Computer network security data transmission method and system and electronic equipment

By employing multi-dimensional certificate verification and dynamic permission allocation, combined with multi-layer encryption and path optimization, the problems of identity forgery, permission abuse, and unreasonable path selection in network data transmission are solved, achieving efficient and secure data transmission.

CN120880768APending Publication Date: 2025-10-31JINING POLYTECHNIC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511219528.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In existing technologies, network data transmission suffers from problems such as identity forgery, abuse of permissions, data tampering, and unreasonable transmission path selection, resulting in low security and efficiency.

Method used

The method employs multi-dimensional certificate verification, dynamic permission allocation, multi-layer encryption, and optimized transmission path, including digital certificate verification, permission allocation, data distribution, bit inversion, template replacement, transmission channel filtering, and path optimization for both communicating parties. Combined with the SDN controller to delete unnecessary nodes, it achieves dynamic adjustment and optimal path selection.

Benefits of technology

It reduces the risk of identity forgery, enables fine-grained control of permissions, enhances data confidentiality and anti-tampering capabilities, improves bandwidth utilization and transmission efficiency, and reduces transmission delays and the impact of failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880768A_ABST
    Figure CN120880768A_ABST
Patent Text Reader

Abstract

The invention discloses a computer network security data transmission method, a computer network security data transmission system and electronic equipment, relates to the technical field of data transmission, solves the technical problems that authority distribution lacks dynamic adaptability and an encryption mechanism is insufficient in anti-aggressiveness, and improves the security of the data transmission by adopting multi-dimensional certificate verification and combining a flexible exception handling mechanism. According to the method, the identity forgery risk is reduced, fine permission control is achieved based on the minimum permission principle and a dynamic adjustment and auditing permission allocation mode, data confidentiality and tamper-resistant capacity are enhanced through multi-layer encryption operation such as data sharing, binary partition, bit inversion and template replacement, and the security of the data is improved. Structured management of encrypted data is realized through a binding mechanism and metadata verification, integrity in a transmission process is guaranteed, transmission channels are screened by integrating multiple indexes, a data type is combined to adapt a compression algorithm, the bandwidth utilization rate is improved, and transmission delay and fault influence are reduced based on a node simplification technology of dynamic path evaluation and an SDN (Software Defined Network) controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission technology, specifically to a computer network security data transmission method, system, and electronic device. Background Technology

[0002] With the rapid development of digital technology, the demand for network security data transmission is increasing, and its security and efficiency have become the core focus of attention.

[0003] According to patent application CN119922011A, a method and apparatus for network security data transmission in computers are disclosed. The method includes acquiring real-time threat intelligence data, real-time packet loss rate, and real-time transmission performance parameters; encrypting these parameters to obtain encrypted fragmented data; inputting the real-time transmission performance parameters into a path performance evaluation model to obtain a path performance score; sorting the path performance scores to obtain a set of transmission paths; matching the transmission paths to obtain sequence correspondences; generating complete transmission data based on the sequence correspondences; performing anti-attack optimization based on the real-time transmission performance parameters to obtain a link connection strategy; analyzing the link quality based on the real-time packet loss rate to obtain a transmission link quality score; and dynamically adjusting the transmission link quality score, link connection strategy, and complete transmission data to obtain real-time transmission data.

[0004] Currently, network data transmission faces multiple challenges: the risk of identity forgery between communicating parties, data leakage due to abuse of permissions, data tampering during transmission, and inefficiency caused by unreasonable selection of transmission channels and paths.

[0005] While existing technologies employ digital certificate authentication, encryption algorithms, and transmission channel filtering, they suffer from the following limitations: single dimension of identity verification, lack of dynamic adaptability in permission allocation, insufficient resistance to attacks in encryption mechanisms, and reliance on static configuration for transmission path and channel selection.

[0006] Therefore, there is an urgent need for a comprehensive solution integrating authentication, access control, data encryption, and transmission optimization to ensure the confidentiality, integrity, controllability, and efficiency of secure data transmission. Summary of the Invention

[0007] To address the shortcomings of existing technologies, this invention provides a computer network security data transmission method, system, and electronic device, which solves the problems of lack of dynamic adaptability in permission allocation and insufficient resistance to attacks in encryption mechanisms.

[0008] To achieve the above objectives, the present invention provides the following technical solution: a computer network security data transmission method, the method comprising the following steps:

[0009] The system verifies the digital certificates of both communicating parties. If an anomaly is found, a verification anomaly signal is generated. Operation feedback is obtained and analyzed to generate a command to continue transmission or prohibit transmission. At the same time, permissions are assigned based on preset rules.

[0010] The acquired network security data to be transmitted is divided into three equal parts according to its capacity, and binary conversion, segmentation and reversal are performed to obtain reversed equal-divided data packets. The data packets are then replaced and encrypted according to the replacement template to generate encrypted data packets.

[0011] Based on the real-time transmission speed, a pre-selected transmission channel is obtained by filtering the transmission channel and calculating its periodic average transmission speed. At the same time, the encrypted data packet is segmented based on this average transmission speed. Then, a compression method is selected according to the corresponding data type to compress the data and generate a compressed data packet.

[0012] After filtering out substandard paths based on the core evaluation indicators of the transmission path, a pre-selected transmission path is obtained, and its comprehensive path value is calculated. The standard transmission path is obtained based on the maximum comprehensive path value, and its corresponding necessary and unnecessary nodes are analyzed. Unnecessary nodes are deleted to obtain the optimized transmission path.

[0013] As a further aspect of the present invention, the method for verifying the digital certificates of both communicating parties is as follows:

[0014] The system acquires the network security data to be transmitted, and simultaneously acquires and verifies the digital certificates of both communicating parties, including their identity information, public keys, CA signatures, and validity periods. If either party's certificate is invalid, tampered with, or the subject does not match, a verification error signal is generated; otherwise, a verification normal signal is generated.

[0015] For verification anomaly signals, the system will process the feedback from both parties. If both parties choose to continue communication, a continue transmission command will be generated. If either party chooses to prohibit communication, a prohibit transmission command will be generated.

[0016] As a further aspect of the present invention, the method of allocating permissions based on preset rules is as follows:

[0017] After identity verification is passed, permissions are automatically assigned and structured information is generated according to preset rules;

[0018] Minimum permissions: Grant necessary permissions based on the role;

[0019] Dynamic adjustment: Temporary authorization based on the scenario, automatic recycling upon task completion;

[0020] Access control audit: Record access control changes and transfer behavior, and regularly check for over-authorization or abnormal use.

[0021] As a further aspect of the present invention, the method for obtaining the reversed equally distributed data packet is as follows:

[0022] The network security data to be transmitted is acquired and labeled, and then divided into three equal parts according to its capacity to obtain an evenly divided data packet. After being converted into binary, it is separated into 12 bits in sequence with an 8-bit interval to obtain a separated binary number. The even-numbered bits of the separated binary number are reversed to form a reversed evenly divided data packet.

[0023] As a further aspect of the present invention, the method for generating encrypted data packets is as follows:

[0024] Using a four-bit binary template, specifically 1111 mapping A, 0000 mapping B, 1100 mapping C, and 0011 mapping D, the interrupted binary bits in the evenly divided data packet are replaced in sequence to generate an encrypted data packet; the total number of replaced characters in each encrypted data packet is counted, and those with the same total number are bundled into a bundled data packet to finally generate encrypted information.

[0025] As a further aspect of the present invention, the method for obtaining the pre-selected transmission channel is as follows:

[0026] Acquire encrypted data packets and analyze the transmission channels. Label all channels i=1, 2, ..., j, where j is the number of transmission channels. Synchronously acquire the real-time transmission speed Vi of each channel and compare it with the speed threshold Vy set by the operator. Select channels with Vi>Vy as pre-selected transmission channels a=1, 2, ..., b, where b is the number of pre-selected transmission channels.

[0027] As a further aspect of the present invention, the method for generating the compressed data packet is as follows:

[0028] With time t as the period, calculate the average periodic transmission speed Pa of the preselected channel a, take the average of all Pa as the segmentation standard, segment the encrypted data packets according to this standard to obtain pre-segmented packets, and then select lossless compression or lossy compression according to the data type to generate compressed data packets.

[0029] As a further aspect of the present invention, the method for obtaining the optimized transmission path is as follows:

[0030] Obtain compressed data packets and transmission paths, collect core indicators and set thresholds as required, filter to obtain pre-selected paths, normalize the transmission delay and packet loss rate of the pre-selected paths, and calculate the comprehensive path value according to the formula: transmission delay index × weight one + packet loss rate index × weight two. Select the path with the largest value as the standard transmission path.

[0031] Obtain the standard path node chain through the SDN controller or routing tools, classify the nodes into necessary and unnecessary nodes, delete the unnecessary nodes, and generate optimized transmission paths by issuing rules through the SDN controller.

[0032] A computer network security data transmission system, comprising:

[0033] The data transmission encryption module is used to divide the acquired network security data to be transmitted into three equal parts according to its capacity, and perform binary conversion, segmentation and reversal to obtain the reversed equal-divided data packet. It then replaces and encrypts the data packet according to the replacement template to generate an encrypted data packet, and transmits it to the data transmission analysis module.

[0034] The data transmission analysis module is used to filter transmission channels based on real-time transmission speed to obtain pre-selected transmission channels, calculate their periodic average transmission speed, and use it as a standard to segment encrypted data packets. Then, it selects a compression method according to the corresponding data type to compress the data packets, generate compressed data packets, and transmit them to the adaptive analysis and management module.

[0035] The adaptive analysis and management module is used to optimize the transmission path corresponding to the compressed data packet. After filtering out the substandard paths according to the core evaluation indicators of the transmission path, a pre-selected transmission path is obtained, and its comprehensive path value is calculated. The standard transmission path is obtained based on the maximum comprehensive path value. The necessary and unnecessary nodes are analyzed, and the unnecessary nodes are deleted to obtain the optimized transmission path. At the same time, it is transmitted to the management information output module.

[0036] The management information output module is used to process data transmission based on the obtained optimized transmission path.

[0037] A computer network security data transmission electronic device, wherein a memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a computer network security data transmission method.

[0038] This invention provides a computer network security data transmission method, system, and electronic device. Compared with existing technologies, it has the following advantages:

[0039] This invention reduces the risk of identity forgery by employing multi-dimensional certificate verification combined with a flexible anomaly handling mechanism. Based on the principle of least privilege and a dynamic adjustment and auditing-based permission allocation mode, it achieves refined permission control, reducing unauthorized transmission and permission abuse. Through multi-layered encryption operations such as data distribution, binary segmentation, bit reversal, and template replacement, it enhances data confidentiality and anti-tampering capabilities. The encrypted data is structured and managed through a binding mechanism and metadata verification to ensure integrity during transmission. It comprehensively selects transmission channels based on multiple indicators and combines data type-adaptive compression algorithms to improve bandwidth utilization. Based on dynamic path evaluation and SDN controller node simplification technology, it achieves optimal path selection and real-time adjustment, reducing transmission latency and the impact of failures. Attached Figure Description

[0040] Figure 1 This is a diagram illustrating the steps and methods of the present invention;

[0041] Figure 2 This is a system diagram of the present invention;

[0042] Figure 3 This is a block diagram of the electronic device of the present invention. Detailed Implementation

[0043] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0044] First Embodiment

[0045] Please see Figure 1 This application provides a method for secure data transmission in a computer network, which specifically includes the following steps:

[0046] Step 1: Obtain the network security data to be transmitted and simultaneously obtain the digital certificates of both communicating parties. The specific digital certificates must contain core fields such as holder identity information, public key, certificate authority signature, and validity period. Verify and judge these certificates. If any set of digital certificates of either communicating party is abnormal, and the abnormality includes invalidity, tampering, or subject mismatch, a verification abnormality signal is generated. Conversely, if the digital certificates of both communicating parties are normal, a verification normality signal is generated. Then, process the obtained verification abnormality signal and obtain the corresponding operation feedback from both communicating parties. If the operation feedback is to continue communication, a continue transmission instruction is generated. Conversely, if any set of operation feedback is to prohibit communication, a prohibit transmission instruction is generated.

[0047] After identity verification is passed, permissions are automatically assigned according to preset rules, generating structured permission assignment information. Further permission assignment is performed based on identity verification, generating permission assignment information. The assignment methods include the principle of least privilege, dynamic permission adjustment, and permission auditing. The principle of least privilege means that based on the role label of the communication subject, only the permissions necessary to complete the current transmission task are granted. For example, ordinary employees can only transmit non-confidential files, while administrators have the permission to transmit core data. Dynamic permission adjustment means that permissions are temporarily granted according to the scenario and automatically revoked after the task is completed. For example, when working remotely, data transmission is only allowed within a specified time period. Permission auditing means that all permission changes and data transmission behaviors are recorded, and the over-authorization or abnormal permission use is checked regularly.

[0048] Step 2: Obtain the network security data to be transmitted, number it sequentially according to the transmission order, and perform integrity verification on each data. For each data, divide it into three equal parts according to the data capacity to generate three equally divided data packets. If the data capacity is not divisible by 3, a padding mechanism is used, such as following the PKCS#7 standard, to pad with random bytes so that the total capacity is an integer multiple of 3, ensuring that the capacity difference of each equally divided data packet does not exceed 1 byte.

[0049] Each evenly divided data packet is converted into a standard binary stream. Based on the original data encoding format, ensuring a one-to-one correspondence between the binary numbers and the original data, 12-bit binary numbers are sequentially extracted from the binary stream as basic units. This is then processed by segmenting the stream in 8-bit increments; that is, after each 12-bit segment, 8 bits are skipped before extracting the next 12 bits, generating several segmented binary numbers. If the binary stream ends with fewer than 12 bits, zeros are padded to make it 12 bits. Even-numbered bits are then reversed on each segmented binary number to generate a reversed evenly divided data packet.

[0050] The even-numbered positions are defined as the 2nd, 4th, 6th, 8th, 10th, and 12th positions from left to right. The 0s in the even-numbered positions are reversed to 1s, and the 1s are reversed to 0s. The odd-numbered positions remain unchanged.

[0051] Four sets of fixed 4-bit binary numbers are used as the basic replacement templates. The specific replacement templates are 1111, 0000, 1100 and 0011, which correspond to the characters A, B, C and D respectively. For each segment binary number in the reversed evenly divided data packet, a replacement template is matched for every 4 bits in order from left to right, and the corresponding character is replaced. For example, the segment binary number 111100001100 can be replaced with ABD. An encrypted data packet is generated. The total number of replacement characters in each encrypted data packet is counted. For example, if a certain data contains 5 A's and 3 B's, the total number is 8. Encrypted data packets with the same total number are grouped together and sequentially bundled to generate bundled data packets. Specifically, they are arranged in the order of the original data labels.

[0052] Metadata is added to all bundled data packets, including the original data label, padding information, total number of characters, encryption timestamp, etc., and the overall hash value is calculated as a verification field to finally generate complete encrypted information for subsequent transmission.

[0053] Step 3: Enumerate all currently available transmission channels, labeling them i in the order of discovery (i = 1, 2, ..., j, where j is the total number of channels). Simultaneously collect the core parameters of each channel: real-time transmission speed Vi (average value taken 5 times per second), network latency Ti, and packet loss rate Li. Calculate the loss rate of 100 test data packets. In addition to the speed comparison threshold Vy preset by the operator, supplement it with a latency threshold Ty and a packet loss rate threshold Ly to form a comprehensive screening condition.

[0054] Only the channels that simultaneously satisfy Vi > Vy, Ti < Ty, and Li < Ly are retained as preselected transmission channels, labeled as a, where a = 1, 2, …, b, and b is the number of preselected channels. If no channel meets the conditions, Vy is automatically reduced by 20% for re-screening until at least 1 channel is retained;

[0055] Taking the time period t as the unit, calculate the average transmission speed Pa of each preselected channel a within the period, that is, the periodic transmission speed. Calculate the average value of all Pa of the preselected channels to obtain the final segmentation standard P0. According to P0 and the total size of the encrypted data packet, calculate the theoretical transmission volume of each channel within a single period, and the theoretical transmission volume = P0 × t / 8. Divide the encrypted data packet into n pre-segmented packets. According to the formula n = data packet capacity / theoretical transmission volume, perform data type detection on each pre-segmented packet based on the file header identifier or content characteristics, and select different compression methods according to different data types to generate compressed data packets; specifically, the compression methods include lossy compression and lossless compression. Specifically, lossless compression is applicable to texts, program codes, etc., and lossy compression is applicable to images, audio, videos, etc.

[0056] Step 4: Obtain the compressed data packet and the corresponding transmission path, and collect the core evaluation indicators of the transmission path. The core evaluation indicators include:

[0057] Transmission delay: Round-trip time, reflecting the path response speed;

[0058] Bandwidth utilization rate: The ratio of the currently used bandwidth to the maximum bandwidth of the path;

[0059] Packet loss rate: The ratio of the lost data packets within a unit time;

[0060] Jitter: The fluctuation range of the delay;

[0061] Set the index threshold according to the requirements of the compressed data packet, automatically filter out the non-compliant paths. For example, for real-time trading services, the transmission delay < 30ms, the packet loss rate < 0.05%, and the bandwidth utilization rate < 60%, and obtain the preselected transmission paths. At the same time, perform normalization processing on the transmission delay and packet loss rate corresponding to the preselected transmission paths to obtain the corresponding transmission delay index and packet loss rate index. According to the formula comprehensive path value = transmission delay index × weight one + packet loss rate index × weight two, calculate the comprehensive path value corresponding to the preselected transmission path. The specific values of weight one and weight two are set by the operator, and the sum of the two is 1. Synchronously select the one with the largest comprehensive path value as the standard, denoted as the standard transmission path;

[0062] The complete node chain of the standard transmission path is obtained through the SDN controller or route tracing tool. The function and type of each node are recorded, and the nodes are classified into necessary nodes and unnecessary nodes. Necessary nodes refer to key nodes that cannot be omitted in the path, including mandatory security nodes, topology-required nodes, and business-related nodes. Unnecessary nodes refer to redundant nodes that can be omitted, including redundant forwarding nodes and low-load intermediate nodes. Under the premise of maintaining path reachability and security, all unnecessary nodes are deleted. New forwarding rules are issued through the SDN controller so that data packets are transmitted directly through necessary nodes, generating an optimized transmission path. After the optimized transmission path is enabled, the system re-collects its indicator data every 30 seconds. If the indicator exceeds the threshold three times in a row, the path reselection process is immediately triggered to recalculate the optimal path from the pre-selected paths and switch to it.

[0063] Second Embodiment

[0064] Please see Figure 2 A computer network security data transmission system includes an authentication module, a data transmission encryption module, a data transmission analysis module, an adaptive analysis and management module, and a management information output module, and combines... Figure 2 It can be seen that the information between the above functional modules is transmitted in one direction only;

[0065] The authentication module is used to verify the digital certificates of both communicating parties. If there is an abnormality, an authentication abnormality signal is generated, and operation feedback is obtained and analyzed to generate a continue transmission instruction or a prohibition transmission instruction. At the same time, permissions are allocated based on preset rules, and the network security data to be transmitted is transferred to the data transmission encryption module. The specific processing method is the same as the processing process in step one.

[0066] The data transmission encryption module is used to divide the acquired network security data to be transmitted into three equal parts according to its capacity, and perform binary conversion, segmentation and reversal to obtain the reversed equal-divided data packet. The data packet is then replaced and encrypted according to the replacement template to generate an encrypted data packet, which is then transmitted to the data transmission analysis module. The specific processing method is the same as the processing process in step two.

[0067] The data transmission analysis module is used to filter transmission channels based on real-time transmission speed to obtain pre-selected transmission channels, calculate their periodic average transmission speed, and use it as a standard to segment encrypted data packets. Then, it selects a compression method according to the corresponding data type to compress the data packets, generate compressed data packets, and transmit them to the adaptive analysis management module. The specific processing method is the same as the processing in step three.

[0068] The adaptive analysis and management module is used to optimize the transmission path corresponding to the compressed data packet. After filtering out substandard paths based on the core evaluation indicators of the transmission path, a pre-selected transmission path is obtained, and its comprehensive path value is calculated. The standard transmission path is obtained based on the maximum comprehensive path value, and the necessary and unnecessary nodes are analyzed. The unnecessary nodes are deleted to obtain the optimized transmission path, which is then transmitted to the management information output module. The specific processing method is the same as the processing in step four.

[0069] The management information output module is used to process data transmission based on the obtained optimized transmission path.

[0070] Third Embodiment

[0071] See Figure 3 , Figure 3 This is a schematic block diagram of an electronic device provided according to an embodiment of this application. Figure 3 The electronic device 300 in this embodiment may include one or more processors 301, one or more input devices 302, one or more output devices 303, and one or more memories 304. The processors 301, input devices 302, output devices 303, and memories 304 communicate with each other via a communication bus 305. The memories 304 store computer programs, including program instructions. The processors 301 execute the program instructions stored in the memories 304. The processors 301 are configured to invoke the program instructions to perform the functions of each module / unit in the above system embodiments.

[0072] It should be understood that, in the embodiments of this application, the processor 301 may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0073] Input device 302 may include a touchpad, a fingerprint sensor (for collecting the user's fingerprint information and fingerprint orientation information), a microphone, etc., and output device 303 may include a display (LCD, etc.), a speaker, etc.

[0074] The memory 304 may include read-only memory and random access memory, and provides instructions and data to the processor 301. A portion of the memory 304 may also include non-volatile random access memory. For example, the memory 304 may also store device type information.

[0075] In specific implementations, the processor 301, input device 302, and output device 303 described in the embodiments of this application can execute the implementation described in the first embodiment of the computer network security data transmission method provided in the embodiments of this application, or they can execute the implementation of the system described in the embodiments of this application, which will not be repeated here.

[0076] Some of the data in the above formulas are numerical calculations with dimensions removed, and the contents not described in detail in this specification are all prior art known to those skilled in the art.

[0077] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.

Claims

1. A method for secure data transmission in a computer network, characterized in that, The method includes the following steps: The system verifies the digital certificates of both communicating parties. If an anomaly is found, a verification anomaly signal is generated. Operation feedback is obtained and analyzed to generate a command to continue transmission or prohibit transmission. At the same time, permissions are assigned based on preset rules. The acquired network security data to be transmitted is divided into three equal parts according to its capacity, and binary conversion, segmentation and reversal are performed to obtain reversed equal-divided data packets. The data packets are then replaced and encrypted according to the replacement template to generate encrypted data packets. Based on the real-time transmission speed, a pre-selected transmission channel is obtained by filtering the transmission channel and calculating its periodic average transmission speed. At the same time, the encrypted data packet is segmented based on this average transmission speed. Then, a compression method is selected according to the corresponding data type to compress the data and generate a compressed data packet. After filtering out substandard paths based on the core evaluation indicators of the transmission path, a pre-selected transmission path is obtained, and its comprehensive path value is calculated. The standard transmission path is obtained based on the maximum comprehensive path value, and its corresponding necessary and unnecessary nodes are analyzed. Unnecessary nodes are deleted to obtain the optimized transmission path.

2. The computer network security data transmission method according to claim 1, characterized in that, The method for verifying the digital certificates of both communicating parties is as follows: The system acquires the network security data to be transmitted, and simultaneously acquires and verifies the digital certificates of both communicating parties, including their identity information, public keys, CA signatures, and validity periods. If either party's certificate is invalid, tampered with, or the subject does not match, a verification error signal is generated; otherwise, a verification normal signal is generated. For verification anomaly signals, the system will process the feedback from both parties. If both parties choose to continue communication, a continue transmission command will be generated. If either party chooses to prohibit communication, a prohibit transmission command will be generated.

3. A computer network security data transmission method according to claim 1, characterized in that, The method for allocating permissions based on preset rules is as follows: After identity verification is passed, permissions are automatically assigned and structured information is generated according to preset rules; Minimum permissions: Grant necessary permissions based on the role; Dynamic adjustment: Temporary authorization based on the scenario, automatic recycling upon task completion; Access control audit: Record access control changes and transfer behavior, and regularly check for over-authorization or abnormal use.

4. A computer network security data transmission method according to claim 1, characterized in that, The method for obtaining the inverted equally distributed data packet is as follows: The network security data to be transmitted is acquired and labeled, and then divided into three equal parts according to its capacity to obtain an evenly divided data packet. After being converted into binary, it is separated into 12 bits in sequence with an 8-bit interval to obtain a separated binary number. The even-numbered bits of the separated binary number are reversed to form a reversed evenly divided data packet.

5. A computer network security data transmission method according to claim 1, characterized in that, The method for generating encrypted data packets is as follows: Using a four-bit binary template, specifically 1111 mapping A, 0000 mapping B, 1100 mapping C, and 0011 mapping D, the interrupted binary bits in the evenly divided data packet are replaced in sequence to generate an encrypted data packet; the total number of replaced characters in each encrypted data packet is counted, and those with the same total number are bundled into a bundled data packet to finally generate encrypted information.

6. A computer network security data transmission method according to claim 1, characterized in that, The method for obtaining the pre-selected transmission channel is as follows: Acquire encrypted data packets and analyze the transmission channels. Label all channels i=1, 2, ..., j, where j is the number of transmission channels. Synchronously acquire the real-time transmission speed Vi of each channel and compare it with the speed threshold Vy set by the operator. Select channels with Vi>Vy as pre-selected transmission channels a=1, 2, ..., b, where b is the number of pre-selected transmission channels.

7. A computer network security data transmission method according to claim 1, characterized in that, The method for generating compressed data packets is as follows: With time t as the period, calculate the average periodic transmission speed Pa of the preselected channel a, take the average of all Pa as the segmentation standard, segment the encrypted data packets according to this standard to obtain pre-segmented packets, and then select lossless compression or lossy compression according to the data type to generate compressed data packets.

8. A computer network security data transmission method according to claim 1, characterized in that, The method for obtaining the optimized transmission path is as follows: Obtain compressed data packets and transmission paths, collect core indicators and set thresholds as required, filter to obtain pre-selected paths, normalize the transmission delay and packet loss rate of the pre-selected paths, and calculate the comprehensive path value according to the formula: transmission delay index × weight one + packet loss rate index × weight two. Select the path with the largest value as the standard transmission path. Obtain the standard path node chain through the SDN controller or routing tools, classify the nodes into necessary and unnecessary nodes, delete the unnecessary nodes, and generate optimized transmission paths by issuing rules through the SDN controller.

9. A computer network security data transmission system, used to execute the computer network security data transmission method according to any one of claims 1-8, characterized in that, include: The data transmission encryption module is used to divide the acquired network security data to be transmitted into three equal parts according to its capacity, and perform binary conversion, segmentation and reversal to obtain the reversed equal-divided data packet. It then replaces and encrypts the data packet according to the replacement template to generate an encrypted data packet, and transmits it to the data transmission analysis module. The data transmission analysis module is used to filter transmission channels based on real-time transmission speed to obtain pre-selected transmission channels, calculate their periodic average transmission speed, and use it as a standard to segment encrypted data packets. Then, it selects a compression method according to the corresponding data type to compress the data packets, generate compressed data packets, and transmit them to the adaptive analysis and management module. The adaptive analysis and management module is used to optimize the transmission path corresponding to the compressed data packet. After filtering out the substandard paths according to the core evaluation indicators of the transmission path, a pre-selected transmission path is obtained, and its comprehensive path value is calculated. The standard transmission path is obtained based on the maximum comprehensive path value. The necessary and unnecessary nodes are analyzed, and the unnecessary nodes are deleted to obtain the optimized transmission path. At the same time, it is transmitted to the management information output module. The management information output module is used to process data transmission based on the obtained optimized transmission path.

10. A computer network security data transmission electronic device, characterized in that, At least one processor; And a memory communicatively connected to at least one processor, wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Computer network security data transmission method and device

    CN119922011A