A network environment optimization method and system for trusted data transmission
By optimizing the routing node group and key configuration, the problem of low security in traditional trusted data transmission is solved, and a more secure data transmission path and key management are achieved.
Patent Information
- Application Number
- CN202510925886.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-07-07
AI Technical Summary
In traditional trusted data transmission, fixed-path transmission is easily monitored and cracked by attackers, resulting in a low security factor.
By responding to data transmission requests, obtaining routing node groups and performing path optimization, building a key avoidance space, optimizing transmission paths and key configurations, and ensuring the security of data transmission.
It improves the security of trusted data transmission, avoids path cracking, and enhances the reliability of data transmission.
Smart Images

Figure CN120433940B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data transmission, and in particular to a method and system for optimizing a network environment for trusted data transmission. Background Art
[0002] Traditional trusted data transmission generally follows a fixed path, but fixed-path transmission will form a regular transmission trajectory. Attackers can monitor the long-term traffic of fixed routing nodes, establish a transmission pattern feature library, and then implement encryption analysis or side-channel attacks, resulting in a low data transmission security factor. Summary of the Invention
[0003] The present invention aims to solve the technical problem of low security factor in trusted data transmission in the prior art and provides a network environment optimization method and system for trusted data transmission.
[0004] The technical solution of the present invention to solve the above technical problems is as follows:
[0005] In a first aspect, the present invention provides a method for optimizing a network environment for trusted data transmission, comprising:
[0006] In response to a data transmission request from the first private data space, obtaining a first routing node group and a second routing node group, wherein the first routing node group implements data transmission between the first private data space and the first processing sandbox, and the second routing node group implements data transmission between the first processing sandbox and the blockchain;
[0007] Extracting a second private data space, a transferred data attribute, and a transferred data volume from the data transmission request, wherein the first private data space is a first end of data transmission, and the second private data space is a second end of data transmission;
[0008] performing transmission path optimization of the first routing node group according to the transmission data attribute and the transmission data volume to obtain a first transmission path, and performing transmission path optimization of the second routing node group to obtain a second transmission path;
[0009] A first key avoidance space is constructed by indexing a first historical backtracking key library of the first transmission path to complete configuration of the first key, and a second key avoidance space is constructed by indexing a second historical backtracking key library of the second transmission path to complete configuration of the second key;
[0010] A trusted data transmission environment is configured according to the first key, the first transmission path, the second key, and the second transmission path.
[0011] In a second aspect, the present invention provides a network environment optimization system for trusted data transmission, comprising:
[0012] a data acquisition module, configured to respond to a data transmission request from the first private data space and obtain a first routing node group and a second routing node group, wherein the first routing node group implements data transmission between the first private data space and the first processing sandbox, and the second routing node group implements data transmission between the first processing sandbox and the blockchain;
[0013] a feature extraction module, configured to extract a second private data space, a transferred data attribute, and a transferred data volume from the data transmission request, wherein the first private data space is the first end of the data transmission and the second private data space is the second end of the data transmission;
[0014] a path optimization module, configured to perform transmission path optimization on the first routing node group to obtain a first transmission path, and perform transmission path optimization on the second routing node group to obtain a second transmission path, based on the transmission data attribute and the transmission data volume;
[0015] A key configuration module, configured to construct a first key avoidance space by indexing a first historical backtracking key library of the first transmission path to complete the configuration of the first key, and to construct a second key avoidance space by indexing a second historical backtracking key library of the second transmission path to complete the configuration of the second key;
[0016] The optimized output module is used to configure a trusted data transmission environment according to the first key, the first transmission path, the second key and the second transmission path.
[0017] The beneficial effects of the present invention are:
[0018] Compared with the prior art, the present application first responds to the data transmission request of the first private data space, obtains the first routing node group and the second routing node group, and provides reliable data support for the subsequent data transmission path optimization. Secondly, the second private data space, transmission data attributes and transmission data volume of the data transmission request are extracted, and key information is accurately obtained from the data transmission request, providing a reliable basis for the path optimization of the first routing node group and the second routing node group. Thirdly, according to the transmission data attributes and the transmission data volume, the transmission path optimization of the first routing node group is performed to obtain the first transmission path, and the transmission path optimization of the second routing node group is performed to obtain the second transmission path, thereby obtaining a better data transmission path. Furthermore, a first key avoidance space is constructed by indexing the first historical backtracking key library of the first transmission path to complete the configuration of the first key, and a second key avoidance space is constructed by indexing the second historical backtracking key library of the second transmission path to complete the configuration of the second key, thereby avoiding path cracking. Finally, a trusted data transmission environment is configured based on the first key, the second key, the first transmission path and the second transmission path, thereby improving the security of trusted data transmission.
[0019] Through the above technical solution, this application analyzes data attributes and data volume, and configures a trusted data transmission environment based on the first key, the second key, the first transmission path, and the second transmission path, thereby improving the security of trusted data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 A flow chart of a method for optimizing a network environment for trusted data transmission provided by the present invention;
[0021] Figure 2 This is a structural diagram of a network environment optimization system for trusted data transmission provided by the present invention.
[0022] In the accompanying drawings, the components represented by the reference numerals are as follows:
[0023] Data collection module 11, feature extraction module 12, path optimization module 13, key configuration module 14, optimization output module 15. DETAILED DESCRIPTION
[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present invention.
[0025] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the specified features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.
[0026] In the description of the present invention, the term "for example" is used to mean "used as an example, illustration or illustration". Any embodiment of the present invention described as "for example" is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is given to enable any person skilled in the art to implement and use the present invention. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present invention can be implemented without using these specific details. In other examples, well-known structures and processes are not elaborated in detail to avoid obscuring the description of the present invention with unnecessary details. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed herein.
[0027] Example 1, as Figure 1 As shown, an embodiment of the present invention provides a method for optimizing a network environment for trusted data transmission, including:
[0028] S10: Responding to a data transmission request from the first private data space, obtaining a first routing node group and a second routing node group, wherein the first routing node group implements data transmission between the first private data space and the first processing sandbox, and the second routing node group implements data transmission between the first processing sandbox and the blockchain;
[0029] In the trusted data space architecture, data transfer follows a fixed path: private data space → sandbox → blockchain → target sandbox → target private data space. Data is available but invisible during circulation, enabling secure cross-domain data sharing. Specifically, when a user (i.e., a private data space) initiates a cross-domain data exchange request, raw sensitive data is transferred from the source private data space to a sandbox (such as a Trusted Execution Environment (TEE) or a containerized security sandbox). Within the sandbox, pre-processing operations (such as data desensitization, format conversion, and encryption) are performed to ensure that only necessary, sanitized data enters subsequent processes. The pre-processed data and corresponding integrity verification information (such as a SHA-256 hash value) are then transmitted to the blockchain, where it is stored as evidence using the blockchain's immutable nature, forming a traceable digital fingerprint record. Furthermore, when the target private data space initiates a data retrieval request, the processed data and evidence stored on the blockchain are transmitted via a first routing node group to the target sandbox. The target sandbox verifies data integrity through a hash comparison and then performs secondary verification (such as compliance checks and format adaptation) according to the target domain's rules to ensure that the data meets the recipient's requirements. After verification, the processed data securely enters the target private data space for user use or analysis. However, during traditional fixed-path transmission, a large amount of historical data can be easily reverse-engineered, resulting in a low security factor.
[0030] To address the above issues, this application, within a trusted data space architecture, first responds to data transmission requests from the first private data space (i.e., the user) and obtains a first routing node group and a second routing node group. The first routing node group facilitates raw data transmission between the first private data space and the first processing sandbox, ensuring that sensitive data undergoes pre-processing (e.g., encryption and desensitization) within the securely isolated sandbox. The second routing node group facilitates data transmission between the first processing sandbox and the blockchain, securely storing the desensitized data. This provides reliable data support for subsequent optimization of data transmission paths.
[0031] S20: Extracting a second private data space, a transferred data attribute, and a transferred data volume from the data transmission request, wherein the first private data space is a first end of data transmission, and the second private data space is a second end of data transmission;
[0032] In this embodiment, the second private data space (data transmission destination), data attributes (such as data type and sensitivity level), and data volume of the data transmission request are extracted. The first private data space represents the first end (i.e., the data transmission starting point), while the second private data space represents the second end (i.e., the data transmission destination). Together, these spaces define the physical boundaries of the data flow. The data attributes determine data preprocessing rules (such as whether encryption, desensitization, or format conversion is required) and security level requirements. For example, medical imaging data prioritizes high-security transmission channels, while log-type text data prioritizes low-latency paths. Data volume directly influences path resource allocation: small data volumes prioritize lightweight paths to reduce energy consumption, while large data volumes require high-bandwidth nodes to avoid congestion. This allows accurate extraction of key information from data transmission requests. By integrating this key information, a reliable basis can be provided for path optimization within the first routing node group (first private data space → first processing sandbox) and the second routing node group (first processing sandbox → blockchain).
[0033] S30: performing transmission path optimization of the first routing node group according to the transmission data attribute and the transmission data volume to obtain a first transmission path, and performing transmission path optimization of the second routing node group to obtain a second transmission path;
[0034] Traditional trusted data transmission generally follows a fixed path. During the data transmission process along the fixed path, the original data and pre-processed data are mixed, which can easily lead to resource waste (such as high bandwidth being idle) or congestion (such as small bandwidth carrying large amounts of data).
[0035] To address the above issues, the present application performs transmission path optimization of the first routing node group based on the transmission data attributes and the transmission data volume to obtain the first transmission path, and performs transmission path optimization of the second routing node group to obtain the second transmission path.
[0036] Specifically, step S30 in the method includes:
[0037] When the data transmission request is to send data, the transmission data attributes include to-be-processed data attributes and target transmission data attributes, wherein the to-be-processed data attributes are data attributes that need to be pre-processed before transmission, and the target transmission data attributes are expected data attributes after pre-processing the to-be-processed data attributes;
[0038] According to the attributes of the data to be processed and the attributes of the target transmission data, the data processing rules are matched, and the target transmission statistical data quantity of the historical processing sample group of the data processing rules is calculated in combination with the amount of data to be processed;
[0039] performing transmission path optimization of the first routing node group according to the amount of data to be processed to obtain the first transmission path;
[0040] According to the target transmission statistical data, a transmission path optimization of the second routing node group is performed to obtain the second transmission path.
[0041] In an embodiment of the present application, when the data transmission request is to send data, the transmission data attributes include attributes of the data to be processed and attributes of the target transmission data. The attributes of the data to be processed are those that require preprocessing before transmission. These are the inherent characteristics of the original data before transmission, such as the data format (e.g., JSON, XML, DICOM, etc.), sensitivity level (e.g., personal privacy data, commercial secrets, etc.), and processing requirements (e.g., encryption, desensitization, etc.). For example, the attributes of the data to be processed are medical imaging data (in DICOM format) containing patient ID information. The attributes of the target transmission data are the desired data attributes after preprocessing the attributes of the data to be processed, such as the desired encryption type (e.g., AES-256, RSA, etc.), desensitization level (e.g., K-anonymity, L-diversity, etc.), and compression ratio (e.g., 70% volume reduction). For example, the attributes of the target transmission data are medical imaging data (in JPEG format) with the patient ID information desensitized. This subdivision of the transmission data attributes into attributes of the data to be processed and attributes of the target transmission data provides the necessary data support for subsequent path optimization.
[0042] Next, data processing rules are matched based on the attributes of the data to be processed and the target data to be transmitted. The target transmission statistics of the sample group are then processed based on historical data processing rules for statistical processing of the data volume to be processed. Specifically, data processing rules are the specific operational methods for converting the attributes of the data to be processed into the attributes of the target data to be transmitted. Examples include encryption rules (e.g., AES-256 encryption for sensitive fields), desensitization rules (e.g., obfuscating names), and compression rules (e.g., JPEG compression for image data). Data processing rules can be matched by searching attribute tags within a pre-defined rule library. For example, the attributes of the data to be processed (e.g., medical images in DICOM format, including patient ID information) and the attributes of the target data to be transmitted (e.g., medical images in JPEG format, with patient ID information desensitized) are matched to data processing rules (e.g., DICOM to JPEG with ID field removal). Furthermore, historical records matching the currently matched rule are filtered based on the data processing rule (e.g., DICOM to JPEG with ID field removal), and their data volumes are counted. The data volumes of historical samples matching the same processing rule are then analyzed.
[0043] Furthermore, based on the amount of data to be processed, a transmission path optimization search is performed for the first routing node group to obtain the first transmission path. Specifically, a router state evaluation index is first obtained. The router state evaluation index is calibrated based on the amount of data to be processed and based on a routing state matching table to obtain a baseline characteristic value for the router evaluation index. A path fitness function is then constructed based on the baseline characteristic value for the router evaluation index and the evaluation index weight distribution. Based on the first routing node group, several data transmission paths are constructed between the first private data space and the first processing sandbox. Finally, based on the path fitness function, the multiple data transmission paths are optimized for maximum fitness to obtain the first transmission path.
[0044] Finally, based on the target transmission statistical data amount, a transmission path optimization search is performed on the second routing node group to obtain the second transmission path. Specifically, when the data transmission request is to receive data, based on the amount of transmitted data, a transmission path optimization search is performed on the first routing node group to obtain the first transmission path, and a transmission path optimization search is performed on the second routing node group to obtain the second transmission path.
[0045] Furthermore, the step of “optimizing the transmission path of the first routing node group according to the amount of data to be processed to obtain the first transmission path” includes:
[0046] Obtaining a router status evaluation index, wherein the router status evaluation index has a predefined evaluation index weight distribution;
[0047] According to the amount of data to be processed, calibrate the router status evaluation index based on the routing status matching table to obtain a router evaluation index benchmark characteristic value;
[0048] According to the router evaluation index benchmark characteristic value and the evaluation index weight distribution, a path fitness function is constructed:
[0049] ,
[0050] in, represents the path fitness, M represents the total number of path router nodes, Q represents the total number of evaluation index attributes, Characterize the characteristic value of the i-th attribute evaluation index of the j-th router, Characterize the benchmark characteristic value of the i-th attribute evaluation index of the j-th router, Characterizes a small constant, M ≥ 1, Represents the weight of the evaluation index of the i-th attribute;
[0051] Constructing, based on the first routing node group, several data transmission paths between the first private data space and the first processing sandbox;
[0052] Based on the path fitness function, the plurality of data transmission paths are optimized for maximum fitness to obtain the first transmission path.
[0053] In an embodiment of the present application, router status evaluation indicators (such as Q attributes such as bandwidth, delay, load rate, and security) are first obtained, where the router status evaluation indicators have a predefined evaluation indicator weight distribution, that is, each evaluation indicator is assigned a predefined weight. The weight is determined by those skilled in the art based on actual conditions. For example, a predefined bandwidth weight of 0.4, a delay weight of 0.3, a security weight of 0.2, and a load rate weight of 0.1 are predefined. Different weights can reflect the importance of different evaluation indicators.
[0054] Secondly, based on the amount of data to be processed, the router state evaluation index is calibrated based on the routing state matching table to obtain a router evaluation index baseline characteristic value. The routing state matching table is a predefined multidimensional mapping table that can dynamically match the router evaluation index baseline characteristic value based on the amount of data to be processed. For example, if the amount of data to be processed is 100MB, the routing state matching table matches the bandwidth baseline value of 120MB / s (ensuring transmission completion within 1 second) and the delay baseline value of ≤50ms. In this way, the baseline characteristic value is dynamically adjusted based on the amount of data to be processed. When the data amount is large, a high-bandwidth path is preferentially selected, and when the data amount is small, a low-bandwidth path is preferentially selected, so that the transmission path is more in line with actual needs.
[0055] Next, a path fitness function is constructed based on the router evaluation index benchmark characteristic value and the evaluation index weight distribution:
[0056] ,
[0057] in, represents the path fitness, M represents the total number of path router nodes, Q represents the total number of evaluation index attributes, Characterize the characteristic value of the i-th attribute evaluation index of the j-th router, Characterize the benchmark characteristic value of the i-th attribute evaluation index of the j-th router, Characterizes a small constant, M ≥ 1, Represents the weight of the evaluation index of the i-th attribute. Specifically, the path fitness The larger the constant, the better the path. Avoid numerator / denominator being 0, the weight of the i-th attribute evaluation index The use of an exponential function, reflecting the importance of different evaluation metrics, aims to make the impact of each metric more pronounced and enhance robustness against outliers. Furthermore, the path fitness function simultaneously considers multiple evaluation metrics, such as bandwidth, latency, security, and load factor, to avoid irrational path selection due to a single metric. By calculating the path fitness of multiple data transmission paths and then optimizing for the maximum fitness, the optimal transmission path solution is found among conflicting metrics such as bandwidth, latency, and security.
[0058] Furthermore, based on the first routing node group, several data transmission paths between the first privacy data space and the first processing sandbox are constructed. Specifically, with the first privacy data space as the starting point and the first processing sandbox as the end point, all possible path combinations are generated in the first routing node group based on the network topology. For example, with the first privacy data space (A) as the starting point and the first processing sandbox (C) as the end point, path 1: A→B→C, path 2: A→D→C, and path 2: A→E→C are constructed. Furthermore, necessary constraints can be set, for example, setting the path length M ≤ 10 to avoid excessive delays caused by too long paths; setting the load rate of each router node ≤ 70% to ensure node availability.
[0059] Finally, based on the path fitness function, the multiple data transmission paths are optimized for the maximum fitness value to obtain the first transmission path. Specifically, the path fitness function is used to calculate the fitness value of each candidate path, and the path with the maximum fitness value is selected as the first transmission path. For example, if the fitness values of three paths are calculated, and the fitness value of path 1 is 0.82, the fitness value of path 2 is 0.75, and the fitness value of path 3 is 0.91, then path 3, with the maximum fitness value, is selected as the first transmission path.
[0060] Furthermore, the “optimizing the plurality of data transmission paths for maximum fitness based on the path fitness function to obtain the first transmission path” includes:
[0061] Based on the path fitness function, performing fitness evaluation on the plurality of data transmission paths to obtain a plurality of fitness evaluation values;
[0062] Performing path similarity evaluation on the plurality of data transmission paths to obtain a path similarity set, wherein the path similarity is equal to the ratio of the number of routers with the same sequence number and bit number to the number of routers in the union of the two compared paths;
[0063] Clustering the plurality of data transmission paths based on a path similarity threshold and in combination with the path similarity set to obtain a plurality of groups of data transmission paths;
[0064] Based on the fitness evaluation values, the maximum fitness data transmission path of the group with the largest fitness mean is selected, and the data transmission paths of the entire group of the group with the smallest fitness mean are subjected to path similarity reduction mutation with the maximum fitness data transmission path to obtain an expanded data transmission path, and the number of iterations is increased by one, with the initial number of iterations being equal to 0;
[0065] When the number of iterations meets the preset number of iterations, the data transmission path with the maximum global fitness value is output and set as the first transmission path.
[0066] In the embodiment of the present application, the fitness of the plurality of data transmission paths is first evaluated based on the path fitness function to obtain a plurality of fitness evaluation values. Specifically, the path fitness of the plurality of data transmission paths (e.g., path 1, path 2, ..., path N) generated based on the aforementioned path fitness function is calculated to obtain a plurality of fitness evaluation values.
[0067] Next, a path similarity evaluation is performed on the data transmission paths to obtain a path similarity set. Path similarity is the ratio of the number of routers with the same sequence number and bit number to the number of routers in the union of the two paths being compared. Specifically, path similarity = number of intersections / number of unions = number of routers with the same sequence number and bit number / total number of routers in both paths. For example, if path 1 is A→B→C→D and path 2 is A→E→C→D, and the number of routers with the same sequence number and bit number in paths 1 and 2 is 3, and the total number of routers in both paths is 5, then path similarity = 3 / 5 = 0.6.
[0068] Next, based on a path similarity threshold, the data transmission paths are clustered in combination with the path similarity set to obtain multiple groups of data transmission paths. Specifically, the path similarity threshold is a pre-set value, such as 0.5. The data transmission paths are then clustered in combination with the path similarity set, for example, Group 1: {Path 1, Path 2, Path 3}, Group 2: {Path 4, Path 5}, and Group 3: {Path 6, Path 7}. Path groups with high similarity may share multiple common nodes (such as a router), resulting in local optima. Local optima are avoided by optimizing the transmission paths of path groups with low similarity.
[0069] Furthermore, based on the fitness evaluation values, the maximum fitness data transmission path of the group with the largest fitness mean is selected, and a path similarity reduction mutation is performed on all data transmission paths of the group with the smallest fitness mean to obtain an expanded data transmission path. The number of iterations is increased by one, and the initial number of iterations is equal to 0. Specifically, the fitness means of the multiple groups of data transmission paths are first calculated. For example, the fitness means of group 1 are calculated to be 0.73, the fitness means of group 2 are 0.82, and the fitness means of group 3 are 0.86. The fitness mean of group 3 is the largest, and the fitness mean of group 1 is the smallest. The maximum fitness data transmission path within group 3 is selected, and a path similarity reduction mutation is performed on all data transmission paths of group 1. Furthermore, the maximum fitness data transmission path of the group with the largest fitness mean is used as the mutation target to ensure the correct optimization direction. The path group of the group with the smallest fitness mean is subjected to reduction mutation to accelerate the elimination of inefficient paths. For example, the maximum fitness data transmission path of the group with the largest fitness mean is A→B→C→D, and the path k within the group with the smallest fitness mean is A→E→F→D. The path k is mutated to A→B→F→D to obtain the expanded data transmission path, the fitness evaluation value of the mutated path is calculated, and the number of iterations is increased by one. As the number of iterations increases, the path fitness value increases monotonically and eventually converges to the vicinity of the global optimal solution.
[0070] Finally, when the number of iterations reaches a preset number, the data transmission path with the highest global fitness is output and set as the first transmission path. Specifically, the iteration terminates when the number of iterations reaches a preset number (e.g., 10), at which point the path with the highest global fitness is output as the first transmission path. In this way, by reducing variation over multiple iterations, local optima are avoided.
[0071] Furthermore, the step of “performing transmission path optimization of the first routing node group based on the transmission data attribute and the transmission data volume to obtain a first transmission path, and performing transmission path optimization of the second routing node group to obtain a second transmission path” includes:
[0072] When the data transmission request is to receive data, based on the amount of transmitted data, the transmission path optimization of the first routing node group is performed to obtain a first transmission path, and the transmission path optimization of the second routing node group is performed to obtain a second transmission path.
[0073] In this embodiment of the present application, when a data reception request is received, since the transmitted data has already undergone preprocessing (e.g., encryption, desensitization, etc.), its transmission data attributes (e.g., format, security level, etc.) and data volume are predetermined. There is no need to match preprocessing rules as is required for sending data. Instead, transmission path optimization between the first routing node group and the second routing node group can be performed directly based on the data volume. Specifically, following the same method described above, transmission path optimization is performed for the first routing node group based on the path fitness function to obtain a first transmission path. Path optimization is then performed for data transmission between the first processing sandbox and the blockchain in the second routing node group to obtain a second transmission path. Compared to sending data, path optimization for receiving data simplifies input parameters and avoids complex preprocessing-related computations through parallel optimization, thereby improving efficiency.
[0074] In summary, compared to the prior art, this application performs transmission path optimization on a first routing node group based on the attributes and amount of transmitted data to obtain a first transmission path, and then performs transmission path optimization on a second routing node group to obtain a second transmission path. In this way, a more optimal transmission path is matched based on the data attributes and amount of data.
[0075] S40: constructing a first key avoidance space by indexing the first historical backtracking key library of the first transmission path to complete the configuration of the first key, and constructing a second key avoidance space by indexing the second historical backtracking key library of the second transmission path to complete the configuration of the second key;
[0076] If the new and old keys are similar (the Hamming distance is small), it is possible to infer some bits of the new key through the historical key library, and then crack the encrypted data (such as differential attacks on algorithms such as AES and RSA), resulting in low data transmission security.
[0077] To address the above problem, the present application constructs a first key avoidance space by indexing the first historical backtracking key library of the first transmission path to complete the configuration of the first key, and constructs a second key avoidance space by indexing the second historical backtracking key library of the second transmission path to complete the configuration of the second key.
[0078] Specifically, step S40 in the method includes:
[0079] Randomly generate a key to be selected;
[0080] Calculate the mean Hamming distance between the candidate key and all keys in the first key avoidance space, and set the mean Hamming distance as the avoidance coefficient;
[0081] When the avoidance coefficient meets the avoidance coefficient threshold, the candidate key is set to the first key; otherwise, the candidate key is updated to execute a loop.
[0082] In the embodiment of the present application, a candidate key is first randomly generated. For example, a binary string that meets the key length requirements is generated based on a cryptographically secure random number generator (such as a SHA-256 hash derivative), for example, a 256-bit AES candidate key is generated.
[0083] Next, the mean Hamming distance between the candidate key and all keys in the first key avoidance space is calculated and set as the avoidance coefficient. The first key avoidance space is the set of all keys previously used on the first transmission path, and the mean Hamming distance between all keys in the first key avoidance space is calculated.
[0084] Finally, if the avoidance coefficient meets the avoidance coefficient threshold, the candidate key is set as the first key. Otherwise, the candidate key is updated and the cycle is repeated. The avoidance coefficient threshold is a preset avoidance coefficient threshold. For example, the threshold is set to avoidance coefficient / 2. When the avoidance coefficient is greater than or equal to the avoidance coefficient threshold, the candidate key is sufficiently different from the historical key and is set as the first key. When the avoidance coefficient is less than the avoidance coefficient threshold, the iterative optimization is continued through the mutation operation until the condition is met, thereby completing the configuration of the first key.
[0085] Furthermore, according to the same method, the second history backtracking key library of the second transmission path is indexed to construct a second key avoidance space to complete the configuration of the second key.
[0086] In summary, compared to the prior art, this application constructs a first key avoidance space by indexing the first historical backtracking key library of the first transmission path to complete the configuration of the first key, and constructs a second key avoidance space by indexing the second historical backtracking key library of the second transmission path to complete the configuration of the second key. Thus, by constructing a key avoidance space and introducing Hamming distance mean evaluation, it ensures that the newly generated key is sufficiently different from the historical key, thereby improving the security of data transmission.
[0087] S50: Configure a trusted data transmission environment according to the first key, the first transmission path, the second key and the second transmission path.
[0088] In this embodiment, a trusted data transmission environment is configured based on a first key, a second key, and first and second transmission paths. Specifically, the first transmission path (privacy space → first processing sandbox) dynamically calibrates the router status baseline value based on the amount of data to be processed, uses a fitness function to optimize the optimal transmission path, and encrypts the original data using a first key that meets the avoidance coefficient, ensuring efficient and secure transmission of sensitive data. The second transmission path, based on received data requests and the known amount of data, is then optimized, and the trusted data transmission environment is configured accordingly, enhancing the security of trusted data transmission.
[0089] In summary, the embodiments of the present application have at least the following technical effects:
[0090] Compared with the existing technology, this application first responds to the data transmission request of the first private data space, obtains the first routing node group and the second routing node group, and provides reliable data support for subsequent data transmission path optimization.
[0091] Secondly, the second privacy data space, transmission data attributes and transmission data volume of the data transmission request are extracted, and key information is accurately obtained from the data transmission request to provide differentiated path optimization basis for the first routing node group and the second routing node group.
[0092] Again, based on the attributes and amount of transmitted data, the transmission path optimization of the first routing node group is performed to obtain the first transmission path, and the transmission path optimization of the second routing node group is performed to obtain the second transmission path. In this way, a better transmission path is matched based on the data attributes and data amount.
[0093] Furthermore, a first key avoidance space is constructed by indexing the first historical backtracking key library of the first transmission path to complete the configuration of the first key. A second key avoidance space is constructed by indexing the second historical backtracking key library of the second transmission path to complete the configuration of the second key. In this way, by constructing a key avoidance space and introducing the Hamming distance mean evaluation, the newly generated key is ensured to be sufficiently different from the historical key, thereby improving the security of data transmission.
[0094] Finally, a trusted data transmission environment is configured based on the first key, the second key, the first transmission path, and the second transmission path, thereby improving the security of trusted data transmission.
[0095] Through the above technical solution, this application analyzes data attributes and data volume, and configures a trusted data transmission environment based on the first key, the second key, the first transmission path, and the second transmission path, thereby improving the security of trusted data transmission.
[0096] Example 2, as Figure 2As shown, based on the same inventive concept as the method for optimizing a network environment for trusted data transmission provided in the first embodiment, the embodiment of the present invention further provides a system for optimizing a network environment for trusted data transmission, including:
[0097] Data collection module 11, configured to respond to a data transmission request from the first private data space and obtain a first routing node group and a second routing node group, wherein the first routing node group enables data transmission between the first private data space and the first processing sandbox, and the second routing node group enables data transmission between the first processing sandbox and the blockchain;
[0098] a feature extraction module 12, configured to extract a second private data space, a transferred data attribute, and a transferred data volume from the data transmission request, wherein the first private data space is the first end of the data transmission and the second private data space is the second end of the data transmission;
[0099] a path optimization module 13 configured to perform transmission path optimization on the first routing node group to obtain a first transmission path, and perform transmission path optimization on the second routing node group to obtain a second transmission path, based on the transmission data attribute and the transmission data volume;
[0100] A key configuration module 14 is configured to construct a first key avoidance space by indexing a first historical backtracking key library of the first transmission path to complete the configuration of the first key, and to construct a second key avoidance space by indexing a second historical backtracking key library of the second transmission path to complete the configuration of the second key;
[0101] The optimization output module 15 is configured to configure a trusted data transmission environment according to the first key, the first transmission path, the second key and the second transmission path.
[0102] The data acquisition module 11 is specifically used for:
[0103] In response to a data transmission request from the first private data space, a first routing node group and a second routing node group are obtained, wherein the first routing node group implements data transmission between the first private data space and the first processing sandbox, and the second routing node group implements data transmission between the first processing sandbox and the blockchain.
[0104] The feature extraction module 12 is specifically configured to:
[0105] Extracting a second private data space, a transmission data attribute, and a transmission data volume of the data transmission request, wherein the first private data space is a first end of data transmission, and the second private data space is a second end of data transmission.
[0106] The path optimization module 13 is specifically configured to:
[0107] When the data transmission request is to send data, the transmission data attributes include to-be-processed data attributes and target transmission data attributes, wherein the to-be-processed data attributes are data attributes that need to be pre-processed before transmission, and the target transmission data attributes are expected data attributes after pre-processing the to-be-processed data attributes;
[0108] According to the attributes of the data to be processed and the attributes of the target transmission data, the data processing rules are matched, and the target transmission statistical data quantity of the historical processing sample group of the data processing rules is calculated in combination with the amount of data to be processed;
[0109] performing transmission path optimization of the first routing node group according to the amount of data to be processed to obtain the first transmission path;
[0110] According to the target transmission statistical data, a transmission path optimization of the second routing node group is performed to obtain the second transmission path.
[0111] Furthermore, the step of “matching data processing rules according to the attributes of the data to be processed and the attributes of the target transmission data, and calculating the target transmission statistical data of the historical processing sample group of the data processing rules in combination with the amount of data to be processed” includes:
[0112] Performing data volume fluctuation ratio statistics based on the historical processing sample group to obtain a data volume fluctuation ratio set, wherein the data volume fluctuation ratio is equal to the ratio of the target record data volume to the record data volume to be processed;
[0113] Performing a central tendency analysis on the data volume fluctuation ratio set to obtain a data volume fluctuation ratio fitting value;
[0114] The product of the data volume fluctuation ratio fitting value and the amount of data to be processed is calculated to obtain the target transmission statistical data amount.
[0115] Furthermore, the step of “optimizing the transmission path of the first routing node group according to the amount of data to be processed to obtain the first transmission path” includes:
[0116] Obtaining a router status evaluation index, wherein the router status evaluation index has a predefined evaluation index weight distribution;
[0117] According to the amount of data to be processed, calibrate the router status evaluation index based on the routing status matching table to obtain a router evaluation index benchmark characteristic value;
[0118] According to the router evaluation index benchmark characteristic value and the evaluation index weight distribution, a path fitness function is constructed:
[0119] ,
[0120] in, represents the path fitness, M represents the total number of path router nodes, Q represents the total number of evaluation index attributes, Characterize the characteristic value of the i-th attribute evaluation index of the j-th router, Characterize the benchmark characteristic value of the i-th attribute evaluation index of the j-th router, Characterizes a small constant, M ≥ 1, Represents the weight of the evaluation index of the i-th attribute;
[0121] Constructing, based on the first routing node group, several data transmission paths between the first private data space and the first processing sandbox;
[0122] Based on the path fitness function, the plurality of data transmission paths are optimized for maximum fitness to obtain the first transmission path.
[0123] Furthermore, the “optimizing the plurality of data transmission paths for maximum fitness based on the path fitness function to obtain the first transmission path” includes:
[0124] Based on the path fitness function, performing fitness evaluation on the plurality of data transmission paths to obtain a plurality of fitness evaluation values;
[0125] Performing path similarity evaluation on the plurality of data transmission paths to obtain a path similarity set, wherein the path similarity is equal to the ratio of the number of routers with the same sequence number and bit number to the number of routers in the union of the two compared paths;
[0126] Clustering the plurality of data transmission paths based on a path similarity threshold and in combination with the path similarity set to obtain a plurality of groups of data transmission paths;
[0127] Based on the fitness evaluation values, the maximum fitness data transmission path of the group with the largest fitness mean is selected, and the data transmission paths of the entire group of the group with the smallest fitness mean are subjected to path similarity reduction mutation with the maximum fitness data transmission path to obtain an expanded data transmission path, and the number of iterations is increased by one, with the initial number of iterations being equal to 0;
[0128] When the number of iterations meets the preset number of iterations, the data transmission path with the maximum global fitness value is output and set as the first transmission path.
[0129] Furthermore, the step of “performing transmission path optimization of the first routing node group based on the transmission data attribute and the transmission data volume to obtain a first transmission path, and performing transmission path optimization of the second routing node group to obtain a second transmission path” includes:
[0130] When the data transmission request is to receive data, based on the amount of transmitted data, the transmission path optimization of the first routing node group is performed to obtain a first transmission path, and the transmission path optimization of the second routing node group is performed to obtain a second transmission path.
[0131] The key configuration module 14 is specifically configured to:
[0132] Randomly generate a key to be selected;
[0133] Calculate the mean Hamming distance between the candidate key and all keys in the first key avoidance space, and set the mean Hamming distance as the avoidance coefficient;
[0134] When the avoidance coefficient meets the avoidance coefficient threshold, the candidate key is set to the first key; otherwise, the candidate key is updated to execute a loop.
[0135] The optimization output module 15 is specifically configured to:
[0136] A trusted data transmission environment is configured according to the first key, the first transmission path, the second key, and the second transmission path.
[0137] In summary, the embodiments of the present application have at least the following technical effects:
[0138] Compared with the prior art, the present application first responds to the data transmission request of the first private data space through the data acquisition module, obtains the first routing node group and the second routing node group, and provides reliable data support for the subsequent data transmission path optimization. Secondly, through the feature extraction module, the second private data space, transmission data attributes and transmission data volume of the data transmission request are extracted, and key information is accurately obtained from the data transmission request, providing a reliable basis for the path optimization of the first routing node group and the second routing node group. Thirdly, through the path optimization module, according to the transmission data attributes and transmission data volume, the transmission path optimization of the first routing node group is performed to obtain the first transmission path, and the transmission path optimization of the second routing node group is performed to obtain the second transmission path, thereby obtaining a more optimal data transmission path. Furthermore, through the key configuration module, the first key avoidance space is constructed by indexing the first historical backtracking key library of the first transmission path to complete the configuration of the first key, and the second key avoidance space is constructed by indexing the second historical backtracking key library of the second transmission path to complete the configuration of the second key, thereby avoiding path cracking. Finally, by optimizing the output module, a trusted data transmission environment is configured based on the first key, the second key, the first transmission path, and the second transmission path, thereby improving the security of trusted data transmission.
[0139] It should be noted that, in the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0140] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0141] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0142] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0143] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0144] Although preferred embodiments of the present invention have been described, additional changes and modifications to these embodiments may occur to those skilled in the art once the basic inventive concepts become known.
[0145] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention and its equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A method for optimizing a network environment for trusted data transmission, characterized in that: The first digital sandbox for a trusted data space architecture, including: In response to a data transmission request from the first private data space, obtaining a first routing node group and a second routing node group, wherein the first routing node group implements data transmission between the first private data space and the first processing sandbox, and the second routing node group implements data transmission between the first processing sandbox and the blockchain; Extracting a second private data space, a transferred data attribute, and a transferred data volume from the data transmission request, wherein the first private data space is a first end of data transmission, and the second private data space is a second end of data transmission; performing transmission path optimization on the first routing node group according to the transmission data attribute and the transmission data volume to obtain a first transmission path, and performing transmission path optimization on the second routing node group to obtain a second transmission path; A first key avoidance space is constructed by indexing a first historical backtracking key library of the first transmission path to complete configuration of the first key, and a second key avoidance space is constructed by indexing a second historical backtracking key library of the second transmission path to complete configuration of the second key; A trusted data transmission environment is configured according to the first key, the first transmission path, the second key, and the second transmission path.
2. The method according to claim 1, wherein According to the transmission data attribute and the transmission data volume, performing transmission path optimization of the first routing node group to obtain a first transmission path, and performing transmission path optimization of the second routing node group to obtain a second transmission path, comprising: When the data transmission request is to send data, the transmission data attributes include to-be-processed data attributes and target transmission data attributes, wherein the to-be-processed data attributes are data attributes that need to be pre-processed before transmission, and the target transmission data attributes are expected data attributes after pre-processing the to-be-processed data attributes; According to the attributes of the data to be processed and the attributes of the target transmission data, matching the data processing rules, and combining the amount of data to be processed with the target transmission statistical data amount of the historical processing sample group of the data processing rules; performing transmission path optimization of the first routing node group according to the amount of data to be processed to obtain the first transmission path; According to the target transmission statistical data, a transmission path optimization of the second routing node group is performed to obtain the second transmission path.
3. The method according to claim 2, wherein According to the attributes of the data to be processed and the attributes of the target transmission data, matching the data processing rules, and combining the amount of data to be processed with the target transmission statistical data of the historical processing sample group of the data processing rules, including: Performing data volume fluctuation ratio statistics based on the historical processing sample group to obtain a data volume fluctuation ratio set, wherein the data volume fluctuation ratio is equal to the ratio of the target record data volume to the record data volume to be processed; Performing a central tendency analysis on the data volume fluctuation ratio set to obtain a data volume fluctuation ratio fitting value; The product of the data volume fluctuation ratio fitting value and the amount of data to be processed is calculated to obtain the target transmission statistical data amount.
4. The method according to claim 2, wherein Optimizing the transmission path of the first routing node group according to the amount of data to be processed to obtain the first transmission path includes: Obtaining a router status evaluation index, wherein the router status evaluation index has a predefined evaluation index weight distribution; According to the amount of data to be processed, calibrate the router status evaluation index based on the routing status matching table to obtain a router evaluation index benchmark characteristic value; According to the router evaluation index benchmark characteristic value and the evaluation index weight distribution, a path fitness function is constructed: , in, represents the path fitness, M represents the total number of path router nodes, Q represents the total number of evaluation index attributes, Characterize the characteristic value of the i-th attribute evaluation index of the j-th router, Characterize the benchmark characteristic value of the i-th attribute evaluation index of the j-th router, Characterizes a small constant, M ≥ 1, Represents the weight of the evaluation index of the i-th attribute; Constructing, based on the first routing node group, several data transmission paths between the first private data space and the first processing sandbox; Based on the path fitness function, the plurality of data transmission paths are optimized for maximum fitness to obtain the first transmission path.
5. The method according to claim 4, wherein Based on the path fitness function, optimizing the plurality of data transmission paths for maximum fitness to obtain the first transmission path includes: Based on the path fitness function, performing fitness evaluation on the plurality of data transmission paths to obtain a plurality of fitness evaluation values; Performing path similarity evaluation on the plurality of data transmission paths to obtain a path similarity set, wherein the path similarity is equal to the ratio of the number of routers with the same sequence number and bit number to the number of routers in the union of the two compared paths; Clustering the plurality of data transmission paths based on a path similarity threshold and in combination with the path similarity set to obtain a plurality of groups of data transmission paths; Based on the fitness evaluation values, the maximum fitness data transmission path of the group with the largest fitness mean is selected, and the data transmission paths of the entire group of the group with the smallest fitness mean are subjected to path similarity reduction mutation with the maximum fitness data transmission path to obtain an expanded data transmission path, and the number of iterations is increased by one, with the initial number of iterations being equal to 0; When the number of iterations meets the preset number of iterations, the data transmission path with the maximum global fitness value is output and set as the first transmission path.
6. The method according to claim 1, wherein According to the transmission data attribute and the transmission data volume, performing transmission path optimization of the first routing node group to obtain a first transmission path, and performing transmission path optimization of the second routing node group to obtain a second transmission path, comprising: When the data transmission request is to receive data, based on the amount of transmitted data, the transmission path optimization of the first routing node group is performed to obtain a first transmission path, and the transmission path optimization of the second routing node group is performed to obtain a second transmission path.
7. The method according to claim 1, wherein Constructing a first key avoidance space by indexing a first historical backtracking key library of the first transmission path to complete configuration of the first key includes: Randomly generate a key to be selected; Calculate the mean Hamming distance between the candidate key and all keys in the first key avoidance space, and set the mean Hamming distance as the avoidance coefficient; When the avoidance coefficient meets the avoidance coefficient threshold, the candidate key is set to the first key; otherwise, the candidate key is updated to execute a loop.
8. A network environment optimization system for trusted data transmission, characterized in that: Used to perform the method according to any one of claims 1 to 7, comprising: a data acquisition module, configured to respond to a data transmission request from the first private data space and obtain a first routing node group and a second routing node group, wherein the first routing node group implements data transmission between the first private data space and the first processing sandbox, and the second routing node group implements data transmission between the first processing sandbox and the blockchain; a feature extraction module, configured to extract a second private data space, a transferred data attribute, and a transferred data volume from the data transmission request, wherein the first private data space is the first end of the data transmission and the second private data space is the second end of the data transmission; a path optimization module, configured to perform transmission path optimization on the first routing node group to obtain a first transmission path, and perform transmission path optimization on the second routing node group to obtain a second transmission path, based on the transmission data attribute and the transmission data volume; A key configuration module, configured to construct a first key avoidance space by indexing a first historical backtracking key library of the first transmission path to complete the configuration of the first key, and to construct a second key avoidance space by indexing a second historical backtracking key library of the second transmission path to complete the configuration of the second key; The optimized output module is used to configure a trusted data transmission environment according to the first key, the first transmission path, the second key and the second transmission path.
Citation Information
Patent Citations
Data receiving device, data transmission system, and key generating device
CN109428715A
Method and device for determining shortest path
CN116319517A