SDWAN-based distributed data set security sharing control method and system
By obtaining the data set to be shared and its memory size in the SDWAN system and selecting the safest network node for data sharing, the problem of SDWAN not being intelligent enough in distributed data sharing is solved, and the secure sharing and rapid restoration of distributed data sets are realized.
Patent Information
- Application Number
- CN202510347002.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-24
AI Technical Summary
Software-defined wide area networks (SDWANs) are not intelligent enough in distributed data sharing, and it is difficult to effectively improve the intelligence of distributed data sharing.
By obtaining the data set to be shared and its memory size, determining the security parameters and evaluation value of the network node, selecting the safest network node for data sharing, and dividing the data into multiple data sets for distributed sharing.
It realizes the secure sharing of distributed data sets based on SDWAN, improves the intelligence and security of data sharing, and can quickly restore the data set after the data sharing is completed.
Smart Images

Figure CN120200804A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology or communication technology, and particularly relates to a control method and system for secure sharing of distributed data sets based on SDWAN. Background Art
[0002] In practical applications, software-defined wide area network (SDWAN) is a collection of a series of technologies, which can be simply understood as applying the technology of software-defined networking (SDN) to the management of wide area network (WAN). Among them, software-defined networking technology can use virtualization technology to simplify the management and operation of data centers. Similarly, applying related technologies to wide area networks can also simplify the control of wide area networks by enterprise users.
[0003] Currently, software-defined wide area network is not intelligent enough in distributed data sharing. Therefore, how to improve the intelligence of distributed data sharing for SDWAN urgently needs to be solved. Summary of the Invention
[0004] Embodiments of this application provide a control method and system for secure sharing of distributed data sets based on SDWAN, aiming to improve the intelligence of distributed data sharing for SDWAN.
[0005] In a first aspect, embodiments of this application provide a control method for secure sharing of distributed data sets based on SDWAN, which is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. The method includes:
[0006] Obtain a data set to be shared and the memory size of the data set to be shared, where the data set to be shared includes multiple data;
[0007] Determine the security parameters of the n network nodes to obtain n security parameters;
[0008] Determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values;
[0009] Determine the number of sharing nodes m corresponding to the memory size; m is a positive integer less than or equal to n;
[0010] Select the largest m security evaluation values from the n security evaluation values, and obtain the network nodes corresponding to the m security evaluation values to obtain m network nodes;
[0011] Divide the multiple data into m data sets; each data set corresponds to a network node index, and each data in each data set corresponds to a data position index of the data set to be shared;
[0012] Generate an index list according to the network node indexes and related data position indexes of the m data sets;
[0013] Share the m data sets to the m network nodes respectively, and save the index list.
[0014] In a second aspect, an embodiment of the present application provides a control system for secure sharing of distributed data sets based on SDWAN, which is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. The control system for secure sharing of distributed data sets based on SDWAN includes: an acquisition unit, a determination unit, a division unit, a generation unit, and a sharing unit, where,
[0015] The acquisition unit is used to acquire the data set to be shared and the memory size of the data set to be shared, where the data set to be shared includes multiple data;
[0016] The determination unit is used to determine the security parameters of the n network nodes to obtain n security parameters; determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values; determine the number of sharing nodes m corresponding to the memory size; m is a positive integer less than or equal to n;
[0017] The acquisition unit is further used to select the largest m security evaluation values from the n security evaluation values, and acquire the network nodes corresponding to the m security evaluation values to obtain m network nodes;
[0018] The division unit is used to divide the multiple data into m data sets; each data set corresponds to a network node index, and each data in each data set corresponds to a data position index of the data set to be shared;
[0019] The generation unit is used to generate an index list according to the network node indexes and related data position indexes of the m data sets;
[0020] The sharing unit is used to share the m data sets to the m network nodes respectively, and save the index list.
[0021] Implementing the embodiments of the present application has the following beneficial effects:
[0022] It can be seen that the control method and system for secure sharing of distributed datasets based on SDWAN described in the embodiments of the present application are applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. Obtain the dataset to be shared and the memory size of the dataset to be shared. The dataset to be shared includes multiple data. Determine the security parameters of the n network nodes to obtain n security parameters. Determine the security evaluation values of the n network nodes based on the n security parameters to obtain n security evaluation values. Determine the number of sharing nodes m corresponding to the memory size; m is a positive integer less than or equal to n. Select the largest m security evaluation values from the n security evaluation values, and obtain the network nodes corresponding to the m security evaluation values to get m network nodes. Divide the multiple data into m datasets; each dataset corresponds to a network node index, and each data in each dataset corresponds to a data location index of the dataset to be shared. Generate an index list based on the network node indexes and relevant data location indexes of the m datasets. Share the m datasets to the m network nodes respectively and save the index list. It is possible to determine the corresponding number of sharing nodes based on the memory size of the dataset to be shared, select an equal number of the safest network nodes based on the number of sharing nodes, divide the dataset to be shared into datasets equal in number to the number of sharing nodes, and generate an index list based on the network node indexes of the datasets and the data location indexes of the data. Furthermore, realize the distributed secure sharing of the dataset to be shared, and quickly restore the dataset to be shared from the m network nodes after the sharing of the dataset to be shared is completed. In this way, the intelligence of distributed data sharing is improved for SDWAN. Description of the Drawings
[0023] To more clearly illustrate the technical solutions in the embodiments of the present application or in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0024] Figure 1 It is a flowchart of a control method for secure sharing of distributed datasets based on SDWAN provided by an embodiment of the present application;
[0025] Figure 2 It is a schematic structural diagram of an SDWAN system provided by an embodiment of the present application;
[0026] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application;
[0027] Figure 4It is a functional unit composition block diagram of a control system for secure sharing of distributed datasets based on SDWAN provided by an embodiment of the present application. Detailed implementation manners
[0028] In the specification and claims of the present application and the above-mentioned drawings, terms such as "first", "second", etc. are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may also include steps or units not listed in a possible example, or may also include other steps or units inherent to these processes, methods, products or devices in a possible example.
[0029] Referring to "embodiment" herein means that a specific feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.
[0030] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present application.
[0031] In the embodiments of the present application, the carrying capacity (carrying capacity value) can be understood as an important indicator for measuring the performance of a communication system or network in the communication field. In specific applications, the carrying capacity mainly refers to the amount of data or traffic that a communication system can process and transmit on the premise of meeting certain quality of service (QoS) requirements. Correspondingly, the node carrying capacity can be understood as the amount of data or traffic that a node can process and transmit on the premise of meeting certain quality of service requirements.
[0032] In the embodiments of the present application, the electronic device may include any electronic device with specific communication functions, and the electronic device may include but is not limited to: intelligent robots, smart phones, servers, routers, gateways, smart switches, tablet computers, wearable devices, smart cars, smart watches, smart bracelets, smart glasses, vehicle-mounted devices, computing devices, or other processing devices connected to a wireless modem, as well as various forms of user equipment (UE), mobile stations (MS), terminal devices, etc., which are not limited herein.
[0033] Please refer to Figure 1 , Figure 1 FIG. is a schematic flowchart of a control method for secure sharing of distributed data sets based on SDWAN provided by an embodiment of the present application. As shown in the figure, it is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. The control method for secure sharing of distributed data sets based on SDWAN includes:
[0034] 101. Obtain the data set to be shared and the memory size of the data set to be shared, where the data set to be shared includes multiple data.
[0035] In specific implementation, as Figure 2 shown, the SDWAN system may include n network nodes, where n is an integer greater than 1. Among them, the SDWAN system may be implemented based on an Internet of Things system, a vehicle-to-everything system, or a smart home system.
[0036] In specific implementation, each network node can be regarded as an electronic device, and the data set to be shared can be shared from one network node of the SDWAN system to other network nodes. Specifically, the data set to be shared and the memory size of the data set to be shared can be obtained. The data set to be shared includes multiple data, and the data set to be shared and the memory size of the data set to be shared reflect the data sharing requirements to a certain extent.
[0037] 102. Determine the security parameters of the n network nodes to obtain n security parameters.
[0038] Among them, the security parameter of a network node can be understood to include any relevant parameter for evaluating the security of the network node. The security parameter of a network node may include at least one of the following: protocol parameter, hardware parameter, software parameter, security software parameter, etc., which are not limited herein.
[0039] In specific implementation, the security parameter of each network node among the n network nodes can be determined to obtain n security parameters.
[0040] Optionally, after obtaining the dataset to be shared and the memory size of the dataset to be shared in step 102, the following steps may further be included:
[0041] Extract keywords from the dataset to be shared to obtain target keywords;
[0042] When a preset keyword exists in the target keywords, execute the step of determining the security parameters of the n network nodes to obtain n security parameters;
[0043] When the preset keyword does not exist in the target keywords, determine a first network node corresponding to the memory size;
[0044] Share the dataset to be shared to the first network node.
[0045] Among them, the preset keyword can be set in advance or be the system default.
[0046] In specific implementation, keywords can be extracted from the dataset to be shared to obtain target keywords. When a preset keyword exists in the target keywords, it indicates that there is data that requires security consideration. Furthermore, step 102 can be executed, which helps to improve the intelligence of distributed data sharing for SDWAN subsequently.
[0047] Among them, the number of the first network nodes can correspond to the memory size, that is, different memory sizes correspond to different numbers of shared nodes. The first network node can be a network node with the same number of any shared nodes among the n network nodes.
[0048] Correspondingly, when the preset keyword does not exist in the target keywords, it indicates that there is no data that requires security consideration. Determine the first network node corresponding to the memory size, and only need to consider the network nodes with the same number of shared nodes corresponding to the memory size, and then share the dataset to be shared to the first network node. In this way, it can ensure that SDWAN improves the flexibility of distributed data sharing.
[0049] 103. Determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values.
[0050] In a specific implementation, each of the n security parameters can be used to evaluate the security of a network node, obtaining n security evaluation values. For example, a mapping relationship between preset security parameters and security evaluation values can be pre-stored. Furthermore, the corresponding security evaluation value can be determined based on this mapping relationship. For example, when the security parameter includes 1 security parameter, the corresponding security evaluation value can be directly determined based on the mapping relationship between the preset security parameter and the security evaluation value. When the security parameter includes multiple security parameters, the security evaluation value corresponding to each security parameter can be determined based on the mapping relationship between the preset security parameter and the security evaluation value, and these security evaluation values are weighted and calculated to obtain the final security evaluation value.
[0051] 104. Determine the number of shared nodes m corresponding to the memory size; m is a positive integer less than or equal to n.
[0052] In a specific implementation, a mapping relationship between a preset memory size and the number of shared nodes can be pre-stored. Furthermore, the number of shared nodes corresponding to the corresponding memory size can be determined based on this mapping relationship. Specifically, the number of shared nodes m corresponding to the memory size of the data set to be shared can be determined, where m is a positive integer less than or equal to n.
[0053] 105. Select the largest m security evaluation values from the n security evaluation values, and obtain the network nodes corresponding to the m security evaluation values, obtaining m network nodes.
[0054] In the embodiments of the present application, the largest m security evaluation values can be selected from the n security evaluation values, and the network nodes corresponding to the m security evaluation values can be obtained, obtaining m network nodes, that is, some network nodes with the highest security can be selected for data sharing, thereby ensuring data sharing security.
[0055] 106. Divide the multiple data into m data sets; each data set corresponds to a network node index, and each data in each data set corresponds to a data position index of the data set to be shared.
[0056] In the embodiments of the present application, multiple data can be divided into m data sets, each data set corresponds to a network node index, and each data in each data set corresponds to a data position index of the data set to be shared. In this way, the data set to be shared can be distributed and shared to multiple network nodes, ensuring data sharing security.
[0057] Among them, the network node index is used to identify the network node, and the data position index is used to identify the position or storage address of the data in the data set to be shared.
[0058] Optionally, step 106 above, dividing the multiple data into m data sets may include the following steps:
[0059] Determine the node carrying capacity values of the m network nodes to obtain m node carrying capacity values;
[0060] Determine the data carrying percentages of the m network nodes according to the m node carrying capacity values to obtain m data carrying percentages; the sum of the m data carrying percentages is 1;
[0061] Obtain the data attribute information of each data in the multiple data;
[0062] Determine the importance evaluation values of the multiple data according to the data attribute information of each data to obtain multiple importance evaluation values;
[0063] Sort the multiple data in descending order of the importance evaluation values according to the multiple importance evaluation values to obtain the sorted multiple data;
[0064] Divide the sorted multiple data into the m data sets according to the m security evaluation values and the m data carrying percentages.
[0065] In a specific implementation, the node carrying capacity values of m network nodes can be determined to obtain m node carrying capacity values, and then the data carrying percentages of the m network nodes can be determined according to the m node carrying capacity values to obtain m data carrying percentages. The sum of the m data carrying percentages is 1. The total sum of the m node carrying capacity values can be calculated, and then the ratio between each node carrying capacity value in the m node carrying capacity values and the total sum can be determined to obtain m ratios. These m ratios are the m data carrying percentages.
[0066] Furthermore, the data attribute information of each data in the multiple data can be obtained. The data attribute information may include at least one of the following: data type, data source, data structure, data format, data keyword, etc., which is not limited here.
[0067] Then, the mapping relationship between the preset data attribute information and the importance evaluation value can be pre-stored. Furthermore, based on this mapping relationship, the importance evaluation value corresponding to each data in the multiple data can be determined to obtain multiple importance evaluation values. Then, the multiple data can be sorted in descending order of the importance evaluation values according to the multiple importance evaluation values to obtain the sorted multiple data. In this way, the data can be sorted according to the principle of high importance priority.
[0068] Further, multiple sorted data can be divided into m data sets according to m security evaluation values and m data carrying percentages. The m security evaluation values correspond to m network nodes, and the m data carrying percentages are deeply related to the carrying capacities of the m network nodes. In this way, based on the principle of high priority of importance and the carrying capacities of network nodes, the data can be divided into m data sets, so that the divided data sets are related to the security and the carrying capacities of network nodes, which helps to ensure subsequent synchronous distributed secure data sharing.
[0069] 107. Generate an index list according to the network node indexes and related data position indexes of the m data sets.
[0070] In the embodiments of the present application, an index list can be generated according to the network node indexes and related data position indexes of the m data sets. The index list can be used to quickly restore the data set to be shared from the m network nodes after the sharing of the data set to be shared is completed.
[0071] 108. Share the m data sets to the m network nodes respectively and save the index list.
[0072] In the embodiments of the present application, the m data sets can be shared to the m network nodes respectively, and the index list is saved, so that the data set to be shared can be quickly restored from the m network nodes after the sharing of the data set to be shared is completed.
[0073] Among them, the index list can be saved in a specified device in the SDWAN system, and the specified device can include a cloud server or an edge server.
[0074] In specific implementation, m processes can be used to share the m data sets to the m network nodes respectively, or m threads can also be used to share the m data sets to the m network nodes respectively. In this way, synchronous distributed secure data sharing can be achieved.
[0075] Optionally, in step 108 above, sharing the m data sets to the m network nodes respectively can be implemented in the following manner:
[0076] Determine the average value of the importance evaluation values of all data in the first data set to obtain a first average value; the first data set is any one of the m data sets;
[0077] Determine the reference security evaluation value corresponding to the first average value;
[0078] Obtain the first security evaluation value of the target network node corresponding to the first data set;
[0079] When the reference security evaluation value is greater than the first security evaluation value, encrypt the first data set according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set;
[0080] Share the encrypted first data set to the target network node;
[0081] When the first security evaluation value is less than or equal to the first security evaluation value, directly share the first data set to the target network node.
[0082] In a specific implementation, taking the first data set as an example, the first data set is any one of the m data sets. The average value of the importance evaluation values of all the data in the first data set can be determined to obtain the first average value. That is, the sum of the importance evaluation values of all the data in the first data set is calculated, and then this sum is divided by the number of data in the first data set (i.e., the number of importance evaluation values corresponding to the first data set) to obtain the first average value. The first average value reflects the security requirements of the data.
[0083] Of course, the mapping relationship between the preset average value and the security evaluation value can also be stored in advance. Furthermore, the reference security evaluation value corresponding to the first average value can be determined based on this mapping relationship. In this way, the importance and security can be unified, which is convenient for comparing the differences between the security requirements of the data and the security performance of the network node.
[0084] Next, the first security evaluation value of the target network node corresponding to the first data set can be obtained. When the reference security evaluation value is greater than the first security evaluation value, the security requirement of the data is higher than the security performance of the network node. Furthermore, the first data set can be encrypted according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set, and then the encrypted first data set is shared to the target network node. Thus, in the process of data sharing, encryption can be used to make up for the security performance of the network node, further ensuring the security of data sharing.
[0085] Correspondingly, when the first security evaluation value is less than or equal to the first security evaluation value, it means that the security requirement of the data is not higher than the security performance of the network node, that is, the security performance of the network node can already meet the security requirement of data sharing. Then, the data to be shared does not need to be encrypted, but the first data set is directly shared to the target network node. Thus, while ensuring the security of data sharing, the flexibility of data sharing can also be guaranteed.
[0086] Optionally, for the above step of encrypting the first data set according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set, it can be implemented in the following manner:
[0087] Determine a first difference between the reference security evaluation value and the first security evaluation value;
[0088] Determine a first encryption algorithm corresponding to the first security evaluation value;
[0089] Obtain an algorithm control parameter set corresponding to the first encryption algorithm, where the algorithm control parameter set includes multiple algorithm control parameters, and each algorithm control parameter corresponds to a difference;
[0090] Determine the absolute value of the difference between the first difference and the difference corresponding to each algorithm control parameter, obtaining multiple absolute values;
[0091] Select the minimum value among the multiple absolute values, and determine a target algorithm control parameter according to the minimum value;
[0092] Encrypt the first data set according to the target algorithm control parameter and the first encryption algorithm to obtain the encrypted first data set.
[0093] In specific implementation, a first difference between the reference security evaluation value and the first security evaluation value can be determined, that is, the first difference = reference security evaluation value - first security evaluation value. A mapping relationship between a preset security evaluation value and an encryption algorithm can also be pre-stored. Furthermore, a first encryption algorithm corresponding to the first security evaluation value can be determined based on this mapping relationship. In this way, an encryption algorithm corresponding to the security performance of the network node can be selected.
[0094] Next, obtain the algorithm control parameter set corresponding to the first encryption algorithm. This algorithm control parameter set includes multiple algorithm control parameters, and each algorithm control parameter corresponds to a difference. The algorithm control parameter is used to control the algorithm effect of the first encryption algorithm, and the algorithm effect can include at least one of the following: encryption complexity, encryption duration, encryption method, etc., which are not limited here.
[0095] Correspondingly, the absolute value of the difference between the first difference and the difference corresponding to each algorithm control parameter can be determined, obtaining multiple absolute values. Then, select the minimum value among the multiple absolute values, and determine the target algorithm control parameter according to the minimum value. For example, the algorithm control parameter corresponding to the minimum value can be selected as the target algorithm control parameter. Finally, the first data set can be encrypted according to the target algorithm control parameter and the first encryption algorithm to obtain the encrypted first data set. In this way, not only can an encryption algorithm corresponding to the security performance of the network node be configured, but also the corresponding algorithm control parameters can be dynamically adapted based on the difference between the security requirements of the data and the security performance of the network node, so that the final encryption effect not only meets the security requirements of the data but also is deeply adapted to the security performance of the network node, thereby ensuring data sharing security.
[0096] Of course, it is also possible to determine the decryption algorithm and algorithm control parameters corresponding to the target algorithm control parameters and the first encryption algorithm, and then save the decryption algorithm and algorithm control parameters in the server. Only specified users can obtain the decryption algorithm and algorithm control parameters from the server, thereby ensuring the security of data sharing.
[0097] Optionally, for the above steps, determining the target algorithm control parameters according to the minimum value can be implemented in the following manner:
[0098] Obtain the reference algorithm control parameters corresponding to the minimum value;
[0099] Encrypt the first data set according to the reference algorithm control parameters and the first encryption algorithm to obtain a reference data set;
[0100] Estimate the first data transmission duration of the first data set;
[0101] Estimate the second data transmission duration of the reference data set;
[0102] Determine the first deviation degree between the second data transmission duration and the first data transmission duration;
[0103] Determine the first feedback fine-tuning parameter corresponding to the first deviation degree;
[0104] Perform feedback fine-tuning on the reference algorithm control parameters according to the first feedback fine-tuning parameter to obtain the target algorithm control parameters.
[0105] In specific implementation, it is possible to obtain the algorithm control parameters corresponding to the minimum value to obtain the reference algorithm control parameters. Then, according to the reference algorithm control parameters and the first encryption algorithm, encrypt the first data set to obtain a reference data set. Next, estimate the first data transmission duration of the first data set and the second data transmission duration of the reference data set. Then, determine the first deviation degree between the second data transmission duration and the first data transmission duration. The first deviation degree = (second data transmission duration - first transmission duration) / first transmission duration. The first deviation degree not only reflects the degree of deviation but also the direction of deviation.
[0106] Next, the mapping relationship between the preset deviation degree and the feedback fine-tuning parameter can be pre-stored. Furthermore, the first feedback fine-tuning parameter corresponding to the first deviation degree can be determined based on this mapping relationship. Finally, the reference algorithm control parameter can be feedback fine-tuned according to the first feedback fine-tuning parameter to obtain the target algorithm control parameter, that is, the target algorithm control parameter = (1 + the first feedback fine-tuning parameter) * the reference algorithm control parameter. In this way, not only can the corresponding algorithm control parameter be dynamically adapted based on the difference between the security requirements of the data and the security performance of the network node, but also the algorithm control parameter can be dynamically feedback adjusted based on the data transmission performance difference brought by introducing the encryption algorithm and the algorithm control parameter, so that the final encryption effect not only meets the security requirements of the data, but also is deeply adapted to the security performance of the network node and the data transmission performance difference before and after sharing. Thus, the data sharing security can be guaranteed.
[0107] It can be seen that the control method for distributed dataset security sharing based on SDWAN described in the embodiments of the present application is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. The dataset to be shared and the memory size of the dataset to be shared are obtained. The dataset to be shared includes multiple data. The security parameters of the n network nodes are determined to obtain n security parameters. The security evaluation values of the n network nodes are determined according to the n security parameters to obtain n security evaluation values. The number of shared nodes m corresponding to the memory size is determined; m is a positive integer less than or equal to n. The largest m security evaluation values are selected from the n security evaluation values, and the network nodes corresponding to the m security evaluation values are obtained to get m network nodes. The multiple data are divided into m datasets; each dataset corresponds to a network node index, and each data in each dataset corresponds to a data position index of the dataset to be shared. An index list is generated according to the network node indexes and the relevant data position indexes of the m datasets. The m datasets are respectively shared to the m network nodes, and the index list is saved. The corresponding number of shared nodes can be determined based on the memory size of the dataset to be shared, and an equal number of the safest network nodes can be selected based on the number of shared nodes. The dataset to be shared is divided into datasets equal in number to the number of shared nodes, and an index list is generated based on the network node indexes of the datasets and the data position indexes of the data. Furthermore, the distributed security sharing of the dataset to be shared is realized, and after the dataset to be shared is shared, the dataset to be shared is quickly restored from the m network nodes. In this way, the intelligence of distributed data sharing is improved for SDWAN.
[0108] Consistent with the above embodiments, please refer to Figure 3 , Figure 3It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As shown in the figure, the electronic device includes a processor, a memory, a communication interface, and one or more programs. Among them, the above one or more programs are stored in the above memory and are configured to be executed by the above processor. In the embodiment of the present application, it is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. The above program includes instructions for performing the following steps:
[0109] Obtain the data set to be shared and the memory size of the data set to be shared. The data set to be shared includes multiple data;
[0110] Determine the security parameters of the n network nodes to obtain n security parameters;
[0111] Determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values;
[0112] Determine the number of sharing nodes m corresponding to the memory size; m is a positive integer less than or equal to n;
[0113] Select the largest m security evaluation values from the n security evaluation values, and obtain the network nodes corresponding to the m security evaluation values to obtain m network nodes;
[0114] Divide the multiple data into m data sets; each data set corresponds to a network node index, and each data in each data set corresponds to a data position index of the data set to be shared;
[0115] Generate an index list according to the network node indexes and relevant data position indexes of the m data sets;
[0116] Share the m data sets to the m network nodes respectively, and save the index list.
[0117] Optionally, in terms of dividing the multiple data into m data sets, the above program includes instructions for performing the following steps:
[0118] Determine the node bearing capacity values of the m network nodes to obtain m node bearing capacity values;
[0119] Determine the bearing data percentages of the m network nodes according to the m node bearing capacity values to obtain m bearing data percentages; the sum of the m bearing data percentages is 1;
[0120] Obtain the data attribute information of each data in the multiple data;
[0121] Determine the importance evaluation values of the multiple data according to the data attribute information of each data, and obtain multiple importance evaluation values;
[0122] Sort the multiple data in descending order of the importance evaluation values according to the multiple importance evaluation values, and obtain the sorted multiple data;
[0123] Divide the sorted multiple data into the m data sets according to the m security evaluation values and the m data bearing percentages.
[0124] Optionally, in terms of sharing the m data sets to the m network nodes respectively, the above program includes instructions for performing the following steps:
[0125] Determine the mean value of the importance evaluation values of all the data in the first data set, and obtain the first mean value; the first data set is any one of the m data sets;
[0126] Determine the reference security evaluation value corresponding to the first mean value;
[0127] Obtain the first security evaluation value of the target network node corresponding to the first data set;
[0128] When the reference security evaluation value is greater than the first security evaluation value, encrypt the first data set according to the reference security evaluation value and the first security evaluation value, and obtain the encrypted first data set;
[0129] Share the encrypted first data set to the target network node;
[0130] When the first security evaluation value is less than or equal to the first security evaluation value, directly share the first data set to the target network node.
[0131] Optionally, in terms of encrypting the first data set according to the reference security evaluation value and the first security evaluation value to obtain the encrypted first data set, the above program includes instructions for performing the following steps:
[0132] Determine the first difference between the reference security evaluation value and the first security evaluation value;
[0133] Determine the first encryption algorithm corresponding to the first security evaluation value;
[0134] Obtain the algorithm control parameter set corresponding to the first encryption algorithm, and the algorithm control parameter set includes multiple algorithm control parameters, and each algorithm control parameter corresponds to a difference;
[0135] Determine the absolute value of the difference between the first difference and the differences corresponding to each algorithm control parameter, obtaining a plurality of absolute values;
[0136] Select the minimum value among the plurality of absolute values, and determine the target algorithm control parameter according to the minimum value;
[0137] Encrypt the first data set according to the target algorithm control parameter and the first encryption algorithm to obtain the encrypted first data set.
[0138] Optionally, after obtaining the data set to be shared and the memory size of the data set to be shared, the above program further includes instructions for performing the following steps:
[0139] Extract keywords from the data set to be shared to obtain target keywords;
[0140] When a preset keyword exists in the target keywords, execute the step of determining the security parameters of the n network nodes to obtain n security parameters;
[0141] When the preset keyword does not exist in the target keywords, determine the first network node corresponding to the memory size;
[0142] Share the data set to be shared to the first network node.
[0143] It can be seen that the electronic device described in the embodiments of the present application is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. The method includes obtaining a dataset to be shared and the memory size of the dataset to be shared. The dataset to be shared includes multiple data. Determine the security parameters of the n network nodes to obtain n security parameters. Determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values. Determine the number of shared nodes m corresponding to the memory size; m is a positive integer less than or equal to n. Select the largest m security evaluation values from the n security evaluation values, and obtain the network nodes corresponding to the m security evaluation values to obtain m network nodes. Divide the multiple data into m datasets; each dataset corresponds to a network node index, and each data in each dataset corresponds to a data position index of the dataset to be shared. Generate an index list according to the network node indexes and relevant data position indexes of the m datasets. Share the m datasets to the m network nodes respectively, and save the index list. It is possible to determine the corresponding number of shared nodes based on the memory size of the dataset to be shared, and select an equal number of the safest network nodes based on the number of shared nodes. Divide the dataset to be shared into datasets equal in number to the number of shared nodes, and generate an index list based on the network node indexes of the datasets and the data position indexes of the data. Furthermore, the dataset to be shared is realized for distributed and secure sharing, and after the dataset to be shared is shared, the dataset to be shared is quickly restored from the m network nodes. In this way, the intelligence of distributed data sharing is improved for SDWAN.
[0144] Figure 4 FIG. 400 is a functional unit composition block diagram of a control system 400 for secure sharing of distributed datasets based on SDWAN according to an embodiment of the present application. The control system 400 for secure sharing of distributed datasets based on SDWAN is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. The control system 400 for secure sharing of distributed datasets based on SDWAN includes: an obtaining unit 401, a determining unit 402, a dividing unit 403, a generating unit 404, and a sharing unit 405. Among them,
[0145] The obtaining unit 401 is configured to obtain a dataset to be shared and the memory size of the dataset to be shared, where the dataset to be shared includes multiple data;
[0146] The determining unit 402 is configured to determine the security parameters of the n network nodes to obtain n security parameters; determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values; determine the number of shared nodes m corresponding to the memory size; m is a positive integer less than or equal to n;
[0147] The obtaining unit 401 is further configured to select the largest m security evaluation values from the n security evaluation values, and obtain the network nodes corresponding to the m security evaluation values, so as to obtain m network nodes;
[0148] The partitioning unit 403 is configured to partition the multiple pieces of data into m data sets; each data set corresponds to a network node index, and each piece of data in each data set corresponds to a data position index of the data set to be shared;
[0149] The generating unit 404 is configured to generate an index list according to the network node indexes and relevant data position indexes of the m data sets;
[0150] The sharing unit 405 is configured to separately share the m data sets to the m network nodes and save the index list.
[0151] Optionally, in terms of partitioning the multiple pieces of data into m data sets, the partitioning unit 403 is specifically configured to:
[0152] Determine the node carrying capacity values of the m network nodes to obtain m node carrying capacity values;
[0153] Determine the data carrying percentages of the m network nodes according to the m node carrying capacity values to obtain m data carrying percentages; the sum of the m data carrying percentages is 1;
[0154] Obtain the data attribute information of each piece of data in the multiple pieces of data;
[0155] Determine the importance evaluation values of the multiple pieces of data according to the data attribute information of each piece of data to obtain multiple importance evaluation values;
[0156] Sort the multiple pieces of data in descending order of the importance evaluation values according to the multiple importance evaluation values to obtain the sorted multiple pieces of data;
[0157] Partition the sorted multiple pieces of data into the m data sets according to the m security evaluation values and the m data carrying percentages.
[0158] Optionally, in terms of separately sharing the m data sets to the m network nodes, the sharing unit 405 is specifically configured to:
[0159] Determine the average value of the importance evaluation values of all the data in the first data set to obtain a first average value; the first data set is any one of the m data sets;
[0160] Determine the reference security evaluation value corresponding to the first average value;
[0161] Obtain the first security evaluation value of the target network node corresponding to the first data set;
[0162] When the reference security evaluation value is greater than the first security evaluation value, encrypt the first data set according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set;
[0163] Share the encrypted first data set to the target network node;
[0164] When the first security evaluation value is less than or equal to the first security evaluation value, directly share the first data set to the target network node.
[0165] Optionally, in terms of encrypting the first data set according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set, the sharing unit 405 is specifically used for:
[0166] Determine the first difference between the reference security evaluation value and the first security evaluation value;
[0167] Determine the first encryption algorithm corresponding to the first security evaluation value;
[0168] Obtain the algorithm control parameter set corresponding to the first encryption algorithm, where the algorithm control parameter set includes multiple algorithm control parameters, and each algorithm control parameter corresponds to a difference;
[0169] Determine the absolute value of the difference between the first difference and the difference corresponding to each algorithm control parameter to obtain multiple absolute values;
[0170] Select the minimum value among the multiple absolute values, and determine the target algorithm control parameter according to the minimum value;
[0171] Encrypt the first data set according to the target algorithm control parameter and the first encryption algorithm to obtain the encrypted first data set.
[0172] Optionally, after obtaining the data set to be shared and the memory size of the data set to be shared, the control system 400 for secure sharing of distributed data sets based on SDWAN is further specifically used for:
[0173] Extract keywords from the data set to be shared to obtain target keywords;
[0174] When a preset keyword exists in the target keywords, execute the step of determining the security parameters of the n network nodes to obtain n security parameters;
[0175] When the preset keyword does not exist in the target keyword, determine a first network node corresponding to the memory size;
[0176] Share the to-be-shared data set to the first network node.
[0177] It can be seen that the control system for secure sharing of distributed data sets based on SDWAN described in the embodiments of the present application is applied to an SDWAN system. The SDWAN system includes n network nodes, where n is an integer greater than 1. Obtain a to-be-shared data set and the memory size of the to-be-shared data set. The to-be-shared data set includes multiple data. Determine the security parameters of the n network nodes to obtain n security parameters. Determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values. Determine the number of sharing nodes m corresponding to the memory size; m is a positive integer less than or equal to n. Select the largest m security evaluation values from the n security evaluation values, and obtain the network nodes corresponding to the m security evaluation values to obtain m network nodes. Divide the multiple data into m data sets; each data set corresponds to a network node index, and each data in each data set corresponds to a data position index of the to-be-shared data set. Generate an index list according to the network node indexes and relevant data position indexes of the m data sets. Share the m data sets to the m network nodes respectively and save the index list. The corresponding number of sharing nodes can be determined based on the memory size of the to-be-shared data set, and an equal number of the safest network nodes can be selected based on the number of sharing nodes. Divide the to-be-shared data set into data sets equal in number to the number of sharing nodes, and generate an index list based on the network node indexes of the data sets and the data position indexes of the data. Furthermore, the to-be-shared data set is securely shared in a distributed manner, and after the to-be-shared data set is shared, the to-be-shared data set can be restored quickly from the m network nodes. In this way, the intelligence of distributed data sharing is improved for SDWAN.
[0178] It can be understood that the functions of the program modules of the control system for secure sharing of distributed data sets based on SDWAN in this embodiment can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can refer to the relevant descriptions of the above method embodiments and will not be elaborated here.
[0179] The embodiments of the present application further provide a computer storage medium. The computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute some or all of the steps of any method recorded in the above method embodiments. The above computer includes an electronic device.
[0180] The embodiments of the present application also provide a computer program product. The computer program product includes a non-transitory computer-readable storage medium storing a computer program. The computer program is operable to cause a computer to execute some or all of the steps of any one of the methods described in the foregoing method embodiments. The computer program product may be a software installation package, and the computer includes an electronic device.
[0181] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, some steps may be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0182] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0183] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.
[0184] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0185] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0186] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on such understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the above methods in various embodiments of this application. The aforementioned memory includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), external hard drives, magnetic disks, or optical discs.
[0187] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory, and the memory can include: flash drives, read-only memories (English: Read-Only Memory, abbreviated: ROM), random access memories (English: Random Access Memory, abbreviated: RAM), magnetic disks, or optical discs, etc.
[0188] The above has introduced the embodiments of this application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A control method for secure sharing of distributed data sets based on SDWAN, characterized in that: Applied to a SDWAN system, the SDWAN system includes n network nodes, where n is an integer greater than 1, and the method includes: Acquire a data set to be shared and a memory size of the data set to be shared, wherein the data set to be shared includes a plurality of data; Determining security parameters of the n network nodes to obtain n security parameters; Determining security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values; Determine the number m of shared nodes corresponding to the memory size; m is a positive integer less than or equal to n; Selecting the largest m security evaluation values from the n security evaluation values, and obtaining network nodes corresponding to the m security evaluation values to obtain m network nodes; Divide the multiple data into m data sets; each data set corresponds to a network node index, and each data in each data set corresponds to a data location index of the data set to be shared; Generate an index list according to the network node indexes of the m data sets and the related data location indexes; The m data sets are shared to the m network nodes respectively, and the index list is saved.
2. The method according to claim 1, characterized in that The dividing the plurality of data into m data sets comprises: Determining node carrying capacity values of the m network nodes to obtain m node carrying capacity values; Determine the data carrying percentages of the m network nodes according to the m node carrying capacity values, and obtain m data carrying percentages; the sum of the m data carrying percentages is 1; Acquire data attribute information of each data among the plurality of data; Determining importance evaluation values of the plurality of data according to the data attribute information of each data to obtain a plurality of importance evaluation values; According to the plurality of importance evaluation values, the plurality of data are sorted from large to small according to the importance evaluation values to obtain a plurality of sorted data; The sorted multiple data are divided into the m data sets according to the m security evaluation values and the m data-carrying percentages.
3. The method according to claim 2, characterized in that The sharing of the m data sets to the m network nodes respectively includes: Determine the average importance evaluation value of all data in a first data set to obtain a first average; the first data set is any data set among the m data sets; Determining a reference safety evaluation value corresponding to the first mean; Obtaining a first security evaluation value of a target network node corresponding to the first data set; When the reference security evaluation value is greater than the first security evaluation value, encrypting the first data set according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set; Sharing the encrypted first data set to the target network node; When the first security evaluation value is less than or equal to the first security evaluation value, the first data set is directly shared to the target network node.
4. The method according to claim 3, characterized in that The step of encrypting the first data set according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set includes: determining a first difference between the reference safety rating value and the first safety rating value; Determining a first encryption algorithm corresponding to the first security evaluation value; Obtain an algorithm control parameter set corresponding to the first encryption algorithm, the algorithm control parameter set including multiple algorithm control parameters, each algorithm control parameter corresponding to a difference value; determining an absolute value of a difference between the first difference and a difference corresponding to each algorithm control parameter to obtain a plurality of absolute values; Selecting a minimum value among the multiple absolute values, and determining a target algorithm control parameter according to the minimum value; The first data set is encrypted according to the target algorithm control parameter and the first encryption algorithm to obtain the encrypted first data set.
5. The method according to any one of claims 1 to 4, characterized in that: After obtaining the data set to be shared and the memory size of the data set to be shared, the method further includes: Extracting keywords from the data set to be shared to obtain target keywords; When there is a preset keyword in the target keyword, executing the step of determining the security parameters of the n network nodes to obtain n security parameters; When the preset keyword does not exist in the target keyword, determining a first network node corresponding to the memory size; The to-be-shared data set is shared to the first network node.
6. A control system for secure sharing of distributed data sets based on SDWAN, characterized in that: Applied to the SDWAN system, the SDWAN system includes n network nodes, n is an integer greater than 1, and the control system for secure sharing of distributed data sets based on the SDWAN includes: an acquisition unit, a determination unit, a division unit, a generation unit and a sharing unit, wherein: The acquisition unit is used to acquire a data set to be shared and a memory size of the data set to be shared, wherein the data set to be shared includes a plurality of data; The determining unit is used to determine the security parameters of the n network nodes to obtain n security parameters; determine the security evaluation values of the n network nodes according to the n security parameters to obtain n security evaluation values; determine the number m of shared nodes corresponding to the memory size; m is a positive integer less than or equal to n; The acquisition unit is further configured to select the largest m security evaluation values from the n security evaluation values, and acquire network nodes corresponding to the m security evaluation values to obtain m network nodes; The division unit is used to divide the multiple data into m data sets; each data set corresponds to a network node index, and each data in each data set corresponds to a data location index of the data set to be shared; The generating unit is used to generate an index list according to the network node indexes and related data location indexes of the m data sets; The sharing unit is used to share the m data sets to the m network nodes respectively and save the index list.
7. The control system for secure sharing of distributed data sets based on SDWAN according to claim 6, characterized in that: In the aspect of dividing the plurality of data into m data sets, the dividing unit is specifically used for: Determining node carrying capacity values of the m network nodes to obtain m node carrying capacity values; Determine the data carrying percentages of the m network nodes according to the m node carrying capacity values, and obtain m data carrying percentages; the sum of the m data carrying percentages is 1; Acquire data attribute information of each data among the plurality of data; Determining importance evaluation values of the plurality of data according to the data attribute information of each data to obtain a plurality of importance evaluation values; According to the plurality of importance evaluation values, the plurality of data are sorted from large to small according to the importance evaluation values to obtain a plurality of sorted data; The sorted multiple data are divided into the m data sets according to the m security evaluation values and the m data-carrying percentages.
8. The control system for secure sharing of distributed data sets based on SDWAN according to claim 7, characterized in that: In the aspect of sharing the m data sets to the m network nodes respectively, the sharing unit is specifically used for: Determine the average importance evaluation value of all data in a first data set to obtain a first average; the first data set is any data set among the m data sets; Determining a reference safety evaluation value corresponding to the first mean; Obtaining a first security evaluation value of a target network node corresponding to the first data set; When the reference security evaluation value is greater than the first security evaluation value, encrypting the first data set according to the reference security evaluation value and the first security evaluation value to obtain an encrypted first data set; Sharing the encrypted first data set to the target network node; When the first security evaluation value is less than or equal to the first security evaluation value, the first data set is directly shared to the target network node.
9. The control system for secure sharing of distributed data sets based on SDWAN according to claim 8, characterized in that: In the aspect of encrypting the first data set according to the reference security evaluation value and the first security evaluation value to obtain the encrypted first data set, the sharing unit is specifically used to: determining a first difference between the reference safety rating value and the first safety rating value; Determining a first encryption algorithm corresponding to the first security evaluation value; Obtain an algorithm control parameter set corresponding to the first encryption algorithm, the algorithm control parameter set including multiple algorithm control parameters, each algorithm control parameter corresponding to a difference value; determining an absolute value of a difference between the first difference and a difference corresponding to each algorithm control parameter to obtain a plurality of absolute values; Selecting a minimum value among the multiple absolute values, and determining a target algorithm control parameter according to the minimum value; The first data set is encrypted according to the target algorithm control parameter and the first encryption algorithm to obtain the encrypted first data set.
10. The control system for secure sharing of distributed data sets based on SDWAN according to any one of claims 6 to 9, characterized in that: After obtaining the data set to be shared and the memory size of the data set to be shared, the control system for secure sharing of distributed data sets based on SDWAN is further specifically used for: Extracting keywords from the data set to be shared to obtain target keywords; When there is a preset keyword in the target keyword, executing the step of determining the security parameters of the n network nodes to obtain n security parameters; When the preset keyword does not exist in the target keyword, determining a first network node corresponding to the memory size; The to-be-shared data set is shared to the first network node.