Multi-channel intelligent aggregation and distribution method and device for covert communication tunnel and medium
By building controlled hidden communication tunnel resources and source message tag analysis, the transmission bottlenecks and concealment problems of hidden tunnel technology in complex network environments are solved, efficient multi-channel intelligent aggregation and diversion are achieved, and the reliability and security of data transmission are improved.
Patent Information
- Application Number
- CN202510376912.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-22
AI Technical Summary
The existing hidden tunneling technology has transmission bottlenecks and insufficient service continuity in the high dynamic bandwidth requirements and complex heterogeneous network environments, lacks multi-channel load balancing and concealment, and the link aggregation solution is complex, which can easily lead to network blockage.
By building controlled hidden communication tunnel resources, analyzing source messages to form additional tags, aggregation and shunt control of tunnel resources and reorganizing routing node lists according to the tag quantization transmission requirements, realizing multi-channel intelligent aggregation and shunt.
It improves the reliability and security of data transmission, enhances the flexibility and manageability of the network, and ensures concealment and bandwidth management in complex network environments.
Smart Images

Figure CN120358194A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and in particular to a multi-channel intelligent aggregation and shunt method, device and medium for a covert communication tunnel. Background Art
[0002] With the rapid development of the Internet, data security and privacy protection have become increasingly important. Although traditional covert tunnel technologies can provide point-to-point single-channel data encryption transmission, they have limitations in the face of high-dynamic bandwidth requirements and complex heterogeneous network environments. For example, the single data link constructed by existing covert tunnel technologies is prone to becoming a transmission bottleneck, and the continuity of services cannot be guaranteed when the link fails. Moreover, the simple point-to-point link connection lacks sufficient concealment and is easily detected and intercepted. There is a lack of functions such as multi-channel load balancing and enhanced concealment support. Existing link aggregation solutions only perform bandwidth management for general transmission protocols and cannot guarantee data security. When implementing the bandwidth aggregation function, complex network configurations of devices are often required, and configuration errors can form network loops, causing network congestion and other faults. Summary of the Invention
[0003] In view of the above problems, embodiments of the present invention provide a multi-channel intelligent aggregation and shunt method, device and medium for a covert communication tunnel, so as to solve the technical problem that necessary functions are lacking in the prior art for data transmission using a covert communication tunnel.
[0004] The multi-channel intelligent aggregation and shunt method for a covert communication tunnel according to an embodiment of the present invention includes:
[0005] Constructing a controlled covert communication tunnel resource from a plurality of covert communication tunnels;
[0006] Analyzing the transmission state of a source message to form an additional tag of the source message, and quantifying the transmission requirement of the source message through the additional tag;
[0007] Performing aggregation and shunt control of the covert communication tunnel resource according to the transmission requirement quantified by the additional tag, and controlling the encrypted encapsulation of the source message by the covert communication tunnel to be transmitted to a target node;
[0008] Providing a routing node list according to the concealment requirement quantified by the additional tag, and re-encapsulating and transmitting the source message according to the routing node list.
[0009] In an embodiment of the present invention, the composition of the covert communication tunnel resource includes:
[0010] Determining configuration information and configuration status for each covert communication tunnel;
[0011] Updating the covert communication tunnel resource according to the configuration status.
[0012] In one embodiment of the present invention, the additional tag for forming the source message includes:
[0013] Obtain the source message of the service or traffic that requests a covert communication tunnel;
[0014] Parse and identify the transmission status for the proprietary fields or flag bits in the source message;
[0015] After forming the additional tag for the source message according to the transmission status, forward the source message.
[0016] In one embodiment of the present invention, the aggregation and diversion control of the covert communication tunnel resources includes:
[0017] Quantify the index range of the service or traffic transmission requirements according to the additional tag;
[0018] Adapt the covert communication tunnel resources according to the index range to determine the set of covert communication tunnels;
[0019] Forward the source message to the corresponding covert communication tunnel according to the preset multi-channel intelligent aggregation and diversion strategy.
[0020] In one embodiment of the present invention, the re-encapsulation of the source message includes:
[0021] Form a list of routing nodes by screening the covert communication tunnel resources according to the concealment requirements;
[0022] After re-encapsulating the source message according to the list of routing nodes, forward it to the corresponding covert communication tunnel.
[0023] The multi-channel intelligent aggregation and diversion device for the covert communication tunnel in the embodiment of the present invention includes:
[0024] A resource formation module, configured to form a controlled set of covert communication tunnel resources from several covert communication tunnels;
[0025] A demand marking module, configured to parse the transmission status of the source message, form an additional tag for the source message, and quantify the transmission requirements of the source message through the additional tag;
[0026] A resource control module, configured to perform aggregation and diversion control of the covert communication tunnel resources according to the transmission requirements quantified by the additional tag, and control the encrypted encapsulation of the covert communication tunnel to transmit the source message to the target node;
[0027] An additional enhancement module, configured to provide a list of routing nodes according to the concealment requirements quantified by the additional tag, and perform re-encapsulation and transmission of the source message according to the list of routing nodes.
[0028] The electronic device in the embodiment of the present invention includes:
[0029] A processor, a memory, and an interface for communicating with the gateway;
[0030] The memory is used to store programs and data, and the processor calls the programs stored in the memory to execute the above-mentioned multi-channel intelligent aggregation and diversion method.
[0031] In the computer-readable storage medium according to an embodiment of the present invention, the computer-readable storage medium includes a program, and the program is used to execute the above-mentioned multi-channel intelligent aggregation and diversion method when executed by a processor.
[0032] The multi-channel intelligent aggregation and diversion method, device and medium of the covert communication tunnel according to the embodiment of the present invention. Dynamically allocate tunnel resources according to data transmission requirements. Form a unified scheduling resource for the covert communication tunnel, and perform on-demand scheduling of the available bandwidth of the covert communication tunnel according to the transmission requirements for services or services. Ensure the availability of covert transmission in terms of bandwidth, routing reliability, etc. At the same time, use the change of routing nodes to enhance the concealment of tunnel transmission and improve transmission security, which not only improves the reliability and security of data transmission, but also enhances the flexibility and manageability of the network. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 The figure shows a schematic flowchart of the multi-channel intelligent aggregation and diversion method of the covert communication tunnel according to an embodiment of the present invention.
[0034] Figure 2 The figure shows a schematic diagram of data transmission in the actual application of the multi-channel intelligent aggregation and diversion method of the covert communication tunnel according to an embodiment of the present invention.
[0035] Figure 3 The figure shows a schematic diagram of packet re-encapsulation in the actual application of the multi-channel intelligent aggregation and diversion method of the covert communication tunnel according to an embodiment of the present invention.
[0036] Figure 4 The figure shows a schematic diagram of the architecture of the multi-channel intelligent aggregation and diversion device of the covert communication tunnel according to an embodiment of the present invention.
[0037] Figure 5 The figure shows a schematic diagram of the architecture of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] In order to make the purpose, technical solution and advantages of the present invention clearer and more understandable, the present invention will be further described below in conjunction with the accompanying drawings and specific embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0039] The multi-channel intelligent aggregation and diversion method of the covert communication tunnel according to an embodiment of the present invention is as Figure 1 shown. InFigure 1 In this embodiment of the present invention, it includes:
[0040] Step 100: Construct a controlled covert communication tunnel resource from a number of covert communication tunnels.
[0041] Those skilled in the art can understand that a covert communication tunnel forms a dedicated transmission channel through, for example, the tunneling network protocol to encrypt the data transmission process opaquely, forming a reliable data transmission between nodes. A controlled link resource between nodes can be formed through the covert communication tunnel resource, and the link resources can have differences in terms of bandwidth, routing redundancy, encryption strength, routing distance, routing reliability, etc.
[0042] Step 200: Analyze the transmission status of the source message to form an additional label for the source message, and quantify the transmission requirements of the source message through the additional label.
[0043] Those skilled in the art can understand that the source message is encapsulated according to a general service protocol, and the encapsulated content includes, but is not limited to, data fields such as payload, source address, destination address, check information, bandwidth requirements, latency requirements, and jitter requirements. Analyzing the source message according to the communication protocol can obtain the status requirements of the payload during data transmission for a specific service or business, and the status requirements include, but are not limited to, bandwidth requirements, real-time requirements, and security requirements, etc. Through preset rules, the status requirements can be quantified into a definite information identifier, and the information identifier can include type and value. By converting the information identifier into the additional label data of the source message to characterize the data transmission requirements of the corresponding service or business.
[0044] Step 300: Perform aggregation and diversion control on the covert communication tunnel resource according to the transmission requirements quantified by the additional label, and control the encrypted encapsulation and transmission of the source message through the covert communication tunnel to the destination node.
[0045] Through the preset logic judgment rule for the additional label, extract the additional label to identify the transmission guarantee requirements and perform corresponding control of the transmission traffic. The aggregation and diversion control targets the covert communication tunnel resource, and performs transmission scheduling of the source message according to the availability of parameter indicators such as the bandwidth, encryption strength, and transmission route reliability of each covert communication tunnel to meet the transmission of the effective data payload.
[0046] Step 400: Provide a list of routing nodes according to the covertness requirements quantified by the additional label, and perform re-encapsulation and transmission of the source message according to the list of routing nodes.
[0047] Extract the covertness requirements of the additional tags and control the corresponding routing nodes through the preset logic judgment rules for the additional tags. The routing node list provides the node addresses for the effective payload to jump between different nodes, and increases the covertness of data transmission by adjusting the nodes. Embed the routing node data by repackaging the source message.
[0048] The multi-channel intelligent aggregation and diversion method of the covert communication tunnel in the embodiment of the present invention dynamically allocates tunnel resources according to the data transmission requirements. Form a unified scheduling resource for the covert communication tunnel, and form an on-demand scheduling of the available bandwidth of the covert communication tunnel according to the transmission requirements of the service or business. Ensure the availability of covert transmission from aspects such as bandwidth, rate, and routing reliability. At the same time, use the change of routing nodes to enhance the covertness of tunnel transmission and improve the transmission security.
[0049] As Figure 1 shown, in an embodiment of the present invention, step 100 includes:
[0050] Step 110: Determine the configuration information and configuration status for each covert communication tunnel.
[0051] The covert communication tunnel mainly relies on the public Internet, forms an encrypted link service similar to VPN through IPSec technology or SSL technology, and constructs a secure private network tunnel based on the TCP / IP network. The configuration information of the covert communication tunnel is related to the adopted constituent technologies, including but not limited to encryption strength, transmission bandwidth or rate, delay, jitter, encryption strength, etc., and also includes the device type and transmission medium type used in the link formation process. And the change of configuration information during the establishment and maintenance of the covert communication tunnel.
[0052] Step 120: Update the resources of the covert communication tunnel according to the configuration status.
[0053] Update the resources of the covert communication tunnel according to the configuration information and the periodic configuration status. Determine the availability of the covert communication tunnel through the update. The availability status includes but not limited to establishable, maintainable, bandwidth utilization rate, rate upper and lower limits, delay count, jitter count, etc.
[0054] The multi-channel intelligent aggregation and diversion method of the covert communication tunnel in the embodiment of the present invention forms different dimensions for measuring tunnel resources through the collection, statistics, and update of the status of the covert communication tunnel, provides a measurement basis for the entire life cycle of the system tunnel resources, ensures that the resource availability can be continuously quantified, and can provide real-time indicators of tunnel resources for the data transmission requirements of services or businesses.
[0055] As Figure 1 shown, in an embodiment of the present invention, step 200 includes:
[0056] Step 210: Obtain the source message of the service or business that requests a covert communication tunnel.
[0057] Accept the source message of the service or business that has a request for a covert communication tunnel. The source message adopts a general encapsulation protocol. According to the protocol standard definition, the source message includes corresponding exclusive fields, flag bits, and corresponding information (data) payloads.
[0058] Step 220: Analyze and identify the transmission status from the exclusive fields or flag bits in the source message.
[0059] The analysis is carried out according to the preset mapping rules of the encapsulation protocol fields or flag bits. The transmission status identified through analysis includes the quantification of the bandwidth requirements, real-time requirements, security requirements, etc. of the current service or business. The above quantification content can reflect the current transmission status (transmission adaptability) of the service or business, or can also reflect the subsequent transmission status (transmission requirements) of the service or business.
[0060] Step 230: After forming an additional label for the source message according to the transmission status, forward the source message.
[0061] Those skilled in the art can understand that the transmission status information carried by different encapsulation protocols is not exactly the same. According to the preset mapping rules of the encapsulation protocol fields or flag bits, quantification results different from those related to transmission can be obtained. Convert the quantification results into additional data corresponding to the transmission requirements according to the preset mapping rules to form an additional label attached to or bound to the source message, so that the source message carries the judgment basis for its transmission requirements.
[0062] The multi-path intelligent aggregation and diversion method of the covert communication tunnel in the embodiment of the present invention forms a quantitative identifier for the transmission requirements by analyzing the status information of the source message. It provides a dynamic quantification mechanism for the transmission requirements of services and businesses with covert communication tunnel transmission requirements and a trigger mechanism for multi-path aggregation and diversion during the data transmission process, providing an intelligent processing basis for aggregation and diversion.
[0063] As Figure 1 shown, in an embodiment of the present invention, step 300 includes:
[0064] Step 310: Quantify the index range of the transmission requirements of the service or business according to the additional label.
[0065] The indicators of the transmission requirements include but are not limited to bandwidth, encryption strength, stability, and real-time performance. The quantification according to the additional label can be continuously quantified or periodically quantified with reference to the service or business type. The index range refers to the tolerance of the service or business on the corresponding index.
[0066] Step 320: Adapt the covert communication tunnel resources according to the index range, and determine the set of covert communication tunnels.
[0067] Through resource adaptation, different covert communication tunnels can be adapted for different metric ranges. A set of covert communication tunnels can be formed according to the importance of the metrics. There is a one-to-one, one-to-many, or many-to-one adaptation relationship between the metrics and the covert communication tunnels.
[0068] Step 330: Forward the source packets to the corresponding covert communication tunnels according to the preset multi-path intelligent aggregation and diversion strategy.
[0069] The aggregation and diversion control strategy includes, but is not limited to, evenly diverting a large number of source packets to different covert communication tunnels, allocating a small number of source packets to the same covert communication tunnel, allocating urgent source packets to the covert communication tunnel with the shortest route, allocating source packets to the covert communication tunnel with the highest encryption strength, etc. When the source packets enter the covert communication tunnel, source packet encryption encapsulation is formed.
[0070] The multi-path intelligent aggregation and diversion method of the covert communication tunnel in the embodiment of the present invention forms an aggregation and diversion control mechanism for concurrent covert communication tunnels for transmission metrics. It can intelligently schedule the resources of the metric covert communication tunnels according to service or business requirement metrics, and make full use of existing resources to ensure transmission availability.
[0071] As Figure 1 shown, in an embodiment of the present invention, step 400 includes:
[0072] Step 410: Form a list of routing nodes through screening of covert communication tunnel resources according to the concealment requirement.
[0073] The covert communication tunnel resources provide the node addresses at both ends of the covert communication tunnel and the routing topology network data within the control area, and can form node screening and node jump routing according to the concealment requirement.
[0074] Step 420: After re-encapsulating the source packets according to the list of routing nodes, forward them to the corresponding covert communication tunnels.
[0075] By re-encapsulating the source packets with standard encapsulation, multi-node jump distribution can be supported, ensuring concealment while adapting to complex network environments.
[0076] The multi-path intelligent aggregation and diversion method of the covert communication tunnel in the embodiment of the present invention provides a multi-node jump distribution mechanism based on resource configuration. It makes full use of the covert communication tunnel resources to improve transmission security and flexibility.
[0077] In practical applications, the process of using the multi-path intelligent aggregation and diversion method of the covert communication tunnel in the above embodiment is as Figure 2 shown. In Figure 2In this method, the netfilter framework of the Linux operating system is used as the message processing kernel to process the source message stream formed by the network card, and the TPROXY service is used to form a covert communication tunnel resource. For the source messages with the need for covert communication tunnels, additional tag processing (mark) is performed. The Nftables under the netfilter framework is used to form the corresponding mapping rules and control policies. The continuous source messages are forwarded to the input nodes of the corresponding covert communication tunnels. The message is repackaged as Figure 3 shown. In Figure 3 , the source message uses the node address in the covert communication tunnel resource to form message repackaging and form a new forwarding route.
[0078] In the specific implementation, when the data passes through the kernel, it is marked with a specific mark by the firewall and forwarded to a specific port through policy routing. This port is listened by the locally running TPROXY service.
[0079] The locally running socket program written in the golang language receives the raw network data forwarded by the Linux kernel, and this service repackages and encrypts the message and sends it to the specified node. Nftables is a tool used to replace the existing iptables command to configure the relevant policies of the firewall. Netfilter is a framework for processing various network data in the Linux kernel, and the commands issued by the user-state nftables program will take effect in the netfilter framework.
[0080] A multi-channel intelligent aggregation and diversion device for a covert communication tunnel according to an embodiment of the present invention is as Figure 4 shown. In Figure 4 , this embodiment includes:
[0081] A resource formation module 10, configured to form a controlled covert communication tunnel resource from a plurality of covert communication tunnels;
[0082] A requirement marking module 20, configured to perform transmission state analysis on the source message, form an additional tag of the source message, and quantify the transmission requirement of the source message through the additional tag;
[0083] A resource control module 30, configured to perform aggregation and diversion control of the covert communication tunnel resource according to the transmission requirement quantified by the additional tag, and control the encrypted transmission of the source message encapsulated by the covert communication tunnel to the target node;
[0084] An additional enhancement module 40, configured to provide a list of routing nodes according to the concealment requirement quantified by the additional tag, and perform source message repackaging and transmission according to the list of routing nodes.
[0085] As Figure 4 shown, in an embodiment of the present invention, the resource formation module 10 includes:
[0086] The status acquisition unit 11 is configured to determine the configuration information and configuration status for each covert communication tunnel;
[0087] The status update unit 12 is configured to update the covert communication tunnel resources according to the configuration status.
[0088] As Figure 4 shown, in an embodiment of the present invention, the requirement marking module 20 includes:
[0089] The message receiving unit 21 is configured to obtain the source message of the service or traffic that requests a covert communication tunnel;
[0090] The message identifying unit 22 is configured to analyze and identify the transmission status from the proprietary fields or flag bits in the source message;
[0091] The label attaching unit 23 is configured to form an additional label for the source message according to the transmission status and then forward the source message.
[0092] As Figure 4 shown, in an embodiment of the present invention, the resource control module 30 includes:
[0093] The metric identifying unit 31 is configured to quantify the metric range of the service or traffic transmission requirement according to the additional label;
[0094] The metric matching unit 32 is configured to adapt the covert communication tunnel resources according to the metric range and determine the set of covert communication tunnels;
[0095] The tunnel scheduling unit 33 is configured to forward the source message to the corresponding covert communication tunnel according to the preset multi-channel intelligent aggregation and diversion strategy.
[0096] As Figure 4 shown, in an embodiment of the present invention, the additional enhancement module 40 includes:
[0097] The node adaptation unit 41 is configured to form a list of routing nodes by screening the covert communication tunnel resources according to the concealment requirement;
[0098] The re-encapsulation unit 42 is configured to re-encapsulate the source message according to the list of routing nodes and then forward it to the corresponding covert communication tunnel.
[0099] The embodiments of the present application also provide a specific implementation manner of an electronic device that can implement all the steps in the method in the above embodiments. Please refer to Figure 5 . In Figure 5 , the electronic device 600 specifically includes the following:
[0100] A processor 610, a memory 620, a communication unit 630, and a bus 640;
[0101] Among them, the processor 610, the memory 620, and the communication unit 630 complete mutual communication through the bus 640; the communication unit 630 is used to implement information transmission between related devices or components such as the server and the terminal device.
[0102] The processor 610 is used to call the computer program in the memory 620. When the processor executes the computer program, all steps in the multi-path intelligent aggregation and shunt method of the hidden communication tunnel in the above embodiment are implemented.
[0103] Those of ordinary skill in the art should understand that the memory can be, but is not limited to, random access memory (Random Access Memory, abbreviated as RAM), read-only memory (Read Only Memory, abbreviated as ROM), programmable read-only memory (Programmable Read-Only Memory, abbreviated as PROM), erasable programmable read-only memory (Erasable Programmable Read-Only Memory, abbreviated as EPROM), electrically erasable programmable read-only memory (Electric Erasable Programmable Read-Only Memory, abbreviated as EEPROM), etc. Among them, the memory is used to store programs, and the processor executes the programs after receiving execution instructions. Further, the software programs and modules in the above memory may also include an operating system, which may include various software components and / or drivers for managing system tasks (such as memory management, storage device control, power management, etc.), and may communicate with various hardware or software components to provide a running environment for other software components.
[0104] The processor can be an integrated circuit chip with signal processing capabilities. The above-mentioned processor can be a general-purpose processor, including a central processing unit (Central Processing Unit, abbreviated as CPU), a network processor (Network Processor, abbreviated as NP), etc. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0105] The present application also provides a computer-readable storage medium, and the computer-readable storage medium includes a program, and the program is used to execute the multi-path intelligent aggregation and shunt method of the hidden communication tunnel provided in any one of the foregoing method embodiments when executed by a processor.
[0106] Those of ordinary skill in the art should understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: various media such as ROM, RAM, magnetic disk or optical disk that can store program codes, and the specific type of the medium is not limited in this application.
[0107] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A multi-channel intelligent aggregation and diversion method for a concealed communication tunnel, characterized in that Comprising: Constructing a number of covert communication tunnels into a controlled covert communication tunnel resource; Performing a transmission status analysis on the source message to form an additional tag for the source message, and quantifying the transmission requirement of the source message through the additional tag; Performing an aggregation and diversion control of the covert communication tunnel resource according to the transmission requirement quantified by the additional tag, and controlling the covert communication tunnel to encapsulate and transmit the source message to the target node; Providing a list of routing nodes according to the concealment requirement quantified by the additional tag, and re-encapsulating and transmitting the source message according to the list of routing nodes.
2. The multi-channel intelligent aggregation and shunt method according to claim 1, characterized in that, The composition of the covert communication tunnel resource includes: For each covert communication tunnel, determining the configuration information and configuration status; Updating the covert communication tunnel resource according to the configuration status.
3. The multi-channel intelligent aggregation and diversion method according to claim 1, characterized in that, The formation of the additional tag for the source message includes: Obtaining the source message of the service or service that requests the covert communication tunnel; Parsing and identifying the transmission status of the proprietary field or flag bit in the source message; Forwarding the source message after forming the additional tag for the source message according to the transmission status.
4. The multi-channel intelligent aggregation and shunting method according to claim 1, characterized in that, The aggregation and diversion control of the covert communication tunnel resource includes: Quantifying the index range of the transmission requirement of the service or service according to the additional tag; Adapting the covert communication tunnel resource according to the index range to determine the set of covert communication tunnels; Forwarding the source message to the corresponding covert communication tunnel according to the preset multi-channel intelligent aggregation and diversion strategy.
5. The multi-channel intelligent aggregation and shunting method according to claim 1, characterized in that, The re-encapsulation of the source message includes: Screening to form a list of routing nodes through the covert communication tunnel resource according to the concealment requirement; Re-encapsulating the source message according to the list of routing nodes and forwarding it to the corresponding covert communication tunnel.
6. A multi-channel intelligent aggregation and shunt device for a covert communication tunnel, characterized in that, Comprising: A resource formation module for constructing a number of covert communication tunnels into a controlled covert communication tunnel resource; A requirement marking module for performing a transmission status analysis on the source message to form an additional tag for the source message, and quantifying the transmission requirement of the source message through the additional tag; A resource control module for performing an aggregation and diversion control of the covert communication tunnel resource according to the transmission requirement quantified by the additional tag, and controlling the covert communication tunnel to encapsulate and transmit the source message to the target node; An additional enhancement module for providing a list of routing nodes according to the concealment requirement quantified by the additional tag, and re-encapsulating and transmitting the source message according to the list of routing nodes.
7. An electronic device, characterized in that, Comprising: A processor, a memory, and an interface for communicating with the gateway; The memory is used to store programs and data, and the processor calls the programs stored in the memory to execute the multi-channel intelligent aggregation and diversion method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a program, and the program is used to execute the multi-channel intelligent aggregation and diversion method according to any one of claims 1 to 5 when executed by the processor.