Network data secure transmission method and system
By acquiring the feature vectors of network data streams, calculating quantization scores, and adjusting the resource allocation and encryption strength of data transmission, the problem of insufficient security protection capabilities in existing technologies is solved, and efficient and secure network data transmission is achieved.
Patent Information
- Application Number
- CN202511525855.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2026-01-06
AI Technical Summary
In existing technologies, network data transmission methods cannot adjust encryption strength and computational resource efficiency according to data sensitivity, resulting in insufficient security protection capabilities and an inability to achieve fine-grained control at the data level.
By acquiring the feature vectors of network data streams, calculating quantization scores, adjusting resource allocation and encryption strength for data transmission, monitoring network environment changes in real time, and dynamically adjusting transmission paths and encryption strategies, advanced encryption of high-risk data and basic encryption of low-risk data can be achieved.
It achieves alignment between security requirements and encryption strength, reduces overall encryption computing power consumption, improves the security of transmission paths for high-risk data and its resistance to brute-force attacks, and reduces data leakage incidents.
Smart Images

Figure CN121283751A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network data transmission technology, and in particular to a method and system for secure network data transmission. Background Technology
[0002] In the information age, secure network data transmission is a core area for ensuring the stable operation of information systems and protecting user privacy; any data security vulnerability can lead to serious consequences. Therefore, researching efficient and secure network data transmission methods is of paramount importance.
[0003] In one existing technology, a static rule matching mode is used for data classification and security policy binding. Specific rules need to be configured in advance and solidified into the system. The same encryption algorithm and strength are used to encrypt the data. Data transmission priority is allocated based on fixed port mapping. A total of three priority levels are set: high, medium and low. The priority is bound to bandwidth resources and remains unchanged. Data transmission is carried out through a single fixed path. All data is transmitted through a preset VPN channel.
[0004] However, existing technologies use fixed encryption algorithms and key cycles, which cannot adjust the strength according to data sensitivity, nor can they dynamically optimize efficiency based on computing resources. This results in a coexistence of over-security and under-security. Existing technologies use ports as the smallest processing unit, failing to achieve fine-grained control at the data level and unable to adjust security strategies based on the characteristics of individual data. In summary, existing technologies suffer from insufficient security protection capabilities. Summary of the Invention
[0005] This invention provides a method and system for secure network data transmission to address the problem of insufficient security protection capabilities in existing technologies.
[0006] In a first aspect, to solve the above-mentioned technical problems, the present invention provides a method for secure network data transmission, comprising: Acquire network data stream, extract feature vectors from the network data stream, and calculate the quantization score of the feature vectors to obtain a preliminary quantization score; The network data is classified by comparing the preliminary quantified score with a preset score threshold and mapping the priority of the network data according to the comparison result. Based on the classification results, adjust the resource allocation during data transmission to obtain suggested adjustment values; The risk level of data transmission is matched according to the proposed adjustment value. If the risk level is high, the advanced encryption standard is selected, and if the risk level is low, the basic encryption standard is selected, thus obtaining the encryption strength adjustment scheme. The priority parameters for data transmission are extracted from the encryption strength adjustment scheme, and the transmission queues are sorted to obtain an initial priority sequence; According to the initial priority sequence, monitor the changes in network environment indicators. If the changes exceed the preset indicator range, recalculate the priority parameters. If the changes are within the preset indicator range, maintain the current priority sequence to obtain an adjusted priority sequence. Based on the network environment change indicators during the data transmission of high-priority tags, the matching relationship between the change indicators and the data transmission of high-priority tags is analyzed, and the path selection is adjusted according to the matching relationship to obtain the intermediate value of path adjustment. The data transmission path is adjusted based on the intermediate value of the path, and the detailed attributes of low-priority data are recorded to obtain path optimization parameters; The data transmission path is optimized based on the path optimization parameters to obtain a secure network data transmission configuration.
[0007] In a second aspect, the present invention provides a network data security transmission system, comprising: The data acquisition module is used to acquire network data streams, extract feature vectors from the network data streams, and calculate the quantization score of the feature vectors to obtain a preliminary quantization score. The data comparison module is used to compare the preliminary quantified score with a preset score threshold, and map the priority of the network data according to the comparison result to obtain the classification result of the network data. The data adjustment module is used to adjust the resource allocation during data transmission based on the classification results to obtain suggested adjustment values. The data selection module is used to match the risk level of data transmission according to the adjustment suggestion value. If the risk level is high, the advanced encryption standard is selected; if the risk level is low, the basic encryption standard is selected, thus obtaining the encryption strength adjustment scheme. The data sorting module is used to extract the priority parameters of data transmission from the encryption strength adjustment scheme and sort the transmission queue to obtain an initial priority sequence. The data calculation module is used to monitor changes in network environment indicators based on the initial priority sequence. If the changes exceed the preset indicator range, the priority parameters are recalculated. If the changes are within the preset indicator range, the current priority sequence is maintained, thus obtaining an adjusted priority sequence. The data analysis module is used to monitor changes in network environment indicators during the data transmission of high-priority tags according to the adjusted priority sequence, analyze the matching relationship between the changes in indicators and the data transmission of high-priority tags, adjust the path selection according to the matching relationship, and obtain the intermediate value of path adjustment. The data recording module is used to adjust the data transmission path according to the intermediate value of the path adjustment, and record the detailed attributes of low-priority data to obtain path optimization parameters; The data transmission module is used to optimize the data transmission path according to the path optimization parameters to obtain a secure network data transmission configuration.
[0008] Thirdly, the present invention also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the network data secure transmission method described in any one of the above.
[0009] Fourthly, the present invention also provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the network data secure transmission method described in any one of the above.
[0010] Compared with the prior art, the present invention has the following beneficial effects: (1) This solution adjusts the recommended values to match the risk level. High risk corresponds to advanced encryption standard (AES-256+GCM certification), and low risk corresponds to basic encryption standard (AES-128+CBC), so as to align security requirements with encryption strength. Low-risk data uses basic encryption to reduce computing power consumption, and the released computing power can support the encryption processing of high-risk data. High-risk data uses advanced encryption to improve the ability to resist brute-force attacks, reduce the overall encryption computing power consumption, and improve the attack resistance rate of high-risk data.
[0011] (2) This solution pre-sets a dedicated path pool with a security level of ≥4 for high-priority data. The path security capability and data encryption strength are matched bidirectionally. The security indicators of the high-priority data transmission path are monitored in real time. If the path is detected to be tampered with, it immediately switches to the backup security link in the path pool. The switching time can be stably controlled within 100-200ms to avoid data exposure window. This improves the security compliance rate of the transmission path for high-priority and high-risk data and reduces data leakage events caused by insecure paths. Attached Figure Description
[0012] Figure 1 This is a schematic diagram of the network data secure transmission method provided in the first embodiment of the present invention; Figure 2 This is a schematic diagram of the network data security transmission system provided in the second embodiment of the present invention. Detailed Implementation
[0013] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0014] Reference Figure 1 The first embodiment of the present invention provides a method for secure network data transmission, comprising the following steps: S11, acquire network data stream, extract feature vectors based on the network data stream, and calculate the quantization score of the feature vectors to obtain a preliminary quantization score; S12, compare the preliminary quantified score with the preset score threshold, and map the priority of the network data according to the comparison result to obtain the level classification result of the network data; S13, adjust the resource allocation during data transmission based on the grade classification results to obtain the adjustment suggestion value; S14. Match the risk level of data transmission according to the proposed adjustment value. If the risk level is high, select the advanced encryption standard. If the risk level is low, select the basic encryption standard to obtain the encryption strength adjustment scheme. S15, extract the priority parameters of data transmission from the encryption strength adjustment scheme, and sort the transmission queue to obtain the initial priority sequence; S16, monitor the changing indicators of the network environment according to the initial priority sequence. If the changing indicators exceed the preset indicator range, recalculate the priority parameters. If the changing indicators are within the preset indicator range, maintain the current priority sequence to obtain the adjusted priority sequence. S17, according to the adjusted priority sequence, monitor the network environment change indicators during the data transmission of high-priority tags, analyze the matching relationship between the change indicators and the data transmission of high-priority tags, adjust the path selection according to the matching relationship, and obtain the intermediate value of path adjustment; S18, adjust the data transmission path according to the intermediate value of the path adjustment, and record the detailed attributes of low priority data to obtain path optimization parameters; S19, optimize the data transmission path according to the path optimization parameters to obtain the network data secure transmission configuration.
[0015] In step S11, a network data stream is acquired, a feature vector is extracted from the network data stream, and the quantization score of the feature vector is calculated to obtain a preliminary quantization score.
[0016] It should be noted that the system captures the entire network data stream in real time through TCP / IP protocol ports, covering business scenarios such as finance (transaction requests, payment instructions), healthcare (ECG data, medical record transmission), and government affairs (official document interaction, user information synchronization). At the same time, it retains complete metadata of the data packets, including source address, destination address, data payload, timestamp, protocol type, and task identifier fields. A custom TCP / IP parsing script is used to split the continuous data stream into discrete, independent transmission tasks based on the task identifier field in the data packet (such as "Transaction ID: TXN12345" in the financial scenario). Each task corresponds to a clear business objective (such as "transfer 10,000 yuan" or "transmit 30 minutes of ECG data of a patient").
[0017] Based on a predefined sensitivity assessment rule base, sensitive information is extracted from the data packet payload of each transmission task and assigned values. The sensitivity assessment rule base is a structured set of rules built based on business scenario requirements and historical risk data. The effectiveness of the rules is verified by backtracking through historical data (e.g., 1,000 data with known risk levels are substituted into the rule base to verify the matching degree between the sensitive value output and the actual risk, which must reach more than 90%). The evaluation dimensions include information type (including personal identification information) and core business data (core business data plays a decisive role in business continuity, user rights, and system stability, and leakage / loss / delay will lead to direct losses). Sensitivity values are assigned to the data, using a quantitative method of adding weights to a basic range. The basic range is 0.7-1.0 by default. The weights are added in the range of 0.1-0.3 according to the urgency of the business. For example, real-time transmission data (such as medical ECG, real-time financial payment) is weighted in the range of 0.2-0.3, while non-real-time but critical data (such as historical transaction record archives) is weighted in the range of 0.1-0.2. Ordinary log data is assigned a default range of 0.1-0.3 (such as 0.2 for server temperature logs) and no weights are added.
[0018] Business scenario labels are extracted from task identifiers or data packet context (such as the "Business Type" field in the protocol header or data payload keywords) and encoded into vectors according to preset rules. The data sensitivity assessment value is then horizontally concatenated with the business scenario encoded vector to form a feature vector. The preset encoding rules employ one-hot encoding combined with scenario priority mapping, assigning a unique vector to each business scenario using one-hot encoding. The feature vectors are input into a pre-trained SVM model, which outputs a preliminary quantization score by determining the vector's position relative to the hyperplane in the feature space.
[0019] Collect at least 10,000 historical transmission task data entries, each containing a feature vector (e.g., [0.9,1,0,0], including sensitive evaluation values and one-hot scene vectors). Divide the dataset into a training set (7,000 entries) and a validation set (3,000 entries) in a 7:3 ratio. The training set is used for model learning, and the validation set is used to evaluate model accuracy. Since the feature vectors are low-dimensional (usually 4-8 dimensions), a linear kernel is selected to balance training efficiency and classification accuracy. Optimize the penalty parameter C (controlling the intensity of misclassification penalty) and gamma value (controlling the influence range of the kernel function) using a grid search method. For example, test C=1, 10, 100, gamma=0.1, 1, 10, and select the parameter combination that minimizes the quantization score prediction error on the validation set (e.g., C=10, gamma=1). Input the training set feature vectors into the SVM model and learn the hyperplane by minimizing the classification margin and misclassification penalty to establish a mapping function from feature vector to quantization score. Input the validation set into the trained model and calculate the mean absolute error (MAE) between the "predicted quantized score" and the "human-labeled score". Ensure that the MAE is ≤ 0.05 (i.e. the deviation between the predicted value and the true value does not exceed 0.05). If the accuracy does not meet the standard (e.g., MAE = 0.1), supplement the training data (add 2000 labeled data) or adjust the hyperparameters (e.g., increase the C value to reduce misclassification) and retrain until the accuracy requirement is met.
[0020] In step S12, the comparison between the preliminary quantized score and a preset score threshold, and the mapping of network data priorities based on the comparison results to obtain the network data classification results, includes: If the initial quantization score is higher than the preset score threshold, it is marked as a high importance marker; if the initial quantization score is lower than the preset score threshold, it is marked as a low importance marker, and the marker assignment result is obtained. The label allocation results are mapped to primary priority labels using a pre-established priority label mapping table to obtain the hierarchical classification results of the network data.
[0021] It should be noted that the preset score thresholds are verified through historical risk data. Network data transmission records from the past 1-3 years are collected, covering target business scenarios such as finance, healthcare, and government affairs. Candidate thresholds (0.1, 0.2...0.9) are set in increments of 0.1 within the 0-1 range. The matching degree between high / low importance markers and actual risk events is tested at each threshold. The proportion of actual high-risk data (where a risk event has occurred) that is misclassified as low importance markers is calculated (false negative rate). The proportion of actual low-risk data (where no risk event has occurred) that is misclassified as "high importance markers" is calculated (false positive rate). The "false negative rate - false positive rate" curve of each candidate threshold is analyzed using ROC curves (Receiver Operational Characteristics curves), and the threshold with the largest area under the curve (AUC) is selected (i.e., set to 0.5).
[0022] If the initial quantification score is greater than 0.5 (e.g., 0.85 for financial transfer data, 0.92 for medical ECG data), it is judged as a high-importance data, and such data should be given priority in terms of security and real-time performance. If the initial quantification score is less than 0.5 (e.g., 0.25 for ordinary log data, 0.3 for public policy query data), it is judged as a low-importance data, and such data can have its security strategy strength appropriately reduced to improve transmission efficiency. Based on the primary priority conversion of the priority label mapping table, a one-to-one correspondence between labels and priorities is pre-established, with high-importance labels corresponding to priority A and low-importance labels corresponding to priority C. The label allocation results are substituted into the mapping table, and the primary priority labels are directly output to obtain the classification results of the network data.
[0023] In step S13, adjusting resource allocation during data transmission based on the classification results to obtain suggested adjustment values includes: Obtain indicators of changes in the network environment; A comprehensive environmental score is calculated based on the change indicators and the classification results to obtain a dynamic environmental quantification value. If the dynamic environment quantization value is higher than the preset quantization threshold, it is marked as a high priority label; if the dynamic environment quantization value is lower than the preset quantization threshold, it is marked as a low priority label, thus obtaining the optimized priority label after secondary adjustment. Based on the optimization priority label, resource allocation is adjusted to obtain a resource allocation scheme; The timeliness of the resource allocation plan is evaluated, and the resource allocation is adjusted based on the evaluation results to obtain the recommended adjustment value.
[0024] It should be noted that network environment change indicators are core parameters reflecting real-time transmission conditions. These need to be collected in real time by distributed network monitoring nodes (such as sensors built into routers and switches) at a sampling frequency of 1 second per sampling. Core indicators include bandwidth utilization (current path bandwidth used / total bandwidth, e.g., dedicated line bandwidth utilization of 70%); transmission latency (average time for data packets to travel from source to destination, e.g., 5ms); packet loss rate (percentage of data packets lost per unit time, e.g., 0.1%); and node load (CPU / memory utilization of data processing nodes, e.g., 60%). After collection, the indicators need to be standardized (mapped to the 0-1 range). For example, bandwidth utilization of 70% → standardized value of 0.7, latency of 5ms (threshold upper limit of 10ms) → standardized value of 0.5. The weights of indicators are adjusted according to the business priority of the classification results. High-priority data focuses on real-time performance and stability, while low-priority data focuses on resource utilization. If the classification result is priority A (high importance), the weights are set as follows: latency (weight 0.3) > packet loss rate (weight 0.25) > node load (weight 0.2) > bandwidth utilization (weight 0.15) > scenario-related indicators (weight 0.1). If the classification result is priority C (low importance), the weights are set as follows: bandwidth utilization (weight 0.3) > node load (weight 0.25) > latency (weight 0.2) > packet loss rate (weight 0.15) > scenario-related indicators (weight 0.1). The network environment indicators are weighted and calculated. The dynamic environment quantification value is equal to the sum of the standardized values of each indicator multiplied by the corresponding scenario weight.
[0025] Network environment metrics data (bandwidth utilization, latency, packet loss rate, etc.) from the past 6 months were collected to form a sample set containing 10,000+ records. Candidate thresholds (0.5, 0.55, 0.6...0.7) were set at 0.05 intervals within the 0-1 range. These candidate thresholds were then validated in the real-time network environment of the past month, resulting in a quantization threshold of 0.6. The dynamic environment quantization value was evaluated using the preset quantization threshold to correct priority labels and address the mismatch between static classification and dynamic network conditions. If the dynamic environment quantization value is greater than 0.6 (indicating a poor network environment, such as 90% bandwidth utilization and 15ms latency), the original priority A is upgraded to priority A+ (requiring additional resource guarantees); the original priority C remains priority C (without resource preemption). If the dynamic environment quantization value is less than 0.6 (indicating a good network environment, such as 30% bandwidth utilization and 3ms latency), the original priority A remains priority A; the original priority C is downgraded to priority C- (further releasing resources).
[0026] Based on the optimized priority labels, the resource scheduling engine is invoked to allocate transmission resources. Different optimized priorities correspond to different resource configuration strategies: For priority A+ services, 40%-60% of the dedicated line basic bandwidth is allocated, which is adjusted elastically according to real-time load. Core nodes with a load of <30% are prioritized for node selection, and low-priority resources can be preempted in the conflict handling mechanism (such as interrupting part of the bandwidth of priority C-). For priority A services, 20%-40% of the dedicated line basic bandwidth is allocated, and 20% of the redundant bandwidth is released to the low-priority shared bandwidth pool for use by low- and medium-priority data when idle. Core nodes with a load of <50% are selected, and resources are shared with priority A+ during conflict handling, but the priority is lower than A+. Priority C corresponds to 30% of the shared bandwidth, and ordinary nodes with a load of <70% are selected. Resources are not preempted during conflict handling, and if the bandwidth is insufficient, it enters a queuing state. Priority C- corresponds to 10% of the shared bandwidth, and edge nodes with a load of <80% are selected. Transmission is delayed when resources are insufficient.
[0027] The timeliness of the resource allocation scheme is evaluated. The timeliness evaluation indicators include transmission completion time and resource utilization. If the transmission completion time exceeds the transmission threshold (set to 2 seconds, calculated by collecting data transmission records of similar data over the past 3 months and statistically analyzing the 95th percentile transmission time, i.e., the time that 95% of normal transmissions can complete, the transmission time is the threshold), then the bandwidth allocation is increased by 10%, and the node with a lower load is switched. If the resource utilization is too low (e.g., 80% bandwidth is allocated but only 40% is actually used), then the bandwidth allocation is reduced to 50%, and resources are released to other tasks. The evaluation and adjustment are repeated until all indicators meet the standards. The final output resource allocation parameters are the adjustment recommendations.
[0028] In step S14, the risk level of data transmission is matched according to the adjustment suggestion value. If the risk level is high, an advanced encryption standard is selected; if the risk level is low, a basic encryption standard is selected, resulting in an encryption strength adjustment scheme, including: The risk level is obtained by matching the suggested adjustment value with a pre-established business scenario rule base. If the risk level is higher than a preset risk threshold, a high-risk label is generated; if the risk level is lower than the preset risk threshold, a low-risk label is generated, thus obtaining a risk level label. Based on the risk level label, the corresponding encryption scheme is queried from the pre-established encryption scheme library. If the label is high-risk, an advanced encryption scheme is selected; if the label is low-risk, a basic encryption scheme is selected, and the encryption scheme selection result is obtained. Based on the encryption scheme selection result, the encryption strength and security level are quantified to obtain the encryption strength value; Traffic features are extracted from the network data stream and their matching relationship with the encryption strength value is analyzed. An encryption strength adjustment scheme is obtained based on the matching relationship.
[0029] It should be noted that the business scenario rule base contains the mapping logic of adjusting the suggested value parameter → risk level. The core parameters of the suggested value are broken down into three categories, including the priority label after optimization in step S13 (such as A+, A, C, C-), the business scenario type, which needs to cover core areas such as finance (cross-border transfer, balance inquiry), medical care (real-time ECG, medical record archiving), and government affairs (confidential documents, public notices), and the intensity of resource allocation, including the proportion of dedicated line bandwidth and node load.
[0030] The generation of the rule base requires multiple iterations, starting with the identification of over 100 initial rules (e.g., "Priority A++ financial cross-border transfer + 80% dedicated bandwidth → Risk Level 9" and "Priority C-+ ordinary system logs + 10% shared bandwidth → Risk Level 3"). These rules are then validated using historical data from the past six months. If the accuracy of a rule's risk level prediction is below 90%, the parameter weights are adjusted to ultimately form a stable rule set. During actual matching, the system first extracts the three types of parameters from the suggested adjustment values, then traverses the rule base using a fuzzy matching algorithm based on a decision tree: the root node of the decision tree represents the priority label, prioritizing rule branches containing "A+"; the child nodes represent the business scenario type, further identifying rules related to financial cross-border transfers; and the leaf nodes represent the resource allocation intensity, accurately matching the rules corresponding to 80% dedicated bandwidth. The final output is a risk level of 9 (out of 10, with higher scores indicating more severe consequences of data leakage or tampering, requiring higher levels of encryption protection).
[0031] The preset risk threshold is determined by collecting encryption performance data from the past 12 months. Data verification shows that when the risk level is >7, using advanced encryption standards (such as AES-256) can reduce the data leakage rate from 1% (when using basic encryption) to 0.01% without significantly increasing transmission latency (because this type of data allocates more core node resources). When the risk level is <7, using basic encryption standards (such as AES-128) can control the leakage rate below 0.5%, while reducing computing power consumption by 30%. Therefore, 7 is the optimal threshold. Tag generation follows strict judgment rules: if the risk level is >7, the system automatically generates a high-risk tag and adds the judgment criteria to the tag (e.g., "Risk level 9 > threshold 7, business type: cross-border financial transfer"); if the risk level is <7 (e.g., 3 for ordinary logs, 5 for public notices), a low-risk tag is generated, resulting in the risk level tag.
[0032] The construction of the encryption scheme library involves two parts: algorithm selection and parameter design. The algorithm selection is based on the AES series algorithms (AES-256, AES-128). This series of algorithms is an internationally recognized symmetric encryption standard, and its security has been verified over a long period of time. At the same time, it reserves an extension interface for Chinese national cryptographic algorithms (such as SM4). For parameter design, differentiated parameters need to be defined for high-risk and low-risk labels. Risk labels correspond to advanced encryption standards, and the algorithm selected is AES-256 (key length 256 bits). The key rotation cycle is set to 1 hour (because for high-risk data such as cross-border transfers, using the same key for a long time increases the risk of being cracked. 1 hour is a security window determined based on historical attack data). The encryption mode adopts GCM (Galois / Counter Mode), which has both encryption and authentication functions and can detect whether the data has been tampered with in real time. The security level is marked as 9 points (0-10 points, based on a comprehensive evaluation of the algorithm's anti-cracking ability, key cycle, and mode security). The relative value of computing power consumption is 100 (based on the computing power consumption of AES-128, AES-256 consumes about twice as much computing power due to its longer key).
[0033] Low-risk labels correspond to basic encryption standards, with the AES-128 algorithm (128-bit key length) selected. The key rotation cycle is set to 24 hours (low-risk data, such as logs, has low timeliness; a longer rotation cycle reduces key management overhead). The encryption mode adopted is CBC (Cipher Block Chaining), which has high encryption efficiency, consumes 20% less computing power than GCM, has a security level of 6, and a relative computing power consumption of 50. The scheme library is stored in a relational database, with table structures including risk labels, encryption algorithms, key rotation cycles, encryption modes, and fields, resulting in the encryption scheme selection results.
[0034] The encryption strength value is obtained by dividing the minimum value of computing power consumption compared to 100 by 100, subtracting the quotient from 1, multiplying by 0.3, and finally adding the result of multiplying the security level by 0.1 and then by 0.7. The weights of 0.7 and 0.3 are set based on the contribution analysis of security level and computing power consumption to the effectiveness of encryption strength in historical data. 1000 sets of encryption scheme application cases were selected (covering high / low risk data and different computing power scenarios), and the security level, computing power consumption, and actual encryption effect (leakage rate, resistance to attack) were statistically analyzed. The correlation between security level and encryption effect was analyzed; the contribution analysis showed that the correlation coefficient between security level and encryption effect was 0.82 (highly positive correlation, with the leakage rate decreasing by about 0.1% for every 1 point increase in security level), while the correlation coefficient between computing power consumption and encryption effect was only 0.35 (weak correlation, with a 20% reduction in computing power consumption only improving transmission efficiency by 5% and not affecting security capabilities); based on the correlation coefficient ratio (0.82:0.35≈2.3:1), the weights were simplified to 7:3 to ensure that the quantitative results of encryption strength value highly match the actual encryption effect.
[0035] It should be noted that the setting of various weight parameters in this solution (including but not limited to the weight of network environment indicators and the weight of priority parameter calculation) follows a similar determination principle as the weight of encryption strength value. Based on historical operation and maintenance data, the correlation coefficients between each dimension indicator and the final transmission target (such as security and timeliness) are statistically analyzed, and the ratio of the correlation coefficients is simplified into an operable weight ratio. Those skilled in the art can determine the best weight parameters suitable for their own scenario through such correlation and regression analysis based on the historical data of their specific business system.
[0036] Traffic characteristics need to cover three dimensions: data volume, transmission frequency, and real-time requirements. By parsing the payload length field of TCP / IP packets, the total data volume of a single transmission task is calculated to obtain the data volume, which is then classified into small data volume (<1MB), medium data volume (1-10MB), and large data volume (>10MB). The transmission frequency adopts a 1-second sliding window mechanism to count the number of data packets with the same service identifier per unit time, and is classified into low frequency (<10 times / second), medium frequency (10-50 times / second), and high frequency (>50 times / second). Real-time requirements can be judged by keywords in the service scenario identifier (e.g., data packets containing the fields "real-time ECG" or "instant transfer" indicate high real-time requirements; data packets containing the fields "log archiving" or "historical query" indicate low real-time requirements), and corresponding to the service tolerance latency threshold (e.g., high real-time requirement latency threshold ≤200ms, low real-time requirement ≤1000ms).
[0037] To determine whether encrypted data meets the business latency threshold and whether the computing power consumption does not exceed the node's capacity limit, consider high-risk cross-border transfer data (encryption scheme AES-256+GCM, strength value 0.63), with traffic characteristics of high frequency (120 times / second) and small data volume (100KB). System monitoring found that the computing power consumption of this encryption scheme caused the core node's CPU utilization to surge to 85% (exceeding the 70% security load threshold), and the transmission latency increased from 150ms to 400ms (exceeding the 200ms business threshold). In this case, the encryption scheme needs to be adjusted: retain the AES-256 algorithm to ensure security, but optimize the GCM mode to a "lightweight GCM mode" (referring to an optimized implementation that reduces the computational and communication overhead of GCM mode while maintaining its core security features by reducing the authentication data length or adjusting the initialization vector generation strategy), and extend the key rotation cycle from 10 minutes to 15 minutes (reducing the computing power consumption for key generation and distribution). After the adjustment, the computing power consumption decreased to 80, the CPU utilization decreased to 60%, and the latency dropped back to 180ms (meeting the threshold). The encryption strength value was recalculated as: (9×0.1)×0.7+(1-80 / 100)×0.3=0.63+0.06=0.69. The encryption strength adjustment scheme was output in a structured format, including four core elements: the adjusted encryption parameters, the encryption strength value, the reason for the adjustment, and the expected effect.
[0038] It is worth noting that all threshold parameters in this solution (score threshold 0.5, quantification threshold 0.6, risk threshold 7, etc.) are recommended initial values based on typical business scenarios. In actual deployment, it is recommended to gradually calibrate through A / B testing to establish a parameter system that conforms to specific business characteristics. All machine learning models (such as SVM classifiers) should be retrained regularly with new data to maintain classification accuracy.
[0039] In step S15, extracting the data transmission priority parameter from the encryption strength adjustment scheme and sorting the transmission queue to obtain an initial priority sequence includes: Extract service identifiers and traffic characteristics from the network data stream, and obtain the corresponding service weights from a pre-established service weight table; Priority parameters are calculated based on the business weights and traffic characteristics to obtain priority parameters; If the priority label of the data is a high priority label, query the queue scheduling rules of the high priority label from the pre-established scheduling rule base, and generate a high priority queue sort by combining the priority parameter; If the priority label of the data is a low priority label, query the queue scheduling rules for low priority labels from the pre-established scheduling rule base, combine the priority parameters, generate a low priority queue sorting, and obtain a queue scheduling scheme. A data transmission queue is generated according to the queue scheduling scheme, and the data type and transmission delay are extracted. The matching relationship between the data type and the transmission delay is analyzed, and an optimized transmission sequence is generated based on the matching relationship. Based on the optimized transmission sequence and the encryption strength adjustment scheme, the priority order of the transmission queue is adjusted to obtain the initial priority sequence.
[0040] It should be noted that the business identifier is obtained by parsing the application layer protocol field in the header of the data packet. For example, in a financial scenario, the data packet contains the identifier "TRANSACTION_TYPE=cross-border transfer". The traffic characteristics reuse the core parameters extracted from S14, including data size (e.g., 100KB / 50MB), transmission frequency (e.g., 120 times / second / 1 time / hour), and real-time requirements (e.g., latency threshold 200ms / 1000ms), and are uniformly standardized to a score of 0-10 (the higher the real-time requirement and the more critical the data, the higher the score). The priority parameter is the core quantitative indicator for measuring the urgency of data transmission. It is calculated by weighting the business weight and traffic characteristics. The priority parameter is the sum of the business weight and traffic characteristics multiplied by their respective weight ratios. The traffic characteristics need to be uniformly standardized to a range of 0-1. The standardized traffic characteristic is equal to the original value of the traffic characteristic divided by 10. The sum of the corresponding weight ratios of the two is 1, which can be configured according to different business types.
[0041] Collect over 10,000 business transmission records from the past 12 months. Each record must include the business type, historical leakage / delay events, and the amount of loss / scope of impact. Calculate the correlation between business type and historical risk losses (the correlation is obtained by calculating the ratio of the frequency of security events or timeout / delay events in the historical data of a specific business type to the average frequency of all businesses, and then normalizing after logarithmic processing). Adjust the basic weights according to the mapping rule of "correlation → weight": a correlation of 0.8-1.0 corresponds to a weight of 0.8-1.0, and a correlation of 0.5-0.7 corresponds to a weight of 0.5-0.7, ensuring that the weights are positively correlated with actual risk losses, and establish a business weight table. In the business weight table, a "Business Type - Weight Matching Sub-table" is added, which is divided into three categories according to business type: business-dominant (such as government confidential documents, financial end-of-day reconciliation), with a weight ratio (business weight: flow characteristics) of 0.8:0.2; flow-sensitive (such as financial high-frequency trading, medical emergency ECG), with a weight ratio (business weight: flow characteristics) of 0.5:0.5; and general balanced (such as ordinary cross-border transfers, government information disclosure notices), with a weight ratio (business weight: flow characteristics) of 0.6:0.4.
[0042] Based on the risk level labels output by S14, a preset scheduling rule base is invoked, and differentiated queue sorting is generated by combining priority parameters. The rule base stores scheduling logic categorized into "high-priority labels" and "low-priority labels." High-risk labels are set to preemptive scheduling, which can interrupt the transmission resources of low-priority queues; dedicated line bandwidth is guaranteed at ≥80%; and an expedited channel is triggered when latency exceeds the limit. Low-risk labels are set to non-preemptive scheduling, using only shared bandwidth and not preempting resources; sorting is based on "first-come, first-served"; and transmission can be delayed under high load. For all data with "high-risk labels," they are sorted from high to low priority parameters and marked with a "preemptible" flag; for data with "low-risk labels," they are first sorted in ascending order of priority parameters, and if parameters are the same, they are sorted by arrival time and marked with a "non-preemptible" flag.
[0043] The matching relationship between data types and transmission latency is analyzed to generate optimized transmission sequences. Data types are divided into three categories according to "real-time requirements": strong real-time, weak real-time, and non-real-time. Strong real-time types include real-time ECGs and high-frequency transactions (latency threshold ≤ 500ms); weak real-time types include cross-border transfers and confidential documents (latency threshold ≤ 2s); and non-real-time types include ordinary logs and historical backups (latency threshold ≤ 10s). Transmission latency is calculated through simulation. For example, based on the current queue length and bandwidth allocation, the time from when each piece of data enters the queue to when transmission is completed is predicted (e.g., if the high-priority queue currently has 5 pieces of data and a total bandwidth of 100Mbps, the predicted transmission latency for cross-border transfers is 1.2s, and for real-time ECG data it is 1.8s). If the predicted latency exceeds the data type threshold, the transmission order is adjusted and the data is transmitted with priority. For example, in the high-priority queue, the predicted latency of real-time ECG data (threshold 500ms) is 1.8s (exceeding the standard), while the predicted latency of cross-border transfer data (threshold 2s) ahead of it is 1.2s (not exceeding the standard). → The real-time ECG data is moved to the front of the cross-border transfer queue and transmitted with priority to ensure that its latency is reduced to 400ms (meeting the standard). The optimized transmission sequence is then generated.
[0044] The final initial priority sequence needs to incorporate the security requirements of the encryption strength adjustment scheme to ensure that data with high encryption strength (which is more likely to be targeted by attacks) has less exposure time in the queue. For data in the optimized transmission sequence, if the encryption strength value is >0.6 (e.g., AES-256 scheme, strength value 0.69), it is prioritized under the same priority parameter; if the encryption strength value is <0.6 (e.g., AES-128 scheme, strength value 0.57), the original order is maintained, resulting in the final initial priority sequence.
[0045] In step S16, the network environment change indicators are monitored according to the initial priority sequence. If the change indicators exceed the preset indicator range, the priority parameters are recalculated. If the change indicators are within the preset indicator range, the current priority sequence is maintained, thus obtaining an adjusted priority sequence.
[0046] It should be noted that the network environment change indicators monitored according to the initial priority sequence include basic performance indicators and encryption resource indicators. Basic performance indicators include bandwidth utilization (current path used bandwidth / total bandwidth), transmission latency (round-trip time), packet loss rate (percentage of packets lost per unit time), and node load (CPU / memory utilization of data processing nodes). Encryption resource indicators include encryption computing power utilization (number of CPU cores used by the current encryption task / total number of cores) and key rotation response time (time spent generating and distributing new keys). A hierarchical sampling strategy is used to determine the monitoring frequency and sampling method. Links associated with high-priority queues (such as cross-border transfers and real-time ECGs) are sampled at a high frequency of 100ms / sample; links associated with low-priority queues (such as ordinary logs) are sampled at a low frequency of 1s / sample. Sampled data is uploaded in real-time to the central scheduling node through a distributed monitoring agent (deployed on routers, switches, and server nodes).
[0047] The preset indicator range serves as the baseline for judging whether the network environment is normal. It needs to be determined by combining the tolerance threshold of the business scenario and historical stable state data. The fluctuation range of indicators during normal network operation over the past 3 months (e.g., the 95th percentile) should be statistically analyzed. For example, if the bandwidth utilization rate of a financial leased line is stable between 20% and 60%, this range should be used as the basic range. Referring to the maximum tolerance for latency and packet loss in step S14 (e.g., a latency threshold of 500ms for real-time ECG), 80% of the business tolerance threshold should be set as the warning upper limit (e.g., 400ms). The security upper limit for node load should be set to 70% (exceeding this may trigger performance degradation), and the upper limit for encryption computing power utilization should be set to 80% (reserving 20% to handle sudden encryption tasks). If all monitoring indicators are within the preset range, the network environment is considered stable, and the current initial priority sequence is maintained. If any indicator exceeds the preset range, the network environment is considered abnormal, and the priority parameters are recalculated.
[0048] When the network environment is abnormal, the priority parameters need to be recalculated based on the new environment state. The new priority parameters are calculated by multiplying the service weight by 0.5 and the standardized traffic feature by 0.5, then multiplying the network environment coefficient by 0.2 and then adding 0.8, and finally multiplying the two sums together (the network environment coefficient can be directly taken according to the network state level, with a coefficient of 1.0 under normal conditions; 2.0 under slight anomalies; and 3.0 under severe anomalies). After recalculating the priority parameters, the system reorders the initial sequence according to the new parameters, generates an adjusted priority sequence, and updates the transmission queue in real time. The high-priority queue is sorted in descending order according to the new parameters and retains the "preemptible" characteristic (the transmission of low-parameter data can be interrupted if the new parameter is high). When the low-priority queue is reordered, if the network environment is abnormal (such as the shared bandwidth utilization rate rising to 90%), it is sorted in ascending order according to the new parameters (the transmission of low-parameter data is delayed to release resources), and the "first-come, first-served" principle is canceled.
[0049] In step S17, the step of monitoring network environment change indicators during the data transmission of high-priority tags according to the adjusted priority sequence, analyzing the matching relationship between the change indicators and the high-priority data transmission, adjusting path selection according to the matching relationship, and obtaining intermediate path adjustment values includes: Based on the adjusted priority sequence monitoring, the network environment change indicators during the data transmission of high-priority tags are obtained; If the change index exceeds the preset index threshold, the sensitivity of the data is evaluated to obtain the data sensitivity evaluation result; The encryption strength is extracted from the data of high-priority tags. If the encryption strength is higher than a preset high-strength threshold, the data with high encryption strength is moved to the front of the priority sequence to obtain an updated priority sequence. The matching relationship between the change index and data transmission is analyzed based on the update priority sequence, and the path selection is adjusted according to the matching relationship to obtain the intermediate value of path adjustment.
[0050] It should be noted that monitoring network environment changes for high-priority data transmission involves establishing dedicated monitoring links for data marked as "high-priority" in the priority sequence (such as cross-border financial transfers and real-time medical ECGs). This allows for real-time capture of network environment fluctuations during transmission, focusing solely on the transmission path of high-priority data, including its dedicated links, core nodes, and encryption resources (to avoid consuming additional resources by monitoring low-priority data). The four key indicators most impactful on high-priority data are real-time transmission latency, path packet loss rate, remaining node encryption computing power (e.g., AES-256 computing power decreasing from 50% to 10%), and link stability score (based on the frequency of indicator fluctuations over the past 10 seconds, ranging from 1 to 10, with scores below 6 considered unstable). Millisecond-level sampling (50ms / time) is used to measure network environment changes.
[0051] The preset threshold values can be calculated by multiplying the ordinary threshold by 0.8. The ordinary high-priority threshold is the maximum acceptable upper limit of the indicator in this business scenario. Refer to the preset range in step S16. For example: Financial high priority: latency threshold 160ms (ordinary high priority is 200ms), packet loss rate threshold 0.4%; Medical high priority: latency threshold 320ms (ordinary high priority is 400ms), packet loss rate threshold 0.2%. When the monitored change indicators exceed the preset thresholds (such as latency > 200ms, packet loss rate > 0.5%), the sensitivity of the currently transmitted data needs to be assessed. Based on the sensitive identification fields in the data packet (such as "DATA_LEVEL=Top Secret" "PII=Contains Personal Privacy"), scores are given from 3 dimensions (0-10 points) and the average is taken, including the impact of leakage (such as life safety); compliance requirements (such as whether it complies with the Personal Information Protection Law); and real-time dependence (such as whether the interruption leads to decision-making errors). The assessment results are divided into three levels: high sensitivity (≥8 points, such as cross-border transfers), medium sensitivity (5-7 points, such as non-real-time medical records), and low sensitivity (<5 points, such as internal high-priority notifications).
[0052] If the encryption strength is greater than 0.6, the data is upgraded from a high-priority sequence to ultra-high priority and marked with the "path exclusive" flag (it can preempt path resources of other high-priority data); if the encryption strength is less than or equal to 0.6, the original high-priority sequence is maintained, but it is marked with "path shared" (it does not preempt resources, but only uses idle paths first). The system determines whether the current path meets the data's sensitivity and encryption strength requirements. If the data is highly sensitive and has high encryption strength, and the current path latency is 300ms > the threshold of 160ms, then the match fails (the path cannot guarantee real-time performance); if the data is moderately sensitive (or low sensitive) and has high encryption strength, and the current path packet loss rate is 0.3% < the threshold of 0.4%, then the match is successful (no adjustment is needed).
[0053] The system selects an alternative path from a pre-defined high-priority path pool (including backup dedicated lines, low-load core nodes, and links with sufficient encryption computing power). Priority rules include: remaining encryption computing power > 50% (ensuring efficient processing of high-encryption-strength data); historical latency < 80% of a threshold (reserving buffer space; for example, if the threshold is 160ms, a path with latency < 128ms will be selected); and link stability score > 8 points (reducing the probability of further adjustments). The output includes key parameters of the new path, yielding intermediate values for path adjustments. The pre-defined high-priority path pool is a set of high-quality transmission links reserved in advance for high-priority data. Transmission links can be extracted from historical transmission data and stored in a database. In step S18, adjusting the data transmission path based on the intermediate value of the path adjustment and recording the detailed attributes of low-priority data to obtain path optimization parameters includes: Traffic features and business scenario identifiers are extracted from low-priority data. If the traffic features exceed a preset feature threshold, the business scenario identifier is evaluated to obtain a business evaluation result. Based on the business evaluation results, the encryption strength is extracted from the low-priority data. If the encryption strength is higher than the preset low-priority threshold, the corresponding data is adjusted to the priority sequence to obtain the optimized priority sequence. Based on the detailed attributes of low-priority data recorded in the optimization priority sequence, the intermediate values of the path adjustment are adjusted according to the detailed attributes to obtain the path optimization parameters.
[0054] It should be noted that low-priority data (such as ordinary system logs and public notices) may occupy high-priority path resources when their traffic surges or encryption strength is high. The traffic characteristics defined in step S14 are reused to parse the identification fields from the packet header, such as "DATA_TYPE=system log", "BUSINESS=public announcement", and "URGENCY=non-urgent", to obtain the business scenario identifier. The preset feature thresholds are set based on the principle of not affecting high-priority path resources. For example, data size ≤ 500MB (score ≤ 5 points); transmission frequency ≤ 10 times per hour (score ≤ 3 points); bandwidth utilization ≤ 30% (score ≤ 4 points). If any feature score > the threshold, it is determined that the preset feature threshold has been exceeded. The business scenario identifier is evaluated from two dimensions: resource consumption necessity and latency tolerance (0-10 points). The average value is taken as the evaluation result. Resource consumption necessity verifies whether the purpose of data transmission is necessary (e.g., system logs are used for fault diagnosis, necessity 8 points; redundant backup files, necessity 3 points). Latency tolerance indicates whether transmission can be delayed (e.g., non-urgent notifications can be delayed for 24 hours, tolerance 10 points; daily reports must be completed on the same day, tolerance 5 points). The evaluation results are divided into three levels: need attention (≥ 7 points, such as high necessity + medium tolerance), can be postponed (4-6 points), and can be ignored (< 4 points).
[0055] The preset low-strength threshold is set to 0.5 (corresponding to the basic AES-128 encryption strength). For low-priority data that exceeds the threshold and is assessed as requiring attention, its encryption strength value is extracted (reusing the calculation result from step S14) and compared with the preset low-strength threshold. If the encryption strength > 0.5, the data is upgraded from low-priority sequence to medium-low priority and marked as having priority to use idle resources (transmitted when the high-priority path is idle, without preemption). If the encryption strength ≤ 0.5, the original low-priority sequence is maintained and it is marked as having only shared resources (transmitted during off-peak hours, such as 2-4 AM). By recording the detailed attributes of the low-priority data, the intermediate value of the path adjustment generated in step S17 is corrected. The detailed attribute records include resource usage attributes, security attributes, and service attributes. Among them, resource usage attributes include data size (e.g., 1GB), peak bandwidth requirement (e.g., 50Mbps), and transmission time preference (e.g., off-peak hours); security attributes include encryption strength (e.g., 0.6) and whether it contains sensitive fields (e.g., internal IP); service attributes include assessment results (e.g., requiring attention) and latency tolerance threshold (e.g., ≤ 24 hours).
[0056] If low-priority data requires enhanced encryption, 10% of the bandwidth allocation from the high-priority path is reserved as shared idle bandwidth (e.g., the bandwidth allocation for ZX-001 is reduced from 80% to 70%, reserving 10% for its use during idle periods). If low-priority data has negligible encryption, it is allocated to a dedicated low-priority link (e.g., shared bandwidth link ID=GX-002) to avoid occupying high-priority path resources. The final output path optimization parameters include the corrected key path parameters, such as: High-priority main path: dedicated line ID=ZX-001, bandwidth allocation 70%, encryption computing power reserved 60% (to ensure high-priority data); shared idle bandwidth: 10% (for use by medium and low-priority data during idle periods); low-priority dedicated link: ID=GX-002, bandwidth 20%, only enabled between 2-4 AM; switching trigger condition: when the high-priority path load is <50%, medium and low-priority data are allowed to use shared bandwidth.
[0057] In step S19, the data transmission path is optimized according to the path optimization parameters to obtain a secure network data transmission configuration.
[0058] It should be noted that a "priority-path" mapping rule is constructed based on path optimization parameters to establish a binding relationship between data of different priorities and transmission paths, avoiding resource conflicts caused by mixed path usage. The mapping rule must cover all priority types (ultra-high / high / medium-low / low), including ultra-high priority data (such as cross-border transfers + AES-256 encryption): bound to the dedicated line ranked first in the "high-priority path pool" (such as ZX-001), configured with a "path exclusive" flag (not allowing other data to occupy it), and locking the encryption computing power ≥60% (ensuring uninterrupted encryption processing). High priority data (such as real-time ECG with AES-192 encryption): bound to the redundant links ranked 2nd-3rd in the "high-priority path pool" (such as YL-002, YL-003), configured with "path sharing but high-priority occupancy" (automatically preempting resources when conflicting with medium-low priority data). For low-to-medium priority data (such as system logs requiring monitoring with AES-192 encryption): bind to the shared idle bandwidth of a high-priority path (e.g., 10% of the reserved bandwidth of ZX-001), and configure idle transmission trigger conditions (only enabled when high-priority data occupies <50% of the bandwidth). For low-priority data (such as ordinary logs with AES-128 encryption): bind to a low-priority dedicated link (e.g., GX-002), configure transmission during off-peak hours, and limit the maximum bandwidth usage of a single data entry to ≤20% (to avoid congestion).
[0059] Based on the resource allocation baseline in the path optimization parameters (such as 70% bandwidth for high-priority paths, 10% for shared paths, and 20% for low-priority paths), a dynamic resource allocation strategy is optimized, including dynamic bandwidth allocation and encrypted computing power allocation. The dynamic bandwidth allocation includes: high-priority paths: default bandwidth of 70%, which is automatically increased to 90% when ultra-high-priority data transmission is detected (temporarily compressing shared bandwidth to 10%), and restored after the transmission ends; shared idle bandwidth: 10% baseline, which can be temporarily extended to 30% when the high-priority data load is <30% (for accelerating the transmission of medium and low-priority data); low-priority dedicated links: 20% fixed bandwidth, which is only open during off-peak hours and automatically closed during peak hours (such as 9:00-18:00) to avoid resource occupation. The allocation of encrypted computing power includes reserving an encrypted computing power pool (such as 50% of the total computing power) for nodes bound to high-priority paths, of which ≥30% is dedicated to the AES-256 algorithm (to ensure ultra-high priority data), and 20% is shared by AES-192 / 128; low-priority data can only use 30% of the remaining 50% of computing power (to avoid crowding out the encryption resources of high-priority data).
[0060] The above optimization results are integrated into a standardized configuration file (such as JSON format), which contains all execution details for the transmission system to directly call, generating the final network data secure transmission configuration.
[0061] It should be noted that when a high-priority task preempts the resources of a low-priority task, the system will record the context state of the interrupted task (including transmission progress, source / destination address, service identifier, etc.) and place it in a specific 'suspended queue'. Once the system detects that network resources have recovered sufficiently (e.g., the total bandwidth utilization is less than 50% for more than 10 seconds), or the waiting time of the suspended task is close to its latency tolerance threshold, the scheduler will automatically resume transmission from its breakpoint to ensure the final completion of all services.
[0062] In summary, this solution aligns security requirements with encryption strength by adjusting recommended values to match risk levels. High-risk data corresponds to advanced encryption standards (AES-256 + GCM certification), while low-risk data corresponds to basic encryption standards (AES-128 + CBC). Low-risk data uses basic encryption, reducing computational power consumption, and the freed-up computing power can support the encryption processing of high-risk data. High-risk data uses advanced encryption, improving resistance to brute-force attacks, reducing overall encryption computational power consumption, and increasing the attack resistance rate of high-risk data. This solution pre-defines a dedicated path pool with a security level ≥4 for high-priority data. Path security capabilities and data encryption strength are matched bidirectionally. Security indicators of high-priority data transmission paths are monitored in real time. If path tampering is detected, the system immediately switches to a backup secure link in the path pool. The switching time can be stably controlled within 100-200ms, avoiding data exposure windows. This improves the security compliance rate of high-priority, high-risk data transmission paths and reduces data leakage incidents caused by insecure paths.
[0063] Reference Figure 2 The second embodiment of the present invention provides a network data security transmission system, comprising: The data acquisition module is used to acquire network data streams, extract feature vectors from the network data streams, and calculate the quantization score of the feature vectors to obtain a preliminary quantization score. The data comparison module is used to compare the preliminary quantified score with a preset score threshold, and map the priority of the network data according to the comparison result to obtain the classification result of the network data. The data adjustment module is used to adjust the resource allocation during data transmission based on the classification results to obtain suggested adjustment values. The data selection module is used to match the risk level of data transmission according to the adjustment suggestion value. If the risk level is high, the advanced encryption standard is selected; if the risk level is low, the basic encryption standard is selected, thus obtaining the encryption strength adjustment scheme. The data sorting module is used to extract the priority parameters of data transmission from the encryption strength adjustment scheme and sort the transmission queue to obtain an initial priority sequence. The data calculation module is used to monitor changes in network environment indicators based on the initial priority sequence. If the changes exceed the preset indicator range, the priority parameters are recalculated. If the changes are within the preset indicator range, the current priority sequence is maintained, thus obtaining an adjusted priority sequence. The data analysis module is used to monitor changes in network environment indicators during the data transmission of high-priority tags according to the adjusted priority sequence, analyze the matching relationship between the changes in indicators and the data transmission of high-priority tags, adjust the path selection according to the matching relationship, and obtain the intermediate value of path adjustment. The data recording module is used to adjust the data transmission path according to the intermediate value of the path adjustment, and record the detailed attributes of low-priority data to obtain path optimization parameters; The data transmission module is used to optimize the data transmission path according to the path optimization parameters to obtain a secure network data transmission configuration.
[0064] It should be noted that the network data security transmission system provided in this embodiment of the invention is used to execute all the process steps of the network data security transmission method in the above embodiment. The working principles and beneficial effects of the two are one-to-one, so they will not be described again.
[0065] This invention also provides an electronic device. The electronic device includes a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a network data secure transmission program. When the processor executes the computer program, it implements the steps described in the various network data secure transmission method embodiments above, for example... Figure 1 The step S11 shown. Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in the above system embodiments, such as the data transmission module.
[0066] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device.
[0067] The electronic device may be a desktop computer, laptop computer, handheld computer, or smart tablet, etc. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the above components are merely examples of electronic devices and do not constitute a limitation on the electronic device. It may include more or fewer components than described above, or combine certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, etc.
[0068] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the electronic device, connecting all parts of the electronic device via various interfaces and lines.
[0069] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0070] If the modules / units integrated into the electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or system capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.
[0071] It should be noted that the system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the system embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0072] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A network data security transmission method, characterized by, The method comprises the following steps: obtaining a network data stream, extracting a feature vector from the network data stream, and calculating a quantization score of the feature vector to obtain a preliminary quantization score; comparing the preliminary quantization score with a preset score threshold, and mapping the priority of the network data according to the comparison result to obtain a hierarchical classification result of the network data; adjusting resource allocation during data transmission according to the hierarchical classification result to obtain an adjustment suggestion value; matching the risk level of data transmission according to the adjustment suggestion value, selecting high-level encryption standard if the risk level is high, and selecting basic encryption standard if the risk level is low to obtain an encryption strength adjustment scheme; extracting a priority parameter of data transmission from the encryption strength adjustment scheme and performing transmission queue sorting to obtain an initial priority sequence; monitoring a change indicator of the network environment according to the initial priority sequence, recalculating the priority parameter if the change indicator exceeds a preset indicator range, and maintaining the current priority sequence if the change indicator is within the preset indicator range to obtain an adjusted priority sequence; monitoring a change indicator of the network environment during the data transmission process of the high-priority label according to the adjusted priority sequence, analyzing the matching relationship between the change indicator and the high-priority data transmission, and adjusting the path selection according to the matching relationship to obtain a path adjustment intermediate value; adjusting the data transmission path according to the path adjustment intermediate value and recording the detail attributes of the low-priority data to obtain a path optimization parameter; optimizing the data transmission path according to the path optimization parameter to obtain a network data security transmission configuration.
2. The network data security transmission method of claim 1, wherein, The method comprises the following steps: if the preliminary quantization score is higher than the preset score threshold, marking it as a high importance label, and if the preliminary quantization score is lower than the preset score threshold, marking it as a low importance label to obtain a label allocation result; mapping the label allocation result to a primary priority label using a pre-established priority label mapping table to obtain a hierarchical classification result of the network data.
3. The network data security transmission method of claim 1, wherein, The method comprises the following steps: obtaining a change indicator of the network environment; calculating a comprehensive environment score according to the change indicator and the hierarchical classification result to obtain a dynamic environment quantization value; if the dynamic environment quantization value is higher than a preset quantization threshold, marking it as a high-priority label, and if the dynamic environment quantization value is lower than a preset quantization threshold, marking it as a low-priority label to obtain an optimized priority label after secondary adjustment; adjusting resource allocation according to the optimized priority label to obtain a resource allocation scheme; evaluating the timeliness according to the resource allocation scheme, adjusting resource allocation according to the evaluation result to obtain an adjustment suggestion value.
4. The network data security transmission method of claim 1, wherein, The method comprises the following steps: According to the adjustment suggestion value, a risk level is matched from a pre-established business scenario rule library; If the risk level is higher than a preset risk threshold, a high-risk label is generated, and if the risk level is lower than the preset risk threshold, a low-risk label is generated, to obtain a risk level label; According to the risk level label, a corresponding encryption scheme is queried from a pre-established encryption scheme library, if it is a high-risk label, a high-level encryption scheme is selected, and if it is a low-risk label, a basic encryption scheme is selected, to obtain an encryption scheme selection result; According to the encryption scheme selection result, an encryption strength and a security level are quantified, to obtain an encryption strength value; From the network data stream, traffic features are extracted, and a matching relationship with the encryption strength value is analyzed, and an encryption strength adjustment scheme is obtained according to the matching relationship.
5. The network data security transmission method of claim 1, wherein, The priority parameter of data transmission is extracted from the encryption strength adjustment scheme, and a transmission queue is sorted, to obtain an initial priority sequence, including: From the network data stream, business identifiers and traffic features are extracted, and corresponding business weights are queried from a pre-established business weight table; According to the business weight and the traffic feature, a priority parameter is calculated, to obtain a priority parameter; If the priority label of the data is a high-priority label, a queue scheduling rule of the high-priority label is queried from a pre-established scheduling rule library, and a high-priority queue sorting is generated in combination with the priority parameter; If the priority label of the data is a low-priority label, a queue scheduling rule of the low-priority label is queried from a pre-established scheduling rule library, and a low-priority queue sorting is generated in combination with the priority parameter, to obtain a queue scheduling scheme; According to the queue scheduling scheme, a data transmission queue is generated, and a data type and a transmission time delay are extracted, a matching relationship between the data type and the transmission time delay is analyzed, and an optimized transmission sequence is generated according to the matching relationship; According to the optimized transmission sequence, in combination with the encryption strength adjustment scheme, the priority order of the transmission queue is adjusted, to obtain an initial priority sequence.
6. The network data security transmission method of claim 1, wherein, According to the adjustment priority sequence, a change index of a network environment in a data transmission process of a high-priority label is monitored, a matching relationship between the change index and the high-priority data transmission is analyzed, and a path selection is adjusted according to the matching relationship, to obtain a path adjustment intermediate value, including: According to the adjustment priority sequence, a change index of a network environment in a data transmission process of a high-priority label is monitored; If the change index exceeds a preset index threshold, the sensitivity of the data is evaluated, to obtain a data sensitivity evaluation result; From the high-priority label data, an encryption strength is extracted, if the encryption strength is higher than a preset high-strength threshold, the data with high encryption strength is adjusted to the front of the priority sequence, to obtain an updated priority sequence; According to the updated priority sequence, a matching relationship between the change index and the data transmission is analyzed, and a path selection is adjusted according to the matching relationship, to obtain a path adjustment intermediate value.
7. The network data security transmission method of claim 1, wherein, According to the path adjustment intermediate value, a data transmission path is adjusted, and a detail attribute of low-priority data is recorded, to obtain a path optimization parameter, including: Extracting traffic features and service scenario identification from low-priority data, if the traffic features exceed the preset feature threshold, the service scenario identification is evaluated to obtain a service evaluation result; According to the service evaluation result, the encryption strength is extracted from the low-priority data, if the encryption strength is higher than the preset low-intensity threshold, the corresponding data is adjusted to the priority sequence, and an optimized priority sequence is obtained; According to the optimization priority sequence, the details of the low-priority data are recorded, and the path adjustment intermediate value is adjusted according to the details, and the path optimization parameter is obtained.
8. A network data security transmission system characterized by, Comprise: Data acquisition module, for acquiring network data stream, extracting feature vector from the network data stream, and calculating the quantization score of the feature vector to obtain a preliminary quantization score; Data comparison module, for comparing the preliminary quantization score with the preset score threshold, and mapping the priority of network data according to the comparison result to obtain the classification result of network data; Data adjustment module, for adjusting the resource allocation during data transmission according to the classification result to obtain an adjustment suggestion value; Data selection module, for matching the risk level of data transmission according to the adjustment suggestion value, if the risk level is high, selecting high-level encryption standard, if the risk level is low, selecting basic encryption standard, obtaining encryption strength adjustment scheme; Data sorting module, for extracting priority parameters of data transmission from the encryption strength adjustment scheme, and sorting the transmission queue to obtain an initial priority sequence; Data calculation module, for monitoring the change index of network environment according to the initial priority sequence, if the change index exceeds the preset index range, recalculating the priority parameter, if the change index is in the preset index range, maintaining the current priority sequence, obtaining the adjustment priority sequence; Data analysis module, for monitoring the change index of network environment in the data transmission process of high-priority label according to the adjustment priority sequence, analyzing the matching relationship between the change index and the high-priority data transmission, adjusting the path selection according to the matching relationship, obtaining the path adjustment intermediate value; Data recording module, for adjusting the data transmission path according to the path adjustment intermediate value, and recording the details of the low-priority data to obtain the path optimization parameter; Data transmission module, for optimizing the data transmission path according to the path optimization parameter to obtain the network data security transmission configuration.
Citation Information
Cited By
Intelligent sensitive data protection method and system
CN122394963A