A data flow method and system based on high-speed data network

By using a high-speed data network management platform and deterministic network technology, the problems of data security and transmission quality in data circulation and transactions have been solved, enabling secure and reliable data transmission and meeting the needs of efficient data circulation between enterprises.

CN120811772BActive Publication Date: 2025-12-12NANJING FUTURE NETWORK CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511277718.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-12-12
Estimated Expiration
2045-09-09

AI Technical Summary

Technical Problem

Existing data circulation and trading systems suffer from poor data security and difficulty in guaranteeing transmission quality. In particular, when data transactions are conducted on the public Internet, sensitive data is easily stolen, and insufficient transmission performance leads to network congestion and delays.

Method used

A data flow method based on high-speed data networks is adopted, and secure isolation transmission between enterprises is achieved through a high-speed data network management platform. Isolation transmission tunnels are built using soft data gateways, deterministic network technologies, and VPN instances. Combined with NAT translation, whitelisting, and QoS settings, the security and quality of data transmission are ensured.

Benefits of technology

It achieves end-to-end encrypted transmission, ensuring the privacy and stability of data transmission, providing deterministic network transmission quality, meeting the needs of high concurrency and large-scale data transactions, reducing the risk of data leakage and improving transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811772B_ABST
    Figure CN120811772B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of data flow, and discloses a data flow method and system based on a high-speed data network. The method comprises the following steps: returning a soft data gateway download address to a supplier and a demander based on their subscription requests; obtaining a transaction request initiated by the demander to the supplier to generate a service identification ID; sending a configuration instruction to the soft data gateway corresponding to the demander and the supplier based on the service identification ID to realize the interconnection of the demander connector and the supplier connector and the setting of data transmission quality; allocating an independent VPN instance for the service identification ID, and binding the demand network quality to construct an isolated transmission tunnel; when the data transaction is completed, sequentially closing the isolated transmission tunnel, deleting the QoS setting, deleting the white list, and closing the intranet network; and obtaining the unsubscription request of the supplier and the demander to allow them to unload the corresponding soft data gateway. The application has high data flow security and high transmission quality.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data flow, in particular to a data flow method and system based on high-speed data network. BACKGROUND

[0002] Digital transformation refers to the process of enterprises conducting data flow through digital technology and realizing data transaction. Since digital transformation can effectively improve enterprise competitiveness, optimize resource allocation, etc., it is gradually promoted and applied in the actual industry.

[0003] In the current process of digital transformation, data transactions based on digital data flow excessively rely on public Internet for data transmission. Specifically, a data flow service platform needs to be built, and each data demander and supplier is required to upload data to the data flow service platform based on public Internet for subsequent transactions. This results in the following technical defects in data flow and transaction:

[0004] Firstly, when enterprises conduct data transactions through public Internet, there is a lack of end-to-end encryption mechanism at the network level, and sensitive data is at risk of being stolen and tampered with during transmission, which not only endangers business secrets and privacy security, but also may cause systematic data security risks. Secondly, the public Internet service mode is "best effort", so it is difficult to guarantee transmission quality, and network congestion and delay often occur when dealing with high concurrency and large-scale data transactions, which results in the inability to transmit critical business data in time.

[0005] Therefore, the above data security problems and transmission performance problems caused by public Internet not only expose enterprise core data assets to risks, but also restrict the efficient flow and market cultivation of data elements. SUMMARY

[0006] The present application aims to provide a data flow method and system based on high-speed data network to solve the technical problems of poor data security and difficult transmission quality guarantee caused by excessive reliance on public Internet in the current data flow and transaction process.

[0007] To achieve the above purpose, the present application proposes the following technical solutions:

[0008] In a first aspect, a data flow method based on high-speed data network is provided, characterized by being based on a pre-built high-speed data network management platform, comprising:

[0009] returning a soft data gateway download address to the supplier and the demander based on their subscription requests; when the soft data gateway corresponding to the supplier and the demander is installed and put into operation, uniformly issuing Deny rules to each soft data gateway;

[0010] Obtaining a transaction request initiated by a demand side to a supply side, and generating a service identification ID based on the transaction request; wherein the service identification ID comprises: demand side information, supply side information, and demand network quality; the demand side information and the supply side information each comprise: enterprise name, enterprise connector address, and soft data gateway name;

[0011] Sending a configuration instruction to the soft data gateways corresponding to the demand side and the supply side based on the service identification ID to achieve interconnection between the demand side connector and the supply side connector and setting of the demand network quality during data transmission; wherein the configuration instruction comprises: NAT conversion, whitelist setting, and QoS setting;

[0012] Allocating an independent VPN instance for the service identification ID, and binding the demand network quality to the independent VPN instance to build an isolated transmission tunnel based on deterministic network technology;

[0013] When data transaction based on an end-to-end transmission network constructed by the supply side connector, the isolated transmission channel, and the demand side connector is completed, deleting the independent VPN instance to close the isolated transmission tunnel, and deleting each configuration instruction to close the intranet network between the supply side connector and the demand side connector;

[0014] Obtaining a subscription request of the supply side and the demand side to return a permission instruction to them; wherein the permission instruction is used to allow the supply side and the demand side to uninstall the corresponding soft data gateway.

[0015] Further, the allocating an independent VPN instance for the service identification ID, and binding the demand network quality to the independent VPN instance to build an isolated transmission tunnel based on deterministic network technology; comprises:

[0016] Embedding a path instruction in the header of the deterministic network to specify a forwarding path for the isolated transmission tunnel; wherein the forwarding path comprises a main forwarding path and a backup forwarding path, and if there is a link fault in the main forwarding path during data flow transmission, the backup forwarding path is automatically switched to;

[0017] Realizing priority forwarding of corresponding data based on the service priority carried by the segment identifier in the deterministic network.

[0018] Further, the obtaining a transaction request initiated by a demand side to a supply side, and generating a service identification ID based on the transaction request; comprises:

[0019] Verifying the transaction qualification of the supply side and the demand side based on the transaction request; wherein the transaction qualification comprises: transaction identity and transaction authority;

[0020] Generating a network work order after verification, to generate the service identification ID based on the network work order.

[0021] Further comprising:

[0022] The soft data gateway corresponding to the supply side and the demand side accesses the backbone network built based on the deterministic network through the dual-mode network channel; wherein, the dual-mode network includes the Internet channel and the high-speed data private network channel.

[0023] Further comprising:

[0024] Obtain the online state and real-time network transmission quality of the soft data gateway corresponding to the supply side and the demand side; wherein, the real-time network transmission quality includes real-time bandwidth, real-time delay, real-time packet loss rate and real-time jitter;

[0025] When the soft data gateway is offline or the real-time network transmission quality is lower than the demand network quality, send a warning message to the background control end.

[0026] In the second aspect, a data flow system based on high-speed data network is provided, which is based on a pre-built high-speed data network management platform, comprising:

[0027] The subscription feedback module is used to return the soft data gateway download address to the supply side and the demand side based on their subscription requests; when the soft data gateway corresponding to the supply side and the demand side is installed and online, the Deny rule is uniformly issued to each soft data gateway;

[0028] The identification generation module is used to obtain the transaction request initiated by the demand side to the supply side, and generate a business identification ID based on the transaction request; wherein, the business identification ID includes: demand side information, supply side information and demand network quality; the demand side information and the supply side information both include: enterprise name, enterprise connector address and soft data gateway name;

[0029] The access network setting module is used to send a configuration instruction to the soft data gateway corresponding to the demand side and the supply side based on the business identification ID to realize the interconnection between the demand side connector and the supply side connector and the setting of the demand network quality during data transmission; wherein, the configuration instruction includes: NAT conversion, white list setting and QoS setting;

[0030] The backbone network setting module is used to allocate an independent VPN instance for the business identification ID, and bind the demand network quality to the independent VPN instance to build an isolated transmission tunnel based on the deterministic network technology;

[0031] The transaction end feedback module is configured to delete the independent VPN instance to close the isolated transmission tunnel and delete each configuration instruction to close the intranet network between the supply-side connector and the demand-side connector when determining that the data transaction between the supply side and the demand side based on the end-to-end transmission network constructed by the supply-side connector, the isolated transmission channel and the demand-side connector is ended;

[0032] The unsubscribe feedback module is configured to obtain the unsubscribe request of the supply side and the demand side to return permission instructions to them, wherein the permission instructions are used to allow the supply side and the demand side to unload the corresponding soft data gateway.

[0033] Further, the backbone network setting module comprises:

[0034] The path setting unit is configured to embed path instructions in the header of the deterministic network to specify a forwarding path for the isolated transmission tunnel, wherein the forwarding path comprises a main forwarding path and a backup forwarding path, and the backup forwarding path is automatically switched to when the main forwarding path exists link failure in the data flow transmission.

[0035] The priority setting unit is configured to realize the priority forwarding of the corresponding data based on the service priority carried by the segment identifier in the deterministic network.

[0036] Further, the identification generation module comprises:

[0037] The qualification verification unit is configured to verify the transaction qualification of the supply side and the demand side based on the transaction request, wherein the transaction qualification comprises a transaction identity and a transaction permission.

[0038] The work order generation unit is configured to generate a network work order after the verification is passed to generate the service identification ID based on the network work order.

[0039] In a third aspect, an electronic device is provided, comprising at least one processor coupled with a memory, wherein the memory stores a computer program configured to be executed by the processor to implement the method.

[0040] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program configured to be executed by a processor to implement the method.

[0041] Advantages:

[0042] From the above technical solutions, the technical solutions of the present application provide a data flow transmission method based on a high-speed data network, which is based on a pre-built high-speed data network management platform to solve the security and transmission quality problems existing in the current data flow transaction.

[0043] The method sequentially comprises a subscription stage, a transaction request stage, a transaction stage, a transaction end stage and a cancellation stage. In the subscription stage, the unified management and scheduling of the enterprise access equipment by the high-speed data network management platform is realized through the plug-and-play deployment of the soft data gateway, and the safe isolation of the services between the soft data gateways is realized through the Deny rule. In the transaction request stage, the access network and the backbone network are set respectively. In the access network setting, the interconnection between the demand side connector and the supply side connector and the data transmission quality setting are realized by sending a configuration instruction to the soft data gateways corresponding to the demand side and the supply side based on the service identifier ID. Specifically, the address of the supply side connector and the address of the demand side connector are converted into the internal network address of the same network segment through NAT conversion; the communication connection between the supply side connector and the demand side connector is opened through the white list setting; the demand network quality is set through the QoS setting to ensure the data transmission quality of the supply side connector and the demand side connector. In the backbone network setting, the deterministic network technology is introduced to realize the data flow between the two parties based on the exclusive network, thereby ensuring the privacy of the transmission link. At the same time, the demand network quality is set based on the QoS setting, and is bound in the VPN instance of the backbone network to ensure the bandwidth, delay, jitter and packet loss demand in the transmission process, effectively ensuring the transmission quality. At this time, in the transaction stage, the high-security and high-quality data flow can be realized based on the above-mentioned network channel. In the transaction end stage, the enterprise supply and demand parties send a transaction closing request to the platform through the corresponding connectors, and realize the dynamic on-demand allocation of network resources through resource release and link cleaning to meet the security and high-quality transmission demand of other supply and demand parties with data transaction demand. In the cancellation stage, the supply side and the demand side are allowed to unload the corresponding soft data gateway, avoiding the data leakage risk of the two parties of the completed transaction due to data residue.

[0044] As can be seen from the above, the technical scheme constructs an end-to-end secure transmission system through the network deployment of just-in-time, and provides a deterministic transmission capability of "delay commitment and path anticipation". Further, the security and quality demand of data flow are met.

[0045] It should be understood that all combinations of the aforementioned concepts and additional concepts described below (provided such concepts are not mutually inconsistent) are contemplated as being part of the inventive subject matter.

[0046] The foregoing and other aspects, embodiments and features of the present teachings can be better understood from the following detailed description taken in conjunction with the accompanying drawings. Other aspects, embodiments and features of the present teachings will be apparent from the detailed description and the drawings. BRIEF DESCRIPTION OF DRAWINGS

[0047] The accompanying drawings are not intended to be drawn to scale. In the drawings, each same or like component illustrated in the various drawings can be denoted by the same reference numerals. For the sake of clarity, not every component can be labeled in every drawing. Embodiments of various aspects of the present application will now be described, by way of example only, with reference to the accompanying drawings in which:

[0048] Figure 1 Flow chart of the data flow method based on high-speed data network according to the present embodiment;

[0049] Figure 2 Flow chart of the service identification ID generation;

[0050] Figure 3 Flow chart of the forwarding path setting;

[0051] Figure 4 Flow chart of the network setup between the access network and the backbone network;

[0052] Figure 5 Flow chart of the transmission abnormality early warning;

[0053] Figure 6 Structure block diagram of the data flow system based on high-speed data network according to the present embodiment;

[0054] Figure 7 Structure block diagram of the electronic device according to the present embodiment. DETAILED DESCRIPTION

[0055] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions of the embodiments of the present application will be described clearly and completely below with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments of the present application. Based on the described embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort belong to the scope of protection of the present application. Unless otherwise defined, the technical terms or scientific terms used herein should be understood as the common meanings by those of ordinary skill in the art to which the present application belongs.

[0056] As used in the specification and claims of this application, the terms "first", "second", and similar terms do not imply any order, quantity, or importance, but rather are used to distinguish one element from another. Also, the singular forms "a", "an", and "the" do not preclude the plural forms unless the context clearly indicates otherwise. The terms "include", "comprise", and similar terms are used synonymously to refer to the presence of the stated feature, integer, step, operation, element, component, or a combination thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or combinations thereof. The terms "upper", "lower", "left", "right", and the like are used to indicate relative positional relationships, which can change when the absolute positions of the described objects change.

[0057] Under the background of deepening digital transformation, data circulation using public infrastructure faces severe challenges. Specifically, the current data transaction process relies heavily on public internet transmission, which exposes two key problems: first, the security risks are prominent. When enterprises conduct data transactions through public internet, there is a lack of end-to-end encryption mechanism at the network level, and sensitive data is at risk of being stolen and tampered with during transmission, which not only endangers business secrets and privacy security, but also may cause systemic data security risks. Second, the transmission performance bottleneck is obvious. The service mode of public internet cannot guarantee the transmission quality, and when dealing with high concurrency and large-scale data transactions, network congestion and delay often occur, which leads to the failure of timely transmission of critical business data. These problems not only restrict the efficient circulation and market cultivation of data elements, but also expose the core data assets of enterprises to risks. At the same time, existing connectors and data circulation service platforms have formed a system, and network-level optimization and reconstruction need to be smoothly embedded in a minimal invasive manner. Based on this, the present embodiment aims to provide a data circulation method based on high-speed data network to solve the above technical problems.

[0058] The data circulation method based on high-speed data network described in the present embodiment will be described in detail below with reference to the accompanying drawings.

[0059] The method adds a fixed deployment high-speed data network management platform and a dynamically deployed soft data gateway to the existing data flow system, and the smooth embedding of the method is realized under the premise of minimum invasion. The high-speed data network management platform is open. Specifically, the current data flow infrastructure adopts a hierarchical management method, and each region constructs its own data flow service platform. The high-speed data network management platform of the embodiment can meet the needs of third-party data flow service platform calls through the RESTful API interface. At the same time, it meets the data flow platform identity verification, network subscription, and transaction start / close trigger high-speed data network start / close on-demand service.

[0060] The high-speed data network management platform is a comprehensive network management platform for data transaction scenarios, which realizes unified control of the whole process of data transmission through modular design, and the core functions are divided into the following six modules:

[0061] (1) Enterprise management module: focusing on enterprise access and basic information management, specifically used for maintaining the connection relationship of the connector and the soft data gateway (such as supporting the association configuration of the enterprise-level connector and the soft data gateway), managing enterprise information (such as enterprise basic information, access permission management, etc.), and providing bottom support for multi-tenant isolation and business domain separation.

[0062] (2) Data gateway module: realizing the whole life cycle monitoring and version control of the soft data gateway, specifically used for real-time monitoring of the gateway state (such as online / offline state, resource occupancy rate, etc.), real-time management of data (such as data flow, transmission quality index collection), and version management (such as gateway firmware / software upgrade, rollback, etc.), to ensure the efficient and stable operation of the gateway.

[0063] (3) Transaction network demand management module: facing the network resource scheduling demand of data transaction, specifically used for providing management of demand work orders (such as network demand work orders of enterprises submitting bandwidth, delay, etc.), tracking of work order sources (such as recording demanders and transaction scenarios, adapting to multiple data flow service platforms and connectors), work order processing (such as demand review, resource allocation process handling), work order statistics (such as transaction volume, processing timeliness, etc. Data visualization analysis), to realize the precise matching of business demand and network resources.

[0064] (4) API interface management module: Provide standardized interface services and security management and control for enterprise connectors or data flow service platforms to turn on and off network resources and other third-party calls. Specifically, it is used for identity authentication (such as authenticating the user identity of a trusted data space platform), transaction network opening / closing (such as triggering the dynamic activation or release of network resources through an API), network quality monitoring (such as real-time collection of bandwidth, latency, packet loss rate, etc.), alarm information monitoring (such as automatic early warning of abnormal states), supporting cross-platform collaboration and business automation.

[0065] (5) Controller interface module: As a bridge between the platform and the underlying network equipment, it is specifically used for setting up access network controllers (such as managing the bandwidth elasticity allocation of Internet / leased line hybrid access networks and tenant business isolation), deterministic controller settings (such as controlling the traffic scheduling strategy of the backbone network deterministic network), and bidirectional communication settings between the access side network and the backbone network, thereby converting upper-level business strategies into device execution instructions and building an automated closed loop of "business intent-network configuration".

[0066] (6) User and log management module: Through user management, it supports "user-role-permission" three-level control, allocates operation permissions according to tenants or functions, and realizes multi-tenant business isolation; through log management, it manages system logs (such as platform running state records) and operation logs (such as user behavior audit tracing), meeting compliance requirements and problem troubleshooting needs.

[0067] The soft data gateway is quickly integrated into an enterprise connector (soft / hard adaptation) or a data flow service platform through soft plug-in technology, realizing the instant use of high-speed data networks. The core functions are divided into the following five modules:

[0068] (1) Firewall management module: Provides border security protection for data transmission, and based on preset strategies, it controls the access of data streams in and out of the gateway (such as IP black / white lists, port filtering, protocol detection, etc.), preventing unauthorized access and malicious attacks, and ensuring the confidentiality and integrity of data transmission.

[0069] (2) Tunnel management module: Responsible for building and maintaining secure encrypted transmission channels (such as IPSec, GRE, etc.), realizing private transmission of data between enterprises or across regions. It supports tunnel creation, configuration (including encryption algorithm, key management), state monitoring (such as connection state, transmission traffic), and fault self-healing, ensuring the stability and reliability of data links in cross-network environments.

[0070] (3) QoS management module: Provide differentiated network resource allocation strategies for different types of data transaction business needs. Through priority division (such as delay-sensitive transaction data priority scheduling), bandwidth guarantee (for reserving fixed bandwidth for critical business), traffic shaping (for limiting non-core business bandwidth occupation), etc. Means to ensure the transmission efficiency and stability of high-priority data.

[0071] (4) NAT management module: Solve the address conflict problem of high-speed data private network and public data transmission network. Through DNAT / SNAT rule configuration (such as private IP and public IP mapping), realize the safe access of enterprise connector equipment, hide the internal network topology at the same time, and improve the network security.

[0072] (5) Version management module: Responsible for the whole life cycle management and control of gateway device firmware and software version, including version query (i.e. current running version confirmation), upgrade package management (such as new version upload, verification), remote upgrade (including batch / on-demand upgrade) and version rollback (i.e. restore historical stable version when current version is abnormal), to ensure the continuous iteration and running stability of gateway function.

[0073] Based on the above network level architecture optimization, the method described in this embodiment completes the closed-loop data flow from high-speed data network subscription, network opening triggered by initiating data transaction, network closing after transaction, and high-speed data network unsubscription through the cooperation of high-speed data network management platform, access side controller, backbone network deterministic controller, soft data gateway and enterprise connector. Specifically, as shown in Figure 1 the figure, it includes the following steps:

[0074] Step S202, return the soft data gateway download address to the supplier and the demander based on their subscription request; when the soft data gateway corresponding to the supplier and the demander is installed and put into operation, the Deny rule is uniformly issued to each soft data gateway.

[0075] This step is in the high-speed data network subscription stage, which is used to realize the plug-and-play deployment of soft data gateway and establish the unified management foundation of platform to enterprise access equipment. The Deny rule is used to ensure the safe isolation of network business between the corresponding soft data gateways.

[0076] In a specific implementation, the enterprise side performs the following operations: an enterprise user initiates a subscription request for a high-speed data network, and the enterprise connector or data flow service platform synchronizes enterprise subscription information to the high-speed data network management platform through an API interface. At this time, the high-speed data network management platform automatically opens an account for the enterprise and returns a download address of a software data gateway. The enterprise will pull the corresponding image file from the high-speed data network management platform to the enterprise connector or data flow service platform according to the download address to complete one-key installation. In the embodiment, the enterprise connector includes a supplier connector and a demander connector. The corresponding software data gateway includes a supplier gateway and a demander gateway; they will start automatically after installation and report to the high-speed data network management platform.

[0077] Step S204, obtaining a transaction request initiated by a demander to a supplier, and generating a business identification ID based on the transaction request.

[0078] Specifically, the transaction request contains the following contents: (1) transaction object: demander-enterprise A, supplier-enterprise B. (2) transmission network: channel type-high-speed data private network. (3) business parameters: 3.1-transaction type-file transmission, real-time data flow; 3.2-service quality requirement-basic bandwidth: ≥ [X] Mbps, end-to-end delay: ≤ [Y] ms, security level: meet [Z] level protection requirements of the Data Security Law. (4) additional requirements: 4.1-transmission encryption standard: SM4 national encryption algorithm; 4.2-network reliability: 99.99% availability.

[0079] The business identification ID includes the following contents: demander information, supplier information, and demand network quality; the demander information and the supplier information each include: enterprise name, enterprise connector address, and software data gateway name. As a specific implementation, in order to improve the security and logicality of data transaction, in combination with the above-mentioned Figure 2 As shown in FIG. 7, before obtaining the business identification ID, the following operations are further included:

[0080] Step S20402, verifying the transaction qualification of the supplier and the demander based on the transaction request.

[0081] Specifically, the transaction qualification includes transaction identity and transaction permission.

[0082] Step S20404, generating a network work order after the verification is passed, to generate the business identification ID based on the network work order.

[0083] Step S206, sending a configuration instruction to the software data gateway corresponding to the demander and the supplier based on the business identification ID to realize the interconnection between the demander connector and the supplier connector and the demand network quality setting during data transmission.

[0084] In the embodiment, the configuration instruction includes NAT conversion, whitelist setting, and QoS setting. The NAT conversion is used to convert the address of the supply-side connector and the address of the demand-side connector into an intranet address in the same network segment; the whitelist is used to open the communication connection between the supply-side connector and the demand-side connector; and the QoS setting is used to ensure the data transmission quality of the supply-side connector and the demand-side connector.

[0085] In step S208, an independent VPN instance is allocated for the service ID, and the demand network quality is bound to the independent VPN instance to build an isolated transmission tunnel based on a deterministic network technology.

[0086] As a preferred embodiment, in combination with Figure 3 As shown in the figure, the corresponding setting of the forwarding path is also performed in the following manner:

[0087] In step S20802, a path instruction is embedded in the header of the deterministic network to specify a forwarding path for the isolated transmission tunnel.

[0088] In the embodiment, the forwarding path includes a main forwarding path and a backup forwarding path, and the backup forwarding path is automatically switched to when a link fault exists in the main forwarding path during data flow.

[0089] In step S20804, a service priority is carried for a segment identifier of the deterministic network to realize the priority forwarding of corresponding data.

[0090] Based on steps S20802-S20804, the transmission quality during data flow can be further ensured through the setting of the main and backup paths and the setting of the service priority. In specific implementation, in order to meet the above requirements, the corresponding deterministic network technology is an SRv6 deterministic network technology.

[0091] As another preferred embodiment, in combination with Figure 4 As shown in the figure, the network between the demand-side connector and the backbone network, and the network between the supply-side connector and the backbone network are set in the following manner:

[0092] In step S20822, the soft data gateway corresponding to the supply side and the demand side are both accessed to the backbone network built based on a deterministic network through a dual-mode network channel.

[0093] Specifically, the dual-mode network includes an Internet channel and a high-speed data private network channel. The Internet channel has the characteristics of low cost and can provide cost-effective transmission services; the high-speed data private network channel guarantees ultra-low latency and SLA reachability through MPLS / VPLS enterprise-level private lines, and realizes the optimization of cost and performance; and thus the data transmission requirements of different customer groups can be met.

[0094] At this time, the corresponding network settings of the access side and the backbone network can be implemented based on steps S204-S208. Specifically, in the implementation process, the data flow service platform will call the high-speed data network management platform through the standardized API interface, the platform verifies the transaction qualifications (such as identity authentication, permission verification) of enterprise A and enterprise B (i.e. demand side, supply side), after verification, generates a network work order, generates a business identification ID according to the work order demand, and automatically calls the edge access controller to send configuration instructions (NAT conversion, QoS setting, whitelist setting, etc.) to the soft data gateway of both parties, generates the internal network IP of the connector, and ensures the intercommunication between the supply side connector and the demand side connector; call the backbone network deterministic controller to open the high-speed data network tunnel corresponding to the transaction business of the transaction parties. Further specifically, the QoS setting is used to configure the network strategy according to the transaction demand, including exclusive bandwidth (supporting bandwidth elastic setting), end-to-end delay and other indicators. The whitelist setting allows only the IP addresses of the enterprise A connector and the enterprise B connector to access, limits unrelated devices to access, and the enterprise A connector and the enterprise B connector complete communication parameter negotiation (such as encryption key, port mapping) through the internal network IP address allocated by the platform, and ensures the privacy of the transmission link.

[0095] For ease of understanding, the following example is given: define the demand side as enterprise A and the supply side as enterprise B. Enterprise A needs to obtain the business data set of enterprise B, and the transmission bandwidth needs to reach 200Mbps. After identity authentication, both parties have subscribed to high-speed data network services (i.e. installed corresponding soft data gateway), and the APN001 information of the business identification record generated according to the network work order is shown in Table 1.

[0096] Table 1 Specific information of business identification

[0097]

[0098] According to the corresponding information of the business identifier ID, the platform calls the access side controllers of enterprise A and enterprise B, performs NAT conversion, converts the address 100.70.0.10 of the supply side connector (34256724LJQ) into the intranet address 10.0.0.234 / 24, converts the address 200.70.0.10 of the demand side connector (2342124LJQ) into 10.0.1.234 / 24, and punches through the network connection from the demand side connector to the demand side soft data gateway to the demand side connector to the supply side connector by setting a whitelist; the configuration information of QoS limiting speed 200 Mbps for this intranet network segment is issued to the soft data gateways of the two parties, so as to ensure the bandwidth of the access side. At the same time, the tunnel information of the two parties of the soft data gateway to the backbone network is constructed, and the IPsec+GRE mode is adopted for encrypted transmission, so as to ensure the data security of the access side network transmission. On the backbone network side, the deterministic business (VPN+SRv6 deterministic network technology+business identifier ID policy template diversion) for this business identifier is constructed. Specifically, an independent VPN instance (such as VRF) is allocated for each business identifier ID, and the independent VPN instance is bound to QoS limiting speed 200 Mbps. At this time, even if multiple enterprises are concurrent transactions, they can be isolated through different VPN channels to avoid traffic mixing. The SRv6 deterministic network technology embeds "path instructions (Segments)" in the IPv6 header. The platform specifies a fixed forwarding path (such as bypassing congested nodes) for the transaction channel through the pre-set SRv6 Policy, so as to ensure the end-to-end delay jitter. The SID (segment identifier) of SRv6 can carry the business priority, which is combined with the "QoS configuration" (200 Mbps bandwidth guarantee index) in the VPN to realize the priority forwarding of transaction traffic and avoid being squeezed out of resources by ordinary traffic. SRv6 supports BFD (Bidirectional Forwarding Detection) and FRR (Fast Reroute). If the link fails, it can quickly switch to the backup forwarding path to ensure the business continuity of the ongoing transaction. Thus, the traditional IP network "best effort" forwarding mode is broken through, and the deterministic transmission capability of "delay commitment, path anticipation" is provided for transaction type business.

[0099] In the specific data transmission and transaction process, the two-level encryption architecture of access side and backbone network is adopted at the transmission layer, and the transmission is performed through a special channel to avoid public network exposure risk. Specifically, for access side encryption, a private channel between enterprise connectors is established based on IPsec+GRE tunnel; for backbone network encryption, operator-level transmission protection is realized through SRv6.

[0100] At the same time, full-link intelligent supervision is also performed in the data transmission and transaction process to further ensure the data transmission reliability. Specifically, in combination with Figure 5 As shown in the figure, the method comprises the following steps:

[0101] Step S20902, obtaining the online state and real-time network transmission quality of the soft data gateway corresponding to the supply side and the demand side.

[0102] Specifically, the real-time network transmission quality includes real-time bandwidth, real-time delay, real-time packet loss rate, and real-time jitter.

[0103] Step S20904, when the soft data gateway is offline or the real-time network transmission quality is lower than the required network quality, sending a warning message to the background control end.

[0104] At this time, based on steps S20902-S20904, the corresponding early warning mechanism can ensure the smooth progress of the entire data transmission.

[0105] Continuing, after the data transaction is completed, the following steps are performed:

[0106] Step S210, when the data transaction based on the end-to-end transmission network constructed by the supply side connector, the isolated transmission channel, and the demand side connector is completed, deleting the independent VPN instance to close the isolated transmission tunnel, and deleting each configuration instruction to close the intranet network between the supply side connector and the demand side connector.

[0107] Step S212, obtaining the unsubscription request of the supply side and the demand side to return permission instructions to them.

[0108] In the embodiment, the permission instruction is used to allow the supply side and the demand side to uninstall the corresponding soft data gateway. At this time, based on steps S210-S212, resource release and link cleaning can be performed when the transaction is completed, realizing dynamic on-demand allocation of network resources.

[0109] As can be seen from the above, the method of the embodiment has the following technical advantages:

[0110] (1) Through the combination of "enterprise connector + one-key installation of soft data gateway", the enterprise end can complete the access without professional IT personnel. The enterprise only needs to send a subscription request to trigger the automatic download and start of the soft data gateway. The platform side opens an account through the enterprise management module, allocates a platform intranet address, and links the network controller to generate enterprise, connection relationship, IP pool, and other network resources. The whole process can realize the corresponding network parameter configuration without manual operation of the enterprise. It breaks the traditional mode of manual on-site configuration of routers and firewalls for dedicated line access, and greatly reduces the use threshold of enterprises.

[0111] (2) Based on the transaction-driven dynamic network resource scheduling mechanism, the automation process of transaction request is realized. When the demand side submits a transaction request through the demand side connector, it only needs to specify the network index, and the platform can generate a network work order and automatically call the edge access controller to complete the QoS configuration (bandwidth / latency guarantee), whitelist (security isolation), and backbone network bidirectional virtual private channel creation. The gateway side synchronously receives the configuration instructions issued by the platform, and the whole process is free of manual intervention, with the time delay from transaction request to network opening compressed to minutes. The traditional "static network resource pre-allocation" mode is upgraded to "dynamic on-demand allocation", and the network resources (bandwidth, IP, channel) are deeply bound to the transaction scenario, realizing the closed-loop automation of "transaction initiation-resource scheduling-network connection" and improving the resource utilization rate by more than 60%.

[0112] (3) The two-way symmetric inter-enterprise virtual intranet isolation technology builds a "end-to-end encryption + intranet IP isolation" secure communication system. During the transaction process, the supply and demand sides communicate through "high-speed virtual intranet", and only the intranet IP of the other connector can be seen, and the physical network layer is not directly exposed, and the platform realizes the intercommunication of only transaction-related IPs through whitelist restriction. The virtual channel is managed by the platform, supporting two-way symmetric QoS guarantee (such as low delay and jitter control), meeting the needs of financial and industrial scenarios that require real-time performance. At the same time, unlike the "single-point access" mode of traditional VPN, the "two-end symmetric isolation" mechanism is created, which not only guarantees the security of cross-enterprise data transmission (prevents intermediate node eavesdropping), but also ensures business continuity through a dedicated channel.

[0113] (4) The transaction lifecycle-driven network resource automatic recycling mechanism realizes the whole-process closed loop of transaction closure and resource release. After the transaction is completed, the enterprise only needs to trigger "transaction closure", and the platform automatically calls the edge access controller to clear the whitelist, delete the QoS configuration, and notify the gateway on both sides to recycle the channel resources, realizing the intranet network closure. The resource recycling granularity is accurate to "single transaction channel", avoiding the waste problem of traditional dedicated line "long-term occupation of resources". The real-time linkage mechanism of "transaction state-network resources" is established, and the resource is recycled in seconds through event-driven (rather than timed scanning), which improves the network resource reuse rate by more than 40% and reduces the use cost of enterprises.

[0114] The above program can run in a processor, or can also be stored in a memory (or called computer readable storage medium), the computer readable medium includes permanent and non-permanent, movable and non-movable medium can be realized by any method or technology information storage. Information can be computer readable instructions, data structure, program module or other data. Examples of computer storage medium include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disc read only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage device or any other non-transmission medium, which can be used to store information that can be accessed by a computing device. According to the definition in this paper, computer readable medium does not include temporary computer readable medium, such as modulated data signal and carrier wave.

[0115] These computer programs can also be loaded into a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate computer implemented processing, so that the instructions executed on the computer or other programmable device provide a process for implementing the functions specified in the flow Figure 1 One flow or multiple flows and / or the functions specified in the block Figure 1 One block or multiple blocks, and different steps can be realized by different modules.

[0116] The embodiment also provides a data flow system based on high-speed data network, including a pre-built high-speed data network management platform. And combined with Figure 6 As shown in the figure, it includes the following functional modules:

[0117] The order feedback module is used for returning the soft data gateway download address to the supply side and the demand side based on the order request of the supply side and the demand side; when the soft data gateway corresponding to the supply side and the demand side is installed and online, the Deny rule is uniformly issued to each soft data gateway, and the safety isolation of network service between the corresponding soft data gateways is ensured.

[0118] The identity generation module is used for obtaining the transaction request initiated by the supply side to the demand side, and generating a business identity ID based on the transaction request; wherein the business identity ID includes: demand side information, supply side information and demand network quality; the demand side information and the supply side information both include: enterprise name, enterprise connector address and soft data gateway name.

[0119] The access network setting module is configured to send a configuration instruction to the soft data gateway corresponding to the demand side and the supply side based on the service ID to realize interconnection between the demand side connector and the supply side connector and data transmission quality setting; wherein the configuration instruction includes NAT conversion, whitelist setting and QoS setting.

[0120] The backbone network setting module is configured to allocate an independent VPN instance for the service ID, and bind the demand network quality to the independent VPN instance to build an isolated transmission tunnel based on deterministic network technology;

[0121] The transaction end feedback module is configured to delete the independent VPN instance to close the isolated transmission tunnel and delete each configuration instruction to close the internal network between the supply side connector and the demand side connector when the data transaction between the supply side and the demand side based on the end-to-end transmission network constructed by the supply side connector, the isolated transmission channel and the demand side connector is ended.

[0122] The unsubscribe feedback module is configured to obtain the unsubscribe request of the supply side and the demand side to return a permission instruction to them; wherein the permission instruction is used to allow the supply side and the demand side to unload the corresponding soft data gateway.

[0123] Since the system is built based on the method, the above has been explained, and will not be repeated here.

[0124] For example, the backbone network setting module includes:

[0125] The path setting unit is configured to embed a path instruction in the header of the deterministic network to specify a forwarding path for the isolated transmission tunnel; wherein the forwarding path includes a main forwarding path and a backup forwarding path, and if there is a link fault in the main forwarding path in the data flow, the backup forwarding path is automatically switched to.

[0126] The priority setting unit is configured to carry service priority for the segment identifier of the deterministic network to realize priority forwarding of the corresponding data.

[0127] For another example, the identification generation module includes:

[0128] The qualification verification unit is configured to verify the transaction qualification of the supply side and the demand side based on the transaction request; wherein the transaction qualification includes transaction identity and transaction authority.

[0129] The work order generation unit is configured to generate a network work order after verification to generate the service ID based on the network work order.

[0130] At the same time, combined with Figure 7Also shown, there is provided an electronic device comprising at least one processor coupled with a memory having stored therein a computer program configured to be executed by the processor to perform the method.

[0131] Further, there is also provided a computer readable storage medium having stored thereon a computer program for execution by a processor to implement the method.

[0132] The system, electronic device and storage medium described in the embodiments achieve the lightweight access-dynamic scheduling-symmetrical isolation-automatic recycling-standard coordination full-link innovation, solve the problems of complex access, resource waste, low security and slow response in traditional cross-enterprise data transmission, and provide a safe, reliable and high-speed network service for enterprise data circulation and transaction, which can be well applied in B2B real-time transaction, industrial internet, financial data interaction and the like.

[0133] Although the present application has been disclosed with reference to the preferred embodiments thereof, it is not intended to limit the application. Those skilled in the art with ordinary knowledge can make various modifications and improvements without departing from the spirit and scope of the application. Therefore, the scope of protection of the present application shall be subject to the scope defined by the claims.

Claims

1. A data flow method based on a high-speed data network, characterized by, Based on the pre-built high-speed data network management platform, and the designed soft data gateway; The high-speed data network management platform comprises an enterprise management module, a transaction network demand management module, an API interface management module and a controller docking module; the enterprise management module is used for maintaining the connection relationship of the connector and the soft data gateway, managing enterprise information, and providing underlying support for multi-tenant isolation and business domain division; the transaction network demand management module is used for the network resource scheduling demand of data transaction, and realizes the matching of business demand and network resources; the API interface management module is used for providing standardized interface services and security control, and is called by the enterprise connector or the data flow service platform when opening and closing the network resources; the controller docking module is used for setting the access network controller, determining the controller setting, and setting the bidirectional communication between the access side network and the backbone network, so as to convert the upper business strategy into device execution instructions, and build an automatic closed loop between the business intention and the network configuration; The soft data gateway comprises a firewall management module, a QoS management module and a NAT management module; the firewall management module performs access control on the data flow entering and exiting the gateway based on the preset strategy, and guarantees the confidentiality and integrity of data transmission; the QoS management module provides differentiated network resource allocation strategies for the demand of different types of data transaction business; the NAT management module solves the address conflict problem between the high-speed data private network and the public data transmission network, realizes the safe access of the enterprise connector device through the DNAT / SNAT rule configuration, hides the internal network topology, and improves the network security; It comprises: Based on the subscription request of the supply side and the demand side, the soft data gateway download address is returned to them; when the soft data gateways corresponding to the supply side and the demand side are installed and put into operation, the Deny rule is uniformly issued to each soft data gateway; Obtain the transaction request initiated by the demand side to the supply side, and generate a business identification ID based on the transaction request; wherein the business identification ID comprises: demand side information, supply side information and demand network quality; the demand side information and the supply side information both comprise: enterprise name, enterprise connector address and soft data gateway name; Based on the business identification ID, a configuration instruction is sent to the soft data gateways corresponding to the demand side and the supply side to realize the interconnection between the demand side connector and the supply side connector and the setting of the demand network quality during data transmission; wherein the configuration instruction comprises: NAT conversion, whitelist setting and QoS setting; The supply side connector address and the demand side connector address are converted into internal network addresses of the same network segment through NAT conversion; the communication connection between the supply side connector and the demand side connector is opened through whitelist setting; the demand network quality is set through QoS setting to ensure the data transmission quality of the supply side connector and the demand side connector; allocating an independent VPN instance for the service identification ID, and binding the required network quality to the independent VPN instance to build an isolated transmission tunnel based on deterministic network technology; wherein the soft data gateway corresponding to the supplier and the demander accesses the backbone network built based on deterministic network through a dual-mode network channel; wherein the dual-mode network includes an Internet channel and a high-speed data private network channel; deleting the independent VPN instance to close the isolated transmission tunnel and deleting each configuration instruction to close the intranet network between the supplier connector and the demander connector when determining that the data transaction based on the end-to-end transmission network built by the supplier connector, the isolated transmission tunnel and the demander connector is completed; obtaining the unsubscription request of the supplier and the demander to return a permission instruction to them; wherein the permission instruction is used to allow the supplier and the demander to uninstall the corresponding soft data gateway.

2. The data flow communication method based on high-speed data network according to claim 1, characterized in that, The method for allocating an independent VPN instance for the service identification ID, and binding the required network quality to the independent VPN instance to build an isolated transmission tunnel based on deterministic network technology; includes: embedding path instructions in the header of the deterministic network to specify a forwarding path for the isolated transmission tunnel; wherein the forwarding path includes a main forwarding path and a backup forwarding path, and the backup forwarding path is automatically switched to when there is a link fault in the main forwarding path in the data flow; implementing the priority forwarding of the corresponding data based on the service priority carried by the segment identifier in the deterministic network.

3. The data flow communication method based on high-speed data network according to claim 1, characterized in that, The method for obtaining the transaction request initiated by the demander to the supplier, and generating a service identification ID based on the transaction request; includes: verifying the transaction qualifications of the supplier and the demander based on the transaction request; wherein the transaction qualifications include transaction identity and transaction authority; generating a network work order after the verification is passed to generate the service identification ID based on the network work order.

4. The data flow communication method based on high-speed data network according to claim 1, characterized in that, The method includes: obtaining the online state and real-time network transmission quality of the soft data gateway corresponding to the supplier and the demander; wherein the real-time network transmission quality includes real-time bandwidth, real-time delay, real-time packet loss rate and real-time jitter; sending a warning information to the background control end when the soft data gateway is offline or the real-time network transmission quality is lower than the required network quality.

5. A data flow system based on a high-speed data network, characterized by The method built based on any one of claims 1-4 includes: a subscription feedback module for returning a soft data gateway download address to the supplier and the demander based on their subscription request; and uniformly issuing a Deny rule to each soft data gateway when the soft data gateway corresponding to the supplier and the demander is installed and online; an identification generation module for obtaining the transaction request initiated by the demander to the supplier, and generating a service identification ID based on the transaction request; wherein the service identification ID includes demander information, supplier information and required network quality; and the demander information and the supplier information both include enterprise name, enterprise connector address and soft data gateway name. The access network setting module is configured to send configuration instructions to the soft data gateways corresponding to the demand side and the supply side based on the service ID to set the quality of the demand network when the interconnection and data transmission between the demand side connector and the supply side connector are implemented; wherein the configuration instructions include NAT conversion, white list setting and QoS setting; The backbone network setting module is configured to allocate an independent VPN instance for the service ID, and bind the quality of the demand network to the independent VPN instance to build an isolated transmission tunnel based on deterministic network technology; The transaction end feedback module is configured to delete the independent VPN instance to close the isolated transmission tunnel and delete each configuration instruction to close the internal network between the supply side connector and the demand side connector when the data transaction based on the end-to-end transmission network built by the supply side connector, the isolated transmission tunnel and the demand side connector is ended; The subscription feedback module is configured to obtain the subscription request of the supply side and the demand side to return permission instructions to them; wherein the permission instructions are used to allow the supply side and the demand side to unload the corresponding soft data gateway.

6. The high-speed data network-based data flow system according to claim 5, wherein, The backbone network setting module includes: The path setting unit is configured to embed path instructions in the header of the deterministic network to specify a forwarding path for the isolated transmission tunnel; wherein the forwarding path includes a main forwarding path and a backup forwarding path, and if there is a link fault in the main forwarding path in the data flow, the backup forwarding path is automatically switched to; The priority setting unit is configured to realize the priority forwarding of the corresponding data based on the service priority carried by the segment identifier in the deterministic network.

7. The high-speed data network based data flow system of claim 5, wherein, The identification generation module includes: The qualification verification unit is configured to verify the transaction qualifications of the supply side and the demand side based on the transaction request; wherein the transaction qualifications include transaction identity and transaction authority; The work order generation unit is configured to generate a network work order after the verification is passed to generate the service ID based on the network work order.

8. An electronic device, comprising: The computer program is configured to be run by the processor to execute the method of any one of claims 1-4.

9. A computer-readable storage medium, characterized in that, The computer program is configured to be run by the processor to execute the method of any one of claims 1-4.

Citation Information

Patent Citations

  • VPN construction method and apparatus, and computer-readable storage medium

    CN109274570A