Cross-network data transmission method and system based on topology optimization

By planning communication links with an encrypted topology and encrypting the data, the security issues in cross-network data transmission are resolved, and the security and efficiency of data transmission are improved.

CN120389913BActive Publication Date: 2025-09-05NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510876730.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-09-05
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

Existing cross-network data transmission methods have limited protection capabilities when facing complex network attacks, and data can be easily stolen, tampered with, or monitored. Even if complex encryption algorithms are used, the risk of leakage is relatively high.

Method used

A cross-network data transmission method based on topology optimization is adopted to plan the communication links of the encryption topology structure, encrypt the data through encryption routing and forwarding routing, and set up a mirror-symmetric decryption topology structure at the remote end to ensure that only routes that meet the decryption topology structure can decrypt the data.

Benefits of technology

It effectively prevents data from being stolen or tampered with during transmission, improves the security and processing efficiency of data transmission, and flexibly adjusts the encryption topology to adapt to different data characteristics and network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389913B_ABST
    Figure CN120389913B_ABST
Patent Text Reader

Abstract

The present invention discloses a cross-network data transmission method based on topology optimization, comprising: receiving data to be transmitted in a first network; planning a communication link with an encrypted topology structure according to the data to be transmitted; sending the data to be transmitted to a corresponding topology node according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encryption route, or generating encrypted data based on the data to be transmitted and sending it to a second network when the corresponding topology node is a forwarding route. The cross-network data transmission method based on topology optimization of the present invention encrypts the data to be transmitted by planning a communication link with an encrypted topology structure, thereby avoiding the risk of data being intercepted and decrypted, ensuring that only routes that comply with the decryption topology structure can completely decrypt the data, effectively preventing the data from being stolen or tampered with during transmission, and improving the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and in particular relates to a cross-network data transmission method and system based on topology structure optimization. Background Art

[0002] In today's digital age, the demand for cross-network data transmission is growing, encompassing diverse areas such as cross-regional enterprise offices, cloud computing data exchange, and IoT device data communication. However, existing cross-network data transmission methods offer limited protection against increasingly complex cyberattacks. When transmitted over public networks, data is susceptible to theft, tampering, or eavesdropping, leading to the leakage of sensitive information. Furthermore, with the increasing number of password cracking methods and their increasing speed, even with sophisticated encryption algorithms, data interception poses a significant risk of leakage. Summary of the Invention

[0003] In order to solve the above problems existing in the prior art, the present invention provides a cross-network data transmission method and system based on topology optimization. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0004] A cross-network data transmission method based on topology optimization, applied to a local end, includes:

[0005] receiving data to be transmitted in the first network;

[0006] Planning a communication link having an encrypted topology structure based on the data to be transmitted, wherein the encrypted topology structure includes a plurality of topology nodes, the topology nodes include encryption routes and forwarding routes, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are parallel structures, and the at least four encrypted routes have at least one serial structure and one parallel structure;

[0007] The data to be transmitted is sent to the corresponding topological node according to the encrypted topological structure, so that the data to be transmitted is encrypted when the corresponding topological node is an encryption route, or encrypted data is generated according to the data to be transmitted and sent to the second network when the corresponding topological node is a forwarding route, wherein each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; accordingly, the remote end has a decryption topological structure that is mirror-symmetric to the encryption topological structure to decrypt the encrypted data.

[0008] In a specific embodiment, sending the data to be transmitted to a corresponding topology node according to the encryption topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encryption route, or forwarding the data to be transmitted to a second network when the corresponding topology node is a forwarding route, includes:

[0009] generating a data processing request frame according to the encrypted topological structure, wherein the data processing request frame includes a characteristic mark of the data to be transmitted, an identifier of each topological node, a type of each topological node, and a position of each topological node;

[0010] After sending the data processing request frame to the corresponding topological node, the corresponding topological node generates a lookup table matching the feature tag of the data to be transmitted based on the feature tag of the data to be transmitted;

[0011] The data to be transmitted is sent to a corresponding topological node, so that the corresponding topological node encrypts the data to be transmitted or forwards it to a second network according to the lookup table.

[0012] In a specific embodiment, sending the data to be transmitted to a corresponding topological node so that the corresponding topological node encrypts the data to be transmitted or forwards it to the second network according to the lookup table includes:

[0013] The data to be transmitted is sent to the corresponding topological node, so that the corresponding topological node parses the data to be transmitted to obtain a characteristic tag of the data to be transmitted. After comparing the characteristic tag of the data to be transmitted with the lookup table, the data to be transmitted is encrypted or forwarded to the second network according to the type of the topological node and the position of the topological node.

[0014] In a specific embodiment, encrypting the data to be transmitted according to the type of the topological node and the position of the topological node includes:

[0015] When the topological node is an encrypted route, a node position code is obtained according to the position of the topological node, and the data to be transmitted received by the topological node is encrypted according to the node position code to obtain node encrypted data;

[0016] When it is determined according to the lookup table that the next node of the node is an encrypted route and has a serial structure, the node encrypted data and the node position code are sent to the next node as the data to be transmitted; or, when it is determined according to the lookup table that the next node of the node is an encrypted route and has a parallel structure, the node encrypted data is divided according to the number of parallel nodes, and each divided data, division identifier and node position code is sent as the data to be transmitted to the corresponding multiple next nodes; or, when it is determined according to the lookup table that the next node of the node is a forwarding route, the node encrypted data and the node position code are encapsulated and sent to the forwarding route.

[0017] In a specific embodiment, when the topological node is determined to be a sink node, the received data to be transmitted sent by a node above the topological node are combined and differentiated by a connection field to form the data to be encrypted of the node.

[0018] The present invention discloses a cross-network data transmission system based on topology optimization, comprising:

[0019] A data receiving module, configured to receive data to be transmitted in the first network;

[0020] a topology planning module, configured to plan a communication link having an encrypted topology structure based on the data to be transmitted, wherein the encrypted topology structure includes a plurality of topology nodes, each of which includes an encryption route and a forwarding route, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes being in a parallel structure, and the at least four encrypted routes having at least one serial structure and one parallel structure;

[0021] A topology encryption module is used to send the data to be transmitted to the corresponding topology node according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encryption route, or to generate encrypted data based on the data to be transmitted and send it to the second network when the corresponding topology node is a forwarding route, wherein each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; accordingly, the remote end has a decryption topology structure that is mirror-symmetric to the encryption topology structure to decrypt the encrypted data.

[0022] In a specific embodiment, the topology encryption module includes:

[0023] an encryption request unit, configured to generate a data processing request frame according to the encrypted topology structure, wherein the data processing request frame includes a feature tag of the data to be transmitted, an identifier of each topological node, a type of each topological node, and a position of each topological node;

[0024] a lookup table generating unit, configured to, after sending the data processing request frame to the corresponding topological node, enable the corresponding topological node to generate a lookup table matching the feature tag of the data to be transmitted based on the feature tag of the data to be transmitted;

[0025] The encryption unit is configured to send the data to be transmitted to a corresponding topological node, so that the corresponding topological node encrypts the data to be transmitted or forwards it to a second network according to the lookup table.

[0026] In a specific embodiment, the encryption unit specifically includes: sending the data to be transmitted to a corresponding topological node, allowing the corresponding topological node to parse the data to be transmitted to obtain a characteristic tag of the data to be transmitted, comparing the characteristic tag of the data to be transmitted with a lookup table, and encrypting or forwarding the data to be transmitted to a second network according to the type of the topological node and the position of the topological node.

[0027] In a specific embodiment, encrypting the data to be transmitted according to the type of the topological node and the position of the topological node includes:

[0028] When the topological node is an encrypted route, a node position code is obtained according to the position of the topological node, and the data to be transmitted received by the topological node is encrypted according to the node position code to obtain node encrypted data;

[0029] When it is determined according to the lookup table that the next node of the node is an encrypted route and has a serial structure, the node encrypted data and the node position code are sent to the next node as the data to be transmitted; or, when it is determined according to the lookup table that the next node of the node is an encrypted route and has a parallel structure, the node encrypted data is divided according to the number of parallel nodes, and each divided data, division identifier and node position code is sent as the data to be transmitted to the corresponding multiple next nodes; or, when it is determined according to the lookup table that the next node of the node is a forwarding route, the node encrypted data and the node position code are encapsulated and sent to the forwarding route.

[0030] In a specific embodiment, when the topological node is determined to be a sink node, the received data to be transmitted sent by a node above the topological node are combined and differentiated by a connection field to form the data to be encrypted of the node.

[0031] Beneficial effects of the present invention:

[0032] The cross-network data transmission method based on topology optimization of the present invention encrypts the data to be transmitted by planning a communication link with an encrypted topology. This method can avoid the risk of data being intercepted and decrypted, ensuring that only routes that conform to the decryption topology can fully decrypt the data, thereby effectively preventing theft or tampering of data during transmission and greatly improving the security of data transmission. Due to the flexibility of topology adjustment, the encryption topology can be adjusted at any time according to different data characteristics and network environments, thereby achieving data encryption while efficiently transmitting data and improving processing efficiency.

[0033] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 This is a flowchart of a cross-network data transmission method based on topology optimization provided by an embodiment of the present invention;

[0035] Figure 2 This is a schematic diagram of a topological structure provided by an embodiment of the present invention;

[0036] Figure 3 This is another schematic diagram of a topological structure provided by an embodiment of the present invention;

[0037] Figure 4 This is a module block diagram of a cross-network data transmission system based on topology optimization provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0038] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.

[0039] Example 1

[0040] See Figure 1 , Figure 1 This is a flowchart of a cross-network data transmission method based on topology optimization provided by an embodiment of the present invention, which is applied to a local end and includes:

[0041] S1. Receive data to be transmitted in a first network. In this embodiment, the first network may be, for example, an internal local area network. The data to be transmitted is generally data generated by a terminal device. Generally, the scope of an internal local area network is usually limited to one region. When transmitting across regions, it still needs to rely on public network resources for transmission. Therefore, after being routed through the internal local area network, it is finally transmitted to a routing device connected to the public network.

[0042] S2. Planning a communication link having an encrypted topology structure based on the data to be transmitted, wherein the encrypted topology structure includes a plurality of topology nodes, each of which includes an encryption route and a forwarding route. The encrypted topology structure includes at least four sequentially connected encryption routes and at least two forwarding routes, wherein the at least two forwarding routes are parallel structures, and the at least four encryption routes have at least one serial structure and one parallel structure.

[0043] Specifically, the encryption topology can be determined based on the amount of data to be transmitted and the importance of the data. For example, when the amount of data is large, in order to improve the data transmission efficiency, the data can be distributed to multiple parallel topology structures for transmission. When the importance of the data is high, in order to improve the security of data transmission, multiple serial topology structures can be set. It should be noted that as the number of serial structures increases, the resulting data transmission efficiency will also be greatly reduced. Although the parallel structure can improve the transmission efficiency to a certain extent, it will make the entire encryption topology complex, resulting in redundant transmission data and logical confusion. Therefore, it is necessary to plan a suitable encryption topology. When planning the encryption topology, since the data to be transmitted is encrypted through the topology nodes during the transmission process, the topology nodes include encryption routes for encryption and forwarding routes for sending the encrypted data to the external network. In this embodiment, please refer to Figure 2 The minimum encryption topology includes at least four sequentially connected encryption routes and at least two forwarding routes. Terminal device T1 first sends data to be transmitted to encryption route RC1A. After encryption, RC1A encrypts the data once, splits it, and sends it to two parallel encryption routes, RC2A and RC3A. Encryption route RC2A encrypts the received encrypted data and sends it to encryption route RC4A, which encrypts it again in a serial configuration. The encrypted data is then sent to forwarding route RT1A, which then sends the data to the external network. After encryption, RC3A sends the encrypted data directly to forwarding route RT2A, which then sends the data to the external network. In this minimum encryption topology, encryption routes RC2A and RC3A are parallel, while encryption routes RC2A and RC4A are serial.

[0044] S3. Send the data to be transmitted to the corresponding topological node according to the encrypted topological structure, so as to encrypt the data to be transmitted when the corresponding topological node is an encryption route, or generate encrypted data based on the data to be transmitted and send it to the second network when the corresponding topological node is a forwarding route, wherein each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; accordingly, the remote end has a decryption topological structure that is mirror-symmetric to the encryption topological structure to decrypt the encrypted data.

[0045] Specifically, when the terminal device T1 is ready to transmit data, it needs to request routing resources. Since the traditional transmission method does not involve the encryption of the topology structure, the process of requesting routing resources in the traditional method is relatively simple. First, the source address and destination address are determined, and then the routing method is directly determined based on the source address and destination address using routing rules such as the shortest path principle. However, since this embodiment needs to give priority to satisfying a specific routing structure, when requesting routing resources, the following steps are performed: 1. Determine a routing structure that meets this condition based on the data to be transmitted; 2. Traverse the routing nodes in the first network of the local end and screen the routing nodes that meet the specific routing structure; 3. Use routing rules such as the shortest path principle to select the optimal routing node from the routing nodes that meet the specific routing structure to obtain an encrypted topology structure.

[0046] After determining the encryption topology, each routing node needs to be informed of the specific processing rules, including:

[0047] S31. Generate a data processing request frame according to the encrypted topology structure, where the data processing request frame includes a feature tag of the data to be transmitted, an identifier of each topology node, a type of each topology node, and a position of each topology node;

[0048] The characteristic mark of the data to be transmitted is used to identify the source of the data, so that after receiving the data, the topological node can determine whether it is data that needs to be encrypted through the data header. The identifier of the topological node is the number of the topological node in the encrypted topological structure, so that other nodes can quickly locate the node through this number. The types of topological nodes include encryption nodes and forwarding nodes. The position of the topological node is used to indicate the position of a certain node in the topological structure in the encrypted topological structure. The position can also explain the relationship between the node and the adjacent nodes. Through the characteristic mark of the data to be transmitted, the identifier of each topological node, the type of each topological node and the position of each topological node, each topological node can clearly understand the position of the node in the entire encrypted topological structure, as well as the position of other nodes, thereby facilitating the reception and transmission of data. Optionally, the data processing request frame can also include the encryption method of each topological node.

[0049] S32. After sending the data processing request frame to the corresponding topological node, the corresponding topological node generates a lookup table that matches the feature tag of the data to be transmitted based on the feature tag of the data to be transmitted; the lookup table includes all the contents in the data processing request frame. Since each node has a different position in the encrypted topological structure, it is necessary to generate a lookup table based on its own situation to facilitate subsequent searches.

[0050] S33: Send the data to be transmitted to a corresponding topological node, so that the corresponding topological node encrypts the data to be transmitted or forwards it to the second network according to the lookup table.

[0051] Specifically, the data to be transmitted is sent to the corresponding topological node, so that the corresponding topological node parses the data to be transmitted to obtain a characteristic tag of the data to be transmitted, and after comparing the characteristic tag of the data to be transmitted with the lookup table, the data to be transmitted is encrypted or forwarded to the second network according to the type of the topological node and the position of the topological node. The second network of this embodiment can be, for example, a public network or a network that is not at the same logical address as the first network.

[0052] Correspondingly, at the decryption end, that is, at the remote end, a network topology that is a mirror image of the local end needs to be deployed to perform decryption, otherwise, the decryption operation cannot be performed. Figure 2 For example, the destination address of the encrypted data is RT1B and RT2B. After the second network transmits the data to RT1B and RT2B, RT1B and RT2B first parse the encrypted data to obtain the header data. Using the header data, they generate the mirror network topology corresponding to the encrypted data, and then decrypt it according to the reverse process of the encryption process. Decryption routes RC2B and RC3B send the corresponding decrypted data to decryption route RC1B. RC1B combines the data and decrypts it. Finally, the decrypted data is sent to the remote terminal device T2. Specifically, to facilitate decryption at the decryption end, the encryption and decryption algorithm of this embodiment preferably adopts a symmetric encryption and decryption algorithm. For example, the local end can use the AES encryption algorithm for encryption. Since the network topologies are mirror images of each other, the decryption end uses the corresponding AES decryption algorithm for decryption. At the same time, depending on the encryption level requirements, a 128-bit or 256-bit key is generally used.

[0053] The following situations are included in the processing:

[0054] When the topological node is an encrypted route, a node position code is obtained according to the position of the topological node, and the data to be transmitted received by the topological node is encrypted according to the node position code to obtain node encrypted data; the node position code is used to generate the key required by the symmetric encryption algorithm.

[0055] When it is determined according to the lookup table that the next node of the node is an encrypted route and has a serial structure, the node encrypted data and the node position code are sent to the next node as the data to be transmitted; or, when it is determined according to the lookup table that the next node of the node is an encrypted route and has a parallel structure, the node encrypted data is divided according to the number of parallel nodes, and each divided data, division identifier and node position code is sent as the data to be transmitted to the corresponding multiple next nodes; or, when it is determined according to the lookup table that the next node of the node is a forwarding route, the node encrypted data and the node position code are encapsulated and sent to the forwarding route.

[0056] by Figure 2 Taking the structure as an example, the data to be transmitted is first sent to the encryption router RC1A through T1. The data header of the data to be transmitted carries the characteristic mark of the data to be transmitted. The encryption router RC1A extracts the characteristic mark after parsing and compares the characteristic mark with the pre-stored lookup table. Specifically, the lookup table includes the routing path of the data to be transmitted and the content of the current node processing the data to be transmitted. The encryption router RC1A determines that it is the first routing node, and after processing, it sends the encrypted data through two parallel routing paths. Therefore, the received transmission data is directly encrypted. Since the encrypted data needs to be transmitted in two ways, the encrypted data needs to be split. The specific splitting method can be: split the encrypted data proportionally according to the maximum encryption routing length of each parallel path; add a split field to the encrypted data header after segmentation to mark the segmentation position to facilitate subsequent data combination. The segmented data is then sent separately according to the address of the next routing node in the lookup table. For example, in this embodiment, the maximum route length of the RC2A parallel path is 2 (RC2A-RC4A), while the maximum route length of the RC3A parallel path is 1 (RC2A). Therefore, the data is split in a 1:2 ratio, i.e., the RC2A data volume: RC3A data volume = 1:2. Because the path with the longest path length requires more encryption, resulting in a longer processing time and a larger encrypted data volume, less data is allocated to that path, thereby improving overall processing efficiency.

[0057] Preferably, when it is determined that the topological node is a sink node, the received data to be transmitted sent by a node above the topological node are combined and differentiated by a connection field to form the data to be encrypted of the node.

[0058] To better illustrate the solution of this embodiment, see Figure 3In this topology, part of the data output by RC11 and all the data output by RC12 converge to the same node RC14. Specifically, the encryption router RC10 parses the data to be transmitted and then encrypts it. Since there are two parallel encryption nodes after RC10, data segmentation is required. Since the maximum number of encryption paths for each subsequent path is 3, the data volume is split in a 1:1 manner. When RC11 performs subsequent segmentation, branch RC11 acts as a parallel path to another path RC12 for convergence. During convergence, the two data need to be combined. Therefore, they are connected through the connection field and used to distinguish the two during subsequent decryption.

[0059] The cross-network data transmission method based on topology optimization of this embodiment encrypts the data to be transmitted by planning a communication link with an encrypted topology. This method can avoid the risk of data being intercepted and decrypted, ensuring that only routes that conform to the decryption topology can fully decrypt the data, effectively preventing theft or tampering of data during transmission and significantly improving the security of data transmission. Due to the flexibility of topology adjustment, the encryption topology can be adjusted at any time according to different data characteristics and network environments, thereby achieving data encryption while efficiently transmitting data and improving processing efficiency.

[0060] See Figure 4 , Figure 4 This is a module block diagram of a cross-network data transmission system based on topology optimization provided by an embodiment of the present invention, including:

[0061] A data receiving module, configured to receive data to be transmitted in the first network;

[0062] a topology planning module, configured to plan a communication link having an encrypted topology structure based on the data to be transmitted, wherein the encrypted topology structure includes a plurality of topology nodes, each of which includes an encryption route and a forwarding route, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes being in a parallel structure, and the at least four encrypted routes having at least one serial structure and one parallel structure;

[0063] A topology encryption module is used to send the data to be transmitted to the corresponding topology node according to the encrypted topology structure, so as to encrypt the data to be transmitted when the corresponding topology node is an encryption route, or to generate encrypted data based on the data to be transmitted and send it to the second network when the corresponding topology node is a forwarding route, wherein each parallel structure node sends at least a part of the data to be transmitted, and at least a part of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; accordingly, the remote end has a decryption topology structure that is mirror-symmetric to the encryption topology structure to decrypt the encrypted data.

[0064] In a specific embodiment, the topology encryption module includes:

[0065] an encryption request unit, configured to generate a data processing request frame according to the encrypted topology structure, wherein the data processing request frame includes a feature tag of the data to be transmitted, an identifier of each topological node, a type of each topological node, and a position of each topological node;

[0066] a lookup table generating unit, configured to, after sending the data processing request frame to the corresponding topological node, enable the corresponding topological node to generate a lookup table matching the feature tag of the data to be transmitted based on the feature tag of the data to be transmitted;

[0067] The encryption unit is configured to send the data to be transmitted to a corresponding topological node, so that the corresponding topological node encrypts the data to be transmitted or forwards it to a second network according to the lookup table.

[0068] In a specific embodiment, the encryption unit specifically includes: sending the data to be transmitted to a corresponding topological node, allowing the corresponding topological node to parse the data to be transmitted to obtain a characteristic tag of the data to be transmitted, comparing the characteristic tag of the data to be transmitted with a lookup table, and encrypting or forwarding the data to be transmitted to a second network according to the type of the topological node and the position of the topological node.

[0069] In a specific embodiment, encrypting the data to be transmitted according to the type of the topological node and the position of the topological node includes:

[0070] When the topological node is an encrypted route, a node position code is obtained according to the position of the topological node, and the data to be transmitted received by the topological node is encrypted according to the node position code to obtain node encrypted data;

[0071] When it is determined according to the lookup table that the next node of the node is an encrypted route and has a serial structure, the node encrypted data and the node position code are sent to the next node as the data to be transmitted; or, when it is determined according to the lookup table that the next node of the node is an encrypted route and has a parallel structure, the node encrypted data is divided according to the number of parallel nodes, and each divided data, division identifier and node position code is sent as the data to be transmitted to the corresponding multiple next nodes; or, when it is determined according to the lookup table that the next node of the node is a forwarding route, the node encrypted data and the node position code are encapsulated and sent to the forwarding route.

[0072] In a specific embodiment, when the topological node is determined to be a sink node, the received data to be transmitted sent by a node above the topological node are combined and differentiated by a connection field to form the data to be encrypted of the node.

[0073] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature identified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.

[0074] In the description of this specification, the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification.

[0075] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0076] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A cross-network data transmission method based on topology optimization, applied to a local end, characterized in that: include: receiving data to be transmitted in the first network; Planning a communication link having an encrypted topology structure based on the data to be transmitted, wherein the encrypted topology structure includes a plurality of topology nodes, the topology nodes include encryption routes and forwarding routes, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes are parallel structures, and the at least four encrypted routes have at least one serial structure and one parallel structure; The data to be transmitted is sent to a corresponding topological node according to the encryption topological structure, so that the data to be transmitted is encrypted when the corresponding topological node is an encryption route, and encrypted data is generated based on the data to be transmitted and sent to a second network when the corresponding topological node is a forwarding route, wherein each parallel structure node sends at least a portion of the data to be transmitted, and at least a portion of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; accordingly, the remote end has a decryption topological structure that is mirror-symmetric to the encryption topological structure to decrypt the encrypted data; The method includes: sending the data to be transmitted to a corresponding topology node according to the encryption topology structure, encrypting the data to be transmitted when the corresponding topology node is an encryption route, and forwarding the data to be transmitted to a second network when the corresponding topology node is a forwarding route, including: generating a data processing request frame according to the encrypted topological structure, wherein the data processing request frame includes a characteristic mark of the data to be transmitted, an identifier of each topological node, a type of each topological node, and a position of each topological node; After sending the data processing request frame to the corresponding topological node, the corresponding topological node generates a lookup table matching the feature tag of the data to be transmitted based on the feature tag of the data to be transmitted; Sending the data to be transmitted to a corresponding topological node, so that the corresponding topological node encrypts the data to be transmitted or forwards it to a second network according to the lookup table; Sending the data to be transmitted to a corresponding topological node, so that the corresponding topological node encrypts the data to be transmitted or forwards it to the second network according to the lookup table, includes: The data to be transmitted is sent to the corresponding topological node, so that the corresponding topological node parses the data to be transmitted to obtain a characteristic tag of the data to be transmitted. After comparing the characteristic tag of the data to be transmitted with the lookup table, the data to be transmitted is encrypted or forwarded to the second network according to the type of the topological node and the position of the topological node.

2. The cross-network data transmission method based on topology optimization according to claim 1, characterized in that: Encrypting the data to be transmitted according to the type of the topological node and the position of the topological node includes: When the topological node is an encrypted route, a node position code is obtained according to the position of the topological node, and the data to be transmitted received by the topological node is encrypted according to the node position code to obtain node encrypted data; When it is determined according to the lookup table that the next node of the node is an encrypted route and has a serial structure, the node encrypted data and the node position code are sent to the next node as the data to be transmitted; or, when it is determined according to the lookup table that the next node of the node is an encrypted route and has a parallel structure, the node encrypted data is divided according to the number of parallel nodes, and each divided data, division identifier and node position code is sent as the data to be transmitted to the corresponding multiple next nodes; or, when it is determined according to the lookup table that the next node of the node is a forwarding route, the node encrypted data and the node position code are encapsulated and sent to the forwarding route.

3. The cross-network data transmission method based on topology optimization according to claim 1, characterized in that: When it is determined that the topological node is a sink node, the received data to be transmitted sent by a node above the topological node are combined and differentiated through the connection field to form the data to be encrypted of the node.

4. A cross-network data transmission system based on topology optimization, characterized in that: include: A data receiving module, configured to receive data to be transmitted in the first network; a topology planning module, configured to plan a communication link having an encrypted topology structure based on the data to be transmitted, wherein the encrypted topology structure includes a plurality of topology nodes, each of which includes an encryption route and a forwarding route, the encrypted topology structure includes at least four encrypted routes and at least two forwarding routes connected in sequence, the at least two forwarding routes being in a parallel structure, and the at least four encrypted routes having at least one serial structure and one parallel structure; a topology encryption module, configured to send the data to be transmitted to a corresponding topology node according to the encrypted topology structure, encrypt the data to be transmitted when the corresponding topology node is an encryption route, and generate encrypted data based on the data to be transmitted and send it to a second network when the corresponding topology node is a forwarding route, wherein each parallel structure node sends at least a portion of the data to be transmitted, and at least a portion of the data to be transmitted sent by all parallel structures can be combined to obtain the complete data to be transmitted; accordingly, the remote end has a decryption topology structure that is mirror-symmetric to the encryption topology structure to decrypt the encrypted data; The topology encryption module includes: an encryption request unit, configured to generate a data processing request frame according to the encrypted topology structure, wherein the data processing request frame includes a feature tag of the data to be transmitted, an identifier of each topological node, a type of each topological node, and a position of each topological node; a lookup table generating unit, configured to, after sending the data processing request frame to the corresponding topological node, enable the corresponding topological node to generate a lookup table matching the feature tag of the data to be transmitted based on the feature tag of the data to be transmitted; an encryption unit, configured to send the data to be transmitted to a corresponding topological node, so that the corresponding topological node encrypts the data to be transmitted or forwards it to a second network according to the lookup table; The encryption unit specifically includes: sending the data to be transmitted to the corresponding topological node, allowing the corresponding topological node to parse the data to be transmitted to obtain a characteristic tag of the data to be transmitted, comparing the characteristic tag of the data to be transmitted with the lookup table, and encrypting or forwarding the data to be transmitted to the second network according to the type of the topological node and the position of the topological node.

5. The cross-network data transmission system based on topology optimization according to claim 4 is characterized in that: Encrypting the data to be transmitted according to the type of the topological node and the position of the topological node includes: When the topological node is an encrypted route, a node position code is obtained according to the position of the topological node, and the data to be transmitted received by the topological node is encrypted according to the node position code to obtain node encrypted data; When it is determined according to the lookup table that the next node of the node is an encrypted route and has a serial structure, the node encrypted data and the node position code are sent to the next node as the data to be transmitted; or, when it is determined according to the lookup table that the next node of the node is an encrypted route and has a parallel structure, the node encrypted data is divided according to the number of parallel nodes, and each divided data, division identifier and node position code is sent as the data to be transmitted to the corresponding multiple next nodes; or, when it is determined according to the lookup table that the next node of the node is a forwarding route, the node encrypted data and the node position code are encapsulated and sent to the forwarding route.

6. The cross-network data transmission system based on topology optimization according to claim 4, characterized in that: When it is determined that the topological node is a sink node, the received data to be transmitted sent by a node above the topological node are combined and differentiated through the connection field to form the data to be encrypted of the node.

Citation Information

Patent Citations

  • Dynamic overlay network topology construction method and device based on blockchain cross-chain interaction

    CN112600699A

  • Network layer multipath forwarding method

    CN120034484A