Data transmission protection system and method based on communication state
By introducing a communication status-based protection mechanism in the data transmission system, the data transmission speed reduction caused by the cloud-based synchronous cache occupies transmission channels is solved, and more efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510142770.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-16
AI Technical Summary
In the prior art, when data is cached in the cloud synchronously, it is necessary to occupy the transmission channel of the normal transmission system, resulting in a decrease in the data transmission speed.
The data transmission protection system based on communication status is adopted, including the communication status monitoring module, analysis and decision-making module, protection execution module, data cache module, encryption and decryption module and identity authentication module. By monitoring the status of the communication link in real time, analyzing decisions and executing protection measures, dynamically adjusting the transmission strategy, reducing the interference of synchronization in the cloud to the main data transmission.
It effectively reduces data transmission delay, improves data processing efficiency, reduces security risks during data transmission, and provides a more reliable and efficient network communication solution.
Smart Images

Figure CN120017346A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and in particular to a data transmission protection system and method based on communication status. Background Art
[0002] The data transmission protection system is a system used to ensure the security and integrity of data during transmission. In the current digital age, data transmission is ubiquitous. Whether it is transmitted between different devices through the network or in cloud storage environments, data flows face many risks.
[0003] In the existing technology, the system mainly works through a variety of technical means. For example, encryption technology is used to convert data into ciphertext for transmission. Only a specific recipient can decrypt and restore it using a key to prevent the data from being stolen and then directly read. At the same time, it can also perform data integrity verification, compare data before and after transmission, and identify whether the data has been tampered with. In addition, the system will also provide access control functions to perform security authentication on the transmission link to ensure that only legitimate users and devices can participate in data transmission.
[0004] However, in the actual data transmission and caching process, cloud-based synchronous caching of data often requires occupying the transmission channel of the current normal transmission system. Therefore, when the total transmission speed is constant, the normal transmission of data will be affected, thereby reducing its transmission speed. In view of this, we propose a data transmission protection system and method based on communication status. Summary of the invention
[0005] In view of the deficiencies in the prior art, the present invention provides a data transmission protection system and method based on communication status, which solves the problem that cloud synchronization caching of data often requires occupying the transmission channel of the current normal transmission system, thereby reducing the transmission speed during normal data transmission.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a data transmission protection system and method based on communication status, including the following modules:
[0007] Communication status monitoring module: used to monitor the communication link status of data transmission in real time, including network delay, bandwidth utilization, packet loss rate, and signal strength parameters.
[0008] Analysis and decision-making module: used to receive the communication status data from the communication status monitoring module, and conduct comprehensive analysis based on the preset security policies and performance thresholds.
[0009] Protection execution module: used to perform specific protection operations according to the instructions of the analysis and decision module.
[0010] Data cache module: used to temporarily store data to be transmitted and received data during the data transmission process, and to synchronize part of the data to be transmitted with the cloud.
[0011] Encryption and decryption module: used to encrypt the data to be transmitted, and select the corresponding encryption strategy according to the importance and sensitivity of the data.
[0012] Identity authentication module: used to authenticate both ends of data transmission, using a mechanism that combines multiple authentication methods including digital certificates, username and password, and biometric identification to ensure the authenticity and legitimacy of the identities of the source and destination of data transmission.
[0013] Preferably, the communication status monitoring module adopts a distributed monitoring architecture and deploys monitoring sub-nodes at key nodes of the network, including core switches and border routers. These sub-nodes independently collect local communication status data and transmit the data to the central analysis node through a distributed data aggregation and synchronization mechanism.
[0014] Preferably, the machine learning algorithm in the analysis and decision-making module adopts a deep neural network model, which takes the multi-dimensional communication status data obtained by the communication status monitoring module as input, and outputs corresponding protection strategy recommendations through feature extraction and pattern recognition of multiple layers of neurons. The training process of the deep neural network model adopts an adaptive learning rate adjustment algorithm, which dynamically optimizes the learning rate according to the convergence of the training error to improve the training efficiency and accuracy of the model.
[0015] Preferably, the protection execution module adopts a dynamic adaptive protection strategy, and based on the monitoring and analysis of real-time communication status parameters including network delay, packet loss rate, and bandwidth utilization, the system automatically and dynamically adjusts the data transmission protection strategy.
[0016] Preferably, the data cache module includes a data prediction module, a data queue module, a multi-path transmission module and a summary storage module. The data prediction module is used to analyze historical data transmission patterns and user behavior data, build a prediction model, predict in advance the data that the user may need, and automatically pre-fetch data to the local cache when the communication link is idle or under load. The data queue module is used to allocate corresponding cache queues for data waiting to be cached and temporarily store the data waiting to be cached.
[0017] Preferably, the multi-path transmission module dynamically allocates the transmission ratio of the current main data transmission path and the transmission ratio during the cloud data synchronization process based on the network topology and the real-time communication status of each link, and supports manual input of weighted parameters to adjust the transmission ratio. The summary storage module is used to finally summarize and store the data transmitted by the multi-path transmission module.
[0018] Preferably, the encryption / decryption module uses a hybrid encryption strategy that combines a chaotic encryption algorithm with a traditional encryption algorithm in the process of selecting the encryption algorithm and generating the key. The chaotic encryption algorithm generates a pseudo-random sequence as part of the encryption key or disrupts the traditional encryption key based on a specific chaotic mapping function. The parameters of the chaotic mapping function are dynamically adjusted according to the network security indicators provided by the communication status monitoring module.
[0019] The data transmission protection method based on communication status includes the following steps:
[0020] S1: Communication status monitoring steps
[0021] Start the communication status monitoring module, use a variety of detection methods to obtain the communication link status parameters in the data transmission process in real time, and store and organize them in time series to form communication status data records. The detection methods include multi-protocol monitoring and in-depth analysis;
[0022] S2: Analytical decision-making steps
[0023] The analysis and decision-making module reads the communication status data records, compares and analyzes the current communication status parameters with the preset security policies and performance thresholds, and determines whether the communication status is normal. If abnormal, it determines the protection measures based on the predefined decision rules and intelligent decision-making driven by machine learning. Strategy simulation and evaluation can be performed before decision-making, and multi-strategy fusion and dynamic adjustment are supported;
[0024] S3: Protection execution steps
[0025] The protection execution module receives protection measures instructions and performs corresponding protection operations according to the instructions, including link switching, rate adjustment, encryption enhancement and other operations using a modular protection component architecture, and has hardware acceleration and offloading support capabilities as well as cross-platform and heterogeneous network adaptation capabilities;
[0026] S4: Data caching and recovery steps
[0027] The data cache module continuously caches data during data transmission. When the communication status is abnormal and the transmission is interrupted, the data status is saved. After the communication is restored to normal, the protection execution module resumes data transmission based on the cached data status information. The data cache module adopts a multi-level cache architecture and intelligent cache management, and has cache data redundancy and verification and repair functions as well as a cache and transmission collaborative optimization mechanism;
[0028] S5: Encryption and decryption steps
[0029] At the data sending end, encryption algorithms and keys are selected to encrypt data according to the importance and sensitivity of the data. The receiving end uses the corresponding decryption key and algorithm for decryption. The encryption algorithm library can be dynamically updated and adaptively selected, and has encryption key management and dynamic update mechanisms. At the same time, there is pre-research and integration preparation for quantum encryption technology;
[0030] S6: Identity authentication step
[0031] Before data transmission is established, the identity authentication module uses a multimodal fusion authentication method based on digital certificates, usernames and passwords, and biometrics to authenticate both ends of the data transmission. It combines a blockchain-based identity authentication and trust management system with a context-aware identity authentication enhancement mechanism to regularly review the identity during the transmission process.
[0032] Preferably, in the S5 encryption and decryption step, a cache replacement algorithm based on data heat prediction is adopted in cache data management before data caching. The algorithm analyzes the access history of the data by building a model, predicts the access probability of the data in a future period of time as a data heat index, and sorts and replaces the data in the cache according to the heat index, giving priority to retaining high-heat data in the cache.
[0033] Preferably, the S6 identity authentication step uses a weighted feature fusion algorithm in the biometric multimodal fusion authentication process, and assigns a dynamic weight to each biometric feature based on the differences in accuracy, stability and anti-counterfeiting. The weight is adjusted based on the network risk level monitored by the communication status monitoring module and the user's historical authentication behavior analysis results. The matching scores of multiple biometric features are fused by weighted summation to obtain the final authentication decision result.
[0034] The present invention provides a data transmission protection system and method based on communication status.
[0035] Beneficial effects:
[0036] 1. The present invention can effectively reduce data transmission delay and improve data processing efficiency through the data prediction module and the multi-path transmission module in the data cache module. The data prediction module uses advanced algorithms to predict data access patterns, thereby preparing data in advance to ensure that data can be quickly accessed when needed; the multi-path transmission module dynamically allocates the transmission ratio of the current main data transmission path and the transmission ratio in the cloud data synchronization process according to the input or default processing strategy, thereby avoiding the cloud data synchronization process from causing significant interference to the main data transmission process.
[0037] 2. The present invention establishes a dynamic adaptive protection strategy in the protection execution module. Based on the monitoring and analysis of real-time communication status parameters including network delay, packet loss rate, and bandwidth utilization, the system can automatically and dynamically adjust the data transmission protection strategy and execute the corresponding protection strategy according to the calculated adjustment parameters, thereby effectively reducing the security risks in the data transmission process. Through this mechanism, the present invention not only improves the security of data transmission, but also ensures the transmission efficiency, providing users with a more reliable and efficient network communication solution.
[0038] 3. Through the S6 identity authentication step, the present invention can assign dynamic weights to each biometric feature according to the differences in accuracy, stability and anti-counterfeiting, thereby achieving more accurate and secure identity authentication. The use of weighted feature fusion algorithm enables the authentication process to be intelligently adjusted according to the network risk level and user historical behavior, thereby ensuring the security of authentication while also improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 This is the module diagram of the data transmission protection system based on communication status;
[0040] Figure 2 It is a schematic diagram of a data cache module of the present invention;
[0041] Figure 3 The data cache module of the present invention is executed as a flow chart;
[0042] Figure 4 This is a flow chart of the data transmission protection method based on communication status;
[0043] Figure 5 This is an authentication flow chart of the identity authentication step of the present invention. DETAILED DESCRIPTION
[0044] The following will be combined with the drawings in the specification of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0045] Example:
[0046] Please see attached Figure 1 - Attachment Figure 3 , an embodiment of the present invention provides a data transmission protection system based on communication status, comprising the following modules:
[0047] Communication status monitoring module: used to monitor the communication link status of data transmission in real time, including network delay, bandwidth utilization, packet loss rate, and signal strength parameters.
[0048] Analysis and decision-making module: used to receive the communication status data from the communication status monitoring module, and conduct comprehensive analysis based on the preset security policies and performance thresholds.
[0049] Protection execution module: used to perform specific protection operations according to the instructions of the analysis and decision module.
[0050] Data cache module: used to temporarily store data to be transmitted and received data during the data transmission process, and to synchronize part of the data to be transmitted with the cloud.
[0051] Encryption and decryption module: used to encrypt the data to be transmitted, and select the corresponding encryption strategy according to the importance and sensitivity of the data.
[0052] Identity authentication module: used to authenticate both ends of data transmission, using a mechanism that combines multiple authentication methods including digital certificates, username and password, and biometric identification to ensure the authenticity and legitimacy of the identities of the source and destination of data transmission.
[0053] The communication status monitoring module adopts a distributed monitoring architecture and deploys monitoring sub-nodes at key nodes of the network, including core switches and border routers. These sub-nodes independently collect local communication status data and transmit the data to the central analysis node through a distributed data aggregation and synchronization mechanism.
[0054] The machine learning algorithm in the analysis and decision-making module adopts a deep neural network model, which uses the multi-dimensional communication status data obtained by the communication status monitoring module as input, and outputs corresponding protection strategy recommendations after feature extraction and pattern recognition of multiple layers of neurons. The training process of the deep neural network model adopts an adaptive learning rate adjustment algorithm, which dynamically optimizes the learning rate according to the convergence of the training error to improve the training efficiency and accuracy of the model.
[0055] The protection execution module adopts a dynamic adaptive protection strategy, and based on the monitoring and analysis of real-time communication status parameters including network delay, packet loss rate, and bandwidth utilization, the system automatically and dynamically adjusts the data transmission protection strategy. The established adaptive protection strategy algorithm is as follows:
[0056] Algorithm principle:
[0057] Using fuzzy control theory, network delay (D), packet loss rate (L) and bandwidth utilization (U) are used as input fuzzy variables, and the adjustment parameters of the protection strategy (including the encryption strength adjustment factor k e, data transmission rate adjustment factor k r , Standby link switching threshold T s ) as the output fuzzy variable. Through the predefined fuzzy rule table, the fuzzy value of the input variable is inferred to obtain the fuzzy result of the output variable, and finally the precise protection strategy adjustment parameters are obtained through clarification processing.
[0058] Algorithm formula:
[0059] Fuzzification process:
[0060] For network delay D, the fuzzy set is defined as {low (LD), medium (MD), high (HD)}, and its membership function can be adopted as triangular membership
[0061] Attribute function:
[0062]
[0063]
[0064] Where D 1、 D 2、 D3 is the threshold of network delay, for example, D1 = 20ms, D2 = 50ms, D3 = 100ms;
[0065] For the packet loss rate L, the fuzzy set is defined as {Low (LL), Medium (ML), High (HL)}, and the membership function is constructed in a similar way to the network delay, with the thresholds set to L1 = 0.01, L2 = 0.05, and L3 = 0.1;
[0066] For bandwidth utilization U, define the fuzzy set as {low (LU), medium (MU), high (HU)}, and set the thresholds as U1 = 0.3, U2 = 0.6, U3 = 0.9;
[0067] For the encryption strength adjustment factor k e , define the fuzzy set as {weak (WE), medium (ME), strong (SE)};
[0068] For data transmission rate adjustment factor k r , define the fuzzy set as {reduce (RD), maintain (MN), improve (IN)};
[0069] For the standby link switching threshold T s , define the fuzzy set as {low (LT), medium (MT), high (HT)}.
[0070] Create a fuzzy rule table:
[0071] rule D L U <![CDATA[k e ]]> <![CDATA[k r ]]> <![CDATA[T s ]]> 1 LD LL LU WE IN HT 2 LD LL MU WE MN MT 3 LD LL HU ME RD LT ... ... ... ... ... ... ...
[0072] For example, rule 1 means that when the network latency is low, the packet loss rate is low, and the bandwidth utilization is low, the encryption strength is adjusted to weak, the data transmission rate is increased, and the backup link switching threshold is set to high (i.e., it is not easy to switch to the backup link).
[0073] Reasoning and Clarification:
[0074] According to the membership degree of input variables and fuzzy rules, the fuzzy set of output variables is obtained by reasoning, and then clarified by the centroid method to obtain the accurate k e , k r and T s For example, for the encryption strength adjustment factor k e The clear formula is:
[0075]
[0076] in are the quantitative values corresponding to the fuzzy sets "weak (WE)", "medium (ME)" and "strong (SE)" (for example, WE = 0.3, ME = 0.6, SE = 0.9), is the membership degree of the corresponding fuzzy set obtained by reasoning;
[0077] Example:
[0078] Assume that the current network delay D = 30ms, packet loss rate L = 0.03, and bandwidth utilization U = 0.4;
[0079] First, fuzzify:
[0080]
[0081] Reasoning is performed based on the fuzzy rule table. For example, for rule 2 (LD, LL, MU), the encryption strength adjustment factor k e The activation level of weak (WE) is For rule 3 (LD, LL, HU), its effect on k e The activation level in is
[0082] The encryption strength adjustment factor k is obtained by clarifying it through the centroid method e The value of k is assumed to be e = 0.4, which means that the encryption strength will be appropriately enhanced but still at a level between weak and medium. Similarly, the data transmission rate adjustment factor k can be calculated r and the standby link switching threshold T s The protection execution module then executes the corresponding protection strategy based on these adjustment parameters, such as adjusting the parameters of the encryption algorithm to enhance the encryption strength to the corresponding level, r Adjust the data transmission rate according to Ts Determine whether to switch to the backup link.
[0083] The data cache module includes a data prediction module, a data queue module, a multi-path transmission module and a summary storage module. The data prediction module is used to analyze historical data transmission patterns and user behavior data, build a prediction model, predict in advance the data that users may need, and automatically pre-fetch data to the local cache when the communication link is idle or underloaded. The data queue module is used to allocate corresponding cache queues for data waiting to be cached and temporarily store the data waiting to be cached. The data prediction module established here includes the following algorithm:
[0084] Algorithm principle:
[0085] An algorithm is established for data forecasting. First, the STL algorithm is used to decompose the historical data transmission sequence into trend items, seasonal items, and residual items. Then, a model is established for the trend item for forecasting, and the seasonal item is extrapolated according to the historical cycle law. Finally, the predicted trend item, seasonal item, and residual item are added together to obtain the final forecast result. This hybrid method can effectively handle the trend, seasonality, and irregular fluctuations in the data and improve the accuracy of the forecast.
[0086] Algorithm formula:
[0087] Let the original data sequence be y t , after STL decomposition, we get the trend term T t , Seasonal ItemS t and the residual term R t , that is, y t =T t +S t +R t ;
[0088] For the trend term T t , construct the prediction model, the formula is as follows:
[0089]
[0090] Seasonal ItemS t Extrapolate the forecast based on the historical period m (e.g., day as the period, m = 24 hours), that is,
[0091] Final prediction value
[0092]
[0093] Example:
[0094] Taking network data traffic prediction as an example, the hourly data traffic of the past week is collected as historical data. First, the STL algorithm is used to decompose the data, and the trend item shows that the overall data traffic is slowly rising. The seasonal item shows that there are obvious traffic peaks and valleys every day (such as high traffic during daytime working hours and low traffic at night). A model is established for the trend item to predict the predicted value of the trend item. According to the historical law of the seasonal item, the seasonal item value at future moments is extrapolated and predicted. Assuming that the residual at the current moment is r, the predicted trend item, seasonal item and residual are added to get the predicted value of the data traffic in the next hour. If it is predicted that the traffic will increase in a certain period and the communication link is currently idle, the data prediction module triggers the pre-fetching of relevant data to the local cache.
[0095] The multi-path transmission module dynamically allocates the transmission ratio of the current main data transmission path and the transmission ratio during the cloud data synchronization process based on the network topology and the real-time communication status of each link, and supports manual input of weighted parameters to adjust the transmission ratio. The summary storage module is used to finally summarize and store the data transmitted by the multi-path transmission module. The multi-path transmission module constructed here includes the following algorithms:
[0096] Algorithm principle:
[0097] Comprehensively consider the network topology and the real-time communication status of each link (such as bandwidth B, delay D, packet loss rate L) as well as the manually entered weighted parameters W m To dynamically allocate the transmission ratio P of the current main data transmission path m Transmission ratio P during synchronization with cloud data c First, the basic weight W of the link is calculated according to the real-time communication status of the link. b , and then combine the manually entered weighted parameters to get the final weight W, and then allocate the transmission ratio according to the weight.
[0098] Algorithm formula:
[0099] The basic weight of link i The calculation is as follows:
[0100]
[0101] Final weight (in are manually entered weighting parameters).
[0102] Transmission ratio of the main data transmission path Transmission ratio during synchronization with cloud data The allocation is as follows:
[0103]
[0104] Where α is a pre-set ratio coefficient for dividing the main data transmission and cloud synchronization transmission, and satisfies
[0105] Algorithm example:
[0106] Assume there are two links L1 and L2, 链路 The bandwidth of L1 is B1 = 100 Mbps, the delay is D1 = 20 ms, and the packet loss rate is L1 = 0.02; the bandwidth of link L2 is B2 = 80 Mbps, the delay is D2 = 15 ms, and the packet loss rate is L2 = 0.03. The manually entered weighting parameter W m1 =2,W m2 =1, set α = 0.3 (i.e. 30% is used for cloud synchronization transmission). First calculate the basic weight:
[0107]
[0108] Final weights:
[0109] W1=0.0272×2≈0.0544
[0110] W2=0.0301×1=0.0301
[0111] Transmission ratio of the main data transmission path:
[0112]
[0113] Transmission ratio during cloud data synchronization:
[0114]
[0115] During data transmission, if the link status changes or the weighted parameters are manually adjusted, the transmission ratio will be recalculated.
[0116] The encryption and decryption module uses a hybrid encryption strategy that combines a chaotic encryption algorithm with a traditional encryption algorithm in the process of selecting an encryption algorithm and generating a key. The chaotic encryption algorithm generates a pseudo-random sequence as part of an encryption key or scrambles a traditional encryption key based on a specific chaotic mapping function. The parameters of the chaotic mapping function are dynamically adjusted according to the network security indicators provided by the communication status monitoring module.
[0117] Please see attached Figure 4 - Attachment Figure 5 , a data transmission protection method based on communication status, comprising the following steps:
[0118] S1: Communication status monitoring steps
[0119] Start the communication status monitoring module, use a variety of detection methods to obtain the communication link status parameters in the data transmission process in real time, and store and organize them in time series to form communication status data records. The detection methods include multi-protocol monitoring and in-depth analysis;
[0120] S2: Analytical decision-making steps
[0121] The analysis and decision-making module reads the communication status data records, compares and analyzes the current communication status parameters with the preset security policies and performance thresholds, and determines whether the communication status is normal. If abnormal, it determines the protection measures based on the predefined decision rules and intelligent decision-making driven by machine learning. Strategy simulation and evaluation can be performed before decision-making, and multi-strategy fusion and dynamic adjustment are supported;
[0122] S3: Protection execution steps
[0123] The protection execution module receives protection measures instructions and performs corresponding protection operations according to the instructions, including link switching, rate adjustment, encryption enhancement and other operations using a modular protection component architecture, and has hardware acceleration and offloading support capabilities as well as cross-platform and heterogeneous network adaptation capabilities;
[0124] S4: Data caching and recovery steps
[0125] The data cache module continuously caches data during data transmission. When the communication status is abnormal and the transmission is interrupted, the data status is saved. After the communication is restored to normal, the protection execution module resumes data transmission based on the cached data status information. The data cache module adopts a multi-level cache architecture and intelligent cache management, and has cache data redundancy and verification and repair functions as well as a cache and transmission collaborative optimization mechanism;
[0126] S5: Encryption and decryption steps
[0127] At the data sending end, encryption algorithms and keys are selected to encrypt data according to the importance and sensitivity of the data. The receiving end uses the corresponding decryption key and algorithm for decryption. The encryption algorithm library can be dynamically updated and adaptively selected, and has encryption key management and dynamic update mechanisms. At the same time, there is pre-research and integration preparation for quantum encryption technology;
[0128] S6: Identity authentication step
[0129] Before data transmission is established, the identity authentication module uses a multimodal fusion authentication method based on digital certificates, usernames and passwords, and biometrics to authenticate both ends of the data transmission. It combines a blockchain-based identity authentication and trust management system with a context-aware identity authentication enhancement mechanism to regularly review the identity during the transmission process.
[0130] In the S5 encryption and decryption step, a cache replacement algorithm based on data heat prediction is used in cache data management before data caching. The algorithm analyzes the access history of the data by building a model, predicts the access probability of the data in a certain period of time in the future as the data heat index, and sorts and replaces the data in the cache according to the heat index, giving priority to retaining high-heat data in the cache.
[0131] The S6 identity authentication step uses a weighted feature fusion algorithm in the biometric multimodal fusion authentication process. According to the differences in accuracy, stability and anti-counterfeiting of different biometrics, a dynamic weight is assigned to each biometric feature. The weight is adjusted according to the network risk level monitored by the communication status monitoring module and the user's historical authentication behavior analysis results. The matching scores of multiple biometric features are fused by weighted summation to obtain the final authentication decision result. The process involves the following algorithms:
[0132] Algorithm principle:
[0133] First, perform independent feature extraction and match score calculation for different biometric features (such as fingerprints, facial features, irises, etc.). Then, according to the pre-set evaluation index system, combined with the network risk level provided by the communication status monitoring module and the user's historical authentication behavior analysis results, dynamically assign weights to each biometric feature. Finally, multiply the matching score of each biometric feature by the corresponding weight and sum them up to obtain the final authentication decision score, which is compared with the preset authentication threshold to determine whether the authentication is successful.
[0134] Algorithm formula:
[0135] Suppose there are n types of biometrics, and the matching score of the i-th biometric is S i , and its corresponding dynamic weight is w i , then the final certification decision is
[0136] The calculation formula of S is:
[0137]
[0138] Among them, the weight w i The calculation is based on the following factors:
[0139] w i =α×R i +β×A i +γ×F i +δ×H i
[0140] Here, R i represents the adjustment factor based on the network risk level, A i represents the accuracy factor of biometric feature i, Fi represents the stability factor of biometric feature i, H i Represents the anti-counterfeiting factor of biometric feature i. α, β, γ, δ are the corresponding weight coefficients, and satisfy α+β+γ+δ=1. Network risk level adjustment factor R i The calculation of can be set according to the network risk level L (for example, low risk: L = 1; medium risk: L = 2; high risk: L = 3), such as:
[0141]
[0142] where r i1 、r i2 、r i3 is the specific coefficient accuracy factor A set for biometric feature i at different network risk levels i , stability factor F i and the anti-counterfeiting factor H i It can be obtained based on statistical analysis of historical data or expert experience evaluation, and the value range is between [0,1];
[0143] Example:
[0144] Assume that there are three biometric features for authentication: fingerprint (feature 1), facial features (feature 2) and iris (feature 3). Known accuracy factors: A1 = 0.8, A2 = 0.7, A3 = 0.9; stability factors: F1 = 0.7, F2 = 0.6, F3 = 0.8; anti-counterfeiting factors: H1 = 0.6, H2 = 0.5, H3 = 0.7. Assume that the weight coefficients α = 0.3, β = 0.3, γ = 0.2, δ = 0.2. The current network risk level is medium risk (L = 2). Assume that the network risk level adjustment factors for medium risk are: R1 = 0.4, R2 = 0.3R3 = 0.5;
[0145] Calculate weights:
[0146] w1=0.3×0.4+0.3×0.8+0.2×0.7+0.2×0.6=0.62
[0147] w2=0.3×0.3+0.3×0.7+0.2×0.6+0.2×0.5=0.52
[0148] w3=0.3×0.5+0.3×0.9+0.2×0.8+0.2×0.7=0.76
[0149] Assume that the matching score of the fingerprint is S1=0.8, the matching score of the facial feature is S2=0.7, and the matching score of the iris is S3=0.9.
[0150] Calculate the final certification decision score:
[0151] S=0.62×0.8+0.52×0.7+0.76×0.9=1.648
[0152] Assume that the authentication threshold is 1.5. Since S>1.5, the authentication is successful.
[0153] In actual applications, if the network risk level increases, for example, to high risk, the network risk level adjustment factor of the corresponding biometric will change, and the weight will also be adjusted accordingly, so as to make authentication decisions more strictly. At the same time, as the user's historical authentication behavior data continues to accumulate and analyze, the accuracy factor, stability factor, and anti-counterfeiting factor can also be dynamically updated to further optimize the weight distribution and the accuracy of the authentication results.
[0154] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A data transmission protection system based on communication status, characterized in that: Includes the following modules: Communication status monitoring module: used to monitor the communication link status of data transmission in real time, including network delay, bandwidth utilization, packet loss rate, and signal strength parameters. Analysis and decision-making module: used to receive the communication status data from the communication status monitoring module, and conduct comprehensive analysis based on the preset security policies and performance thresholds. Protection execution module: used to perform specific protection operations according to the instructions of the analysis and decision module. Data cache module: used to temporarily store data to be transmitted and received data during the data transmission process, and to synchronize part of the data to be transmitted with the cloud. Encryption and decryption module: used to encrypt the data to be transmitted, and select the corresponding encryption strategy according to the importance and sensitivity of the data. Identity authentication module: used to authenticate both ends of data transmission, using a mechanism that combines multiple authentication methods including digital certificates, username and password, and biometric identification to ensure the authenticity and legitimacy of the identities of the source and destination of data transmission.
2. The data transmission protection system based on communication status according to claim 1, characterized in that: The communication status monitoring module adopts a distributed monitoring architecture and deploys monitoring sub-nodes at key nodes of the network, including core switches and border routers. These sub-nodes independently collect local communication status data and transmit the data to the central analysis node through a distributed data aggregation and synchronization mechanism.
3. The data transmission protection system based on communication status according to claim 1, characterized in that: The machine learning algorithm in the analysis and decision-making module adopts a deep neural network model, which uses the multi-dimensional communication status data obtained by the communication status monitoring module as input, and outputs corresponding protection strategy recommendations after feature extraction and pattern recognition of multiple layers of neurons. The training process of the deep neural network model adopts an adaptive learning rate adjustment algorithm, which dynamically optimizes the learning rate according to the convergence of the training error to improve the training efficiency and accuracy of the model.
4. The data transmission protection system based on communication status according to claim 1, characterized in that: The protection execution module adopts a dynamic adaptive protection strategy, and based on the monitoring and analysis of real-time communication status parameters including network delay, packet loss rate, and bandwidth utilization, the system automatically and dynamically adjusts the data transmission protection strategy.
5. The data transmission protection system based on communication status according to claim 1, characterized in that: The data cache module includes a data prediction module, a data queue module, a multi-path transmission module and a summary storage module. The data prediction module is used to analyze historical data transmission patterns and user behavior data, build a prediction model, predict in advance the data that the user may need, and automatically pre-fetch data to the local cache when the communication link is idle or under load. The data queue module is used to allocate corresponding cache queues for data waiting to be cached and temporarily store the data waiting to be cached.
6. The data transmission protection system based on communication status according to claim 5, characterized in that: The multi-path transmission module dynamically allocates the transmission ratio of the current main data transmission path and the transmission ratio during the cloud data synchronization process based on the network topology and the real-time communication status of each link, and supports manual input of weighted parameters to adjust the transmission ratio. The summary storage module is used to finally summarize and store the data transmitted by the multi-path transmission module.
7. The data transmission protection system based on communication status according to claim 1, characterized in that: The encryption and decryption module uses a hybrid encryption strategy that combines a chaotic encryption algorithm with a traditional encryption algorithm in the process of selecting an encryption algorithm and generating a key. The chaotic encryption algorithm generates a pseudo-random sequence as part of an encryption key or scrambles a traditional encryption key based on a specific chaotic mapping function. The parameters of the chaotic mapping function are dynamically adjusted according to the network security indicators provided by the communication status monitoring module.
8. The data transmission protection method based on communication status according to claim 1, characterized in that: The following steps are involved: S1: Communication status monitoring steps Start the communication status monitoring module, use a variety of detection methods to obtain the communication link status parameters in the data transmission process in real time, and store and organize them in time series to form communication status data records. The detection methods include multi-protocol monitoring and in-depth analysis; S2: Analytical decision-making steps The analysis and decision-making module reads the communication status data records, compares and analyzes the current communication status parameters with the preset security policies and performance thresholds, and determines whether the communication status is normal. If abnormal, it determines the protection measures based on the predefined decision rules and intelligent decision-making driven by machine learning. Strategy simulation and evaluation can be performed before decision-making, and multi-strategy fusion and dynamic adjustment are supported; S3: Protection execution steps The protection execution module receives protection measures instructions and performs corresponding protection operations according to the instructions, including link switching, rate adjustment, encryption enhancement and other operations using a modular protection component architecture, and has hardware acceleration and offloading support capabilities as well as cross-platform and heterogeneous network adaptation capabilities; S4: Data caching and recovery steps The data cache module continuously caches data during data transmission. When the communication status is abnormal and the transmission is interrupted, the data status is saved. After the communication is restored to normal, the protection execution module resumes data transmission based on the cached data status information. The data cache module adopts a multi-level cache architecture and intelligent cache management, and has cache data redundancy and verification and repair functions as well as a cache and transmission collaborative optimization mechanism; S5: Encryption and decryption steps At the data sending end, encryption algorithms and keys are selected to encrypt data according to the importance and sensitivity of the data. The receiving end uses the corresponding decryption key and algorithm for decryption. The encryption algorithm library can be dynamically updated and adaptively selected, and has encryption key management and dynamic update mechanisms. At the same time, there is pre-research and integration preparation for quantum encryption technology; S6: Identity authentication step Before data transmission is established, the identity authentication module uses a multimodal fusion authentication method based on digital certificates, usernames and passwords, and biometrics to authenticate both ends of the data transmission. It combines a blockchain-based identity authentication and trust management system with a context-aware identity authentication enhancement mechanism to regularly review the identity during the transmission process.
9. The data transmission protection method based on communication status according to claim 8, characterized in that: In the S5 encryption and decryption step, a cache replacement algorithm based on data heat prediction is used in cache data management before data caching. The algorithm analyzes the access history of the data by building a model, predicts the access probability of the data in a certain period of time in the future as the data heat index, and sorts and replaces the data in the cache according to the heat index, giving priority to retaining high-heat data in the cache.
10. The data transmission protection method based on communication status according to claim 8, characterized in that: The S6 identity authentication step uses a weighted feature fusion algorithm in the biometric multimodal fusion authentication process. According to the differences in accuracy, stability and anti-counterfeiting of different biometrics, a dynamic weight is assigned to each biometric feature. The weight is adjusted based on the network risk level monitored by the communication status monitoring module and the user's historical authentication behavior analysis results. The matching scores of multiple biometric features are fused by weighted summation to obtain the final authentication decision result.