Secure communication method and system based on distributed transmission
By building a communication monitoring model, integrating the operating status and transmission status of the transmission nodes, forming a security status pair, and dynamically constructing a distributed transmission path, the problems of node status changes and differentiated security requirements of transmission content in existing technologies are solved, and efficient and secure distributed transmission is achieved.
Patent Information
- Application Number
- CN202510788286.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing distributed transmission solutions have deficiencies in terms of node status changes and differentiated security requirements of transmission content, resulting in high risk of malicious node intrusion, mismatched transmission path resource configuration, and low transmission efficiency or interruption.
By building a communication monitoring model, integrating the operating status and transmission status of the transmission nodes, forming a security status pair, combining the confidentiality level and timeliness requirements, dynamically building a distributed transmission path, and updating the node status in real time to optimize the path.
It achieves multi-dimensional security protection and efficient transmission, improves the communication system's anti-attack capability and transmission efficiency, and meets dynamic security and optimization needs.
Smart Images

Figure CN120658451A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and specifically to a secure communication method and system based on distributed transmission. Background Art
[0002] In the field of data security, the reliability and efficiency of secure communications face multiple technical bottlenecks. Existing solutions mostly use static path construction mechanisms, which cannot dynamically adapt to changes in transmission node status and the differentiated security requirements of transmission content:
[0003] On the one hand, traditional distributed transmission only evaluates node availability through a single dimension (such as node connectivity or historical transmission delay), and does not integrate the three-dimensional security assessment system of hardware operating status (such as device load, trusted authentication level) and transmission service quality (such as encryption strength, throughput). As a result, malicious nodes or faulty nodes may be selected into the transmission path, causing data leakage or transmission interruption.
[0004] On the other hand, the transmission path construction process is decoupled from the confidentiality and timeliness requirements of the transmitted content. For example, high-confidential data may flow through nodes with insufficient hardware stability, or time-sensitive data may be forced to be transmitted through high-latency paths, making it difficult to achieve a precise match between security requirements and resource allocation.
[0005] In addition, existing dynamic adjustment mechanisms mostly rely on global reconstruction strategies, which require interrupting the overall transmission and recalculating the complete path. They cannot meet the optimization needs under the real-time fluctuations of node status in distributed networks, resulting in reduced transmission efficiency or service interruption.
[0006] The Chinese invention patent application publication number CN119788419A discloses a financial communication method and a financial communication system between distributed devices, but the invention performs poorly in terms of the dynamics of the transmission path.
[0007] In summary, a new technical solution for secure communication in distributed transmission is urgently needed. Summary of the Invention
[0008] The purpose of this application is to provide a secure communication method and system based on distributed transmission to solve the technical problems raised in the above background technology.
[0009] To achieve the above objectives, this application discloses the following technical solutions:
[0010] In a first aspect, the present application discloses a secure communication method based on distributed transmission, the method comprising:
[0011] S1: Build a communication monitoring model using historical distributed transmission information, wherein the communication monitoring model is used to determine the security status of the transmission node; wherein the historical distributed transmission information includes historical operation data of the transmission node and its corresponding operation status, and historical transmission data of the transmission node and its corresponding transmission status;
[0012] S2: running the communication monitoring model to determine the security status of each transmission node, where the security status is a number pair determined by the running status and the transmission status;
[0013] S3: Obtain transmission requirements, build a distributed transmission path and communicate based on the security status determined in S3; wherein the transmission requirements include confidentiality requirements and timeliness requirements.
[0014] Preferably, the communication monitoring model is set on the transmission node after being constructed.
[0015] Preferably, the construction of a communication monitoring model using historical distributed transmission data specifically includes:
[0016] Obtaining and analyzing the historical distributed transmission information;
[0017] Extracting features from the operating data corresponding to different operating states to obtain operating features; wherein the operating features are used to characterize the physical operating conditions of the transmission node;
[0018] A first mapping relationship between the operating characteristics and different operating states is established, and the first mapping relationship and the operating characteristics are stored in the communication monitoring model.
[0019] Preferably, the method of constructing a communication monitoring model using historical distributed transmission information further includes:
[0020] Obtaining and analyzing the historical distributed transmission information;
[0021] Extracting features from transmission data corresponding to different transmission states to obtain transmission features; wherein the transmission features are used to characterize whether the transmission node can meet the transmission requirements when transmitting;
[0022] A second mapping relationship between the transmission characteristics and different transmission states is established, and the second mapping relationship and the transmission characteristics are stored in the communication monitoring model.
[0023] Preferably, the safety state is a number pair determined by the running state and the transmission state, specifically including:
[0024] Presetting a quantification tool in the communication monitoring model, and quantifying the operating state and the transmission state based on the quantification tool to obtain corresponding operating state indexes and transmission state indexes;
[0025] The operation state index and the transmission state index are concatenated to obtain the number pair, which is defined as the safe state.
[0026] Preferably, the transmission requirements are:
[0027] Disassemble the transmission content that needs to be communicated to obtain the corresponding transmission data slices;
[0028] The confidentiality level requirement and timeliness requirement corresponding to the transmission data piece are obtained and defined as the transmission requirement.
[0029] Preferably, the construction of a distributed transmission path and communication specifically includes:
[0030] Starting from the communication starting point, based on the transmission requirements, the next communication node is determined according to the following steps:
[0031] A1: For the next communication node of the current communication node, filter out the communication nodes whose transmission status in the security state meets the transmission requirements, and generate a set of communication nodes to be transmitted;
[0032] A2: sorting each communication node in the set of communication nodes to be transmitted based on the quality of the operating status, and selecting the communication node with the best operating status as the next hop transmission node;
[0033] A3: Repeat steps A1 to A2 until the transmission reaches the communication endpoint.
[0034] Preferably, when transmitting to any intermediate communication node, the security status update of the next communication node is obtained in real time through the communication monitoring model deployed on the communication node; if there is a communication node with a better operating status and a transmission status that still meets the transmission requirements in the updated set of communication nodes to be transmitted, then the transmission is immediately switched to the better communication node.
[0035] Preferably, the operating data includes at least CPU load rate, memory usage rate and storage read and write speed;
[0036] The transmission data includes at least transmission delay, throughput, bit error rate and encryption protocol strength.
[0037] In a second aspect, the present application discloses a secure communication system based on distributed transmission, which is applicable to the secure communication method based on distributed transmission as described above, and includes:
[0038] A model building module, the model building module being configured to: build a communication monitoring model using historical distributed transmission information, the communication monitoring model being used to determine the security status of a transmission node; wherein the historical distributed transmission information includes historical operating data of the transmission node and its corresponding operating status, and historical transmission data of the transmission node and its corresponding transmission status;
[0039] A security status determination module, the security status determination module being configured to: run the communication monitoring model to determine the security status of each transmission node, the security status being a number pair determined by the operating status and the transmission status;
[0040] A path construction module is configured to: obtain transmission requirements, and based on the security status determined in the security status determination module, construct a distributed transmission path and communicate; wherein the transmission requirements include confidentiality requirements and timeliness requirements.
[0041] Beneficial effects: The secure communication method and system based on distributed transmission of the present application realize multi-dimensional protection and efficient transmission of secure communication; the communication monitoring model constructed through historical distributed transmission information integrates operation data and transmission data to form a security status number pair including operation status and transmission status, and evaluates node security in three dimensions, solving the defects of single-dimensional evaluation of existing solutions; the communication monitoring model is deployed on the communication node, supports distributed autonomous decision-making, and avoids single point failure of the central communication node; the quantification tool converts the status into a numerical value and forms a number pair, providing a standardized evaluation basis for path construction; data sharding is combined with confidentiality and timeliness requirements to achieve precise matching of transmission strategy and content characteristics; node-by-node screening is carried out by first meeting the transmission status requirements and then sorting by operation status to ensure that the path is both responsive and has hardware stability support; real-time acquisition of communication node security status updates and dynamic switching of better communication nodes to achieve lightweight optimization of distributed transmission paths and avoid the inefficiency of global reconstruction; effectively improves the communication security, reliability and transmission efficiency in distributed transmission, meeting differentiated security needs and real-time dynamic optimization scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 A flowchart of a secure communication method based on distributed transmission provided in an embodiment of the present application;
[0044] Figure 2 A flowchart of constructing a distributed transmission path and communicating in a secure communication method based on distributed transmission provided in an embodiment of the present application;
[0045] Figure 3 This is a structural block diagram of a secure communication system based on distributed transmission provided in an embodiment of the present application. DETAILED DESCRIPTION
[0046] The following is a clear and complete description of the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0047] In this document, the term "comprising" is intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0048] In distributed transmission scenarios, existing secure communication solutions mostly use static path construction and only evaluate node security through a single dimension (such as node connectivity or latency). They are unable to take into account both hardware operating status (such as load and trust level) and transmission service quality (such as encryption strength and timely response). This leads to a high risk of malicious node intrusion, a mismatch between path resource configuration and transmission requirements, and difficulty in meeting dynamic security and efficient transmission needs.
[0049] In view of the above problems, the first aspect of this embodiment discloses Figure 1 A secure communication method based on distributed transmission is shown, the method comprising:
[0050] S1: Build a communication monitoring model using historical distributed transmission information. The communication monitoring model is used to determine the security status of the transmission node. The historical distributed transmission information includes historical operation data of the transmission node and its corresponding operation status, and historical transmission data of the transmission node and its corresponding transmission status.
[0051] S2: Run the communication monitoring model to determine the security status of each transmission node. The security status is a number pair determined by the operation status and the transmission status.
[0052] S3: Obtain transmission requirements, build distributed transmission paths and communicate based on the security status determined in S3; transmission requirements include confidentiality requirements and timeliness requirements.
[0053] Through the above, a communication monitoring model is constructed through historical distributed transmission information, and the operation data and transmission data are integrated to form a security status number pair including the operation status and transmission status, thereby realizing a three-dimensional security assessment of the transmission node and solving the one-sidedness of the single-dimensional assessment of the existing technology; by combining the security status output by the communication monitoring model with the transmission requirements (confidentiality level, timeliness) to construct a path, it is ensured that high-confidentiality data flows through nodes with stable hardware and high encryption strength, and time-sensitive data selects a low-latency path, thereby achieving a precise match between security requirements and resource allocation; the distributed path construction mechanism avoids dependence on central nodes, and combined with real-time dynamic security status assessment, it significantly improves the communication system's anti-attack capability and transmission efficiency, and provides an efficient solution for differentiated secure communications in distributed scenarios.
[0054] In existing distributed secure communication solutions, monitoring models often rely on centralized server deployment, resulting in high communication overhead and latency. To address these issues, this embodiment optimizes the configuration of the established communication monitoring model by combining it with a distributed transmission architecture.
[0055] Specifically, after the communication monitoring model is constructed, it is set on the transmission node.
[0056] By placing the communication monitoring model at the transmission node, decentralized autonomous decision-making is achieved for the distributed system. Each node can obtain the security status of the next communication node locally in real time, avoiding the single point of failure and communication bottlenecks of centralized servers. This reduces data transmission across nodes, improving the real-time nature of status updates and path building. This enhances system robustness, ensuring efficient and complete secure communication path building even when communication nodes join or leave.
[0057] Research on existing distributed communication monitoring models has found that they often overlook the hierarchical analysis of operational and transmission data during their construction, or focus solely on the physical operational status of nodes (such as hardware load) without considering transmission quality of service (such as latency and encryption capabilities). Alternatively, they analyze only transmission data and lack an assessment of hardware stability. This results in models that fail to fully characterize node security status, making path construction prone to problems such as selecting nodes with hardware faults or mismatching transmission strategies with node capabilities. To address these issues, this embodiment utilizes existing machine learning techniques to optimize the monitoring model.
[0058] Specifically, a communication monitoring model is constructed using historical distributed transmission data, including:
[0059] Obtain and parse historical distributed transmission information;
[0060] Extracting features from the operating data corresponding to different operating states to obtain operating features; wherein the operating features are used to characterize the physical operating conditions of the transmission node;
[0061] A first mapping relationship between the operating characteristics and different operating states is established, and the first mapping relationship and the operating characteristics are stored in a communication monitoring model.
[0062] Specifically, building a communication monitoring model using historical distributed transmission information also includes:
[0063] Obtain and parse historical distributed transmission information;
[0064] Extracting features from the transmission data corresponding to different transmission states to obtain transmission features; wherein the transmission features are used to characterize whether the transmission node can meet the transmission requirements when transmitting;
[0065] A second mapping relationship between the transmission characteristics and different transmission states is established, and the second mapping relationship and the transmission characteristics are stored in the communication monitoring model.
[0066] It should be noted that this embodiment utilizes an existing deep learning model to construct the communication monitoring model. Furthermore, the first and second mapping relationships can be established using any existing data feature processing technology, aiming to achieve the goal of obtaining real-time operation features based on real-time operation data, obtaining real-time operation status based on real-time operation features, and obtaining real-time transmission features based on real-time transmission data, obtaining real-time transmission status based on real-time transmission features.
[0067] Through the above, by extracting the operation characteristics and transmission characteristics in layers, the mapping relationship between the physical operation status and the transmission service capability is established, so that the communication monitoring model has a two-dimensional evaluation capability; among which:
[0068] Operational feature extraction focuses on hardware operation data, accurately identifying device health, preventing faulty or heavily loaded nodes from participating in transmission, and improving path hardware stability.
[0069] Transmission feature extraction combined with transmission data directly correlates to transmission requirements, ensuring that node transmission capabilities match business needs;
[0070] The establishment of a dual mapping relationship enables the communication monitoring model to three-dimensionally characterize the node security status, providing multi-dimensional data support for subsequent path construction, and solving the problems of one-sided evaluation of existing technologies and disconnection between strategies and capabilities.
[0071] Determining the security status of communication nodes is a common analysis method in existing secure communication technologies. However, it is often presented in qualitative descriptions (such as normal, abnormal) or single numerical values (such as trust scores), lacking differentiated quantitative assessments of operational and transmission statuses. This status description is difficult to directly use for numerical comparisons in path construction, resulting in an inability to accurately distinguish node security levels. This can easily lead to high-risk and low-risk nodes being treated equally, or transmission strategies failing to match the actual capabilities of nodes. To address this issue, this embodiment quantifies operational and transmission statuses based on existing quantification tools and performs further optimization based on the quantified results.
[0072] Specifically, the safety state is a number pair determined by the operating state and the transmission state, including:
[0073] A quantification tool is preset in the communication monitoring model, and the operation state and the transmission state are quantified based on the quantification tool to obtain corresponding operation state index and transmission state index;
[0074] The operation status index and the transmission status index are concatenated to obtain a number pair, which is defined as a safe state.
[0075] It should be noted that the quantification tool used for the operating status in this embodiment can be, but is not limited to, weighted summing of the data of each different item in the operating data to obtain the operating status index; the quantification tool used for the transmission status can be, but is not limited to, weighted summing of the data of each different item in the transmission data to obtain the transmission operating status index.
[0076] By converting the operating status and transmission status into indexed pairs, a standardized and refined assessment of security status is achieved. Specifically, the operating status index quantifies hardware stability, while the transmission status index quantifies service responsiveness. The pairing format intuitively reflects the node's comprehensive performance in hardware security and transmission efficiency, achieving a two-dimensional numerical representation. The standardized index facilitates rapid screening and sorting of communication nodes, avoiding the ambiguity of qualitative assessments and improving path construction efficiency. The pairing structure supports flexible configuration, enabling the system to dynamically adjust node selection strategies based on varying transmission requirements. This addresses the shortcomings of existing technologies, which suffer from a single evaluation dimension and poor policy adaptability, enabling dynamic policy adaptation.
[0077] As a preferred implementation of this embodiment, the security status of communication nodes can be further verified by utilizing the trajectory of changes in the plane of the number pairs corresponding to the security status, thereby providing a more refined data foundation for the screening and sorting of communication nodes. Specifically, a security status index is calculated by counting the inflection points in the trajectory of changes in the plane of the number pairs corresponding to the security status during a preset monitoring period, and then the security status index is used to optimize the communication nodes. This optimization method may include, but is not limited to, fitting the security status index to obtain a security status index threshold. When the real-time security status index does not fall within the security status index threshold, the communication node is determined to require maintenance, thereby providing more solid equipment protection for secure communications.
[0078] Existing distributed transmission solutions often use a unified transmission strategy for the entire data packet, failing to differentiate between the security and timeliness requirements of different content components. This can lead to the mixing of high-security data with general data, or the deprioritization of time-sensitive content due to overall path constraints. To address this issue, this embodiment utilizes existing data depacketization technology to process the data.
[0079] Specifically, the transmission requirements are as follows:
[0080] Disassemble the transmission content that needs to be communicated to obtain the corresponding transmission data slices;
[0081] Obtain the confidentiality level and timeliness requirements corresponding to the transmitted data piece and define them as transmission requirements.
[0082] It should be noted that, in this embodiment, the data slices are marked using existing data marking technology, and the marking result is the confidentiality level requirement and timeliness requirement. The corresponding transmission requirement is obtained by identifying the corresponding mark.
[0083] Through the above, by breaking down the transmission content into data slices and marking them with confidentiality requirements and timeliness requirements, differentiated transmission at the slice level can be achieved. High-security paths are constructed for high-confidence data slices, and low-latency paths are constructed for time-sensitive data slices. This improves resource utilization and transmission efficiency, and solves the problems of security redundancy or insufficient timeliness caused by a unified strategy for the entire package.
[0084] Existing distributed path construction often uses a one-time, global planning model, without distinguishing between transmission requirements and the real-time correlation of node status. This results in either fixed routing, unable to dynamically respond to node status fluctuations, or prioritizing a single dimension (such as latency), causing high-security data to flow through low-security nodes. To address this issue, this embodiment designs a node-by-node dynamic optimization mechanism to avoid inefficient transmission and security risks.
[0085] Specifically, such as Figure 2 As shown, building a distributed transmission path and communicating, specifically including:
[0086] Starting from the communication starting point, based on the transmission requirements, the next communication node is determined based on the following steps:
[0087] A1: For the next communication node of the current communication node, filter out the communication nodes whose transmission status in the security state meets the transmission requirements, and generate a set of communication nodes to be transmitted;
[0088] A2: Sort each communication node in the set of communication nodes to be transmitted based on their operating status, and select the communication node with the best operating status as the next-hop transmission node;
[0089] A3: Repeat steps A1 to A2 until the transmission reaches the communication endpoint.
[0090] It should be noted that the method for determining the next communication node for the current communication node in this embodiment can be, but is not limited to, directly using each communication node that has a communication connection with the current communication node as the next communication node, for example, adjacent communication nodes. The next-hop transmission node is determined based on dynamic screening and sorting of each adjacent communication node.
[0091] Through the above, hierarchical optimization of transmission paths is achieved through a node-by-node dynamic optimization mechanism. Step A1 first selects nodes whose transmission status meets the confidentiality and timeliness requirements to ensure the basic security and responsiveness of the path, avoid invalid nodes from participating in the transmission, and achieve priority filtering of transmission requirements; Step A2 sorts qualified nodes according to the quality of hardware operation status, giving priority to nodes with stronger stability, providing hardware support for high-level data, balancing security and efficiency, and achieving secondary sorting of operation status; Through node-by-node iteration in step A3, path construction adapts to the local discovery characteristics of distributed networks (such as the dynamic changes of adjacent communication nodes), and the optimal path can be generated without global information, improving the scalability and real-time performance of the system, and solving the problem that the existing global planning model has a strong dependence on the central node and poor dynamic adaptability.
[0092] As a preferred implementation of this embodiment, when the ranking of the operational status is insufficient to distinguish the quality of communication nodes, the security status index is used to further perform the ranking. Specifically, by calculating whether the difference in the operational status indexes of adjacent communication nodes falls within a preset operational status index difference threshold, it is determined that the ranking of the operational status is insufficient to distinguish the quality of communication nodes, and the security status index is used to further perform the ranking, thereby optimizing the selection of the next-hop transmission node.
[0093] Preferably, when transmitting to any intermediate communication node, the security status update of the next communication node is obtained in real time through the communication monitoring model deployed on the communication node; if there is a communication node with a better operating status and the transmission status still meets the transmission requirements in the updated set of communication nodes to be transmitted, it will immediately switch to the better communication node for transmission.
[0094] By acquiring the security status updates of the next communication node in real time and dynamically switching the transmission path, communication efficiency and reliability are significantly improved. The status of the next-hop node is evaluated in real time at the intermediate node, and when a more optimal node is found, it is switched immediately without interrupting the overall transmission, achieving optimization while transmitting. When the original path node experiences a sudden increase in load or a decrease in encryption capabilities, it can switch to the backup node in a timely manner to avoid potential transmission interruptions or data leaks. The optimal node is selected based on the latest status data, ensuring that high-density data always flows through a path with stable hardware and efficient transmission, maximizing system resource utilization. The transmission path is equipped with adaptive adjustment capabilities, which is particularly suitable for distributed scenarios where node status frequently fluctuates.
[0095] Specifically, the operating data includes at least CPU load rate, memory usage rate, and storage read and write speed;
[0096] Transmission data includes at least transmission delay, throughput, bit error rate and encryption protocol strength.
[0097] It should be noted that the collection and determination of the operating data and the transmission data in this embodiment are common knowledge for those skilled in the art.
[0098] The second aspect of this embodiment discloses Figure 3 A secure communication system based on distributed transmission is shown, and the system is applicable to the secure communication method based on distributed transmission as described above. The system includes:
[0099] A model building module, the model building module is configured to: build a communication monitoring model using historical distributed transmission information, the communication monitoring model being used to determine the security status of the transmission node; wherein the historical distributed transmission information includes historical operation data of the transmission node and its corresponding operation status and historical transmission data of the transmission node and its corresponding transmission status;
[0100] A security status determination module, the security status determination module is configured to: run a communication monitoring model to determine the security status of each transmission node, where the security status is a number pair determined by the operating status and the transmission status;
[0101] The path construction module is configured to: obtain transmission requirements, build a distributed transmission path and communicate based on the security status determined in the security status determination module; wherein the transmission requirements include confidentiality requirements and timeliness requirements.
[0102] It should be noted that the distributed transmission-based secure communication system of this embodiment corresponds to the aforementioned distributed transmission-based secure communication method. Therefore, any details not specifically described in the distributed transmission-based secure communication system of this embodiment, including but not limited to functional definitions, operating principles, and technical effects, can be referred to in the aforementioned distributed transmission-based secure communication method and are not further elaborated herein.
[0103] In summary, the secure communication method and system based on distributed transmission in this embodiment realize multi-dimensional protection and efficient transmission of secure communication; the communication monitoring model constructed through historical distributed transmission information integrates operation data and transmission data to form a security status number pair including operation status and transmission status, and evaluates node security in three dimensions, solving the defect of single-dimensional evaluation of existing solutions; the communication monitoring model is deployed on the communication node, supports distributed autonomous decision-making, and avoids single point failure of the central communication node; the quantification tool converts the status into a numerical value and forms a number pair, providing a standardized evaluation basis for path construction; data segmentation combines confidentiality and timeliness requirements to achieve precise matching of transmission strategy and content characteristics; node-by-node screening is carried out by first meeting the transmission status requirements and then sorting by operation status to ensure that the path meets both responsiveness and hardware stability; real-time acquisition of communication node security status updates and dynamic switching of better communication nodes to achieve lightweight optimization of distributed transmission paths and avoid the inefficiency of global reconstruction; effectively improves the communication security, reliability and transmission efficiency in distributed transmission, meeting differentiated security needs and real-time dynamic optimization scenarios.
[0104] In the embodiments provided herein, it should be understood that the embodiments described herein can be implemented in hardware, software, firmware, middleware, code, or any appropriate combination thereof. For hardware implementation, the processor can be implemented in one or more of the following units: an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a processor, a controller, a microcontroller, a microprocessor, other electronic units designed to implement the functions described herein, or a combination thereof. For software implementation, part or all of the processes of the embodiments can be completed by instructing the relevant hardware through a computer program. When implemented, the above program can be stored in a computer-readable storage medium or transmitted as one or more instructions or codes on a computer-readable storage medium. Computer-readable storage media include computer storage media and communication media, wherein the communication media include any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that a computer can access. The computer-readable storage medium can include, but is not limited to, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer.
[0105] Finally, it should be noted that the above is only a preferred embodiment of the present application and is not intended to limit the present application. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or make equivalent replacements for some of the technical features therein. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A secure communication method based on distributed transmission, characterized in that: The method includes: S1: Build a communication monitoring model using historical distributed transmission information, wherein the communication monitoring model is used to determine the security status of the transmission node; wherein the historical distributed transmission information includes historical operation data of the transmission node and its corresponding operation status, and historical transmission data of the transmission node and its corresponding transmission status; S2: running the communication monitoring model to determine the security status of each transmission node, where the security status is a number pair determined by the running status and the transmission status; S3: Obtain transmission requirements, build a distributed transmission path and communicate based on the security status determined in S3; wherein the transmission requirements include confidentiality requirements and timeliness requirements.
2. The secure communication method based on distributed transmission according to claim 1, characterized in that: After the communication monitoring model is constructed, it is set on the transmission node.
3. The secure communication method based on distributed transmission according to claim 1, characterized in that: The construction of a communication monitoring model using historical distributed transmission data specifically includes: Obtaining and analyzing the historical distributed transmission information; Extracting features from the operating data corresponding to different operating states to obtain operating features; wherein the operating features are used to characterize the physical operating conditions of the transmission node; A first mapping relationship between the operating characteristics and different operating states is established, and the first mapping relationship and the operating characteristics are stored in the communication monitoring model.
4. The secure communication method based on distributed transmission according to claim 1, characterized in that: The method of constructing a communication monitoring model using historical distributed transmission information further includes: Obtaining and analyzing the historical distributed transmission information; Extracting features from transmission data corresponding to different transmission states to obtain transmission features; wherein the transmission features are used to characterize whether the transmission node can meet the transmission requirements when transmitting; A second mapping relationship between the transmission characteristics and different transmission states is established, and the second mapping relationship and the transmission characteristics are stored in the communication monitoring model.
5. The secure communication method based on distributed transmission according to claim 1, characterized in that: The safety state is a number pair determined by the operating state and the transmission state, specifically including: Presetting a quantification tool in the communication monitoring model, and quantifying the operating state and the transmission state based on the quantification tool to obtain corresponding operating state indexes and transmission state indexes; The operation state index and the transmission state index are concatenated to obtain the number pair, which is defined as the safe state.
6. The secure communication method based on distributed transmission according to claim 1, characterized in that: The transmission requirements are specifically: Disassemble the transmission content that needs to be communicated to obtain the corresponding transmission data slices; The confidentiality level requirement and timeliness requirement corresponding to the transmission data piece are obtained and defined as the transmission requirement.
7. The secure communication method based on distributed transmission according to claim 2, characterized in that: The construction of a distributed transmission path and communication specifically includes: Starting from the communication starting point, based on the transmission requirements, the next communication node is determined according to the following steps: A1: For the next communication node of the current communication node, filter out the communication nodes whose transmission status in the security state meets the transmission requirements, and generate a set of communication nodes to be transmitted; A2: sorting each communication node in the set of communication nodes to be transmitted based on the quality of the operating status, and selecting the communication node with the best operating status as the next hop transmission node; A3: Repeat steps A1 to A2 until the transmission reaches the communication endpoint.
8. The secure communication method based on distributed transmission according to claim 7, characterized in that: When transmitting to any intermediate communication node, the security status update of the next communication node is obtained in real time through the communication monitoring model deployed on the communication node; if there is a communication node with a better operating status and a transmission status that still meets the transmission requirements in the updated set of communication nodes to be transmitted, it will immediately switch to the better communication node for transmission.
9. The secure communication method based on distributed transmission according to claim 1, characterized in that: The operating data includes at least CPU load rate, memory usage rate and storage read and write speed; The transmission data includes at least transmission delay, throughput, bit error rate and encryption protocol strength.
10. A secure communication system based on distributed transmission, the system being applicable to the secure communication method based on distributed transmission as claimed in any one of claims 1 to 9, characterized in that: The system includes: A model building module, the model building module being configured to: build a communication monitoring model using historical distributed transmission information, the communication monitoring model being used to determine the security status of a transmission node; wherein the historical distributed transmission information includes historical operating data of the transmission node and its corresponding operating status, and historical transmission data of the transmission node and its corresponding transmission status; A security status determination module, the security status determination module being configured to: run the communication monitoring model to determine the security status of each transmission node, the security status being a number pair determined by the operating status and the transmission status; A path construction module is configured to: obtain transmission requirements, and based on the security status determined in the security status determination module, construct a distributed transmission path and communicate; wherein the transmission requirements include confidentiality requirements and timeliness requirements.
Citation Information
Patent Citations
Financial communication method and financial communication system between distributed devices
CN119788419A