Information data secure transmission method and system
By building a topological model of the aviation airport network and dynamically selecting transmission paths, encryption protocol allocation and virtual tunnel encryption technology, the delay problem of traditional encryption technology in high-frequency and large-scale data transmission is solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510198491.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-22
AI Technical Summary
Traditional encryption technology has high computing overhead in high-frequency and large-scale data transmission, resulting in delay problems and affecting the real-time and efficiency of information transmission at the aviation airport.
By systematically analyzing the aviation airport network communication data, building an airport network communication topology model, dynamically selecting the transmission path, and dynamically allocating the encryption protocol based on the load mode and security of the transmission node, realizing virtual tunnel encryption of data packets.
It reduces data transmission delay, improves the efficiency and security of transmission paths, ensures real-time transmission of critical data, and improves aviation operation efficiency and security.
Smart Images

Figure CN120017388A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information transmission, and in particular to a method and system for securely transmitting information data. Background Art
[0002] With the rapid development of the global aviation industry, airports, as important hubs for flight management and passenger services, carry a large amount of critical data in their information systems, including flight plans, passenger information, baggage tracking, security monitoring, etc. This information not only involves the operational efficiency of airlines, but also the safety and privacy protection of passengers. In the past few decades, the information transmission system of airports has mainly relied on traditional communication protocols and security measures, such as encryption technology, identity authentication, digital signatures, etc., to ensure the confidentiality and integrity of data during transmission. Traditional secure transmission methods include data transmission based on encryption algorithms, communication guarantees based on VPN (virtual private network) and TLS (transport layer security) protocols, and trust management relying on centralized certification authorities. Although these technologies guarantee the security of data transmission to a certain extent, traditional encryption technologies such as symmetric encryption and public key encryption can effectively prevent data from being stolen, but their computational overhead in high-frequency and large-scale data transmission is large, resulting in delays in the transmission process. In the transmission of information at airports, the real-time and rapid response of data transmission are crucial. For example, in the process of flight scheduling and emergency handling, delays may lead to untimely information transmission and even affect aviation safety. However, existing encryption algorithms, especially when the data volume is large and involves multiple transmission nodes, often add additional delays and bandwidth consumption, thus affecting the overall efficiency of the system. Summary of the invention
[0003] Based on this, it is necessary for the present invention to provide a method and system for securely transmitting information data to solve at least one of the above technical problems.
[0004] To achieve the above purpose, a method for securely transmitting information data includes the following steps:
[0005] Step S1: Acquire aviation airport network communication data, and perform communication network topology analysis on the aviation airport network communication data to obtain an airport network communication topology model; select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated;
[0006] Step S2: Performing a security assessment of the intersection of transmission node load patterns on the airport network communication topology model according to the aviation airport network communication data to obtain transmission node security data; dynamically assigning a transmission path encryption protocol to the transmission path data to be assigned based on the transmission node security data to obtain an encrypted path mapping table;
[0007] Step S3: Obtain node verification data, and perform transmission node verification space frequency weighted credibility assessment on the node verification data to obtain a node behavior analysis report;
[0008] Step S4: Based on the node behavior analysis report and the encryption path mapping table, the data packet virtual tunnel is encrypted to obtain the aviation airport encrypted data packet to be transmitted, and the data packet is uploaded to the airport network security management platform to execute the data transmission task;
[0009] Step S5: Acquire the real-time communication data of the aviation airport network, perform abnormal data recovery on the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to execute the data transmission task.
[0010] The present invention can effectively understand and optimize the overall structure of the network and ensure the efficiency and reliability of the data transmission path by systematically analyzing the aviation airport network communication data and building an airport network communication topology model. This process helps identify and avoid potential network bottlenecks and reduce delays in the data transmission process, especially for data transmission tasks involving multiple transmission nodes. In the process of selecting the data transmission path, the optimal transmission path can be dynamically selected in combination with the network topology model, further improving the speed and accuracy of the transmission, ensuring that emergency information and important data can be transmitted in real time, thereby improving the efficiency and safety of aviation operations. By performing an intersection evaluation on the load mode and security of the transmission node, more accurate node security data can be obtained, and the transmission path encryption protocol can be dynamically allocated based on the data. In this way, not only can the security of data transmission be ensured, but also the performance bottleneck caused by excessive encryption can be reduced, avoiding the delay and bandwidth consumption caused by traditional encryption algorithms in high-frequency and large-scale data transmission. This process is particularly helpful to improve the stability and response speed of the system under high load conditions, and ensure the timeliness of key services such as flight scheduling, passenger information, and baggage tracking. Transmission of node verification data Node verification spatial frequency weighted credibility assessment can effectively detect potential security risks. By analyzing node behavior, abnormal behavior can be identified and responded to in a timely manner to prevent data leakage or tampering. This process is crucial to improving overall network security, especially when transmitting sensitive information, it can maximize the integrity and confidentiality of data and prevent unauthorized access. During data packet transmission, the application of virtual tunnel encryption technology can ensure the security of data in network transmission and prevent data from being stolen or tampered with during transmission. At the same time, the real-time abnormal data recovery mechanism can ensure that data can be quickly restored and the continuity of data transmission can be guaranteed in the event of network interruption or data loss. This solution can not only improve the security of data transmission, but also ensure that the integrity and timely delivery of data can be guaranteed in the event of network failure or attack, thereby improving the reliability and security of the entire airport information system.
[0011] Optionally, step S1 specifically includes:
[0012] Step S11: obtaining the aviation airport network communication data through the airport network security management platform, and performing data preprocessing on the aviation airport network communication data to obtain the aviation airport network communication data to be analyzed;
[0013] Step S12: extracting airport network communication features from the aviation airport network communication data to be analyzed, and obtaining network communication connection data and network dynamic resource allocation data;
[0014] Step S13: Analyze the airport network topology structure according to the network communication connection data to obtain an airport network topology map;
[0015] Step S14: performing dynamic topology data modeling on the airport network topology map based on the network dynamic resource allocation data to obtain an airport network communication topology structure model;
[0016] Step S15: Select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated.
[0017] By acquiring and preprocessing aviation airport network communication data, the present invention can effectively clean and normalize the original data to make it suitable for subsequent detailed analysis. This process can eliminate noise data and improve the accuracy of the analysis results, thereby providing a reliable basis for subsequent decision-making. By extracting airport network communication characteristics, including network communication connection data and dynamic resource allocation data, we can gain an in-depth understanding of the current state of the network and the use of its resources, thereby providing accurate data support for the next step of network topology analysis and resource management. Using these data to analyze the network topology structure can help build an overall view of the airport network, identify each node and its interconnected relationship, thereby providing a clear framework for optimizing network performance and ensuring data transmission. Topological data modeling based on dynamic resource allocation data can make the airport network communication topology structure more in line with the actual situation, taking into account the dynamic changes in resource allocation, and ensuring that the network model is real-time and adaptable. This process is crucial for dealing with resource reallocation during peak periods or emergencies, and can improve the flexibility and responsiveness of the system. Ultimately, by selecting the data transmission path based on the established network topology model, the optimal path planning can be achieved to ensure the efficiency and security of data transmission, especially in a complex network environment with multiple nodes and multiple paths. It can achieve path optimization, reduce transmission delays and bandwidth waste, ensure that key data can be delivered on time and accurately, and improve the overall efficiency and stability of the system.
[0018] Optionally, step S13 is specifically:
[0019] Step S131: extracting device identity features and device connection frequency features according to the network communication connection data to obtain network device identity data and network device connection frequency data;
[0020] Step S132: performing communication network node identification on the network device identity data to obtain communication network node data;
[0021] Step S133: dividing the communication network node data according to the network device connection frequency data to obtain network connection source node data and network connection target node data;
[0022] Step S134: performing node link relationship identification on the network connection source node data and the network connection target node data to obtain network node link relationship data;
[0023] Step S135: Perform network node topology structure analysis based on network node link relationship data and communication network node data to obtain an airport network topology map.
[0024] The present invention can identify the unique identities of different devices and the connection frequencies between devices by extracting device identity features and device connection frequency features from network communication connection data, which provides basic data for further identifying the roles and behavior patterns of various devices in the network. Device identity data helps to confirm the legitimacy and trust level of the device, while device connection frequency data reveals the activity intensity and frequent connection patterns of devices in the network, thereby providing an important basis for evaluating network load, monitoring abnormal behavior, etc. By identifying communication network nodes from device identity data, each device in the network can be mapped to a specific network node, helping to build a clear network node map. Node identification further refines the device roles in the network and helps to accurately analyze the network structure. Using network device connection frequency data to divide nodes effectively distinguishes source nodes and target nodes in the network, which helps to clarify the direction of data flow and the traffic distribution of the network topology. This division provides useful information for subsequent network path optimization, data traffic prediction, etc. By identifying the link relationship of network connection source nodes and target nodes, the communication paths and their relationships between different nodes can be accurately captured, thereby further optimizing network management and improving data transmission efficiency. Finally, by analyzing the network node topology structure based on the node-link relationship and network node data, a complete topology map of the airport network can be drawn, thereby better understanding the overall architecture of the network, identifying potential bottleneck nodes and vulnerabilities, providing a basis for network optimization and security protection, and improving network reliability and efficiency.
[0025] Optionally, step S2 specifically includes:
[0026] Step S21: extracting network communication security logs and network traffic monitoring data from the aviation airport network communication data to obtain network communication security logs and network traffic monitoring data, and performing frequency domain conversion on the network traffic monitoring data to obtain a network traffic monitoring spectrum;
[0027] Step S22: dividing the intrusion node frequency of the airport network communication topology model according to the network communication security log to obtain intrusion frequency node division data;
[0028] Step S23: performing traffic load pattern recognition according to the network traffic monitoring spectrum to obtain network traffic non-periodic load pattern data and network traffic periodic load pattern data; performing high-frequency load pattern node division according to the network traffic non-periodic load pattern data and the network traffic periodic load pattern data to obtain high-frequency load pattern node division data;
[0029] Step S24: Perform transmission node security assessment according to the intrusion frequency node division data and the high-frequency load mode node division data to obtain transmission node security data;
[0030] Step S25: dynamically allocate the transmission path encryption protocol to the transmission path data to be allocated based on the transmission node security data to obtain an encrypted path mapping table.
[0031] The present invention can comprehensively grasp the security status and traffic characteristics of the network by extracting network communication security logs and network traffic monitoring data from aviation airport network communication data, and provide basic data for subsequent analysis. The extraction of these data not only helps to monitor the network security status in real time, but also can reveal potential attack behaviors and abnormal traffic. The frequency domain conversion of network traffic monitoring data can convert complex signals in the time domain into frequency domain signals, thereby revealing the periodic and non-periodic characteristics of traffic, and further help to identify potential abnormal patterns in traffic. By dividing the intrusion node frequency of the airport network communication topology model according to the network communication security log, nodes with frequent security threats can be identified, providing valuable input for the network security early warning system. The identification of traffic load patterns helps to distinguish periodic and non-periodic traffic characteristics, and can identify possible high-risk nodes by analyzing the high-frequency mode nodes of the traffic load, so as to make a protective response in advance when the network traffic load is high. Combining the intrusion frequency node data with the high-frequency load mode node division data to evaluate the security of the transmission node, the security risk and load pressure of the node can be comprehensively considered, the security of the transmission path can be quantitatively evaluated, and potential weak nodes or high-risk nodes can be identified, providing a basis for path optimization and encryption measures. Based on the transmission node security data, the transmission path encryption protocol is dynamically allocated to the allocated transmission path data, which can ensure the security of the data transmission process and optimize the encryption path mapping table, thereby improving the data transmission efficiency while ensuring security.
[0032] Optionally, step S24 is specifically:
[0033] Perform node classification on the intrusion frequency node division data to obtain high-frequency communication intrusion node data and low-frequency communication intrusion node data;
[0034] Perform node classification on the high-frequency load mode node division data to obtain high-frequency periodic load mode node data and high-frequency non-periodic load mode node data;
[0035] Perform node intersection operation based on high-frequency communication intrusion node data and high-frequency non-periodic load mode node data to obtain low-security transmission node data;
[0036] Perform node intersection calculation based on low-frequency communication intrusion node data and low-frequency non-periodic load mode node data to obtain high-security transmission node data;
[0037] The low-security transmission node data and the high-security transmission node data are combined to obtain transmission node security data.
[0038] The present invention can classify nodes into high-frequency communication intrusion nodes and low-frequency communication intrusion nodes according to communication frequency by classifying intrusion frequency node division data, so as to more accurately identify nodes that are attacked at high frequencies and relatively safe nodes in the network. This classification helps to evaluate and prioritize network security risks, so that network security managers can take corresponding measures to strengthen protection for high-frequency communication intrusion nodes. At the same time, by classifying high-frequency load mode node division data, high-frequency load nodes can be divided into periodic load mode and non-periodic load mode nodes, and the traffic characteristics of these nodes can be further analyzed to find out potential load problems. For high-frequency communication intrusion nodes and high-frequency non-periodic load mode node data, node intersection operations can be performed to identify nodes that are facing high-frequency intrusion attacks and bearing non-periodic high loads. These nodes have lower security and may be weak links in the network, and need to be given priority to strengthen protection. By performing intersection operations on low-frequency communication intrusion node data and low-frequency non-periodic load mode node data, nodes that are less attacked and have stable load patterns can be determined. These nodes are considered to have higher security and can be used as the preferred nodes for secure transmission paths. Finally, by merging the low-security transmission node data and the high-security transmission node data, a comprehensive transmission node security data can be obtained, which can provide decision support for subsequent data transmission path selection and encryption protocol allocation, and ensure the security and stability of the data transmission process.
[0039] Optionally, step S3 specifically includes:
[0040] Step S31: Obtain node verification data through the network security management platform, and perform data preprocessing on the node verification data to obtain the node verification data to be analyzed;
[0041] Step S32: extract node verification features from the node verification data to be analyzed, and obtain node verification device location data and node verification device frequency data;
[0042] Step S33: Perform spatial distribution statistics of the verification equipment according to the node verification equipment location data to obtain equipment verification location frequency data; perform verification equipment verification frequency statistics on the node verification equipment frequency data to obtain equipment short-time verification frequency data;
[0043] Step S34: performing device verification abnormal behavior detection based on the device verification location frequency data and the device short-time verification frequency data to obtain node verification behavior detection data;
[0044] Step S35: Perform transmission node credibility assessment on the airport network communication topology model based on the node verification behavior detection data to obtain a node behavior analysis report.
[0045] The present invention obtains and pre-processes node verification data through a network security management platform, which helps to effectively remove noise data and redundant information, thereby providing accurate input data for subsequent analysis and ensuring the reliability and validity of node verification data. Feature extraction of the node verification data to be analyzed, especially extracting the location and frequency data of the node verification device, can provide a deeper understanding of the behavior patterns of devices in the network and help identify possible abnormal behaviors or risks. Spatial distribution statistics based on the node verification device location data can help discover the distribution patterns of devices in the network, and then identify potential security weaknesses; verification frequency statistics of the node verification device frequency data can reveal the activity level of the device in a short period of time, identify frequently verified devices, and indicate the presence of security risks or faults. At the same time, by combining the device verification location frequency data and the device short-time verification frequency data, device verification abnormal behavior detection can be performed, and devices that violate conventional verification behaviors can be discovered at the first time, which improves the detection efficiency of abnormal events and reduces the occurrence of potential security threats. Finally, the credibility of transmission nodes in the airport network communication topology model is evaluated based on the node verification behavior detection data. The generated node behavior analysis report can provide airport network managers with detailed and clear security status feedback, help optimize the network architecture, enhance network defense, and ensure the security and reliability of data transmission.
[0046] Optionally, step S35 is specifically:
[0047] Step S351: extract abnormal verification behavior nodes from the node verification behavior detection data to obtain abnormal verification behavior node data;
[0048] Step S352: Perform abnormal verification behavior frequency statistics and abnormal verification behavior time period statistics according to the abnormal verification behavior node data to obtain node abnormal verification behavior frequency data and node abnormal verification behavior time period distribution data;
[0049] Step S353: Calculate the severity score of abnormal behavior based on the node abnormal verification behavior frequency data to obtain the node abnormal behavior severity score data;
[0050] Step S354: Calculate the node abnormal verification behavior period proportion according to the node abnormal verification behavior period distribution data to obtain the node abnormal verification behavior period proportion data;
[0051] Step S355: weighting the node behavior safety score data on the node abnormal behavior severity score data and the node abnormal verification behavior time period proportion data to obtain the node behavior safety score data;
[0052] Step S356: Visualize the node score space of the airport network communication topology model according to the node behavior security score data to obtain a node behavior analysis report.
[0053] The present invention can effectively identify abnormal nodes that may exist in the network by extracting abnormal verification behavior nodes from node verification behavior detection data. This process helps to quickly lock potential security threat sources. Further frequency and time period statistics of abnormal verification behavior nodes can deeply understand the frequency of these abnormal behaviors and their time distribution, help analyze the regularity and frequency of abnormal behaviors, and thus identify high-risk time periods and nodes that may affect system security. On this basis, calculating the severity score of abnormal behavior is helpful for hierarchical management of abnormal nodes and giving priority to high-risk nodes, thereby improving the security of the system. By calculating the proportion of abnormal verification behavior time periods, the distribution of abnormal behaviors in different time periods can be evaluated, providing a reference for security reinforcement in critical periods. After weighting the node behavior security score, the comprehensive security score of each node can be obtained. This score can provide a scientific basis for subsequent security policy formulation and guide network administrators to take different security protection measures for nodes with different security levels. Finally, using the node behavior security score data for spatial visualization can help network administrators more intuitively understand the security status of each node in the network, effectively identify security weaknesses, and provide data support for network optimization and enhanced protection.
[0054] Optionally, step S4 specifically includes:
[0055] Step S41: selecting a data transmission security node according to the node behavior analysis report to obtain security node data to be distributed;
[0056] Step S42: selecting a path with a high security node ratio in the encryption path mapping table according to the security node data to be distributed, and obtaining the encryption path data to be distributed;
[0057] Step S43: performing encryption key negotiation on the encrypted path data to be distributed, obtaining an encryption key pair, and uploading it to the airport network security management platform to execute the encryption key distribution task;
[0058] Step S44: acquiring the data to be transmitted of the aviation airport, and performing data preprocessing on the data to be transmitted of the aviation airport to obtain the data to be transmitted of the aviation airport to be analyzed;
[0059] Step S45: segmenting the data to be transmitted by the airport to be analyzed into data packets to obtain a set of segmented data packets to be transmitted;
[0060] Step S46: Encrypt the virtual tunnel data of the segmented data packet set to be transmitted according to the encryption key to obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to execute the data transmission task.
[0061] The present invention selects data transmission security nodes according to the node behavior analysis report, which can effectively ensure that only nodes with high security levels are passed during the data transmission process, avoiding potential security threat nodes, thereby enhancing the overall protection capability of the system. Based on the security node data to be distributed, the encryption path mapping table is selected for the path with high security node proportion, which helps to select the most suitable security path to transmit data, avoid data passing through a path with low security, and reduce the risk of data leakage or tampering. The negotiation and distribution of encryption keys ensure that the data has high-intensity encryption protection during the transmission process, so that the confidentiality and integrity of the information can be guaranteed during the entire transmission process, effectively preventing the data from being stolen or tampered with. In the data preprocessing process, the data to be transmitted is effectively cleaned and sorted, which helps to improve the transmission efficiency and accuracy of the data. By segmenting the data packet, the large block of data is divided into multiple small data packets for transmission, which can effectively avoid the delay problem that may occur in the large data transmission, while optimizing the use of network bandwidth and improving the stability of data transmission. Finally, the data packet is encrypted through a virtual tunnel, which ensures that the data can still maintain confidentiality and security in a complex network environment, greatly improves the system's anti-attack ability and data protection ability, and ensures the safety and efficiency of aviation airport information transmission.
[0062] Optionally, step S5 specifically includes:
[0063] Step S51: acquiring the real-time communication data of the aviation airport, and performing data preprocessing on the real-time communication data of the aviation airport to obtain the real-time communication data of the aviation airport network to be analyzed;
[0064] Step S52: Detect node link abnormal values on the real-time communication data of the aviation airport network to be analyzed by using the airport network communication topology model to obtain a real-time abnormality detection log;
[0065] Step S53: performing data packet delay calculation according to the real-time anomaly detection log to obtain data packet delay data, and classifying and calculating the data packet delay data according to a preset lost data packet delay threshold to obtain lost data packets;
[0066] Step S54: decrypting the lost data packet according to the encryption key to obtain a decrypted lost data packet;
[0067] Step S55: reconstructing the decrypted lost data packets based on the segmented data packet set to be transmitted to obtain a restored data packet;
[0068] Step S56: selecting a low-latency transmission path for the restored data packet according to the encrypted path data to be distributed, to obtain restored transmission path data;
[0069] Step S57: Based on the encryption key pair, the virtual tunnel data is encrypted for the restored transmission path data and the restored data packet to obtain the restored encrypted data packet, and uploaded to the airport network security management platform to execute the data transmission task.
[0070] The present invention can effectively filter and organize the real-time data flowing in the network by acquiring the real-time communication data of the aviation airport and preprocessing it, so as to ensure the efficiency and accuracy of data analysis. The node link outlier detection of the data to be analyzed by using the airport network communication topology model is helpful to timely discover and identify potential abnormal behavior or attack behavior, and enhance the real-time monitoring and response capabilities of the system. Through the calculation of data packet delay, the delay in communication can be quantified, and the loss of data packets caused by network problems or attacks can be classified by the preset loss packet delay threshold, which is helpful to locate and filter out the loss of data packets caused by network problems or attacks, thereby ensuring the integrity and timeliness of transmission. The encryption and decryption of the lost data packets can not only restore the lost data packets, but also ensure the data security in the decryption process, and avoid data leakage or tampering. The reconstruction of the lost data packets effectively solves the problem of data loss caused by network problems, ensures the complete transmission of data, and improves the robustness and recovery ability of the system. Selecting a low-latency transmission path to restore the transmission of data packets helps to reduce the delay in data transmission and improve the real-time performance of data transmission, which is particularly important in emergency situations or high-priority data transmission. Finally, by encrypting the transmission path through a virtual tunnel and re-encrypting the data packets, the confidentiality and integrity of the restored data packets during transmission can be further ensured, avoiding any potential security threats, thereby effectively improving the security and communication efficiency of the aviation airport network, ensuring aviation safety while ensuring the efficiency and accuracy of information transmission.
[0071] Optionally, this specification also provides an information data secure transmission system, which is used to execute the information data secure transmission method as described above, and the information data secure transmission system includes:
[0072] The communication network topology structure analysis module is used to obtain the aviation airport network communication data, and perform communication network topology structure analysis on the aviation airport network communication data to obtain the airport network communication topology structure model; select the data transmission path according to the airport network communication topology structure model to obtain the transmission path data to be allocated;
[0073] The node security assessment module is used to perform a security assessment of the intersection of transmission node load patterns on the airport network communication topology model according to the aviation airport network communication data, and obtain the transmission node security data; based on the transmission node security data, the transmission path encryption protocol is dynamically allocated to the transmission path data to be allocated, and an encrypted path mapping table is obtained;
[0074] The node behavior analysis module is used to obtain node verification data and perform transmission node verification space frequency weighted credibility assessment on the node verification data to obtain a node behavior analysis report;
[0075] The data packet encryption module is used to perform data packet virtual tunnel encryption based on the node behavior analysis report and the encryption path mapping table, obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to perform the data transmission task;
[0076] The real-time communication feedback recovery module is used to obtain the real-time communication data of the aviation airport network, and recover the abnormal data of the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
[0077] The information data security transmission system of the present invention can implement any information data security transmission method of the present invention, and is used to combine the operation and signal transmission medium between various modules to complete the information data security transmission method. The internal modules of the system cooperate with each other, thereby improving the security and stability of the data transmission process. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] Other features, objects and advantages of the present invention will become more apparent from the detailed description of non-limiting embodiments thereof made with reference to the following drawings:
[0079] Figure 1 This is a schematic diagram of the steps of the information data security transmission method of the present invention;
[0080] Figure 2Detailed step flow diagram of step S1 in the present invention;
[0081] Figure 3 Detailed step flow diagram of step S2 in the present invention;
[0082] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0083] The technical method of the present invention is described clearly and completely below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by technicians in this field without creative work are within the scope of protection of the present invention.
[0084] In addition, the accompanying drawings are only schematic illustrations of the present invention and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor methods and / or microcontroller methods.
[0085] It should be understood that, although the terms "first", "second", etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are used only to distinguish one unit from another unit. For example, without departing from the scope of the exemplary embodiments, the first unit may be referred to as the second unit, and similarly the second unit may be referred to as the first unit. The term "and / or" used herein includes any and all combinations of one or more of the listed associated items.
[0086] To achieve this, please refer to Figures 1 to 3 The present invention provides a method for securely transmitting information data, the method comprising the following steps:
[0087] Step S1: Acquire aviation airport network communication data, and perform communication network topology analysis on the aviation airport network communication data to obtain an airport network communication topology model; select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated;
[0088] In this embodiment, the traffic monitoring equipment (such as SNMP-based network monitoring system, traffic analyzer or bandwidth acquisition equipment) deployed in the airport network collects communication data from each node in real time, including bandwidth, delay, packet loss rate, traffic type (TCP / UDP), and device connection status. The collected network communication data may include the transmission rate (unit: Mbps) of each node, the transmission delay (unit: ms), the packet loss rate (unit: %), and the communication traffic between nodes (unit: GB). These data are obtained through the network management platform and preprocessed (for example, using data cleaning technology to remove outliers or fill missing values). Next, the shortest path algorithm based on graph theory (such as Dijkstra or A* algorithm) is used to perform topological structure analysis on these data. By calibrating the attributes of each network node (such as node bandwidth, transmission delay, etc.), a topological structure model of the airport network is constructed, and the transmission capacity and bandwidth capacity of the node will participate in the path selection algorithm as parameters. When selecting a data transmission path, the shortest path algorithm ensures that the selected path has the lowest packet loss rate (e.g., 0.01%) under bandwidth capacity (e.g., 10Gbps) and maximum delay (e.g., within 100ms). Through this topology, the best data transmission path is selected, and the path is dynamically selected according to the traffic load, and finally the transmission path data to be allocated is obtained.
[0089] Step S2: Performing a security assessment of the intersection of transmission node load patterns on the airport network communication topology model according to the aviation airport network communication data to obtain transmission node security data; dynamically assigning a transmission path encryption protocol to the transmission path data to be assigned based on the transmission node security data to obtain an encrypted path mapping table;
[0090] In this embodiment, the node security feature data obtained through the network security management platform includes the physical security of the node (for example, the device firewall level, the device vulnerability level), the authentication level (for example, whether it passes multi-factor authentication), the communication frequency of the node (unit: times / hour) and the access rights of the device (such as IP whitelist). These data will be used as input to calculate the security score of each node (for example, a scoring system of 0-100). For each transmission node, the encryption protocol will be dynamically selected according to its security score (for example, nodes below 70 are considered less secure). For example, low-security nodes will use stronger encryption protocols (such as AES-256), while high-security nodes can use lighter encryption protocols (such as AES-128 or TLS1.2). Through the dynamic allocation of encryption protocols, an encryption path mapping table is generated, which will bind each transmission path to a specific encryption protocol to ensure that the data protection strength during the transmission process matches the network security environment.
[0091] Step S3: Obtain node verification data, and perform transmission node verification space frequency weighted credibility assessment on the node verification data to obtain a node behavior analysis report;
[0092] In this embodiment, the verification data of each node is obtained through the airport network security management platform. The data sources include device authentication information (such as node identity ID, certificate chain), authentication credentials (such as JWT tokens), device registration information, access logs and behavior logs (such as login time, access frequency, etc.). Next, abnormal behavior detection will be performed by setting reasonable verification frequency thresholds (such as 5 authentication requests per hour) and behavior patterns (such as abnormal large traffic access within 10 minutes). For each node, if its behavior exceeds the preset security standard (such as the number of login failures within a certain period of time, or abnormal access frequency), it will be marked as abnormal. The abnormal behavior of each node is determined by machine learning algorithms (such as K-means clustering analysis, decision tree model), and node verification behavior detection data is generated. Based on these data, the credibility of the node is evaluated, and the credibility score of each node is obtained by combining the node's historical behavior data, verification frequency (such as the number of authentication requests per hour) and abnormal event frequency (such as a credibility of 80% indicates that the node has a certain risk). These data generate a node behavior analysis report to provide a basis for subsequent encryption key distribution and security decision-making.
[0093] Step S4: Based on the node behavior analysis report and the encryption path mapping table, the data packet virtual tunnel is encrypted to obtain the aviation airport encrypted data packet to be transmitted, and the data packet is uploaded to the airport network security management platform to execute the data transmission task;
[0094] In this embodiment, based on the node behavior analysis report and the encryption path mapping table, a key negotiation protocol (such as the Diffie-Hellman key exchange protocol) is used to generate an encryption key pair. During the key pair generation process, multiple parameter verifications are performed, such as confirming that the node's credibility score is greater than a set threshold (for example, 70%) to ensure that the key exchange process is safe and reliable. The generated encryption key pair will be distributed to each network node through a secure channel. After the key distribution is completed, virtual tunnel technology (such as IPsec or SSL / TLS) will be used to encrypt the data to be transmitted. This encryption process uses a strong encryption algorithm (such as AES-256), and the encrypted data packet includes information such as timestamp, data packet ID, encryption key identifier, etc. The encrypted data packet will be uploaded to the airport network security management platform, and the data transmission task will be executed according to the scheduling strategy within the system. The uploaded data packet will be encrypted and transmitted along the predetermined path to ensure the security and privacy of the data.
[0095] Step S5: Acquire the real-time communication data of the aviation airport network, perform abnormal data recovery on the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to execute the data transmission task.
[0096] In this embodiment, the real-time monitoring system deployed in the airport network security management platform is used to obtain real-time communication data of the network, including transmission delay (such as less than 100ms is normal), packet loss rate (such as less than 0.01%), and network bandwidth utilization rate (such as reaching 80% or more is a high load state). By setting reasonable thresholds (such as delay fluctuations exceeding 3%, packet loss rate of 5%, etc.), real-time anomaly detection algorithms (such as anomaly detection based on time series, weighted average method, etc.) will be triggered. When an anomaly is detected, a real-time anomaly detection log will be generated to record data such as the anomaly time, location, and type of anomaly. Based on these detection logs, packet loss retransmission technology (such as an automatic retransmission mechanism based on TCP) or a packet recovery algorithm (such as using forward error correction technology FEC) will be used to recover abnormal data. The recovered data packet will be re-encrypted according to the encryption key, re-encapsulated, and encrypted and transmitted through a predetermined path. The restored encrypted data packet will be uploaded to the network security management platform to ensure that the data is transmitted to the destination safely and accurately as planned.
[0097] Optionally, step S1 specifically includes:
[0098] Step S11: obtaining the aviation airport network communication data through the airport network security management platform, and performing data preprocessing on the aviation airport network communication data to obtain the aviation airport network communication data to be analyzed;
[0099] In this embodiment, traffic monitoring equipment (such as SNMP-based network monitoring system, traffic analyzer or bandwidth acquisition equipment) is deployed in the airport network to collect communication data from each node in real time (including bandwidth, delay, packet loss rate, traffic type (TCP / UDP), and device connection status, etc.), and upload these communication data to the airport network security management platform.
[0100] Step S12: extracting airport network communication features from the aviation airport network communication data to be analyzed, and obtaining network communication connection data and network dynamic resource allocation data;
[0101] In this embodiment, based on the pre-processed airport network communication data, feature extraction algorithms (such as PCA and LDA) are used to reduce the dimension of the data, extract key features, and obtain network communication connection data (such as connection nodes, communication delay, bandwidth, etc.) and network dynamic resource allocation data (such as traffic load, routing allocation, etc.). For example, the bandwidth usage, delay fluctuation and traffic pattern of each node are extracted from the communication data of 500 nodes to obtain complete network communication connection and resource allocation feature data.
[0102] Step S13: Analyze the airport network topology structure according to the network communication connection data to obtain an airport network topology map;
[0103] In this embodiment, according to the extracted network communication connection data, a graph algorithm (such as Dijkstra and Kruskal algorithms) is used to analyze the relationship between communication nodes and construct a network topology map. In specific implementation, the nodes are represented as routers or switches in the airport network, and the edges represent communication links or data flows. The shortest path between nodes is determined by the delay and bandwidth data between nodes, thereby forming a network topology map of the aviation airport. For example, for the main switch of an airport, a topology map containing 100 nodes and 150 connection links is constructed by analyzing the multiple sub-network nodes connected to it.
[0104] Step S14: performing dynamic topology data modeling on the airport network topology map based on the network dynamic resource allocation data to obtain an airport network communication topology structure model;
[0105] In this embodiment, based on the extracted network dynamic resource allocation data (such as bandwidth utilization, load balancing information, etc.), dynamic network modeling technology (such as Markov chain modeling, time series analysis) is applied to model the dynamic topology data on the airport network topology map. This model can reflect the changes in network resources (such as bandwidth changes, node load changes) in real time, thereby generating a dynamic airport network communication topology structure model. For example, using periodic network data, a dynamic topology model that can be adjusted according to real-time bandwidth load is established, and it is updated every 30 seconds to reflect the traffic changes in the airport network.
[0106] Step S15: Select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated.
[0107] In this embodiment, based on the obtained airport network communication topology model, the shortest path algorithm (such as Bellman-Ford) or the optimal path selection algorithm is used to select the optimal data transmission path according to the real-time network status (such as bandwidth, delay, node security). The transmission path selection considers multiple factors, including the available bandwidth of the node, delay, network traffic load, etc. For example, during the data transmission process, if the bandwidth of a certain path is insufficient or the delay is too high, the system will automatically switch to another path to ensure smooth and efficient data transmission, and finally obtain the transmission path data set to be allocated.
[0108] Optionally, step S13 is specifically:
[0109] Step S131: extracting device identity features and device connection frequency features according to the network communication connection data to obtain network device identity data and network device connection frequency data;
[0110] In this embodiment, based on the network communication connection data, the device identity extraction algorithm (such as based on MAC address, IP address, device model, etc.) is first used to extract the identity characteristics of each device. Subsequently, the connection frequency characteristics of the device are extracted through device connection frequency analysis (such as based on the number of connections per hour or per day). For example, for an airport network system, the system will extract the device identity data of each router and switch in the past week based on historical data records, and its connection frequency in different time periods. For example, the average number of connections per hour for a certain switch is 30 times, while the connection frequency of another switch is only 10 times, thereby obtaining the device identity data and connection frequency data.
[0111] Step S132: performing communication network node identification on the network device identity data to obtain communication network node data;
[0112] In this embodiment, device identity data is used to identify communication network nodes, and a graph-theory-based node identification method (such as connectivity graph analysis or BFS algorithm) is used to classify device identities, identify devices belonging to the same network segment, and identify them as the same communication network node. Specifically, by associating the identified devices with switches, routers and other devices, each key device in the airport network will be marked as a communication network node. For example, the airport network includes multiple levels of switches, routers and wireless access points. The system identifies nodes such as main switches and terminal device access points by analyzing information such as device MAC addresses and IP addresses to form a network node data set.
[0113] Step S133: dividing the communication network node data into communication network node data according to the network device connection frequency data, and obtaining network connection source node data and network connection target node data;
[0114] In this embodiment, a clustering algorithm (such as K-means clustering) is used to divide the communication network nodes into network connection source nodes and target nodes based on the device connection frequency data. The division is based on the source and target of the device connection, such as a switch or router is the starting point of the connection traffic (source node), and the other device is the target node. For example, if a router establishes connections with multiple terminal devices every hour and the connection frequency is high, the router is classified as a source node; and the terminal devices connected to this router are classified as target nodes.
[0115] Step S134: performing node link relationship identification on the network connection source node data and the network connection target node data to obtain network node link relationship data;
[0116] In this embodiment, the link relationship between the network connection source node data and the target node data is identified, and the network traffic analysis algorithm (such as link prediction or maximum flow algorithm) is applied to identify the communication link between the source node and the target node. Specifically, the data packet flow path in the network protocol (such as TCP / IP protocol) is used to detect the data transmission between the nodes in the network. For example, when a node A frequently communicates with multiple nodes B, C, etc., the link relationship between these nodes will be analyzed, the communication link data between them will be identified, and finally the link relationship between the source node and the target node will be obtained.
[0117] Step S135: Perform network node topology structure analysis based on network node link relationship data and communication network node data to obtain an airport network topology map.
[0118] In this embodiment, the network node topology is analyzed using a graph algorithm based on the network node link relationship data and the communication network node data, and finally a complete topology diagram of the airport network is generated. Specifically, each device of the airport network (such as a switch, a router, a terminal device, etc.) is first represented as a node in the graph, and the communication link between the devices is represented as an edge in the graph. A graph algorithm (such as the Dijkstra shortest path algorithm, the Kruskal minimum spanning tree algorithm, or the Bellman-Ford algorithm) is used to analyze the connection relationship and transmission path between the devices, thereby identifying the shortest path and transmission route between each node in the network. For example, in actual applications, if there is a complex link relationship between a main switch of an airport and multiple sub-switches and wireless access points, the system will use a graph algorithm to calculate the shortest connection path between each device, and at the same time comprehensively consider the bandwidth, delay, and load attributes of the network nodes to generate an effective topology model. This topology diagram not only shows the direct connection relationship between device nodes, but also provides a basis for subsequent optimization of data transmission paths to ensure communication efficiency and stability.
[0119] Optionally, step S2 specifically includes:
[0120] Step S21: extracting network communication security logs and network traffic monitoring data from the aviation airport network communication data to obtain network communication security logs and network traffic monitoring data, and performing frequency domain conversion on the network traffic monitoring data to obtain a network traffic monitoring spectrum;
[0121] In this embodiment, network communication security log extraction and network traffic monitoring data extraction are performed on the aviation airport network communication data to obtain network communication security logs and network traffic monitoring data. The real-time communication data of each node and link is extracted from the network monitoring device through the airport network security management platform, including information such as transmission data packets, transmission protocols, transmission delays, and communication errors. Then, the network traffic monitoring data is converted into the frequency domain, and the time domain signal is converted into a frequency domain signal using a fast Fourier transform (FFT) to obtain a spectrum diagram. At this time, high-frequency interference signals, potential communication attacks, and irregular traffic patterns in the traffic can be identified through frequency domain analysis. For example, if there is an excessively high frequency of data packet transmission or abnormal communication fluctuations in the monitoring data, the data will be extracted and used as the basic data for further analysis. The spectrum diagram of the network traffic is obtained to provide information support for subsequent security analysis and evaluation.
[0122] Step S22: dividing the intrusion node frequency of the airport network communication topology model according to the network communication security log to obtain intrusion frequency node division data;
[0123] In this embodiment, the communication security log of each node is analyzed, and the frequency of intrusion nodes is divided by identifying abnormal behaviors that frequently appear in the log (such as frequent retransmissions, connection rejections, abnormal login attempts, etc.). The intrusion behaviors of these nodes are divided into different frequency levels (for example: low frequency, medium frequency and high frequency), so as to evaluate the potential threat level of each node within a certain time range. By dividing these intrusion nodes, it is possible to identify which nodes have frequent security incidents in a short period of time, thereby providing a basis for network security assessment and subsequent protection strategies. For example, if the intrusion frequency of a node reaches the high frequency range, it means that the node is experiencing a network attack or malicious traffic.
[0124] Step S23: performing traffic load pattern recognition according to the network traffic monitoring spectrum to obtain network traffic non-periodic load pattern data and network traffic periodic load pattern data; performing high-frequency load pattern node division according to the network traffic non-periodic load pattern data and the network traffic periodic load pattern data to obtain high-frequency load pattern node division data;
[0125] In this embodiment, the signal distribution of different frequencies in the spectrum diagram is analyzed to identify periodic and non-periodic changes in network traffic. For example, after fast Fourier transform (FFT), network traffic can be divided into two modes: periodic fluctuations and irregular fluctuations. Periodic load patterns usually indicate normal network usage patterns, while non-periodic load patterns are traffic fluctuations caused by malicious attacks or network anomalies. After identification, high-frequency load pattern nodes are further divided according to the characteristics of the traffic, and high-frequency load pattern nodes are classified from low-frequency load pattern nodes. Based on the traffic frequency, each node will be automatically labeled and identified as a high-frequency load pattern node or a low-frequency load pattern node, thereby helping to discover potential high-load or high-risk nodes.
[0126] Step S24: Perform transmission node security assessment according to the intrusion frequency node division data and the high-frequency load mode node division data to obtain transmission node security data;
[0127] In this embodiment, the intrusion frequency node data and high-frequency load pattern node data are combined to perform a multi-dimensional security assessment. Specifically, the system evaluates the security and reliability of these nodes by analyzing nodes that are frequently attacked or have abnormal loads. For example, the intersection of nodes with high intrusion frequencies and high-load non-periodic pattern nodes will be marked as "high-risk" nodes, while nodes with low-frequency intrusions and high-load periodicity will be marked as "low-risk" nodes. This process relies on deep learning models and rule engines to automatically evaluate the risk level of each node and output the security data of the transmission node.
[0128] Step S25: dynamically allocate the transmission path encryption protocol to the transmission path data to be allocated based on the transmission node security data to obtain an encrypted path mapping table.
[0129] In this embodiment, the transmission path to be allocated is analyzed and the encryption protocol is dynamically allocated based on the security data of the node. First, different levels of encryption protocols are allocated to each node based on the security data of the node (such as intrusion frequency, load pattern, etc.). For low-security nodes, a strong encryption algorithm, such as AES-256-bit encryption, is automatically selected to ensure the confidentiality of the transmitted data; for high-security nodes, a lower-strength encryption algorithm (such as AES-128-bit encryption) is selected. Next, an encryption path mapping table is generated in combination with the network topology and path allocation requirements, which includes the encryption protocol and corresponding encryption level of each path. In this way, it is ensured that each path uses an encryption protocol that matches its security. Finally, the encryption path mapping table is uploaded to the airport network security management platform to provide encryption path guidance for subsequent data transmission.
[0130] Optionally, step S24 is specifically:
[0131] Perform node classification on the intrusion frequency node division data to obtain high-frequency communication intrusion node data and low-frequency communication intrusion node data;
[0132] In this embodiment, the network traffic is monitored and the intrusion frequency data of the node is extracted. The intrusion frequency data is quantified based on the number of intrusion events of the node within a period of time, and a time window (such as 30 minutes) is selected for analysis. When the number of intrusion events is higher than the preset threshold (for example, more than 5 intrusion events per hour), the node is classified as a high-frequency communication intrusion node, otherwise it is classified as a low-frequency communication intrusion node. Through this classification, nodes with high-frequency attack behaviors can be identified for subsequent security assessment.
[0133] Perform node classification on the high-frequency load mode node division data to obtain high-frequency periodic load mode node data and high-frequency non-periodic load mode node data;
[0134] In this embodiment, the load pattern of the node is identified based on the long-term analysis of the traffic load data. A high-frequency load pattern node generally refers to a node that maintains high load or high traffic transmission in frequent time periods. When the load of the node fluctuates periodically and the fluctuation amplitude exceeds a certain threshold, it is classified as a high-frequency periodic load pattern node; and when the load changes without obvious regularity and shows no periodic changes, the node is classified as a high-frequency non-periodic load pattern node. This classification helps to identify nodes with different load behaviors and further determine the security of transmission.
[0135] Perform node intersection operation based on high-frequency communication intrusion node data and high-frequency non-periodic load mode node data to obtain low-security transmission node data;
[0136] In this embodiment, the classified high-frequency communication intrusion nodes and the classified high-frequency non-periodic load mode nodes are intersected to find the node data that meets both requirements. For example, when a node is both a high-frequency intrusion node and a non-periodic node with irregular load changes, the node will be automatically marked as a low-security node. The specific implementation of the intersection operation can be completed through SQL query or set operation, and finally the node data with low security risk is identified.
[0137] Perform node intersection calculation based on low-frequency communication intrusion node data and low-frequency non-periodic load mode node data to obtain high-security transmission node data;
[0138] In this embodiment, the classified low-frequency communication intrusion node data and low-frequency non-periodic load mode node data are intersected to identify nodes belonging to both. These nodes exhibit low-frequency intrusion behaviors and infrequent load changes, indicating that these nodes have high security and are suitable for data transmission as high-security nodes. The intersection operation ensures that only nodes that meet these two conditions can be classified as high-security nodes, avoiding nodes with high-frequency attacks or load fluctuations from participating in important data transmission.
[0139] The low-security transmission node data and the high-security transmission node data are combined to obtain transmission node security data.
[0140] In this embodiment, the obtained low-security transmission node data and the obtained high-security transmission node data are merged. The merging process includes integrating the two sets of data into a comprehensive data set. Through the data merging operation, the two sets of node data are integrated into a complete transmission node security data set. During the merging process, the low-security node data and the high-security node data are directly spliced according to the original format to ensure that the data of each node remains in its original state. For example, if the low-security node data includes information such as node ID, intrusion frequency, load pattern, etc., and the high-security node data includes information such as node ID, load pattern, historical security records, etc., all relevant feature data of each node will be retained during the merge. Ultimately, the merged data set will include the security information of all transmission nodes, which will provide the basis for the subsequent transmission path encryption protocol allocation.
[0141] Optionally, step S3 specifically includes:
[0142] Step S31: Obtain node verification data through the network security management platform, and perform data preprocessing on the node verification data to obtain the node verification data to be analyzed;
[0143] In this embodiment, the network security management platform obtains node verification data once an hour. The data includes the device's identity authentication information, verification timestamp, verification request frequency, and geographic location. After the data is acquired, preprocessing operations are performed, including removing invalid data and format conversion. In this process, the Z-score method is used to detect outliers in the verification frequency, and abnormal data exceeding 3 standard deviations is removed. After data cleaning, a data set in a unified format is generated to ensure that the verification request data of each device has a standard timestamp (accurate to seconds), location data (accurate to 4 decimal places) and verification frequency data (time window is 30 minutes). The cleaned data is stored in the database and is ready for subsequent analysis.
[0144] Step S32: extract node verification features from the node verification data to be analyzed, and obtain node verification device location data and node verification device frequency data;
[0145] In this embodiment, the Pandas library in Python is used to extract device location data and device frequency data based on the cleaned data. The device location data is extracted based on longitude and latitude with an accuracy of 5 meters. The geographical location of each device is obtained by calculating the average location coordinates of the device; the device frequency data is obtained by counting the number of verification requests for each node within 30 minutes, using a time window length of 10 minutes to calculate the verification frequency and change trend of each node. The verification frequency data of the device is calculated using the sliding window method, and the verification frequency data of each device will be smoothed by the standard deviation to ensure the stability and accuracy of the data.
[0146] Step S33: Perform spatial distribution statistics of the verification equipment according to the node verification equipment location data to obtain equipment verification location frequency data; perform verification equipment verification frequency statistics on the node verification equipment frequency data to obtain equipment short-time verification frequency data;
[0147] In this embodiment, the device location data uses the K-means clustering algorithm to perform spatial distribution statistics, dividing the airport area into 50 grids, each with a side length of 100 meters. The number and distribution of verification devices in each grid are counted. The verification frequency data is calculated by counting the number of verifications of the device by hour, and the short-term verification frequency of the device is calculated based on a time window length of 60 minutes (unit: times / minute), and a verification frequency heat map is generated by visualization. The data parameters used in this process include: the number of clusters in the K-means clustering is set to 50, and the time window is set to every hour.
[0148] Step S34: performing device verification abnormal behavior detection based on the device verification location frequency data and the device short-time verification frequency data to obtain node verification behavior detection data;
[0149] In this embodiment, the device behavior is analyzed by using an anomaly detection algorithm in combination with the spatial distribution data and frequency data of the device. By setting a reasonable threshold (for example, the verification frequency exceeds a certain standard deviation), those devices with abnormal behavior can be identified. For example, the device is verified during abnormal periods or frequently verified at different locations. The anomaly detection algorithm can use a statistical Z-score method or an isolated forest algorithm based on machine learning, etc., to score the device according to the preset behavior pattern, and finally output a list of devices with abnormal behavior. The verification frequency and location frequency data of the device are Z-score processed respectively, and the nodes with detection values exceeding 3 standard deviations are marked as abnormal. Further, an anomaly detection is performed using an isolated forest algorithm, in which the parameters of the model are set to 100 trees and 20 samples, which are used to identify devices with abnormal verification frequencies. The detection results identify abnormal devices through threshold settings (such as devices with a verification frequency greater than 5 times / minute are considered to be frequently verified devices), and a list of abnormal behaviors of the device is generated. Finally, according to the nodes associated with the device, the abnormal behavior detection results of the device are mapped to the associated nodes, thereby generating node verification behavior detection data.
[0150] Step S35: Perform transmission node credibility assessment on the airport network communication topology model based on the node verification behavior detection data to obtain a node behavior analysis report.
[0151] In this embodiment, the credibility of each node is evaluated, and the evaluation indicators include the node's verification frequency, the geographic location consistency of the verification request (for example, whether the device verification occurs in the expected area), and the success rate of the verification request. In specific implementation, the weighted average method is used, and the verification frequency weight is set to 0.6, the location consistency weight is set to 0.3, and the verification success rate weight is set to 0.1 to calculate the comprehensive credibility score of each node. The credibility score of the node is calculated by comprehensively considering the behavior pattern of the device. The score ranges from 0 to 1. The higher the score, the higher the security of the node. Finally, a node behavior analysis report is generated, which will include the node security score, ranking, and recommended measures for unsafe nodes.
[0152] Optionally, step S35 is specifically:
[0153] Step S351: extract abnormal verification behavior nodes from the node verification behavior detection data to obtain abnormal verification behavior node data;
[0154] In this embodiment, the node verification behavior detection data is analyzed, and the Z-score method is used to detect abnormal verification behavior nodes. The threshold is set to 3 standard deviations, and verification behaviors beyond this range will be considered abnormal behaviors. Further, the verification request frequency of the node is tracked using data flow detection technology to screen out nodes with abnormally high request times in a short period of time. For example, nodes with more than 100 requests within 5 minutes will be marked as abnormal verification behavior nodes. These abnormal nodes are extracted according to this rule, and a list of abnormal verification behavior nodes is generated to ensure that only nodes with significant deviations are identified as abnormal.
[0155] Step S352: Perform abnormal verification behavior frequency statistics and abnormal verification behavior time period statistics according to the abnormal verification behavior node data to obtain node abnormal verification behavior frequency data and node abnormal verification behavior time period distribution data;
[0156] In this embodiment, the verification frequency of each abnormal verification behavior node is counted, the number of verification requests per hour, day and month is calculated, and the Pandas library is used for data processing to generate a frequency distribution graph. At the same time, the time period of the abnormal verification behavior node is analyzed using the time series analysis method, and the frequency of abnormal behavior of each node in different time periods (such as 8:00-9:00, 12:00-13:00, etc.) is counted to form the node abnormal behavior time period distribution data. The time window length used for this time period statistics is 1 hour, and the frequency statistics are divided into high-frequency intervals and low-frequency intervals to distinguish between high-incidence periods and low-incidence periods of abnormal behavior.
[0157] Step S353: Calculate the severity score of abnormal behavior based on the node abnormal verification behavior frequency data to obtain the severity score data of the node abnormal behavior;
[0158] In this embodiment, the frequency data of each abnormal verification behavior node is standardized. By calculating the standard deviation of each node in its abnormal behavior frequency and multiplying it by a weight coefficient (such as 0.7), the degree of frequency deviation is converted into a score, and the score range is set to 0 to 10 points. The frequency score and the number of times the node is abnormal (for example, 5 consecutive verification failures) jointly affect the severity score of the node. The weighted average method is used, and the frequency score weight is 0.5 and the abnormal number score weight is 0.5. The parameters used in this step are that the frequency deviation standardization coefficient is set to 2, and the weight coefficient and weighted score are dynamically adjusted according to the settings.
[0159] Step S354: Calculate the node abnormal verification behavior period proportion according to the node abnormal verification behavior period distribution data to obtain the node abnormal verification behavior period proportion data;
[0160] In this embodiment, the time period during which abnormal verification behavior of the node occurs is counted, and the abnormal behavior ratio of each node is calculated. According to the historical verification data, the normal verification time interval of the node verification is determined, and the abnormal verification time period ratio of the node is calculated based on this normal time interval. For example, if the normal verification time interval of a node is 8:00-10:00, and the abnormal behavior of the node occurs in the two time periods of 8:00-9:00 and 12:00-13:00, and the total number of occurrences is 20 times, and 10 times in the 8:00-9:00 time period, then the abnormal behavior ratio of its normal verification time period is 50%, and the abnormal behavior ratio of the abnormal verification time period is 50%. Use Excel or a database table to count the ratios of different time periods, generate the time period ratio data for each node, and output the probability of abnormal behavior of each node in different time periods.
[0161] Step S355: weighting the node behavior safety score data on the node abnormal behavior severity score data and the node abnormal verification behavior time period proportion data to obtain the node behavior safety score data;
[0162] In this embodiment, according to the abnormal behavior severity score of each node and the abnormal verification behavior period proportion data, a weighting coefficient is set (for example, the severity score weighting coefficient is 0.4, the normal period abnormal proportion weighting coefficient is 0.2, and the abnormal period abnormal proportion weighting coefficient is 0.4) to perform weighted synthesis. After weighting, the comprehensive security score of the node reflects the overall security risk of the node. The higher the score, the greater the security risk of the node. The weighted score is calculated based on the weighted average method, and the synthesized score can be dynamically updated to facilitate real-time adjustment of the node's security assessment.
[0163] Step S356: Visualize the node score space of the airport network communication topology model according to the node behavior security score data to obtain a node behavior analysis report.
[0164] In this embodiment, a visualization tool (such as Gephi or Matplotlib) is used to spatially visualize the security score of each node, and the network topology diagram is combined with the node score to generate a dynamic visualization chart. In the visualization diagram, high-security nodes are displayed in green, and low-security nodes are displayed in red, showing the location and distribution of high-risk nodes in the network through graphics. During the specific implementation, the force-directed layout algorithm is used to layout the network nodes to ensure that the node security score can be intuitively reflected in the figure. Finally, a node behavior analysis report is generated, which lists the security score and risk assessment of each node in detail, and the report can be used for security auditing and network optimization.
[0165] Optionally, step S4 specifically includes:
[0166] Step S41: selecting a data transmission security node according to the node behavior analysis report to obtain security node data to be distributed;
[0167] In this embodiment, based on the security score data in the node behavior analysis report, nodes with security scores higher than the set threshold (for example, nodes with scores higher than 80% of the scores) are selected as security nodes. On this basis, the network segments where these nodes are located are screened out for secure transmission tasks. Furthermore, by analyzing the behavior patterns of the nodes, such as the authentication success rate and the normal communication frequency, the stability of the selected nodes is further verified to ensure the security of data transmission. Finally, the security node data to be distributed is obtained, recorded as the security node data set to be distributed, and prepared for subsequent encryption path allocation.
[0168] Step S42: selecting a path with a high security node ratio in the encryption path mapping table according to the security node data to be distributed, and obtaining the encryption path data to be distributed;
[0169] In this embodiment, the node ID and the corresponding security score are extracted from the security node data to be distributed, and the nodes with higher scores are sorted according to the scores, and the nodes with higher scores (for example, the nodes with the top 30% scores) are selected. Then, the paths occupied by these high-security nodes are screened and optimized through the encryption path mapping table. In the specific operation, an optimal encryption path is selected for data transmission based on indicators such as bandwidth, latency and security score of each path. When selecting a path, paths with stable transmission, large bandwidth and low latency are given priority. Finally, the encrypted path data set to be distributed is obtained for the next encryption task.
[0170] Step S43: performing encryption key negotiation on the encrypted path data to be distributed, obtaining an encryption key pair, and uploading it to the airport network security management platform to execute the encryption key distribution task;
[0171] In this embodiment, a public key encryption algorithm (such as RSA or ECC) is used for key negotiation. A symmetric encryption key is generated through a security protocol (such as the Diffie-Hellman key exchange protocol). These encryption algorithms are used to securely connect to the terminal nodes of each path to be distributed, and generate a dedicated encryption key pair. After the key is generated, the key pair is securely stored and uploaded to the airport network security management platform through an encrypted communication channel. After the platform receives the key, it executes the key distribution task to ensure that each encrypted path has the corresponding encryption key for data transmission.
[0172] Step S44: acquiring the data to be transmitted of the aviation airport, and performing data preprocessing on the data to be transmitted of the aviation airport to obtain the data to be transmitted of the aviation airport to be analyzed;
[0173] In this embodiment, the aviation airport data to be transmitted (such as flight scheduling data or cargo transportation information) is obtained from the data source (such as the internal application system of the airport). These data are initially cleaned and formatted, invalid or erroneous data are eliminated, and the valid data are standardized. By using data processing tools (such as the Pandas library in Python), the data is organized into a unified format, and field filling, deduplication and outlier processing are performed according to preset rules. Finally, the aviation airport data to be analyzed is generated and is ready for further data packet segmentation operations.
[0174] Step S45: segmenting the data to be transmitted by the airport to be analyzed into data packets to obtain a set of segmented data packets to be transmitted;
[0175] In this embodiment, the data to be analyzed is segmented according to the preset packet size, and the size of each data packet is set to 1MB to 10MB to balance transmission efficiency and data security. During the segmentation process, a unique identifier is generated for each data packet, and necessary header information such as source node ID, target node ID, timestamp, etc. is attached. Appropriate segmentation is also performed according to the type of data content (such as text, video, or sensor data) to ensure that each data packet contains complete valid data and maintains data integrity and order.
[0176] Step S46: Encrypt the virtual tunnel data of the segmented data packet set to be transmitted according to the encryption key to obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to execute the data transmission task.
[0177] In this embodiment, each segmented data packet to be transmitted is encrypted by a pre-acquired encryption key pair. A symmetric encryption algorithm (such as AES-256) is used for data encryption, and a 256-bit key length is selected to ensure high data security. During the encryption process, each data packet is bound to a corresponding encryption key pair, and an encrypted data packet is generated. Each encrypted data packet will be attached with a unique identifier (such as a packet sequence number, source node and target node identifiers, encryption timestamp, etc.) when encrypted, and the header information will be ensured not to be tampered with to maintain the integrity of the data. In order to ensure the confidentiality of data during network transmission, the encrypted data packet is further encapsulated by a virtual tunnel protocol (such as IPSec or SSL / TLS) to form an encrypted "tunnel" and specify a transmission path. Specifically, when using the IPSec protocol, an encrypted IP data packet is generated, and the data packet is encapsulated in a new IP header by the tunnel protocol to ensure that the data has multiple layers of encryption protection when it is transmitted in the network. When using the SSL / TLS protocol, an encrypted connection is created for each data packet to ensure the encryption and integrity of each data packet during network transmission. During the data packet encryption process, a hash value (such as SHA-256) is calculated and appended to verify the integrity of the data packet. When the data packet reaches the target node, the target node will use the same key pair to decrypt the data packet and verify the hash value to ensure that the data has not been tampered with. The encrypted data packet will be uploaded to the airport network security management platform, which will arrange the data transmission task according to the encryption path and node information to ensure that the data is transmitted to the target node safely and stably.
[0178] Optionally, step S5 specifically includes:
[0179] Step S51: acquiring the real-time communication data of the aviation airport, and performing data preprocessing on the real-time communication data of the aviation airport to obtain the real-time communication data of the aviation airport network to be analyzed;
[0180] In this embodiment, multiple communication devices (such as routers, switches, wireless access points, etc.) of the airport network are integrated to collect the information of the passing data packets in real time. Data preprocessing includes first filtering out error data packets (such as packets with mismatched checksums), then classifying the data according to the protocol type (such as TCP, UDP), and converting the data format, such as converting the original binary data packet into metadata in JSON format, to facilitate subsequent processing and analysis. During the preprocessing process, filtering rules are adopted, such as discarding a single data packet exceeding 2MB, to ensure the efficiency of subsequent analysis.
[0181] Step S52: Detect node link abnormal values on the real-time communication data of the aviation airport network to be analyzed by using the airport network communication topology model to obtain a real-time abnormality detection log;
[0182] In this embodiment, real-time data traffic monitoring is performed based on the airport network communication topology model. All passing links are detected with the help of set thresholds (such as the traffic of a single link exceeds 5GB / s or the delay exceeds 300ms). If the transmission delay, throughput or packet loss rate of the link is abnormal, it will be marked as an abnormal link, and an abnormal detection log will be generated to record the node, link and specific time when the abnormality occurred. This process is also combined with a model based on machine learning to continuously train the topology model to enhance the accuracy of anomaly detection.
[0183] Step S53: performing data packet delay calculation according to the real-time anomaly detection log to obtain data packet delay data, and classifying and calculating the data packet delay data according to a preset lost data packet delay threshold to obtain lost data packets;
[0184] In this embodiment, the delay is calculated in real time by comparing the sending time and receiving time of the data packets transmitted by the abnormal link in the real-time anomaly detection log. For each network node passed, its delay is calculated and the delay time is stored and counted. If the delay exceeds the set threshold (such as 300ms), the data packet will be marked as a "delayed data packet". According to the preset lost data packet delay threshold (such as continuous delays exceeding 3 times and exceeding 1000ms), it will be classified and marked as "lost data packets", and the identifiers and timestamps of these lost data packets will be recorded as the basis for subsequent processing. In order to improve accuracy, anomaly detection is also combined with the traffic analysis model to identify potential lost data packets.
[0185] Step S54: decrypting the lost data packet according to the encryption key to obtain a decrypted lost data packet;
[0186] In this embodiment, the data packet is decrypted by retrieving the relevant symmetric encryption key (e.g., AES-256 key) from the airport network security management platform. The decryption process includes using the acquired key in combination with the decryption process of the encryption algorithm (e.g., AES decryption) to restore the encrypted data byte by byte. All decryption operations are performed through a protected hardware security module (HSM) to prevent key leakage and ensure the security of the data decryption process. The decryption process will be carried out strictly in accordance with the set encryption protocol to ensure data integrity and security, and the decrypted data packet will be returned to the upper-level network application for further processing.
[0187] Step S55: reconstructing the decrypted lost data packets based on the segmented data packet set to be transmitted to obtain a restored data packet;
[0188] In this embodiment, after the lost data packet is decrypted, the specific location of the lost packet is determined based on the sequence number (Sequence Number) of the data packet and the source and destination addresses. Based on this information, a data retransmission mechanism (such as a TCP-based retransmission mechanism or a UDP application layer retransmission) is used to recover the lost data packet. If the lost packet cannot be recovered by retransmission, an error correction algorithm (such as the Reed-Solomon algorithm) is used to infer and recover the lost data using the complete data packets transmitted before and after. Each data packet in the recovery process will be checked to ensure that the reconstructed data packet is complete and meets the network protocol requirements. All recovered data packets will be returned to the data stream in the correct order to ensure smooth communication and data correctness.
[0189] Step S56: selecting a low-latency transmission path for the restored data packet according to the encrypted path data to be distributed, to obtain restored transmission path data;
[0190] In this embodiment, after the recovery data packet is reconstructed, the best path will be selected according to the real-time network topology and link quality data (such as bandwidth, delay, packet loss rate, etc.). The shortest path algorithm (such as Dijkstra algorithm) is used to calculate the possible transmission path, and the current network load and delay are taken into account. By monitoring the real-time delay of each link, the link with a delay of less than 100ms and a low load will be selected for data packet transmission. During the path selection process, the path will also be adjusted according to dynamic traffic analysis to ensure low-latency transmission and avoid high-traffic or congested nodes. At this time, the recovery data packet will be routed to the best path to ensure that the delay during transmission is minimized.
[0191] Step S57: Based on the encryption key pair, the virtual tunnel data is encrypted for the restored transmission path data and the restored data packet to obtain the restored encrypted data packet, and uploaded to the airport network security management platform to execute the data transmission task.
[0192] In this embodiment, after the transmission path is restored and determined, the data packet is encrypted based on the pre-assigned encryption key, and the data is protected using virtual tunnel technology (such as IPsec or SSL / TLS protocol). Specifically, the data packet is encapsulated and encrypted through the encryption protocol to ensure that it is not stolen or tampered with during network transmission. During the encryption process, the data is encrypted using a randomly generated initialization vector (IV) and encryption key to ensure that the encryption results of each data packet are different. The encrypted data packet will be stored and managed through the airport network security management platform. When the transmission task is executed, the encrypted data is taken out from the platform and sent to ensure the security and confidentiality of data transmission.
[0193] Optionally, this specification also provides an information data secure transmission system, which is used to execute the information data secure transmission method as described above, and the information data secure transmission system includes:
[0194] The communication network topology structure analysis module is used to obtain the aviation airport network communication data, and perform communication network topology structure analysis on the aviation airport network communication data to obtain the airport network communication topology structure model; select the data transmission path according to the airport network communication topology structure model to obtain the transmission path data to be allocated;
[0195] The node security assessment module is used to perform a security assessment of the intersection of transmission node load patterns on the airport network communication topology model according to the aviation airport network communication data, and obtain the transmission node security data; based on the transmission node security data, the transmission path encryption protocol is dynamically allocated to the transmission path data to be allocated, and an encrypted path mapping table is obtained;
[0196] The node behavior analysis module is used to obtain node verification data and perform a weighted credibility assessment of the node verification data by transmitting the node verification space frequency to obtain a node behavior analysis report;
[0197] The data packet encryption module is used to perform data packet virtual tunnel encryption based on the node behavior analysis report and the encryption path mapping table, obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to perform the data transmission task;
[0198] The real-time communication feedback recovery module is used to obtain the real-time communication data of the aviation airport network, and recover the abnormal data of the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
[0199] Therefore, the embodiments should be regarded as illustrative and non-restrictive from all points, and the scope of the present invention is limited by the appended claims rather than the above description, and it is therefore intended that all changes falling within the meaning and range of equivalent elements of the application documents are included in the present invention.
[0200] The above description is only a specific embodiment of the present invention, so that those skilled in the art can understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but should conform to the widest scope consistent with the principles and novel features invented herein.
Claims
1. A method for secure transmission of information data, characterized in that: The following steps are involved: Step S1: Acquire aviation airport network communication data, and perform communication network topology analysis on the aviation airport network communication data to obtain an airport network communication topology model; select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated; Step S2: Performing a security assessment of the intersection of transmission node load patterns on the airport network communication topology model based on the aviation airport network communication data to obtain transmission node security data; Based on the transmission node security data, a transmission path encryption protocol is dynamically allocated to the transmission path data to be allocated, and an encrypted path mapping table is obtained; Step S3: Obtain node verification data, and perform transmission node verification space frequency weighted credibility assessment on the node verification data to obtain a node behavior analysis report; Step S4: Based on the node behavior analysis report and the encryption path mapping table, the data packet virtual tunnel is encrypted to obtain the aviation airport encrypted data packet to be transmitted, and the data packet is uploaded to the airport network security management platform to execute the data transmission task; Step S5: Acquire the real-time communication data of the aviation airport network, perform abnormal data recovery on the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to execute the data transmission task.
2. The information data security transmission method according to claim 1, characterized in that: Step S1 is specifically as follows: Step S11: obtaining the aviation airport network communication data through the airport network security management platform, and performing data preprocessing on the aviation airport network communication data to obtain the aviation airport network communication data to be analyzed; Step S12: extracting airport network communication features from the aviation airport network communication data to be analyzed, and obtaining network communication connection data and network dynamic resource allocation data; Step S13: Analyze the airport network topology structure according to the network communication connection data to obtain an airport network topology map; Step S14: performing dynamic topology data modeling on the airport network topology map based on the network dynamic resource allocation data to obtain an airport network communication topology structure model; Step S15: Select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated.
3. The information data security transmission method according to claim 2 is characterized in that: Step S13 is specifically as follows: Step S131: extracting device identity features and device connection frequency features according to the network communication connection data to obtain network device identity data and network device connection frequency data; Step S132: performing communication network node identification on the network device identity data to obtain communication network node data; Step S133: dividing the communication network node data into communication network node data according to the network device connection frequency data, and obtaining network connection source node data and network connection target node data; Step S134: performing node link relationship identification on the network connection source node data and the network connection target node data to obtain network node link relationship data; Step S135: Perform network node topology structure analysis based on network node link relationship data and communication network node data to obtain an airport network topology map.
4. The information data security transmission method according to claim 1, characterized in that: Step S2 is specifically as follows: Step S21: extracting network communication security logs and network traffic monitoring data from the aviation airport network communication data to obtain network communication security logs and network traffic monitoring data, and performing frequency domain conversion on the network traffic monitoring data to obtain a network traffic monitoring spectrum; Step S22: dividing the intrusion node frequency of the airport network communication topology model according to the network communication security log to obtain intrusion frequency node division data; Step S23: performing traffic load pattern recognition according to the network traffic monitoring spectrum to obtain network traffic aperiodic load pattern data and network traffic periodic load pattern data; Perform high-frequency load mode node division according to network traffic non-periodic load mode data and network traffic periodic load mode data to obtain high-frequency load mode node division data; Step S24: Perform transmission node security assessment according to the intrusion frequency node division data and the high-frequency load mode node division data to obtain transmission node security data; Step S25: dynamically allocate the transmission path encryption protocol to the transmission path data to be allocated based on the transmission node security data to obtain an encrypted path mapping table.
5. The information data security transmission method according to claim 1, characterized in that: Step S24 is specifically as follows: Perform node classification on the intrusion frequency node division data to obtain high-frequency communication intrusion node data and low-frequency communication intrusion node data; Perform node classification on the high-frequency load mode node division data to obtain high-frequency periodic load mode node data and high-frequency non-periodic load mode node data; Perform node intersection operation based on high-frequency communication intrusion node data and high-frequency non-periodic load mode node data to obtain low-security transmission node data; Perform node intersection calculation based on low-frequency communication intrusion node data and low-frequency non-periodic load mode node data to obtain high-security transmission node data; The low-security transmission node data and the high-security transmission node data are combined to obtain transmission node security data.
6. The information data security transmission method according to claim 1, characterized in that: Step S3 is specifically as follows: Step S31: Obtain node verification data through the network security management platform, and perform data preprocessing on the node verification data to obtain the node verification data to be analyzed; Step S32: extract node verification features from the node verification data to be analyzed, and obtain node verification device location data and node verification device frequency data; Step S33: Perform spatial distribution statistics of the verification equipment according to the node verification equipment location data to obtain equipment verification location frequency data; perform verification equipment verification frequency statistics on the node verification equipment frequency data to obtain equipment short-time verification frequency data; Step S34: performing device verification abnormal behavior detection based on the device verification location frequency data and the device short-time verification frequency data to obtain node verification behavior detection data; Step S35: Perform transmission node credibility assessment on the airport network communication topology model based on the node verification behavior detection data to obtain a node behavior analysis report.
7. The information data security transmission method according to claim 6, characterized in that: Step S35 is specifically as follows: Step S351: extract abnormal verification behavior nodes from the node verification behavior detection data to obtain abnormal verification behavior node data; Step S352: Perform abnormal verification behavior frequency statistics and abnormal verification behavior time period statistics according to the abnormal verification behavior node data to obtain node abnormal verification behavior frequency data and node abnormal verification behavior time period distribution data; Step S353: Calculate the severity score of abnormal behavior based on the node abnormal verification behavior frequency data to obtain the severity score data of the node abnormal behavior; Step S354: Calculate the node abnormal verification behavior period proportion according to the node abnormal verification behavior period distribution data to obtain the node abnormal verification behavior period proportion data; Step S355: weighting the node behavior safety score data on the node abnormal behavior severity score data and the node abnormal verification behavior time period proportion data to obtain the node behavior safety score data; Step S356: Visualize the node score space of the airport network communication topology model according to the node behavior security score data to obtain a node behavior analysis report.
8. The information data secure transmission method according to claim 1, characterized in that: Step S4 is specifically as follows: Step S41: selecting a data transmission security node according to the node behavior analysis report to obtain security node data to be distributed; Step S42: selecting a path with a high security node ratio in the encryption path mapping table according to the security node data to be distributed, and obtaining the encryption path data to be distributed; Step S43: performing encryption key negotiation on the encrypted path data to be distributed, obtaining an encryption key pair, and uploading it to the airport network security management platform to execute the encryption key distribution task; Step S44: acquiring the data to be transmitted of the aviation airport, and performing data preprocessing on the data to be transmitted of the aviation airport to obtain the data to be transmitted of the aviation airport to be analyzed; Step S45: segmenting the data to be transmitted by the airport to be analyzed into data packets to obtain a set of segmented data packets to be transmitted; Step S46: Encrypt the virtual tunnel data of the segmented data packet set to be transmitted according to the encryption key to obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to execute the data transmission task.
9. The information data security transmission method according to claim 1, characterized in that: Step S5 is specifically as follows: Step S51: acquiring the real-time communication data of the aviation airport, and performing data preprocessing on the real-time communication data of the aviation airport to obtain the real-time communication data of the aviation airport network to be analyzed; Step S52: Detect node link abnormal values on the real-time communication data of the aviation airport network to be analyzed by using the airport network communication topology model to obtain a real-time abnormality detection log; Step S53: performing data packet delay calculation according to the real-time anomaly detection log to obtain data packet delay data, and classifying and calculating the data packet delay data according to a preset lost data packet delay threshold to obtain lost data packets; Step S54: decrypting the lost data packet according to the encryption key to obtain a decrypted lost data packet; Step S55: reconstructing the decrypted lost data packets based on the segmented data packet set to be transmitted to obtain a restored data packet; Step S56: selecting a low-latency transmission path for the restored data packet according to the encrypted path data to be distributed, to obtain restored transmission path data; Step S57: Based on the encryption key pair, the virtual tunnel data is encrypted for the restored transmission path data and the restored data packet to obtain the restored encrypted data packet, and uploaded to the airport network security management platform to execute the data transmission task.
10. An information data security transmission system, characterized in that: Used to execute the information data security transmission method as claimed in claim 1, the information data security transmission system comprises: The communication network topology structure analysis module is used to obtain the aviation airport network communication data, and perform communication network topology structure analysis on the aviation airport network communication data to obtain the airport network communication topology structure model; select the data transmission path according to the airport network communication topology structure model to obtain the transmission path data to be allocated; The node security assessment module is used to perform a security assessment of the intersection of transmission node load patterns on the airport network communication topology model according to the aviation airport network communication data, and obtain the transmission node security data; based on the transmission node security data, the transmission path encryption protocol is dynamically allocated to the transmission path data to be allocated, and an encrypted path mapping table is obtained; The node behavior analysis module is used to obtain node verification data and perform a weighted credibility assessment of the node verification data by transmitting the node verification space frequency to obtain a node behavior analysis report; The data packet encryption module is used to perform data packet virtual tunnel encryption based on the node behavior analysis report and the encryption path mapping table, obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to perform the data transmission task; The real-time communication feedback recovery module is used to obtain the real-time communication data of the aviation airport network, and recover the abnormal data of the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
Citation Information
Patent Citations
Distributed data encryption transmission system
CN117955749A
Method for automatically verifying security of communication software
CN119071073A
Industrial internet security situation assessment system based on deep learning
CN119324819A
Intrusion management
US20150271193A1
Systems and methods for securing information
US20210014205A1
Cited By
Database management method based on data analysis
CN120296007A