Data transmission system and method based on security identification and control
By using IP-free firewall units to perform random feature sampling and security level matching before data transmission in the Internet of Things environment, the problem of inefficiency of traditional firewall mechanisms is solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510675201.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-05-23
AI Technical Summary
The prior art cannot effectively perform security authentication before data transmission in the Internet of Things environment, resulting in inefficient data transmission. In addition, traditional firewall mechanisms cannot match the optimal transmission channel for different devices and data attributes, increasing hardware cost and delay.
Before data transmission begins, a pre-communication link is established with the data sending end using an IP-free firewall unit to conduct random feature sampling, determine the data interaction channel, and match different communication protocols and channels according to the security level to achieve forward data security authentication.
Improve data transmission efficiency, reduce hardware costs, ensure terminal security, and select the optimal transmission channel at different security levels, reducing delay and interruption.
Smart Images

Figure CN120342755A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security authentication and control, and particularly relates to a data transmission system and method based on security authentication and control, a computer-readable storage medium for implementing the method, a computer program product, and an electronic device. Background Art
[0002] With the rapid popularization of the Internet of Things, the concept of Internet of Everything (IoE) has been proposed. IoE connects various devices to the network through various communication technologies such as Wi-Fi, Bluetooth, Zigbee, 5G, etc.; with the help of sensors and actuators, it collects and processes data in the physical world and realizes remote control of devices; it uses cloud computing and edge computing technologies to store and analyze massive data to provide support for decision-making. The Internet of Everything improves the efficiency of production and life, creates new business models and employment opportunities, but also brings problems such as data security and privacy protection, device compatibility and interoperability.
[0003] Currently, most of the Internet of Things security protection measures are implemented through software, such as setting up software firewalls, dedicated line encryption transmission, etc. For this reason, the Chinese authorized invention patent "A Distributed Information Network Security Protection Method, System and Its Readable Storage Medium" (authorization announcement number CN116566682B) transfers the security rules of other IP-less hardware firewalls to the current IP-less hardware firewall on the basis of network pre-configuration, so that it plays a role in temporary security protection.
[0004] However, related technologies can only start security authentication and analysis when the data actually arrives, which affects the data transmission efficiency when the data stream is continuously generated; in addition, in the IoE environment, the types of devices and data attributes are diverse, and the required data transmission protocols and data transmission security control levels are also different. The firewall technology adopted by related technologies can only screen out whether the data has risks, and does not specifically match the optimal data transmission channel when there is no risk or the risk levels are different, which also reduces the data transmission efficiency; in addition, when there are multiple execution units (including data transmission devices, firewall units), how to implement different configurations and controls of centralized security access policies is also a technical problem to be solved. Summary of the Invention
[0005] In view of the above technical problems, the present invention provides a data transmission system and method based on security authentication and control in the IoE environment, a computer-readable storage medium for implementing the method, a computer program product, and an electronic device.
[0006] In the first aspect of the present invention, a data transmission system based on security authentication and control is proposed. The system includes at least one data sending end and at least one data receiving end;
[0007] The data receiving end is configured without an IP firewall unit;
[0008] When the data receiving end receives a data sending request, the IP firewall unit is turned on, enabling the IP firewall unit to establish a pre-communication link with the data sending end;
[0009] The IP firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link, and the sampling instruction is used to perform random feature sampling on the data set to be sent by the data sending end;
[0010] Based on the data sample features obtained from the random feature sampling, the IP firewall unit determines the current data interaction channel between the data receiving end and the data sending end;
[0011] Based on the current data interaction channel, the data sending end transmits data to the data receiving end.
[0012] The data sample features include first data sample features and second data sample features;
[0013] The first data sample features are obtained by the data sending end performing random feature sampling on the data set to be sent based on the sampling instruction;
[0014] The second data sample features are obtained by the IP firewall unit performing random feature sampling on the data set to be sent based on the sampling instruction.
[0015] In practical applications, the present invention can also be centrally managed based on a management center and communicate using a physical network interface.
[0016] Therefore, the data transmission system based on security authentication and control in the first aspect can also be implemented based on a distributed terminal firewall framework, and the system includes an execution unit group and a management center group;
[0017] The execution unit group includes multiple execution units, and each execution unit includes a networking and deployment module and an access control module;
[0018] The management center group includes a security operation and maintenance management module, a status monitoring management module, and a policy configuration management module;
[0019] The security operation and maintenance management module includes a traffic log unit, a traffic statistics unit, a traffic analysis unit, an alarm handling unit, and a report unit;
[0020] The state monitoring and management module includes a central operation state unit, an execution unit deployment state unit, an execution unit operation state unit, a terminal connection state management unit, and a terminal IP / Mac management unit;
[0021] The policy configuration and management module includes a policy management unit, a remote management unit, a batch management unit, a distribution management unit, and a dynamic port opening unit;
[0022] In practical applications, each protected terminal device (including the data sender / data receiver) is connected to the physical port of the switch device through each corresponding execution unit under the distributed terminal firewall framework, and then is centrally managed by the management center based on the distributed terminal firewall framework, while recording the test process.
[0023] In the second aspect of the present invention, a data transmission method based on security authentication and control is proposed. The method is applied to at least one data receiver, and the method includes the following steps:
[0024] When a data sending request is received, the IP-free firewall unit of the data receiver is enabled, so that the IP-free firewall unit establishes a pre-communication link with the data sender;
[0025] The IP-free firewall unit sends a sampling instruction to the data sender based on the pre-communication link. The sampling instruction is used to perform random feature sampling on the data set to be sent by the data sender;
[0026] Based on the data sample features obtained from the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiver and the data sender;
[0027] Based on the current data interaction channel, the data sender transmits data to the data receiver.
[0028] During the process of the data sender transmitting data to the data receiver based on the current data interaction channel, the IP-free firewall unit continuously sends sampling instructions to the data sender based on the pre-communication link to continuously perform random feature sampling on the data set to be sent by the data sender;
[0029] Based on the data sample features obtained from the continuous random feature sampling, the IP-free firewall unit determines whether to maintain the current data interaction channel between the data receiver and the data sender, or replace the current data interaction channel.
[0030] The IP-free firewall unit is pre-configured with multiple data interaction channels, and each data interaction channel corresponds to a different security evaluation level and communication protocol;
[0031] Based on the data sample features obtained by the IP-free firewall unit through the random feature sampling, after evaluating the security level of the data set to be sent by the data sending end and the applicable communication protocol, the current data interaction channel between the data receiving end and the data sending end is determined.
[0032] The IP-free firewall unit is a detachable IP-free hardware firewall unit.
[0033] In the third aspect of the present invention, a data transmission method based on security authentication and control in an IoE environment is proposed. The method is applied to at least one data sending end, and the method includes the following steps:
[0034] Determine at least one data receiving end and send a data transmission request to the data receiving end;
[0035] Perform random feature sampling on the first data set to be sent, and send the first data sample features obtained by the random feature sampling to the data receiving end;
[0036] Based on the data interaction channel called by the data receiving end, transmit the first data set to be sent to the data receiving end;
[0037] Moreover, while transmitting the first data set to be sent, prepare the second data set to be sent.
[0038] Wherein, the method further includes:
[0039] After sending the data transmission request to the data receiving end, a pre-communication link is established between the data receiving end and the data sending end. The data receiving end sends the random feature sampling instruction to the data sending end based on the pre-communication link, and the random feature sampling instruction is used to instruct the data sending end to perform random feature sampling on the first data set to be sent.
[0040] After sending the data transmission request to the data receiving end, a pre-communication link is established between the data receiving end and the data sending end. The data receiving end performs random feature sampling on the first data set to be sent based on the pre-communication link, and obtains the second data sample features;
[0041] The data receiving end determines the data interaction channel called by the data receiving end based on the first data sample features and the second data sample features.
[0042] In the fourth aspect of the present invention, a computer-readable storage medium is further provided for storing computer instructions. When the computer instructions run on an electronic device, the electronic device is enabled to execute all or part of the steps of the aforementioned data transmission method based on security authentication and control.
[0043] In the fifth aspect of the present invention, a computer device is further proposed. The computer device includes a processor and a memory. The memory is used to store instructions, and the processor is used to call the instructions in the memory, so that the computer device executes the data transmission method based on security authentication and control mentioned above.
[0044] In the sixth aspect of the present invention, a computer program product is further proposed. The product includes a computer program. When the computer program is executed, all or part of the steps of the data transmission method based on security authentication and control mentioned above are implemented.
[0045] In the technical solution of the present invention, in the IoE environment, when the data receiving end receives a data sending request, the IP-free firewall unit is enabled, so that the IP-free firewall unit establishes a pre-communication link with the data sending end; the IP-free firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link; based on the data sample features obtained by random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end; based on the current data interaction channel, the data sending end transmits data to the data receiving end. The present invention moves the data security authentication forward to before the start of data transmission, and matches different transmission channels according to different security authentication results, which can improve the data transmission efficiency while ensuring the security of the terminal.
[0046] The further advantages of the present invention will be further detailed in the specific embodiment part in combination with the accompanying drawings of the specification. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0048] Figure 1 is the scenario architecture diagram of the data transmission system based on security authentication and control according to an embodiment of the present invention;
[0049] Figure 2 is the main flow schematic diagram of the data transmission method based on security authentication and control according to an embodiment of the present invention;
[0050] Figure 3 is the main flow schematic diagram of the data transmission method based on security authentication and control according to another preferred embodiment of the present invention;
[0051] Figure 4It is a schematic diagram of the principle for determining the current data interaction channel between the data receiving end and the data sending end in the method embodiment of the present invention;
[0052] Figure 5 It is a schematic diagram of an embodiment of a product based on the technical solution of the present invention, which is centrally managed by a management center and communicates using physical network interfaces; Detailed implementation manners
[0053] In the detailed implementation manners of the present application, if the embodiments of the related technical solutions involve user-related data, when the embodiments of the present application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of the related data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0054] See Figure 1 , Figure 1 It is a scenario architecture diagram of a data transmission system based on security authentication and control according to an embodiment of the present invention.
[0055] In Figure 1 , multiple data receiving ends, multiple data sending ends, and multiple IP-less firewall unit modules are shown.
[0056] It can be understood that the concepts of the data receiving end and the data sending end are relative, that is, the data receiving end can also be the data sending end at the same time. In practical applications, especially in the IoE environment, the data receiving end and the data sending end can be any Internet of Things device that can generate data information and has the ability to send and receive data.
[0057] For a certain Internet of Things device, when it generates data information that needs to be sent out, it is called the "data sending end"; and when it is ready to receive the data information sent by another Internet of Things device, it is converted to the "data receiving end". Of course, for an Internet of Things device, "receiving data" and "sending data" can exist in a sequential order or can be carried out simultaneously. What the present invention focuses on is the data transmission process between a certain "data sending end" and a certain "data receiving end".
[0058] In various embodiments of the present invention, "data", "information", and "message" can all be used as the transmission objects between a certain "data sending end" and a certain "data receiving end", and their types include any combination of plain text, hyperlink, image, voice, video, operation instruction, etc. For the convenience of description, they are unified as "data".
[0059] In Figure 1In an embodiment, for each Internet of Things device, a detachable (pluggable), switchable (activated / dormant) IP-free firewall unit module can be configured for it. Preferably, the IP-free firewall unit is a detachable IP-free hardware firewall unit.
[0060] When a certain Internet of Things device is used as a data receiving end, its corresponding IP-free firewall unit module is turned on; when it is used as a data sending end, its corresponding IP-free firewall unit module is turned off (detached, dormant) to achieve an energy-saving effect.
[0061] When the data receiving end receives a data sending request, the IP-free firewall unit is turned on, so that the IP-free firewall unit establishes a pre-communication link with the data sending end;
[0062] The IP-free firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link, and the sampling instruction is used to perform random feature sampling on the data set to be sent by the data sending end;
[0063] Based on the data sample features obtained by the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end;
[0064] Based on the current data interaction channel, the data sending end transmits data to the data receiving end.
[0065] It can be seen that the present invention moves data security authentication forward to before the start of data transmission. Specifically, when the data receiving end receives a data sending request, the IP-free firewall unit is first turned on, so that the IP-free firewall unit establishes a pre-communication link with the data sending end;
[0066] The establishment of the "pre-communication link" is not for transmitting real data. At this time, for the data receiving end, since the security attributes of the data to be received are unknown, there is a certain system risk if the receiving channel is directly opened.
[0067] In the prior art, usually a firewall or a filtering module is placed in front, and the data to be received is first processed and intercepted by the firewall or the filtering module, and then received or rejected as the case may be. This can achieve a certain security effect in the general data transmission process.
[0068] However, in the IoE scenario, a large number of IoT devices generate data interconnection and interoperability after accessing the network through different protocols or interfaces, including Wi-Fi, Bluetooth, Zigbee, 5G, infrared, etc. By collecting multi-source data information, near-field or remote control of devices is achieved, as well as visual analysis of data. The data generated in most scenarios targets actual objects with physical meanings (any combination of plain text, hyperlinks, images, voice, video, operation instructions, etc.). These actual objects have very obvious and regular characteristics (such as time-series characteristics, periodic characteristics, data range change characteristics). If it is an operation instruction, there are corresponding characteristics, such as remote control operations, near-field communication operations, etc., and the corresponding instructions are pre-configured. A large number of IoT devices accessing the network itself constitute a security grid. Data sending and receiving should be in a continuous and uninterruptible normal state for most of the time.
[0069] In this scenario, the risks faced by data transmission mainly come from sudden network attacks, such as abnormal traffic injection, data attacks from devices outside the remote grid, and disturbances from abnormal near-field devices. If a firewall or a filtering module is still placed in front, and the data to be received is first processed and intercepted by the firewall or the filtering module, and then received or rejected according to the situation, the negative impacts brought include:
[0070] (1) Interrupt the normal IoE data transmission and sending, resulting in a large time delay in the control of grid devices in the IoT area, which is unacceptable in some application scenarios that require real-time performance or have a low tolerance for latency;
[0071] (2) For risk characteristics such as "abnormal traffic injection, data attacks from devices outside the remote grid, and disturbances from abnormal near-field devices", traditional firewall mechanisms may fail, and the filtering rules of the filtering module need to be pre-configured and cannot be updated in real time;
[0072] (3) An additional intermediate storage medium needs to be configured to temporarily receive the data to be filtered. If it is a simple "one-to-one" transmission, the additional hardware cost is acceptable (which can be recorded as O(1)); however, for N IoT devices in the IoE scenario, the additional hardware cost will increase sharply (that is
[0073] (4) After traditional firewalls and filtering mechanisms detect risk characteristics, they generally perform unified filtering processing and do not provide different levels of processing channels for different situations.
[0074] To address the above problems, the technical solution of the present invention is to first activate the IP-free firewall unit, so that the IP-free firewall unit establishes a pre-communication link with the data sender. Then, the IP-free firewall unit sends a random sampling instruction to the data sender based on the pre-communication link, and the sampling instruction is used to perform random feature sampling on the data set to be sent by the data sender.
[0075] As mentioned above, in the IoE scenario, the risks faced by data transmission mainly come from sudden network attacks, such as abnormal traffic injection, data attacks from remote off-grid devices, and disturbances from near-field abnormal devices. Although these risks are unpredictable, the risk characteristics must be hidden in the data set to be sent, and the hidden locations are random. At the same time, different from the existing technology where data is generated, sent, and detected simultaneously, in the embodiments of the present invention, the data sender must determine at least one data receiver after the data set to be sent is ready, and send a data transmission request to the data receiver. The data transmission request carries information such as the size of the data set to be sent, the generation time (time range), data format, data storage location, etc.
[0076] At this time, the data set to be sent is set to an unmodifiable (read-only) state. Therefore, if there is risk feature injection, it can only occur during the data generation stage and cannot escape (because the risk features have merged with the data set itself into an unmodifiable read-only state).
[0077] To detect whether there are risk features in the data set to be sent, based on the randomness of its injection, the IP-free firewall unit sends a random sampling instruction to the data sender based on the pre-communication link, and the sampling instruction is used to perform random feature sampling on the data set to be sent by the data sender.
[0078] Specifically, the random sampling instruction is implemented based on a random sampling function. The random sampling function determines multiple sampling positions and sampling ranges based on information such as the size of the data set to be sent, the generation time (time range), data format, data storage location, etc., so as to obtain multiple data sample features.
[0079] The data sample features include data itself features such as the integrity of the sampled data, the continuity of the data at adjacent sampling points, and the size of the unit data sampled. It can also include abnormal risk point features obtained by sampling, such as risk keywords, warning codes, and alarm data formats matched from the sampling range using regular expressions.
[0080] Of course, different sampling functions can obtain different sampling features, and those skilled in the art can preset different sampling functions based on different data to be transmitted.
[0081] Based on the data sample features obtained by the random feature sampling, the IP-free firewall unit can evaluate the security level of the data set to be sent by the data sender and the applicable communication protocol.
[0082] Preferably, the IP-free firewall unit is pre-configured with multiple data interaction channels, and each data interaction channel corresponds to a different security evaluation level and communication protocol.
[0083] For example, the security level can be pre-divided into low, medium, and high levels, or can be quantified into levels from 0 to 5. The applicable communication protocols include synchronous / asynchronous communication protocols, hypertext communication protocols, publish-subscribe protocols, application layer open source protocols, full-duplex communication protocols, etc.
[0084] Taking low, medium, and high as an example, when no risk features are found in the data sample features obtained by the random feature sampling, for example, multiple sampled data are all complete, continuous, and do not match risk keywords, warning codes, alarm data formats, etc., the security level of the data set to be sent by the data sender is evaluated as low;
[0085] When in the data sample features obtained by the random feature sampling, it is found that multiple sampled data are all complete and continuous, but risk keywords, warning codes, alarm data formats, etc. are matched at individual positions, the security level of the data set to be sent by the data sender is evaluated as medium;
[0086] When in the data sample features obtained by the random feature sampling, it is found that multiple sampled data are all incomplete and discontinuous (meaning that there are injections at different multiple positions), the security level of the data set to be sent by the data sender is evaluated as high.
[0087] When the security level is low, according to the device type of the data sender and the data generation method, application layer open source protocols, full-duplex communication protocols, etc. can be selected.
[0088] Preferably, the application layer open source protocol can be AMQP, which can ensure fast data transmission without delay; the full-duplex communication protocol can be a communication protocol based on WebSocket, which can perform full-duplex communication on a single TCP connection, overcoming the limitations of HTTP being stateless and one-way communication. It performs excellently in real-time interaction scenarios.
[0089] When the security level is low, if the HTTP status is stable, asynchronous communication protocols, hypertext communication protocols, etc. can also be selected.
[0090] When the security level is medium, the synchronous communication protocol is preferred. At this time, the data to be transmitted itself has certain risks. Therefore, the use of the synchronous communication protocol for transmission can ensure that after the data segment subset without security risks is successfully sent, the next data segment subset will be sent after receiving the confirmation response from the receiving end. In this way, the data transmission continuity is ensured as much as possible through the synchronous response, and the data segment subset with security risks can be identified in time and discarded (excluded from the data transmission process).
[0091] When the security level is high, a publish-subscribe protocol such as MQTT is preferred. For example, communication between smart home devices, such as smart bulbs and sensors, can use the MQTT protocol to transmit data.
[0092] Under the "publish-subscribe" protocol, the publisher is responsible for publishing (producing, sending) data, and the consumer is responsible for consuming (receiving) data. The consumer pre-registers the type of message data it is interested in and only responds to message data of these registered types.
[0093] By adopting the publish-subscribe protocol, even if there are risks in the data to be sent, these risk instructions are not registered (subscribed) by the subscriber (consumer). Therefore, the relevant instructions will not be executed and will not affect the security of the system or equipment. For those normal instructions, since they are pre-registered, they can also be executed normally without interrupting the normal transmission of the data flow.
[0094] After the non-IP firewall unit determines the current data interaction channel between the data receiving end and the data sending end, the data sending end can transmit data to the data receiving end based on the current data interaction channel.
[0095] That is to say, the present invention not only moves data security authentication forward to before data transmission begins, but also matches different transmission channels according to different security authentication results, thereby improving data transmission efficiency while ensuring terminal security.
[0096] Furthermore, the data sample features obtained by random feature sampling based on which the above security assessment is based can be obtained by the data sending end or the data receiving end.
[0097] Preferably, in order to avoid "pseudo-random" sampling when the data receiving end is hijacked, the random sampling process is performed jointly by the data sending end and the data receiving end to achieve random supervision.
[0098] Specifically, the data sample feature includes a first data sample feature and a second data sample feature;
[0099] The first data sample feature is obtained by the data sending end performing random feature sampling on the data set to be sent based on the sampling instruction;
[0100] The second data sample feature is obtained by the IP-free firewall unit performing random feature sampling on the dataset to be sent based on the sampling instruction.
[0101] At this time, the IP-free firewall unit evaluates the first security level and applicable first communication protocol of the dataset to be sent by the data sender based on the first data sample feature; and simultaneously evaluates the second security level and applicable second communication protocol of the dataset to be sent by the data sender based on the second data sample feature.
[0102] When there is a contradiction (inconsistency) between the first security level and the applicable first communication protocol, the second security level and the applicable second communication protocol are used, and the current data interaction channel between the data receiver and the data sender is determined.
[0103] In practical applications, the present invention can also be centrally managed based on a management center and communicate using a physical network interface.
[0104] Therefore, Figure 1 The data transmission system based on security authentication and control can also be implemented based on a distributed terminal firewall framework.
[0105] At this time, the system can implement a distributed firewall architecture for the execution unit networking configuration policy based on a centralized management mode.
[0106] Specifically, the above system further includes an execution unit group and a management center group; the execution unit group includes multiple execution units, and each execution unit includes a networking and deployment module and an access control module.
[0107] The management center group includes a security operation and maintenance management module, a status monitoring management module, and a policy configuration management module.
[0108] The security operation and maintenance management module includes a traffic log unit, a traffic statistics unit, a traffic analysis unit, an alarm handling unit, and a report unit.
[0109] The status monitoring management module includes a center operation status unit, an execution unit deployment status unit, an execution unit operation status unit, a terminal connection status management unit, and a terminal IP / Mac management unit.
[0110] The policy configuration management module includes a policy management unit, a remote management unit, a batch management unit, a distribution management unit, and a dynamic port opening unit.
[0111] In practical applications, after each protected terminal device (including the data sender / data receiver) is connected to the physical port of the switch device through each corresponding execution unit under the distributed terminal firewall framework, it is centrally managed by the management center based on the distributed terminal firewall framework. Meanwhile, the test process is recorded. A unified management center can be used to implement the control framework for protecting terminal devices under the distributed firewall framework of multiple execution units.
[0112] Next, the basic working principle of the product form formed by the present invention in practical applications will be specifically introduced.
[0113] In specific arrangements, the product form formed by the technical solution of the present invention mainly consists of a unified management center that controls multiple distributed IP-less firewall units.
[0114] The management center needs to implement network access control. The execution unit needs to form a network with the management center to accept the management of the management center, including implementing the policies issued by the management center, the access control policies issued, etc.
[0115] In a preferred embodiment, the management center can directly communicate with the IP-less execution unit (IP-less hardware firewall unit) to issue a deployment instruction. After intercepting the deployment instruction, the execution unit parses out the IP address feature of the management center from it; thus, the execution unit can establish a communication association with the management center based on the IP address feature, that is, directly maintain a connection with the management center.
[0116] Generally, the protected terminal device uses the DHCP network, resulting in its IP address being unable to be fixed and changing every day. If the IP address is used as the feature code, the matching of management objects cannot be achieved.
[0117] Therefore, as another preferred embodiment, when the management center issues relevant deployment policies to the protected terminal device, the MAC code of the terminal device is further used as the feature code to ensure that the management center can determine the identity of the protected terminal device, so as to continue to implement the relevant deployment policies for network access control.
[0118] Based on the embodiment of the relevant deployment policy for network access control, the security protection of relevant protected devices (including data senders / data receivers, execution units) can be effectively carried out.
[0119] As a more specific example, in the IoE environment, the protected related devices can be, for example, smart light poles equipped with cameras and their voice control devices. In the conventional environment during data transmission, these protected devices are in a "naked" state, posing a great security risk. Based on the control embodiment of the centralized management center of the present invention, the management center can issue corresponding network access control policies to the execution unit to perform security access control on it, thereby enhancing the security of the protected terminal devices.
[0120] On the basis of introducing the principle of the system embodiment, next Figures 2 - 5 different implementation manners of the method embodiment are introduced.
[0121] Figure 2 The main process schematic diagram of the data transmission method based on security authentication and control according to an embodiment of the present invention is shown.
[0122] Figure 2 From the perspective of the data receiving end, the method mainly includes the following steps:
[0123] When a data sending request is received, the IP-free firewall unit of the data receiving end is enabled, so that the IP-free firewall unit establishes a pre-communication link with the data sending end.
[0124] The IP-free firewall unit sends a sampling instruction to the data sending end based on the pre-communication link, and the sampling instruction is used to randomly sample the feature of the data set to be sent by the data sending end.
[0125] Based on the data sample features obtained by the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end.
[0126] Based on the current data interaction channel, the data sending end transmits data to the data receiving end.
[0127] Preferably, the IP-free firewall unit is pre-configured with multiple data interaction channels, and each data interaction channel corresponds to a different security evaluation level and communication protocol.
[0128] The IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end after evaluating the security level and applicable communication protocol of the data set to be sent by the data sending end based on the data sample features obtained by the random feature sampling.
[0129] When the security level is low, according to the device type and data generation method of the data sending end, application layer open source protocols, full-duplex communication protocols, etc. can be selected.
[0130] Preferably, the application layer open source protocol can be AMQP, which can ensure fast and non-delayed data transmission; the full-duplex communication protocol can be a communication protocol based on WebSocket, which can perform full-duplex communication on a single TCP connection, overcoming the limitations of HTTP being stateless and one-way communication. It performs excellently in real-time interaction scenarios.
[0131] When the security level is low, if the HTTP status is stable, asynchronous communication protocols, hypertext transfer protocols, etc. can also be selected.
[0132] When the security level is medium, a synchronous communication protocol is preferred. At this time, there are certain risks in the data to be transmitted itself. Therefore, when using a synchronous communication protocol for transmission, it can be ensured that after a subset of data segments without security risks is successfully sent and an acknowledgment response is received from the receiving end, the next subset of data segments is sent. In this way, the continuity of data transmission is ensured as much as possible through synchronous responses, and at the same time, subsets of data segments with security risks can be identified in a timely manner.
[0133] When the security level is high, a publish-subscribe protocol such as MQTT is preferred. For example, in the communication between smart home devices, devices such as smart bulbs and sensors can use the MQTT protocol to transmit data.
[0134] During the process of the data sender transmitting data to the data receiver based on the current data interaction channel, the IP-free firewall unit continuously sends sampling instructions to the data sender based on the pre-communication link to continuously perform random feature sampling on the data set to be sent by the data sender;
[0135] Based on the data sample features obtained from continuous random feature sampling, the IP-free firewall unit determines whether the data receiver and the data sender maintain the current data interaction channel or replace the current data interaction channel.
[0136] It can be seen that the data sender can determine at least one data receiver only after preparing the current data set to be sent each time, and send a data transmission request to the data receiver. The data transmission request carries information such as the size of the data set to be sent, the generation time (time range), data format, and data storage location.
[0137] Then, the data to be transmitted is sent based on the IP-free firewall unit; at the same time, the data sender continues to prepare the next data set to be sent to repeat the above process.
[0138] Specifically, Figure 3 The main process schematic diagram of the data transmission method based on security authentication and control showing another preferred embodiment of the present invention.
[0139] In Figure 3Taking the first data set and the second data set to be sent successively as an example, the relevant steps are implemented as follows ( Figure 3 The step numbers are omitted):
[0140] S1: The data sender prepares the first data set to be sent;
[0141] S2: The data sender sends a data transmission request to the data receiver;
[0142] S3: The data receiver activates the IP-free firewall unit, so that the IP-free firewall unit establishes a pre-communication link with the data sender;
[0143] S4: The IP-free firewall unit sends a sampling instruction to the data sender based on the pre-communication link;
[0144] S5: Randomly sample the features of the first data set to be sent based on the random sampling instruction to obtain data sample features;
[0145] S6: The IP-free firewall unit determines the current data interaction channel between the data receiver and the data sender based on the data sample features;
[0146] S7: Based on the current data interaction channel, while the data sender transmits data to the data receiver, the data sender prepares the second data set to be sent;
[0147] S8: The IP-free firewall unit sends a sampling instruction to the data sender based on the pre-communication link;
[0148] S9: Randomly sample the features of the second data set to be sent based on the random sampling instruction to obtain data sample features, and go to step S6.
[0149] It can be understood that the data sender will continuously generate the first data set, the second data set,..., the Nth data set. After each data set is generated, the sending process can refer to the foregoing steps, that is, the method can be a loop process for sequentially processing and transmitting the first data set, the second data set,..., the ith data set... The data interaction channel for each data set needs to be re-determined according to the data sample features of the current random sampling. The sampling function used for each re-sampling changes, and the sampling parameters are also dynamically updated (for example, the random sampling function determines multiple sampling positions and sampling ranges based on information such as the size, generation time (time range), data format, and data storage location of the data set to be sent) to avoid the "pseudo-random" phenomenon.
[0150] Figure 4 It is a schematic diagram of the principle for determining the current data interaction channel between the data receiver and the data sender in the method embodiment of the present invention.
[0151] Among them, the sampling process is further optimized, and the related methods include:
[0152] The IP-free firewall unit establishes a pre-communication link with the data sender;
[0153] The IP-free firewall unit sends a sampling instruction to the data sender based on the pre-communication link;
[0154] The data sender performs random feature sampling on the data set to be sent based on the sampling instruction to obtain the first data sample feature; the data receiver performs random feature sampling on the data set to be sent based on the sampling instruction to obtain the second data sample feature;
[0155] At this time, the IP-free firewall unit evaluates the first security level and the applicable first communication protocol of the data set to be sent by the data sender based on the first data sample feature; at the same time, it evaluates the second security level and the applicable second communication protocol of the data set to be sent by the data sender based on the second data sample feature;
[0156] When there is a contradiction (inconsistency) between the first security level and the applicable first communication protocol, the second security level and the applicable second communication protocol are used, and the current data interaction channel between the data receiver and the data sender is determined.
[0157] When the method embodiment is described from the perspective of the data sender, the specific implementation steps include:
[0158] Determine at least one data receiver and send a data transmission request to the data receiver;
[0159] Perform random feature sampling on the first data set to be sent and send the first data sample feature obtained by the random feature sampling to the data receiver;
[0160] Transmit the first data set to be sent to the data receiver based on the data interaction channel called by the data receiver;
[0161] Moreover, while transmitting the first data set to be sent, prepare the second data set to be sent.
[0162] After sending the data transmission request to the data receiver, the data receiver and the data sender establish a pre-communication link, and the data receiver sends the random feature sampling instruction to the data sender based on the pre-communication link, and the random feature sampling instruction is used to instruct the data sender to perform random feature sampling on the first data set to be sent.
[0163] The data receiving end performs random feature sampling on the first data set to be sent based on the pre-communication link, and obtains second data sample features;
[0164] The data receiving end determines the data interaction channel called by the data receiving end based on the first data sample features and the second data sample features.
[0165] In practical applications, the present invention needs to be centrally managed based on a management center and uses a physical network interface for communication. Figure 5 The figure shows a schematic diagram of a product embodiment that is centrally managed based on the technical solution of the present invention and uses a physical network interface for communication.
[0166] Among them, the management center centrally manages the multiple data receiving ends, multiple data sending ends, and multiple IP-free firewall unit modules, and uses a physical network interface for related communication.
[0167] It can be seen that by adopting the above improved technical solution, compared with the prior art, there are at least the following advantages:
[0168] (1) During most of the data transmission process, it is not necessary to interrupt the normal IoE data transmission and sending, ensuring real-time performance, minimizing latency, and meeting the application requirements of some IoE scenarios with low latency tolerance;
[0169] (2) It is not necessary to configure an intermediate storage medium, reducing the hardware layout cost;
[0170] (3) Move data security authentication forward to before the start of data transmission, and match different transmission channels according to different security authentication results, which can improve data transmission efficiency while ensuring terminal security.
[0171] (4) Based on the embodiment of the relevant deployment strategy of network access control, it can effectively protect the security of relevant protected devices (including data sending ends / data receiving ends, execution units).
[0172] For other technologies, principles, algorithms, or models not detailed in this application, reference can be made to the prior art.
[0173] In summary, in the technical solution of the present invention, when the data receiving end receives a data sending request, the IP-free firewall unit is activated, so that the IP-free firewall unit establishes a pre-communication link with the data sending end; the IP-free firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link; based on the data sample features obtained by random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end; based on the current data interaction channel, the data sending end transmits data to the data receiving end. The present invention advances data security authentication to before the start of data transmission, and matches different transmission channels according to different security authentication results, which can improve data transmission efficiency while ensuring terminal security.
[0174] In the foregoing embodiment part, the present invention provides multiple embodiments, each of which can constitute an independent technical solution and may contribute to the prior art and solve corresponding technical problems. However, it should be noted that different embodiments can be combined with each other without violating logic; at the same time, each embodiment can solve at least one technical problem, but it is not required that each individual embodiment solve multiple or all technical problems.
[0175] The method embodiments and systems of the present invention have been shown and described above. However, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirits of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A data transmission method based on security authentication and control, the method being applied to at least one data receiving end, characterized in that, The method includes the following steps: When a data sending request is received, the IP-free firewall unit of the data receiving end is enabled, so that the IP-free firewall unit establishes a pre-communication link with the data sending end; Based on the pre-communication link, the IP-free firewall unit sends a sampling instruction to the data sending end, and the sampling instruction is used to perform random feature sampling on the data set to be sent by the data sending end; Based on the data sample features obtained by the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end; Based on the current data interaction channel, the data sending end transmits data to the data receiving end.
2. The data transmission method based on security authentication and control according to claim 1, characterized in that During the process of the data sending end transmitting data to the data receiving end based on the current data interaction channel, the IP-free firewall unit continuously sends a sampling instruction to the data sending end based on the pre-communication link, so as to continuously perform random feature sampling on the data set to be sent by the data sending end; Based on the data sample features obtained by continuous random feature sampling, the IP-free firewall unit determines to maintain the current data interaction channel between the data receiving end and the data sending end, or replace the current data interaction channel.
3. The data transmission method based on security authentication and control according to claim 1, characterized in that The IP-free firewall unit is pre-configured with multiple data interaction channels, and each data interaction channel corresponds to a different security evaluation level and communication protocol; After evaluating the security level and applicable communication protocol of the data set to be sent by the data sending end based on the data sample features obtained by the random feature sampling, the IP-free firewall unit determines the current data interaction channel between the data receiving end and the data sending end.
4. The data transmission method based on security authentication and control according to claim 1, characterized in that The IP-free firewall unit is a detachable IP-free hardware firewall unit.
5. A data transmission method based on security authentication and control, the method being applied to at least one data sender, characterized in that, The method includes the following steps: Determine at least one data receiving end and send a data transmission request to the data receiving end; Perform random feature sampling on the first data set to be sent, and send the first data sample features obtained by the random feature sampling to the data receiving end; Based on the data interaction channel called by the data receiving end, transmit the first data set to be sent to the data receiving end; And while transmitting the first data set to be sent, prepare the second data set to be sent.
6. The data transmission method based on security authentication and control according to claim 5, characterized in that After sending the data transmission request to the data receiving end, a pre-communication link is established between the data receiving end and the data sending end, and the data receiving end sends the random feature sampling instruction to the data sending end based on the pre-communication link, and the random feature sampling instruction is used to instruct the data sending end to perform random feature sampling on the first data set to be sent.
7. The data transmission method based on security authentication and control according to claim 5, characterized in that, After sending a data transmission request to the data receiving end, a pre-communication link is established between the data receiving end and the data sending end, and the data receiving end performs random feature sampling on the first data set to be sent based on the pre-communication link to obtain second data sample features; The data receiving end determines the data interaction channel called by the data receiving end based on the first data sample features and the second data sample features.
8. A data transmission system based on security authentication and control, the system includes at least one data sending end and at least one data receiving end, characterized in that: The data receiving end is configured with a non-IP firewall unit; When the data receiving end receives a data sending request, the non-IP firewall unit is enabled, so that the non-IP firewall unit establishes a pre-communication link with the data sending end; The non-IP firewall unit sends a random sampling instruction to the data sending end based on the pre-communication link, and the sampling instruction is used to perform random feature sampling on the data set to be sent by the data sending end; Based on the data sample features obtained by the random feature sampling, the non-IP firewall unit determines the current data interaction channel between the data receiving end and the data sending end; Based on the current data interaction channel, the data sending end transmits data to the data receiving end.
9. The data transmission system based on security authentication and control according to claim 8, characterized in that: The data sample features include first data sample features and second data sample features; The first data sample features are obtained by the data sending end performing random feature sampling on the data set to be sent based on the sampling instruction; The second data sample features are obtained by the non-IP firewall unit performing random feature sampling on the data set to be sent based on the sampling instruction.
10. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the data transmission method according to any one of claims 1 to 4 or 5-7.
Citation Information
Patent Citations
A distributed information network security protection method, system, and its readable storage medium.
CN116566682B
Firewall flow detection method, system and device based on sflow and medium
CN115361191A
Secure interaction method and system for internal and external network data
CN116545763A
Distributed information network security protection method and system and readable storage medium thereof
CN116566682A
Network traffic security detection method, apparatus and device, and readable storage medium
CN117061373A