base. When the data packet to be transmitted fails to successfully match any keyword in the sensitive information rule base, add a first-class label to the data packet to be transmitted and record it as a first-class data packet. The first-class data packet is directly moved to the transmission module. When the data packet to be transmitted successfully matches any keyword in the sensitive information rule base, add a second-class label to the data packet to be transmitted and record it as a second-class data packet. When analyzing the access situation of the data packets to be transmitted, the data packets to be transmitted without a type of label are selected.

3. The data security transmission system for IDC according to claim 2, characterized in that: The classification module obtains the final sensitivity level of the data packet to be transmitted, including: Setting the sensitivity level of a class of data packets as an initial sensitivity level, and using the initial sensitivity level as a final sensitivity level; The second type of data packets are graded according to their sensitivity levels, and the sensitivity levels are determined by satisfying the following relationship: Among them, S1 is the sensitivity level, S0 is the initial sensitivity level, L is the total number of paragraphs in the current data packet, and L s is the number of successfully matched paragraphs in the current data packet, N is the number of successful matches, and W i is the sensitivity coefficient corresponding to the i-th keyword in the sensitive information rule base, D is the size of the current data packet to be transmitted; α1, α2 and α3 are the data content weight coefficients; When the sensitivity level of the data packet to be transmitted is adjusted, the access situation of the data packet to be transmitted is obtained, and the final sensitivity level is calculated based on the access situation: Among them, S is the final sensitivity level, F is the access frequency, U is the access user type value, M is the access mode value, τ is the time decay rate, T is the current time, and T0 is the creation time of the data packet to be transmitted; when the access user types are administrator access, ordinary user access, and external user access, the values ​​of U are -1, 0, and 1 respectively; when the access modes are ordinary access, batch download, and API remote call, the values ​​of M are 0, 5, and 8 respectively; β1, β2, β3, and β4 are access behavior weight coefficients.

4. The data security transmission system for IDC according to claim 3, characterized in that: When the segmentation module segments the data packets to be transmitted, it includes: Obtaining a sensitive information position index, determining a starting position and an ending position of the sensitive information according to the sensitive information position index, calculating a center point of the sensitive information, and using the center point as a cutting point to obtain a plurality of first sub-data packets; The real-time remaining bandwidth is obtained, a division threshold is preset and recorded as R, and a division judgment factor is calculated according to the real-time remaining bandwidth and the current first sub-data packet. The division judgment factor is calculated and obtained through the following relationship: Wherein, r is the division judgment factor, d1 is the size of the first sub-packet, and B(t) is the real-time remaining bandwidth; When r≥R, the first sub-data packet is split twice to obtain a plurality of second sub-data packets.

5. The data security transmission system for IDC according to claim 4, characterized in that: When the first sub-packet is further split to obtain the second sub-packet, the number of the second sub-packets is indivual.

6. The data security transmission system for IDC according to claim 5, characterized in that: When the encryption module encrypts the sub-data packet, it includes: A first level threshold and a second level threshold are preset, and the first level threshold is smaller than the second level threshold, and the first level threshold and the second level threshold divide the sensitivity level into a first level interval, a second level interval and a third level interval from low to high, and the final sensitivity level corresponding to the sub-data packet before the division is compared with the first level threshold and the second level threshold, respectively, to divide the sub-data packet into the corresponding level interval and determine the encryption method; When the sub-data packet is located in the first level interval, a preset lightweight encryption is performed; When the sub-data packet is located in the second level interval, a preset standard level encryption is performed; When the sub-data packet is located in the third level interval, a preset multi-level encryption is performed.

7. The data security transmission system for IDC according to claim 6, characterized in that: After the encryption method is determined, the real-time available resources are obtained and the estimated resources required for encryption are calculated, and all the sub-data packets to be encrypted are sorted according to the real-time available resources, the estimated resources required for encryption and the final sensitivity level, and encryption is started in sequence; When sorting the sub-data packets, each sub-data packet is given a priority, and the sub-data packets are sorted in order according to the size of the priority, and the priority satisfies the following relationship: Among them, P i is the priority value of the ith sub-packet, D i is the size of the ith sub-packet, C i is the estimated encryption resource required for the ith sub-packet, S i is the final sensitivity level of the ith sub-packet, λ is the time decay rate, T is the current time, T0 is the creation time of the ith sub-packet to be transmitted before the division, R a are real-time available resources, and K1, K2, and K3 are priority weight coefficients respectively.

8. The data security transmission system for IDC according to claim 7, characterized in that: The level threshold of the transmission module during transmission is the second level threshold; The disguised data packet and the data packet to be transmitted use the same source IP and port number and the same encryption method.

9. A data security transmission method for IDC, applied to the data security transmission system for IDC as claimed in any one of claims 1 to 8, characterized in that: include: S1: pre-defines a sensitive information rule base and filters the data packets to be transmitted according to the sensitive information rule base; Analyze the access situation of the data packet to be transmitted, wherein the access situation includes the access frequency of the data packet to be transmitted, the type of access user, the access period and the access method; S2: Based on the sensitive information rule base and the size of the data packet to be transmitted, the data packet to be transmitted is graded for sensitivity and the sensitive information location index is determined; based on the access situation of the data packet to be transmitted, the sensitivity level of the data packet to be transmitted is adjusted to obtain the final sensitivity level of the data packet to be transmitted; S3: obtaining the real-time remaining bandwidth, and dividing the data packet to be transmitted into a plurality of sub-data packets according to the final sensitivity level and the real-time remaining bandwidth; S4: configuring encryption resources for the sub-data packet according to the final sensitivity level for encryption; S5: Obtain the final sensitivity level. When the final sensitivity level is greater than or equal to a preset level threshold, generate a disguised data packet according to the data packet to be transmitted, and send the disguised data packet and the encrypted sub-data packets to the receiving end in sequence.

Citation Information

Patent Citations

  • Network data transmission method and system

    CN115766706A

  • Vehicle sensitive data encryption method, vehicle sensitive data decryption method, vehicle sensitive data encryption and decryption method, client, server, vehicle sensitive data encryption and decryption system, vehicle sensitive data encryption and decryption equipment and medium

    CN117395042A