High-security transmission method and system for data of GreatDB database

By acquiring the fixed IP address of the GreatDB database server for data transmission, leveraging the security compensation coefficient of the relay edge device and the server's encryption capabilities, and planning the data transmission method, the problems of security, server load, and storage pressure in traditional database data transmission are solved, achieving highly secure and stable data transmission.

CN120822232AActive Publication Date: 2025-10-21GREATOPENSOURCE INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511310268.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2025-10-21
Estimated Expiration
2045-09-15

AI Technical Summary

Technical Problem

Traditional database data transmission faces the problems of fixed IP paths being vulnerable to theft attacks, the inability to apply dynamic IP path adjustment, increased server load and storage pressure on the destination end. It is difficult to balance the security of data transmission, server load and storage pressure on the destination end while ensuring the stable operation of the database server.

Method used

By obtaining the fixed IP data transmission tasks of the GreatDB database server, a data transmission requirement list is established. Utilizing the security compensation coefficient of the relay edge device and the encryption capabilities of the server, the data transmission method is planned, selecting either encrypted transmission via the GreatDB database server or transmission via a dynamic IP path through the relay edge device.

Benefits of technology

While ensuring the stable operation of the database server, a scientific and reasonable high-security data transmission was achieved by balancing the security of data transmission, server load, and destination storage pressure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120822232A_ABST
    Figure CN120822232A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of databases, and discloses a GreatDB database data high-security transmission method and system, and the method comprises the steps: obtaining a plurality of fixed IP data transmission tasks of a GreatDB database server in a target time period, building a data transmission demand list, employing the security compensation coefficient of a transfer edge device configured by the GreatDB database server, and achieving the high-security transmission of the GreatDB database data. And based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, each fixed IP data transmission task is planned to select encrypted transmission through the GreatDB database server or data dynamic IP path transmission through the transfer edge device. Therefore, by considering the data processing of the GreatDB database server, the data storage of the second terminal and the security of data transmission of a plurality of fixed IPs in the target time period, based on a scientific and reasonable high-security transmission strategy of the GreatDB database data, on the premise of ensuring the stable operation of the database server, the security of the data transmission of the plurality of fixed IPs in the target time period is improved. And the security of data transmission, the load of the server and the storage pressure of the destination end are balanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of database technology, and in particular to a method and system for highly securely transmitting data from a GreatDB database. Background Art

[0002] The GreatDB database server serves as the core forwarding and processing node between data sources (such as branch databases and IoT devices) and data destinations (such as headquarters data centers and cloud platforms). It is widely used in scenarios such as cross-regional data synchronization, multi-departmental business data aggregation, and data sharing in medical or government systems. Its core functions include extracting key information from transmitted data (such as filtering valid fields) and encrypted forwarding to ensure efficient and secure data transmission.

[0003] However, traditional database data transmission faces multiple technical challenges: on the one hand, fixed IP transmission paths are vulnerable to theft attacks. Although dynamically adjusting IP paths can enhance security, this method cannot be applied because the database needs to maintain a stable connection to ensure data consistency and permission management; on the other hand, the traditional method of relying on the database server itself for encrypted transmission will significantly increase the server load in large-scale data scenarios, resulting in processing delays and reduced concurrency capabilities; in addition, when deploying edge transit nodes to divert the load, the lack of encryption and key information extraction capabilities of edge devices not only reduces the security of data transmission, but also causes storage pressure problems due to the influx of large amounts of raw data, which exceeds the storage and cleanup capabilities of the data destination.

[0004] Therefore, in the field of database data transmission, how to balance the security of data transmission, server load and storage pressure at the destination end while ensuring the stable operation of the database server is a technical problem that needs to be solved urgently. Summary of the Invention

[0005] The present invention provides a method and system for highly secure transmission of GreatDB database data, aiming to solve at least one of the above-mentioned technical problems.

[0006] To achieve the above objectives, the present invention provides a method for transmitting data in a GreatDB database with high security, the method comprising the following steps: Obtain several fixed IP data transmission tasks of the GreatDB database server in a target period; wherein each of the fixed IP data transmission tasks is configured as a data transmission task between a first terminal having a fixed IP transmission source address and a second terminal having a fixed IP transmission destination address; Extract the importance of transmitted data, data transmission security sensitivity, and the amount of periodic forwarding data in each fixed IP data transmission task, and establish a data transmission requirement list; Query the security compensation coefficient of each transit edge device in the transit edge device set configured by the GreatDB database server, and based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, plan the data transmission method for each fixed IP data transmission task for each transmission cycle within the target period, and summarize and generate a data transmission strategy; The data transmission strategy is distributed to the first terminal, the second terminal, the transit edge device and the GreatDB database server, driving the first terminal and the second terminal to perform data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device.

[0007] Optionally, obtain several fixed IP data transmission task steps of the GreatDB database server during the target period, specifically including: receiving a plurality of fixed IP data transmission requests, and executing a task establishment request judgment between a first terminal and a second terminal in the fixed IP data transmission requests; When the task establishment request is judged to meet the requirements, the fixed IP transmission source address, fixed IP transmission destination address and data transmission association information in each fixed IP data transmission request are extracted, and a fixed IP data transmission task corresponding to each fixed IP data transmission request is established.

[0008] Optionally, receiving a plurality of fixed IP data transmission requests, and performing a step of determining a task establishment request between a first terminal and a second terminal in the fixed IP data transmission requests, specifically includes: Upon receiving each fixed IP data transmission request sent by the target terminal, extracting the fixed IP transmission source address of the first terminal and the fixed IP transmission destination address of the second terminal in the fixed IP data transmission request, and synchronously generating a task establishment confirmation signal; When the target terminal is the first terminal of the data source, the task establishment confirmation signal is sent to the second terminal, and the second terminal determines whether the first terminal is an allowed data transmission source in the data transmission reception list, and if so, determines that the task establishment request between the first terminal and the second terminal meets the requirements; When the target terminal is the second terminal for data purposes, the task establishment confirmation signal is sent to the first terminal. When a transmission confirmation instruction based on the task establishment confirmation signal feedback from the first terminal is received, it is determined that the task establishment request between the first terminal and the second terminal meets the requirements.

[0009] Optionally, extract the importance of the transmitted data, the security sensitivity of the data transmission, and the amount of periodically forwarded data in each fixed IP data transmission task, and create a data transmission requirement list, specifically including: Parsing the data transmission associated information in each fixed IP data transmission task, and extracting several transmission task keywords in the data transmission associated information; According to several transmission task keywords in the data transmission association information, the importance of transmission data, the data transmission security sensitivity and the amount of periodically forwarded data in each fixed IP data transmission task are determined, and a data transmission requirement list is established.

[0010] Optionally, the step of determining the importance of transmitted data, the security sensitivity of data transmission, and the amount of periodically forwarded data in each fixed IP data transmission task based on the plurality of transmission task keywords in the data transmission association information specifically includes: Calculate the total importance score and the total sensitivity score of the plurality of transmission task keywords according to the method of accumulating the assigned scores based on each transmission task keyword and the preset importance keyword set with the first weight assignment and the preset sensitivity keyword set with the second weight assignment; Calculate the data forwarding volume of each transmission cycle based on the forwarding frequency words and single forwarding data volume in several transmission task keywords; The calculated total importance score, total sensitivity score, and data forwarding volume in each transmission cycle are used as the importance of transmitted data, data transmission security sensitivity, and the volume of periodic forwarding data in the corresponding fixed IP data transmission task, respectively.

[0011] Optionally, the steps for querying the security compensation coefficient of each transit edge device in the transit edge device set configured on the GreatDB database server include: Query the IP dynamic adjustment plan information of the transit edge device set configured by the GreatDB database server; wherein, the IP dynamic adjustment plan information stores the duration of each transit edge device at each moment within the target period from the last periodic IP dynamic adjustment; According to the duration of each transit edge device's dynamic IP adjustment at each moment from the previous period, and based on the numerical growth relationship between the unit duration and the security compensation coefficient, the security compensation coefficient of each transit edge device at each moment in the target period is calculated.

[0012] Optionally, based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, a data transmission mode for each fixed IP data transmission task is planned for each transmission cycle within a target period, and a data transmission strategy step is summarized and generated, specifically including: Obtaining the encryption processing capability of the GreatDB database server; wherein the encryption processing capability is configured as the maximum amount of data to be encrypted per transmission cycle obtained in advance through testing; Querying the data storage capacity reported in advance by each second terminal on the GreatDB database server; wherein the data storage capacity is configured as the maximum data storage capacity within the target period; Based on the data transmission demand list of several fixed IP data transmission tasks within the target time period and the security compensation coefficient of each transit edge device, taking into account the encryption processing capability of the GreatDB database server and the data storage capability of each second terminal, with the encryption processing capability and data storage capability as constraints, and with the minimum data transmission risk as the optimization goal, the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target time period is optimized; wherein, the data transmission mode includes compression and encryption transmission from the first terminal to the second terminal via the GreatDB database server and direct transmission from the first terminal to the second terminal via the transit edge device; Summarize the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target period and generate a data transmission strategy.

[0013] Optionally, considering the encryption processing capability of the GreatDB database server and the data storage capability of each second terminal, with encryption processing capability and data storage capability as constraints and minimum data transmission risk as the optimization goal, the data transmission method and steps for each fixed IP data transmission task for each transmission cycle within the target period are optimized, specifically including: Considering the maximum amount of data that the GreatDB database server performs encryption processing on in each transmission cycle and the maximum amount of data storage of each second terminal within the target period; After each fixed IP data transmission task that performs data transmission from the first terminal to the second terminal is assigned to the GreatDB database server or the transit edge device in each transmission cycle within the target time period, the sum of the amount of periodic forwarding data of all fixed IP data transmission tasks assigned to the GreatDB database server in each transmission cycle and the amount of compressed data determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs is less than the maximum amount of data encrypted by the GreatDB database server in each transmission cycle as a first constraint condition; the sum of the amount of data transmitted by the GreatDB database server received by each second terminal in different transmission cycles within the target time period, the amount of data transmitted by the fixed IP data transmission task to which the data amount belongs, determined by the first received data amount determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs, and the second received data amount determined by the amount of data transmitted by the transit edge device received in different transmission cycles is less than the maximum data storage capacity of the second terminal within the target time period as a second constraint condition; the optimization goal is to minimize the sum of the products of the data transmission security sensitivity of several fixed IP data transmission tasks and the security compensation coefficients at each moment within the target time period when they are assigned to the transit edge device; An optimization algorithm is used to solve the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target time period.

[0014] Optionally, the data transmission policy is distributed to the first terminal, the second terminal, the transit edge device, and the GreatDB database server, driving the first terminal and the second terminal to perform the steps of data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device, specifically including: Distribute the data transmission strategy to the first terminal, the second terminal, the transit edge device and the GreatDB database server; Each first terminal transmits the data of the fixed IP data transmission task to the second terminal according to the data transmission method assigned in the data transmission strategy, using data encryption transmission through the GreatDB database server or data dynamic IP path transmission through the transit edge device in each transmission cycle of the target time period.

[0015] In addition, to achieve the above-mentioned purpose, the present invention also provides a GreatDB database data high-security transmission system, comprising: An acquisition module is configured to acquire a number of fixed IP data transmission tasks of the GreatDB database server during a target period; wherein each of the fixed IP data transmission tasks is configured as a data transmission task between a first terminal having a fixed IP transmission source address and a second terminal having a fixed IP transmission destination address; Establish a module for extracting the importance of transmitted data, data transmission security sensitivity, and the amount of periodically forwarded data in each fixed IP data transmission task, and establish a data transmission requirement list; A summary module is used to query the security compensation coefficient of each transit edge device in the transit edge device set configured by the GreatDB database server, and based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, plan the data transmission mode for each fixed IP data transmission task for each transmission cycle within the target period, and summarize and generate a data transmission strategy; The transmission module is used to distribute the data transmission strategy to the first terminal, the second terminal, the transit edge device and the GreatDB database server, driving the first terminal and the second terminal to perform data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device.

[0016] The beneficial effects of the present invention are: a high-security transmission method and system for GreatDB database data are proposed, by obtaining several fixed IP data transmission tasks of the GreatDB database server in the target time period, establishing a data transmission demand list, and utilizing the security compensation coefficient of the transit edge device configured by the queried GreatDB database server. Based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, each fixed IP data transmission task is planned to choose encrypted transmission via the GreatDB database server or dynamic IP path transmission of the data via the transit edge device within the target time period. Therefore, by considering the data processing of the GreatDB database server, the data storage of the second terminal and the security of several fixed IP data transmissions within the target time period, based on a scientific and reasonable high-security transmission strategy for GreatDB database data, the security of data transmission, server load and storage pressure at the destination end are balanced under the premise of ensuring the stable operation of the database server. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 Schematic diagram of the process of a high-security data transmission method of the GreatDB database according to an embodiment of the present invention; Figure 2 This is a structural diagram of the GreatDB database data high-security transmission system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0019] The embodiment of the present invention provides a method for transmitting data in a GreatDB database with high security. Figure 1 , Figure 1 This is a flow chart of the GreatDB database data high-security transmission method according to an embodiment of the present invention.

[0020] In this embodiment, a method for transmitting data in a GreatDB database with high security includes the following steps: S1: Obtain several fixed IP data transmission tasks of the GreatDB database server in a target period; wherein each of the fixed IP data transmission tasks is configured as a data transmission task between a first terminal having a fixed IP transmission source address and a second terminal having a fixed IP transmission destination address; S2: Extract the importance of transmitted data, data transmission security sensitivity, and the amount of periodic forwarding data in each fixed IP data transmission task, and establish a data transmission requirement list; S3: Query the security compensation coefficient of each transit edge device in the transit edge device set configured by the GreatDB database server, and based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, plan the data transmission method for each fixed IP data transmission task for each transmission cycle within the target period, and summarize and generate a data transmission strategy; S4: Distribute the data transmission strategy to the first terminal, the second terminal, the transit edge device and the GreatDB database server, driving the first terminal and the second terminal to perform data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device.

[0021] It should be noted that traditional database data transmission faces multiple technical challenges: on the one hand, fixed IP transmission paths are vulnerable to theft attacks. Although dynamically adjusting IP paths can enhance security, this method cannot be applied because the database needs to maintain a stable connection to ensure data consistency and permission management; on the other hand, the traditional method of relying on the database server itself for encrypted transmission will significantly increase the server load in large-scale data scenarios, resulting in processing delays and reduced concurrency capabilities; in addition, when deploying edge transit nodes to divert the load, the lack of encryption and key information extraction capabilities of edge devices not only reduces the security of data transmission, but also causes storage pressure problems due to the influx of large amounts of raw data, which exceeds the storage and cleanup capabilities of the data destination.

[0022] In order to solve the above problems, this embodiment obtains several fixed IP data transmission tasks of the GreatDB database server in the target period, establishes a data transmission demand list, and uses the security compensation coefficient of the transit edge device configured by the GreatDB database server. Based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, each fixed IP data transmission task is planned to choose encrypted transmission via the GreatDB database server or data dynamic IP path transmission via the transit edge device. Therefore, by considering the data processing of the GreatDB database server, the data storage of the second terminal, and the security of several fixed IP data transmissions within the target period, based on the scientific and reasonable high-security transmission strategy of the GreatDB database data, the security of data transmission, server load and storage pressure at the destination end are balanced under the premise of ensuring the stable operation of the database server.

[0023] In a preferred embodiment, the steps of obtaining several fixed IP data transmission tasks of the GreatDB database server in the target period specifically include: S11: receiving a plurality of fixed IP data transmission requests, and executing a task establishment request determination between a first terminal and a second terminal in the fixed IP data transmission requests; S12: When the task establishment request is judged to meet the requirements, the fixed IP transmission source address, the fixed IP transmission destination address and the data transmission association information in each fixed IP data transmission request are extracted, and a fixed IP data transmission task corresponding to each fixed IP data transmission request is established.

[0024] In this embodiment, by receiving several fixed IP data transmission requests, when it is determined that the conditions for establishing a transmission task are met, a fixed IP data transmission task corresponding to each fixed IP data transmission request is generated, and the fixed IP transmission source address, fixed IP transmission destination address and data transmission association information in the fixed IP data transmission request are placed in the generated fixed IP data transmission task.

[0025] It should be noted that the fixed IP transmission source address is the address of the first terminal in the fixed IP data transmission task, and the fixed IP transmission destination address is the address of the second terminal in the fixed IP data transmission task. The fixed IP transmission source address and the fixed IP transmission destination address are used for the fixed IP data transmission task. When each transmission cycle within the target period is allocated to the GreatDB database server or the transit edge device, the GreatDB database server or the transit edge device is used to perform data transmission between the two addresses.

[0026] In addition, the data transmission association information is configured as the data transmission description text corresponding to the fixed IP data transmission task. Through the data transmission description text, the importance of the transmission data, the data transmission security sensitivity and the data volume of the periodic forwarding data of the fixed IP data transmission task can be known. By parsing the data transmission association information, data support can be provided for the subsequent planning of each fixed IP data transmission task to select encrypted transmission through the GreatDB database server or dynamic IP path transmission of data through the transit edge device.

[0027] On this basis, a plurality of fixed IP data transmission requests are received, and a step of determining a task establishment request between the first terminal and the second terminal in the fixed IP data transmission requests is performed, specifically comprising: S111: upon receiving each fixed IP data transmission request sent by the target terminal, extracting the fixed IP transmission source address of the first terminal and the fixed IP transmission destination address of the second terminal in the fixed IP data transmission request, and synchronously generating a task establishment confirmation signal; S112: When the target terminal is the first terminal of the data source, the task establishment confirmation signal is sent to the second terminal. The second terminal determines whether the first terminal is an allowed data transmission source in the data transmission receiving list. If so, it is determined that the task establishment request between the first terminal and the second terminal meets the requirements. S113: When the target terminal is the second terminal for data purposes, the task establishment confirmation signal is sent to the first terminal. When a transmission confirmation instruction fed back by the first terminal based on the task establishment confirmation signal is received, it is determined that the task establishment request between the first terminal and the second terminal meets the requirements.

[0028] In this embodiment, the received fixed IP data transmission request can be sent by the first terminal or the second terminal. Specifically, if the fixed IP data transmission request comes from the first terminal, after extracting the fixed IP transmission source address of the first terminal and the fixed IP transmission destination address of the second terminal from the fixed IP data transmission request, a task establishment confirmation signal is generated and sent to the second terminal. The second terminal then determines whether the first terminal is a permitted data transmission source based on a pre-generated data transmission reception list. If so, it determines that the task establishment request between the first terminal and the second terminal meets the requirements, and then establishes the fixed IP data transmission task corresponding to the fixed IP data transmission request. If the fixed IP data transmission request comes from the second terminal, after similarly extracting the fixed IP transmission source address of the first terminal and the fixed IP transmission destination address of the second terminal from the fixed IP data transmission request, a task establishment confirmation signal is generated and sent to the first terminal. The first terminal is required to provide a transmission confirmation instruction after confirmation by relevant personnel or procedures, at which point the fixed IP data transmission task corresponding to the fixed IP data transmission request is established.

[0029] It should be noted that this embodiment establishes a fixed IP data transmission task for a fixed IP data transmission request from a first terminal based on the second terminal's (i.e., receiving terminal) permission list. As long as the first terminal is in the second terminal's data source list, the fixed IP data transmission task can be established. In contrast, the establishment of a fixed IP data transmission task for a fixed IP data transmission request from a second terminal is based on human or program verification by the first terminal (i.e., sending terminal). Verification of the second terminal's fixed IP data transmission request by the first terminal is required before the task can be established. Therefore, this embodiment utilizes different authorization rules to establish fixed IP data transmission tasks for the data sending terminal and the data receiving terminal, respectively, providing greater adaptability and security.

[0030] In a preferred embodiment, extracting the importance of transmitted data, the security sensitivity of data transmission, and the amount of periodically forwarded data in each fixed IP data transmission task and establishing a data transmission requirement list step specifically includes: S21: parsing the data transmission associated information in each fixed IP data transmission task, and extracting several transmission task keywords in the data transmission associated information; S22: Determine the importance of transmitted data, data transmission security sensitivity, and the amount of periodically forwarded data in each fixed IP data transmission task based on the multiple transmission task keywords in the data transmission association information, and create a data transmission requirement list.

[0031] On this basis, the steps of determining the importance of the transmitted data, the security sensitivity of the data transmission, and the amount of periodically forwarded data in each fixed IP data transmission task according to the several transmission task keywords in the data transmission association information specifically include: S221: Calculating the total importance score and the total sensitivity score of the plurality of transmission task keywords based on each transmission task keyword and a preset importance keyword set with a first weight assignment and a preset sensitivity keyword set with a second weight assignment by accumulating the assigned scores; S222: Calculating the data forwarding volume of each transmission cycle based on the forwarding frequency words and the single forwarding data volume in the plurality of transmission task keywords; S223: The calculated total importance score, total sensitivity score and data forwarding volume in each transmission cycle are used as the transmission data importance, data transmission security sensitivity and data volume of periodic forwarding data in the corresponding fixed IP data transmission task.

[0032] In this embodiment, the data transmission related information is parsed from each fixed IP data transmission task, and several transmission task keywords are extracted. Then, based on the transmission task keywords, the transmission data importance, data transmission security sensitivity and the amount of periodic forwarding data of each fixed IP data transmission task are determined, so as to establish a data transmission demand list.

[0033] Specifically, it is necessary to first obtain the pre-established importance keyword set and sensitivity keyword set, and then calculate the total importance score and total sensitivity score of several transmission task keywords based on the first weight assignment of each importance keyword in the importance keyword set and the second weight assignment of each sensitivity keyword in the sensitivity keyword set, according to the cumulative assignment score method. The obtained total importance score will be used as the transmission data importance of the fixed IP data transmission task, and the obtained total sensitivity score will be used as the data transmission security sensitivity of the fixed IP data transmission task.

[0034] For example, the importance keyword set may include: high-weighted keywords: core business, critical operations, master data, must not be lost, impacts business continuity, supports core functions, and is related to major decisions; medium-weighted keywords: daily operations, routine data, impacts local functions, and assists in decision-making; and low-weighted keywords: redundant data, backup copies (non-critical), and historical archives (infrequent access). When assigning weights to importance keywords, high-weighted keywords may be assigned 3 points, medium-weighted keywords 2 points, and low-weighted keywords 1 point. If the transmission task keywords for a fixed IP data transmission task include "must not be lost, is related to major decisions, and is related to daily operations," then by accumulating the assigned scores, the total importance score for the fixed IP data transmission task (i.e., the importance of the data being transmitted) can be calculated as 3 points (must not be lost) + 3 points (is related to major decisions) + 2 points (daily operations) = 8 points.

[0035] For example, the sensitivity keyword set may include: extremely high-weighted keywords: classified information, state secrets, military secrets, and unauthorized access that could lead to a major security incident; high-weighted keywords: user privacy data (such as ID card numbers and bank card numbers), trade secrets, core technical data, and disclosure that would incur legal liability; medium-weighted keywords: non-core user information (such as nicknames and regions), internal process data (non-confidential), and disclosure that only impacts reputation; and low-weighted keywords: public data (such as product descriptions and public announcements) and no privacy / confidential attributes. When assigning weights to sensitivity keywords, extremely high-weighted keywords can be assigned 4 points, high-weighted keywords 3 points, medium-weighted keywords 2 points, and low-weighted keywords 1 point. If the transmission task keywords for a fixed-IP data transmission task include "internal process data" and "no privacy attributes," then the total sensitivity score (i.e., data transmission security sensitivity) for the fixed-IP data transmission task can be calculated by accumulating the assigned scores: 2 points (internal process data) + 1 point (no privacy attributes) = 3 points.

[0036] In addition, it is also necessary to extract the forwarding frequency words and single forwarding data volume from several transmission task keywords to calculate the data forwarding volume of each transmission cycle, and use the data forwarding volume of each transmission cycle as the data volume of the periodic forwarding data in the corresponding fixed IP data transmission task.

[0037] For example, the forwarding frequency word is forwarded 30 times in each transmission cycle, and the data volume of a single forwarding is 4 MB. It can be calculated that the data forwarding volume in each transmission cycle is 120 MB.

[0038] It should be noted that the data forwarding volume, importance of transmitted data and data transmission security sensitivity of each transmission cycle calculated by this embodiment will be used as the basis for determining the first constraint condition (data encryption capability of the GreatDB database server), the second constraint condition (data storage capability of the second terminal) and the optimization goal (minimum data transmission risk) in the optimization algorithm when subsequently planning each fixed IP data transmission task to choose encrypted transmission through the GreatDB database server or dynamic IP path transmission of data through the transit edge device.

[0039] Among them, the importance of the transmission data of each fixed IP data transmission task is used to determine the key information extraction ratio of the fixed IP data transmission task in the GreatDB database server, that is, the data extraction rate determined by the ratio of the key information extraction data volume of each transmission cycle to the original data forwarding volume (for example, the data forwarding volume of each transmission cycle is 120MB, the importance of the transmission data is not higher than 2 points, and the data extraction rate is 50%. Then the GreatDB database server will only forward 60MB of data to the second terminal after extracting the key information, which can be greatly reduced). If the importance of the transmission data is higher, more information needs to be retained, and the data extraction rate is higher. If the importance of the transmission data is lower, more information does not need to be retained, and the data extraction rate is lower.

[0040] The relationship between the data extraction rate and the importance of the transmitted data can be divided into preset segments. After determining the data extraction rate of the fixed IP data transmission task, if the fixed IP data transmission task is assigned to the GreatDB database, data extraction and information compression are required according to the corresponding data extraction rate. After extraction and compression, encrypted transmission is performed, which improves the data-information ratio and the transmission security. If the fixed IP data transmission task is assigned to the transit edge device, all the original data forwarding volume will be forwarded, which can alleviate the computing load of the GreatDB database.

[0041] In a preferred embodiment, the step of querying the security compensation coefficient of each transit edge device in the transit edge device set configured by the GreatDB database server specifically includes: S31: querying the IP dynamic adjustment plan information of the transfer edge device set configured by the GreatDB database server; wherein the IP dynamic adjustment plan information stores the duration of each transfer edge device at each moment within the target period from the last periodic IP dynamic adjustment; S32: Calculate the security compensation coefficient of each transit edge device at each moment within the target period based on the duration of each transit edge device's dynamic IP adjustment at each moment from the last period, and based on the numerical growth relationship between the unit duration and the security compensation coefficient.

[0042] In this embodiment, by querying the duration of each transit edge device in the transit edge device set configured by the GreatDB database server at each moment during the target period from the last periodic IP dynamic adjustment, the security compensation coefficient of each transit edge device at each moment during the target period is obtained based on the numerical growth relationship between the preset unit duration and the security compensation coefficient.

[0043] For example, it is found that the time between the last IP adjustment (used to improve the security of data transmission, mainly for protection against data theft via fixed IP paths) of a certain transit edge device at each moment during the target period is 2-4 hours (2 hours at the beginning of the target period, and the duration of the target period is 2 hours), and the numerical growth relationship between the preset unit duration and the security compensation coefficient is a growth rate of 2. Then, the security compensation coefficient of the transit edge device during the target period is calculated to be 4-8 (the specific security compensation coefficient at each moment during the target period is determined according to the position of the moment). It should be noted that the higher the security compensation coefficient, the lower the transmission security. If the GreatDB database server is used to perform encrypted data transmission between the first terminal and the second terminal, the security compensation coefficient is not considered. When selecting a transit edge device for data transmission, the data transmission risk of several fixed IP data transmission tasks during transmission can be quantified by calculating the product and accumulation of the security compensation coefficient and the data transmission security sensitivity.

[0044] Furthermore, based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target period is planned, and the steps of data transmission strategy are summarized and generated, specifically including: S33: Acquire the encryption processing capability of the GreatDB database server; wherein the encryption processing capability is configured as the maximum amount of data to be encrypted per transmission cycle obtained in advance through testing; S34: querying the data storage capacity reported in advance by each second terminal on the GreatDB database server; wherein the data storage capacity is configured as the maximum data storage capacity within the target period; S35: Based on the data transmission demand list of several fixed IP data transmission tasks within the target time period and the security compensation coefficient of each transit edge device, taking into account the encryption processing capability of the GreatDB database server and the data storage capability of each second terminal, with the encryption processing capability and data storage capability as constraints, and with the minimum data transmission risk as the optimization goal, the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target time period is optimized; wherein, the data transmission mode includes the first terminal transmitting compressed and encrypted data to the second terminal via the GreatDB database server and the first terminal transmitting directly to the second terminal via the transit edge device; S36: Summarize the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target period and generate a data transmission strategy.

[0045] In this embodiment, the encryption processing capability of the GreatDB database server is obtained, which is the maximum amount of data to be encrypted in each transmission cycle obtained in advance through testing (the upper limit of the data processing capability caused by the server hardware), and then the data storage capability reported in advance by each second terminal on the GreatDB database server is queried to obtain the maximum data storage capability of each second terminal within the target period (the upper limit of the data storage capability caused by the second terminal storage device). After that, the encryption processing capability of the GreatDB database server and the data storage capability of each second terminal are considered, and the encryption processing capability and data storage capability are used as constraints, and the minimum data transmission risk is used as the optimization goal. The data transmission method of each fixed IP data transmission task for each transmission cycle within the target period is optimized and solved, and then it is determined whether each fixed IP data transmission task sends the data of the first terminal to the second terminal through the GreatDB database server in each transmission cycle within the target period, or sends the data of the first terminal to the second terminal through the transit edge device.

[0046] In practical applications, optimization algorithm models such as particle swarm optimization or genetic algorithm can be used to plan and solve the data transmission mode of several fixed IP data transmission tasks for each transmission cycle within the target period to obtain the final data transmission strategy.

[0047] Furthermore, considering the encryption processing capability of the GreatDB database server and the data storage capability of each second terminal, with encryption processing capability and data storage capability as constraints and minimum data transmission risk as the optimization goal, the data transmission method and steps for each fixed IP data transmission task in each transmission cycle within the target period are optimized, specifically including: S351: Considering the maximum amount of data encrypted by the GreatDB database server in each transmission cycle and the maximum amount of data stored in each second terminal within the target period; S352: After each fixed IP data transmission task that performs data transmission from the first terminal to the second terminal is assigned to the GreatDB database server or the transit edge device in each transmission cycle within the target time period, the sum of the amount of periodic forwarding data of all fixed IP data transmission tasks assigned to the GreatDB database server in each transmission cycle and the amount of compressed data determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs is less than the maximum amount of data that the GreatDB database server performs encryption processing on in each transmission cycle as a first constraint condition, the sum of the amount of data transmitted by the GreatDB database server received by each second terminal in different transmission cycles within the target time period as a first received data amount determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs and the second received data amount determined by the amount of data transmitted by the transit edge device received in different transmission cycles is less than the maximum data storage capacity of the second terminal within the target time period as a second constraint condition, and the optimization target is to minimize the sum of the products of the data transmission security sensitivity of several fixed IP data transmission tasks and the security compensation coefficients at each moment within the target time period when they are assigned to the transit edge device; S353: Using an optimization algorithm to solve the data transmission mode for each fixed IP data transmission task for each transmission cycle within the target time period.

[0048] In this embodiment, the maximum amount of data that the GreatDB database server performs encryption processing on in each transmission cycle and the maximum amount of data storage of each second terminal within the target time period are taken into consideration. The first constraint condition for satisfying the encryption processing capability of the GreatDB database server is that the sum of the amount of periodic forwarding data of all fixed IP data transmission tasks assigned to the GreatDB database server in each transmission cycle and the amount of compressed data determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs is less than the maximum amount of data that the GreatDB database server performs encryption processing on in each transmission cycle. The second constraint condition for satisfying the maximum data storage capacity of the second terminal within the target time period is that the sum of the amount of data transmitted via the GreatDB database server received by each second terminal in different transmission cycles within the target time period and the first received data amount determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs and the second received data amount determined by the amount of data transmitted via the transit edge device received in different transmission cycles is less than the maximum data storage capacity of the second terminal within the target time period.

[0049] On the basis of satisfying the above constraints, the product and accumulation of the data transmission security sensitivity of several fixed IP data transmission tasks and the security compensation coefficient at each moment in the target period when they are assigned to the transit edge device is minimized as the optimization goal to meet the minimum data transmission risk. The optimization algorithm is used to solve whether each fixed IP data transmission task in each transmission cycle within the target period sends the data of the first terminal to the second terminal through the GreatDB database server (compressed and encrypted transmission, so that the overall fixed IP data transmission task has a higher data information ratio and data transmission security), or sends the data of the first terminal to the second terminal through the transit edge device (direct transit transmission, so that the overall fixed IP data transmission task reduces the computational load of the GreatDB database to perform encrypted transmission).

[0050] In a preferred embodiment, the data transmission policy is distributed to the first terminal, the second terminal, the transit edge device, and the GreatDB database server, driving the first terminal and the second terminal to perform the steps of data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device, specifically including: S41: Distribute the data transmission policy to the first terminal, the second terminal, the transit edge device and the GreatDB database server; S42: Each first terminal transmits the data of the fixed IP data transmission task to the second terminal according to the data transmission method assigned in the data transmission strategy, using data encryption transmission through the GreatDB database server or data dynamic IP path transmission through the transit edge device in each transmission cycle of the target time period.

[0051] In this embodiment, by considering the data processing of the GreatDB database server, the data storage of the second terminal, and the security of data transmission of several fixed IPs within the target period, based on the scientific and reasonable high-security transmission strategy of GreatDB database data, while ensuring the stable operation of the database server, the security of data transmission, server load and storage pressure at the destination are balanced.

[0052] Reference Figure 2 , Figure 2 This is a structural diagram of the GreatDB database data high-security transmission system according to an embodiment of the present invention.

[0053] like Figure 2 As shown, the GreatDB database data high-security transmission system proposed in the embodiment of the present invention includes: An acquisition module 10 is configured to acquire a plurality of fixed IP data transmission tasks of the GreatDB database server during a target period; wherein each of the fixed IP data transmission tasks is configured as a data transmission task between a first terminal having a fixed IP transmission source address and a second terminal having a fixed IP transmission destination address; Establishing module 20, for extracting the importance of transmission data, data transmission security sensitivity and the amount of periodically forwarded data in each fixed IP data transmission task, and establishing a data transmission requirement list; The summarizing module 30 is used to query the security compensation coefficient of each transit edge device in the transit edge device set configured by the GreatDB database server, and based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, plan the data transmission mode for each fixed IP data transmission task for each transmission cycle within the target period, and summarize and generate a data transmission strategy; The transmission module 40 is used to distribute the data transmission strategy to the first terminal, the second terminal, the transit edge device and the GreatDB database server, driving the first terminal and the second terminal to perform data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device.

[0054] Other embodiments or specific implementation methods of the GreatDB database data high-security transmission system of the present invention can refer to the above-mentioned method embodiments and will not be repeated here.

[0055] It should be understood that, in the description of this specification, reference to terms such as "one embodiment," "another embodiment," "other embodiments," or "first to Nth embodiments" means that the specific features, structures, materials, or characteristics described in conjunction with that embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any appropriate manner in any one or more embodiments or examples.

[0056] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0057] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A high-security data transmission method for GreatDB database, characterized in that: The method comprises the following steps: Obtain several fixed IP data transmission tasks of the GreatDB database server in a target period; wherein each of the fixed IP data transmission tasks is configured as a data transmission task between a first terminal having a fixed IP transmission source address and a second terminal having a fixed IP transmission destination address; Extract the importance of transmitted data, data transmission security sensitivity, and the amount of periodic forwarding data in each fixed IP data transmission task, and establish a data transmission requirement list; Query the security compensation coefficient of each transit edge device in the transit edge device set configured by the GreatDB database server, and based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, plan the data transmission method for each fixed IP data transmission task for each transmission cycle within the target period, and summarize and generate a data transmission strategy; The data transmission strategy is distributed to the first terminal, the second terminal, the transit edge device and the GreatDB database server, driving the first terminal and the second terminal to perform data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device.

2. The GreatDB database data high-security transmission method according to claim 1, characterized in that: Obtain several fixed IP data transmission task steps for the GreatDB database server during the target period, including: receiving a plurality of fixed IP data transmission requests, and executing a task establishment request judgment between a first terminal and a second terminal in the fixed IP data transmission requests; When the task establishment request is judged to meet the requirements, the fixed IP transmission source address, fixed IP transmission destination address and data transmission association information in each fixed IP data transmission request are extracted, and a fixed IP data transmission task corresponding to each fixed IP data transmission request is established.

3. The GreatDB database data high-security transmission method according to claim 2, characterized in that: Receiving a plurality of fixed IP data transmission requests, and executing a step of determining a task establishment request between a first terminal and a second terminal in the fixed IP data transmission requests, specifically comprising: Upon receiving each fixed IP data transmission request sent by the target terminal, extracting the fixed IP transmission source address of the first terminal and the fixed IP transmission destination address of the second terminal in the fixed IP data transmission request, and synchronously generating a task establishment confirmation signal; When the target terminal is the first terminal of the data source, the task establishment confirmation signal is sent to the second terminal, and the second terminal determines whether the first terminal is an allowed data transmission source in the data transmission reception list, and if so, determines that the task establishment request between the first terminal and the second terminal meets the requirements; When the target terminal is the second terminal for data purposes, the task establishment confirmation signal is sent to the first terminal. When a transmission confirmation instruction based on the task establishment confirmation signal feedback from the first terminal is received, it is determined that the task establishment request between the first terminal and the second terminal meets the requirements.

4. The GreatDB database data high-security transmission method according to claim 1, characterized in that: Extract the importance of the transmitted data, the security sensitivity of the data transmission, and the amount of periodic forwarding data in each fixed IP data transmission task, and create a data transmission requirements list. The steps include: Parsing the data transmission associated information in each fixed IP data transmission task, and extracting several transmission task keywords in the data transmission associated information; According to several transmission task keywords in the data transmission association information, the importance of transmission data, the data transmission security sensitivity and the amount of periodically forwarded data in each fixed IP data transmission task are determined, and a data transmission requirement list is established.

5. The GreatDB database data high-security transmission method according to claim 4, characterized in that: The step of determining the importance of transmitted data, the security sensitivity of data transmission, and the amount of periodically forwarded data in each fixed IP data transmission task based on the plurality of transmission task keywords in the data transmission association information specifically includes: Calculate the total importance score and the total sensitivity score of the plurality of transmission task keywords according to the method of accumulating the assigned scores based on each transmission task keyword and the preset importance keyword set with the first weight assignment and the preset sensitivity keyword set with the second weight assignment; Calculate the data forwarding volume of each transmission cycle based on the forwarding frequency words and single forwarding data volume in several transmission task keywords; The calculated total importance score, total sensitivity score, and data forwarding volume in each transmission cycle are used as the importance of transmitted data, data transmission security sensitivity, and the volume of periodic forwarding data in the corresponding fixed IP data transmission task, respectively.

6. The GreatDB database data high-security transmission method according to claim 1, characterized in that: The steps to query the security compensation coefficient of each transfer edge device in the transfer edge device set configured by the GreatDB database server include: Query the IP dynamic adjustment plan information of the transit edge device set configured by the GreatDB database server; wherein, the IP dynamic adjustment plan information stores the duration of each transit edge device at each moment within the target period from the last periodic IP dynamic adjustment; According to the duration of each transit edge device's dynamic IP adjustment at each moment from the previous period, and based on the numerical growth relationship between the unit duration and the security compensation coefficient, the security compensation coefficient of each transit edge device at each moment in the target period is calculated.

7. The GreatDB database data high-security transmission method according to claim 6, characterized in that: Based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, the data transmission method for each fixed IP data transmission task is planned for each transmission cycle within the target period, and the steps of summarizing and generating a data transmission strategy are specifically included: Obtaining the encryption processing capability of the GreatDB database server; wherein the encryption processing capability is configured as the maximum amount of data to be encrypted per transmission cycle obtained in advance through testing; Querying the data storage capacity reported in advance by each second terminal on the GreatDB database server; wherein the data storage capacity is configured as the maximum data storage capacity within the target period; Based on the data transmission demand list of several fixed IP data transmission tasks within the target time period and the security compensation coefficient of each transit edge device, taking into account the encryption processing capability of the GreatDB database server and the data storage capability of each second terminal, with the encryption processing capability and data storage capability as constraints, and with the minimum data transmission risk as the optimization goal, the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target time period is optimized; wherein, the data transmission mode includes compression and encryption transmission from the first terminal to the second terminal via the GreatDB database server and direct transmission from the first terminal to the second terminal via the transit edge device; Summarize the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target period and generate a data transmission strategy.

8. The GreatDB database data high-security transmission method according to claim 7, characterized in that: Considering the encryption processing capability of the GreatDB database server and the data storage capability of each second terminal, with encryption processing capability and data storage capability as constraints and minimum data transmission risk as the optimization goal, the data transmission method and steps for each fixed IP data transmission task in each transmission cycle within the target period are optimized, including: Considering the maximum amount of data that the GreatDB database server performs encryption processing on in each transmission cycle and the maximum amount of data storage of each second terminal within the target period; After each fixed IP data transmission task that performs data transmission from the first terminal to the second terminal is assigned to the GreatDB database server or the transit edge device in each transmission cycle within the target time period, the sum of the amount of periodic forwarding data of all fixed IP data transmission tasks assigned to the GreatDB database server in each transmission cycle and the amount of compressed data determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs is less than the maximum amount of data encrypted by the GreatDB database server in each transmission cycle as a first constraint condition; the sum of the amount of data transmitted by the GreatDB database server received by each second terminal in different transmission cycles within the target time period, the amount of data transmitted by the fixed IP data transmission task to which the data amount belongs, determined by the first received data amount determined by the data extraction rate corresponding to the importance of the transmission data of the fixed IP data transmission task to which the data amount belongs, and the second received data amount determined by the amount of data transmitted by the transit edge device received in different transmission cycles is less than the maximum data storage capacity of the second terminal within the target time period as a second constraint condition; the optimization goal is to minimize the sum of the products of the data transmission security sensitivity of several fixed IP data transmission tasks and the security compensation coefficients at each moment within the target time period when they are assigned to the transit edge device; An optimization algorithm is used to solve the data transmission mode of each fixed IP data transmission task for each transmission cycle within the target time period.

9. The GreatDB database data high-security transmission method according to claim 1, characterized in that: The data transmission policy is distributed to the first terminal, the second terminal, the transit edge device, and the GreatDB database server, driving the first terminal and the second terminal to perform the steps of data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device, specifically including: Distribute the data transmission strategy to the first terminal, the second terminal, the transit edge device and the GreatDB database server; Each first terminal transmits the data of the fixed IP data transmission task to the second terminal according to the data transmission method assigned in the data transmission strategy, using data encryption transmission through the GreatDB database server or data dynamic IP path transmission through the transit edge device in each transmission cycle of the target time period.

10. A GreatDB database data high-security transmission system, characterized by: include: An acquisition module is configured to acquire a number of fixed IP data transmission tasks of the GreatDB database server during a target period; wherein each of the fixed IP data transmission tasks is configured as a data transmission task between a first terminal having a fixed IP transmission source address and a second terminal having a fixed IP transmission destination address; Establish a module for extracting the importance of transmitted data, data transmission security sensitivity, and the amount of periodically forwarded data in each fixed IP data transmission task, and establish a data transmission requirement list; A summary module is used to query the security compensation coefficient of each transit edge device in the transit edge device set configured by the GreatDB database server, and based on the data encryption capability of the GreatDB database server and the data storage capability of each second terminal, plan the data transmission mode for each fixed IP data transmission task for each transmission cycle within the target period, and summarize and generate a data transmission strategy; The transmission module is used to distribute the data transmission strategy to the first terminal, the second terminal, the transit edge device and the GreatDB database server, driving the first terminal and the second terminal to perform data encryption transmission through the GreatDB database server and data dynamic IP path transmission through the transit edge device.

Citation Information

Patent Citations

  • Multi-entity resource, security, and service management in edge computing deployments

    CN114026834A

  • Data encryption transmission method and device of cloud side end, and storage medium

    CN118200039A

  • External data access platform and external data access method

    CN119669337A

  • Method and system for scheduling cloud terminal call center data based on edge computing

    CN120378493A

  • Structural data synchronization method and system of relational database

    CN120631982A