Cyberspace data transmission method and device

By obtaining the forwarding path and exchange node information of the ad hoc network, updating the session key and encryption mechanism, the problem of low reliability and security of the transmission path in the ad hoc network is solved, and high-security data transmission in the dynamic environment is achieved.

CN120091304BActive Publication Date: 2025-08-12INST OF AUTOMATION CHINESE ACAD OF SCI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510521596.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-08-12
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

In the dynamic environment, the existing ad hoc network has low reliability and transparency in transmission paths, and relying on the static password mechanism cannot identify network threats in a timely manner, resulting in low data transmission security.

Method used

By obtaining the forwarding path information and exchange node information of network space data packets, querying malicious nodes and updating the forwarding path and session key, data transmission is carried out using a distributed encryption mechanism.

Benefits of technology

It improves the security and reliability of data transmission in an ad hoc network environment, and enhances the identification and isolation capabilities of malicious nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120091304B_ABST
    Figure CN120091304B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of ad hoc network security technology and provides a method and apparatus for cyberspace data transmission. The method comprises: obtaining forwarding path information and switching node information of a cyberspace data packet; when the forwarding path information is inconsistent with an expected path, querying the switching node information for malicious nodes, and updating the forwarding path information based on the location information of the malicious nodes to obtain updated forwarding path information; updating a session key corresponding to the expected path based on the updated forwarding path information to obtain an updated session key; and encrypting and transmitting the cyberspace data packet based on the updated session key and the updated forwarding path information. The method of the present invention improves the security of cyberspace data transmission in an ad hoc network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of self-organizing network security technology, and in particular to a network space data transmission method and device. Background Art

[0002] With the rapid development of the Internet of Things and wireless communication technology, ad hoc network technology has gradually been widely used, especially in the fields of mobile communications, smart homes and emergency rescue.

[0003] In related technologies, existing self-organizing networks mostly adopt traditional centralized security management strategies. In the dynamic self-organizing network scenario, the frequent changes in network topology make it difficult for centralized management to maintain efficient and reliable security protection. For example, when the self-organizing network centrally manages data flows, the reliability and transparency of different data flow transmission paths are low; in terms of authentication and access control, the self-organizing network relies on static, password-based mechanisms, which are prone to security vulnerabilities. Especially when facing attacks from malicious actors, it is impossible to timely and accurately identify potential threats in the network, resulting in low data transmission security.

[0004] Therefore, how to achieve effective security management in a dynamic ad hoc network environment and improve the security of data transmission and network reliability has become an important issue that needs to be solved urgently. Summary of the Invention

[0005] The present invention provides a method and device for transmitting cyberspace data, which are used to solve the problems in the prior art where, when a self-organizing network adopts a centralized security management strategy for data transmission, the reliability and transparency of different transmission paths are low, and the self-organizing network relies on a static, password-based mechanism and cannot timely and accurately identify potential threats in the network, resulting in low security of the self-organizing network transmitting cyberspace data. The present invention improves the security of cyberspace data transmission in the self-organizing network.

[0006] The present invention provides a cyberspace data transmission method, which is applied to an ad hoc network and includes:

[0007] Obtain the forwarding path information and switching node information of network space data packets;

[0008] When the forwarding path information is inconsistent with the expected path, querying a malicious node from the switching node information, and updating the forwarding path information according to the location information of the malicious node to obtain updated forwarding path information; and updating the session key corresponding to the expected path according to the updated forwarding path information to obtain an updated session key;

[0009] The network space data packet is encrypted and transmitted according to the updated session key and the updated forwarding path information.

[0010] According to a cyberspace data transmission method provided by the present invention, the acquired cyberspace data packet includes a PFV header, and the PFV header includes multiple identifiers, and the multiple identifiers are used to mark the data flow, the time window of the data flow, the verification status of each hop and at least one of the MAC authentication, the switching node and forwarding path of the data flow.

[0011] According to a method for transmitting network space data provided by the present invention, the network space data packet obtained includes a PFV header, and the PFV header includes multiple identifiers, and the multiple identifiers are used to mark the switching node, forwarding path, verification status of each hop, and MAC authentication of the data flow;

[0012] After querying the exchange node information for malicious nodes, the method further includes:

[0013] The MAC authentication information is verified hop by hop through the switching node, and after confirming that the network space data packet has not been tampered with, verification information is added to the end of the forwarding path information to obtain new forwarding path information; the verification information is used to indicate that the MAC authentication information has passed the verification.

[0014] According to a cyberspace data transmission method provided by the present invention, each session key corresponds to at least one subkey, and the at least one subkey performs multi-level encryption on different forwarding paths through a hop-by-hop verification method.

[0015] According to a cyberspace data transmission method provided by the present invention, the session key and the at least one subkey are periodically updated.

[0016] According to a network space data transmission method provided by the present invention, the obtained network space data packet includes a PFV header, and the PFV header includes a PathTrace identifier, and the PathTrace identifier is used to record forwarding path information of the network space data packet;

[0017] The querying of malicious nodes from the exchange node information includes:

[0018] Identifying an abnormal path in the forwarding path information based on the PathTrace identifier;

[0019] The location information of the malicious node is determined from the abnormal path, and the network participation authority of the malicious node is cut off.

[0020] According to a cyberspace data transmission method provided by the present invention, determining the location information of the malicious node from the abnormal path includes:

[0021] A binary search method is used to search for malicious nodes in the abnormal path to obtain location information of the malicious nodes.

[0022] The present invention also provides a network space data transmission device, comprising:

[0023] An information acquisition module is used to obtain the forwarding path information and switching node information of the network space data packet;

[0024] an updating module, configured to, when the forwarding path information is inconsistent with the expected path, query a malicious node from the switching node information, and update the forwarding path information according to the location information of the malicious node to obtain updated forwarding path information; and update a session key corresponding to the expected path according to the updated forwarding path information to obtain an updated session key;

[0025] A transmission module is used to encrypt and transmit the network space data packet according to the updated session key and the updated forwarding path information.

[0026] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the network space data transmission method as described above is implemented.

[0027] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described methods for transmitting network space data.

[0028] The present invention also provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above-described methods for transmitting data in cyberspace.

[0029] The cyberspace data transmission method and device provided by the present invention obtain the forwarding path information and switching node information of the cyberspace data packet through the controller of the self-organizing network. When the forwarding path information is inconsistent with the expected path, malicious nodes are queried from the switching node information, and the forwarding path information and the session key corresponding to the expected path are updated according to the location information of the malicious node. Finally, the cyberspace data packet is encrypted and transmitted according to the updated session key and the updated forwarding path information, thereby improving the security of cyberspace data transmission in the self-organizing network. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0031] Figure 1 It is a flow chart of the cyberspace data transmission method provided by the present invention.

[0032] Figure 2 It is a flow chart of the path verification mechanism method provided by the present invention.

[0033] Figure 3 It is a structural diagram of the network space data transmission device provided by the present invention.

[0034] Figure 4 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0035] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0036] The following combination Figure 1-Figure 3 The present invention describes the network space data transmission method and device.

[0037] Figure 1 It is a flowchart of the network space data transmission method provided by the present invention, such as Figure 1 As shown, the cyberspace data transmission method, applied to a self-organizing network, includes the following steps:

[0038] Step 110: Obtain the forwarding path information and switching node information of the network space data packet.

[0039] In this step, Ad Hoc Networks provide flexible and reliable solutions for spatial data transmission through decentralization, multi-hop routing, and dynamic topology adjustment capabilities, and are particularly suitable for network environments without infrastructure or with dynamic changes.

[0040] In this step, verifiable path information is added to the cyberspace data packet to ensure that the transmission path is traceable and verifiable. By adding record switching node information to the cyberspace data packet, the switching nodes that have forwarded the data packet are recorded for tracking the path.

[0041] In this embodiment, when packetizing network space data, the header field can be independently designed. For example, the identifier SwitchID is added to the header to record the switching node that forwarded the data packet to track the transmission path of the data flow. The identifier PathTrace is added to the header to dynamically expand the header field and record the actual path passed by the data packet.

[0042] In some embodiments, obtaining a network space data packet includes a PFV header, and the PFV header includes multiple identifiers, and the multiple identifiers are used to mark the data flow, the time window of the data flow, at least one of the verification status and MAC authentication of each hop, the switching node and forwarding path of the data flow.

[0043] In this embodiment, the PFV header includes the following identifiers:

[0044] FlowID‌ is used to assign a unique identifier (such as a hash value) to each data flow to distinguish different data flows. It is suitable for heterogeneous network environments.

[0045] ‌TimeID‌, used to mark the time window of the data packet (such as a timestamp or sequence number), supporting dynamic adjustment of path strategies (for example, to cope with network congestion).

[0046] ‌SwitchID‌ is used to record the unique identifier of the current forwarding node (such as IP+port) and to track the nodes that the data packet passes through.

[0047] ‌PathTrace‌ is used to dynamically expand the field and append the ID of each node passed in sequence to form the actual path record.

[0048] ‌HopValidity‌, used for the verification status bit (0 / 1) of each node, initially 0, and updated to 1 after passing verification.

[0049] MAC, used for HMAC-based authentication codes, uses a shared key to generate header key fields (FlowID+TimeID+PathTrace) to ensure header integrity. Specifically, data integrity can be verified through a hop-by-hop message authentication code (MAC) calculated based on a distributed key.

[0050] In this embodiment, a PFV header including the above-mentioned identifier is designed in a data packet. When a data packet is transmitted through an ad hoc network, the source node generates a PFV header and fills in the initial fields (FlowID, TimeID). When each subsequent node forwards the packet, it updates the SwitchID, appends the PathTrace, and calculates the MAC to generate a phased MAC check value for data integrity verification.

[0051] Step 120: When the forwarding path information is inconsistent with the expected path, query the malicious node from the switching node information, and update the forwarding path information according to the location information of the malicious node to obtain updated forwarding path information; update the session key corresponding to the expected path according to the updated forwarding path information to obtain an updated session key.

[0052] In this step, the actual path is compared with the pre-planned expected path to detect whether the paths are consistent. If the actual path of the data packet is consistent with the preset path, it can be used to locate the malicious node.

[0053] In this embodiment, the controller of the ad hoc network assigns an ExpectedPath (e.g., node sequence A→B→C→D) to each FlowID. When each node receives a packet, it checks whether the PathTrace matches the ExpectedPath prefix (e.g., when arriving at B, the PathTrace should be A→B). If all HopValidity values are 1 and PathTrace = ExpectedPath, the path is valid.

[0054] In this embodiment, if the PathTrace deviates from the ExpectedPath (for example, an unauthorized node E appears in the path), or if HopValidity = 0, an exception alarm is triggered, and the first inconsistent node is located in the PathTrace. The malicious node is then found by calculating whether the individual path is abnormal, and the corresponding node is marked for isolation.

[0055] Specifically, each time a data flow is planned, the controller distributes the planned path (expected path) and session key to participating nodes. The path is stored in the temporary storage space of each node. The relationship between the ExpectedPath and PathTrace, as well as the validity of each hop, is expressed as follows:

[0056] ;

[0057] in, N 1, N 2,…, N k Indicates 1 to k A hash function, M 1, M 2,…, M m Indicates the actual paths that the data packets take, corresponding to 1 to m This embodiment verifies whether the actual path matches the planned path by checking the PathTrace field, which can be specifically expressed by the following formula:

[0058] ;

[0059] The first time a node appears where the current path of the data flow is different from the expected path, j is the encoding of the exchange node sequence, j ∈(1, m If an inconsistency is detected, the controller backtracks from the abnormal location and recursively confirms the problem node;

[0060] In this embodiment, obtaining a network space data packet includes a PFV header, and the PFV header includes a PathTrace identifier, which is used to record forwarding path information of the network space data packet; and querying malicious nodes from the switching node information includes:

[0061] Based on the PathTrace identifier, abnormal paths in the forwarding path information are identified; the location information of the malicious node is determined from the abnormal path, and the network participation rights of the malicious node are cut off.

[0062] Specifically, the path anomaly is detected through the PathTrace field of the abnormal data packet to locate the malicious node, and its participation in the network is cut off in real time.

[0063] According to a cyberspace data transmission method provided by the present invention, determining the location information of a malicious node from an abnormal path includes:

[0064] In this embodiment, a binary search method is used to search for malicious nodes in abnormal paths to obtain location information of the malicious nodes, which can effectively improve the efficiency of locating the malicious nodes.

[0065] In this embodiment, after obtaining the location information of the malicious node, the controller reallocates the safe path by the following formula: NewPath (i.e. updated forwarding path information) and bypass the problem area (including malicious nodes):

[0066] ;

[0067] In this embodiment, the controller can also dynamically update the session keys of participating nodes by the following formula: (i.e., the updated session key) to prevent the disclosure of messages involving the identified problem areas.

[0068] ;

[0069] in, H Same as above N , represents the hash function, S is the current system key; is the latest timestamp, For nodes A unique identifier for the .

[0070] Figure 2 This is a flow chart of the path verification mechanism method provided by the present invention. Figure 2 In the illustrated embodiment, a path verification mechanism method includes the following steps:

[0071] (1) Data packet generation and forwarding, used to generate cyberspace data packets and forward them within the ad hoc network;

[0072] (2) The controller plans the expected path (distributes the path and session key). The controller plans the expected path for data packet transmission and distributes the path and session key.

[0073] (3) Nodes forward data packets hop by hop (PFV header update). As data packets are forwarded hop by hop between nodes, each node updates the PFV (Packet Forwarding Verification) header.

[0074] (4) The controller verifies the path consistency (comparing PathTrace with the expected path). After the controller receives the path information (PathTrace), it compares the path information with the planned expected path to verify the consistency of the path.

[0075] ‌ (5) If the path is normal, the data packet continues to be transmitted along the current path until the target node receives the data; if the path is abnormal, the individual path anomalies are calculated (malicious nodes are discovered). For example, by comparing and analyzing, individual paths with anomalies are identified, and malicious nodes may be discovered.

[0076] ‌ (6) In the case of path anomaly, malicious node positioning is used to determine the malicious nodes in the abnormal path.

[0077] (7) Dynamic path repair: The controller starts the dynamic path repair mechanism to replan and distribute new paths to bypass malicious nodes.

[0078] ‌ (8) Dynamic Key Update‌: Dynamically update session keys throughout the process or after path repair to enhance security.

[0079] The above steps (1)-(8) form a closed-loop path verification and repair mechanism to ensure that data packets can be transmitted safely and reliably.

[0080] Step 130: Encrypt and transmit the network space data packet according to the updated session key and the updated forwarding path information.

[0081] In this step, after obtaining the updated session key and updated forwarding path information, the PathTrace field of the data packet is checked before the node forwards it to see if it matches the new path. If it deviates, an alarm is triggered and reported to the controller. If it matches, the new session key is used to re-encrypt and encapsulate the network space data packet, and communication transmission is carried out.

[0082] The cyberspace data transmission method provided by the embodiment of the present invention obtains the forwarding path information and switching node information of the cyberspace data packet through the controller of the self-organizing network. When the forwarding path information is inconsistent with the expected path, malicious nodes are queried from the switching node information, and the forwarding path information and the session key corresponding to the expected path are updated according to the location information of the malicious node. Finally, the cyberspace data packet is encrypted and transmitted according to the updated session key and the updated forwarding path information, thereby improving the security of cyberspace data transmission in the self-organizing network.

[0083] In some embodiments, the network space data packet obtained includes a PFV header, and the PFV header includes multiple identifiers, and the multiple identifiers are used to mark the switching node, forwarding path, verification status of each hop and MAC authentication of the data flow; after querying the malicious node from the switching node information, the method also includes: verifying the MAC authentication information hop by hop through the switching node, and adding verification information to the end of the forwarding path information after confirming that the network space data packet has not been tampered with to obtain new forwarding path information; the verification information is used to indicate that the MAC authentication information has passed the verification.

[0084] In this embodiment, a distributed verification mechanism is designed to ensure data integrity. For example, the switching node verifies that the data has not been tampered with through the MAC (Message Authentication Code) field before forwarding it and discards the data packets that fail the verification. This is specifically expressed as follows:

[0085] ;

[0086] in, For the The MAC corresponding to each node, For the MAC corresponding to each node; For the The key corresponding to each node, HMAC is the hash message authentication code function; Payload is the payload of the packet, Headers is the header of the data packet, For nodes Corresponding hop-by-hop verification results.

[0087] In this embodiment, when integrity marking is performed, the data packet records a "verification success" mark at the end of the path to submit to the target node; each time the verification fails, the abnormal data packet header is reported to the controller and marked as lost.

[0088] Specifically, when the HopValidity value of a hop's verification status is 0 (MAC verification failed), the controller determines that the node (such as Node B) is a potential malicious node. Then, combined with historical path logs (NodeTrace) and traffic behavior analysis (such as abnormal retransmission rate), the malicious behavior pattern is confirmed; the controller generates a new forwarding path ExpectedPath' and updates the expected forwarding path ExpectedPath in the PFV header; when the data packet passes through the new path node, after completing MAC verification at each hop, a verification tag is appended to the end of the NodeTrace, and finally the new forwarding path information is generated, providing a basis for subsequent data statistics and path analysis.

[0089] The cyberspace data transmission method provided by the embodiment of the present invention performs hop-by-hop verification of MAC authentication information through a switching node, and adds verification information to the end of the forwarding path information after confirming that the cyberspace data packet has not been tampered with, thereby obtaining new forwarding path information, thereby enhancing data integrity and anti-tampering capabilities, and improving the reliability of the data packet transmission path in a dynamic network environment.

[0090] In some embodiments, each session key corresponds to at least one subkey, and the at least one subkey performs multi-level encryption on different forwarding paths through hop-by-hop verification.

[0091] In this embodiment, a key negotiation mechanism consistent with the dynamic ad hoc network is designed in combination with a session key generation method based on a hash message authentication code (HMAC). That is, the controller and each switching node negotiate a distributed session key at the beginning of communication. All verification operations are based on subkeys derived from the session key, and communication security is ensured through the transport layer security protocol between devices.

[0092] Specifically, each session key generates multiple subkeys through a key derivation function (such as HKDF), which are used for encryption and authentication of different forwarding paths or hops.

[0093] In this embodiment, the subkey is bound to a path identifier (such as a path ID or a node sequence) to ensure encryption isolation of different paths in the same session.

[0094] In this embodiment, the controller distributes the master session key to the path entry node through a security protocol (such as IKEv2), and subsequent nodes derive subkeys on demand.

[0095] In this embodiment, the key lifecycle can also be linked to the path status. When the path changes, the subkey is triggered to be regenerated and synchronized to the new path node.

[0096] In this embodiment, each hop node uses the corresponding subkey to encrypt the data packet (such as AES-128) and calculate the MAC (such as HMAC-SHA256) to ensure data integrity and source trust. When verification fails (such as MAC mismatch), the node marks the abnormality and triggers path switching to prevent malicious nodes from continuing to eavesdrop or tamper with the data.

[0097] The cyberspace data transmission method provided by an embodiment of the present invention sets each session key to correspond to at least one subkey, and at least one subkey performs multi-level encryption on different forwarding paths through hop-by-hop verification. By deriving subkeys based on session keys in a self-organizing network and combining them with hop-by-hop verification to achieve multi-level encryption, data security and transmission controllability under dynamic paths are improved.

[0098] In some embodiments, the session key and at least one subkey are periodically updated.

[0099] In this embodiment, the key expires in a fixed time period, and the key is updated to enhance security. The update formula is as follows:

[0100] ;

[0101] in, For exchange nodes and The session key between them, HMAC is the message authentication code of the hash function, For nodes The session key, is a time window identifier, used to identify the j-th time window.

[0102] In this embodiment, a fixed time window expiration mechanism is set to automatically update the session key and its subkeys. For example, a strict life cycle (such as 5 minutes to 30 minutes) is set for the session key and the subkey, and they automatically expire after the timeout and trigger an update.

[0103] In this embodiment, event-driven updating of the session key and its subkeys can also be set. For example, when abnormal behavior is detected (such as path change or MAC verification failure), the current key is immediately discarded and a new key is generated.

[0104] The cyberspace data transmission method provided by the embodiment of the present invention reduces the risk of key leakage and improves the anti-attack capability of the ad hoc network by setting the session key and at least one subkey for periodic update.

[0105] The following describes the network space data transmission device provided by the present invention. The network space data transmission device described below and the network space data transmission method described above can be referenced to each other.

[0106] Figure 3 This is a schematic diagram of the structure of the network space data transmission device provided by the present invention. Figure 3 As shown, the cyberspace data transmission device includes: an information acquisition module 310, an update module 320 and a transmission module 330.

[0107] Information acquisition module 310, used to obtain the forwarding path information and switching node information of the network space data packet;

[0108] An updating module 320 is configured to, when the forwarding path information is inconsistent with the expected path, query the switching node information for malicious nodes, update the forwarding path information based on the location information of the malicious nodes, and obtain updated forwarding path information; and update the session key corresponding to the expected path based on the updated forwarding path information to obtain an updated session key.

[0109] The transmission module 330 is used to encrypt and transmit the network space data packet according to the updated session key and the updated forwarding path information.

[0110] The cyberspace data transmission device provided by an embodiment of the present invention obtains the forwarding path information and switching node information of the cyberspace data packet through the controller of the self-organizing network. When the forwarding path information is inconsistent with the expected path, the malicious node is queried from the switching node information, and the forwarding path information and the session key corresponding to the expected path are updated according to the location information of the malicious node. Finally, the cyberspace data packet is encrypted and transmitted according to the updated session key and the updated forwarding path information, thereby improving the security of the cyberspace data transmission in the self-organizing network.

[0111] Figure 4 An example of a physical structure diagram of an electronic device is shown below. Figure 4As shown, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communications bus 440. The processor 410, the communications interface 420, and the memory 430 communicate with each other via the communications bus 440. The processor 410 may invoke logic instructions in the memory 430 to execute a cyberspace data transmission method, which includes: obtaining forwarding path information and switching node information of a cyberspace data packet; when the forwarding path information is inconsistent with an expected path, querying the switching node information for malicious nodes, and updating the forwarding path information based on the location information of the malicious nodes to obtain updated forwarding path information; updating a session key corresponding to the expected path based on the updated forwarding path information to obtain an updated session key; and encrypting and transmitting the cyberspace data packet based on the updated session key and the updated forwarding path information.

[0112] Furthermore, the logic instructions in the aforementioned memory 430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0113] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the cyberspace data transmission method provided by the above methods, which includes: obtaining forwarding path information and switching node information of the cyberspace data packet; when the forwarding path information is inconsistent with the expected path, querying malicious nodes from the switching node information, and updating the forwarding path information according to the location information of the malicious node to obtain updated forwarding path information; updating the session key corresponding to the expected path according to the updated forwarding path information to obtain an updated session key; and encrypting and transmitting the cyberspace data packet according to the updated session key and the updated forwarding path information.

[0114] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the cyberspace data transmission method provided by the above-mentioned methods, the method comprising: obtaining forwarding path information and switching node information of a cyberspace data packet; when the forwarding path information is inconsistent with the expected path, querying malicious nodes from the switching node information, and updating the forwarding path information according to the location information of the malicious node to obtain updated forwarding path information; updating the session key corresponding to the expected path according to the updated forwarding path information to obtain an updated session key; and encrypting and transmitting the cyberspace data packet according to the updated session key and the updated forwarding path information.

[0115] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0116] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0117] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for transmitting data in cyberspace, applied to a self-organizing network, characterized in that: include: Obtain the forwarding path information and switching node information of network space data packets; When the forwarding path information is inconsistent with the expected path, querying a malicious node from the switching node information, and updating the forwarding path information according to the location information of the malicious node to obtain updated forwarding path information; and updating the session key corresponding to the expected path according to the updated forwarding path information to obtain an updated session key; encrypting and transmitting the cyberspace data packet according to the updated session key and the updated forwarding path information; Each session key corresponds to at least one subkey, and the at least one subkey performs multi-level encryption on different forwarding paths through hop-by-hop verification; Each session key generates multiple subkeys through a key derivation function, which are respectively used for encryption and authentication of different forwarding paths or hops; the multiple subkeys are bound to the path identifier; The lifecycle of each subkey is linked to the path status. When the path changes, the subkey is regenerated and synchronized to the new path node. Each hop node is used to encrypt and calculate the MAC of the data packet using the corresponding subkey; when the verification fails, the node marks the abnormality and triggers the path switching.

2. The cyberspace data transmission method according to claim 1, characterized in that: The obtained network space data packet includes a PFV header, and the PFV header includes multiple identifiers, and the multiple identifiers are used to mark the data flow, the time window of the data flow, at least one of the verification status and MAC authentication of each hop, the switching node and forwarding path of the data flow.

3. The cyberspace data transmission method according to claim 1, characterized in that: The obtained network space data packet includes a PFV header, and the PFV header includes multiple identifiers, and the multiple identifiers are used to mark the switching node, forwarding path, verification status of each hop and MAC authentication of the data flow; After querying the exchange node information for malicious nodes, the method further includes: The MAC authentication information is verified hop by hop through the switching node, and after confirming that the network space data packet has not been tampered with, verification information is added to the end of the forwarding path information to obtain new forwarding path information; the verification information is used to indicate that the MAC authentication information has passed the verification.

4. The method for transmitting data in cyberspace according to claim 1, wherein: The session key and the at least one subkey are periodically updated.

5. The method for transmitting data in cyberspace according to claim 1, wherein: The obtained network space data packet includes a PFV header, and the PFV header includes a PathTrace identifier, and the PathTrace identifier is used to record forwarding path information of the network space data packet; The querying of malicious nodes from the exchange node information includes: Identifying an abnormal path in the forwarding path information based on the PathTrace identifier; The location information of the malicious node is determined from the abnormal path, and the network participation authority of the malicious node is cut off.

6. The cyberspace data transmission method according to claim 5, characterized in that: Determining the location information of the malicious node from the abnormal path includes: A binary search method is used to search for malicious nodes in the abnormal path to obtain location information of the malicious nodes.

7. A network space data transmission device, using the network space data transmission method according to claim 1, characterized in that: include: An information acquisition module is used to obtain the forwarding path information and switching node information of the network space data packet; an updating module, configured to, when the forwarding path information is inconsistent with the expected path, query a malicious node from the switching node information, and update the forwarding path information according to the location information of the malicious node to obtain updated forwarding path information; and update a session key corresponding to the expected path according to the updated forwarding path information to obtain an updated session key; A transmission module is used to encrypt and transmit the network space data packet according to the updated session key and the updated forwarding path information.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the cyberspace data transmission method according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the cyberspace data transmission method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Reconfigurable dynamic path verification method based on authentication fragments

    CN111541611A

  • Information processing method, node, and computer readable storage medium

    WO2024001322A1