Computer network security data transmission method and device
Through dynamic encryption algorithm switching, path optimization, sharded metadata index table and federated learning technology, the problem of difficult real-time and complete data transmission in the existing technology of computer network security data transmission is solved, and efficient and secure data transmission in dynamic threat environments is achieved.
Patent Information
- Application Number
- CN202510317956.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2045-03-18
AI Technical Summary
The prior art is difficult to achieve real-time and complete data transmission in computer network secure data transmission, especially when facing dynamic threat environments and high real-time requirements, traditional security transmission mechanisms have significant limitations in encryption policy flexibility, multi-path collaborative optimization and data integrity guarantee.
By obtaining real-time threat intelligence data and transmission performance parameters, dynamically switch the encryption algorithm and shard encryption processing data; optimize the transmission path using the path performance evaluation model and decision tree algorithm; build a shard metadata index table for shard arrival time analysis, and verify data integrity through a hash matching mechanism; use federated learning technology to perform global link quality analysis, and dynamically adjust the encryption algorithm switching frequency, transmission path selection strategy and virtual node configuration parameters.
It realizes real-time response to threat intelligence changes in dynamic threat environments, ensures the security and integrity of data transmission, improves transmission efficiency, and reduces the risk of data loss caused by network fluctuations or attacks.
Smart Images

Figure CN119922011A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of computer network security and data transmission, and in particular to a computer network security data transmission method and device. Background Art
[0002] At present, computer network security data transmission faces the dual challenges of dynamic threat environment and high real-time requirements. Especially when dealing with constantly changing network attack methods, traditional secure transmission mechanisms have significant limitations in encryption strategy flexibility, multi-path collaborative optimization and data integrity assurance. It is difficult to achieve a dynamic balance between security protection and transmission efficiency in a complex network environment.
[0003] In one existing technology, computer network security data transmission mainly adopts fixed encryption algorithms and static path selection strategies. A single encryption algorithm based on a predefined security level is bound to a specific transmission path, resulting in the inability to adapt to encryption switching response delays and path performance fluctuations. At the same time, there is a lack of dynamic control mechanisms for fragment arrival order and integrity verification during fragment transmission, which often leads to fragment loss or out-of-order reorganization failure due to network path differences. In addition, the generation and update of false network topology relies on periodic manual configuration, which makes it difficult to respond to real-time attack feature changes in a timely manner, resulting in defense lags. However, the existing technology is difficult to achieve real-time and complete computer network security data transmission due to rigid encryption switching, lack of coordination between path selection and fragment transmission, and insufficient data reorganization verification mechanism.
[0004] In summary, the existing technology has the problem that it is difficult to achieve real-time and complete computer network secure data transmission. Summary of the invention
[0005] The present invention provides a computer network secure data transmission method and device to achieve real-time and complete computer network secure data transmission.
[0006] In a first aspect, in order to solve the above technical problems, the present invention provides a computer network secure data transmission method, comprising: Acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, perform dynamic encryption algorithm switching based on the real-time threat intelligence data, perform fragment encryption processing on the data to be transmitted, and obtain encrypted fragment data; Inputting the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; According to the path performance score and in combination with a preset screening threshold, a decision tree algorithm is used to prioritize paths that meet the threshold condition to obtain a transmission path set; According to the encrypted shard data and the transmission path set, a shard metadata index table is constructed and a shard arrival time sequence analysis is performed, and a buffer queue is established to match and obtain a sequence correspondence between the received shards and the original shards; Perform integrity check on the fragment identifiers of the sequence correspondence through a hash matching mechanism to generate complete transmission data; Extract and analyze attack features from the real-time threat intelligence data and the real-time transmission performance parameters, perform anti-attack optimization, and obtain virtual node layout and link connection strategies; According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter, a global link quality analysis is performed using a federated learning technique to obtain a transmission link quality score; According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters are dynamically adjusted to obtain real-time transmission data.
[0007] In an optional implementation, the acquiring of real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters, and data to be transmitted, dynamically switching encryption algorithms based on the real-time threat intelligence data, and performing fragment encryption processing on the data to be transmitted to obtain encrypted fragment data includes: Obtain real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters of multiple network paths, and data to be transmitted; The real-time transmission performance parameters include real-time transmission speed, real-time traffic characteristics and transmission stability data of multiple network paths; Based on the real-time threat intelligence data, dynamic trend prediction is predicted by time series analysis, the magnitude of threat level change is calculated and security level intervals are divided to obtain dynamic security level assessment parameters; According to the dynamic security level assessment parameters, in combination with a preset encryption algorithm library, dynamic matching of encryption algorithm types is performed to obtain an encryption algorithm dynamic selection model; According to the dynamic selection model of the encryption algorithm and the dynamic security level assessment parameters, an adaptive sharding strategy is adopted to shard the data to be transmitted, and the shard size is adjusted based on the preset data sensitivity to obtain initial shard data; Dynamic encryption processing is performed according to the initial shard data. When it is detected that the dynamic security level assessment parameter is increased, the encryption algorithm switching mechanism is triggered during the shard transmission process, and the encryption compatibility of the previous and next shards is maintained to obtain encrypted shard data.
[0008] In an optional implementation, the preset path performance evaluation model training process includes: Obtain historical real-time transmission performance parameters; Input the historical real-time transmission performance parameters into the linear regression model to obtain the historical path performance score; When the number of training times is greater than or equal to the preset number of training times, the training is determined to be completed, and a path performance evaluation model of the trained path is obtained; In an optional implementation, the path performance score is combined with a preset screening threshold, and a decision tree algorithm is used to prioritize the paths that meet the threshold condition to obtain a transmission path set, including: According to the path performance score and in combination with a preset screening threshold, a decision tree algorithm is used to prioritize the paths that meet the threshold conditions to obtain an initial optimal path set; According to the initial optimal path set, a dynamic programming algorithm is used to allocate the shard transmission tasks in real time, and the arrival time of each shard is detected to obtain the difference in the arrival time of the shards; According to the fragment arrival time difference and the real-time transmission performance parameter, in combination with a path performance evaluation model, the path performance is re-evaluated and priority sorting is performed to obtain a transmission path set.
[0009] In an optional implementation, the step of constructing a shard metadata index table and performing shard arrival time sequence analysis based on the encrypted shard data and the transmission path set, and establishing a buffer queue to match the sequence correspondence between the received shards and the original shards includes: According to the encrypted shard data and the transmission path set, a hash value of the encrypted shard data is calculated using a hash algorithm, and a shard metadata index table is constructed by combining a unique identifier and a shard sequence number in the encrypted shard data; According to the fragment metadata index table, fragment arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence between the received fragments and the original fragments.
[0010] In an optional implementation, the hash matching mechanism performs integrity check on the fragment identifier of the sequence correspondence to generate complete transmission data, including: According to the sequence correspondence, the integrity of the shard identifier is checked in combination with the preset hash verification rules. When a shard is missing or the identifier does not match, the shard is logically reorganized in sequence using a multi-level sorting algorithm based on the shard metadata index table to obtain intermediate reorganized data that conforms to the original shard data structure; According to the intermediate reorganized data, the sequence correspondence and the shard metadata index table, a verification and completion algorithm is used to perform shard boundary verification and overall hash value comparison, detect data integrity and insert intermediate reorganized data for completion to generate complete transmission data.
[0011] In an optional implementation, extracting and analyzing attack features based on the real-time threat intelligence data and the real-time transmission performance parameters, performing anti-attack optimization, and obtaining virtual node layout and link connection strategies include: According to the real-time threat intelligence data and the real-time transmission performance parameters, a three-dimensional attack feature set including attack source, attack type and attack target is obtained through multi-dimensional feature correlation analysis; According to the three-dimensional attack feature set, a dynamic weight allocation algorithm is used to analyze the threat probability distribution of different attack paths in real time to obtain an attack behavior analysis report; According to the attack behavior analysis report and the real-time transmission performance parameters, the mapping relationship between the false node deployment density and the link connection strength is analyzed to obtain a false network topology generation model; According to the false network topology generation model, the attack behavior analysis report and the real-time transmission performance parameters, an analysis is performed based on a preset network topology anonymity evaluation rule to obtain the similarity of traffic characteristics between the false node and the real node; According to the traffic feature similarity, anti-attack optimization is performed in combination with a preset link confusion index to obtain a virtual node layout and link connection strategy.
[0012] In an optional implementation, the global link quality analysis is performed using federated learning technology according to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter to obtain a transmission link quality score, including: According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, differential privacy technology is used to protect data interaction between nodes, and data is divided to each edge node for local model training, so as to obtain a distributed evaluation framework based on federated learning; Establishing a dynamic trust scoring model based on the distributed evaluation framework and the real-time transmission performance parameters, analyzing the historical transmission success rate and the real-time transmission performance parameters, and obtaining an initial dynamic trust score; According to the distributed evaluation framework, a federated aggregation algorithm is used to weight the local model parameters of each edge node, and the node trust score weight coefficient is periodically updated to obtain a global link quality evaluation model that is updated in real time; The initial dynamic trust score and the real-time transmission performance parameter are input into the global link quality assessment model, and a multi-dimensional score calculation is performed to obtain a transmission link quality score.
[0013] In an optional implementation, dynamically adjusting the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data includes: According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, the threat intelligence change rate and network load fluctuation characteristics are analyzed to construct a multi-dimensional optimization space including security level, transmission efficiency and topology anonymity indicators; According to the multi-dimensional optimization space, an evolutionary algorithm is used to perform iterative solution, analyze the balance point between security and transmission efficiency, and obtain the encryption algorithm switching frequency and path selection priority coefficient; According to the link connection strategy, the real-time changes of the false network topology adjustment are analyzed, a dynamic response mechanism for virtual node configuration is established, and the resource allocation strategy is obtained by optimizing the inverse relationship between node deployment density and link connection strength; According to the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, a strategy matching verification is performed to obtain real-time transmission data.
[0014] In a second aspect, the present invention provides a computer network data transmission security device, comprising: A data acquisition module is used to acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, dynamically switch the encryption algorithm based on the real-time threat intelligence data, perform fragment encryption processing on the data to be transmitted, and obtain encrypted fragment data; A path evaluation module, used to input the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; A sorting set module is used to prioritize the paths that meet the threshold conditions using a decision tree algorithm according to the path performance score and a preset screening threshold, so as to obtain a transmission path set; A timing analysis module is used to construct a shard metadata index table and perform shard arrival time sequence analysis based on the encrypted shard data and the transmission path set, and to establish a buffer queue to match the sequence correspondence between the received shards and the original shards; A data reorganization module is used to perform integrity check on the fragment identifiers of the sequence correspondence through a hash matching mechanism to generate complete transmission data; A virtual layout module, used to extract and analyze attack features according to the real-time threat intelligence data and the real-time transmission performance parameters, perform anti-attack optimization, and obtain virtual node layout and link connection strategies; A link analysis module, configured to perform global link quality analysis based on the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter using federated learning technology to obtain a transmission link quality score; The result output module is used to dynamically adjust the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data.
[0015] In a fourth aspect, the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned computer network security data transmission methods.
[0016] Compared with the prior art, the present invention has the following beneficial effects: (1) The present invention responds to threat intelligence changes in real time through a dynamic encryption algorithm switching mechanism, ensuring that encryption policies can be quickly adjusted when security threats are detected. This rapid response capability greatly enhances the security of data transmission, reduces potential data leakage risks, and maintains efficient data protection in a dynamic threat environment.
[0017] (2) The present invention realizes the dynamic optimization selection of the transmission path based on the path performance evaluation model and decision tree algorithm. This mechanism can intelligently select the optimal path for data transmission according to the changes in network status and threat intelligence. This not only improves the efficiency of data transmission, but also reduces the risk of data loss caused by network fluctuations or attacks.
[0018] (3) The present invention uses the shard metadata index table and hash matching mechanism to implement integrity verification and intelligent reorganization of shard data. This method can automatically repair disordered and missing data shards, ensuring the integrity and accuracy of data during transmission. This provides a reliable basis for subsequent data processing and analysis.
[0019] (4) The present invention combines federated learning technology to build a distributed link quality assessment network to accurately perceive the global transmission status. Through the collaborative calculation of edge nodes, the link quality assessment is continuously optimized, so that the system can more accurately monitor and manage the status of the entire network, improving the security and stability of the overall network.
[0020] (5) The present invention uses a false network topology generation model to dynamically deploy virtual nodes to confuse the attack path. This defense mechanism can adjust the node layout and link connection strategy in real time, effectively resisting attacks against the actual network structure. This increases the difficulty for attackers to discover the real network topology, thereby further enhancing network security protection capabilities.
[0021] (6) The present invention coordinates encryption strength, path priority and node configuration parameters through an adaptive parameter adjustment mechanism in a multi-dimensional optimization space. The evolutionary algorithm is used to dynamically balance security level and transmission efficiency, so that the encryption strength of the fragments is dynamically adapted to the threat level, the transmission path allocation is matched with the network load status in real time, and the virtual node deployment density is adjusted synchronously with the change of attack characteristics. This method ensures that data can be transmitted safely and efficiently even in a complex and changeable network environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 It is a flowchart of a computer network secure data transmission method provided by the first embodiment of the present invention; Figure 2 It is a schematic diagram of the structure of a computer network secure data transmission device provided by the second embodiment of the present invention. DETAILED DESCRIPTION
[0023] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0024] Reference Figure 1 The first embodiment of the present invention provides a computer network secure data transmission method, comprising the following steps: S11, acquiring real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, dynamically switching encryption algorithms based on the real-time threat intelligence data, performing fragment encryption processing on the data to be transmitted, and obtaining encrypted fragment data; S12, inputting the real-time transmission performance parameter into a preset path performance evaluation model to obtain a path performance score; S13, according to the path performance score, combined with the preset screening threshold, a decision tree algorithm is used to prioritize the paths that meet the threshold conditions to obtain a transmission path set S14, constructing a fragment metadata index table according to the encrypted fragment data and the transmission path set, performing fragment arrival time sequence analysis, and establishing a buffer queue to match and obtain a sequence correspondence between the received fragment and the original fragment; S15, performing integrity check on the fragment identifiers of the sequence correspondence through a hash matching mechanism to generate complete transmission data; S16, extracting and analyzing attack features according to the real-time threat intelligence data and the real-time transmission performance parameters, performing anti-attack optimization, and obtaining a virtual node layout and link connection strategy; S17, performing global link quality analysis using federated learning technology according to the real-time packet loss rate, the end-to-end delay, and the real-time transmission performance parameter to obtain a transmission link quality score; S18, dynamically adjusting the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data.
[0025] In step S11, it is necessary to obtain real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, dynamically switch the encryption algorithm based on the real-time threat intelligence data, and perform fragmented encryption processing on the data to be transmitted to obtain encrypted fragmented data.
[0026] In one implementation, real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters, and data to be transmitted are obtained, dynamic encryption algorithm switching is performed based on the real-time threat intelligence data, and the data to be transmitted is encrypted in slices to obtain encrypted slice data, including: Acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters of multiple network paths and data to be transmitted; the real-time transmission performance parameters include real-time transmission speed of multiple network paths, real-time traffic characteristics and transmission stability data; based on the real-time threat intelligence data, use time series analysis to predict dynamic trends, calculate the amplitude of threat level changes and divide security level intervals to obtain dynamic security level assessment parameters; based on the dynamic security level assessment parameters, combine with a preset encryption algorithm library to dynamically match encryption algorithm types to obtain an encryption algorithm dynamic selection model; based on the encryption algorithm dynamic selection model and the dynamic security level assessment parameters, use an adaptive fragmentation strategy to fragment the data to be transmitted, adjust the fragment size based on the preset data sensitivity, and obtain initial fragmentation data; based on the initial fragmentation data, perform dynamic encryption processing, and when it is detected that the dynamic security level assessment parameters are increased, trigger the encryption algorithm switching mechanism during the fragmentation transmission process, and maintain the encryption compatibility of the previous and next fragments to obtain encrypted fragmentation data.
[0027] It should be noted that the dynamic security level assessment parameters are quantitative security indicators generated by extracting time-series features and predicting trends of real-time threat intelligence data. Specifically, the dynamic security level assessment parameters are obtained by analyzing the time-series change characteristics of network attack frequency, attack type distribution and threat propagation rate, calculating the change gradient of threat intensity in the future period, and mapping the change gradient with the preset security level division rules to obtain a discrete security level value, which is used to dynamically match the encryption algorithm strength level; the encrypted shard data is shard data after the initial shard data is encrypted in real time using an encryption algorithm associated with the dynamic security level assessment parameters. The encrypted shard data acquisition process is as follows: by continuously monitoring changes in security levels, dynamically switching the encryption algorithm type according to changes in threat situations during shard transmission, and embedding the algorithm identifier and version compatibility information in the shard header to ensure that the receiving end can still correctly decrypt historical shards when the shard encryption method changes, so as to obtain the encrypted shard data that takes into account both security and transmission continuity.
[0028] In step S12, the real-time transmission performance parameters need to be input into a preset path performance evaluation model to obtain a path performance score.
[0029] In one implementation, the preset path performance evaluation model training process includes: Obtain historical real-time transmission performance parameters; Input the historical real-time transmission performance parameters into the linear regression model to obtain the historical path performance score; When the number of training times is greater than or equal to the preset number of training times, the training is determined to be completed, and a path performance evaluation model of the trained path is obtained; It should be noted that the path performance evaluation model is a prediction model established by correlating historical real-time transmission performance parameters with historical path performance scores using a linear regression algorithm, and is used to map real-time transmission performance parameters into quantifiable path performance indicators; the path performance score is a comprehensive path performance evaluation value output by the path performance evaluation model, and is obtained by inputting real-time transmission speed, packet loss rate, and stability data into a trained regression model for forward calculation. The path performance score directly reflects the transmission capacity level of the current path, and serves as the core input parameter for the decision tree algorithm to prioritize paths, and is used to guide the dynamic programming algorithm to achieve path allocation optimization for sharded transmission tasks.
[0030] In step S13, it is necessary to prioritize the paths that meet the threshold conditions using a decision tree algorithm based on the path performance score and a preset screening threshold, so as to obtain a transmission path set.
[0031] In one implementation, based on the path performance score and in combination with a preset screening threshold, a decision tree algorithm is used to prioritize paths that meet the threshold condition to obtain a transmission path set, including: According to the path performance score, combined with a preset screening threshold, a decision tree algorithm is used to prioritize the paths that meet the threshold conditions to obtain an initial optimal path set; according to the initial optimal path set, a dynamic programming algorithm is used to allocate slice transmission tasks in real time, detect the arrival time of each slice, and obtain the slice arrival time difference; according to the slice arrival time difference and the real-time transmission performance parameters, combined with a path performance evaluation model, the path performance is re-evaluated and prioritized to obtain a transmission path set.
[0032] It should be noted that the decision tree algorithm is a machine learning method that realizes path priority sorting by performing feature splitting and rule matching on the path performance score. The decision tree algorithm constructs a tree classification structure with transmission delay, bandwidth utilization and packet loss rate as decision nodes according to the real-time scoring data output by the path performance evaluation model, and then divides the path performance level according to the preset screening threshold and generates a priority sorting list; the re-evaluation of path performance and priority sorting is a dynamic path optimization process realized by the feedback mechanism of the fragment arrival time difference. In the process, the path performance score is first dynamically corrected according to the fragment arrival time difference and the real-time transmission performance parameters, and the real-time transmission performance parameters are adjusted, and the updated real-time transmission performance parameters are input into the path The path performance evaluation model recalculates the comprehensive score of the path, and then uses the decision tree algorithm to perform feature splitting and rule matching on the revised score data to generate a new priority sorting list; the transmission path set is an executable path combination formed after the initial sorting result is verified by the dynamic programming algorithm for sharding task allocation. The acquisition process of the transmission path set is as follows: first, the decision tree algorithm is used to screen out candidate paths with scores higher than the threshold from all available paths, and then the dynamic programming algorithm is used to simulate the delay difference and load distribution of the shard transmission task on different paths, and the path weight coefficient is dynamically adjusted according to the difference in shard arrival time, and finally the transmission path set that takes into account transmission efficiency and stability is formed, which is used to guide the multi-path collaborative transmission of encrypted shard data.
[0033] In step S14, it is necessary to construct a shard metadata index table and perform shard arrival time sequence analysis based on the encrypted shard data and the transmission path set, and establish a buffer queue to match the sequence correspondence between the received shards and the original shards.
[0034] In one implementation, according to the encrypted shard data and the transmission path set, a shard metadata index table is constructed and a shard arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence between the received shards and the original shards, including: According to the encrypted shard data and the transmission path set, a hash algorithm is used to calculate the hash value of the encrypted shard data, and a shard metadata index table is constructed in combination with the unique identifier and shard sequence number in the encrypted shard data; according to the shard metadata index table, a shard arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence between the received shards and the original shards.
[0035] It should be noted that the shard metadata index table is a set of encrypted shard data feature identifiers generated by a hash algorithm, which is used to record the logical order, encryption features and transmission path mapping relationship of the shard data. The above shard metadata index table is obtained by extracting the shard unique identifier, shard sequence number and hash value to construct a multidimensional index field; the buffer queue is a temporary storage structure dynamically constructed based on the shard metadata index table, and the shard temporary storage management is realized by recording the shard arrival time sequence and matching the original shard sequence relationship. The acquisition process of the buffer queue is as follows: the shard metadata index table performs actual shard arrival timing analysis, dynamically adjusts the physical storage position of the shard in the queue, and automatically triggers the multi-level sorting algorithm when a shard is detected to be missing or out of order. The logical positions of the shards are rearranged. When it is detected that the shards are complete and in order, the buffer queue is determined according to the physical storage position of the shards in the current queue; the sequence correspondence is a shard position mapping rule formed by dynamically matching the shard arrival time sequence with the shard metadata index table. The process of obtaining the sequence correspondence is as follows: first, the original shard logical sequence template is established according to the sequence number field in the shard metadata index table, and then the physical position offset of the shard in the reorganized sequence is dynamically corrected by analyzing the actual arrival timestamps and path transmission delay characteristics of the shards in the buffer queue, and finally a sequence correspondence that can accurately reflect the original order of the shards and the current transmission status is formed, which is used to guide the multi-level sorting algorithm to realize the intelligent reorganization and integrity verification of disordered shards.
[0036] In step S15, it is necessary to perform integrity check on the fragment identifier of the sequence correspondence through a hash matching mechanism to generate complete transmission data.
[0037] In one implementation, the integrity check of the fragment identifier of the sequence correspondence is performed through a hash matching mechanism to generate complete transmission data, including: According to the sequence correspondence, the integrity of the shard identifier is checked in combination with the preset hash verification rules. When it is detected that a shard is missing or the identifier does not match, the shards are logically reorganized in sequence based on the shard metadata index table using a multi-level sorting algorithm to obtain intermediate reorganized data that conforms to the original shard data structure; according to the intermediate reorganized data, the sequence correspondence and the shard metadata index table, a check and completion algorithm is used to perform a shard boundary check and an overall hash value comparison, detect data integrity, insert intermediate reorganized data for completion, and generate complete transmission data.
[0038] It should be noted that the logical order reorganization when a missing fragment or an identifier mismatch is detected is an intelligent repair mechanism realized by the identifier, sequence number and hash value features recorded in the fragment metadata index table. According to the original fragment logical sequence template pre-stored in the fragment metadata index table, a multi-level sorting algorithm is used to dynamically sort the received fragments according to the fragment sequence priority, path transmission delay compensation value and adjacent fragment association degree. The logical position offset of the fragment in the reorganized sequence is dynamically corrected by calculating the fragment arrival time deviation and the path transmission stability parameter. At the same time, the hash value features stored in the fragment metadata index table are used to mark and isolate the abnormal fragments, and finally a fragment data structure consistent with the original fragment is generated. The intermediate reconstructed data is consistent with the structure, providing the correct fragmentation order benchmark and integrity verification basis for subsequent verification and completion; the complete transmission data is the final available data reconstructed through the hash matching verification and verification completion mechanism, and the acquisition process of the complete transmission data is as follows: first, the fragments in the buffer queue are compared with the hash value and the identifier is verified, and the logical order of the fragments is restored according to the metadata index table after the abnormal fragments are removed, and then the damage to the fragment edge data caused by network jitter is repaired through the boundary verification algorithm, and finally the reconstructed intermediate data is verified for consistency with the original overall hash value to ensure that the reconstructed data and the source data are completely matched in terms of content integrity and structural consistency, so as to obtain the complete transmission data.
[0039] In step S16, it is necessary to extract and analyze attack features based on the real-time threat intelligence data and the real-time transmission performance parameters, perform anti-attack optimization, and obtain virtual node layout and link connection strategies.
[0040] In one implementation, based on the real-time threat intelligence data and the real-time transmission performance parameters, attack features are extracted and analyzed, anti-attack optimization is performed, and virtual node layout and link connection strategies are obtained, including: According to the real-time threat intelligence data and the real-time transmission performance parameters, a three-dimensional attack feature set including attack sources, attack types and attack targets is obtained through multi-dimensional feature correlation analysis; according to the three-dimensional attack feature set, a dynamic weight allocation algorithm is used to analyze the threat probability distribution of different attack paths in real time to obtain an attack behavior analysis report; according to the attack behavior analysis report and the real-time transmission performance parameters, the mapping relationship between the false node deployment density and the link connection strength is analyzed to obtain a false network topology generation model; according to the false network topology generation model, the attack behavior analysis report and the real-time transmission performance parameters, an analysis is performed based on preset network topology concealment evaluation rules to obtain the traffic feature similarity between the false nodes and the real nodes; according to the traffic feature similarity, anti-attack optimization is performed in combination with a preset link confusion index to obtain a virtual node layout and link connection strategy.
[0041] It should be noted that the use of a dynamic weight allocation algorithm to analyze the threat probability distribution of different attack paths in real time is a threat quantification assessment process achieved through the dynamic association of a three-dimensional attack feature set with real-time transmission performance parameters. The dynamic weight coefficient is set according to the geographical distribution density of the attack source, the hazard level of the attack type, and the sensitivity of the attack target. The comprehensive threat value of each attack path is calculated in combination with the real-time transmission delay and packet loss rate data of the network path. The trend of the attack frequency and intensity is predicted through a sliding time window mechanism to generate a threat probability heat map. Finally, an attack behavior analysis report containing attack path characteristics, threat evolution trends, and defense priority recommendations is formed, providing a quantitative basis for the formulation of defense strategies for the false network topology generation model. The false network topology generation model is a dynamic defense strategy generation framework constructed by correlating and analyzing the three-dimensional attack feature set with real-time transmission performance parameters. The false network topology generation model generates a dynamic defense strategy based on the attack behavior analysis report. The threat probability distribution law revealed by the report is combined with the quantitative relationship between the deployment density of false nodes and the link connection strength to calculate the attack risk level of different areas, and then automatically generate a deceptive network structure configuration plan; the virtual node layout and the link connection strategy are executable deployment plans formed by optimizing the topology concealment evaluation rules and link confusion indicators. The acquisition process of the virtual node layout and the link connection strategy is as follows: first, the traffic feature similarity between the false nodes and the real nodes is analyzed to determine the node camouflage effect, and then the link confusion indicator is used to evaluate the misleading ability of the false link to the attacker. Finally, the node distribution density and the link connection strength ratio are dynamically adjusted in combination with the real-time network load status to form the virtual node layout and the link connection strategy that can effectively hide the real network topology structure and maintain normal data transmission efficiency. When an attack occurs, decoy nodes are quickly deployed and high-simulation communication links are constructed to divert attack traffic.
[0042] In step S17, it is necessary to use federated learning technology to perform global link quality analysis based on the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters to obtain a transmission link quality score.
[0043] In one implementation, a global link quality analysis is performed using federated learning technology according to the real-time packet loss rate, the end-to-end delay, and the real-time transmission performance parameter to obtain a transmission link quality score, including: According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, differential privacy technology is used to protect data interaction between nodes, and data is divided to each edge node for local model training to obtain a distributed evaluation framework based on federated learning; according to the distributed evaluation framework and the real-time transmission performance parameters, a dynamic trust scoring model is established, and the historical transmission success rate and the real-time transmission performance parameters are analyzed to obtain an initial dynamic trust score; according to the distributed evaluation framework, a federated aggregation algorithm is used to weightedly fuse the local model parameters of each edge node, and the node trust score weight coefficient is periodically updated to obtain a real-time updated global link quality evaluation model; the initial dynamic trust score and the real-time transmission performance parameters are input into the global link quality evaluation model, and a multi-dimensional score calculation is performed to obtain a transmission link quality score.
[0044] It should be noted that the distributed evaluation framework is an edge node collaborative computing system built through federated learning technology, which uses differential privacy technology to desensitize the link state data exchanged between nodes, and divides the local data set to each edge node for distributed model training, forming a collaborative architecture that takes into account data privacy and global evaluation capabilities; the differential privacy technology used in the construction of the distributed evaluation framework is a computing method that adds controllable noise to data or model parameters to achieve privacy protection. It is applied to the local model training stage of the edge node. By performing noise perturbations on the gradient information and statistical characteristics of the interactions between nodes, it ensures that the transmission performance data of a single node cannot be reversely deduced, while maintaining the effectiveness of the global model training; the initial dynamic trust score is a node reliability estimate generated based on historical transmission success rate, delay stability and real-time performance fluctuation characteristics. By analyzing the transmission behavior patterns and the frequency of abnormal events of the nodes within a specific time window, the score weights are dynamically updated in combination with the sliding window mechanism; the transmission link quality The score is a comprehensive evaluation result output by the global link quality assessment model after the fusion calculation of multi-dimensional network parameters, which is used to guide the dynamic optimization of the encrypted shard transmission path and the real-time adjustment of the virtual topology defense strategy; the federal aggregation algorithm used in the process of obtaining the transmission link quality score is the core mechanism for integrating distributed node model parameters in the federated learning framework. The federal aggregation algorithm fuses the local model parameters trained by each edge node by weighted average, and the weight value is dynamically adjusted according to the node's dynamic trust score and historical evaluation accuracy. In the link quality assessment scenario of the present invention, the federal aggregation algorithm periodically collects the local model output of each node based on differential privacy protection, and generates a global consensus model by calculating the spatial similarity and contribution index of the model parameters, so that each edge node can not only participate in model training using local real-time transmission data, but also obtain link quality assessment capabilities beyond the limitations of local data through the aggregated global model, and finally obtains a transmission link quality score that accurately reflects the status of the entire network and does not leak node privacy through iterative optimization.
[0045] In a specific embodiment, differential privacy technology achieves privacy protection in the federated learning framework by injecting controllable noise into the local model training process of the edge node. Specifically, each edge node adds random perturbations to the transmission delay feature distribution and packet loss rate statistics when calculating the gradient information required for link quality assessment, so that attackers cannot restore the original transmission performance parameters through reverse engineering, while maintaining the effectiveness of gradient updates. For example, when an edge node calculates the delay feature mean of the local model, it first adds noise that meets the differential privacy requirements to the original delay data and then calculates the mean, ensuring that the output model parameters cannot be associated with the sensitive data of the specific node. The federated aggregation algorithm is responsible for effectively integrating the local models processed by each node. Its working principle is that the central server regularly collects the noisy model parameters uploaded by each node, and dynamically allocates aggregation weights according to the node's historical evaluation accuracy and real-time trust score. For example, when a node has a high recent transmission success rate and a stable trust score, its model parameters will obtain a higher weight ratio during global aggregation. This dynamic weighting mechanism not only reflects the difference in node contributions but also avoids low-quality nodes from interfering with the global model training results. Finally, through multiple rounds of iterations, a global link quality assessment model is generated that can reflect the link status characteristics of the entire network but cannot trace the data details of a single node.
[0046] In step S18, it is necessary to dynamically adjust the encryption algorithm switching frequency, transmission path selection strategy and virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data.
[0047] In one implementation, according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters are dynamically adjusted to obtain real-time transmission data, including: According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, the threat intelligence change rate and network load fluctuation characteristics are analyzed, and a multidimensional optimization space including security level, transmission efficiency and topology anonymity indicators is constructed; according to the multidimensional optimization space, an evolutionary algorithm is used to perform iterative solution, analyze the balance point between security and transmission efficiency, and obtain the encryption algorithm switching frequency and path selection priority coefficient; according to the link connection strategy, the real-time changes of the false network topology adjustment are analyzed, and a dynamic response mechanism for virtual node configuration is established, which is optimized through the inverse relationship between node deployment density and link connection strength to obtain a resource allocation strategy; according to the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, a policy matching verification is performed to obtain real-time transmission data.
[0048] It should be noted that the construction of the multi-dimensional optimization space is to establish a decision analysis framework by integrating the transmission link quality score, virtual node layout parameters and complete transmission data characteristics, and dynamically calculate the security level weight, the correlation between the transmission efficiency coefficient and the topology anonymity index based on the threat intelligence change rate and the network load fluctuation characteristics, so as to form a three-dimensional parameter space that can be quantified and evaluated; the iterative solution using the evolutionary algorithm is to explore the optimal combination of the encryption algorithm switching frequency and the path priority coefficient in the optimization space by simulating the selection, crossover and mutation mechanism in the biological evolution process, and screen out the equilibrium solution set that meets the minimum tolerance value of the security level and maximizes the transmission efficiency through multiple generations of population iterations; the encryption algorithm The switching frequency of the encryption algorithm is a policy adjustment cycle determined by analyzing the dynamic correlation between the security level threshold and the transmission link quality score. The core reasoning process of the encryption algorithm switching frequency is as follows: based on the balance relationship between the security level weight and the transmission efficiency coefficient in the multi-dimensional optimization space, the influence of the switching intervals of different encryption strengths on the network performance is simulated during the iterative solution of the evolutionary algorithm to screen out the optimal frequency parameters that can meet the real-time threat protection needs and avoid transmission delays caused by frequent switching; the path selection priority coefficient is a quantitative indicator obtained by comprehensively calculating the path transmission efficiency, security level adaptability and topology anonymity contribution of the evolutionary algorithm in the multi-dimensional parameter space. The reasoning process of the priority coefficient is as follows: first, the basic priority is calculated according to the historical performance data and real-time load status of each path, and then the enhanced effect of path anonymity is weighted and corrected in combination with the current virtual node layout to obtain the path selection priority coefficient that reflects the comprehensive transmission capacity of the path. The path selection priority coefficient directly determines the distribution ratio of the fragment data on different paths. The high-priority path undertakes the key fragment transmission task, and the low-priority path is used for auxiliary transmission and redundant backup, ensuring that the optimal path combination is always selected in a dynamic network environment to achieve the optimal balance between security and efficiency; the virtual node configuration dynamic response mechanism is to analyze the node deployment density and link connection strength in the false topology adjustment decision. The real-time change trend of the degree is calculated, and a dynamic mapping model of resource allocation ratio and attack defense effectiveness is constructed. The ratio of virtual node resource input and real link protection strength is automatically adjusted according to the inverse relationship; the real-time transmission data is the final available data stream generated after strategy matching verification. The acquisition process of the real-time transmission data is as follows: based on the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, the validity and stability of the parameter combination in the real network environment are verified, and an optimized transmission scheme that meets the requirements of dynamic adaptation of encryption strength, transmission path load balancing and false topology concealment is formed, so as to obtain the real-time transmission data under the current transmission scheme.
[0049] In order to facilitate the understanding of the present invention, some preferred embodiments of the present invention are further described below.
[0050] The following describes the working process of the present invention using a common scenario as an example. Figure 2 , which is Figure 1 Schematic diagram of the working scenario of the method.
[0051] In the high-frequency order transmission scenario of the securities trading system, the present invention realizes the secure transmission and complete reorganization of millisecond-level trading instructions through a full-link dynamic collaborative control mechanism. When the trading terminal initiates a high-frequency trading instruction involving a large amount of funds, the threat intelligence collection module deployed at the edge node of the exchange first collects real-time threat intelligence data, including abnormal login behavior detection, DDoS attack traffic identification, and malicious code propagation feature analysis. The dynamic encryption module based on real-time threat intelligence immediately starts the threat level assessment. When it detects that the frequency of abnormal login attempts increases suddenly in the same period and the attack source IP shows a regular distribution, the system determines that the current threat level has been raised to level three, and then automatically selects an asymmetric encryption algorithm from the preset encryption algorithm library to encrypt the trading instruction data. At this time, the data sharding module adopts a differentiated sharding strategy according to the sensitive attributes of the trading instruction (such as amount threshold, account type), compresses the size of the shard where the core trading parameters (price, quantity) are located to 50% of the conventional shard, and embeds a dynamically generated encryption algorithm identifier in the shard header to ensure that the encryption method can be accurately identified during subsequent reorganization.
[0052] After completing the shard encryption, the path evaluation module uses a linear regression model to calculate the comprehensive performance score of each path based on the real-time transmission performance parameters of the exchange's internal private network. When it is detected that a traditional main path has a delay exceeding the 5 millisecond threshold due to burst traffic, the decision tree algorithm immediately raises the priority of the backup low-latency path to the first place, and allocates the key transaction parameter shards to this path for transmission through a dynamic programming algorithm. At the same time, the shard transmission process synchronously triggers the false network topology generation mechanism. The security protection module dynamically deploys virtual nodes on the periphery of the real trading server cluster based on the currently detected attack features (such as port scanning behavior against a specific trading server), generates bait nodes with the same response characteristics as the real server, and builds multiple false communication links, making it difficult for attackers to identify the real data transmission path.
[0053] When the encrypted shard data reaches the receiving end through the optimized transmission path, the data reorganization module starts the multi-level verification mechanism. First, integrity verification is performed based on the hash identifier embedded in the shard header. By comparing the hash value of the shard data with the pre-stored value in the metadata index table, the shards with data damage caused by network jitter are quickly identified. For the detected abnormal shards, a shard retransmission request is initiated through the backup path. At the same time, the timestamp information of the received shards in the buffer queue is used to logically reorganize the shards that arrive out of order using a multi-level sorting algorithm. When the core transaction parameter shards are slightly delayed due to path switching, the reorganization algorithm performs intelligent interpolation based on the logical correlation between the shards to ensure that the data reorganization is completed within the specified time window without affecting the timeliness of the transaction.
[0054] The federated learning evaluation network continues to play a role throughout the data transmission process. The local evaluation model deployed at the edge nodes of exchanges in various places regularly collects link quality data in the local area (including latency fluctuations and packet loss event frequency), desensitizes sensitive data through differential privacy technology, and uploads the model parameters to the central aggregation server. The federated aggregation algorithm dynamically adjusts the weight coefficient according to the historical evaluation accuracy of each node to generate a global link quality evaluation model. When an edge node continuously detects an abnormal increase in the packet loss rate of a specific path, the dynamic trust scoring model immediately lowers the trust level of the path, and adjusts the layout strategy of the false nodes and links in real time to obtain the virtual node layout and link connection strategy.
[0055] Finally, a multi-dimensional decision optimization space is constructed by integrating multi-dimensional parameters such as link quality score, virtual topology anonymity index and data reorganization success rate. An improved genetic algorithm is used to dynamically tune key parameters such as encryption algorithm switching frequency, path selection weight coefficient, and virtual node update cycle. When a surge in network load is detected during high-frequency trading hours, the encryption strength of non-critical data is automatically reduced to improve transmission efficiency, while the deployment density of virtual nodes is increased to strengthen security protection. This dynamic balance mechanism enables the system to complete a full set of emergency responses including encryption strategy switching, path reselection and false topology reconstruction within 30 milliseconds when encountering sudden network attacks, ensuring that transaction instructions can still maintain an end-to-end delay of less than 8 milliseconds in extreme network environments, and that data integrity is maintained.
[0056] The entire workflow forms a complete control closed loop, from threat perception driving encryption strategy adjustment to path optimization to ensure transmission timeliness, and then to ensure information integrity through data verification, and finally to achieve global state perception and parameter self-optimization with the help of federated learning. It effectively solves the inherent contradiction between security protection and transmission efficiency in securities trading scenarios. When an APT attack on the trading system occurs, the system can successfully mislead the attack traffic through dynamically added false nodes, while ensuring that the transmission of real transaction data is not affected. When a trunk line is interrupted due to physical failure, the path evaluation model can switch the traffic to the backup line within 5 milliseconds, and adjust the shard size through an adaptive sharding strategy to adapt to the new network carrying capacity, ensuring the continuous transmission of key trading instructions. This dynamic computer network security data transmission method enables the securities trading system to maintain the stable operation of the financial market in the face of complex network attacks and sudden network failures.
[0057] In summary, the present invention discloses a computer network data security data transmission method, including obtaining real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, dynamically switching encryption algorithms based on the real-time threat intelligence data, performing shard encryption processing on the data to be transmitted, and obtaining encrypted shard data; inputting the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; according to the path performance score, combined with a preset screening threshold, using a decision tree algorithm to prioritize paths that meet the threshold conditions to obtain a transmission path set; according to the encrypted shard data and the transmission path set, constructing a shard metadata index table and performing shard arrival time sequence analysis, establishing a buffer queue to match the obtained Receive a sequence correspondence between the fragment and the original fragment; based on the sequence correspondence, perform integrity check on the fragment identifier of the sequence correspondence through a hash matching mechanism to generate complete transmission data; based on the real-time threat intelligence data and the real-time transmission performance parameters, extract and analyze attack features, perform anti-attack optimization, and obtain virtual node layout and link connection strategy; based on the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, use federated learning technology to perform global link quality analysis to obtain a transmission link quality score; based on the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, dynamically adjust the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters to obtain real-time transmission data.
[0058] The present invention responds to threat intelligence changes in real time through a dynamic encryption algorithm switching mechanism, dynamically optimizes transmission path selection in combination with a path performance evaluation model based on linear regression and decision tree algorithms, uses hash identification and buffer queues to achieve integrity verification and sequential reorganization of fragmented data, and constructs a distributed link quality evaluation network through federated learning technology to accurately perceive the transmission state, while dynamically generating a false network topology based on attack feature analysis to enhance defense capabilities, and finally coordinates encryption strength, path selection and topology anonymity through an adaptive parameter adjustment mechanism in a multidimensional optimization space, so that fragmented encryption processing, multi-path collaborative transmission and data integrity assurance form a closed-loop control, and realizes millisecond-level response of encryption strategy switching and transmission path optimization under a dynamic threat environment, ensuring the complete and orderly reorganization of fragmented data under network path performance fluctuations and attack interference. Thus, the present invention realizes real-time and complete computer network security data transmission.
[0059] Reference Figure 2 The second embodiment of the present invention provides a computer network data transmission security device, comprising: A data acquisition module is used to acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, dynamically switch the encryption algorithm based on the real-time threat intelligence data, perform fragment encryption processing on the data to be transmitted, and obtain encrypted fragment data; A path evaluation module, used to input the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; A sorting set module is used to prioritize the paths that meet the threshold conditions using a decision tree algorithm according to the path performance score and a preset screening threshold, so as to obtain a transmission path set; A timing analysis module is used to construct a shard metadata index table and perform shard arrival time sequence analysis based on the encrypted shard data and the transmission path set, and to establish a buffer queue to match the sequence correspondence between the received shards and the original shards; A data reorganization module is used to perform integrity check on the fragment identifiers of the sequence correspondence through a hash matching mechanism to generate complete transmission data; A virtual layout module, used to extract and analyze attack features according to the real-time threat intelligence data and the real-time transmission performance parameters, perform anti-attack optimization, and obtain virtual node layout and link connection strategies; A link analysis module, configured to perform global link quality analysis based on the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter using federated learning technology to obtain a transmission link quality score; The result output module is used to dynamically adjust the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data.
[0060] It should be noted that a computer network secure data transmission device provided in an embodiment of the present invention is used to execute all the process steps of a computer network secure data transmission method of the above embodiment, and the working principles and beneficial effects of the two correspond one to one, so they will not be repeated here.
[0061] An embodiment of the present invention further provides an electronic device. The electronic device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a computer network data transmission security program. When the processor executes the computer program, the steps in the above-mentioned computer network data transmission security method embodiments are implemented, such as Figure 1 Alternatively, when the processor executes the computer program, the functions of the modules / units in the above-mentioned device embodiments are realized, such as the virtual layout module.
[0062] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing specific functions, which are used to describe the execution process of the computer program in the electronic device.
[0063] The electronic device may be a computing device such as a desktop computer, a notebook, a PDA, and a smart tablet. The electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art will appreciate that the above components are merely examples of electronic devices and do not constitute a limitation on the electronic device. The electronic device may include more or fewer components than the above components, or may combine certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.
[0064] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the electronic device, and uses various interfaces and lines to connect various parts of the entire electronic device.
[0065] The memory can be used to store the computer program and / or module, and the processor realizes various functions of the electronic device by running or executing the computer program and / or module stored in the memory, and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0066] Wherein, if the module / unit integrated in the electronic device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the present invention implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Wherein, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0067] It should be noted that the device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, in the accompanying drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art may understand and implement it without paying any creative effort.
[0068] The specific embodiments described above further illustrate the purpose, technical solutions and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. It is particularly pointed out that for those skilled in the art, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention should be included in the scope of protection of the present invention.
Claims
1. A computer network secure data transmission method, characterized in that: include: Acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, perform dynamic encryption algorithm switching based on the real-time threat intelligence data, perform fragment encryption processing on the data to be transmitted, and obtain encrypted fragment data; Inputting the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; According to the path performance score and in combination with a preset screening threshold, a decision tree algorithm is used to prioritize the paths that meet the threshold conditions to obtain a transmission path set; According to the encrypted shard data and the transmission path set, a shard metadata index table is constructed and a shard arrival time sequence analysis is performed, and a buffer queue is established to match and obtain a sequence correspondence between the received shards and the original shards; Perform integrity check on the fragment identifiers of the sequence correspondence through a hash matching mechanism to generate complete transmission data; Extract and analyze attack features based on the real-time threat intelligence data and the real-time transmission performance parameters, perform anti-attack optimization, and obtain virtual node layout and link connection strategies; According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter, a global link quality analysis is performed using a federated learning technique to obtain a transmission link quality score; According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters are dynamically adjusted to obtain real-time transmission data.
2. The computer network secure data transmission method according to claim 1, characterized in that: The acquiring of real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, performing dynamic encryption algorithm switching based on the real-time threat intelligence data, performing fragment encryption processing on the data to be transmitted, and obtaining encrypted fragment data, includes: Obtain real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters of multiple network paths, and data to be transmitted; The real-time transmission performance parameters include real-time transmission speed, real-time traffic characteristics and transmission stability data of multiple network paths; Based on the real-time threat intelligence data, dynamic trend prediction is predicted by time series analysis, the magnitude of threat level change is calculated and security level intervals are divided to obtain dynamic security level assessment parameters; According to the dynamic security level assessment parameters, in combination with a preset encryption algorithm library, dynamic matching of encryption algorithm types is performed to obtain an encryption algorithm dynamic selection model; According to the dynamic selection model of the encryption algorithm and the dynamic security level assessment parameters, an adaptive sharding strategy is adopted to shard the data to be transmitted, and the shard size is adjusted based on the preset data sensitivity to obtain initial shard data; Dynamic encryption processing is performed according to the initial shard data. When it is detected that the dynamic security level assessment parameter is increased, the encryption algorithm switching mechanism is triggered during the shard transmission process, and the encryption compatibility of the previous and next shards is maintained to obtain encrypted shard data.
3. The computer network secure data transmission method according to claim 1, characterized in that: The preset path performance evaluation model training process includes: Obtain historical real-time transmission performance parameters; Input the historical real-time transmission performance parameters into the linear regression model to obtain the historical path performance score; When the number of training times is greater than or equal to a preset number of training times, the training is determined to be completed, and a path performance evaluation model of the trained path is obtained.
4. The computer network secure data transmission method according to claim 1, characterized in that: The path performance score is combined with a preset screening threshold and a decision tree algorithm is used to prioritize the paths that meet the threshold conditions to obtain a transmission path set, including: According to the path performance score and in combination with a preset screening threshold, a decision tree algorithm is used to prioritize the paths that meet the threshold conditions to obtain an initial optimal path set; According to the initial optimal path set, a dynamic programming algorithm is used to allocate the shard transmission tasks in real time, and the arrival time of each shard is detected to obtain the difference in the arrival time of the shards; According to the fragment arrival time difference and the real-time transmission performance parameter, in combination with a path performance evaluation model, the path performance is re-evaluated and priority sorting is performed to obtain a transmission path set.
5. The computer network secure data transmission method according to claim 1, characterized in that: The step of constructing a fragment metadata index table according to the encrypted fragment data and the transmission path set, performing fragment arrival time sequence analysis, and establishing a buffer queue to match the sequence correspondence between the received fragment and the original fragment includes: According to the encrypted shard data and the transmission path set, a hash value of the encrypted shard data is calculated using a hash algorithm, and a shard metadata index table is constructed by combining a unique identifier and a shard sequence number in the encrypted shard data; According to the fragment metadata index table, fragment arrival time sequence analysis is performed, and a buffer queue is established to match the sequence correspondence between the received fragments and the original fragments.
6. The computer network secure data transmission method according to claim 1, characterized in that: The integrity check of the fragment identifier of the sequence correspondence is performed by a hash matching mechanism to generate complete transmission data, including: According to the sequence correspondence, the integrity of the shard identifier is checked in combination with the preset hash verification rules. When a shard is missing or the identifier does not match, the shard is logically reorganized in sequence using a multi-level sorting algorithm based on the shard metadata index table to obtain intermediate reorganized data that conforms to the original shard data structure; According to the intermediate reorganized data, the sequence correspondence and the shard metadata index table, a verification and completion algorithm is used to perform shard boundary verification and overall hash value comparison, detect data integrity and insert intermediate reorganized data for completion to generate complete transmission data.
7. The computer network secure data transmission method according to claim 1, characterized in that: The extracting and analyzing attack features according to the real-time threat intelligence data and the real-time transmission performance parameters, performing anti-attack optimization, and obtaining virtual node layout and link connection strategies include: According to the real-time threat intelligence data and the real-time transmission performance parameters, a three-dimensional attack feature set including attack source, attack type and attack target is obtained through multi-dimensional feature correlation analysis; According to the three-dimensional attack feature set, a dynamic weight allocation algorithm is used to analyze the threat probability distribution of different attack paths in real time to obtain an attack behavior analysis report; According to the attack behavior analysis report and the real-time transmission performance parameters, a mapping relationship between false node deployment density and link connection strength is analyzed to obtain a false network topology generation model; According to the false network topology generation model, the attack behavior analysis report and the real-time transmission performance parameters, an analysis is performed based on a preset network topology anonymity evaluation rule to obtain the similarity of traffic characteristics between the false node and the real node; According to the traffic feature similarity, anti-attack optimization is performed in combination with a preset link confusion index to obtain a virtual node layout and link connection strategy.
8. The computer network secure data transmission method according to claim 1, characterized in that: The method of performing global link quality analysis based on the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter using federated learning technology to obtain a transmission link quality score includes: According to the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameters, differential privacy technology is used to protect data interaction between nodes, and data is divided to each edge node for local model training, so as to obtain a distributed evaluation framework based on federated learning; Establishing a dynamic trust scoring model based on the distributed evaluation framework and the real-time transmission performance parameters, analyzing the historical transmission success rate and the real-time transmission performance parameters, and obtaining an initial dynamic trust score; According to the distributed evaluation framework, a federated aggregation algorithm is used to weight the local model parameters of each edge node, and the node trust score weight coefficient is periodically updated to obtain a global link quality evaluation model that is updated in real time; The initial dynamic trust score and the real-time transmission performance parameter are input into the global link quality assessment model, and a multi-dimensional score calculation is performed to obtain a transmission link quality score.
9. The computer network secure data transmission method according to claim 1, characterized in that: The method of dynamically adjusting the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data includes: According to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data, the threat intelligence change rate and network load fluctuation characteristics are analyzed to construct a multi-dimensional optimization space including security level, transmission efficiency and topology anonymity indicators; According to the multi-dimensional optimization space, an evolutionary algorithm is used to perform iterative solution, analyze the balance point between security and transmission efficiency, and obtain the encryption algorithm switching frequency and path selection priority coefficient; According to the link connection strategy, the real-time changes of the false network topology adjustment are analyzed, a dynamic response mechanism for virtual node configuration is established, and the resource allocation strategy is obtained by optimizing the inverse relationship between node deployment density and link connection strength; According to the resource allocation strategy, the encryption algorithm switching frequency, the path selection priority coefficient and the complete transmission data, a strategy matching verification is performed to obtain real-time transmission data.
10. A computer network secure data transmission device, characterized in that: include: A data acquisition module is used to acquire real-time threat intelligence data, real-time packet loss rate, real-time end-to-end delay, real-time transmission performance parameters and data to be transmitted, dynamically switch the encryption algorithm based on the real-time threat intelligence data, perform fragment encryption processing on the data to be transmitted, and obtain encrypted fragment data; A path evaluation module, used to input the real-time transmission performance parameters into a preset path performance evaluation model to obtain a path performance score; A sorting set module is used to prioritize the paths that meet the threshold conditions using a decision tree algorithm according to the path performance score and a preset screening threshold, so as to obtain a transmission path set; A timing analysis module is used to construct a shard metadata index table and perform shard arrival time sequence analysis based on the encrypted shard data and the transmission path set, and to establish a buffer queue to match the sequence correspondence between the received shards and the original shards; A data reorganization module is used to perform integrity check on the fragment identifiers of the sequence correspondence through a hash matching mechanism to generate complete transmission data; A virtual layout module, used to extract and analyze attack features according to the real-time threat intelligence data and the real-time transmission performance parameters, perform anti-attack optimization, and obtain virtual node layout and link connection strategies; A link analysis module, configured to perform global link quality analysis based on the real-time packet loss rate, the end-to-end delay and the real-time transmission performance parameter using federated learning technology to obtain a transmission link quality score; The result output module is used to dynamically adjust the encryption algorithm switching frequency, the transmission path selection strategy and the virtual node configuration parameters according to the transmission link quality score, the virtual node layout, the link connection strategy and the complete transmission data to obtain real-time transmission data.
Citation Information
Patent Citations
Data transmission and link switching method, electronic equipment and readable storage medium
CN115460662A
Encryption optimization method for data communication
CN118944952A
Intelligent prioritization of assessment and remediation of common vulnerabilities and exposures for network nodes
US20230336581A1
Cited By
Remote cooperation and data synchronization method of all-in-one machine
CN120091027A
Data secure transmission method and system, computer and storage medium
CN120342616A
Method, device and equipment for dynamically adjusting quality of video polyphonic ringtone and medium
CN120499315A
Method, device, equipment and medium for dynamically adjusting the quality of video ringback tone
CN120499315B
Control system and method for flexible material production line
CN120509688A