Method and system for secure transmission of information data
By constructing an airport network topology model and a dynamic encryption protocol, the problems of delay and bandwidth consumption in aviation airport information transmission caused by traditional encryption technology are solved, secure and real-time data transmission is achieved, and system efficiency and security are improved.
Patent Information
- Application Number
- CN202510198491.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-22
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-02-22
AI Technical Summary
Traditional encryption technology has high computational overhead in aviation and airport information transmission, resulting in increased delays and bandwidth consumption, affecting the real-time performance of data transmission and system efficiency, especially when transmitting high-frequency and large-scale data.
By building an airport network communication topology model, data transmission path selection and dynamic allocation of encryption protocols are carried out, and node verification and virtual tunnel encryption are combined to achieve secure transmission of data packets and real-time recovery of abnormal data.
It improves the security and real-time performance of data transmission, reduces latency and bandwidth consumption, ensures the timely transmission of critical information, and improves the efficiency and safety of aviation operations.
Smart Images

Figure CN120017388B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information transmission, and in particular to a method and system for securely transmitting information data. Background Art
[0002] With the rapid development of the global aviation industry, airports, as crucial hubs for flight management and passenger services, carry a vast amount of critical data in their information systems, including flight schedules, passenger information, baggage tracking, and security monitoring. This information not only impacts airline operational efficiency but also passenger safety and privacy. For the past few decades, airport information transmission systems have primarily relied on traditional communication protocols and security measures, such as encryption, identity authentication, and digital signatures, to ensure the confidentiality and integrity of data during transmission. Traditional secure transmission methods include data transmission based on encryption algorithms, communication security based on VPNs (Virtual Private Networks) and TLS (Transport Layer Security) protocols, and trust management relying on centralized certification authorities. While these technologies provide a certain degree of data security, traditional encryption techniques such as symmetric and public-key cryptography, while effective in preventing data theft, carry high computational overhead for high-frequency, high-volume data transmission, leading to transmission delays. Real-time data transmission and rapid response are crucial for airport information transmission. For example, in flight scheduling and emergency response, delays can lead to untimely information delivery and even compromise aviation safety. However, existing encryption algorithms, especially when the data volume is large and involves multiple transmission nodes, often add additional delays and bandwidth consumption, thereby affecting the overall efficiency of the system. Summary of the Invention
[0003] Based on this, it is necessary for the present invention to provide a method and system for securely transmitting information data to solve at least one of the above technical problems.
[0004] To achieve the above-mentioned purpose, a method for securely transmitting information data includes the following steps:
[0005] Step S1: Acquire aviation airport network communication data, and perform communication network topology analysis on the aviation airport network communication data to obtain an airport network communication topology model; select a data transmission path based on the airport network communication topology model to obtain transmission path data to be allocated;
[0006] Step S2: performing a security assessment of the intersection of transmission node load patterns on the airport network communication topology model based on the aviation airport network communication data to obtain transmission node security data; dynamically assigning a transmission path encryption protocol to the transmission path data to be assigned based on the transmission node security data to obtain an encrypted path mapping table;
[0007] Step S3: Obtain node verification data, and perform a weighted credibility assessment of the node verification data using the transmission node verification space frequency to obtain a node behavior analysis report;
[0008] Step S4: Based on the node behavior analysis report and the encryption path mapping table, the data packet is encrypted in a virtual tunnel to obtain the airport encrypted data packet to be transmitted, and uploaded to the airport network security management platform to execute the data transmission task;
[0009] Step S5: Acquire the real-time communication data of the aviation airport network, perform abnormal data recovery on the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
[0010] By systematically analyzing aviation and airport network communication data and constructing a model of the airport network communication topology, this method effectively understands and optimizes the overall network structure, ensuring the efficiency and reliability of data transmission paths. This process helps identify and avoid potential network bottlenecks and reduces data transmission delays, particularly for data transmission tasks involving multiple transmission nodes. In the data transmission path selection process, incorporating the network topology model allows for the dynamic selection of the optimal transmission path, further improving transmission speed and accuracy, ensuring the real-time transmission of emergency information and critical data, and thus enhancing aviation operational efficiency and safety. By evaluating the intersection of transmission node load patterns and security, more accurate node security data can be obtained, and encryption protocols for transmission paths can be dynamically assigned based on this data. This not only ensures data transmission security but also reduces performance bottlenecks caused by over-encryption, avoiding the delays and bandwidth consumption associated with traditional encryption algorithms when transmitting high-frequency, high-volume data. This process is particularly helpful in improving system stability and responsiveness under high load conditions, ensuring the timeliness of critical services such as flight scheduling, passenger information, and baggage tracking. Node verification data transmission. A spatial frequency-weighted credibility assessment of node verification effectively detects potential security risks. By analyzing node behavior, it promptly identifies and responds to abnormal behavior, preventing data leakage or tampering. This process is crucial for improving overall network security, especially when transmitting sensitive information, ensuring data integrity and confidentiality to the greatest extent possible and preventing unauthorized access. During data packet transmission, the application of virtual tunnel encryption technology ensures data security during network transmission, preventing data theft or tampering during transmission. Furthermore, a real-time abnormal data recovery mechanism ensures rapid data recovery and continuous data transmission in the event of network interruptions or data loss. This solution not only improves data transmission security but also ensures data integrity and timely delivery in the event of network failures or attacks, thereby enhancing the reliability and security of the entire airport information system.
[0011] Optionally, step S1 specifically includes:
[0012] Step S11: obtaining the aviation airport network communication data through the airport network security management platform, and performing data preprocessing on the aviation airport network communication data to obtain the aviation airport network communication data to be analyzed;
[0013] Step S12: extracting airport network communication features from the aviation airport network communication data to be analyzed, and obtaining network communication connection data and network dynamic resource allocation data;
[0014] Step S13: Analyzing the airport network topology structure based on the network communication connection data to obtain an airport network topology map;
[0015] Step S14: performing dynamic topology data modeling on the airport network topology map based on the network dynamic resource allocation data to obtain an airport network communication topology structure model;
[0016] Step S15: Select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated.
[0017] By acquiring and pre-processing aviation airport network communication data, the present invention can effectively clean and normalize the original data, making it suitable for subsequent detailed analysis. This process can eliminate noise data and improve the accuracy of the analysis results, thereby providing a reliable basis for subsequent decision-making. By extracting airport network communication characteristics, including network communication connection data and dynamic resource allocation data, we can gain an in-depth understanding of the current status of the network and the usage of its resources, thereby providing accurate data support for the next step of network topology analysis and resource management. Using these data to analyze the network topology structure can help build an overall view of the airport network, identify each node and its interconnected relationship, and thus provide a clear framework for optimizing network performance and ensuring data transmission. Topology data modeling based on dynamic resource allocation data can make the airport network communication topology structure more in line with actual conditions, take into account the dynamic changes in resource allocation, and ensure that the network model is real-time and adaptable. This process is crucial for dealing with resource reallocation during peak periods or emergencies, and can improve the flexibility and responsiveness of the system. Ultimately, by selecting data transmission paths based on the established network topology model, optimal path planning can be achieved to ensure the efficiency and security of data transmission. Especially in complex network environments with multiple nodes and multiple paths, path optimization can be achieved, transmission delays and bandwidth waste can be reduced, ensuring that critical data can be delivered on time and accurately, thereby improving the overall efficiency and stability of the system.
[0018] Optionally, step S13 is specifically as follows:
[0019] Step S131: extracting device identity features and device connection frequency features based on the network communication connection data to obtain network device identity data and network device connection frequency data;
[0020] Step S132: performing communication network node identification on the network device identity data to obtain communication network node data;
[0021] Step S133: dividing the communication network node data into communication network node data according to the network device connection frequency data to obtain network connection source node data and network connection target node data;
[0022] Step S134: performing node link relationship identification on the network connection source node data and the network connection target node data to obtain network node link relationship data;
[0023] Step S135: Perform network node topology analysis based on the network node link relationship data and the communication network node data to obtain an airport network topology diagram.
[0024] By extracting device identity features and device connection frequency features from network communication connection data, the present invention can identify the unique identities of different devices and the connection frequencies between them. This provides foundational data for further identifying the roles and behavior patterns of individual devices in the network. Device identity data helps confirm the legitimacy and trust level of a device, while device connection frequency data reveals the activity intensity and frequent connection patterns of devices in the network, providing an important basis for assessing network load and monitoring abnormal behavior. By performing communication network node identification on device identity data, each device in the network can be mapped to a specific network node, helping to build a clear network node map. Node identification further refines the device roles in the network and facilitates accurate analysis of the network structure. Using network device connection frequency data to perform node partitioning effectively distinguishes source and destination nodes in the network, helping to clarify the direction of data flow and the traffic distribution of the network topology. This partitioning provides useful information for subsequent network path optimization, data traffic forecasting, and other tasks. By identifying the link relationships between network connection source and destination nodes, the communication paths and relationships between different nodes can be accurately captured, further optimizing network management and improving data transmission efficiency. Finally, by analyzing the network node topology structure based on the node-link relationship and network node data, a complete topology map of the airport network can be drawn, thereby better understanding the overall architecture of the network, identifying potential bottleneck nodes and vulnerabilities, providing a basis for network optimization and security protection, and improving network reliability and efficiency.
[0025] Optionally, step S2 is specifically:
[0026] Step S21: extracting network communication security logs and network traffic monitoring data from the airport network communication data to obtain network communication security logs and network traffic monitoring data, and performing frequency domain conversion on the network traffic monitoring data to obtain a network traffic monitoring spectrum;
[0027] Step S22: dividing the airport network communication topology model by intrusion node frequency according to the network communication security log to obtain intrusion frequency node division data;
[0028] Step S23: performing traffic load pattern recognition based on the network traffic monitoring spectrum to obtain network traffic aperiodic load pattern data and network traffic periodic load pattern data; performing high-frequency load pattern node division based on the network traffic aperiodic load pattern data and the network traffic periodic load pattern data to obtain high-frequency load pattern node division data;
[0029] Step S24: performing a transmission node security assessment based on the intrusion frequency node division data and the high-frequency load mode node division data to obtain transmission node security data;
[0030] Step S25: dynamically assigning a transmission path encryption protocol to the transmission path data to be assigned based on the transmission node security data to obtain an encrypted path mapping table.
[0031] By extracting network communication security logs and network traffic monitoring data from airport network communication data, the present invention can comprehensively understand the network's security status and traffic characteristics, providing foundational data for subsequent analysis. Extracting this data not only facilitates real-time monitoring of network security but also reveals potential attacks and abnormal traffic. Frequency-domain conversion of network traffic monitoring data converts complex time-domain signals into frequency-domain signals, revealing the periodic and aperiodic characteristics of traffic flow and further facilitating the identification of potential abnormal patterns in traffic. By frequency-segmenting the airport network communication topology model based on network communication security logs, nodes that frequently pose security threats can be identified, providing valuable input for network security early warning systems. Traffic load pattern identification helps distinguish periodic from aperiodic traffic characteristics and, by analyzing nodes with high-frequency traffic load patterns, identifies potentially high-risk nodes, enabling proactive protective responses when network traffic loads are high. Combining data from intrusion frequency nodes with data from high-frequency load pattern node segmentation to assess transmission node security comprehensively considers node security risks and load pressure, quantitatively assessing the security of transmission paths, identifying potential weak or high-risk nodes, and providing a basis for path optimization and encryption measures. Based on this transmission node security data, the transmission path encryption protocol is dynamically allocated to the allocated transmission path data, which can ensure the security of the data transmission process and optimize the encryption path mapping table, thereby improving data transmission efficiency while ensuring security.
[0032] Optionally, step S24 is specifically as follows:
[0033] Perform node classification on the intrusion frequency node division data to obtain high-frequency communication intrusion node data and low-frequency communication intrusion node data;
[0034] Performing node classification on the high-frequency load mode node division data to obtain high-frequency periodic load mode node data and high-frequency non-periodic load mode node data;
[0035] Perform node intersection calculation based on high-frequency communication intrusion node data and high-frequency non-periodic load mode node data to obtain low-security transmission node data;
[0036] Perform node intersection calculation based on low-frequency communication intrusion node data and low-frequency non-periodic load mode node data to obtain high-security transmission node data;
[0037] The low-security transmission node data and the high-security transmission node data are combined to obtain transmission node security data.
[0038] The present invention classifies nodes by dividing the intrusion frequency node data into high-frequency communication intrusion nodes and low-frequency communication intrusion nodes according to the communication frequency, thereby more accurately identifying nodes that are frequently attacked and relatively safe nodes in the network. This classification helps to assess and prioritize network security risks, allowing network security managers to take appropriate measures to strengthen protection for high-frequency communication intrusion nodes. At the same time, by classifying the high-frequency load pattern node data, high-frequency load nodes can be divided into periodic load pattern and non-periodic load pattern nodes, and the traffic characteristics of these nodes can be further analyzed to find potential load problems. By performing node intersection operations on the data of high-frequency communication intrusion nodes and high-frequency non-periodic load pattern nodes, nodes that are both facing high-frequency intrusion attacks and bearing non-periodic high loads can be identified. These nodes have lower security and may be weak links in the network, requiring priority protection. By performing intersection operations on the data of low-frequency communication intrusion nodes and low-frequency non-periodic load pattern nodes, nodes that are less attacked and have stable load patterns can be determined. These nodes are considered to have higher security and can be used as preferred nodes for secure transmission paths. Finally, by merging the low-security transmission node data and the high-security transmission node data, a comprehensive transmission node security data can be obtained, which provides decision support for subsequent data transmission path selection and encryption protocol allocation, ensuring the security and stability of the data transmission process.
[0039] Optionally, step S3 specifically includes:
[0040] Step S31: Obtain node verification data through the network security management platform, and perform data preprocessing on the node verification data to obtain the node verification data to be analyzed;
[0041] Step S32: extracting node verification features from the node verification data to be analyzed, and obtaining node verification device location data and node verification device frequency data;
[0042] Step S33: Perform verification device spatial distribution statistics based on the node verification device location data to obtain device verification location frequency data; perform verification device verification frequency statistics on the node verification device frequency data to obtain device short-term verification frequency data;
[0043] Step S34: performing device verification abnormal behavior detection based on the device verification location frequency data and the device short-time verification frequency data to obtain node verification behavior detection data;
[0044] Step S35: Perform transmission node credibility assessment on the airport network communication topology model based on the node verification behavior detection data to obtain a node behavior analysis report.
[0045] The present invention obtains and pre-processes node verification data through a network security management platform, which helps to effectively remove noise data and redundant information, thereby providing accurate input data for subsequent analysis and ensuring the reliability and validity of the node verification data. Feature extraction of the node verification data to be analyzed, especially extracting the location and frequency data of the node verification device, can provide a deeper understanding of the behavior patterns of devices in the network and help identify possible abnormal behaviors or risks. Spatial distribution statistics based on the node verification device location data can help discover the distribution patterns of devices in the network and then identify potential security weaknesses; verification frequency statistics of the node verification device frequency data can reveal the activity level of the device in a short period of time, identify frequently verified devices, and indicate the existence of security risks or faults. At the same time, by combining the device verification location frequency data and the device short-time verification frequency data to perform device verification abnormal behavior detection, devices that violate conventional verification behavior can be discovered in the first time, improving the detection efficiency of abnormal events and reducing the occurrence of potential security threats. Finally, the transmission node credibility assessment of the airport network communication topology model is performed based on the node verification behavior detection data. The generated node behavior analysis report can provide airport network managers with detailed and clear security status feedback, help optimize the network architecture, enhance network defense, and ensure the security and reliability of data transmission.
[0046] Optionally, step S35 is specifically as follows:
[0047] Step S351: extract abnormal verification behavior nodes from the node verification behavior detection data to obtain abnormal verification behavior node data;
[0048] Step S352: performing abnormal verification behavior frequency statistics and abnormal verification behavior time period statistics based on abnormal verification behavior node data to obtain node abnormal verification behavior frequency data and node abnormal verification behavior time period distribution data;
[0049] Step S353: Calculating the severity score of abnormal behavior based on the node abnormal verification behavior frequency data to obtain node abnormal behavior severity score data;
[0050] Step S354: Calculate the node abnormal verification behavior period ratio based on the node abnormal verification behavior period distribution data to obtain the node abnormal verification behavior period ratio data;
[0051] Step S355: weighting the node abnormal behavior severity score data and the node abnormal verification behavior period ratio data by the node behavior security score to obtain the node behavior security score data;
[0052] Step S356: Perform node score space visualization on the airport network communication topology model based on the node behavior security score data to obtain a node behavior analysis report.
[0053] By extracting abnormal verification behavior nodes from node verification behavior detection data, the present invention effectively identifies potentially abnormal nodes within the network. This process helps quickly identify potential security threat sources. Further frequency and time period statistics for abnormal verification behavior nodes provide a deeper understanding of the frequency and temporal distribution of these abnormal behaviors, helping to analyze the regularity and frequency of abnormal behaviors, thereby identifying high-risk time periods and nodes that may impact system security. Based on this, an abnormal behavior severity score is calculated, which facilitates hierarchical management of abnormal nodes and prioritizes high-risk nodes, thereby improving system security. By calculating the proportion of abnormal verification behavior time periods, the distribution of abnormal behaviors within different time periods can be assessed, providing a reference for security reinforcement during critical periods. Weighted node behavior security scores are then applied to derive a comprehensive security score for each node. This score provides a scientific basis for subsequent security policy formulation, guiding network administrators in implementing different security protection measures for nodes at different security levels. Finally, spatial visualization of node behavior security score data helps network administrators more intuitively understand the security status of each node in the network, effectively identifying security vulnerabilities and providing data support for network optimization and enhanced protection.
[0054] Optionally, step S4 is specifically:
[0055] Step S41: selecting a data transmission security node based on the node behavior analysis report to obtain security node data to be distributed;
[0056] Step S42: selecting a path with a high security node ratio from the encryption path mapping table according to the security node data to be distributed, to obtain the encryption path data to be distributed;
[0057] Step S43: performing encryption key negotiation on the encrypted path data to be distributed, obtaining an encryption key pair, and uploading it to the airport network security management platform to execute the encryption key distribution task;
[0058] Step S44: Acquire the data to be transmitted for the airport and perform data preprocessing on the data to be transmitted for the airport to obtain the data to be transmitted for the airport to be analyzed;
[0059] Step S45: segmenting the data to be transmitted from the airport to be analyzed into data packets to obtain a set of segmented data packets to be transmitted;
[0060] Step S46: Encrypt the virtual tunnel data of the segmented data packet set to be transmitted according to the encryption key to obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to execute the data transmission task.
[0061] The present invention selects secure nodes for data transmission based on node behavior analysis reports, effectively ensuring that data transmission only passes through nodes with high security ratings, avoiding potential security threat nodes and thus enhancing the overall protection capabilities of the system. Path selection based on the encrypted path mapping table for high-security node proportions, based on the security node data to be distributed, helps select the most appropriate secure path for data transmission, preventing data from traversing less secure paths and reducing the risk of data leakage or tampering. The negotiation and distribution of encryption keys ensures high-strength encryption protection during data transmission, ensuring the confidentiality and integrity of information throughout the transmission process and effectively preventing data theft or tampering. Effective cleaning and organization of data to be transmitted during data preprocessing helps improve data transmission efficiency and accuracy. By segmenting large data blocks into multiple small data packets for transmission, delays that may occur in large data transmission are effectively avoided, while optimizing network bandwidth utilization and improving data transmission stability. Finally, data packet encryption through virtual tunnels ensures that data remains confidential and secure even in complex network environments, significantly improving the system's anti-attack and data protection capabilities and ensuring the secure and efficient transmission of airport information.
[0062] Optionally, step S5 is specifically:
[0063] Step S51: Acquire the real-time communication data of the airport and perform data preprocessing on the real-time communication data of the airport to obtain the real-time communication data of the airport network to be analyzed;
[0064] Step S52: performing node link outlier detection on the real-time communication data of the aviation airport network to be analyzed using the airport network communication topology model to obtain a real-time anomaly detection log;
[0065] Step S53: performing data packet delay calculation based on the real-time anomaly detection log to obtain data packet delay data, and classifying and calculating the data packet delay data based on a preset lost data packet delay threshold to obtain lost data packets;
[0066] Step S54: decrypting the lost data packet according to the encryption key to obtain a decrypted lost data packet;
[0067] Step S55: reconstructing the decrypted lost data packets based on the segmented data packet set to be transmitted to obtain a restored data packet;
[0068] Step S56: selecting a low-latency transmission path for the restored data packet according to the encrypted path data to be distributed, to obtain restored transmission path data;
[0069] Step S57: Based on the encryption key pair, the virtual tunnel data of the restored transmission path data and the restored data packet is encrypted to obtain the restored encrypted data packet, and uploaded to the airport network security management platform to execute the data transmission task.
[0070] By acquiring real-time communication data of airports and preprocessing it, the present invention can effectively filter and organize the real-time data flowing in the network, ensuring the efficiency and accuracy of data analysis. The use of the airport network communication topology model to detect node link outliers on the data to be analyzed helps to timely discover and identify potential abnormal behaviors or attack behaviors, thereby enhancing the real-time monitoring and response capabilities of the system. Through data packet delay calculation, the delay in communication can be quantified, and classified by the preset lost data packet delay threshold, which helps to locate and filter out lost data packets caused by network problems or attacks, thereby ensuring the integrity and timeliness of transmission. Encrypting and decrypting lost data packets can not only restore lost data packets, but also ensure data security during the decryption process, avoiding data leakage or tampering. The reconstruction of lost data packets effectively solves the problem of data loss caused by network problems, ensures the complete transmission of data, and improves the robustness and recovery capability of the system. Selecting a low-latency transmission path to restore the transmission of data packets helps to reduce delays in data transmission and improve the real-time performance of data transmission, which is particularly important in emergency situations or high-priority data transmission. Finally, by encrypting the transmission path through a virtual tunnel and re-encrypting the data packets, the confidentiality and integrity of the restored data packets during transmission can be further ensured, avoiding any potential security threats, thereby effectively improving the security and communication efficiency of the aviation airport network, ensuring aviation safety while ensuring the efficiency and accuracy of information transmission.
[0071] Optionally, this specification also provides a system for securely transmitting information data, for executing the above-mentioned method for securely transmitting information data. The system for securely transmitting information data includes:
[0072] The communication network topology analysis module is used to obtain aviation and airport network communication data, and perform communication network topology analysis on the aviation and airport network communication data to obtain an airport network communication topology model; select a data transmission path based on the airport network communication topology model to obtain data on the transmission path to be allocated;
[0073] A node security assessment module is used to perform a security assessment of the intersection of transmission node load patterns on the airport network communication topology model based on the aviation airport network communication data to obtain transmission node security data; based on the transmission node security data, a transmission path encryption protocol is dynamically allocated to the transmission path data to be allocated to obtain an encrypted path mapping table;
[0074] The node behavior analysis module is used to obtain node verification data and perform a weighted credibility assessment of the node verification data based on the transmission node verification space frequency to obtain a node behavior analysis report;
[0075] The data packet encryption module is used to perform data packet virtual tunnel encryption based on the node behavior analysis report and the encryption path mapping table, obtain the encrypted data packet to be transmitted to the airport, and upload it to the airport network security management platform to execute the data transmission task;
[0076] The real-time communication feedback recovery module is used to obtain the real-time communication data of the aviation airport network, and recover the abnormal data of the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
[0077] The information data security transmission system of the present invention can implement any information data security transmission method of the present invention, and is used to combine the operation and signal transmission medium between various modules to complete the information data security transmission method. The internal modules of the system cooperate with each other, thereby improving the security and stability of the data transmission process. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] Other features, objects and advantages of the present invention will become more apparent upon reading the detailed description of non-limiting embodiments thereof made with reference to the following drawings:
[0079] Figure 1 This is a schematic flow chart of the steps of the method for securely transmitting information data of the present invention;
[0080] Figure 2Detailed step flow diagram of step S1 in the present invention;
[0081] Figure 3 Detailed step flow diagram of step S2 in the present invention;
[0082] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0083] The following is a clear and complete description of the technical method of the present invention in conjunction with the accompanying drawings. It is obvious that the embodiments described are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts are within the scope of protection of the present invention.
[0084] In addition, the accompanying drawings are merely schematic illustrations of the present invention and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor and / or microcontroller approaches.
[0085] It should be understood that although the terms "first," "second," and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used solely to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the listed associated items.
[0086] To achieve this, please refer to Figures 1 to 3 The present invention provides a method for securely transmitting information data, the method comprising the following steps:
[0087] Step S1: Acquire aviation airport network communication data, and perform communication network topology analysis on the aviation airport network communication data to obtain an airport network communication topology model; select a data transmission path based on the airport network communication topology model to obtain transmission path data to be allocated;
[0088] In this embodiment, traffic monitoring equipment (such as an SNMP-based network monitoring system, traffic analyzer, or bandwidth acquisition device) deployed in the airport network collects communication data from each node in real time, including bandwidth, latency, packet loss rate, traffic type (TCP / UDP), and device connectivity. The collected network communication data may include each node's transmission rate (in Mbps), transmission latency (in milliseconds), packet loss rate (in percent), and the communication volume between nodes (in GB). This data is obtained through a network management platform and preprocessed (for example, using data cleaning techniques to remove outliers or fill in missing values). Next, a graph-theory-based shortest path algorithm (such as Dijkstra or A* algorithm) is used to perform topological analysis on this data. By calibrating the attributes of each network node (such as node bandwidth, transmission latency, etc.), a topological model of the airport network is constructed. The node's transmission capability and bandwidth capacity are used as parameters in the path selection algorithm. When selecting a data transmission path, the shortest path algorithm ensures that the selected path has the lowest packet loss rate (e.g., 0.01%) under bandwidth capacity (e.g., 10Gbps) and maximum latency (e.g., within 100ms). Through this topology, the optimal data transmission path is selected, and paths are dynamically selected based on traffic load, ultimately obtaining the data to be allocated along the transmission path.
[0089] Step S2: performing a security assessment of the intersection of transmission node load patterns on the airport network communication topology model based on the aviation airport network communication data to obtain transmission node security data; dynamically assigning a transmission path encryption protocol to the transmission path data to be assigned based on the transmission node security data to obtain an encrypted path mapping table;
[0090] In this embodiment, the node security feature data obtained through the network security management platform includes the physical security of the node (for example, the device firewall level, the device vulnerability level), the authentication level (for example, whether it passes multi-factor authentication), the communication frequency of the node (unit: times / hour) and the access rights of the device (such as IP whitelist). These data will be used as input to calculate the security score of each node (for example, a scoring system of 0-100). For each transmission node, the encryption protocol will be dynamically selected according to its security score (for example, nodes below 70 are considered less secure). For example, low-security nodes will use stronger encryption protocols (such as AES-256), while high-security nodes can use lighter encryption protocols (such as AES-128 or TLS1.2). Through the dynamic allocation of encryption protocols, an encryption path mapping table is generated, which will bind each transmission path to a specific encryption protocol to ensure that the data protection strength during the transmission process matches the network security environment.
[0091] Step S3: Obtain node verification data, and perform a weighted credibility assessment of the node verification data using the transmission node verification space frequency to obtain a node behavior analysis report;
[0092] In this embodiment, verification data for each node is obtained through the airport network security management platform. Data sources include device authentication information (such as the node's identity ID and certificate chain), authentication credentials (such as JWT tokens), device registration information, access logs, and behavior logs (such as login time and access frequency). Next, abnormal behavior detection is performed by setting reasonable verification frequency thresholds (such as 5 authentication requests per hour) and behavioral patterns (such as abnormally high traffic volume within 10 minutes). For each node, if its behavior exceeds preset security standards (such as the number of failed logins exceeding a certain period of time or abnormal access frequency), it will be marked as abnormal. Machine learning algorithms (such as K-means cluster analysis and decision tree models) are used to determine abnormal behavior of each node and generate node verification behavior detection data. Based on this data, the node's trustworthiness is evaluated. Combined with the node's historical behavior data, verification frequency (such as the number of authentication requests per hour), and the frequency of abnormal events, a trustworthiness score is determined for each node (for example, a trustworthiness score of 80% indicates that the node poses a certain risk). This data is used to generate a node behavior analysis report, which provides a basis for subsequent encryption key distribution and security decision-making.
[0093] Step S4: Based on the node behavior analysis report and the encryption path mapping table, the data packet is encrypted in a virtual tunnel to obtain the airport encrypted data packet to be transmitted, and uploaded to the airport network security management platform to execute the data transmission task;
[0094] In this embodiment, based on the node behavior analysis report and the encryption path mapping table, a key negotiation protocol (such as the Diffie-Hellman key exchange protocol) is used to generate an encryption key pair. During the key pair generation process, multiple parameter verifications are performed, such as confirming that the node's credibility score is greater than a set threshold (for example, 70%), to ensure that the key exchange process is safe and reliable. The generated encryption key pair will be distributed to each network node through a secure channel. After the key distribution is completed, a virtual tunnel technology (such as IPsec or SSL / TLS) will be used to encrypt the data to be transmitted. This encryption process uses a strong encryption algorithm (such as AES-256), and the encrypted data packet includes information such as timestamp, data packet ID, encryption key identifier, etc. The encrypted data packet will be uploaded to the airport network security management platform, and the data transmission task will be executed according to the scheduling policy within the system. The uploaded data packet will be encrypted and transmitted along the predetermined path to ensure the security and privacy of the data.
[0095] Step S5: Acquire the real-time communication data of the aviation airport network, perform abnormal data recovery on the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
[0096] In this embodiment, a real-time monitoring system deployed within the airport network security management platform captures real-time network communication data, including transmission delay (e.g., less than 100ms is considered normal), packet loss rate (e.g., less than 0.01%), and network bandwidth utilization (e.g., over 80% indicates high load). By setting reasonable thresholds (e.g., delay fluctuation exceeding 3%, packet loss rate exceeding 5%), real-time anomaly detection algorithms (e.g., time series-based anomaly detection, weighted average methods, etc.) are triggered. When an anomaly is detected, a real-time anomaly detection log is generated, recording data such as the anomaly time, location, and type. Based on these detection logs, packet retransmission techniques (e.g., TCP-based automatic retransmission mechanisms) or packet recovery algorithms (e.g., using forward error correction (FEC)) are used to recover the anomaly data. The recovered data packets are re-encrypted using the encryption key, re-encapsulated, and encrypted for transmission via a pre-defined path. The recovered encrypted data packets are uploaded to the network security management platform, ensuring that the data is securely and accurately transmitted to its destination as planned.
[0097] Optionally, step S1 specifically includes:
[0098] Step S11: obtaining the aviation airport network communication data through the airport network security management platform, and performing data preprocessing on the aviation airport network communication data to obtain the aviation airport network communication data to be analyzed;
[0099] In this embodiment, traffic monitoring equipment (such as SNMP-based network monitoring systems, traffic analyzers or bandwidth acquisition equipment) is deployed in the airport network to collect communication data from each node in real time (including bandwidth, delay, packet loss rate, traffic type (TCP / UDP), and device connection status, etc.), and upload these communication data to the airport network security management platform.
[0100] Step S12: extracting airport network communication features from the aviation airport network communication data to be analyzed, and obtaining network communication connection data and network dynamic resource allocation data;
[0101] In this example, based on pre-processed airport network communication data, feature extraction algorithms (such as PCA and LDA) are used to reduce the data's dimensionality and extract key features. This results in network communication connection data (such as connected nodes, communication latency, bandwidth, etc.) and network dynamic resource allocation data (such as traffic load and routing allocation). For example, from the communication data of 500 nodes, bandwidth usage, latency fluctuations, and traffic patterns for each node are extracted to obtain complete network communication connection and resource allocation feature data.
[0102] Step S13: Analyzing the airport network topology structure based on the network communication connection data to obtain an airport network topology map;
[0103] In this embodiment, based on the extracted network communication connection data, graph algorithms (such as Dijkstra and Kruskal algorithms) are used to analyze the relationships between communication nodes and construct a network topology. In specific implementations, nodes represent routers or switches in the airport network, and edges represent communication links or data flows. Using latency and bandwidth data between nodes, the shortest paths between nodes are determined, thus forming a network topology for the airport. For example, for an airport's main switch, by analyzing its connected subnetwork nodes, a topology map containing 100 nodes and 150 connecting links is constructed.
[0104] Step S14: performing dynamic topology data modeling on the airport network topology map based on the network dynamic resource allocation data to obtain an airport network communication topology structure model;
[0105] In this embodiment, dynamic network modeling techniques (such as Markov chain modeling and time series analysis) are applied to extract dynamic network resource allocation data (such as bandwidth utilization and load balancing information) to create a dynamic topology model on the airport network topology map. This model can reflect changes in network resources (such as bandwidth and node load) in real time, thereby generating a dynamic airport network communication topology model. For example, using periodic network data, a dynamic topology model is established that can adjust to real-time bandwidth and load, and is updated every 30 seconds to reflect changes in airport network traffic.
[0106] Step S15: Select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated.
[0107] In this embodiment, based on the obtained airport network communication topology model, a shortest path algorithm (such as Bellman-Ford) or an optimal path selection algorithm is used to select the optimal data transmission path based on real-time network status (such as bandwidth, latency, and node security). Transmission path selection considers multiple factors, including available node bandwidth, latency, and network traffic load. For example, if a path has insufficient bandwidth or excessive latency during data transmission, the system automatically switches to another path to ensure smooth and efficient data transmission, ultimately obtaining a transmission path dataset to be allocated.
[0108] Optionally, step S13 is specifically as follows:
[0109] Step S131: extracting device identity features and device connection frequency features based on the network communication connection data to obtain network device identity data and network device connection frequency data;
[0110] In this embodiment, based on network communication connection data, a device identity extraction algorithm (e.g., based on MAC address, IP address, device model, etc.) is first used to extract the identity characteristics of each device. Subsequently, device connection frequency characteristics are extracted through device connection frequency analysis (e.g., based on hourly or daily connection counts). For example, for an airport network system, the system would extract the device identity data of each router and switch over the past week based on historical data records, as well as their connection frequencies in different time periods. For example, if one switch averages 30 connections per hour, while another switch only has 10 connections per hour, the system would then obtain both device identity data and connection frequency data.
[0111] Step S132: performing communication network node identification on the network device identity data to obtain communication network node data;
[0112] In this embodiment, device identity data is used to identify communication network nodes. A graph-based node identification method (such as connectivity graph analysis or the BFS algorithm) is used to classify device identities, identify devices belonging to the same network segment, and label them as the same communication network node. Specifically, by associating the identified devices with switches, routers, and other devices, each key device in the airport network is labeled as a communication network node. For example, the airport network includes multiple layers of switches, routers, and wireless access points. By analyzing device information such as MAC addresses and IP addresses, the system identifies nodes such as the main switch and terminal device access points, forming a network node dataset.
[0113] Step S133: dividing the communication network node data into communication network node data according to the network device connection frequency data to obtain network connection source node data and network connection target node data;
[0114] In this embodiment, a clustering algorithm (such as K-means clustering) is used to divide communication network nodes into network connection source nodes and target nodes based on device connection frequency data. The division is based on the source and target of the device connection. For example, a switch or router is the starting point of the connection traffic (source node), and another device is the target node. For example, if a router establishes connections with multiple terminal devices every hour and the connection frequency is high, the router is classified as a source node; and the terminal devices connected to this router are classified as target nodes.
[0115] Step S134: performing node link relationship identification on the network connection source node data and the network connection target node data to obtain network node link relationship data;
[0116] In this embodiment, the link relationship between the source node data and the target node data of the network connection is identified, and a network traffic analysis algorithm (such as a link prediction or maximum flow algorithm) is applied to identify the communication link between the source node and the target node. Specifically, the data packet flow path in the network protocol (such as the TCP / IP protocol) is used to detect the data transmission between the nodes in the network. For example, when a node A frequently communicates with multiple nodes B, C, etc., the link relationship between these nodes will be analyzed, the communication link data between them will be identified, and finally the link relationship between the source node and the target node will be obtained.
[0117] Step S135: Perform network node topology analysis based on the network node link relationship data and the communication network node data to obtain an airport network topology diagram.
[0118] In this embodiment, a graph algorithm is used to analyze the network node topology based on network node link relationship data and communication network node data, ultimately generating a complete topology map of the airport network. Specifically, each device in the airport network (such as switches, routers, and terminal devices) is represented as a node in the graph, and the communication links between devices are represented as edges in the graph. Graph algorithms (such as the Dijkstra shortest path algorithm, the Kruskal minimum spanning tree algorithm, or the Bellman-Ford algorithm) are used to analyze the connection relationships and transmission paths between devices, thereby identifying the shortest paths and transmission routes between each node in the network. For example, in a practical application, if a main switch at an airport has complex link relationships with multiple sub-switches and wireless access points, the system will use a graph algorithm to calculate the shortest connection path between each device, while also comprehensively considering network node properties such as bandwidth, latency, and load, to generate an effective topology model. This topology map not only shows the direct connection relationships between device nodes but also provides a basis for subsequent optimization of data transmission paths, ensuring communication efficiency and stability.
[0119] Optionally, step S2 is specifically:
[0120] Step S21: extracting network communication security logs and network traffic monitoring data from the airport network communication data to obtain network communication security logs and network traffic monitoring data, and performing frequency domain conversion on the network traffic monitoring data to obtain a network traffic monitoring spectrum;
[0121] In this embodiment, network communication security logs and network traffic monitoring data are extracted from the network communication data of the aviation airport to obtain network communication security logs and network traffic monitoring data. The real-time communication data of each node and link is extracted from the network monitoring equipment through the airport network security management platform, including information such as transmitted data packets, transmission protocols, transmission delays and communication errors. Then, the network traffic monitoring data is converted into the frequency domain, and the time domain signal is converted into a frequency domain signal using the fast Fourier transform (FFT) to obtain a spectrum diagram. At this time, high-frequency interference signals, potential communication attacks and irregular traffic patterns in the traffic can be identified through frequency domain analysis. For example, if there is an excessively high frequency of data packet transmission or abnormal communication fluctuations in the monitoring data, the data will be extracted and used as basic data for further analysis. The spectrum diagram of the network traffic is obtained to provide information support for subsequent security analysis and evaluation.
[0122] Step S22: dividing the airport network communication topology model by intrusion node frequency according to the network communication security log to obtain intrusion frequency node division data;
[0123] In this embodiment, the communication security log of each node is analyzed, and the frequency of intrusion nodes is divided by identifying abnormal behaviors that frequently appear in the log (such as frequent retransmissions, connection rejections, abnormal login attempts, etc.). The intrusion behaviors of these nodes are divided into different frequency levels (for example: low frequency, medium frequency and high frequency), so as to evaluate the potential threat level of each node within a certain time range. By dividing these intrusion nodes, it is possible to identify which nodes have frequent security incidents in a short period of time, thereby providing a basis for network security assessment and subsequent protection strategies. For example, if the intrusion frequency of a node reaches the high frequency range, it means that the node is experiencing a network attack or malicious traffic.
[0124] Step S23: performing traffic load pattern recognition based on the network traffic monitoring spectrum to obtain network traffic aperiodic load pattern data and network traffic periodic load pattern data; performing high-frequency load pattern node division based on the network traffic aperiodic load pattern data and the network traffic periodic load pattern data to obtain high-frequency load pattern node division data;
[0125] In this embodiment, the signal distribution of different frequencies in the spectrum diagram is analyzed to identify periodic and non-periodic changes in network traffic. For example, after fast Fourier transform (FFT), network traffic can be divided into two modes: periodic fluctuations and irregular fluctuations. Periodic load patterns usually indicate normal network usage patterns, while non-periodic load patterns are traffic fluctuations caused by malicious attacks or network anomalies. After identification, high-frequency load pattern nodes are further divided according to the characteristics of the traffic, and high-frequency load pattern nodes are classified from low-frequency load pattern nodes. Based on the traffic frequency, each node will be automatically labeled and identified as a high-frequency load pattern node or a low-frequency load pattern node, thereby helping to discover potential high-load or high-risk nodes.
[0126] Step S24: performing a transmission node security assessment based on the intrusion frequency node division data and the high-frequency load mode node division data to obtain transmission node security data;
[0127] This embodiment combines data from nodes with high intrusion frequency and high-frequency load patterns to conduct a multi-dimensional security assessment. Specifically, the system analyzes nodes that are frequently attacked or have abnormal load patterns to assess their security and reliability. For example, the intersection of nodes with a high intrusion frequency and nodes with a high load aperiodic pattern is labeled as "high-risk," while nodes with low intrusion frequency and high load periodicity are labeled as "low-risk." This process relies on a deep learning model and a rules engine to automatically assess the risk level of each node and output security data for the transmission node.
[0128] Step S25: dynamically assigning a transmission path encryption protocol to the transmission path data to be assigned based on the transmission node security data to obtain an encrypted path mapping table.
[0129] In this embodiment, the transmission paths to be allocated are analyzed and encryption protocols are dynamically assigned based on the security data of the nodes. First, different levels of encryption protocols are assigned to each node based on the security data of the node (such as intrusion frequency, load pattern, etc.). For low-security nodes, a strong encryption algorithm, such as AES-256-bit encryption, is automatically selected to ensure the confidentiality of the transmitted data; while for high-security nodes, a lower-strength encryption algorithm (such as AES-128-bit encryption) is selected. Next, an encryption path mapping table is generated based on the network topology and path allocation requirements, which includes the encryption protocol and corresponding encryption level of each path. In this way, it is ensured that each path uses an encryption protocol that matches its security. Finally, the encryption path mapping table is uploaded to the airport network security management platform to provide encryption path guidance for subsequent data transmission.
[0130] Optionally, step S24 is specifically as follows:
[0131] Perform node classification on the intrusion frequency node division data to obtain high-frequency communication intrusion node data and low-frequency communication intrusion node data;
[0132] In this embodiment, network traffic is monitored and node intrusion frequency data is extracted. Intrusion frequency data is quantified based on the number of intrusion events a node experiences over a period of time, and analysis is performed within a selected time window (e.g., 30 minutes). When the number of intrusion events exceeds a preset threshold (e.g., more than 5 intrusion events per hour), the node is classified as a high-frequency communication intrusion node; otherwise, it is classified as a low-frequency communication intrusion node. This classification allows nodes with high-frequency attack behaviors to be identified for subsequent security assessments.
[0133] Performing node classification on the high-frequency load mode node division data to obtain high-frequency periodic load mode node data and high-frequency non-periodic load mode node data;
[0134] This embodiment identifies the node's load pattern based on long-term analysis of traffic load data. A high-frequency load pattern node typically refers to one that maintains high load or high traffic transmission during frequent time periods. When the node's load fluctuates periodically, and the fluctuation amplitude exceeds a certain threshold, it is classified as a high-frequency periodic load pattern node. When the load changes without obvious patterns and exhibits no periodic changes, the node is classified as a high-frequency non-periodic load pattern node. This classification helps identify nodes with different load behaviors and further determines the security of transmission.
[0135] Perform node intersection calculation based on high-frequency communication intrusion node data and high-frequency non-periodic load mode node data to obtain low-security transmission node data;
[0136] In this embodiment, an intersection operation is performed on the classified high-frequency communication intrusion nodes and the classified high-frequency aperiodic load pattern nodes to identify node data that meets both criteria. For example, if a node is both a high-frequency intrusion node and an aperiodic node with irregular load fluctuations, it is automatically marked as a low-security node. The intersection operation can be implemented using SQL queries or set operations, ultimately identifying node data with low security risks.
[0137] Perform node intersection calculation based on low-frequency communication intrusion node data and low-frequency non-periodic load mode node data to obtain high-security transmission node data;
[0138] In this embodiment, an intersection operation is performed on the classified low-frequency communication intrusion node data and the low-frequency aperiodic load pattern node data to identify nodes that fall under both categories. These nodes exhibit low-frequency intrusion behavior and infrequent load fluctuations, indicating high security and suitable for data transmission as high-security nodes. This intersection operation ensures that only nodes that meet these two criteria are classified as high-security nodes, preventing nodes with high-frequency attacks or fluctuating loads from participating in important data transmission.
[0139] The low-security transmission node data and the high-security transmission node data are combined to obtain transmission node security data.
[0140] In this embodiment, the obtained low-security transmission node data and the obtained high-security transmission node data are merged. The merging process includes integrating the two sets of data into a comprehensive data set. Through the data merging operation, the two sets of node data are integrated into a complete transmission node security data set. During the merging process, the low-security node data and the high-security node data are directly spliced according to the original format to ensure that the data of each node remains in its original state. For example, if the low-security node data includes information such as node ID, intrusion frequency, and load pattern, and the high-security node data includes information such as node ID, load pattern, and historical security records, all relevant feature data of each node will be retained during the merging. Ultimately, the merged data set will include the security information of all transmission nodes, which will provide the basis for the subsequent transmission path encryption protocol allocation.
[0141] Optionally, step S3 specifically includes:
[0142] Step S31: Obtain node verification data through the network security management platform, and perform data preprocessing on the node verification data to obtain the node verification data to be analyzed;
[0143] In this embodiment, the network security management platform obtains node verification data once an hour. The data includes the device's identity authentication information, verification timestamp, verification request frequency, and geographic location, etc. After the data is acquired, preprocessing operations are performed, including removing invalid data and format conversion. In this process, the Z-score method is used to detect outliers in the verification frequency, and abnormal data exceeding 3 standard deviations is removed. After data cleaning, a data set in a unified format is generated to ensure that the verification request data of each device has a standard timestamp (accurate to seconds), location data (accurate to 4 decimal places) and verification frequency data (time window is 30 minutes). The cleaned data is stored in the database and is ready for subsequent analysis.
[0144] Step S32: extracting node verification features from the node verification data to be analyzed, and obtaining node verification device location data and node verification device frequency data;
[0145] In this example, the Pandas library in Python is used to extract device location and frequency data based on the cleaned data. Device location data is extracted based on latitude and longitude with an accuracy of 5 meters. The geographic location of each device is obtained by calculating the average location coordinates of the device. Device frequency data is obtained by counting the number of verification requests for each node within 30 minutes, using a time window of 10 minutes to calculate the verification frequency and change trend of each node. The device verification frequency data is calculated using a sliding window method, and the verification frequency data of each device is smoothed using the standard deviation to ensure data stability and accuracy.
[0146] Step S33: Perform verification device spatial distribution statistics based on the node verification device location data to obtain device verification location frequency data; perform verification device verification frequency statistics on the node verification device frequency data to obtain device short-term verification frequency data;
[0147] In this embodiment, the device location data is spatially distributed using the K-means clustering algorithm, and the airport area is divided into 50 grids, each with a side length of 100 meters. The number and distribution of verification devices in each grid are counted. The verification frequency data is obtained by counting the number of verifications of the device on an hourly basis, calculating the short-term verification frequency of the device (unit: times / minute) based on a time window length of 60 minutes, and generating a verification frequency heat map through visualization. The data parameters used in this process include: the number of clusters in the K-means clustering is set to 50, and the time window is set to every hour.
[0148] Step S34: performing device verification abnormal behavior detection based on the device verification location frequency data and the device short-time verification frequency data to obtain node verification behavior detection data;
[0149] In this embodiment, an anomaly detection algorithm is used to analyze device behavior, combining spatial distribution data and frequency data. By setting a reasonable threshold (for example, a verification frequency exceeding a certain standard deviation), devices with abnormal behavior can be identified. For example, devices may verify at unusual times or frequently verify at different locations. The anomaly detection algorithm can employ statistical methods such as the Z-score method or the machine learning-based isolation forest algorithm to score devices based on pre-defined behavioral patterns and ultimately output a list of devices with abnormal behavior. The device's verification frequency and location frequency data are Z-scored separately, and nodes with detection values exceeding three standard deviations are marked as abnormal. Furthermore, anomaly detection is performed using the isolation forest algorithm, with the model parameters set to 100 trees and 20 samples to identify devices with abnormal verification frequencies. The detection results are then used to identify abnormal devices using thresholds (for example, devices with a verification frequency greater than 5 times / minute are considered frequent verification devices), and a list of abnormal device behavior is generated. Finally, based on the device's associated nodes, the device's abnormal behavior detection results are mapped to the associated nodes, thereby generating node verification behavior detection data.
[0150] Step S35: Perform transmission node credibility assessment on the airport network communication topology model based on the node verification behavior detection data to obtain a node behavior analysis report.
[0151] In this embodiment, the credibility of each node is evaluated, and the evaluation indicators include the node's verification frequency, the geographical consistency of the verification request (for example, whether the device verification occurs in the expected area), and the success rate of the verification request. In specific implementation, the weighted average method is used, and the verification frequency weight is set to 0.6, the location consistency weight is set to 0.3, and the verification success rate weight is set to 0.1 to calculate the comprehensive credibility score of each node. The credibility score of the node is calculated by comprehensively considering the behavior pattern of the device. The score range is from 0 to 1. The higher the score, the higher the security of the node. Finally, a node behavior analysis report is generated. The report will include the node security score, ranking, and recommended measures for unsafe nodes.
[0152] Optionally, step S35 is specifically as follows:
[0153] Step S351: extract abnormal verification behavior nodes from the node verification behavior detection data to obtain abnormal verification behavior node data;
[0154] In this example, we analyze node verification behavior detection data and use the Z-score method to detect nodes with abnormal verification behavior. We set a threshold of 3 standard deviations, and verification behavior outside this range is considered abnormal. Furthermore, we use data flow detection technology to track the frequency of node verification requests, screening out nodes with an abnormally high number of requests within a short period of time. For example, a node with more than 100 requests within 5 minutes will be marked as a node with abnormal verification behavior. These abnormal nodes are extracted according to this rule, and a list of abnormal verification behavior nodes is generated, ensuring that only nodes with significant deviations are identified as abnormal.
[0155] Step S352: performing abnormal verification behavior frequency statistics and abnormal verification behavior time period statistics based on abnormal verification behavior node data to obtain node abnormal verification behavior frequency data and node abnormal verification behavior time period distribution data;
[0156] In this embodiment, the verification frequency of each abnormal verification behavior node is counted, the number of verification requests per hour, day, and month is calculated, the Pandas library is used for data processing, and a frequency distribution graph is generated. At the same time, the time period of the abnormal verification behavior node is analyzed using the time series analysis method, and the frequency of abnormal behavior of each node in different time periods (such as 8:00-9:00, 12:00-13:00, etc.) is counted to form the node abnormal behavior time period distribution data. The time window length used for this time period statistics is 1 hour, and the frequency statistics are divided into high-frequency intervals and low-frequency intervals to distinguish between high-incidence and low-incidence periods of abnormal behavior.
[0157] Step S353: Calculating the severity score of abnormal behavior based on the node abnormal verification behavior frequency data to obtain node abnormal behavior severity score data;
[0158] In this embodiment, the frequency data of each abnormal verification behavior node is standardized. By calculating the standard deviation of each node in its abnormal behavior frequency and multiplying it by a weight coefficient (such as 0.7), the degree of frequency deviation is converted into a score, and the score range is set to 0 to 10 points. The frequency score and the number of times the node is abnormal (for example, 5 consecutive verification failures) jointly affect the severity score of the node. The weighted average method is used, with the frequency score weighted as 0.5 and the number of abnormality score weighted as 0.5. The parameters used in this step are that the frequency deviation standardization coefficient is set to 2, and the weight coefficient and weighted score are dynamically adjusted according to the settings.
[0159] Step S354: Calculate the node abnormal verification behavior period ratio based on the node abnormal verification behavior period distribution data to obtain the node abnormal verification behavior period ratio data;
[0160] In this embodiment, the time periods during which abnormal node verification behaviors occur are counted, and the proportion of abnormal behaviors of each node is calculated. Based on historical verification data, the normal verification time interval for node verification is determined, and the proportion of abnormal node verification time periods is calculated based on this normal time interval. For example, if the normal verification time interval of a node is 8:00-10:00, and the abnormal behavior of the node occurs in the two time periods of 8:00-9:00 and 12:00-13:00, and the total number of occurrences is 20 times, and 10 times in the 8:00-9:00 time period, then the abnormal behavior proportion in the normal verification time period is 50%, and the abnormal behavior proportion in the abnormal verification time period is 50%. Use Excel or a database table to count the proportions of different time periods, and generate the time period proportion data for each node, and output the probability of abnormal behavior of each node in different time periods.
[0161] Step S355: weighting the node abnormal behavior severity score data and the node abnormal verification behavior period ratio data by the node behavior security score to obtain the node behavior security score data;
[0162] In this embodiment, a weighted coefficient is set based on the abnormal behavior severity score and the abnormal verification behavior period ratio data of each node (for example, the severity score weighting coefficient is 0.4, the normal period abnormality ratio weighting coefficient is 0.2, and the abnormal period abnormality ratio weighting coefficient is 0.4) for weighted synthesis. After weighting, the comprehensive security score of the node reflects the overall security risk of the node. The higher the score, the greater the security risk of the node. The weighted score is calculated based on the weighted average method, and the synthesized score can be dynamically updated to facilitate real-time adjustment of the node's security assessment.
[0163] Step S356: Perform node score space visualization on the airport network communication topology model based on the node behavior security score data to obtain a node behavior analysis report.
[0164] In this embodiment, a visualization tool (such as Gephi or Matplotlib) is used to spatially visualize the security score of each node, combining the network topology with the node score to generate a dynamic visualization chart. In the visualization, high-security nodes are displayed in green, and low-security nodes are displayed in red. The location and distribution of high-risk nodes in the network are displayed graphically. In specific implementation, a force-directed layout algorithm is used to layout the network nodes to ensure that the node security score can be intuitively reflected in the graph. Finally, a node behavior analysis report is generated, which lists the security score of each node and its risk assessment in detail. The report can be used for security audits and network optimization.
[0165] Optionally, step S4 is specifically:
[0166] Step S41: selecting a data transmission security node based on the node behavior analysis report to obtain security node data to be distributed;
[0167] In this embodiment, based on the security score data in the node behavior analysis report, nodes with security scores above a set threshold (for example, those with scores above 80%) are selected as safe nodes. Based on this, the network segments containing these nodes are screened for secure transmission tasks. Furthermore, by analyzing node behavior patterns, such as authentication success rates and normal communication frequencies, the stability of the selected nodes is further verified to ensure the security of data transmission. Finally, the data of the safe nodes to be distributed is obtained and recorded as the safe node dataset to be distributed, preparing for subsequent encryption path allocation.
[0168] Step S42: selecting a path with a high security node ratio from the encryption path mapping table according to the security node data to be distributed, to obtain the encryption path data to be distributed;
[0169] In this embodiment, the node ID and corresponding security score are extracted from the security node data to be distributed, and the data is sorted according to the score, and the nodes with higher scores (for example, the nodes with the top 30% scores) are selected. Then, the paths occupied by these high-security nodes are screened and optimized through the encryption path mapping table. In the specific operation, an optimal encryption path is selected for data transmission based on indicators such as bandwidth, latency, and security score of each path. When selecting a path, priority is given to paths with stable transmission, large bandwidth, and low latency. Finally, the encrypted path dataset to be distributed is obtained for the next encryption task.
[0170] Step S43: performing encryption key negotiation on the encrypted path data to be distributed, obtaining an encryption key pair, and uploading it to the airport network security management platform to execute the encryption key distribution task;
[0171] In this embodiment, public key encryption algorithms (such as RSA or ECC) are used for key negotiation. Symmetric encryption keys are generated through security protocols (such as the Diffie-Hellman key exchange protocol). These encryption algorithms are used to establish secure connections with the end nodes of each distribution path, generating a unique encryption key pair. After key generation, the key pair is securely stored and uploaded to the airport network security management platform via an encrypted communication channel. After receiving the key, the platform executes the key distribution task, ensuring that each encrypted path has the corresponding encryption key for data transmission.
[0172] Step S44: Acquire the data to be transmitted for the airport and perform data preprocessing on the data to be transmitted for the airport to obtain the data to be transmitted for the airport to be analyzed;
[0173] In this embodiment, the airport data to be transmitted (e.g., flight scheduling data or cargo transportation information) is obtained from a data source (e.g., an internal airport application system). This data undergoes preliminary cleaning and format conversion to remove invalid or erroneous data and standardize the valid data. By using data processing tools (e.g., the Pandas library in Python), the data is organized into a unified format and field filling, duplication removal, and outlier processing are performed according to preset rules. Finally, the airport data to be transmitted to be analyzed is generated and prepared for further data packet segmentation operations.
[0174] Step S45: segmenting the data to be transmitted from the airport to be analyzed into data packets to obtain a set of segmented data packets to be transmitted;
[0175] In this embodiment, the data to be analyzed is segmented according to a preset packet size, with each packet size set to 1MB to 10MB to balance transmission efficiency and data security. During the segmentation process, a unique identifier is generated for each packet, and necessary header information such as the source node ID, destination node ID, and timestamp are appended. Appropriate segmentation is also performed based on the data content type (such as text, video, or sensor data) to ensure that each packet contains complete and valid data and maintains data integrity and sequence.
[0176] Step S46: Encrypt the virtual tunnel data of the segmented data packet set to be transmitted according to the encryption key to obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to execute the data transmission task.
[0177] In this embodiment, each segmented data packet to be transmitted is encrypted using a pre-acquired encryption key pair. A symmetric encryption algorithm (e.g., AES-256) is used for data encryption, with a 256-bit key length selected to ensure high data security. During the encryption process, each data packet is bound to a corresponding encryption key pair, and an encrypted data packet is generated. Each encrypted data packet is appended with a unique identifier (e.g., packet sequence number, source and destination node identifiers, encryption timestamp, etc.) during encryption, and the packet header information is protected from tampering, maintaining data integrity. To ensure the confidentiality of data during network transmission, the encrypted data packet is further encapsulated using a virtual tunneling protocol (e.g., IPSec or SSL / TLS) to form an encrypted "tunnel" and specify a transmission path. Specifically, when using the IPSec protocol, an encrypted IP data packet is generated and encapsulated in a new IP header using the tunneling protocol, ensuring that the data has multiple layers of encryption protection when transmitted over the network. When using the SSL / TLS protocol, an encrypted connection is created for each data packet, ensuring the encryption and integrity of each data packet during network transmission. During the data packet encryption process, a hash value (such as SHA-256) is calculated and appended to verify the packet's integrity. When the packet reaches the destination node, it decrypts the packet using the same key pair and verifies the hash value to ensure the data has not been tampered with. The encrypted data packet is uploaded to the airport's cybersecurity management platform, which schedules data transmission tasks based on the encryption path and node information, ensuring secure and stable data transmission to the destination node.
[0178] Optionally, step S5 is specifically:
[0179] Step S51: Acquire the real-time communication data of the airport and perform data preprocessing on the real-time communication data of the airport to obtain the real-time communication data of the airport network to be analyzed;
[0180] This embodiment integrates multiple communication devices (such as routers, switches, and wireless access points) within the airport network to collect data packet information in real time. Data preprocessing involves filtering out erroneous packets (e.g., packets with mismatched checksums), classifying the data by protocol type (e.g., TCP, UDP), and converting the data format. For example, raw binary packets are converted to JSON-formatted metadata to facilitate subsequent processing and analysis. During preprocessing, filtering rules are implemented, such as discarding individual packets exceeding 2MB, to ensure efficient subsequent analysis.
[0181] Step S52: performing node link outlier detection on the real-time communication data of the aviation airport network to be analyzed using the airport network communication topology model to obtain a real-time anomaly detection log;
[0182] This example uses a model of the airport network communication topology to monitor real-time data traffic. Using pre-defined thresholds (e.g., traffic exceeding 5GB / s or latency exceeding 300ms on a single link), all passing links are checked. If a link exhibits abnormal transmission delay, throughput, or packet loss, it is flagged as an abnormal link and an anomaly detection log is generated, recording the node, link, and time of the abnormality. This process also incorporates a machine learning-based model to continuously train the topology model, enhancing the accuracy of anomaly detection.
[0183] Step S53: performing data packet delay calculation based on the real-time anomaly detection log to obtain data packet delay data, and classifying and calculating the data packet delay data based on a preset lost data packet delay threshold to obtain lost data packets;
[0184] In this embodiment, the delay is calculated in real time by comparing the sending time and receiving time of the data packets transmitted by the abnormal link in the real-time anomaly detection log. For each network node passed, its delay is calculated and the delay time is stored and counted. If the delay exceeds the set threshold (such as 300ms), the data packet will be marked as a "delayed data packet". According to the preset lost data packet delay threshold (such as continuous delay of more than 3 times and more than 1000ms), it will be classified and marked as a "lost data packet", and the identifiers and timestamps of these lost data packets will be recorded as the basis for subsequent processing. In order to improve accuracy, the traffic analysis model is also combined for anomaly detection to identify potential lost data packets.
[0185] Step S54: decrypting the lost data packet according to the encryption key to obtain a decrypted lost data packet;
[0186] In this embodiment, data packets are decrypted by retrieving the relevant symmetric encryption key (e.g., AES-256 key) from the airport network security management platform. The decryption process involves using the retrieved key, combined with the decryption process of the encryption algorithm (e.g., AES decryption), to restore the encrypted data byte by byte. All decryption operations are performed through a protected hardware security module (HSM) to prevent key leakage and ensure the security of the data decryption process. The decryption process strictly adheres to the established encryption protocol to ensure data integrity and security. The decrypted data packet is then returned to the upper-layer network application for further processing.
[0187] Step S55: reconstructing the decrypted lost data packets based on the segmented data packet set to be transmitted to obtain a restored data packet;
[0188] In this embodiment, after the lost data packet is decrypted, the specific location of the lost packet is determined based on the sequence number (Sequence Number) of the data packet and the source and destination addresses. Based on this information, a data retransmission mechanism (such as a TCP-based retransmission mechanism or UDP application layer retransmission) is used to recover the lost data packet. If the lost packet cannot be recovered by retransmission, an error correction algorithm (such as the Reed-Solomon algorithm) is used to use the complete data packets transmitted before and after to infer and recover the lost data. Each data packet in the recovery process will be verified to ensure that the reconstructed data packet is complete and correct and meets the network protocol requirements. All recovered data packets will be returned to the data stream in the correct order to ensure smooth communication and data accuracy.
[0189] Step S56: selecting a low-latency transmission path for the restored data packet according to the encrypted path data to be distributed, to obtain restored transmission path data;
[0190] In this embodiment, after the recovery data packet is reconstructed, the optimal path is selected based on the real-time network topology and link quality data (such as bandwidth, latency, packet loss rate, etc.). The shortest path algorithm (such as Dijkstra's algorithm) is used to calculate possible transmission paths, taking into account the current network load and latency. By monitoring the real-time latency of each link, a link with a latency of less than 100ms and a low load is selected for data packet transmission. During the path selection process, the path is also adjusted based on dynamic traffic analysis to ensure low-latency transmission and avoid high-traffic or congested nodes. At this time, the recovery data packet will be routed to the optimal path to ensure that the delay during transmission is minimized.
[0191] Step S57: Based on the encryption key pair, the virtual tunnel data of the restored transmission path data and the restored data packet is encrypted to obtain the restored encrypted data packet, and uploaded to the airport network security management platform to execute the data transmission task.
[0192] In this embodiment, after the transmission path is restored and determined, data packets are encrypted using a pre-assigned encryption key, and virtual tunneling technology (such as IPsec or SSL / TLS) is used to protect the data. Specifically, data packets are encapsulated and encrypted using an encryption protocol to prevent them from being eavesdropped or tampered with during network transmission. During the encryption process, data is encrypted using a randomly generated initialization vector (IV) and encryption key, ensuring that the encryption result for each data packet is unique. The encrypted data packets are stored and managed on the airport network security management platform. When the transmission task is executed, the encrypted data is retrieved from the platform and sent, ensuring the security and confidentiality of the data transmission.
[0193] Optionally, this specification also provides a system for securely transmitting information data, for executing the above-mentioned method for securely transmitting information data. The system for securely transmitting information data includes:
[0194] The communication network topology analysis module is used to obtain aviation and airport network communication data, and perform communication network topology analysis on the aviation and airport network communication data to obtain an airport network communication topology model; select a data transmission path based on the airport network communication topology model to obtain data on the transmission path to be allocated;
[0195] A node security assessment module is used to perform a security assessment of the intersection of transmission node load patterns on the airport network communication topology model based on the aviation airport network communication data to obtain transmission node security data; based on the transmission node security data, a transmission path encryption protocol is dynamically allocated to the transmission path data to be allocated to obtain an encrypted path mapping table;
[0196] The node behavior analysis module is used to obtain node verification data and perform a weighted credibility assessment of the node verification data using the transmission node verification space frequency to obtain a node behavior analysis report;
[0197] The data packet encryption module is used to perform data packet virtual tunnel encryption based on the node behavior analysis report and the encryption path mapping table, obtain the encrypted data packet to be transmitted to the airport, and upload it to the airport network security management platform to execute the data transmission task;
[0198] The real-time communication feedback recovery module is used to obtain the real-time communication data of the aviation airport network, and recover the abnormal data of the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
[0199] The present invention is therefore intended to be illustrative and non-restrictive in all respects, with the scope of the invention being defined by the appended claims rather than the foregoing description, and all changes that come within the meaning and range of equivalents of the application documents are intended to be embraced therein.
[0200] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is to be construed in the widest possible manner consistent with the principles and novel features disclosed herein.
Claims
1. A method for securely transmitting information data, characterized in that: The following steps are involved: Step S1: Acquire aviation airport network communication data, and perform communication network topology analysis on the aviation airport network communication data to obtain an airport network communication topology model; select a data transmission path based on the airport network communication topology model to obtain transmission path data to be allocated; Step S2: performing a security assessment of the intersection of transmission node load patterns on the airport network communication topology model based on the aviation airport network communication data to obtain transmission node security data; Based on the transmission node security data, the transmission path data to be allocated is dynamically allocated by the transmission path encryption protocol to obtain an encrypted path mapping table; step S2 is specifically as follows: Step S21: extracting network communication security logs and network traffic monitoring data from the airport network communication data to obtain network communication security logs and network traffic monitoring data, and performing frequency domain conversion on the network traffic monitoring data to obtain a network traffic monitoring spectrum; Step S22: dividing the airport network communication topology model by intrusion node frequency according to the network communication security log to obtain intrusion frequency node division data; Step S23: performing traffic load pattern recognition based on the network traffic monitoring spectrum to obtain network traffic aperiodic load pattern data and network traffic periodic load pattern data; Perform high-frequency load pattern node division according to the network traffic non-periodic load pattern data and the network traffic periodic load pattern data to obtain high-frequency load pattern node division data; Step S24: performing a transmission node security assessment based on the intrusion frequency node division data and the high-frequency load mode node division data to obtain transmission node security data; Step S25: dynamically assigning a transmission path encryption protocol to the transmission path data to be assigned based on the transmission node security data to obtain an encrypted path mapping table; Step S3: Obtain node verification data, and perform a weighted credibility assessment of the node verification data using the transmission node verification space frequency to obtain a node behavior analysis report; Step S4: Based on the node behavior analysis report and the encryption path mapping table, the data packet is encrypted in a virtual tunnel to obtain the airport encrypted data packet to be transmitted, and uploaded to the airport network security management platform to execute the data transmission task; Step S5: Acquire the real-time communication data of the aviation airport network, perform abnormal data recovery on the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
2. The method for securely transmitting information data according to claim 1, wherein: Step S1 is specifically as follows: Step S11: obtaining the aviation airport network communication data through the airport network security management platform, and performing data preprocessing on the aviation airport network communication data to obtain the aviation airport network communication data to be analyzed; Step S12: extracting airport network communication features from the aviation airport network communication data to be analyzed, and obtaining network communication connection data and network dynamic resource allocation data; Step S13: Analyzing the airport network topology structure based on the network communication connection data to obtain an airport network topology map; Step S14: performing dynamic topology data modeling on the airport network topology map based on the network dynamic resource allocation data to obtain an airport network communication topology structure model; Step S15: Select a data transmission path according to the airport network communication topology model to obtain transmission path data to be allocated.
3. The method for securely transmitting information data according to claim 2, wherein: Step S13 is specifically as follows: Step S131: extracting device identity features and device connection frequency features based on the network communication connection data to obtain network device identity data and network device connection frequency data; Step S132: performing communication network node identification on the network device identity data to obtain communication network node data; Step S133: dividing the communication network node data into communication network node data according to the network device connection frequency data to obtain network connection source node data and network connection target node data; Step S134: performing node link relationship identification on the network connection source node data and the network connection target node data to obtain network node link relationship data; Step S135: Perform network node topology analysis based on the network node link relationship data and the communication network node data to obtain an airport network topology diagram.
4. The method for securely transmitting information data according to claim 1, wherein: Step S24 is specifically as follows: Perform node classification on the intrusion frequency node division data to obtain high-frequency communication intrusion node data and low-frequency communication intrusion node data; Performing node classification on the high-frequency load mode node division data to obtain high-frequency periodic load mode node data and high-frequency non-periodic load mode node data; Perform node intersection calculation based on high-frequency communication intrusion node data and high-frequency non-periodic load mode node data to obtain low-security transmission node data; Perform node intersection calculation based on low-frequency communication intrusion node data and low-frequency non-periodic load mode node data to obtain high-security transmission node data; The low-security transmission node data and the high-security transmission node data are combined to obtain transmission node security data.
5. The method for securely transmitting information data according to claim 1, wherein: Step S3 is specifically as follows: Step S31: Obtain node verification data through the network security management platform, and perform data preprocessing on the node verification data to obtain the node verification data to be analyzed; Step S32: extracting node verification features from the node verification data to be analyzed, and obtaining node verification device location data and node verification device frequency data; Step S33: Perform verification device spatial distribution statistics based on the node verification device location data to obtain device verification location frequency data; perform verification device verification frequency statistics on the node verification device frequency data to obtain device short-term verification frequency data; Step S34: performing device verification abnormal behavior detection based on the device verification location frequency data and the device short-time verification frequency data to obtain node verification behavior detection data; Step S35: Perform transmission node credibility assessment on the airport network communication topology model based on the node verification behavior detection data to obtain a node behavior analysis report.
6. The method for securely transmitting information data according to claim 5, wherein: Step S35 is specifically as follows: Step S351: extract abnormal verification behavior nodes from the node verification behavior detection data to obtain abnormal verification behavior node data; Step S352: performing abnormal verification behavior frequency statistics and abnormal verification behavior time period statistics based on abnormal verification behavior node data to obtain node abnormal verification behavior frequency data and node abnormal verification behavior time period distribution data; Step S353: Calculating the severity score of abnormal behavior based on the node abnormal verification behavior frequency data to obtain node abnormal behavior severity score data; Step S354: Calculate the node abnormal verification behavior period ratio based on the node abnormal verification behavior period distribution data to obtain the node abnormal verification behavior period ratio data; Step S355: weighting the node abnormal behavior severity score data and the node abnormal verification behavior period ratio data by the node behavior security score to obtain the node behavior security score data; Step S356: Perform node score space visualization on the airport network communication topology model based on the node behavior security score data to obtain a node behavior analysis report.
7. The method for securely transmitting information data according to claim 1, wherein: Step S4 is specifically as follows: Step S41: selecting a data transmission security node based on the node behavior analysis report to obtain security node data to be distributed; Step S42: selecting a path with a high security node ratio from the encryption path mapping table according to the security node data to be distributed, to obtain the encryption path data to be distributed; Step S43: performing encryption key negotiation on the encrypted path data to be distributed, obtaining an encryption key pair, and uploading it to the airport network security management platform to execute the encryption key distribution task; Step S44: Acquire the data to be transmitted for the airport and perform data preprocessing on the data to be transmitted for the airport to obtain the data to be transmitted for the airport to be analyzed; Step S45: segmenting the data to be transmitted from the airport to be analyzed into data packets to obtain a set of segmented data packets to be transmitted; Step S46: Encrypt the virtual tunnel data of the segmented data packet set to be transmitted according to the encryption key to obtain the aviation airport encrypted data packet to be transmitted, and upload it to the airport network security management platform to execute the data transmission task.
8. The method for securely transmitting information data according to claim 1, wherein: Step S5 is specifically as follows: Step S51: Acquire the real-time communication data of the airport and perform data preprocessing on the real-time communication data of the airport to obtain the real-time communication data of the airport network to be analyzed; Step S52: performing node link outlier detection on the real-time communication data of the aviation airport network to be analyzed using the airport network communication topology model to obtain a real-time anomaly detection log; Step S53: performing data packet delay calculation based on the real-time anomaly detection log to obtain data packet delay data, and classifying and calculating the data packet delay data based on a preset lost data packet delay threshold to obtain lost data packets; Step S54: decrypting the lost data packet according to the encryption key to obtain a decrypted lost data packet; Step S55: reconstructing the decrypted lost data packets based on the segmented data packet set to be transmitted to obtain a restored data packet; Step S56: selecting a low-latency transmission path for the restored data packet according to the encrypted path data to be distributed, to obtain restored transmission path data; Step S57: Based on the encryption key pair, the virtual tunnel data of the restored transmission path data and the restored data packet is encrypted to obtain the restored encrypted data packet, and uploaded to the airport network security management platform to execute the data transmission task.
9. An information data security transmission system, characterized in that: For executing the information data secure transmission method according to claim 1, the information data secure transmission system comprises: The communication network topology analysis module is used to obtain aviation and airport network communication data, and perform communication network topology analysis on the aviation and airport network communication data to obtain an airport network communication topology model; select a data transmission path based on the airport network communication topology model to obtain data on the transmission path to be allocated; A node security assessment module is used to perform a security assessment of the intersection of transmission node load patterns on the airport network communication topology model based on the aviation airport network communication data to obtain transmission node security data; based on the transmission node security data, a transmission path encryption protocol is dynamically allocated to the transmission path data to be allocated to obtain an encrypted path mapping table; The node behavior analysis module is used to obtain node verification data and perform a weighted credibility assessment of the node verification data using the transmission node verification space frequency to obtain a node behavior analysis report; The data packet encryption module is used to perform data packet virtual tunnel encryption based on the node behavior analysis report and the encryption path mapping table, obtain the encrypted data packet to be transmitted to the airport, and upload it to the airport network security management platform to execute the data transmission task; The real-time communication feedback recovery module is used to obtain the real-time communication data of the aviation airport network, and recover the abnormal data of the real-time communication data of the aviation airport network, obtain the restored encrypted data packet, and upload it to the airport network security management platform to perform the data transmission task.
Citation Information
Patent Citations
Distributed data encryption transmission system
CN117955749A
Method for automatically verifying security of communication software
CN119071073A