A data transmission method, apparatus, medium and device

By selecting the optimal tunnel in a zero-trust system and performing protocol-matched encapsulation, the problem of poor anti-interference capability of IPv4/IPv6 tunnels is solved, achieving more efficient and reliable data transmission.

CN119922161BActive Publication Date: 2025-11-07HANGZHOU DPTECH TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510121106.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-11-07
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

In existing zero-trust systems, IPv4/IPv6 tunnels rely on fixed routes, resulting in poor anti-interference capabilities and a tendency to experience packet loss and outages.

Method used

By acquiring the network status of IPv4 and IPv6 tunnels, the best tunnel is selected, and the encapsulation and transmission are performed according to the matching of the tunnel and the encapsulation protocol of the packet data. Dual-stack technology is used to realize the transmission of IPv4 and IPv6 packets.

Benefits of technology

It improves the network anti-interference capability and efficiency of data transmission in zero-trust systems, ensuring the reliability and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922161B_ABST
    Figure CN119922161B_ABST
Patent Text Reader

Abstract

The specification discloses a data transmission method, device, medium and equipment, which selects a target tunnel from an IPV4 tunnel and an IPV6 tunnel by the network states of the IPV4 tunnel and the IPV6 tunnel. Then, the message data to be transmitted and the destination address of the message data are determined, and the encapsulation protocol of the message data is determined according to the destination address. Whether the target tunnel matches the encapsulation protocol of the message data is judged. If yes, the message data is transmitted to a zero trust gateway through the target tunnel. If no, the message data after being disguised is determined, and the disguised message data is transmitted to the zero trust gateway through the target tunnel. According to the network states of the tunnels, the tunnel used for data transmission is determined, and then the IPV6 message is transmitted through the IPV4 tunnel and the IPV4 message data is transmitted through the IPV6 tunnel by using the dual stack technology, so that the network anti-interference capability of a user when using a zero trust system is improved, and the data transmission efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present specification relates to the technical field of computer technology, and particularly relates to a data transmission method and device, medium and equipment. BACKGROUND

[0002] At present, with the development of computer technology, zero trust architecture has gradually become an important concept of new generation network security protection. In the existing zero trust system based on zero trust architecture, the user sends verification information to the zero trust platform through the client installed on the terminal, so that the zero trust platform returns the gateway address to the client and sends the verification passed instruction to the corresponding zero trust gateway after verifying the user's verification information. Then, the user takes the zero trust gateway as an intermediary between the storage address of the target data and the access target data, realizes communication between the storage address of the target data and the access target data, and thus obtains the target data. In order to ensure the security and privacy of the target data in the transmission process, the system usually uses tunnel technology to realize the transmission of the target data.

[0003] In the prior art, in order to further improve the security of data, especially the security of sensitive data, the zero trust system usually establishes a single tunnel in the client and the zero trust gateway to realize data transmission. For example, the client encapsulates data through the most widely used Internet Protocol version 4 (IPV4), and realizes the transmission of encapsulated data through IPV4 tunnel, or encapsulates data through the latest Internet Protocol version 6 (IPV6), and realizes the transmission of encapsulated data through IPV6 tunnel.

[0004] However, a single IPV4 / IPV6 tunnel often depends on a fixed route. If the nodes in the route are congested, faulty, etc., it will cause packet loss or even interruption during data transmission, and the anti-interference ability is poor. Based on this, the present application discloses a data transmission method, device, medium and equipment. SUMMARY

[0005] The present specification provides a data transmission method, device, medium and equipment to partially solve the above problems existing in the prior art.

[0006] The present specification adopts the following technical solutions:

[0007] The method is applied to a terminal in a zero trust system, the zero trust system at least comprising the terminal and a zero trust gateway, and at least comprising an Internet Protocol version 4 (IPV4) tunnel and an Internet Protocol version 6 (IPV6) tunnel between the terminal and the zero trust gateway, comprising

[0008] determining message data to be transmitted and a destination address of the message data, and determining an encapsulation protocol of the message data according to the destination address;

[0009] obtaining network states of the IPV4 tunnel and the IPV6 tunnel, and selecting a target tunnel from the IPV4 tunnel and the IPV6 tunnel according to the network states;

[0010] determining whether the target tunnel matches the encapsulation protocol of the message data;

[0011] if yes, transmitting the message data to the zero trust gateway through the target tunnel, so that the zero trust gateway forwards the message data to the destination address after receiving an identity verification pass instruction of the terminal;

[0012] if no, determining an encapsulation protocol corresponding to the target tunnel, re-encapsulating the message data according to the encapsulation protocol corresponding to the target tunnel, determining a disguised message data, transmitting the disguised message data to the zero trust gateway through the target tunnel, and so that the zero trust gateway forwards the disguised message data to the destination address after receiving the identity verification pass instruction of the terminal.

[0013] Optionally, the zero trust system further comprises a zero trust platform, and before determining the message data to be transmitted, the method further comprises:

[0014] in response to an operation of a user, determining verification information according to the operation;

[0015] sending the identity verification information to the zero trust platform, so that the zero trust platform verifies according to the verification information, and returns a verification pass instruction and sends it to the zero trust gateway when the verification is passed.

[0016] Optionally, the method further comprises:

[0017] sending a detection signal to the zero trust gateway through the IPV4 tunnel and the IPV6 tunnel at a preset frequency, and accepting a detection result returned by the zero trust gateway;

[0018] determining network states of the IPV4 tunnel and the IPV6 tunnel according to the detection result of the most recent at least one time.

[0019] Optionally, the network status comprises at least one of a connection status, a delay, a packet loss rate, and a bandwidth utilization of the IPV4 tunnel and the IPV6 tunnel.

[0020] Optionally, the target tunnel is selected from the IPV4 tunnel and the IPV6 tunnel according to the network status, and specifically comprises:

[0021] The IPV4 tunnel and the IPV6 tunnel are scored according to the network status of the IPV4 tunnel and the IPV6 tunnel acquired last time.

[0022] The target tunnel is selected according to the score.

[0023] Optionally, it is judged whether the target tunnel matches the encapsulation protocol of the message data, and specifically comprises:

[0024] When the encapsulation protocol of the message data is IPV4, it is determined whether the target tunnel is an IPV4 tunnel, if yes, it is indicated that the target tunnel matches the encapsulation protocol of the message data, and if no, it is indicated that the target tunnel does not match the encapsulation protocol of the message data.

[0025] When the encapsulation protocol of the message data is IPV6, it is determined whether the target tunnel is an IPV6 tunnel, if yes, it is indicated that the target tunnel matches the encapsulation protocol of the message data, and if no, it is indicated that the target tunnel does not match the encapsulation protocol of the message data.

[0026] Optionally, the message data is encapsulated again according to the encapsulation protocol corresponding to the target tunnel to determine the disguised message data, and specifically comprises:

[0027] When the encapsulation protocol corresponding to the target tunnel is IPV4, the message data is encapsulated by a user datagram protocol and then encrypted to determine an encrypted message, the encrypted message is re-encapsulated by the IPV4 protocol to determine the disguised message data.

[0028] When the encapsulation protocol corresponding to the target tunnel is IPV6, the message data is encapsulated by a user datagram protocol and then encrypted to determine an encrypted message, the encrypted message is re-encapsulated by the IPV6 protocol to determine the disguised message data.

[0029] The present specification provides a data transmission device, which is used to implement a terminal in a zero trust system, the zero trust system at least comprising the terminal and a zero trust gateway, and at least comprising an Internet Protocol version 4 (IPV4) tunnel and an Internet Protocol version 6 (IPV6) tunnel between the terminal and the zero trust gateway, comprising:

[0030] determining module, configured to determine message data to be transmitted and a destination address of the message data, and determine an encapsulation protocol of the message data according to the destination address;

[0031] an obtaining module, configured to obtain network states of the IPV4 tunnel and the IPV6 tunnel, and select a target tunnel from the IPV4 tunnel and the IPV6 tunnel according to the network states;

[0032] a transmitting module, configured to determine whether the target tunnel matches the encapsulation protocol of the message data, and if yes, transmit the message data to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the message data to the destination address after receiving a terminal identity verification pass instruction, and if no, determine an encapsulation protocol corresponding to the target tunnel, re-encapsulate the message data according to the encapsulation protocol corresponding to the target tunnel, determine a disguised message data, transmit the disguised message data to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the disguised message data to the destination address after receiving the terminal identity verification pass instruction.

[0033] The present specification provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the above data transmission method.

[0034] The present specification provides an electronic device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the above data transmission method when executing the program.

[0035] The above at least one technical solution adopted by the present specification can achieve the following beneficial effects:

[0036] In the data transmission method provided by the present specification, the network states of the IPV4 tunnel and the IPV6 tunnel are obtained, and a target tunnel is selected from the IPV4 tunnel and the IPV6 tunnel. Then, message data to be transmitted and a destination address of the message data are determined, and an encapsulation protocol of the message data is determined according to the destination address. Whether the target tunnel matches the encapsulation protocol of the message data is determined, and if yes, the message data is transmitted to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the message data to the destination address after receiving a terminal identity verification pass instruction, and if no, an encapsulation protocol corresponding to the target tunnel is determined, the message data is re-encapsulated according to the encapsulation protocol corresponding to the target tunnel, disguised message data is determined, the disguised message data is transmitted to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the disguised message data to the destination address after receiving the terminal identity verification pass instruction.

[0037] In the data transmission method, the network state of each tunnel is determined to determine the tunnel used for data transmission, and then the dual stack technology is used to transmit IPV6 message through IPV4 tunnel and transmit IPV4 message data through IPV6 tunnel, so as to improve the network anti-interference ability of users using the zero trust system and improve the data transmission efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0038] The accompanying drawings, which are included to provide a further understanding of the present specification, constitute a part of the present specification, and the illustrative embodiments of the present specification and the description thereof serve to explain the present specification, and do not constitute an improper limitation on the present specification. In the drawings:

[0039] Figure 1 A schematic diagram of a zero trust system based on a zero trust architecture is provided for the present specification;

[0040] Figure 2 A flowchart of a data transmission method is provided for the present specification;

[0041] Figure 3 A schematic diagram of data transmission is provided for the present specification;

[0042] Figure 4 A schematic diagram of a data transmission device is provided for the present specification;

[0043] Figure 5 A structural schematic diagram of an electronic device corresponding to Figure 2 is provided for the present specification. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical scheme and advantages of the present specification clearer, the technical scheme of the present specification will be described clearly and completely in combination with the specific embodiments of the present specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present specification, not all the embodiments. Based on the embodiments in the present specification, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the present application.

[0045] With the development of computer technology, zero trust architecture has gradually become an important concept for new generation network security protection. Zero trust architecture adheres to the principle of "continuous verification, never trust", thereby ensuring terminal security, link security and access control security, and is gradually applied to various scenarios requiring high security and high flexibility, such as remote office and hybrid work environment, cloud native application and micro service architecture, Internet of Things and edge computing, etc.

[0046] As shown in Figure 1 ,Figure 1 A schematic diagram of a zero-trust system based on a zero-trust architecture is provided in the specification, wherein the user operates the zero-trust client in the terminal, sends verification information to the zero-trust platform through the zero-trust client, and makes the zero-trust platform verify the identity of the zero-trust client and the terminal operated by the user based on the verification information. When the identity verification of the zero-trust client and the terminal by the zero-trust platform is passed, the identity verification pass instruction is returned to the zero-trust client in the terminal, and the identity verification pass instruction of the terminal and the client is sent to the zero-trust gateway, so that the zero-trust gateway determines the range of resources accessible by the client according to the identity verification pass instruction. Then, the zero-trust gateway displays the resource directory accessible by the client to the client, so that the user determines the address to be accessed according to the accessible resource directory. Then the client generates an access instruction, and takes the address to be accessed as the destination address of the access instruction, encapsulates the access instruction into an Internet Protocol Packet (IP Packet), i.e. IP packet data, according to the access instruction and the destination address, and sends the IP packet data to the zero-trust gateway through the tunnel corresponding to the IP protocol of the IP packet data. The zero-trust gateway monitors and audits the access instruction in the IP packet data, and forwards it to the destination address.

[0047] However, when the terminal transmits the IP packet data through the corresponding tunnel, a single tunnel is usually established in the client and the zero-trust gateway to realize data transmission, so as to further improve the security of data transmission. For example, the client encapsulates data through the most widely used Internet Protocol version 4 (IPV4), and transmits the encapsulated data through the IPV4 tunnel, or encapsulates data through the latest Internet Protocol version 6 (IPV6), and transmits the encapsulated data through the IPV6 tunnel. However, a single IPV4 / IPV6 tunnel often depends on a fixed route. If the nodes in the route are congested, faulty, etc., it will cause packet loss or even interruption during data transmission, and the anti-interference ability is poor. In order to solve the above problems, the specification provides a data transmission method.

[0048] It should be noted that in the data transmission method provided in the present specification, the data transmission method is applied to a terminal in a zero trust system, and the zero trust system at least includes the terminal and a zero trust gateway, and at least includes an IPV4 tunnel and an IPV6 tunnel between the terminal and the zero trust gateway. In one or more embodiments of the present specification, the terminal is not limited to a specific device, for example, a mobile terminal, a computer, a server, etc., wherein the server can be a separate device or composed of multiple devices, for example, a distributed server, and the present specification does not limit this. It can also refer to a server of a cloud service. In addition, in one or more embodiments of the present specification, the terminal described above can be used as a sending end of message data or a receiving end of message data, and the present specification does not limit this. Whether it is an IPV4 tunnel or an IPV6 tunnel, it refers to a technology of encapsulating another protocol data packet on the network layer. Of course, in one or more embodiments of the present specification, in order to protect the security of data transmission, an Internet Protocol Security (IPsec) tunnel is generally used. Of course, other tunnels can also be used, which can be set according to actual needs, and the present specification does not limit this. For the convenience of description, the following will take the IPsec tunnel as an example to describe the data transmission method.

[0049] The technical solutions provided by the embodiments of the present specification will be described in detail below with reference to the drawings.

[0050] Figure 2 The flowchart of the data transmission method provided by the embodiments of the present specification includes the following steps:

[0051] S200: Determine the message data to be transmitted and the destination address of the message data, and determine the encapsulation protocol of the message data according to the destination address.

[0052] In order to realize the correct transmission of data, the terminal should first determine the message data to be transmitted and the destination address of the message data, and then determine the corresponding encapsulation protocol, so as to determine the encapsulation strategy when transmitting through the tunnel according to the encapsulation protocol subsequently.

[0053] Specifically, the terminal obtains the message data to be transmitted and the destination address of the message data. It should be noted that in one or more embodiments of the present specification, the terminal does not limit how to obtain the message data to be transmitted specifically, which can be directly obtained from the network card, and then the data frame is unpacked to determine the message data to be transmitted and the destination address. The terminal can also determine the data to be transmitted in response to the user's operation on the terminal, for example, in the resource acquisition scenario, the user can determine the directory of the available resources through the zero trust client installed on the terminal after authentication, and then the terminal can generate a resource acquisition instruction according to the user's operation, and encapsulate the resource acquisition instruction to determine the IP message data corresponding to the resource acquisition instruction. Or if the terminal is in a resource acquisition scenario, it receives a resource acquisition instruction that needs to return the corresponding resource to the terminal, and when determining the message data to be transmitted, the terminal can encapsulate the resource to be transmitted as IP message data. Since there are many ways to obtain the message data to be transmitted, this will not be described here, and the present specification does not limit this, which can be set according to actual needs.

[0054] In addition, in one or more embodiments of the present specification, the content in the message data to be transmitted is not limited, which can be a string of instructions, resource data, etc., which can be set according to actual needs.

[0055] Further, when determining the encapsulation protocol of the message data, the terminal can determine the encapsulation protocol according to the protocol supported by the destination address of the message data, or analyze the encapsulation protocol of the message data according to the data header of the message data. Of course, other methods can also be used to determine the encapsulation protocol of the message data, and the present specification does not limit this, which can be set according to actual needs. Generally, the determined encapsulation protocol is IPV4 and IPV6.

[0056] S202: Obtain the network state of the IPV4 tunnel and the IPV6 tunnel, and select a target tunnel from the IPV4 tunnel and the IPV6 tunnel according to the network state.

[0057] Since both IPV4 tunnel and IPV6 tunnel often rely on fixed routing when transmitting data, if network congestion, insufficient bandwidth, etc. occur in the routing, it may cause high data transmission delay or packet loss problem, affecting the user experience. Therefore, in order to realize efficient data transmission, the terminal can determine the network state of the tunnel between the target gateway before data transmission, so as to select a target tunnel. In one or more embodiments of the present specification, the network state of the IPV4 tunnel and the IPV6 tunnel refers to the connection state, delay, packet loss rate, bandwidth utilization rate, etc. of the tunnel, which can be at least one of the indicators for evaluating the data transmission efficiency of the tunnel.

[0058] Specifically, the terminal can first acquire the network states of the IPV4 tunnel and the IPV6 tunnel, and then select the tunnel with the fastest data transmission as the target tunnel according to the network states of the IPV4 tunnel and the IPV6 tunnel.

[0059] It should be noted that in one or more embodiments of the present specification, the terminal does not limit the specific way to determine the network state of the tunnel. The network state of each tunnel can be determined by heartbeat reaction, that is, the terminal sends a detection signal to the zero trust gateway through the IPV4 tunnel and the IPV6 tunnel according to the preset frequency, and then receives the detection result returned by the zero trust gateway. The network state of the IPV4 tunnel and the IPV6 tunnel is determined according to the detection result. Of course, the running state of the tunnel can also be determined by analyzing the log, and other methods can be used to determine the network state of the IPV4 tunnel and the IPV6 tunnel, which can be set according to actual needs, and the present specification does not limit this.

[0060] Therefore, when selecting the target tunnel according to the network states of the IPV4 tunnel and the IPV6 tunnel, the network state of the IPV6 tunnel can be determined first. If the network state of the IPV6 tunnel can reach the preset state, the IPV6 tunnel is preferred as the target tunnel, otherwise, the IPV4 tunnel is selected as the target tunnel. Of course, other methods can also be used to determine the target tunnel. Since there are many methods that can be used, the present specification will be described later, and this will not be described here.

[0061] S204: Determine whether the target tunnel matches the encapsulation protocol of the message data. If yes, execute step S206, if not, execute step S208.

[0062] Since the IPV4 tunnel lacks the mechanism to process and understand the message header of the IPV6 message data, the IPV4 tunnel cannot understand the IPV6 message data. Similarly, the IPV6 tunnel cannot understand the IPV4 message data. Therefore, before transmitting the to-be-transmitted message data through the target tunnel, it is necessary to determine whether the encapsulation protocol of the message data matches the target tunnel, so as to determine which encapsulation strategy should be used to encapsulate the to-be-transmitted message data.

[0063] Specifically, if the target tunnel is an IPV4 tunnel, it is determined whether the encapsulation protocol of the to-be-transmitted message data is IPV4. If yes, it indicates that the target tunnel matches the encapsulation protocol of the to-be-transmitted message data, if not, it indicates that the target tunnel does not match the encapsulation protocol of the to-be-transmitted message data.

[0064] If the target tunnel is an IPV6 tunnel, it is judged whether the encapsulation protocol of the message data to be transmitted is IPV6. If yes, it indicates that the target tunnel matches the encapsulation protocol of the message data to be transmitted. If no, it indicates that the target tunnel does not match the encapsulation protocol of the message data to be transmitted.

[0065] S206: transmitting the message data to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the message data to the destination address after receiving the terminal identity verification pass instruction.

[0066] Since the target tunnel matches the encapsulation protocol of the message data to be transmitted, the target tunnel can be directly used for transmitting the message data. Therefore, the terminal can send the message data to the zero-trust gateway through the target tunnel. So that the zero-trust gateway decapsulates the message data after receiving the terminal identity verification pass instruction, determines the destination address of the message data, and re-encapsulates and forwards to the destination address.

[0067] It should be noted that in one or more embodiments of the present specification, the terminal is not limited to how to determine the address of the zero-trust gateway. In the zero-trust system, at least one zero-trust gateway can be included. When there is only one zero-trust gateway, it indicates that the address of the zero-trust gateway is pre-configured, and the terminal can directly obtain the address of the zero-trust gateway. If the zero-trust system includes multiple zero-trust gateways, the terminal can obtain the address of the corresponding zero-trust gateway when performing identity verification. The present specification does not limit this.

[0068] Of course, in one or more embodiments of the present specification, the zero-trust gateway is not limited to using which tunnel to transmit the message data to the destination address when forwarding the message data to the destination address. The preset tunnel can be used to realize the forwarding of the message data, or the tunnel selection method as described above can be used to determine the tunnel for transmitting the message data. According to actual needs, it can be set.

[0069] S208: determining the encapsulation protocol corresponding to the target tunnel, re-encapsulating the message data according to the encapsulation protocol corresponding to the target tunnel, determining the disguised message data, and transmitting the disguised message data to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the disguised message data to the destination address after receiving the terminal identity verification pass instruction.

[0070] Since the target tunnel does not match the encapsulation protocol of the message data to be transmitted, in order to realize the transmission of the message data, the terminal can disguise the message data to be transmitted, so as to determine the disguised message data, so that the target tunnel can understand and process the message data to be transmitted.

[0071] Specifically, when the terminal performs the disguising of the message data, if the message data to be transmitted is IPV4 message data and the target tunnel is an IPV6 tunnel, the terminal can encapsulate the IPV4 message data into IPV6 message data, and then transmit the message data through the IPV6 tunnel. Similarly, when IPV6 message data is transmitted through an IPV4 tunnel, the terminal can encapsulate the IPV6 message into IPV4 message data, and then transmit the message data through the IPV4 message data.

[0072] Based on Figure 2 As shown in a data transmission method, by acquiring the network states of the IPV4 tunnel and the IPV6 tunnel, a target tunnel is selected from the IPV4 tunnel and the IPV6 tunnel. Then, the message data to be transmitted and the destination address of the message data are determined, and the encapsulation protocol of the message data is determined according to the destination address. It is judged whether the target tunnel matches the encapsulation protocol of the message data. If yes, the message data is transmitted to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the message data to the destination address after receiving the terminal identity verification pass instruction. If no, the encapsulation protocol corresponding to the target tunnel is determined, the message data is encapsulated again according to the encapsulation protocol corresponding to the target tunnel, the disguised message data is determined, the disguised message data is transmitted to the zero-trust gateway through the target tunnel, and the zero-trust gateway forwards the disguised message data to the destination address after receiving the terminal identity verification pass instruction.

[0073] In the above data transmission method, according to the network state of each tunnel, the tunnel used for data transmission is determined, and then the double stack technology is used to realize the transmission of IPV6 message through IPV4 tunnel and the transmission of IPV4 message data through IPV6 tunnel, so as to improve the network anti-interference ability of the user when using the zero-trust system and improve the transmission efficiency of the data.

[0074] Since the present scheme is applied to the scene of the zero-trust system, the zero-trust gateway will not receive and forward the message data before receiving the identity verification pass instruction, therefore, the terminal should first perform identity verification before transmitting the message data through the tunnel. The identity verification is generally completed by the zero-trust platform in the zero-trust system, of course, it can also be completed by the zero-trust gateway, which is not limited in the present specification, and can be set according to actual needs.

[0075] Specifically, if the zero-trust system includes a zero-trust platform, the terminal can further determine verification information in response to a user operation before determining the message data to be transmitted, the verification information being used to indicate the identity of the user and including at least one of an account password, biological information, and a secret key, so that the zero-trust platform verifies the identity of the user according to the received verification information. The verification result is sent to the zero-trust gateway, so that the zero-trust gateway determines whether to accept the message data sent by the client according to the verification result, further ensuring data security.

[0076] In addition, in step S202, when selecting the target tunnel, the terminal can further determine the score of each tunnel according to the determined network state. The better the network state, the higher the score. Then, the target tunnel is selected according to the score, so as to further improve the transmission efficiency of the message data. For example, the various parameters in the obtained network state are weighted to obtain the score of each tunnel. The score of the tunnel can also be realized by a trained model. Of course, in one or more embodiments of the present specification, it is not limited that the terminal specifically adopts which way to calculate the score. Since there are many methods to calculate the score, the present specification does not limit this, and the actual demand can be set.

[0077] In addition, in step S208, when determining the disguised message, in order to further improve the security of data transmission, the terminal can further encapsulate the message data to be transmitted into a new User Datagram Protocol (UDP) data packet, then encrypt the new UDP data packet to determine an encrypted message, so as to improve the confidentiality and integrity of the data, then generate a header of the new UDP data packet according to information such as the destination address of the data to be transmitted, and then encapsulate the UDP data packet containing the header into an IP message data. When encapsulating the new IP message data, the encapsulation protocol depends on the encapsulation protocol of the target tunnel. For example, when the encapsulation protocol corresponding to the target tunnel is IPV4, the encrypted message is re-encapsulated through the IPV4 protocol to determine the disguised message of the message data. Similarly, when the encapsulation protocol corresponding to the target tunnel is IPV6, the encrypted message is re-encapsulated through the IPV6 protocol to determine the disguised message of the message data.

[0078] This specification also provides an embodiment of a zero-trust system resource acquisition process. The zero-trust system includes a first terminal, a network interface card (NIC), a zero-trust platform, a zero-trust gateway, and a second terminal. A zero-trust client is installed on the terminal. When a user wants to acquire resource data at a destination address, the user first sends authentication information to the zero-trust platform through the zero-trust client. This authentication is used by the zero-trust platform to verify the client's identity. Upon successful authentication, the zero-trust platform sends an authentication pass command to the zero-trust gateway and simultaneously returns the authentication pass command to the client. Then, when the client sends a resource acquisition command to the zero-trust gateway, it determines the encapsulation protocol based on the target address of the resource and encapsulates the resource acquisition command into message data. Then, based on the network status of each tunnel, a target tunnel is selected, and the packet data is encapsulated into packet data that the target tunnel can understand. The packet data is then sent to the zero-trust gateway through the target tunnel. The zero-trust gateway decapsulates the packet data, determines the destination address of the packet data, recapsulates the packet data, and sends it to the second terminal. The second terminal decapsulates the packet data, obtains the resource acquisition instruction, determines the resource data to be transmitted according to the resource acquisition instruction, encapsulates the resource data to be transmitted, and sends the encapsulated resource data to the zero-trust gateway. The zero-trust gateway then forwards the encapsulated resource data to the first terminal. After the first terminal performs the decapsulation operation, it obtains the resource data.

[0079] like Figure 3 As shown, Figure 3 This is a schematic diagram of data transmission provided in this specification, in which there are two tunnels between the terminal and the gateway, and the message data transmitted in each tunnel consists of protocol-matched message data and disguised message data.

[0080] Based on the same idea as the data transmission method provided in one or more embodiments of this specification, this specification also provides a corresponding data transmission device, such as... Figure 4 As shown.

[0081] Figure 4 This is a schematic diagram of a data transmission device provided in this specification, specifically including:

[0082] The determining module 400 is used to determine the message data to be transmitted and the destination address of the message data, and to determine the encapsulation protocol of the message data based on the destination address;

[0083] The acquisition module 401 is used to acquire the network status of the IPv4 tunnel and the IPv6 tunnel, and select a target tunnel from the IPv4 tunnel and the IPv6 tunnel according to the network status;

[0084] The transmission module 402 is configured to determine whether the target tunnel matches the encapsulation protocol of the message data; if yes, the message data is transmitted to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the message data to the destination address after receiving the terminal identity verification pass instruction; if no, the encapsulation protocol corresponding to the target tunnel is determined, the message data is encapsulated again according to the encapsulation protocol corresponding to the target tunnel, the encapsulated message data is determined, the encapsulated message data is transmitted to the zero-trust gateway through the target tunnel, and the zero-trust gateway forwards the encapsulated message data to the destination address after receiving the terminal identity verification pass instruction.

[0085] Optionally, the device further comprises a verification module 403, which, in response to a user operation, determines verification information according to the operation, sends the identity verification information to the zero-trust platform, and enables the zero-trust platform to perform verification according to the verification information, returns a verification pass instruction when the verification is passed, and sends the verification pass instruction to the zero-trust gateway.

[0086] Optionally, the acquisition module 401 is specifically configured to send a detection signal to the zero-trust gateway through the IPV4 tunnel and the IPV6 tunnel at a preset frequency, and accept a detection result returned by the zero-trust gateway; and determine the network states of the IPV4 tunnel and the IPV6 tunnel according to the detection result of the most recent at least one time.

[0087] Optionally, the acquisition module 401 is configured to score the IPV4 tunnel and the IPV6 tunnel according to the network states of the IPV4 tunnel and the IPV6 tunnel acquired most recently; and select a target tunnel according to the scores.

[0088] Optionally, the acquisition module 401 is configured to determine whether the target tunnel is an IPV4 tunnel when the encapsulation protocol of the message data is IPV4; if yes, it is determined that the target tunnel matches the encapsulation protocol of the message data, and if no, it is determined that the target tunnel does not match the encapsulation protocol of the message data; and determine whether the target tunnel is an IPV6 tunnel when the encapsulation protocol of the message data is IPV6; if yes, it is determined that the target tunnel matches the encapsulation protocol of the message data, and if no, it is determined that the target tunnel does not match the encapsulation protocol of the message data.

[0089] Optionally, the acquisition module 401 is configured to encrypt the message data after encapsulating the message data through a user datagram protocol when the encapsulation protocol corresponding to the target tunnel is IPV4, to determine an encrypted message, and to re-encapsulate the encrypted message through the IPV4 protocol to determine the encapsulated message data of the message data.

[0090] When the target tunnel corresponds to an IPV6 encapsulation protocol, the message data is encapsulated by a user datagram protocol and then encrypted to determine an encrypted message, the encrypted message is re-encapsulated by the IPV6 protocol to determine a disguised message of the message data.

[0091] The specification also provides a computer readable storage medium storing a computer program, the computer program being used to execute the above Figure 2 The specification provides a data transmission method.

[0092] The specification also provides a computer readable storage medium storing a computer program, the computer program being used to execute the above Figure 5 The schematic structural diagram of the electronic device is shown. As shown in the figure, Figure 5 At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory and a non-volatile memory, and of course, other hardware required by the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs to realize the above Figure 1 The data transmission method.

[0093] Of course, in addition to the software implementation, the specification does not exclude other implementation manners, such as logic devices or software and hardware combined manner, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but also can be hardware or logic device.

[0094] In the 1990s, it was relatively easy to distinguish whether an improvement in a technology was a hardware improvement (e.g., an improvement in the circuit structure of a diode, transistor, switch, etc.) or a software improvement (an improvement in a method flow). However, as technology has evolved, many improvements in method flows today can be considered as direct improvements in hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structures by programming the improved method flows into hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming the PLD, rather than by ordering a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented using "logic compiler" software, which is similar to software compilers used in program development, and the original code to be compiled is written in a specific programming language, which is called a hardware description language (HDL), and there are many such languages, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should be aware that, as long as the method flow is logically programmed in the above-mentioned hardware description languages and programmed into an integrated circuit, a hardware circuit implementing the logical method flow can be easily obtained.

[0095] The controller can be implemented in any suitable way, for example, the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, such as software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20 and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that, in addition to being implemented in pure computer readable program code, the controller can equally well be implemented to perform the same functions using logic gates, switches, an application specific integrated circuit, a programmable logic controller and an embedded microcontroller, etc. by means of a logical programming of the method steps. The controller can thus be considered as a hardware component, and the means comprised therein for performing the various functions can be considered as structures within the hardware component. Alternatively, the means for performing the various functions can even be considered as both a software module implementing the method and a structure within the hardware component.

[0096] The systems, apparatuses, modules or units illustrated by the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0097] For the sake of description, the above apparatuses are described in various units by functions respectively. Of course, the functions of each unit can be implemented in one or more software and / or hardware in implementing the present specification.

[0098] Those skilled in the art will understand that the embodiments of the present specification can be provided as a method, a system or a computer program product. Therefore, the present specification can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present specification can take the form of a computer program product implemented on one or more computer usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0099] The specification is presented with reference to flow diagrams and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the specification. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing element or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more flow or multiple flows and / or blocks Figure 1 one or more flow or multiple flows and / or blocks

[0100] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more flow or multiple flows and / or blocks Figure 1 one or more flow or multiple flows and / or blocks

[0101] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more flow or multiple flows and / or blocks ​ one or more flow or multiple flows and / or blocks

[0102] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0103] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, non-volatile memory, such as read-only memory (ROM), EPROM, and / or flash memory, etc. The memory is an example of computer readable media.

[0104] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0105] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but can also include other elements not expressly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.

[0106] Those skilled in the art will appreciate that embodiments of the present specification can be provided as methods, systems or computer program products. Therefore, the present specification can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present specification can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0107] The present specification can be described in the general context of computer-executable instructions, such as program modules, executed by computers. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The present specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including storage devices.

[0108] The various embodiments described in this specification are described using a numbering of embodiments approach: these are each individually integrated contributions pertaining to different but related aspects of the description. Each of the various embodiments can stand on its own, and each can be combined with the subject matter of other embodiments to produce further embodiments. Where appropriate, therefore, the contents of the specification can be regarded as being incorporated by reference, including the description, drawings, claims, abstract and the like.

[0109] The above description is embodied in the form of embodiments only and is not intended to limit the present specification. The present specification can be variously changed and modified by those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification should be included in the scope of the claims of the present specification.

Claims

1. A data transmission method, characterized by, The method is applied to a terminal in a zero trust system, the zero trust system at least comprising the terminal and a zero trust gateway, and at least comprising an Internet Protocol version 4 (IPV4) tunnel and an Internet Protocol version 6 (IPV6) tunnel between the terminal and the zero trust gateway, comprising determining message data to be transmitted and a destination address of the message data, and determining an encapsulation protocol of the message data according to the destination address; obtaining network states of the IPV4 tunnel and the IPV6 tunnel, and selecting a target tunnel from the IPV4 tunnel and the IPV6 tunnel according to the network states; determining whether the target tunnel matches the encapsulation protocol of the message data; if yes, transmitting the message data to the zero trust gateway through the target tunnel, so that the zero trust gateway forwards the message data to the destination address after receiving a terminal identity verification pass instruction; if no, determining an encapsulation protocol corresponding to the target tunnel, re-encapsulating the message data according to the encapsulation protocol corresponding to the target tunnel, determining pseudo-encapsulated message data, transmitting the pseudo-encapsulated message data to the zero trust gateway through the target tunnel, and so that the zero trust gateway forwards the pseudo-encapsulated message data to the destination address after receiving the terminal identity verification pass instruction.

2. The method of claim 1, wherein, The zero trust system further comprises a zero trust platform, and before determining the message data to be transmitted, the method further comprises: in response to an operation of a user, determining verification information according to the operation; sending the verification information to the zero trust platform, so that the zero trust platform verifies according to the verification information, and returns a verification pass instruction when the verification passes, and sends the verification pass instruction to the zero trust gateway.

3. The method of claim 1, wherein, The method further comprises: sending detection signals to the zero trust gateway through the IPV4 tunnel and the IPV6 tunnel at a preset frequency, and accepting detection results returned by the zero trust gateway; determining network states of the IPV4 tunnel and the IPV6 tunnel according to at least one of the latest detection results.

4. The method of claim 1, wherein, The network states comprise at least one of connectivity states, delays, packet loss rates, and bandwidth utilization rates of the IPV4 tunnel and the IPV6 tunnel.

5. The method of claim 4, wherein, According to the network states, a target tunnel is selected from the IPV4 tunnel and the IPV6 tunnel, specifically comprising: scoring the IPV4 tunnel and the IPV6 tunnel according to the network states of the IPV4 tunnel and the IPV6 tunnel obtained last time; selecting a target tunnel according to the scores.

6. The method of claim 1, wherein, Determining whether the target tunnel matches the encapsulation protocol of the message data specifically comprises: when the encapsulation protocol of the message data is IPV4, determining whether the target tunnel is an IPV4 tunnel, if yes, it is indicated that the target tunnel matches the encapsulation protocol of the message data, and if no, it is indicated that the target tunnel does not match the encapsulation protocol of the message data. When the encapsulation protocol of the message data is IPV6, it is determined whether the target tunnel is an IPV6 tunnel. If yes, it indicates that the target tunnel matches the encapsulation protocol of the message data. If no, it indicates that the target tunnel does not match the encapsulation protocol of the message data.

7. The method of claim 1, wherein, According to the encapsulation protocol corresponding to the target tunnel, the message data is encapsulated again to determine the disguised message data, specifically including: When the encapsulation protocol corresponding to the target tunnel is IPV4, the message data is encapsulated by a user datagram protocol and then encrypted to determine an encrypted message. The encrypted message is re-encapsulated by the IPV4 protocol to determine the disguised message data of the message data. When the encapsulation protocol corresponding to the target tunnel is IPV6, the message data is encapsulated by a user datagram protocol and then encrypted to determine an encrypted message. The encrypted message is re-encapsulated by the IPV6 protocol to determine the disguised message data of the message data.

8. A data transmission apparatus, characterized by comprising: The device is used to implement a terminal in a zero-trust system. The zero-trust system at least includes the terminal and a zero-trust gateway. The terminal and the zero-trust gateway at least include an Internet Protocol version 4 (IPV4) tunnel and an Internet Protocol version 6 (IPV6) tunnel. The device includes: A determination module is configured to determine message data to be transmitted and a destination address of the message data, and determine an encapsulation protocol of the message data according to the destination address. An acquisition module is configured to acquire network states of the IPV4 tunnel and the IPV6 tunnel, and select a target tunnel from the IPV4 tunnel and the IPV6 tunnel according to the network states. A transmission module is configured to determine whether the target tunnel matches the encapsulation protocol of the message data. If yes, the message data is transmitted to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the message data to the destination address after receiving a terminal identity verification pass instruction. If no, an encapsulation protocol corresponding to the target tunnel is determined, the message data is encapsulated again according to the encapsulation protocol corresponding to the target tunnel to determine disguised message data, and the disguised message data is transmitted to the zero-trust gateway through the target tunnel, so that the zero-trust gateway forwards the disguised message data to the destination address after receiving the terminal identity verification pass instruction.

9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program. The computer program is executed by a processor to implement the method in any one of claims 1-7.

10. An electronic device, comprising: The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor implements the method in any one of claims 1-7 when executing the computer program.

Citation Information

Patent Citations

  • Data transmission method and device based on data center, medium and electronic equipment

    CN117354086A

  • Route selection method, network device, system, computer program product and medium

    CN117354234A