Data Transmission Method, Data Sending Device, and Data Receiving Device
By compressing and encrypting the data packets transmitted in the power system and determining the compression strategy based on the size of the data packets, the problem of degradation of transmission performance when data is reversely transmitted is solved, and a higher transmission rate and lower performance impact is achieved.
Patent Information
- Application Number
- CN202510345013.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-21
AI Technical Summary
In power systems, when data is transmitted in reverse, the data format needs to be verified and encrypted, resulting in a degradation in transmission performance.
By compressing and encrypting the packets, the compression strategy is determined based on the size of the packets, improving the transmission rate and reducing the impact of encryption operations on performance.
The transmission rate of data packets is improved, the impact of encryption operations on data transmission performance is reduced, and the compression time of data packets of different sizes is controlled to prevent the compression time from affecting data transmission performance.
Smart Images

Figure CN119854053B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and particularly relates to a data transmission method, a data sending device, a data receiving device, a reverse isolation device, a power system, and a computer-readable storage medium. Background Art
[0002] In a power system, there is a need to retrieve data from a low-security area to a high-security area. To ensure the security, efficiency, and reliability of the retrieval communication, a one-way isolation security protection device needs to be installed at the boundary between the low-security area and the high-security area. Among them, the reverse isolation device is used to transmit data from the low-security area to the high-security area. Since reverse transmission not only requires verifying the data format but also encrypting the data packet, the transmission performance decreases. Therefore, how to reduce the impact of encryption on transmission performance is an urgent problem to be solved at present. Summary of the Invention
[0003] Embodiments of the present invention provide a data transmission method, a data sending device, a data receiving device, a reverse isolation device, a power system, and a computer-readable storage medium to solve at least one of the above-mentioned technical problems.
[0004] The data transmission method according to the embodiments of the present invention is applied to a data sending device of a reverse isolation device. The reverse isolation device further includes a data receiving device. The data sending device is communicatively connected to the data receiving device, and the data receiving device is connected to an application service device. The data transmission method includes:
[0005] Obtain a first data packet;
[0006] Determine a corresponding compression strategy according to the size of the first data packet;
[0007] Compress the first data packet according to the compression strategy to obtain a second data packet;
[0008] Perform encryption and signature on the second data packet to obtain a third data packet;
[0009] Send the third data packet to the data receiving device so that the data receiving device: verify the signature and decrypt the third data packet to obtain a fourth data packet; decompress the fourth data packet according to the compression strategy to obtain a fifth data packet; send the fifth data packet to the application service device.
[0010] In some embodiments, before determining the corresponding compression strategy according to the size of the first data packet, the data transmission method further includes:
[0011] Judge whether the size of the first data packet is greater than or equal to a data packet size threshold;
[0012] When the size of the first data packet is greater than or equal to the data packet size threshold, it is determined that the first data packet needs to be compressed;
[0013] When the size of the first data packet is less than the data packet size threshold, it is determined that the first data packet does not need to be compressed.
[0014] In some embodiments, before determining whether the size of the first data packet is greater than or equal to the data packet size threshold, the data transmission method further includes:
[0015] Performing encryption signature and signature verification decryption on multiple test data packets with different sizes, and recording the first encryption signature time and the first signature verification decryption time;
[0016] Performing compression, encryption signature, signature verification decryption, and decompression on multiple test data packets with different sizes, and recording the first compression time, the second encryption signature time, the second signature verification decryption time, and the first decompression time;
[0017] Determining the data packet size threshold according to the first encryption signature time, the first signature verification decryption time, the first compression time, the second encryption signature time, the second signature verification decryption time, and the first decompression time corresponding to each test data packet.
[0018] In some embodiments, the determining the data packet size threshold according to the first encryption signature time, the first signature verification decryption time, the first compression time, the second encryption signature time, the second signature verification decryption time, and the first decompression time corresponding to each test data packet includes:
[0019] Judging whether the first encryption signature time, the first signature verification decryption time, the first compression time, the second encryption signature time, the second signature verification decryption time, and the first decompression time corresponding to each test data packet meet a predetermined evaluation index;
[0020] Determining the data packet size threshold according to the sizes of the test data packets that meet the predetermined evaluation index;
[0021] Wherein, the predetermined evaluation index includes:
[0022] The difference between the first compression time and the encryption signature time difference is less than a first preset threshold, and the encryption signature time difference is the difference between the first encryption signature time and the second encryption signature time;
[0023] The difference between the first decompression time and the difference in signature verification and decryption time is less than a second preset threshold, where the difference in signature verification and decryption time is the difference between the first signature verification and decryption time and the second signature verification and decryption time.
[0024] In some embodiments, the compression policy includes compression control parameters. Determining the corresponding compression policy according to the size of the first data packet includes:
[0025] When it is necessary to compress the first data packet, determining the corresponding compression control parameters according to the size of the first data packet, where the compression control parameters are positively correlated with the size of the first data packet;
[0026] Compressing the first data packet according to the compression policy to obtain a second data packet includes:
[0027] Compressing the first data packet according to the compression control parameters to obtain the second data packet;
[0028] The data transmission method further includes:
[0029] When it is not necessary to compress the first data packet, using the first data packet as the second data packet.
[0030] In some embodiments, before compressing the first data packet according to the compression control parameters to obtain the second data packet, the data transmission method further includes:
[0031] Obtaining a plurality of candidate compression algorithms;
[0032] Performing a compression performance test on the plurality of candidate compression algorithms to determine the preset compression algorithm;
[0033] Compressing the first data packet according to the compression control parameters to obtain the second data packet includes:
[0034] Compressing the first data packet according to the compression control parameters using the preset compression algorithm to obtain the second data packet.
[0035] In some embodiments, encrypting and signing the second data packet to obtain a third data packet includes:
[0036] Encrypting the second data packet to obtain an encrypted data packet;
[0037] Calculating a hash value of the second data packet to determine a first signature of the second data packet;
[0038] Encapsulating the encrypted data packet and the first signature according to a custom private protocol to obtain the third data packet.
[0039] The data transmission method according to the embodiments of the present invention is applied to a data receiving device of a reverse isolation device. The reverse isolation device further includes a data sending device. The data receiving device is communicatively connected to the data sending device and an application service device respectively. The data transmission method includes:
[0040] Receiving a third data packet sent by the data sending device, where the third data packet is from the data sending device: obtaining a first data packet; determining a corresponding compression policy according to the size of the first data packet; compressing the first data packet according to the compression policy to obtain a second data packet; encrypting and signing the second data packet to obtain the third data packet;
[0041] Performing signature verification and decryption on the third data packet to obtain a fourth data packet;
[0042] Decompressing the fourth data packet according to the compression policy to obtain a fifth data packet;
[0043] Sending the fifth data packet to the application service device.
[0044] In some embodiments, the performing signature verification and decryption on the third data packet to obtain a fourth data packet includes:
[0045] Parsing the third data packet according to a custom private protocol to obtain a parsed data packet and a first signature;
[0046] Decrypting the parsed data packet to obtain a decrypted data packet;
[0047] Calculating a hash value of the decrypted data packet to determine a second signature of the decrypted data packet;
[0048] Determining whether the first signature is the same as the second signature;
[0049] When the first signature is the same as the second signature, determining that the decrypted data packet passes the verification and using the decrypted data packet as the fourth data packet.
[0050] In some embodiments, the compression policy includes compression control parameters. The decompressing the fourth data packet according to the compression policy to obtain a fifth data packet includes:
[0051] Determining whether the fourth data packet needs to be decompressed;
[0052] When the fourth data packet needs to be decompressed, decompressing the fourth data packet according to the compression control parameters to obtain the fifth data packet;
[0053] The data transmission method further includes:
[0054] When it is not necessary to decompress the fourth data packet, using the fourth data packet as the fifth data packet.
[0055] The data sending device according to an embodiment of the present invention is applied to a reverse isolation device. The reverse isolation device further includes a data receiving device. The data sending device is communicatively connected to the data receiving device. The data receiving device is connected to an application service device. The data sending device includes:
[0056] An obtaining module, configured to obtain a first data packet;
[0057] A determining module, configured to determine a corresponding compression policy according to the size of the first data packet;
[0058] A compression module, configured to compress the first data packet according to the compression policy to obtain a second data packet;
[0059] An encryption and signature module, configured to perform encryption and signature on the second data packet to obtain a third data packet;
[0060] A first sending module, configured to send the third data packet to the data receiving device, so that the data receiving device: perform signature verification and decryption on the third data packet to obtain a fourth data packet; decompress the fourth data packet according to the compression policy to obtain a fifth data packet; verify the fifth data packet, and send the fifth data packet that passes the verification to the application service device.
[0061] The data receiving device according to an embodiment of the present invention is applied to a reverse isolation device. The reverse isolation device further includes a data sending device. The data receiving device is communicatively connected to the data sending device and the application service device respectively. The data receiving device includes:
[0062] A receiving module, configured to receive the third data packet sent by the data sending device. The third data packet is from the data sending device: obtaining a first data packet; determining a corresponding compression policy according to the size of the first data packet; compressing the first data packet according to the compression policy to obtain a second data packet; performing encryption and signature on the second data packet to obtain a third data packet;
[0063] A signature verification and decryption module, configured to perform signature verification and decryption on the third data packet to obtain a fourth data packet;
[0064] A decompression module, configured to decompress the fourth data packet according to the compression policy to obtain a fifth data packet;
[0065] A second sending module, configured to send the fifth data packet to the application service device.
[0066] The reverse isolation device according to the embodiment of the present invention, the reverse isolation device includes one or more processors and a memory, the memory stores a computer program, and when the computer program is executed by the processor, the data transmission method of any of the above embodiments is implemented.
[0067] The power system according to the embodiment of the present invention includes the reverse isolation device of any of the above embodiments.
[0068] The computer-readable storage medium according to the embodiment of the present invention, on which a computer program is stored, and when the program is executed by a processor, the data transmission method of any of the above embodiments is implemented.
[0069] In the data transmission method, data sending device, data receiving device, reverse isolation device, power system and computer-readable storage medium according to the embodiments of the present invention, the first data packet is compressed and then encrypted and signed to obtain a third data packet, and the compression policy is determined according to the size of the first data packet. In this way, the transmission rate of the data packet is improved, while reducing the impact of the encryption operation on the data transmission performance, and the compression time of the first data packets of different sizes is controlled within a reasonable range, preventing the data transmission performance of the reverse isolation device from being affected due to too long compression time.
[0070] Additional aspects and advantages of the embodiments of the present invention will be given in part in the following description, will become apparent in part from the following description, or will be learned through the practice of the embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0072] Figure 1 is a flowchart of the data transmission method according to some embodiments of the present invention;
[0073] Figure 2 is a module diagram of the reverse isolation device according to some embodiments of the present invention;
[0074] Figure 3 is a flowchart of the data transmission method according to some embodiments of the present invention;
[0075] Figure 4 is a module diagram of the power system according to some embodiments of the present invention;
[0076] Figure 5 is a flowchart of the data transmission method according to some embodiments of the present invention;
[0077] Figure 6 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0078] Figure 7 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0079] Figure 8 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0080] Figure 9 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0081] Figure 10 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0082] Figure 11 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0083] Figure 12 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0084] Figure 13 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0085] Figure 14 is a schematic flowchart of the data transmission method according to some embodiments of the present invention;
[0086] Figure 15 is a schematic diagram comparing the transmission performance of 1KB data packets in different isolation devices;
[0087] Figure 16 is a schematic diagram comparing the transmission performance of 2KB data packets in different isolation devices;
[0088] Figure 17 is a schematic diagram comparing the transmission performance of 4KB data packets in different isolation devices;
[0089] Figure 18 is a schematic diagram comparing the transmission performance of 8KB data packets in different isolation devices;
[0090] Figure 19 is a schematic diagram comparing the transmission performance of 16KB data packets in different isolation devices;
[0091] Figure 20 is a schematic diagram comparing the transmission performance of 32KB data packets in different isolation devices;
[0092] Figure 21It is a schematic diagram for comparing the transmission performance of 63KB data packets in different isolation devices;
[0093] Figure 22 It is a schematic diagram of the modules of the data sending device according to some embodiments of the present invention;
[0094] Figure 23 It is a schematic diagram of the modules of the data sending device according to some embodiments of the present invention;
[0095] Figure 24 It is a schematic diagram of the modules of data reception according to some embodiments of the present invention;
[0096] Figure 25 It is a schematic diagram of the modules of the reverse isolation device according to some embodiments of the present invention;
[0097] Figure 26 It is a schematic diagram of the connection state between the computer-readable storage medium and the processor according to some embodiments of the present invention. Specific Embodiments
[0098] The following further describes the embodiments of the present invention with reference to the accompanying drawings. The same or similar reference numerals in the drawings denote the same or similar elements or elements having the same or similar functions throughout. Additionally, the embodiments of the present invention described below with reference to the accompanying drawings are exemplary only for explaining the embodiments of the present invention and should not be construed as limiting the present invention.
[0099] Please refer to Figures 1 to 3 , an embodiment of the present invention provides a data transmission method, which is applied to the data sending device 100 of the reverse isolation device 300. The reverse isolation device 300 further includes a data receiving device 200. The data sending device 100 is communicatively connected to the data receiving device 200, and the data receiving device 200 is connected to the application service device. The data transmission method includes:
[0100] S101: Obtain a first data packet;
[0101] S102: Determine a corresponding compression strategy according to the size of the first data packet;
[0102] S103: Compress the first data packet according to the compression strategy to obtain a second data packet;
[0103] S104: Perform encryption and signature on the second data packet to obtain a third data packet;
[0104] S105: Send the third data packet to the data receiving device 200 so that the data receiving device 200: perform verification, signature, and decryption on the third data packet to obtain a fourth data packet; decompress the fourth data packet according to the compression strategy to obtain a fifth data packet; send the fifth data packet to the application service device.
[0105] In the data transmission method according to the embodiment of the present invention, the first data packet is compressed and then encrypted and signed to obtain a third data packet, and the compression strategy is determined according to the size of the first data packet. In this way, the transmission rate of the data packet is improved, while reducing the impact of the encryption and signature operation on the data transmission performance, and the compression time of the first data packets of different sizes is controlled within a reasonable range, preventing the data transmission performance of the reverse isolation device 300 from being affected due to too long compression time.
[0106] Specifically, as Figure 4 shown, the reverse isolation device 300 may be an isolation device of the power system 400, and is used to transmit data from the low security area to the high security area of the power system 400. As Figure 2 shown, the reverse isolation device 300 includes a data sending device 100 and a data receiving device 200. The data sending device 100 may be set in the low security area to obtain data packets in the low security area. The data receiving device 200 may be set in the high security area and is communicatively connected to the data sending device 100 to receive the data packets sent by the data sending device 100. The data receiving device 200 is also communicatively connected to the application service device to send the received data packets to the application service device. The application service device may receive the data packets and further process and analyze the data packets according to the service requirements of the power system 400.
[0107] The following details the data processing and transmission process of the data sending device 100. The data sending device 100 obtains the data packets that need to be transmitted in the low security area, that is, the first data packets. The number of the first data packets may be one or more. After obtaining the first data packets, the data format of the first data packets may be checked to prevent abnormal data packets that do not conform to the data format from being transmitted to other devices. After the format check is completed, the compression strategy corresponding to each first data packet can be determined according to the size of each first data packet. That is to say, different compression strategies can be adopted for the first data packets of different sizes.
[0108] It can be understood that when the same compression strategy is adopted, the compression times of the first data packets of different sizes are different, and the compression time is positively correlated with the size of the first data packet. Therefore, different compression strategies are adopted to compress the first data packets of different sizes, and the compression times of the first data packets of different sizes are controlled within a reasonable range, preventing the data transmission performance of the reverse isolation device 300 from being affected due to too long compression time.
[0109] The first data packet can be compressed according to the compression policy to obtain a second data packet. The second data packet can be encrypted and signed to obtain a third data packet. After obtaining the third data packet, the third data packet can be sent to the data receiving device 200. After the data receiving device 200 receives the third data packet, the third data packet can be verified, signed, and decrypted to obtain a fourth data packet. Then, the fourth data packet can be decompressed according to the compression policy to obtain a fifth data packet. Finally, the fifth data packet is sent to the application service device.
[0110] In the related art, the data packet is directly encrypted and then transmitted. Encryption requires the execution of complex algorithms, which increases the computational complexity, reduces the processing speed, and increases the amount of data to be transmitted. When transmitting a large amount of data, there is a problem of insufficient performance.
[0111] In the embodiments of the present invention, before encryption and signature, the obtained first data packet is compressed. Through compression, the amount of data that needs to be encrypted and signed is reduced, which can effectively improve the encryption and signature speed. Moreover, the third data packet obtained by first compressing and then encrypting and signing has a smaller amount of data than the data packet obtained by directly encrypting. In this way, the transmission rate of the reverse isolation device 300 can be improved, and the impact of the encryption operation on the data transmission performance can be reduced; in the same physical environment and network bandwidth, without changing the hardware configuration of the reverse isolation device 300, the data transmission performance of the reverse isolation device 300 can be effectively improved.
[0112] Please refer to Figure 3 and Figure 5 , in some embodiments, before determining the corresponding compression policy according to the size of the first data packet (i.e., S102), the data transmission method further includes:
[0113] S107: Determine whether the size of the first data packet is greater than or equal to the data packet size threshold;
[0114] S108: When the size of the first data packet is greater than or equal to the data packet size threshold, determine that the first data packet needs to be compressed;
[0115] S109: When the size of the first data packet is less than the data packet size threshold, determine that the first data packet does not need to be compressed.
[0116] Specifically, before determining the corresponding compression policy according to the size of the first data packet, it is necessary to first determine whether the first data packet needs to be compressed. It can be determined according to the size of the first data packet and the data packet size threshold.
[0117] Obtain a preset data packet size threshold, and determine whether the size of the first data packet is greater than or equal to the data packet size threshold. When the size of the first data packet is greater than or equal to the data packet size threshold, it is determined that the first data packet needs to be compressed. When the size of the first data packet is less than the data packet size threshold, it is determined that the first data packet does not need to be compressed. That is to say, only the first data packet with a larger size is compressed, and the first data packet with a smaller size is not compressed.
[0118] It can be understood that for the first data packet with a smaller size, the amount of data reduced by compression is small, the improvement effect on the encryption and signature speed is not obvious, and compression takes a certain amount of time, so the improvement on the data transmission performance is not obvious either. Therefore, there is no need to compress the first data packet with a smaller size. In this way, the data processing process can be simplified, the consumption of computing resources can be reduced, and the overall performance of the reverse isolation device 300 can be optimized.
[0119] The following details the specific process of determining the data packet size threshold.
[0120] Please refer to Figure 6 , in some embodiments, before determining whether the size of the first data packet is greater than or equal to the data packet size threshold (i.e., S107), the data transmission method further includes:
[0121] S110: Perform encryption and signature, and verification and decryption on multiple test data packets with different sizes, and record the first encryption and signature time and the first verification and decryption time;
[0122] S111: Compress, encrypt and sign, verify and decrypt, and decompress multiple test data packets with different sizes, and record the first compression time, the second encryption and signature time, the second verification and decryption time, and the first decompression time;
[0123] S112: Determine the data packet size threshold according to the first encryption and signature time, the first verification and decryption time, the first compression time, the second encryption and signature time, the second verification and decryption time, and the first decompression time corresponding to each test data packet.
[0124] Specifically, before data transmission, multiple test data packets with different sizes can be used for testing to determine the data packet size threshold.
[0125] Obtain multiple test data packets of different sizes, and perform encryption signature and signature verification and decryption on each test data packet in sequence. Record the encryption signature time as the first encryption signature time, and record the signature verification and decryption time as the first signature verification and decryption time. Then perform compression, encryption signature, signature verification and decryption, and decompression on each test data packet in sequence. Record the compression time as the first compression time, record the encryption signature time as the second encryption signature time, record the signature verification and decryption time as the second signature verification and decryption time, and record the decompression time as the second decompression time.
[0126] According to the first encryption signature time, the first signature verification and decryption time, the first compression time, the second encryption signature time, the second signature verification and decryption time, and the first decompression time corresponding to each test data packet, the relationship between the compression time and the encryption signature time of data packets of different sizes, and the relationship between the decompression time and the signature verification and decryption time can be evaluated; thus, according to the relationship between the compression time and the encryption signature time, and the relationship between the decompression time and the signature verification and decryption time, an appropriate data packet size threshold can be determined. In this way, the first data packets that need to be compressed and those that do not need to be compressed can be divided more accurately.
[0127] Please refer to Figure 7 , in some embodiments, determining the data packet size threshold (i.e., S112) according to the first encryption signature time, the first signature verification and decryption time, the first compression time, the second encryption signature time, the second signature verification and decryption time, and the first decompression time corresponding to each test data packet includes:
[0128] S1121: Determine whether the first encryption signature time, the first signature verification and decryption time, the first compression time, the second encryption signature time, the second signature verification and decryption time, and the first decompression time corresponding to each test data packet meet the predetermined evaluation criteria;
[0129] S1122: Determine the data packet size threshold according to the sizes of the test data packets that meet the predetermined evaluation criteria;
[0130] Among them, the predetermined evaluation criteria include:
[0131] The difference between the difference of the first compression time and the encryption signature time is less than the first preset threshold, and the encryption signature time difference is the difference between the first encryption signature time and the second encryption signature time;
[0132] The difference between the difference of the first decompression time and the signature verification and decryption time is less than the second preset threshold, and the signature verification and decryption time difference is the difference between the first signature verification and decryption time and the second signature verification and decryption time.
[0133] Specifically, calculate the difference between the first encryption signature time and the second encryption signature time corresponding to each test data packet to obtain the corresponding encryption signature time difference. Calculate the difference between the first signature verification decryption time and the second signature verification decryption time corresponding to each test data packet to obtain the corresponding signature verification decryption time difference.
[0134] Determine whether the first compression time, encryption signature time difference, first decompression time, and signature verification decryption time difference corresponding to each test data packet meet the predetermined evaluation criteria. The predetermined evaluation criteria include that the difference between the first compression time and the encryption signature time difference is less than the first preset threshold, and the difference between the first decompression time and the signature verification decryption time difference is less than the second preset threshold. Herein, the first preset threshold and the second preset threshold may be the same or different, and the specific values can be set according to the actual situation and are not limited herein.
[0135] For example, the first preset threshold and the second preset threshold can be set as positive numbers approaching zero. Then, the difference between the first compression time and the encryption signature time difference being less than the first preset threshold includes: the first compression time is less than or equal to the encryption signature time difference, and the first compression time is greater than the encryption signature time difference and the difference between the first compression time and the encryption signature time difference approaches zero. The difference between the first decompression time and the signature verification decryption time difference being less than the second preset threshold includes: the first decompression time is less than or equal to the signature verification decryption time difference, and the first decompression time is greater than the signature verification decryption time difference and the difference between the first decompression time and the signature verification decryption time difference approaches zero. Of course, the first preset threshold and the second preset threshold can be set to zero.
[0136] Statistically calculate the size of the test data packets that meet the predetermined evaluation criteria, and the size of the test data packet with the smallest size that meets the predetermined evaluation criteria can be used as the data packet size threshold.
[0137] Please refer to Figure 3 and Figure 8 , in some embodiments, the compression policy includes compression control parameters. Determining the corresponding compression policy according to the size of the first data packet (i.e., S102) includes:
[0138] S1021: When it is necessary to compress the first data packet, determine the corresponding compression control parameters according to the size of the first data packet, where the compression control parameters are positively correlated with the size of the first data packet;
[0139] At this time, compressing the first data packet according to the compression policy to obtain the second data packet (i.e., S103) includes:
[0140] S1031: Compress the first data packet according to the compression control parameters to obtain the second data packet;
[0141] At this time, the data transmission method further includes:
[0142] S113: When there is no need to compress the first data packet, use the first data packet as the second data packet.
[0143] Specifically, the compression policy includes compression control parameters. When it is necessary to compress the first data packet, first determine the corresponding compression control parameters according to the size of the first data packet. The compression control parameters may include the compression ratio.
[0144] In one example, encrypt and sign, and verify the signature and decrypt multiple test data packets with different sizes, and record the third encryption and signature time and the fourth signature verification and decryption time. Compress, encrypt and sign, verify the signature and decrypt, and decompress multiple test data packets with different sizes according to different compression ratios, and record the second compression time, the fourth encryption and signature time, the fourth signature verification and decryption time, and the second decompression time. Determine the compression control parameters corresponding to the test data packets of different sizes according to the third encryption and signature time, the third signature verification and decryption time, the second compression time, the fourth encryption and signature time, the fourth signature verification and decryption time, and the second decompression time corresponding to each test data packet.
[0145] Calculate the difference between the third encryption and signature time and the fourth encryption and signature time corresponding to each test data packet to obtain the corresponding encryption and signature time difference. Calculate the difference between the third signature verification and decryption time and the fourth signature verification and decryption time corresponding to each test data packet to obtain the corresponding signature verification and decryption time difference.
[0146] Judge whether the second compression time, the encryption and signature time difference, the second decompression time, and the signature verification and decryption time difference corresponding to each test data packet meet the parameter evaluation index. The parameter evaluation index includes that the absolute value of the difference between the second compression time and the encryption and signature time difference is less than the third preset threshold. The third preset threshold can be set according to the actual situation and is not limited here. For example, the third preset threshold can be set to a value approaching zero, that is to say, the parameter evaluation index includes: the second compression time ≈ the encryption and signature time difference. In this way, the overall time consumption of data transmission will not be increased.
[0147] The parameter evaluation index also includes that the absolute value of the difference between the second decompression time and the signature verification and decryption time difference is less than the fourth preset threshold. The fourth preset threshold can be set according to the actual situation and is not limited here. The fourth preset threshold can be the same as the third preset threshold or different. The fourth preset threshold can be set to a value approaching zero, that is to say, the parameter evaluation index includes: the second decompression time ≈ the signature verification and decryption time difference. In this way, the overall time consumption of data transmission will not be increased.
[0148] For each test compression package, a corresponding compression ratio can be determined according to the parameter evaluation index, and this compression ratio is the compression control parameter corresponding to the size of the test compression package. For multiple test data packets of different sizes, a compression ratio can be determined respectively, so as to obtain the compression control parameter corresponding to each size. In one example, the value range of the compression ratio is between 2:1 and 3:1.
[0149] According to the size of the first data packet, the corresponding compression control parameter can be determined. Compress the first data packet according to the compression control parameter to obtain the second data packet. It has been found through research that the compression control parameter is positively correlated with the size of the first data packet. When the size of the first data packet is small, the determined compression control parameter is small, so that the first data packet can be compressed faster. When the size of the first data packet is large, the determined compression control parameter is large, so that the data volume of the second data packet after compression is less, and the transmission rate is faster in the subsequent transmission process.
[0150] In some embodiments, the compression control parameter is determined according to the transmission strategy model, and the transmission strategy model is shown as follows:
[0151]
[0152] Where Q represents the device throughput. Represents the compression control parameter (i.e., the compression ratio). Represents the transmission time difference, . , Represents the compression time, Represents the decompression time. , Represents the encryption signature time, Represents the signature verification and decryption time, Represents the transmission time. It can be understood that when the compression control parameter satisfies the above transmission strategy model, the transmission performance can be effectively improved.
[0153] In the embodiments of the present invention, the first data packet is compressed according to the compression control parameter that is positively correlated with the size of the first data packet, and the compression control parameter can be determined according to the parameter evaluation index. In this way, the compression time of the first data packet of different sizes can be controlled within a reasonable range, and the data transmission performance of the reverse isolation device 300 can be optimized without changing the hardware configuration under the same time.
[0154] In addition, when it is not necessary to compress the first data packet, the first data packet can be directly used as the second data packet.
[0155] Please refer to Figure 9, in some embodiments, before compressing the first data packet according to the compression control parameter to obtain the second data packet (i.e., S103), the data transmission method further includes:
[0156] S114: Obtain multiple candidate compression algorithms;
[0157] S115: Perform compression performance tests on multiple candidate compression algorithms to determine the preset compression algorithm;
[0158] At this time, compressing the first data packet according to the compression control parameter to obtain the second data packet (i.e., S1031) includes:
[0159] S10311: Compress the first data packet using the preset compression algorithm according to the compression control parameter to obtain the second data packet.
[0160] Specifically, before compressing the first data packet, it is also necessary to determine the compression algorithm. Multiple candidate compression algorithms can be obtained first, and compression performance tests are performed on multiple candidate compression algorithms. The multiple compression algorithms can include any multiple of compression algorithms such as the LZ4 compression algorithm, the Zstandard (Zstd) compression algorithm, the Snappy compression algorithm, the Brotli compression algorithm, the Gzip compression algorithm, the Bzip2 compression algorithm, the LZMA compression algorithm (such as the 7-Zip compression algorithm), or the Zlib compression algorithm, etc., which are not limited here.
[0161] The compression performance test is as follows: Use multiple candidate compression algorithms to compress and decompress test data packets of the same size, and record the third compression time and the third decompression time, as well as the compression loss. The third compression time, the third decompression time, and the compression loss can all be used as evaluation indicators of compression performance. Compare the third compression time, the third decompression time, and the compression loss of multiple candidate compression algorithms, and comprehensively determine the candidate compression algorithm with the best compression performance as the preset compression algorithm.
[0162] Multiple candidate compression algorithms can also be used to compress and decompress multiple test data packets of different sizes respectively to perform compression performance tests and determine the preset compression algorithm. In this way, an efficient and lossless preset compression algorithm can be determined, avoiding adverse effects of compression operations on data transmission performance.
[0163] In an example, for test data packets of different sizes, the compression performance of the LZ4 compression algorithm is the best. Therefore, the LZ4 compression algorithm is selected as the preset compression algorithm.
[0164] Please refer to Figure 3 and Figure 10 , in some embodiments, encrypting and signing the second data packet to obtain the third data packet (i.e., S104) includes:
[0165] S1041: Encrypt the second data packet to obtain an encrypted data packet;
[0166] S1042: Calculate the hash value of the second data packet to determine the first signature of the second data packet;
[0167] S1043: Package the encrypted data packet and the first signature according to a custom private protocol to obtain a third data packet.
[0168] Specifically, any national cryptography encryption algorithm can be used to encrypt the second data packet to obtain an encrypted data packet. National cryptography encryption algorithms such as SM1 encryption algorithm, SM4 encryption algorithm, etc. In one example, the SM4 encryption algorithm is used to encrypt the second data packet.
[0169] Integrity protection is also required for the second data packet. The specific process is as follows: Calculate the hash value of the second data packet, and the calculated hash value can be used as the first signature of the second data packet. The first signature is used for integrity verification in the data receiving device 200 (which will be described in detail later).
[0170] After that, package the encrypted data packet and the first signature according to a custom private protocol to obtain a third data packet. The custom private protocol root can be set according to actual application requirements. Compared with using a public protocol, it can ensure the security and reliability of communication.
[0171] The following details the data processing and transmission process of the data receiving device 200.
[0172] Please refer to Figure 2 、 Figure 11 and Figure 12 , an embodiment of the present invention also provides a data transmission method, which is applied to the data receiving device 200 of the reverse isolation device 300. The reverse isolation device 300 further includes a data sending device 100, and the data receiving device 200 is respectively communicatively connected to the data sending device 100 and the application service device. The data transmission method includes:
[0173] S201: Receive the third data packet sent by the data sending device 100. The third data packet comes from the data sending device 100: Obtain the first data packet; Determine the corresponding compression strategy according to the size of the first data packet; Compress the first data packet according to the compression strategy to obtain the second data packet; Encrypt and sign the second data packet to obtain the third data packet;
[0174] S202: Verify the signature and decrypt the third data packet to obtain the fourth data packet;
[0175] S203: Decompress the fourth data packet according to the compression strategy to obtain the fifth data packet;
[0176] S204: Send the fifth data packet to the application service device.
[0177] In the data transmission method according to the embodiment of the present invention, the first data packet is compressed and then encrypted and signed to obtain the third data packet, and the compression strategy is determined according to the size of the first data packet. In this way, the transmission rate of the data packet is improved. While reducing the impact of the encryption operation on the data transmission performance, the compression time of the first data packets of different sizes is controlled within a reasonable range, preventing the data transmission performance of the reverse isolation device 300 from being affected due to too long compression time.
[0178] Specifically, after the data sending device 100 obtains the third data packet, it sends the third data packet to the data receiving device 200. The data receiving device 200 receives the third data packet, verifies the signature and decrypts the third data packet to obtain the fourth data packet. Then, according to the compression strategy determined in the data sending device 100, the fourth data packet is decompressed to obtain the fifth data packet. The fifth data packet can be sent by the data receiving device 200 to the application service device for further processing and analysis.
[0179] Please refer to Figure 12 and Figure 13 , in some embodiments, verifying the signature and decrypting the third data packet to obtain the fourth data packet (i.e., S202) includes:
[0180] S2021: Parse the third data packet according to the custom private protocol to obtain the parsed data packet and the first signature;
[0181] S2022: Decrypt the parsed data packet to obtain the decrypted data packet;
[0182] S2023: Calculate the hash value of the decrypted data packet to determine the second signature of the decrypted data packet;
[0183] S2024: Determine whether the first signature is the same as the second signature;
[0184] S2025: When the first signature is the same as the second signature, determine that the decrypted data packet passes the verification, and use the decrypted data packet as the fourth data packet.
[0185] Specifically, after receiving the third data packet, parse the third data packet according to the corresponding custom private protocol in the data sending device 100 to obtain the parsed data packet and the first signature. Then, use the decryption algorithm corresponding to the encryption algorithm in the data sending device 100 to decrypt the parsed data packet to obtain the decrypted data packet.
[0186] During data transmission, data packets may be damaged or tampered with for various reasons, such as hardware failures, software vulnerabilities, etc. Therefore, the data receiving device 200 can perform an integrity check on the decrypted data packets. The check process is as follows: Calculate the hash value of the decrypted data packet, and the calculated hash value can be used as the second signature of the decrypted data packet.
[0187] It can be understood that if the data packet is not damaged or tampered with, the data in the decrypted data packet should be the same as the data in the second data packet in the foregoing embodiment. Since the second signature is calculated based on the decrypted data packet and the first signature is calculated based on the second data packet, the second signature should be consistent with the first signature.
[0188] Compare the first signature and the second signature. If the first signature is the same as the second signature, it indicates that the data packet is not damaged or tampered with during transmission, and the integrity check is qualified. The decrypted data packet with qualified check is used as the fourth data packet. If the first signature is different from the second signature, it indicates that the data packet is damaged or tampered with during transmission, and the integrity check is unqualified. At this time, a problem alarm can be issued.
[0189] In this way, the accuracy and credibility of the data packet content are ensured, the adverse impact of tampered data on the power system 400 is avoided, and problems such as hardware failures and software vulnerabilities in the power system 400 can be detected in a timely manner.
[0190] Please refer to Figure 12 and Figure 14 , in some embodiments, the compression policy includes compression control parameters. Decompress the fourth data packet according to the compression policy to obtain a fifth data packet (i.e., S203), including:
[0191] S2031: Determine whether it is necessary to decompress the fourth data packet;
[0192] S2032: When it is necessary to decompress the fourth data packet, decompress the fourth data packet according to the compression control parameters to obtain a fifth data packet;
[0193] At this time, the data transmission method further includes:
[0194] S205: When it is not necessary to decompress the fourth data packet, use the fourth data packet as the fifth data packet.
[0195] It can be understood that the third data packet may be obtained by compressing, encrypting, and signing, or may be directly encrypted and signed. Therefore, after verifying, decrypting the third data packet to obtain the fourth data packet, it is necessary to determine whether to decompress the fourth data packet.
[0196] For example, when the data sending device 100 compresses the first data packet, a compression flag bit can be added to the second data packet obtained by compression, so that in the data receiving device 200, the fourth data packet can be checked for the compression flag bit. When the compression flag bit is detected, it is determined that the fourth data packet needs to be decompressed, and when the compression flag bit is not detected, it is determined that the fourth data packet does not need to be decompressed.
[0197] When the fourth data packet needs to be decompressed, according to the compression strategy determined in the data sending device 100, the fourth data packet is decompressed using the preset compression algorithm corresponding to the one determined in the data sending device 100 to obtain the fifth data packet. When the fourth data packet does not need to be decompressed, the fourth data packet is directly used as the fifth data packet.
[0198] The following describes in detail the optimization effect of the transmission performance of data transmission using the data transmission method according to the embodiments of the present invention in combination with Tables 1 to 4.
[0199] For comparison, the transmission performance indicators of the forward isolation device can be tested. Multiple transmissions are performed on the forward isolation device using 8 data packets of different sizes, and the transmission rate is recorded in gigabits per second (Gbps). The test results are shown in Table 1:
[0200] Table 1: Test results of the transmission performance indicators of the forward isolation device
[0201]
[0202] The transmission performance of the reverse isolation device in the related art is tested. Multiple transmissions are performed on the reverse isolation device using 8 data packets of different sizes, and the transmission rate is recorded. The test results are shown in Table 2:
[0203] Table 2: Test results of the transmission performance indicators of the reverse isolation device in the related art
[0204]
[0205] The transmission performance of the reverse isolation device 300 using the data transmission method according to the embodiments of the present invention is tested. Multiple transmissions are performed on the reverse isolation device 300 using 8 data packets of different sizes, and the transmission rate is recorded. The test results are shown in Table 3:
[0206] Table 3: Test results of the performance indicators of the reverse isolation device 300 in the embodiments of the present invention
[0207]
[0208] Comparing Table 1 and Table 3 with Table 2 respectively, Table 4 can be obtained as follows:
[0209] Table 4: Comparison of Transmission Performance
[0210]
[0211] For a more intuitive comparison, a curve graph can be drawn based on Tables 1 to 3, as Figures 15 to 21 shown, where the legend "Forward" corresponds to the forward isolation device, the legend "Reverse" corresponds to the reverse isolation device in the related art, and the legend "Reverse Optimization" corresponds to the reverse isolation device 300 of the embodiment of the present invention.
[0212] Combining Tables 1 to 4, and Figures 15 to 21 it can be seen that for the reverse isolation device 300 using the data transmission method of the embodiment of the present invention, when transmitting data packets of different sizes, the transmission performance is on average improved by 74%, and the larger the size of the transmitted data packet, the higher the improvement in transmission performance.
[0213] Please refer to Figure 2 and Figure 22 The embodiment of the present invention further provides a data sending device 100, which is applied to the reverse isolation device 300. The reverse isolation device 300 further includes a data receiving device 200. The data sending device 100 is communicatively connected to the data receiving device 200, and the data receiving device 200 is connected to the application service device. The data sending device 100 includes an acquisition module 10, a determination module 20, a compression module 30, an encryption and signature module 40, and a first sending module 50. The acquisition module 10 is configured to acquire a first data packet. The determination module 20 is configured to determine a corresponding compression strategy according to the size of the first data packet. The compression module 30 is configured to compress the first data packet according to the compression strategy to obtain a second data packet. The encryption and signature module 40 is configured to encrypt and sign the second data packet to obtain a third data packet. The first sending module 50 is configured to send the third data packet to the data receiving device 200, so that the data receiving device 200: verifies the signature and decrypts the third data packet to obtain a fourth data packet; decompresses the fourth data packet according to the compression strategy to obtain a fifth data packet; and sends the fifth data packet to the application service device.
[0214] Please refer to Figure 23 In some embodiments, the data sending device 100 further includes a test module 60. Before determining the corresponding compression strategy according to the size of the first data packet, the test module 60 is configured to determine whether the size of the first data packet is greater than or equal to a data packet size threshold; when the size of the first data packet is greater than or equal to the data packet size threshold, it is determined that the first data packet needs to be compressed; when the size of the first data packet is less than the data packet size threshold, it is determined that the first data packet does not need to be compressed.
[0215] In some embodiments, before determining whether the size of the first data packet is greater than or equal to the data packet size threshold, the test module 60 is specifically configured to perform encryption signature and signature verification decryption on multiple test data packets with different sizes, and record the first encryption signature time and the first signature verification decryption time; perform compression, encryption signature, signature verification decryption, and decompression on multiple test data packets with different sizes, and record the first compression time, the second encryption signature time, the second signature verification decryption time, and the first decompression time; determine the data packet size threshold according to the first encryption signature time, the first signature verification decryption time, the first compression time, the second encryption signature time, the second signature verification decryption time, and the first decompression time corresponding to each test data packet.
[0216] In some embodiments, the test module 60 is specifically configured to determine whether the first encryption signature time, the first signature verification decryption time, the first compression time, the second encryption signature time, the second signature verification decryption time, and the first decompression time corresponding to each test data packet meet a predetermined evaluation index; determine the data packet size threshold according to the sizes of the test data packets that meet the predetermined evaluation index. Wherein, the predetermined evaluation index includes: the difference between the first compression time and the encryption signature time difference is less than the first preset threshold, and the encryption signature time difference is the difference between the first encryption signature time and the second encryption signature time; the difference between the first decompression time and the signature verification decryption time difference is less than the second preset threshold, and the signature verification decryption time difference is the difference between the first signature verification decryption time and the second signature verification decryption time.
[0217] In some embodiments, the compression policy includes compression control parameters. The determination module 20 is specifically configured to determine the corresponding compression control parameters according to the size of the first data packet when the first data packet needs to be compressed, wherein the compression control parameters are positively correlated with the size of the first data packet. At this time, the compression module 30 is specifically configured to compress the first data packet according to the compression control parameters to obtain a second data packet. At this time, the compression module 30 is further configured to use the first data packet as the second data packet when the first data packet does not need to be compressed.
[0218] In some embodiments, before compressing the first data packet according to the compression control parameters to obtain a second data packet, the test module 60 is further configured to obtain multiple candidate compression algorithms; perform compression performance tests on the multiple candidate compression algorithms to determine a preset compression algorithm. At this time, the compression module 30 is specifically configured to compress the first data packet according to the compression control parameters using the preset compression algorithm to obtain a second data packet.
[0219] In some embodiments, the encryption signature module 40 is specifically configured to encrypt the second data packet to obtain an encrypted data packet; calculate the hash value of the second data packet to determine the first signature of the second data packet; encapsulate the encrypted data packet and the first signature according to a custom private protocol to obtain a third data packet.
[0220] It should be noted that the explanations of the data transmission method in the foregoing embodiments are equally applicable to the data sending device 100 in the embodiments of the present invention, and will not be elaborated herein.
[0221] Please refer to Figure 2 and Figure 24 , the embodiments of the present invention further provide a data receiving device 200, which is applied to a reverse isolation device 300. The reverse isolation device 300 further includes a data sending device 100, and the data receiving device 200 is respectively communicatively connected to the data sending device 100 and an application service device. The data receiving device 200 includes a receiving module 210, a decompression module 230, a signature verification and decryption module 220, and a second sending module 240. The receiving module 210 is configured to receive a third data packet sent by the data sending device 100. The third data packet is from the data sending device 100: obtain a first data packet; determine a corresponding compression policy according to the size of the first data packet; compress the first data packet according to the compression policy to obtain a second data packet; encrypt and sign the second data packet to obtain a third data packet. The signature verification and decryption module 220 is configured to perform signature verification and decryption on the third data packet to obtain a fourth data packet. The decompression module 230 is configured to decompress the fourth data packet according to the compression policy to obtain a fifth data packet. The second sending module 240 is configured to send the fifth data packet to the application service device.
[0222] In some embodiments, the signature verification and decryption module 220 is specifically configured to parse the third data packet according to a custom private protocol to obtain a parsed data packet; perform signature verification and decryption on the parsed data packet to obtain a fourth data packet.
[0223] In some embodiments, the compression policy includes compression control parameters. The decompression module 230 is specifically configured to determine whether the fourth data packet needs to be decompressed; when the fourth data packet needs to be decompressed, decompress the fourth data packet according to the compression control parameters to obtain a fifth data packet; the decompression module 230 is further configured to use the fourth data packet as the fifth data packet when the fourth data packet does not need to be decompressed.
[0224] In some embodiments, during the process of parsing the third data packet according to the custom private protocol, the second sending module 240 is further configured to obtain a first signature obtained by parsing. At this time, the second sending module 240 is specifically configured to calculate a hash value of the fifth data packet to determine a second signature of the fifth data packet; determine whether the first signature is the same as the second signature; when the first signature is the same as the second signature, determine that the fifth data packet passes the verification; send the fifth data packet that passes the verification to the application service device.
[0225] It should be noted that the explanations of the data transmission method in the foregoing embodiments are equally applicable to the data receiving device 200 of the embodiments of the present invention, and will not be elaborated herein.
[0226] Please refer to Figure 2 and Figure 25 , an embodiment of the present invention further provides a reverse isolation device 300. The reverse isolation device 300 includes one or more processors 310 and a memory 320. When the computer program stored in the memory 320 is executed by the processor 310, the data transmission method of any of the foregoing embodiments is implemented.
[0227] For example, when the computer program is executed by the processor 310, the following data transmission method is implemented:
[0228] S101: Obtain a first data packet;
[0229] S102: Determine a corresponding compression strategy according to the size of the first data packet;
[0230] S103: Compress the first data packet according to the compression strategy to obtain a second data packet;
[0231] S104: Perform encryption and signature on the second data packet to obtain a third data packet;
[0232] S105: Send the third data packet to the data receiving device 200 so that the data receiving device 200: perform signature verification and decryption on the third data packet to obtain a fourth data packet; decompress the fourth data packet according to the compression strategy to obtain a fifth data packet; send the fifth data packet to the application service device.
[0233] Again, for example, when the computer program is executed by the processor 310, the following data transmission method is implemented:
[0234] S201: Receive the third data packet sent by the data sending device 100. The third data packet is from the data sending device 100: obtain a first data packet; determine a corresponding compression strategy according to the size of the first data packet; compress the first data packet according to the compression strategy to obtain a second data packet; perform encryption and signature on the second data packet to obtain a third data packet;
[0235] S202: Perform signature verification and decryption on the third data packet to obtain a fourth data packet;
[0236] S203: Decompress the fourth data packet according to the compression strategy to obtain a fifth data packet;
[0237] S204: Send the fifth data packet to the application service device.
[0238] It should be noted that the explanations of the data transmission method in the foregoing embodiments are equally applicable to the reverse isolation device 300 of the embodiments of the present invention, and will not be elaborated herein.
[0239] Please refer to Figure 4 , an embodiment of the present invention further provides a power system 400. The power system 400 includes the reverse isolation device 300 of any of the foregoing embodiments.
[0240] It should be noted that the explanations of the data transmission method in the foregoing embodiments are equally applicable to the power system 400 of the embodiments of the present invention, and will not be elaborated herein.
[0241] Please refer to Figure 26 , an embodiment of the present invention further provides a computer-readable storage medium 500, on which a computer program 510 is stored. When the program is executed by a processor 520, the data transmission method of any of the foregoing embodiments is implemented.
[0242] For example, when the computer program 510 is executed by the processor 520, the following data transmission method is implemented:
[0243] S101: Obtain a first data packet;
[0244] S102: Determine a corresponding compression strategy according to the size of the first data packet;
[0245] S103: Compress the first data packet according to the compression strategy to obtain a second data packet;
[0246] S104: Perform encryption and signature on the second data packet to obtain a third data packet;
[0247] S105: Send the third data packet to the data receiving device 200, so that the data receiving device 200: perform signature verification and decryption on the third data packet to obtain a fourth data packet; decompress the fourth data packet according to the compression strategy to obtain a fifth data packet; send the fifth data packet to the application service device.
[0248] For another example, when the computer program 510 is executed by the processor 520, the following data transmission method is implemented:
[0249] S201: Receive the third data packet sent by the data sending device 100. The third data packet is from the data sending device 100: obtain a first data packet; determine a corresponding compression strategy according to the size of the first data packet; compress the first data packet according to the compression strategy to obtain a second data packet; perform encryption and signature on the second data packet to obtain a third data packet;
[0250] S202: Perform signature verification and decryption on the third data packet to obtain a fourth data packet;
[0251] S203: Decompress the fourth data packet according to the compression strategy to obtain a fifth data packet;
[0252] S204: Send the fifth data packet to the application service device.
[0253] It should be noted that the explanations of the data transmission method in the foregoing embodiments are equally applicable to the computer-readable storage medium 500 of the embodiments of the present invention, and will not be elaborated here.
[0254] In summary, in the data transmission method, data sending device 100, data receiving device 200, reverse isolation device 300, power system 400, and computer-readable storage medium 500 of the embodiments of the present invention, the first data packet is compressed and then encrypted and signed to obtain a third data packet, and the compression strategy is determined according to the size of the first data packet. In this way, the transmission rate of the data packet is improved, while reducing the impact of the encryption operation on the data transmission performance, and the compression time of the first data packets of different sizes is controlled within a reasonable range, preventing the data transmission performance of the reverse isolation device 300 from being affected due to too long compression time.
[0255] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without conflict, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0256] Any process or method description shown in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or more executable instructions for implementing a specific logical function or process, and the scope of the preferred embodiments of the present invention includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in a reverse order according to the involved functions, rather than in the order shown or discussed, which should be understood by those skilled in the art of the embodiments of the present invention.
[0257] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definitional sequence list of executable instructions for implementing logical functions, and can be embodied specifically in any computer-readable storage medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in connection with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a computer-readable storage medium can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of the computer-readable storage medium include the following: an electrical connection part with one or more wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable storage medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or otherwise processing it as appropriate, and then storing it in a computer memory.
[0258] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.
[0259] Those of ordinary skill in the art can understand that all or part of the steps carried out in the methods of the above embodiments can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments. In addition, in each of the embodiments of the present invention, the functional units can be integrated in a processing module, or each unit can exist physically alone, or two or more units can be integrated in a module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. When the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. The storage media mentioned above can be read-only memory, magnetic disk or optical disk, etc.
[0260] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention. The scope of the present invention is defined by the claims and their equivalents.
Claims
1. A data transmission method, characterized in that: A data sending device applied to a reverse isolation device, the reverse isolation device further comprising a data receiving device, the data sending device being communicatively connected to the data receiving device, the data receiving device being connected to an application service device, the data transmission method comprising: Get a first data packet; Determining a corresponding compression strategy according to the size of the first data packet; Compressing the first data packet according to the compression strategy to obtain a second data packet; Performing encryption and signing on the second data packet to obtain a third data packet; Sending the third data packet to the data receiving device, so that the data receiving device: verifies and decrypts the third data packet to obtain a fourth data packet; decompresses the fourth data packet according to the compression strategy to obtain a fifth data packet; and sends the fifth data packet to the application service device; Before determining the corresponding compression strategy according to the size of the first data packet, the data transmission method further includes: Determining whether the size of the first data packet is greater than or equal to a data packet size threshold; When the size of the first data packet is greater than or equal to the data packet size threshold, determining that the first data packet needs to be compressed; When the size of the first data packet is smaller than the data packet size threshold, determining that the first data packet does not need to be compressed; Before determining whether the size of the first data packet is greater than or equal to the data packet size threshold, the data transmission method further includes: Perform encryption signing and signature verification and decryption on multiple test data packets of different sizes, and record the first encryption signing time and the first signature verification and decryption time; Compress, encrypt, sign, verify, decrypt and decompress the test data packets of multiple different sizes, and record the first compression time, the second encryption signing time, the second verification and decryption time and the first decompression time; Determine a data packet size threshold according to the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time, and the first decompression time corresponding to each of the test data packets; Determining the data packet size threshold according to the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time, and the first decompression time corresponding to each of the test data packets includes: Determine whether the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time, and the first decompression time corresponding to each of the test data packets meet predetermined evaluation indicators; Determining the data packet size threshold according to the size of the test data packet that meets the predetermined evaluation index; The predetermined evaluation indicators include: The difference between the first compression time and the encryption signature time difference is less than a first preset threshold, and the encryption signature time difference is the difference between the first encryption signature time and the second encryption signature time; The difference between the first decompression time and the signature verification and decryption time difference is less than a second preset threshold, and the signature verification and decryption time difference is the difference between the first signature verification and decryption time and the second signature verification and decryption time.
2. The data transmission method according to claim 1, characterized in that: The compression strategy includes a compression control parameter, and the determining the corresponding compression strategy according to the size of the first data packet includes: When the first data packet needs to be compressed, determining the corresponding compression control parameter according to the size of the first data packet, wherein the compression control parameter is positively correlated with the size of the first data packet; The compressing the first data packet according to the compression strategy to obtain a second data packet includes: compressing the first data packet according to the compression control parameter to obtain the second data packet; The data transmission method further comprises: When there is no need to compress the first data packet, the first data packet is used as the second data packet.
3. The data transmission method according to claim 2, characterized in that: Before compressing the first data packet according to the compression control parameter to obtain the second data packet, the data transmission method further includes: Obtain multiple candidate compression algorithms; Performing compression performance tests on the multiple candidate compression algorithms to determine a preset compression algorithm; The compressing the first data packet according to the compression control parameter to obtain the second data packet includes: The first data packet is compressed using the preset compression algorithm according to the compression control parameters to obtain the second data packet.
4. The data transmission method according to claim 1, characterized in that: The step of encrypting and signing the second data packet to obtain a third data packet includes: encrypting the second data packet to obtain an encrypted data packet; Performing hash value calculation on the second data packet to determine a first signature of the second data packet; The encrypted data packet and the first signature are encapsulated according to a custom private protocol to obtain the third data packet.
5. A data transmission method, characterized in that: A data receiving device applied to a reverse isolation device, wherein the reverse isolation device further comprises a data sending device, wherein the data receiving device is respectively connected to the data sending device and the application service device for communication, and the data transmission method comprises: Receive a third data packet sent by the data sending device, the third data packet originating from the data sending device: obtain a first data packet; determine a corresponding compression strategy according to the size of the first data packet; compress the first data packet according to the compression strategy to obtain a second data packet; encrypt and sign the second data packet to obtain the third data packet; before determining the corresponding compression strategy according to the size of the first data packet, determine whether the size of the first data packet is greater than or equal to the data packet size threshold; when the size of the first data packet is greater than or equal to the data packet size threshold, determine that the first data packet needs to be compressed; when the size of the first data packet is less than the data packet size threshold, determine that the first data packet does not need to be compressed; before determining whether the size of the first data packet is greater than or equal to the data packet size threshold, encrypt and sign and verify and decrypt multiple test data packets of different sizes, and record the first encryption signature time and the first verification and decryption time; compress, encrypt and sign, verify and decrypt and decompress the multiple test data packets of different sizes, and record the first compression time, the second encryption signature time, the second verification and decryption time and the first decompression time; according to the corresponding compression strategy of each test data packet The method comprises: determining the data packet size threshold according to the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time and the first decompression time corresponding to each of the test data packets, including: judging whether the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time and the first decompression time corresponding to each of the test data packets meet the predetermined evaluation index; determining the data packet size threshold according to the size of the test data packet that meets the predetermined evaluation index; wherein the predetermined evaluation index includes: the difference between the first compression time and the encryption signing time difference is less than a first preset threshold, and the encryption signing time difference is the difference between the first encryption signing time and the second encryption signing time; the difference between the first decompression time and the signature verification and decryption time difference is less than a second preset threshold, and the signature verification and decryption time difference is the difference between the first signature verification and decryption time; Performing signature verification and decryption on the third data packet to obtain a fourth data packet; decompressing the fourth data packet according to the compression strategy to obtain a fifth data packet; The fifth data packet is sent to the application service device.
6. The data transmission method according to claim 5, characterized in that: The performing signature verification and decryption on the third data packet to obtain a fourth data packet includes: Parsing the third data packet according to a custom private protocol to obtain a parsed data packet and a first signature; Decrypting the parsed data packet to obtain a decrypted data packet; Performing hash value calculation on the decrypted data packet to determine a second signature of the decrypted data packet; Determining whether the first signature is identical to the second signature; When the first signature is identical to the second signature, the decrypted data packet is determined to be qualified, and the decrypted data packet is used as the fourth data packet.
7. The data transmission method according to claim 5, characterized in that: The compression strategy includes a compression control parameter, and the decompressing the fourth data packet according to the compression strategy to obtain a fifth data packet includes: Determining whether the fourth data packet needs to be decompressed; When the fourth data packet needs to be decompressed, decompress the fourth data packet according to the compression control parameter to obtain the fifth data packet; The data transmission method further comprises: When the fourth data packet does not need to be decompressed, the fourth data packet is used as the fifth data packet.
8. A data transmission device, characterized in that: Applied to a reverse isolation device, the reverse isolation device further includes a data receiving device, the data sending device is communicatively connected to the data receiving device, the data receiving device is connected to an application service device, and the data sending device includes: An acquisition module, used for acquiring a first data packet; A determination module, configured to determine a corresponding compression strategy according to the size of the first data packet; A compression module, configured to compress the first data packet according to the compression strategy to obtain a second data packet; An encryption signature module, used for performing encryption signature on the second data packet to obtain a third data packet; The first sending module is used to send the third data packet to the data receiving device, so that the data receiving device: verifies the signature and decrypts the third data packet to obtain a fourth data packet; decompresses the fourth data packet according to the compression strategy to obtain a fifth data packet; and sends the fifth data packet to the application service device. The data sending device further includes a testing module, which is used to: Determining whether the size of the first data packet is greater than or equal to a data packet size threshold; When the size of the first data packet is greater than or equal to the data packet size threshold, determining that the first data packet needs to be compressed; When the size of the first data packet is smaller than the data packet size threshold, determining that the first data packet does not need to be compressed; Before determining whether the size of the first data packet is greater than or equal to the data packet size threshold, the testing module is specifically configured to: Perform encryption signing and signature verification and decryption on multiple test data packets of different sizes, and record the first encryption signing time and the first signature verification and decryption time; Compress, encrypt, sign, verify, decrypt and decompress the test data packets of multiple different sizes, and record the first compression time, the second encryption signing time, the second verification and decryption time and the first decompression time; Determine a data packet size threshold according to the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time, and the first decompression time corresponding to each of the test data packets; The test module is specifically used for: Determine whether the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time, and the first decompression time corresponding to each of the test data packets meet predetermined evaluation indicators; Determining the data packet size threshold according to the size of the test data packet that meets the predetermined evaluation index; The predetermined evaluation indicators include: The difference between the first compression time and the encryption signature time difference is less than a first preset threshold, and the encryption signature time difference is the difference between the first encryption signature time and the second encryption signature time; The difference between the first decompression time and the signature verification and decryption time difference is less than a second preset threshold, and the signature verification and decryption time difference is the difference between the first signature verification and decryption time and the second signature verification and decryption time.
9. A data receiving device, characterized in that: Applied to a reverse isolation device, the reverse isolation device further includes a data sending device, the data receiving device is respectively connected to the data sending device and the application service device for communication, and the data receiving device includes: A receiving module, used to receive a third data packet sent by the data sending device, the third data packet originating from the data sending device: obtaining a first data packet; determining a corresponding compression strategy according to the size of the first data packet; compressing the first data packet according to the compression strategy to obtain a second data packet; encrypting and signing the second data packet to obtain a third data packet; before determining the corresponding compression strategy according to the size of the first data packet, determining whether the size of the first data packet is greater than or equal to the data packet size threshold; when the size of the first data packet is greater than or equal to the data packet size threshold, determining that the first data packet needs to be compressed; when the size of the first data packet is less than the data packet size threshold, determining that the first data packet does not need to be compressed; before determining whether the size of the first data packet is greater than or equal to the data packet size threshold, encrypting and signing and verifying and decrypting a plurality of test data packets of different sizes, and recording a first encryption signing time and a first verification and decryption time; compressing, encrypting and signing, verifying and decrypting, and decompressing a plurality of test data packets of different sizes, and recording a first compression time, a second encryption signing time, a second verification and decryption time, and a first decompression time; according to each of the test data packets, The method comprises: determining the data packet size threshold according to the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time and the first decompression time corresponding to each of the test data packets; determining the data packet size threshold according to the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time and the first decompression time corresponding to each of the test data packets, including: judging whether the first encryption signing time, the first signature verification and decryption time, the first compression time, the second encryption signing time, the second signature verification and decryption time and the first decompression time corresponding to each of the test data packets meet the predetermined evaluation index; determining the data packet size threshold according to the size of the test data packet that meets the predetermined evaluation index; wherein the predetermined evaluation index includes: the difference between the first compression time and the encryption signing time difference is less than a first preset threshold, and the encryption signing time difference is the difference between the first encryption signing time and the second encryption signing time; the difference between the first decompression time and the signature verification and decryption time difference is less than a second preset threshold, and the signature verification and decryption time difference is the difference between the first signature verification and decryption time and the second signature verification and decryption time; a signature verification and decryption module, configured to perform signature verification and decryption on the third data packet to obtain a fourth data packet; a decompression module, configured to decompress the fourth data packet according to the compression strategy to obtain a fifth data packet; The second sending module is used to send the fifth data packet to the application service device.
10. A reverse isolation device, characterized in that: The reverse isolation device includes one or more processors and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the data transmission method according to any one of claims 1 to 4 or the data transmission method according to any one of claims 5 to 7 is implemented.
11. A power system, characterized in that: Includes the reverse isolation device as claimed in claim 10.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the data transmission method described in any one of claims 1 to 4 or the data transmission method described in any one of claims 5 to 7 is implemented.
Citation Information
Patent Citations
Data transmission method and device based on database storage system, equipment and medium
CN116185657A
Cross-domain security document transmission method based on combined public key system
CN116318723A