Cross-network data transmission method and system based on topological structure optimization
By planning the communication link of the encryption topology in cross-network data transmission, and encrypting the data using encrypted routing and forwarding routing, the problem of insufficient security of data transmission is solved and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510876730.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-06-27
AI Technical Summary
The existing cross-network data transmission methods have limited protection capabilities when facing complex network attacks, and data is easily stolen, tampered or listened with, especially the risk of leaking sensitive information in public network environments is high.
The cross-network data transmission method based on topology optimization is adopted. By planning the communication link of the encrypted topology structure, the data is encrypted using encrypted routing and forwarding routing, and a mirror-symmetric decryption topology is set up on the remote end to ensure that only routes that meet the decrypted topology structure can decrypt data.
Effectively prevent data from being stolen or tampered during transmission, improving the security of data transmission, and the flexibility of topology allows dynamic adjustments based on data characteristics and network environment, and the encryption process improves processing efficiency.
Smart Images

Figure CN120389913A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security, and particularly relates to a cross-network data transmission method and system based on topology structure optimization. Background Art
[0002] In today's digital age, the demand for cross-network data transmission is increasing day by day, covering multiple fields such as enterprise cross-regional office work, cloud computing data interaction, and Internet of Things device data communication. However, the existing cross-network data transmission methods have limited protection capabilities in the face of increasingly complex network attacks. When spreading in a public network environment, data is easily stolen, tampered with, or eavesdropped, resulting in the leakage of sensitive information. And with the increasing number and faster speed of current password cracking methods, even if complex encryption algorithms are used, as long as the data is intercepted, there is a great risk of leakage. Summary of the Invention
[0003] In order to solve the above problems existing in the prior art, the present invention provides a cross-network data transmission method and system based on topology structure optimization. The technical problems to be solved by the present invention are realized through the following technical solutions: A cross-network data transmission method based on topology structure optimization, applied to the local end, includes: Receiving data to be transmitted in a first network; Planning a communication link with an encrypted topology structure according to the data to be transmitted, wherein the encrypted topology structure includes several topology nodes, the topology nodes include encrypted routes and forwarding routes, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are in a parallel structure, and the at least four encrypted routes have at least one serial structure and one parallel structure; Sending the data to be transmitted to the corresponding topology node according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encrypted route, or generate encrypted data according to the data to be transmitted and send it to a second network when the corresponding topology node is a forwarding route, wherein each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; correspondingly, the remote end has a decryption topology structure that is mirror-symmetric to the encrypted topology structure to decrypt the encrypted data.
[0004] In a specific embodiment, sending the data to be transmitted to the corresponding topology node according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encrypted route, or forward the data to be transmitted to a second network when the corresponding topology node is a forwarding route, includes: Generate a data processing request frame according to an encryption topology structure, where the data processing request frame includes a feature tag of data to be transmitted, an identifier of each topology node, a type of each topology node, and a location of each topology node; After sending the data processing request frame to the corresponding topology node, cause the corresponding topology node to generate a lookup table that matches the feature tag of the data to be transmitted based on the feature tag of the data to be transmitted; Send the data to be transmitted to the corresponding topology node, so that the corresponding topology node encrypts the data to be transmitted according to the lookup table or forwards it to a second network.
[0005] In a specific embodiment, sending the data to be transmitted to the corresponding topology node, so that the corresponding topology node encrypts the data to be transmitted according to the lookup table or forwards it to a second network, includes: Send the data to be transmitted to the corresponding topology node, cause the corresponding topology node to parse the data to be transmitted to obtain a feature tag of the data to be transmitted, compare the feature tag of the data to be transmitted with the lookup table, and then encrypt the data to be transmitted or forward it to the second network according to the type of the topology node and the location of the topology node.
[0006] In a specific embodiment, encrypting the data to be transmitted according to the type of the topology node and the location of the topology node includes: When the topology node is an encryption router, obtain a node location code according to the location of the topology node, and encrypt the data to be transmitted received by the topology node according to the node location code to obtain node encrypted data; According to the lookup table, when it is determined that the next node of the node is an encryption router and is in a serial structure, send the node encrypted data and the node location code as the data to be transmitted to the next node; or, according to the lookup table, when it is determined that the next node of the node is an encryption router and is in a parallel structure, divide the node encrypted data according to the number of parallel nodes, and send each divided data, a division identifier, and the node location code as the data to be transmitted to the corresponding multiple next nodes; or, according to the lookup table, when it is determined that the next node of the node is a forwarding router, encapsulate the node encrypted data and the node location code and send them to the forwarding router.
[0007] In a specific embodiment, when it is determined that the topology node is a convergence node, combine the data to be transmitted sent by the previous node of the topology node received, and form the data to be encrypted of the node through a connection field for distinction.
[0008] The present invention discloses a cross-network data transmission system based on topology structure optimization, including: A data receiving module, configured to receive data to be transmitted in a first network; A topology planning module, configured to plan a communication link with an encrypted topology structure according to the data to be transmitted, where the encrypted topology structure includes a plurality of topology nodes, the topology nodes include an encrypted route and a forwarding route, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are in a parallel structure, and the at least four encrypted routes have at least one serial structure and one parallel structure; A topology encryption module, configured to send the data to be transmitted to corresponding topology nodes according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encrypted route, or generate encrypted data according to the data to be transmitted and send it to a second network when the corresponding topology node is a forwarding route, where each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; correspondingly, the remote end has a decryption topology structure that is mirror-symmetric to the encrypted topology structure to decrypt the encrypted data.
[0009] In a specific embodiment, the topology encryption module includes: An encryption request unit, configured to generate a data processing request frame according to the encrypted topology structure, where the data processing request frame includes a feature mark of the data to be transmitted, an identifier of each topology node, a type of each topology node, and a location of each topology node; A lookup table generation unit, configured to send the data processing request frame to the corresponding topology node, so that the corresponding topology node generates a lookup table that matches the feature mark of the data to be transmitted based on the feature mark of the data to be transmitted; An encryption unit, configured to send the data to be transmitted to the corresponding topology node, so that the corresponding topology node encrypts the data to be transmitted according to the lookup table or forwards it to the second network.
[0010] In a specific embodiment, the encryption unit specifically includes: sending the data to be transmitted to the corresponding topology node, causing the corresponding topology node to parse the data to be transmitted to obtain a feature mark of the data to be transmitted, comparing the feature mark of the data to be transmitted with the lookup table, and then encrypting the data to be transmitted or forwarding it to the second network according to the type and location of the topology node.
[0011] In a specific embodiment, encrypting the data to be transmitted according to the type and location of the topology node includes: When the topological node is an encrypted route, obtain a node position code according to the position of the topological node, and encrypt the data to be transmitted received by the topological node according to the node position code to obtain node encrypted data; When it is determined according to the lookup table that the next node of the node is an encrypted route and is in a serial structure, send the node encrypted data and the node position code as the data to be transmitted to the next node. Or, when it is determined according to the lookup table that the next node of the node is an encrypted route and is in a parallel structure, divide the node encrypted data according to the number of parallel nodes, and send each divided data, a division identifier, and the node position code as the data to be transmitted to the corresponding multiple next nodes. Or, when it is determined according to the lookup table that the next node of the node is a forwarding route, encapsulate the node encrypted data and the node position code and send them to the forwarding route.
[0012] In a specific embodiment, when it is determined that the topological node is a convergence node, combine the data to be transmitted received from the previous node of the topological node, and form the data to be encrypted of the node by distinguishing through a connection field.
[0013] Advantages of the present invention: The cross-network data transmission method based on topological structure optimization of the present invention plans a communication link with an encrypted topological structure and encrypts the data to be transmitted, which can avoid the risk of data being intercepted and decrypted, and ensure that only the route that conforms to the decryption topological structure can perform complete decryption processing on the data, thereby effectively preventing the data from being stolen or tampered with during the transmission process, and greatly improving the security of data transmission. Since the adjustment of the topological structure is flexible, the encrypted topological structure can be adjusted at any time according to different data characteristics and network environments, so as to achieve data encryption while efficiently transmitting data, and at the same time improve the processing efficiency.
[0014] The following will further describe the present invention in detail with reference to the drawings and embodiments. Description of the Drawings
[0015] Figure 1 is a schematic flowchart of a cross-network data transmission method based on topological structure optimization provided by an embodiment of the present invention; Figure 2 is a schematic diagram of a topological structure provided by an embodiment of the present invention; Figure 3 is another schematic diagram of a topological structure provided by an embodiment of the present invention; Figure 4 is a block diagram of a cross-network data transmission system module based on topological structure optimization provided by an embodiment of the present invention. Specific Embodiments
[0016] The present invention will be further described in detail below in conjunction with specific embodiments, but the implementation manners of the present invention are not limited thereto.
[0017] Embodiment 1 Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a cross-network data transmission method based on topology structure optimization provided by an embodiment of the present invention, applied to the local end, and includes: S1. Receive data to be transmitted in the first network; in this embodiment, the first network may be, for example, an internal local area network. The data to be transmitted is generally data generated by terminal devices. Generally, the scope of the internal local area network is usually limited to one area. When transmitting across regions, public network resources still need to be used for transmission. Therefore, after routing through the internal local area network, the data is finally transmitted to the routing device connected to the public network.
[0018] S2. Plan a communication link with an encrypted topology structure according to the data to be transmitted, where the encrypted topology structure includes several topology nodes, the topology nodes include encrypted routes and forwarding routes, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are in a parallel structure, and the at least four encrypted routes have at least one serial structure and one parallel structure; Specifically, the encrypted topology structure can be determined according to the data volume and importance of the data to be transmitted. For example, when the data volume is large, in order to improve the data transmission efficiency, the data can be distributed to multiple parallel topology structures for transmission. When the data is of high importance, in order to improve the data transmission security, multiple serial topology structures can be set. It should be noted that as the number of serial structures increases, the data transmission efficiency will also decrease significantly. Although the parallel structure can improve the transmission efficiency to a certain extent, it will make the entire encrypted topology structure complex, resulting in redundant transmitted data and logical confusion. Therefore, a suitable encrypted topology structure needs to be planned. When planning the encrypted topology structure, since the data to be transmitted is encrypted through topology nodes during the transmission process, the topology nodes include encrypted routes for encryption and forwarding routes for sending the encrypted data to the external network. In this embodiment, please refer to Figure 2, the smallest encryption topology structure includes at least four encryption routes and at least two forwarding routes connected in sequence. The terminal device T1 first sends the data to be transmitted to the encryption route RC1A. After the encryption route RC1A performs one encryption, it splits the encrypted data and sends it to two encryption routes RC2A and RC3A in a parallel structure. The encryption route RC2A encrypts the received encrypted data and sends it to the encryption route RC4A in a serial structure for further encryption, and then sends it to the forwarding route RT1A. The RT1A sends the data to the external network. After being encrypted by the encryption route RC3A, it is directly sent to the forwarding route RT2A, and the RT2A sends the data to the external network. In this smallest encryption topology structure, the encryption routes RC2A and RC3A have a parallel structure, and the encryption routes RC2A and RC4A have a serial structure.
[0019] S3. Send the data to be transmitted to the corresponding topology node according to the encryption topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encryption route, or generate encrypted data according to the data to be transmitted and send it to the second network when the corresponding topology node is a forwarding route. Wherein, each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; correspondingly, the remote end has a decryption topology structure that is mirror-symmetric to the encryption topology structure to decrypt the encrypted data.
[0020] Specifically, when the terminal device T1 is ready with the data to be transmitted, it needs to request routing resources. In the traditional transmission method, since there is no encryption of the topology structure, the process of requesting routing resources in the traditional method is relatively simple. First, the source address and the destination address are determined, and the routing method is directly determined according to routing rules such as the shortest path principle based on the source address and the destination address. However, in this embodiment, since a specific routing structure needs to be satisfied first, when requesting routing resources, the following steps are taken: 1. Determine the routing structure that meets this condition according to the data to be transmitted; 2. Traverse the routing nodes in the local first network and filter out the routing nodes that meet the specific routing structure; 3. Select the optimal routing node from the routing nodes that meet the specific routing structure using routing rules such as the shortest path principle to obtain the encryption topology structure.
[0021] After determining the encryption topology structure, it is necessary to inform each routing node of the specific processing rules. Specifically, it includes: S31. Generate a data processing request frame according to the encryption topology structure. The data processing request frame includes the characteristic mark of the data to be transmitted, the identifier of each topology node, the type of each topology node, and the location of each topology node. The characteristic mark of the data to be transmitted is used to identify the data source, so that after receiving the data, the topology node can determine whether the data needs to be encrypted through the data header. The identifier of the topology node is the number of the topology node in the encryption topology structure, so that other nodes can quickly locate the node through this number. The types of topology nodes include encryption nodes and forwarding nodes. The position of the topology node is used to represent the position of a certain node in the topology structure in the encryption topology structure, and this position can also illustrate the relationship between this node and its adjacent nodes. Through the characteristic mark of the data to be transmitted, the identifier of each topology node, the type of each topology node, and the position of each topology node, each topology node can clearly know its own position and the positions of other nodes in the entire encryption topology structure, thus facilitating the reception and sending of data. Optionally, the data processing request frame may further include the encryption method of each topology node.
[0022] S32. After sending the data processing request frame to the corresponding topology node, enable the corresponding topology node to generate a lookup table that matches the characteristic mark of the data to be transmitted based on the characteristic mark of the data to be transmitted; all the contents in the data processing request frame are included in the lookup table. Since the positions of each node in the encryption topology structure are different, it is necessary to generate a lookup table according to its own situation to facilitate subsequent lookup.
[0023] S33. Send the data to be transmitted to the corresponding topology node, so that the corresponding topology node encrypts the data to be transmitted according to the lookup table or forwards it to the second network.
[0024] Specifically, send the data to be transmitted to the corresponding topology node, enable the corresponding topology node to parse the data to be transmitted to obtain the characteristic mark of the data to be transmitted, compare the characteristic mark of the data to be transmitted with the lookup table, and then encrypt the data to be transmitted or forward it to the second network according to the type of the topology node and the position of the topology node. The second network in this embodiment may be, for example, a public network or a network that is not in the same logical address as the first network.
[0025] Correspondingly, at the decryption end, that is, at the remote end, it is necessary to deploy a network topology structure that is a mirror image of the local end to perform decryption. Otherwise, the decryption operation cannot be implemented. Figure 2For example, the destination addresses of the encrypted data are RT1B and RT2B addresses. After the second network transmits the data to RT1B and RT2B, RT1B and RT2B first parse the encrypted data to obtain the header data, generate the mirror network topology corresponding to the encrypted data through the header data, and then decrypt it according to the process opposite to the encryption process. The decryption routes RC2B and RC3B send the corresponding decrypted data to the decryption route RC1B. RC1B combines the data and decrypts it, and finally sends the decrypted data to the terminal device T2 at the remote end. Specifically, for the convenience of decryption at the decryption end, the encryption and decryption algorithms in this embodiment preferably adopt symmetric encryption and decryption algorithms. For example, the local end can use the AES encryption algorithm for encryption. Since the network topology structures of the decryption end are mirror images of each other, the corresponding AES decryption algorithm is used for decryption. At the same time, according to the encryption level requirements, generally 128-bit or 256-bit keys are used.
[0026] During processing, the following situations are included: When the topology node is an encryption route, obtain the node position code according to the position of the topology node, and encrypt the data to be transmitted received by the topology node according to the node position code to obtain the node encrypted data; the node position code is used to generate the key required by the symmetric encryption algorithm.
[0027] According to the lookup table, when it is determined that the next node of the node is an encryption route and is in a serial structure, send the node encrypted data and the node position code as the data to be transmitted to the next node. Or, according to the lookup table, when it is determined that the next node of the node is an encryption route and is in a parallel structure, divide the node encrypted data according to the number of parallel nodes, and send each divided data, the division identifier, and the node position code as the data to be transmitted to the corresponding multiple next nodes. Or, according to the lookup table, when it is determined that the next node of the node is a forwarding route, encapsulate the node encrypted data and the node position code and send them to the forwarding route.
[0028] Take Figure 2Taking the [structure] as an example, the data to be transmitted is first sent to the encryption router RC1A through T1. The data header of the data to be transmitted carries the feature marker of the data to be transmitted. After parsing, the encryption router RC1A extracts the feature marker and compares it with the pre-stored lookup table. Specifically, the lookup table includes the routing path of the data to be transmitted and the content of the current node processing the data to be transmitted. The encryption router RC1A determines that it is the first routing node, and after processing, it sends the encrypted data through two parallel routing paths. Therefore, the received transmission data is directly encrypted. Since the encrypted data needs to be transmitted in two ways, the encrypted data needs to be segmented. The specific segmentation method can be: segment the encrypted data according to the maximum encryption routing length of each parallel path in proportion; add a segmentation field to the data table header of the segmented encrypted data to mark the segmentation position for convenient subsequent data combination. Then, the segmented data is sent separately according to the address of the next routing node in the lookup table. For example, in this embodiment, the maximum routing length of the parallel path of RC2A is 2 (RC2A - RC4A), and the maximum routing length of the parallel path of RC3A is 1 (RC2A). Therefore, when segmenting, it is segmented in the ratio of 1:2, that is, the data volume of RC2A: the data volume of RC3A = 1:2. In this way, since the path with the maximum path length requires more encryption times, longer processing time and larger encrypted data volume, less data is allocated to this path, thus improving the overall processing efficiency.
[0029] Preferably, when it is determined that the topology node is a convergence node, the data to be transmitted sent by the previous node of the topology node received is combined, and the data to be encrypted of this node is formed by distinguishing through the connection field.
[0030] To better illustrate the solution of this embodiment, please refer to Figure 3 , in this topology structure, there is a situation where a part of the data output by RC11 and all the data output by RC12 converge to the same node RC14. Specifically, after parsing the data to be transmitted, the encryption router RC10 performs encryption processing. Since there are two parallel encryption nodes after RC10, data segmentation is required. Since the maximum encryption path of each subsequent path is 3, the data volume is segmented in the ratio of 1:1. And since RC11 is a parallel path of another RC12 during subsequent segmentation and needs to be combined when converging, the two pieces of data are connected through the connection field and used to distinguish the two during subsequent decryption.
[0031] The cross-network data transmission method based on topology structure optimization in this embodiment plans a communication link with an encrypted topology structure, encrypts the data to be transmitted, can avoid the risk of data being intercepted and decrypted, and ensures that only the routes that conform to the decryption topology structure can perform complete decryption processing on the data, thereby effectively preventing the data from being stolen or tampered with during the transmission process, and greatly improving the security of data transmission. Since the adjustment of the topology structure is flexible, the encrypted topology structure can be adjusted at any time according to different data characteristics and network environments, so as to realize data encryption while efficiently transmitting data, and at the same time improve the processing efficiency.
[0032] Please refer to Figure 4 , Figure 4 which is a block diagram of a cross-network data transmission system module provided by an embodiment of the present invention, including: A data receiving module, configured to receive data to be transmitted in a first network; A topology planning module, configured to plan a communication link with an encrypted topology structure according to the data to be transmitted, where the encrypted topology structure includes several topology nodes, the topology nodes include encrypted routes and forwarding routes, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are in a parallel structure, and the at least four encrypted routes have at least one serial structure and one parallel structure; A topology encryption module, configured to send the data to be transmitted to the corresponding topology node according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encrypted route, or generate encrypted data according to the data to be transmitted and send it to a second network when the corresponding topology node is a forwarding route, where each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; correspondingly, the remote end has a decryption topology structure that is mirror-symmetric to the encrypted topology structure to decrypt the encrypted data.
[0033] In a specific embodiment, the topology encryption module includes: An encryption request unit, configured to generate a data processing request frame according to the encrypted topology structure, where the data processing request frame includes a feature marker of the data to be transmitted, an identifier of each topology node, a type of each topology node, and a location of each topology node; A lookup table generation unit, configured to send the data processing request frame to the corresponding topology node, and then enable the corresponding topology node to generate a lookup table that matches the feature marker of the data to be transmitted based on the feature marker of the data to be transmitted; An encryption unit, configured to send the data to be transmitted to corresponding topology nodes, so that the corresponding topology nodes encrypt the data to be transmitted according to the lookup table or forward it to a second network.
[0034] In a specific embodiment, the encryption unit specifically includes: sending the data to be transmitted to corresponding topology nodes, enabling the corresponding topology nodes to parse the data to be transmitted to obtain a feature marker of the data to be transmitted, comparing the feature marker of the data to be transmitted with the lookup table, and then encrypting the data to be transmitted or forwarding it to a second network according to the type and location of the topology nodes.
[0035] In a specific embodiment, encrypting the data to be transmitted according to the type and location of the topology nodes includes: When the topology node is an encryption router, obtaining a node location code according to the location of the topology node, and encrypting the data to be transmitted received by the topology node according to the node location code to obtain node-encrypted data; When it is determined according to the lookup table that the next node of the node is an encryption router and is in a serial structure, sending the node-encrypted data and the node location code as the data to be transmitted to the next node; or when it is determined according to the lookup table that the next node of the node is an encryption router and is in a parallel structure, splitting the node-encrypted data according to the number of parallel nodes, and sending each split data, a split identifier, and the node location code as the data to be transmitted to corresponding multiple next nodes; or when it is determined according to the lookup table that the next node of the node is a forwarding router, encapsulating and sending the node-encrypted data and the node location code to the forwarding router.
[0036] In a specific embodiment, when it is determined that the topology node is a convergence node, combining the data to be transmitted sent by the previous node of the topology node received, and forming the data to be encrypted of the node by distinguishing through a connection field.
[0037] In addition, the terms "first" and "second" are only used for descriptive purposes, and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.
[0038] In the description of this specification, the descriptions with reference to terms such as "one embodiment", "some embodiments", "examples", "specific examples", or "some examples", etc., mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0039] Although the present application has been described herein in connection with various embodiments, however, in implementing the claimed present application, those skilled in the art can understand and realize other variations of the disclosed embodiments by viewing the accompanying drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. A single processor or other unit can implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0040] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. A cross-network data transmission method based on topology structure optimization, applied to the local end, characterized in that Including: Receiving data to be transmitted in a first network; Planning a communication link with an encrypted topology according to the data to be transmitted, wherein the encrypted topology includes a plurality of topology nodes, the topology nodes include encrypted routes and forwarding routes, the encrypted topology includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are in a parallel structure, and the at least four encrypted routes have at least one serial structure and one parallel structure; Sending the data to be transmitted to corresponding topology nodes according to the encrypted topology, so as to encrypt the data to be transmitted when the corresponding topology node is an encrypted route, or generate encrypted data according to the data to be transmitted and send it to a second network when the corresponding topology node is a forwarding route, wherein each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; correspondingly, the remote end has a decryption topology that is mirror-symmetric to the encrypted topology to decrypt the encrypted data.
2. The cross-network data transmission method based on topology structure optimization according to claim 1, wherein Sending the data to be transmitted to corresponding topology nodes according to the encrypted topology, so as to encrypt the data to be transmitted when the corresponding topology node is an encrypted route, or forward the data to be transmitted to a second network when the corresponding topology node is a forwarding route, includes: Generating a data processing request frame according to the encrypted topology, the data processing request frame including a feature marker of the data to be transmitted, an identifier of each topology node, a type of each topology node, and a location of each topology node; After sending the data processing request frame to the corresponding topology node, causing the corresponding topology node to generate a lookup table that matches the feature marker of the data to be transmitted based on the feature marker of the data to be transmitted; Sending the data to be transmitted to the corresponding topology node, so that the corresponding topology node encrypts the data to be transmitted or forwards it to the second network according to the lookup table.
3. The cross-network data transmission method based on topology structure optimization according to claim 2, characterized in that Sending the data to be transmitted to the corresponding topology node, so that the corresponding topology node encrypts the data to be transmitted or forwards it to the second network according to the lookup table, includes: Sending the data to be transmitted to the corresponding topology node, causing the corresponding topology node to parse the data to be transmitted to obtain a feature marker of the data to be transmitted, comparing the feature marker of the data to be transmitted with the lookup table, and then encrypting the data to be transmitted or forwarding it to the second network according to the type and location of the topology node.
4. The cross-network data transmission method based on topology structure optimization according to claim 3, wherein, Encrypting the data to be transmitted according to the type and location of the topology node, includes: When the topology node is an encrypted route, obtaining a node location code according to the location of the topology node, and encrypting the data to be transmitted received by the topology node according to the node location code to obtain node encrypted data; When it is determined according to the lookup table that the next node of the node is an encrypted route and is in a serial structure, the node encrypted data and the node location encoding are sent as data to be transmitted to the next node. Or, when it is determined according to the lookup table that the next node of the node is an encrypted route and is in a parallel structure, the node encrypted data is segmented according to the number of parallel nodes, and each segmented data, the segmentation identifier, and the node location encoding are sent as data to be transmitted to the corresponding multiple next nodes. Or, when it is determined according to the lookup table that the next node of the node is a forwarding route, the node encrypted data and the node location encoding are encapsulated and sent to the forwarding route.
5. The cross-network data transmission method based on topology structure optimization according to claim 3, wherein When it is determined that the topology node is a convergence node, the data to be transmitted sent by the previous node of the topology node received is combined, and the data to be encrypted of the node is formed by distinguishing through the connection field.
6. A cross-network data transmission system based on topological structure optimization, characterized in that, Including: A data receiving module, configured to receive data to be transmitted in the first network; A topology planning module, configured to plan a communication link with an encrypted topology structure according to the data to be transmitted, where the encrypted topology structure includes several topology nodes, the topology nodes include encrypted routes and forwarding routes, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are in a parallel structure, and the at least four encrypted routes have at least one serial structure and one parallel structure; A topology encryption module, configured to send the data to be transmitted to the corresponding topology node according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encrypted route, or generate encrypted data according to the data to be transmitted and send it to the second network when the corresponding topology node is a forwarding route, where each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; correspondingly, the remote end has a decryption topology structure that is mirror-symmetric to the encrypted topology structure to decrypt the encrypted data.
7. The cross-network data transmission system based on topology structure optimization according to claim 6, characterized in that, The topology encryption module includes: An encryption request unit, configured to generate a data processing request frame according to the encrypted topology structure, where the data processing request frame includes a feature marker of the data to be transmitted, an identifier of each topology node, a type of each topology node, and a location of each topology node; A lookup table generation unit, configured to send the data processing request frame to the corresponding topology node, so that the corresponding topology node generates a lookup table that matches the feature marker of the data to be transmitted based on the feature marker of the data to be transmitted; An encryption unit, configured to send the data to be transmitted to the corresponding topology node, so that the corresponding topology node encrypts the data to be transmitted according to the lookup table or forwards it to the second network.
8. The cross-network data transmission system based on topological structure optimization according to claim 7, characterized in that, The encryption unit specifically includes: sending the data to be transmitted to the corresponding topology node, enabling the corresponding topology node to parse the data to be transmitted to obtain a feature marker of the data to be transmitted, comparing the feature marker of the data to be transmitted with a lookup table, and then encrypting the data to be transmitted or forwarding it to a second network according to the type and location of the topology node.
9. The cross-network data transmission system based on topological structure optimization according to claim 8, wherein Encrypting the data to be transmitted according to the type and location of the topology node includes: When the topology node is an encryption router, obtaining a node location code according to the location of the topology node, and encrypting the data to be transmitted received by the topology node according to the node location code to obtain node-encrypted data; When it is determined according to the lookup table that the next node of the node is an encryption router and is in a serial structure, sending the node-encrypted data and the node location code as the data to be transmitted to the next node; or when it is determined according to the lookup table that the next node of the node is an encryption router and is in a parallel structure, dividing the node-encrypted data according to the number of parallel nodes, and sending each divided data, a division identifier, and the node location code as the data to be transmitted to the corresponding multiple next nodes; or when it is determined according to the lookup table that the next node of the node is a forwarding router, encapsulating the node-encrypted data and the node location code and sending them to the forwarding router.
10. The cross-network data transmission system based on topology structure optimization according to claim 8, wherein, When it is determined that the topology node is a convergence node, combining the data to be transmitted sent by the previous node of the topology node received, and differentiating through a connection field to form the data to be encrypted of the node.
Citation Information
Patent Citations
Dynamic overlay network topology construction method and device based on blockchain cross-chain interaction
CN112600699A
Network layer multipath forwarding method
CN120034484A
Path determination method, device and system
WO2017215385A1