SIP (Session Initiation Protocol) signaling interaction method and system under strong network isolation environment
By encapsulating and hashing binding of data during SIP signaling interaction under a strong network isolation environment, the security and integrity issues during data transmission are solved, and the secure transmission of data and the reliability of signaling interaction is realized.
Patent Information
- Application Number
- CN202510149984.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In a strong network isolation environment, how to ensure the security and integrity of data during the transmission process during SIP signaling interaction and avoid data being tampered with or lost has become an important technical challenge.
By obtaining the signaling request sent by the request receiving end, analyzing and determining the signaling response information, data is encapsulated according to the predefined policy, a first hash value of the packaged data is generated, and it is cut and bound to send with the packaged data, so that the request sending end can splice and restore the data according to the hash value, ensuring the integrity and security of the data.
It realizes the secure transmission of data during SIP signaling interaction under a strong network isolation environment, ensuring that data is not tampered with or lost during transmission, and improving the security and reliability of signaling interaction.
Smart Images

Figure CN119995995A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field, and in particular to a SIP signaling interaction method and system in a strongly isolated network environment. Background Art
[0002] SIP (Session Initiation Protocol) is a signaling protocol widely used in communication systems. It has played an important role in many applications such as voice, video communication, and instant messaging. SIP signaling interaction involves two-way communication of requests and responses. In many scenarios, the security, reliability, and data integrity of the SIP protocol are key issues. Especially in a strongly isolated network environment, due to the isolation of the external network and possible malicious attacks, how to ensure the security and integrity of data during transmission during SIP signaling interaction and avoid data tampering or loss has become an important technical challenge. Summary of the invention
[0003] The present application provides a SIP signaling interaction method and system in a strong network isolation environment to solve the above problems.
[0004] In a first aspect, the present application provides a SIP signaling interaction method in a strong network isolation environment, the method comprising: Obtaining a signaling request sent by a request receiving end, analyzing the signaling request, and determining signaling response information; Encapsulating the signaling response information according to a predefined strategy to obtain packaged data; Analyze the packaged data to determine a first hash value of the packaged data; The first hash value and the packaged data are cut, bound and sent so that the request sending end can splice and restore the packaged data according to the first hash value to obtain the original signaling response information.
[0005] Through this solution, the signaling request sent by the request receiving end is obtained to ensure that the receiving end can understand the content and intention of the request. The request is analyzed to determine the signaling response information required for the request, and to prepare for subsequent interactions. The signaling response information is encapsulated according to the predefined strategy, which may include encryption, compression and other processing to reduce the data size and improve transmission efficiency and security. The encapsulated data (packaged data) is easy to transmit and increases the security of the data. The packaged data is hashed to generate a unique hash value to verify the integrity and security of the data. The hash value serves as a proof of data integrity to ensure that the data has not been tampered with during transmission. The hash value is bound to the packaged data to ensure that the hash value remains associated with the data during transmission. This binding relationship enables the receiving end to verify whether the received data is the same as the data at the sending end.
[0006] Optionally, binding the first hash value to the packaged data includes: Analyze the first Hash value to determine the number of bits of the Hash value; According to the number of bits, data mapping is performed between the first Hash value and the packaged data to determine a data volume ratio between the first Hash value and the packaged data; According to the data volume ratio, dynamically cut the mapped first hash value and the packaged data to obtain a plurality of cut hash fragments and a plurality of cut data fragments; For each hash fragment, the corresponding data fragment is determined and bound according to the result of data mapping.
[0007] Through this solution, determining the number of bits of the hash value helps with subsequent data mapping and cutting operations, ensuring that the hash value and data fragments can correctly correspond and match. The first hash value is data mapped with the packaged data to ensure that the length and structure of the hash value and the data can match, so as to facilitate subsequent dynamic cutting and binding operations. Through data mapping, the data volume ratio between the first hash value and the packaged data is determined to provide a basis for dynamic cutting. The mapped first hash value and packaged data are dynamically cut to decompose the data into smaller fragments, increase the complexity of data transmission, and improve security. For each hash fragment, the corresponding data fragment is determined according to the result of data mapping, and they are bound together to ensure that the original data can be correctly restored at the receiving end.
[0008] Optionally, for each hash fragment, determining and binding a corresponding data fragment according to a result of data mapping includes: Analyze the values corresponding to each hash fragment to determine whether there are at least two hash fragments whose values are completely consistent; If it exists, determine the same hash fragment based on the position of the value; Analyze the first hash value to determine the ranking of the same hash fragments; According to the ranking, marking the same hash segments respectively to distinguish the same hash segments; After distinguishing the same hash fragments, the corresponding data fragments are determined according to the result of data mapping and bound one by one.
[0009] Through this solution, the value of each hash fragment is analyzed to check whether there are repeated values. This analysis helps to identify possible data conflicts or errors and ensure the uniqueness and accuracy of the data. If repeated hash fragment values are found, their positions in the data stream are determined. This helps to track and record the order and position of the data fragments, providing a basis for subsequent recovery and reorganization. The first hash value is analyzed to determine the original ranking of the same hash fragment. The analysis of the ranking helps to understand the structure of the data and ensure that the data is kept in the correct order during transmission. The same hash fragments are marked to distinguish them during data transmission and recovery. The marking provides additional information to help the receiving end correctly identify and reorganize the data fragments. The result of the data mapping is used to determine the data fragment corresponding to each hash fragment. The correctness of the data fragments during transmission is ensured, laying the foundation for subsequent data recovery and verification. Each hash fragment is bound to its corresponding data fragment. The binding operation ensures the consistency and integrity of the data fragments during transmission and helps to correctly restore the original data at the receiving end.
[0010] Optionally, the cutting, binding and sending the hash value and the packaged data includes: According to the result of data mapping, corresponding data fragments are determined and bound one by one to obtain a plurality of first data packets; Dynamically combining a plurality of first data packets to obtain a first data group; Performing a hash calculation on the first data group to obtain a second hash value; The second hash value is combined with the first data group to obtain a plurality of second data packets and send them.
[0011] Through this solution, through data mapping, the data fragments corresponding to each hash fragment are determined, and they are bound together to form a first data packet. This helps to ensure that the original data can be correctly restored at the receiving end. The first data group is hashed to obtain a second hash value. The second hash value is used to verify the integrity and security of the first data group during transmission to prevent data tampering or loss. The second hash value is combined with the first data group to form a second data packet. The second data packet contains the original data and the hash value, which is used by the receiving end to verify the integrity and security of the data. The receiving end can verify the received second data packet, and when the data is found to be tampered or lost, the data transmission can be stopped immediately to reduce the amount of data leakage, and because only part of the data is leaked, it can be impossible for the thief to decipher.
[0012] Optionally, combining the second hash value with the first data group to obtain and send a plurality of second data packets includes: Determine the number of dynamic groups according to the first hash value; According to the number of dynamic groups, a number of second data packets are dynamically grouped to obtain and send a second data group.
[0013] Through this solution, the optimal number of data packets is determined by analyzing the characteristics of the first hash value. This helps to balance the efficiency and security of data transmission and ensure the integrity and security of data during transmission. According to the determined number of dynamic groups, the second data packet is dynamically grouped to form a second data group. This grouping can be performed according to the characteristics and requirements of the data, such as grouping according to the order of the data packets or specific rules to improve the efficiency of data transmission.
[0014] Optionally, determining the number of dynamic groups according to the first hash value includes: According to the result of the dynamic cutting, determining the number of segments of the plurality of data segments after cutting; Obtain the last two digits of the first hash value to obtain a verification value; Adding the verification values, and comparing the verification sum obtained by adding the verification values with the number of fragments to determine whether the verification sum is less than the number of fragments; If it is less than, the verification and determination are made as the dynamic group quantity; If it is greater, the verification is parsed to determine the verification and the ones and tens values; The ones digit value and the tens digit value are added to obtain a secondary verification sum, and the secondary verification sum is compared with the number of fragments until the sum is smaller than the number of fragments.
[0015] Through this scheme, the last two digits of the first hash value are extracted as the verification value, which will be used in subsequent operations to determine the number of dynamic groups, ensuring that each file transfer is dynamically changing, and avoiding the need for regular brute force cracking when data leakage occurs. Through simple mathematical operations, the size of the verification sum can preliminarily determine whether further grouping is needed. If the verification sum is less than the number of fragments, no further grouping is required. If the verification sum is less than the number of fragments, the verification sum is directly used as the number of dynamic groups, which can reduce the complexity of grouping and improve transmission efficiency. Through multiple parsing and addition operations, the size of the verification sum is gradually reduced until it is less than or equal to the number of fragments. This process ensures that the final number of dynamic groups can reasonably divide the data while maintaining the integrity and security of the data. At the same time, it can avoid the situation where the number of dynamic groups exceeds the number of fragments generated during cutting.
[0016] Optionally, dynamically grouping the plurality of second data packets according to the number of dynamic groups includes: According to the dynamic cutting result, determine the multi-digit value of each hash fragment after cutting; Calculate the sum of the multi-digit values of each hash fragment, and perform weight distribution according to each sum to obtain a weight distribution result; According to the weight distribution result, a plurality of second data packets are dynamically grouped.
[0017] Through this solution, a number of second data packets can be dynamically grouped according to the number of dynamic groups, thereby optimizing the efficiency and security of data transmission and ensuring the integrity and security of data during transmission.
[0018] In a second aspect, the present application provides a SIP signaling interaction method in a network strong isolation environment, characterized in that it is applied to a request sending end, including: Sending a signaling request to the request receiving end, and receiving data sent by the request receiving end that binds the first hash value to the packaged data; According to the first hash value, the packaged data is spliced and restored to obtain signaling response information.
[0019] In a third aspect, the present application provides a SIP signaling interaction system in a strong network isolation environment, characterized in that it is applied to a request receiving end and includes: A request analysis module, used to obtain a signaling request, analyze the signaling request, and determine signaling response information; A data encapsulation module, used to encapsulate the signaling response information according to a predefined strategy to obtain packaged data; A hash determination module, used for analyzing the packaged data and determining a first hash value of the packaged data; The sending module is used to cut, bind and send the first hash value and the packaged data so that the request sending end can splice and restore the packaged data according to the first hash value to obtain the original signaling response information.
[0020] Optionally, when the sending module binds the first hash value with the packaged data, it is used to: Analyze the first Hash value to determine the number of bits of the Hash value; According to the number of bits, data mapping is performed between the first Hash value and the packaged data to determine a data volume ratio between the first Hash value and the packaged data; According to the data volume ratio, dynamically cut the mapped first hash value and the packaged data to obtain a plurality of cut hash fragments and a plurality of cut data fragments; For each hash fragment, the corresponding data fragment is determined and bound according to the result of data mapping.
[0021] Optionally, when the sending module determines and binds the corresponding data fragment for each hash fragment according to the result of data mapping, it is used to: Analyze the values corresponding to each hash fragment to determine whether there are at least two hash fragments whose values are completely consistent; If it exists, determine the same hash fragment based on the position of the value; Analyze the first hash value to determine the ranking of the same hash fragments; According to the ranking, marking the same hash segments respectively to distinguish the same hash segments; After distinguishing the same hash fragments, the corresponding data fragments are determined according to the result of data mapping and bound one by one.
[0022] Optionally, when the sending module cuts, binds and sends the hash value and the packaged data, it is used to: According to the result of data mapping, corresponding data fragments are determined and bound one by one to obtain a plurality of first data packets; Dynamically combining a plurality of first data packets to obtain a first data group; Performing a hash calculation on the first data group to obtain a second hash value; The second hash value is combined with the first data group to obtain a plurality of second data packets and send them.
[0023] Optionally, when the sending module combines the second hash value with the first data group to obtain and send a plurality of second data packets, it is used to: Determine the number of dynamic groups according to the first hash value; According to the number of dynamic groups, a number of second data packets are dynamically grouped to obtain and send a second data group.
[0024] Optionally, when the sending module determines the number of dynamic groups according to the first hash value, it is used to: According to the result of the dynamic cutting, determining the number of segments of the plurality of data segments after cutting; Obtain the last two digits of the first hash value to obtain a verification value; Adding the verification values, and comparing the verification sum obtained by adding the verification values with the number of fragments to determine whether the verification sum is less than the number of fragments; If it is less than, the verification and determination are made as the number of dynamic groups; If it is greater, the verification is parsed to determine the verification and the ones and tens values; The ones digit value and the tens digit value are added to obtain a secondary verification sum, and the secondary verification sum is compared with the number of fragments until the sum is smaller than the number of fragments.
[0025] Optionally, when the sending module dynamically groups a plurality of second data packets according to the number of dynamic groups, it is used to: According to the dynamic cutting result, determine the multi-digit value of each hash fragment after cutting; Calculate the sum of the multi-digit values of each hash fragment, and perform weight distribution according to each sum to obtain a weight distribution result; According to the weight distribution result, a plurality of second data packets are dynamically grouped.
[0026] In a fourth aspect, the present application provides a SIP signaling interaction system in a strong network isolation environment, characterized in that when applied to a request sending end, it is used to: A transceiver module, used to send a signaling request to a request receiving end, and receive data sent by the request receiving end that binds the first hash value to the packaged data; A data splicing module is used to splice and restore the packaged data according to the first hash value to obtain signaling response information. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0028] Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application; Figure 2 A SIP signaling interaction method in a network strong isolation environment provided by an embodiment of the present application is applied to a flowchart of a request receiving end; Figure 3 A SIP signaling interaction method in a network strong isolation environment provided by an embodiment of the present application is applied to a flowchart of a request sending end; Figure 4 Another specific implementation process of a SIP signaling interaction method in a network strong isolation environment provided by an embodiment of the present application; Figure 5 A schematic diagram of the structure of a SIP signaling interaction system in a strongly isolated network environment provided by an embodiment of the present application; Figure 6 Another schematic diagram of the structure of a SIP signaling interaction system in a strongly isolated network environment is provided for an embodiment of the present application. DETAILED DESCRIPTION
[0029] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0030] In addition, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article, unless otherwise specified, generally means that the associated objects before and after are in an "or" relationship.
[0031] The embodiments of the present application are further described in detail below in conjunction with the drawings in the specification.
[0032] SIP (Session Initiation Protocol) is a signaling protocol widely used in communication systems. It has played an important role in many applications such as voice, video communication, and instant messaging. SIP signaling interaction involves two-way communication of requests and responses. In many scenarios, the security, reliability, and data integrity of the SIP protocol are key issues. Especially in a strongly isolated network environment, due to the isolation of the external network and possible malicious attacks, how to ensure the security and integrity of data during transmission during SIP signaling interaction and avoid data tampering or loss has become an important technical challenge.
[0033] Based on this, the present application provides a SIP signaling interaction method and system in a strong network isolation environment, which obtains a signaling request sent by a request receiving end, analyzes the signaling request, and determines the signaling response information; encapsulates the signaling response information according to a predefined strategy to obtain packaged data; analyzes the packaged data to determine the first hash value of the packaged data; cuts, binds and sends the first hash value with the packaged data so that the request sending end can splice and restore the packaged data according to the first hash value to obtain the original signaling response information. The signaling request sent by the request receiving end is obtained to ensure that the receiving end can understand the content and intention of the request. The request is analyzed to determine the signaling response information required for the request, and prepare for subsequent interactions. The signaling response information is encapsulated according to a predefined strategy, which may include encryption, compression and other processing to reduce the data size and improve transmission efficiency and security. The encapsulated data (packaged data) is easy to transmit and increases the security of the data. The packaged data is hashed to generate a unique hash value for verifying the integrity and security of the data. The hash value serves as a proof of data integrity to ensure that the data has not been tampered with during transmission. Binding the hash value to the packaged data ensures that the hash value and the data remain associated during transmission. This binding relationship enables the receiving end to verify whether the received data is the same as the data sent by the sender.
[0034] Figure 1 A schematic diagram of an application scenario provided by the present application is provided. When data is transmitted in a network isolation state to avoid data leakage or loss, the method provided by the present application is applied. Specifically, the method provided by the present application is applied to any server, which is a request receiving end, and interacts with the server of the request sending end to obtain the signaling request sent by the request receiving end, ensuring that the receiving end can understand the content and intention of the request. Analyze the request, determine the signaling response information required for the request, and prepare for subsequent interactions. Encapsulate the signaling response information according to a predefined strategy, which may include encryption, compression and other processing to reduce the data size and improve transmission efficiency and security. The encapsulated data (packed data) is easy to transmit and increases the security of the data. Hash calculation is performed on the packaged data to generate a unique hash value for verifying the integrity and security of the data. The hash value serves as a proof of data integrity to ensure that the data has not been tampered with during transmission. Bind the hash value to the packaged data to ensure that the hash value remains associated with the data during transmission. This binding relationship enables the receiving end to verify whether the received data is the same as the data of the sending end. The specific implementation method can refer to the following embodiments.
[0035] Figure 2This is a flowchart of a SIP signaling interaction method in a strongly isolated network environment provided by an embodiment of the present application. The method of this embodiment can be applied to the server at the request receiving end in the above scenario. Figure 2 As shown, the method includes: S201. Obtain a signaling request sent by a request receiving end, analyze the signaling request, and determine signaling response information.
[0036] The request receiving end may be the party that receives the request in network communication, and is responsible for processing the signaling request from the request sending end and generating corresponding signaling response information.
[0037] A signaling request may be information sent by a request sender to a request receiver in network communication, for requesting a specific service or operation.
[0038] The signaling response information may be a reply from the request receiving end to the signaling request sent by the request sending end, including the result of request processing, status information or other response content.
[0039] Specifically, since traditional SIP signaling is usually transmitted in plain text, it is vulnerable to attacks such as eavesdropping and tampering. During the transmission process, data may be illegally modified, and traditional verification mechanisms are often insufficient to resist complex attack methods. Therefore, the request receiving end needs to first obtain the SIP signaling request sent by the request sending end. The signaling request is analyzed, its content is understood, and the corresponding signaling response information is determined.
[0040] S202: Encapsulate the signaling response information according to a predefined strategy to obtain packaged data.
[0041] A predefined strategy can be a pre-set processing flow or method based on specific rules and conditions during the data processing process.
[0042] Data encapsulation can be the packaging of original data according to a specific format and structure for easy transmission and processing. The encapsulation process includes adding header information, tail information, checksum information, etc.
[0043] Packed data may be data that has been encapsulated and is ready for transmission.
[0044] Specifically, according to a predefined strategy, data encapsulation is performed on the determined signaling response information to obtain encapsulated packaged data.
[0045] S203: Analyze the packaged data to determine a first hash value of the packaged data.
[0046] The first hash value may be a unique value calculated by using a hash function on the packaged data.
[0047] Specifically, a hash calculation is performed on the encapsulated data (packed data) to generate a first hash value.
[0048] S204: Cut, bind and send the first hash value and the packaged data so that the request sending end can splice and restore the packaged data according to the first hash value to obtain the original signaling response information.
[0049] Cutting can be the process of dividing data or information into smaller parts or segments.
[0050] Binding is the act of associating a hash value with the packaged data, ensuring that they remain consistent during transmission.
[0051] The request sender may be the party that sends a request in network communication, and is responsible for generating a signaling request and sending it to the request receiver.
[0052] Splicing and restoration may be to reassemble the received packetized data fragments into the original signaling response information according to the hash value.
[0053] Specifically, the calculated first hash value is cut with the packaged data to obtain a plurality of hash segments and a plurality of data segments, and each hash segment is bound to a corresponding data segment. The bound content is sent to the request sending end, so that the request sending end splices and restores the packaged data according to the first hash value to obtain the original signaling response information.
[0054] Through this solution, the signaling request sent by the request receiving end is obtained to ensure that the receiving end can understand the content and intention of the request. The request is analyzed to determine the signaling response information required for the request, and to prepare for subsequent interactions. The signaling response information is encapsulated according to the predefined strategy, which may include encryption, compression and other processing to reduce the data size and improve transmission efficiency and security. The encapsulated data (packaged data) is easy to transmit and increases the security of the data. The packaged data is hashed to generate a unique hash value to verify the integrity and security of the data. The hash value serves as a proof of data integrity to ensure that the data has not been tampered with during transmission. The hash value is bound to the packaged data to ensure that the hash value remains associated with the data during transmission. This binding relationship enables the receiving end to verify whether the received data is the same as the data at the sending end.
[0055] In some embodiments, the first hash value is analyzed to determine the number of bits of the hash value; based on the number of bits, the first hash value and the packaged data are data mapped to determine the data volume ratio between the first hash value and the packaged data; based on the data volume ratio, the mapped first hash value and the packaged data are dynamically cut to obtain a number of hash fragments and a number of data fragments after cutting; for each hash fragment, the corresponding data fragment is determined and bound based on the result of the data mapping.
[0056] The number of bits can be the length of data or information, usually measured in bits.
[0057] Data mapping may be head-mapping of the data set of the first hash value and the data set of the packaged data according to a specific rule or format to ensure the consistency and validity of the data in subsequent calculation and transmission processes.
[0058] The data volume ratio may be the size relationship between the data set of the first hash value and the data set of the packaged data, which is usually expressed in the form of a percentage or a ratio.
[0059] Dynamic cutting can be the process of dividing data into segments of different sizes according to the length cutting requirements of equal proportion according to the quantity ratio of data. Since the cutting length is different in different data files, each data transmission is dynamic.
[0060] Hash fragmentation can be the process of splitting a hash value into multiple smaller parts or fragments.
[0061] Data fragmentation may be the division of the packetized data into multiple smaller parts or fragments.
[0062] The result of data mapping may be a mapping relationship between each hash segment and the corresponding data segment after dynamic cutting.
[0063] Specifically, the first hash value is analyzed, the length attribute of the hash value is checked or its length is calculated, and its length (number of bits) is determined. According to the number of bits of the first hash value, data mapping is performed on the first hash value and the packaged data. Through the division operation, it is determined how many hash fragments each data fragment corresponds to, so as to calculate the data volume ratio between the first hash value and the packaged data. According to the data volume ratio, the mapped first hash value and the packaged data are dynamically cut according to the data volume ratio to ensure that the cutting ratio of the packaged data is the same as the cutting ratio of the first hash value. For each cut hash fragment, according to the result of data mapping, a search and matching operation is performed to ensure that each hash fragment is correctly bound to its corresponding data fragment.
[0064] Through this solution, determining the number of bits of the hash value helps with subsequent data mapping and cutting operations, ensuring that the hash value and data fragments can correctly correspond and match. The first hash value is data mapped with the packaged data to ensure that the length and structure of the hash value and the data can match, so as to facilitate subsequent dynamic cutting and binding operations. Through data mapping, the data volume ratio between the first hash value and the packaged data is determined to provide a basis for dynamic cutting. The mapped first hash value and packaged data are dynamically cut to decompose the data into smaller fragments, increase the complexity of data transmission, and improve security. For each hash fragment, the corresponding data fragment is determined according to the result of data mapping, and they are bound together to ensure that the original data can be correctly restored at the receiving end.
[0065] In some embodiments, the numerical value corresponding to each hash fragment is analyzed to determine whether there are at least two hash fragments with completely identical numerical values; if so, the same hash fragment is determined based on the position of the numerical value; the first hash value is analyzed to determine the ranking of the same hash fragment; based on the ranking, the same hash fragments are marked separately to distinguish the same hash fragments; after distinguishing the same hash fragments, the corresponding data fragments are determined based on the results of data mapping and bound one by one.
[0066] The numerical value corresponding to the hash segment may be the specific value of each bit corresponding to the hash segment.
[0067] The position of the value may be the position of the value corresponding to the hash segment in the first hash value.
[0068] The same hash fragment may be a hash fragment with the same value as the first hash value. For example, the value corresponding to the first hash fragment in the SHA-256 hash value may be 1010 in binary, and the value corresponding to the second hash fragment may also be 1010.
[0069] The ranking may be the order and position of the hash fragments in the original hash value.
[0070] Specifically, after the first hash value is cut, the hash fragments may be repeated due to the short length, which may cause confusion in the splicing and restoration process. Therefore, each cut hash fragment is analyzed to determine its value and position. Check whether there are at least two hash fragments with exactly the same value. If there are hash fragments with exactly the same value, determine which are the same hash fragments according to their positions in the original hash value. Analyze the first hash value to determine the ranking of the same hash fragments in the original hash value. According to the ranking, the same hash fragments are marked by adding additional identifiers to the hash fragments or using different serial numbers to distinguish them. Use the results of the data mapping to perform search and matching operations to ensure that each hash fragment corresponds correctly to its corresponding data fragment. Bind each marked hash fragment to its corresponding data fragment. The binding operation can ensure that each hash fragment and its corresponding data fragment can be correctly identified and processed during data transmission and recovery.
[0071] Through this solution, the value of each hash fragment is analyzed to check whether there are repeated values. This analysis helps to identify possible data conflicts or errors and ensure the uniqueness and accuracy of the data. If repeated hash fragment values are found, their positions in the data stream are determined. This helps to track and record the order and position of the data fragments, providing a basis for subsequent recovery and reorganization. The first hash value is analyzed to determine the original ranking of the same hash fragment. The analysis of the ranking helps to understand the structure of the data and ensure that the data is kept in the correct order during transmission. The same hash fragments are marked to distinguish them during data transmission and recovery. The marking provides additional information to help the receiving end correctly identify and reorganize the data fragments. The result of the data mapping is used to determine the data fragment corresponding to each hash fragment. The correctness of the data fragments during transmission is ensured, laying the foundation for subsequent data recovery and verification. Each hash fragment is bound to its corresponding data fragment. The binding operation ensures the consistency and integrity of the data fragments during transmission and helps to correctly restore the original data at the receiving end.
[0072] In some embodiments, based on the results of data mapping, corresponding data fragments are determined and bound one by one to obtain several first data packets; the several first data packets are dynamically combined to obtain a first data group; a hash calculation is performed on the first data group to obtain a second hash value; the second hash value is combined with the first data group to obtain several second data packets and send them.
[0073] The first data packet may be an independent data unit formed by binding the hash fragment with the corresponding data fragment.
[0074] Dynamic combination can be to flexibly combine multiple data units (such as the first data packet) according to needs during the data transmission process. During the transmission of different file data, the combination state can be dynamically changed according to the set rules.
[0075] The second hash value may be a hash value obtained by performing a hash calculation on the first data group.
[0076] Specifically, according to the number of bits of the hash value, data mapping is performed on the hash value and the packaged data to ensure that the lengths of the two are consistent. According to the result of the data mapping, the data fragment corresponding to each hash fragment is determined. Each hash fragment is bound to its corresponding data fragment to form several first data packets. Several first data packets are dynamically combined according to the order of the data packets or specific rules to form several first data groups. Hash calculation is performed on each first data group to obtain the corresponding second hash value. The second hash value is used to verify the integrity and security of the first data group during transmission. The second hash value is combined with the first data group to form several second data packets. The second data packet contains the original data and the hash value, which is used to verify the integrity and security of the data. The combined second data packet is sent to the receiving end. The receiving end can verify the received second data packet to ensure the integrity and security of the data.
[0077] Through this solution, through data mapping, the data fragments corresponding to each hash fragment are determined, and they are bound together to form a first data packet. This helps to ensure that the original data can be correctly restored at the receiving end. The first data group is hashed to obtain a second hash value. The second hash value is used to verify the integrity and security of the first data group during transmission to prevent data tampering or loss. The second hash value is combined with the first data group to form a second data packet. The second data packet contains the original data and the hash value, which is used by the receiving end to verify the integrity and security of the data. The receiving end can verify the received second data packet, and when the data is found to be tampered or lost, the data transmission can be stopped immediately to reduce the amount of data leakage, and because only part of the data is leaked, it can be impossible for the thief to decipher.
[0078] In some embodiments, the second hash value is combined with the first data group to obtain and send several second data packets, including: determining the number of dynamic groups based on the first hash value; dynamically grouping the several second data packets based on the dynamic group number to obtain and send the second data group.
[0079] The dynamic group quantity may be the number of data packets dynamically determined according to a preset rule during the data transmission process.
[0080] Dynamic grouping can be the flexible combination and reorganization of data units according to preset rules during data transmission.
[0081] Specifically, the characteristics of the first hash value, such as the length and distribution of the hash value, are analyzed to determine the number of dynamic groups. The purpose of this step is to optimize the efficiency and security of data transmission and ensure the integrity and security of data during transmission. According to the determined number of dynamic groups, the second data packet is dynamically grouped to form a second data group. The data packets can be grouped according to the order of the data packets or specific rules to improve the efficiency of data transmission. The combined second data group is sent to the receiving end. The receiving end can verify the received second data group to ensure the integrity and security of the data.
[0082] Through this solution, the optimal number of data packets is determined by analyzing the characteristics of the first hash value. This helps to balance the efficiency and security of data transmission and ensure the integrity and security of data during transmission. According to the determined number of dynamic groups, the second data packet is dynamically grouped to form a second data group. This grouping can be performed according to the characteristics and requirements of the data, such as grouping according to the order of the data packets or specific rules to improve the efficiency of data transmission.
[0083] In some embodiments, the number of dynamic groups is determined based on the first hash value, including: determining the number of fragments of a number of data fragments after cutting based on the result of dynamic cutting; obtaining the two last digits of the first hash value to obtain a verification value; adding the verification values, and comparing the verification sum obtained by the addition with the number of fragments to determine whether the verification sum is less than the number of fragments; if less than, determining the verification sum as the number of dynamic groups; if greater, parsing the verification to determine the ones and tens digits of the verification sum; adding the ones and tens digits to obtain a secondary verification sum, and comparing the secondary verification sum with the number of fragments until it is less than the number of fragments.
[0084] The number of segments may be the number of independent data units into which the data is divided during the dynamic segmentation of the data.
[0085] The last two digits may be the last two digits extracted from the hash value.
[0086] The verification sum may be a value obtained by adding the last two digits of the hash value.
[0087] Parsing the proof may be the process of breaking the proof sum into units and tens values.
[0088] Specifically, when a decimal hash value is used, first, the original data is dynamically cut and the data is divided into several small data fragments. The total number of data fragments after cutting is calculated, which will be used as a benchmark in subsequent steps. The last two digits are extracted from the first hash value, and these digits will be used as preliminary verification values. The two digits in the verification value are added to obtain a verification sum. The verification sum is compared with the number of data fragments after cutting. If the verification sum is less than the number of fragments, the verification sum is directly used as the number of dynamic groups. If the verification sum is greater than the number of fragments, the verification sum needs to be further parsed and decomposed into the ones digit value and the tens digit value. The ones digit value and the tens digit value are added to obtain a new verification sum (secondary verification sum). The new verification sum is compared with the number of fragments until a verification sum less than or equal to the number of fragments is found. Once a verification sum less than or equal to the number of fragments is found, this value is used as the final number of dynamic groups, and there will be no vacant dynamic group number, which consumes transmission bandwidth.
[0089] Through this scheme, the last two digits of the first hash value are extracted as the verification value, which will be used in subsequent operations to determine the number of dynamic groups, ensuring that each file transfer is dynamically changing, and avoiding the need for regular brute force cracking when data leakage occurs. Through simple mathematical operations, the size of the verification sum can preliminarily determine whether further grouping is needed. If the verification sum is less than the number of fragments, no further grouping is required. If the verification sum is less than the number of fragments, the verification sum is directly used as the number of dynamic groups, which can reduce the complexity of grouping and improve transmission efficiency. Through multiple parsing and addition operations, the size of the verification sum is gradually reduced until it is less than or equal to the number of fragments. This process ensures that the final number of dynamic groups can reasonably divide the data while maintaining the integrity and security of the data. At the same time, it can avoid the situation where the number of dynamic groups exceeds the number of fragments generated during cutting.
[0090] In some embodiments, based on the dynamic cutting result, the multi-digit value of each hash fragment after cutting is determined; the sum of the multi-digit values of each hash fragment is calculated, and weight distribution is performed based on each sum to obtain a weight distribution result; based on the weight distribution result, a number of second data packets are dynamically grouped.
[0091] A multi-bit value may be a number contained in each data unit in a hash segment.
[0092] The sum of the multi-bit values may be the sum obtained by adding all the multi-bit values in the hash fragment.
[0093] The weight assignment may be to assign a weight value to each hash fragment according to the sum of a multi-bit value.
[0094] Specifically, by cutting the hash fragments, the multi-digit values in each fragment are extracted. This step is to obtain the specific value of each hash fragment for subsequent weight allocation and dynamic grouping. Calculate the sum of the multi-digit values in each hash fragment, and then allocate weights based on these sums. For example, the sum of the values is calculated based on the order of the hash fragments, and the sum of the values of the fragments that are redundant with the number of dynamic groups is discarded. Each time the number of fragments in a group is calculated, the sum of the values of the dynamic group is discarded, so as to calculate the sum of the values of each fragment that accounts for all the remaining fragments, so as to perform weight allocation, and in the process, ensure that there is at least one fragment in each dynamic group, and there will be no vacant dynamic groups. The weight allocation result will determine the importance of each hash fragment in the dynamic grouping, thereby affecting the grouping method of the data packet. According to the weight allocation result, the second data packet is dynamically grouped. When grouping, the ownership of the data packet will be determined based on the weight of each hash fragment to ensure the reasonable distribution and priority of the data packet during transmission. This dynamic grouping can improve the flexibility and efficiency of data transmission while ensuring the integrity and security of the data.
[0095] Through this solution, a number of second data packets can be dynamically grouped according to the number of dynamic groups, thereby optimizing the efficiency and security of data transmission and ensuring the integrity and security of data during transmission.
[0096] Figure 3 The flowchart of a SIP signaling interaction method in a network strong isolation environment provided by an embodiment of the present application is as follows. The method of this embodiment can be applied to the server at the request sending end in the above scenario. Figure 3 As shown, the method includes: S301. Send a signaling request to a request receiving end, and receive data sent by the request receiving end that binds a first hash value with packaged data.
[0097] S302. According to the first hash value, the packaged data is spliced and restored to obtain signaling response information.
[0098] Figure 4 The flowchart of a SIP signaling interaction method in a strongly isolated network environment provided by an embodiment of the present application is as follows. The method of this embodiment can be applied to the server at the request sending end and the server at the request receiving end in the above scenario. Figure 4 As shown, the method includes: S401: The request sending end sends a signaling request to the request receiving end.
[0099] S402, the request receiving end analyzes the signaling request and determines the signaling response information; encapsulates the signaling response information according to a predefined strategy to obtain packaged data; analyzes the packaged data and determines the first hash value of the packaged data; cuts and binds the first hash value and the packaged data and sends the value request sending end.
[0100] S403. The request sending end receives data that binds the first hash value and the packaged data and sends it from the request receiving end; and according to the first hash value, the packaged data is spliced and restored to obtain signaling response information.
[0101] Figure 5 A schematic diagram of the structure of a SIP signaling interaction system in a network strong isolation environment provided by an embodiment of the present application is shown in FIG. Figure 5 As shown, the SIP signaling interaction system 500 in the network strong isolation environment of this embodiment includes: a request analysis module 501, a data encapsulation module 502, a hash determination module 503, and a sending module 504.
[0102] The request analysis module 501 is used to obtain a signaling request, analyze the signaling request, and determine signaling response information; The data encapsulation module 502 is used to encapsulate the signaling response information according to a predefined strategy to obtain packaged data; A hash determination module 503, configured to analyze the packaged data and determine a first hash value of the packaged data; The sending module 504 is used to cut, bind and send the first hash value and the packaged data so that the request sending end can splice and restore the packaged data according to the first hash value to obtain the original signaling response information.
[0103] Optionally, when the sending module 504 binds the first hash value with the packaged data, it is used to: Analyze the first Hash value to determine the number of bits of the Hash value; According to the number of bits, data mapping is performed between the first Hash value and the packaged data to determine a data volume ratio between the first Hash value and the packaged data; According to the data volume ratio, dynamically cut the mapped first hash value and the packaged data to obtain a plurality of cut hash fragments and a plurality of cut data fragments; For each hash fragment, the corresponding data fragment is determined and bound according to the result of data mapping.
[0104] Optionally, when the sending module 504 determines and binds the corresponding data fragment for each hash fragment according to the result of data mapping, it is used to: Analyze the values corresponding to each hash fragment to determine whether there are at least two hash fragments whose values are completely consistent; If it exists, determine the same hash fragment based on the position of the value; Analyze the first hash value to determine the ranking of the same hash fragments; According to the ranking, marking the same hash segments respectively to distinguish the same hash segments; After distinguishing the same hash fragments, the corresponding data fragments are determined according to the result of data mapping and bound one by one.
[0105] Optionally, when the sending module 504 cuts, binds and sends the hash value and the packaged data, it is used to: According to the result of data mapping, corresponding data fragments are determined and bound one by one to obtain a plurality of first data packets; Dynamically combining a plurality of first data packets to obtain a first data group; Performing a hash calculation on the first data group to obtain a second hash value; The second hash value is combined with the first data group to obtain a plurality of second data packets and send them.
[0106] Optionally, when the sending module 504 combines the second hash value with the first data group to obtain and send a plurality of second data packets, it is used to: Determine the number of dynamic groups according to the first hash value; According to the number of dynamic groups, a number of second data packets are dynamically grouped to obtain and send a second data group.
[0107] Optionally, when the sending module 504 determines the number of dynamic groups according to the first hash value, it is used to: According to the result of the dynamic cutting, determining the number of segments of the plurality of data segments after cutting; Obtain the last two digits of the first hash value to obtain a verification value; Adding the verification values, and comparing the verification sum obtained by adding the verification values with the number of fragments to determine whether the verification sum is less than the number of fragments; If it is less than, the verification and determination are made as the dynamic group quantity; If it is greater, the verification is parsed to determine the verification and the ones and tens values; The ones digit value and the tens digit value are added to obtain a secondary verification sum, and the secondary verification sum is compared with the number of fragments until the sum is smaller than the number of fragments.
[0108] Optionally, when the sending module 504 dynamically groups a plurality of second data packets according to the number of dynamic groups, it is configured to: According to the dynamic cutting result, determine the multi-digit value of each hash fragment after cutting; Calculate the sum of the multi-digit values of each hash fragment, and perform weight distribution according to each sum to obtain a weight distribution result; According to the weight distribution result, a plurality of second data packets are dynamically grouped.
[0109] The system of this embodiment can be used to execute the method of any embodiment corresponding to the request receiving end described above. The implementation principle and technical effects are similar and will not be described in detail here.
[0110] Figure 6 A structural diagram of another SIP signaling interaction system in a strong network isolation environment provided by an embodiment of the present application is as follows: Figure 6 As shown, the SIP signaling interaction system 600 in the network strong isolation environment of this embodiment includes: a transceiver module 601 and a data splicing module 602.
[0111] The transceiver module 601 is used to send a signaling request to the request receiving end, and receive data sent by the request receiving end that binds the first hash value with the packaged data; The data splicing module 602 is used to splice and restore the packaged data according to the first hash value to obtain signaling response information.
[0112] The system of this embodiment can be used to execute the method of any embodiment corresponding to the request sending end. The implementation principle and technical effect are similar and will not be described in detail here.
Claims
1. A SIP signaling interaction method in a strong network isolation environment, characterized in that: Applicable to the request receiving end, including: Obtaining a signaling request sent by a request receiving end, analyzing the signaling request, and determining signaling response information; Encapsulating the signaling response information according to a predefined strategy to obtain packaged data; Analyze the packaged data to determine a first hash value of the packaged data; The first hash value and the packaged data are cut, bound and sent so that the request sending end can splice and restore the packaged data according to the first hash value to obtain the original signaling response information.
2. The method according to claim 1, characterized in that The step of binding the first hash value to the packaged data comprises: Analyze the first Hash value to determine the number of bits of the Hash value; According to the number of bits, data mapping is performed between the first Hash value and the packaged data to determine a data volume ratio between the first Hash value and the packaged data; According to the data volume ratio, dynamically cut the mapped first hash value and the packaged data to obtain a plurality of cut hash fragments and a plurality of cut data fragments; For each hash fragment, the corresponding data fragment is determined and bound according to the result of data mapping.
3. The method according to claim 2, characterized in that For each hash fragment, determining and binding the corresponding data fragment according to the result of data mapping includes: Analyze the values corresponding to each hash fragment to determine whether there are at least two hash fragments whose values are completely consistent; If it exists, determine the same hash fragment based on the position of the value; Analyze the first hash value to determine the ranking of the same hash fragments; According to the ranking, marking the same hash segments respectively to distinguish the same hash segments; After distinguishing the same hash fragments, the corresponding data fragments are determined according to the result of data mapping and bound one by one.
4. The method according to claim 3, characterized in that The step of cutting, binding and sending the hash value and the packaged data comprises: According to the result of data mapping, corresponding data fragments are determined and bound one by one to obtain a plurality of first data packets; Dynamically combining a plurality of first data packets to obtain a first data group; Performing a hash calculation on the first data group to obtain a second hash value; The second hash value is combined with the first data group to obtain a plurality of second data packets and send them.
5. The method according to claim 4, characterized in that The combining the second hash value with the first data group to obtain a plurality of second data packets and sending the second data packets comprises: Determine the number of dynamic groups according to the first hash value; According to the number of dynamic groups, a number of second data packets are dynamically grouped to obtain and send a second data group.
6. The method according to claim 5, characterized in that The step of determining the number of dynamic groups according to the first hash value includes: According to the result of the dynamic cutting, determining the number of segments of the plurality of data segments after cutting; Obtain the last two digits of the first hash value to obtain a verification value; Adding the verification values, and comparing the verification sum obtained by adding the verification values with the number of fragments to determine whether the verification sum is less than the number of fragments; If it is less than, the verification and determination are made as the number of dynamic groups; If it is greater, the verification is parsed to determine the verification and the ones and tens values; The ones digit value and the tens digit value are added to obtain a secondary verification sum, and the secondary verification sum is compared with the number of fragments until the sum is smaller than the number of fragments.
7. The method according to claim 5, characterized in that The step of dynamically grouping the plurality of second data packets according to the number of dynamic groups includes: According to the dynamic cutting result, determine the multi-digit value of each hash fragment after cutting; Calculate the sum of the multi-digit values of each hash fragment, and perform weight distribution according to each sum to obtain a weight distribution result; According to the weight distribution result, a plurality of second data packets are dynamically grouped.
8. A SIP signaling interaction method in a network strong isolation environment, characterized in that: Applicable to the request sender, including: Sending a signaling request to the request receiving end, and receiving data sent by the request receiving end that binds the first hash value to the packaged data; According to the first hash value, the packaged data is spliced and restored to obtain signaling response information.
9. A SIP signaling interaction system in a strong network isolation environment, characterized in that: Applicable to the request receiving end, including: A request analysis module, used to obtain a signaling request, analyze the signaling request, and determine signaling response information; A data encapsulation module, used to encapsulate the signaling response information according to a predefined strategy to obtain packaged data; A hash determination module, used for analyzing the packaged data and determining a first hash value of the packaged data; The sending module is used to cut, bind and send the first hash value and the packaged data so that the request sending end can splice and restore the packaged data according to the first hash value to obtain the original signaling response information.
10. A SIP signaling interaction system in a strong network isolation environment, characterized in that: Applicable to the request sender, including: A transceiver module, used to send a signaling request to a request receiving end, and receive data sent by the request receiving end that binds the first hash value to the packaged data; A data splicing module is used to splice and restore the packaged data according to the first hash value to obtain signaling response information.