Data secure transmission method, device, equipment, medium and product

By dynamically determining the transmission security value of the data transmission link based on the security level of the original data and historical transmission data, and generating an encryption key for each data transmission, the data security risk caused by the easy leakage of fixed keys is resolved, thus improving the security of data transmission.

CN121530552APending Publication Date: 2026-02-13LIAONING MOBILE COMM +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511683237.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-17
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

In existing technologies, the use of fixed keys makes the keys highly vulnerable to leakage. Once the key is stolen, all data encrypted with that key is at risk of being decrypted and stolen, resulting in insufficient data transmission security.

Method used

Based on the security level of the original data, historical transmission data, and the attributes of all nodes in the data transmission link, the transmission security value of the data transmission link is dynamically determined, and an encryption key for each data transmission is generated accordingly, so that each key is different and related to the security situation at that time.

Benefits of technology

By dynamically generating encryption keys, the risk of other data being decrypted and stolen after the key is stolen is avoided, thus improving the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530552A_ABST
    Figure CN121530552A_ABST
Patent Text Reader

Abstract

The invention discloses a secure data transmission method, apparatus and device, a medium and a product. The method comprises the steps of determining a transmission security value of a data transmission link according to a security level of original data, a historical transmission condition and attributes of all nodes in the data transmission link; and determining an encryption key for current data transmission according to the transmission security value so as to carry out data transmission. The encryption key for each data transmission can be determined according to the security level and the historical transmission condition of original data and all node attributes in the data transmission link so as to perform data transmission, so that the keys for each data transmission are different and are related to the security condition of the data transmission link at the time, and the situation that the data transmission link cannot be damaged after the key is stolen at one time is avoided. Other data are faced with the risk of being decrypted and stolen, and the security of data transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission technology, and in particular to a data security transmission method, apparatus, device, medium, and product. Background Technology

[0002] In the process of providing data services, data transmission security is a core concern for Subscriber Data Centers (SDCs). Currently, encryption is used to ensure the security of SDC data transmission. The specific process is as follows: the original data to be transmitted is encrypted using a key, the encrypted data is transmitted to the destination node, and then the destination node decrypts it using the same key to obtain the original data. In existing encryption methods, the key is mainly issued by a Certificate Authority (CA) or pre-agreed by both parties. Once the key is determined, it does not change, and all subsequent data is encrypted using this key. The key is a core factor in ensuring data security, and the use of fixed keys makes it highly vulnerable to leakage. For example, if an attacker obtains the fixed key through illegal means (such as theft or cracking), once the fixed key is leaked, all data encrypted using that fixed key is at risk of being decrypted and stolen. Therefore, improving the security of SDC data transmission requires addressing the data security risks caused by the vulnerability of fixed keys. Summary of the Invention

[0003] This invention provides a data security transmission method, apparatus, device, medium, and product. It determines the transmission security value of the data transmission link based on the security level of the original data, historical transmission data, and the attributes of all nodes in the data transmission link. It then determines an encryption key for each data transmission based on this security value, ensuring that the key is different for each data transmission and is related to the security status of the data transmission link at that time. This avoids the risk of all other data being decrypted and stolen if a key is stolen once, thus improving the security of data transmission.

[0004] To achieve the above objectives, embodiments of the present invention provide a data security transmission method, including: The transmission security value of the data transmission link is determined based on the security level of the original data, historical transmission data, and the attributes of all nodes in the data transmission link. The encryption key for the current data transmission is determined based on the transmission security value to facilitate data transmission.

[0005] As an improvement to the above scheme, determining the transmission security value of the data transmission link based on the security level of the original data, historical transmission status, and the attributes of all nodes in the data transmission link includes: Obtain the original data identifier of the raw data to be transmitted and the attributes of all nodes in the data transmission link; The security level and historical transmission history of the original data are determined based on the original data identifier. The transmission security value of the data transmission link is determined based on the security level, the historical transmission data, and the attributes of all nodes.

[0006] As an improvement to the above scheme, determining the transmission security value of the data transmission link based on the security level, the historical transmission status, and the attributes of all nodes includes: The security value of each node in the data transmission link is determined based on the security level, the historical transmission information, and the attributes of all nodes. The transmission security value of the data transmission link is determined based on the security value of each node.

[0007] As an improvement to the above solution, if the node attributes include the node's security attributes, behavioral attributes, and permission attributes, The step of determining the security value of each node in the data transmission link based on the security level, the historical transmission information, and the attributes of all nodes includes: The permission attribute value of each node in the data transmission link is determined based on the security level and the historical transmission data. Obtain the security attribute value, behavior attribute value and corresponding attribute weight of each node, as well as the permission attribute weight of each node; The security value of each node in the data transmission link is determined based on the security attribute value, behavior attribute value, permission attribute value, and corresponding attribute weight of each node.

[0008] As an improvement to the above scheme, determining the permission attribute value of each node in the data transmission link based on the security level and the historical transmission information includes: The probability of each node obtaining the original data is determined based on the security level. Determine the minimum security level for the transmission of the original data based on the historical transmission data; The permission attribute value of each node in the data transmission link is calculated based on the probability, the minimum security level of the transmission, and the permission attribute of each node.

[0009] As an improvement to the above scheme, obtaining the security attribute value, behavior attribute value, and corresponding attribute weight of each node, as well as the permission attribute weight of each node, includes: Calculate the security attribute value and security attribute weight of each node based on the vulnerability status, attack status, and basic security value of each node; Calculate the behavioral attribute value and behavioral attribute weight of each node based on its resource utilization, access status, and occurrence of abnormal events. The permission attribute weight of each node is calculated based on the permission attribute and the maximum value of the permission attribute.

[0010] As an improvement to the above scheme, after determining the transmission security value of the data transmission link, the method further includes: Whether to transmit data is determined based on the aforementioned transmission security value; The step of determining the encryption key for the current data transmission based on the transmission security value to perform data transmission is as follows: If data transmission is to be performed, the encryption key for the current data transmission is determined based on the transmission security value to perform the data transmission.

[0011] As an improvement to the above solution, the method of determining whether to transmit data based on the transmission security value includes one of the following methods: Whether to transmit data is determined based on the security value of each node and the node security value threshold in the transmission security value; Whether to transmit data is determined based on the transmission security value, the security value of each node, the node security value threshold, the historical normal transmission security value, and the preset ratio threshold.

[0012] As an improvement to the above scheme, the step of determining whether to perform data transmission based on the transmission security value, the security value of each node, the node security value threshold, the historical normal transmission security value, and the preset proportion threshold includes: If the security value of each node in the transmission security value is greater than or equal to the node security value threshold, then determine whether the ratio of the standard deviation to the mean of the historical normal transmission security values ​​is greater than a preset ratio threshold. If the ratio is greater than the preset ratio threshold, no data transmission will be performed; If the ratio is not greater than the preset ratio threshold, then it is determined whether to perform data transmission based on the transmission security value, the node security value threshold, and the ratio.

[0013] As an improvement to the above scheme, the step of determining the encryption key for the current data transmission based on the transmission security value to perform data transmission includes: Send the hash value of the transmission security value and the determined time value for data transmission to the destination node, so that the destination node receives the hash value and returns the receiving time value; The encryption key for the current data transmission is generated based on the hash value, the determined time value, and the received time value; The original data is encrypted using the encryption key, and the encrypted data is transmitted to the destination node via the data transmission link, so that the destination node can decrypt the received encrypted data to obtain the original data.

[0014] To achieve the above objectives, embodiments of the present invention provide a data security transmission device, comprising: The transmission security determination module is used to determine the transmission security value of the data transmission link based on the security level of the original data, historical transmission status, and the attributes of all nodes in the data transmission link. An encryption key determination module is used to determine the encryption key for the current data transmission based on the transmission security value in order to transmit the data.

[0015] To achieve the above objectives, embodiments of the present invention provide a data security transmission device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the above-described data security transmission method.

[0016] To achieve the above objectives, embodiments of the present invention also provide a computer-readable storage medium, the computer-readable storage medium including a stored computer program, wherein the computer program, when running, controls the device where the computer-readable storage medium is located to execute the above-described data secure transmission method.

[0017] To achieve the above objectives, embodiments of the present invention also provide a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the above-described secure data transmission method.

[0018] Compared with existing technologies, the data security transmission method, apparatus, device, medium, and product disclosed in this invention determine the transmission security value of the data transmission link based on the security level of the original data, historical transmission information, and the attributes of all nodes in the data transmission link; and determine the encryption key for the current data transmission based on the transmission security value. This allows for the determination of the encryption key for each data transmission based on the security level of the original data, historical transmission information, and the attributes of all nodes in the data transmission link, ensuring that the key is different for each data transmission and is related to the security status of the data transmission link at that time. This avoids the risk of subsequent data being decrypted and stolen after one key is stolen, thus improving the security of data transmission. Attached Figure Description

[0019] Figure 1 This is a flowchart illustrating a data security transmission method provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of a data security management and control platform provided in an embodiment of the present invention; Figure 3 A flowchart illustrating another data security transmission method provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a data security transmission device provided in an embodiment of the present invention; Figure 5 This is a structural block diagram of a data security transmission device provided in an embodiment of the present invention. Detailed Implementation

[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] It should be noted that the terms "comprising" and "specific" in this invention, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or device.

[0022] Please see Figure 1 , Figure 1 This is a flowchart illustrating a secure data transmission method provided in an embodiment of the present invention. The secure data transmission method includes: S1, determine the transmission security value of the data transmission link based on the security level of the original data, historical transmission status, and the attributes of all nodes in the data transmission link; S2, determine the encryption key for the current data transmission based on the transmission security value to perform data transmission.

[0023] For example, the secure data transmission method is implemented by the user data center. The secure data transmission method described in this embodiment can be applied to a data security management platform, such as... Figure 2 As shown, Figure 2This is a schematic diagram of a data security management platform provided in an embodiment of the present invention. The data security transmission method is used in the data flow monitoring and analysis module of the platform for the secure transmission of monitored data. The user data center can interact with target nodes. The user data center obtains the security level, historical transmission status, and attributes of all nodes in the data transmission link (e.g., node attributes include the node's security attributes, behavioral attributes, and permission attributes). Based on the security level, historical transmission status, and all node attributes, it determines and calculates the transmission security value of the data transmission link, and generates an encryption key for the current data transmission. This allows for the determination of an encryption key for each data transmission based on the security level, historical transmission status, and attributes of all nodes in the data transmission link. This ensures that the key is different for each data transmission and is related to the security status of the data transmission link at that time, preventing the risk of decryption and theft of other data after a key is stolen, thus improving the security of data transmission.

[0024] Specifically, step S1 includes: S11, Obtain the original data identifier of the original data to be transmitted and the attributes of all nodes in the data transmission link; S12, determine the security level and historical transmission status of the original data based on the original data identifier; S13, determine the transmission security value of the data transmission link based on the security level, the historical transmission status, and the attributes of all nodes.

[0025] Specifically, in step S11, execution can be triggered based on a data request. For example, when a node A requests data B (raw data) from the SDC, node A sends a data request to the SDC. This data request includes the identifier of data B and the identifier of node A. Based on the data request, the identifier of data B is obtained, which is the original data identifier. SDC sends an attribute retrieval request to node A based on node A's identifier. Each node in the link to node A will send its own node attributes to SDC based on the attribute retrieval request. This allows us to obtain the attribute information of each node in the entire data transmission link established between node A and SDC. The node attributes are identified by the node identifier.

[0026] Alternatively, execution can be triggered by a task. For example, when SDC executes a task, if the task includes a subtask to transmit data B to node A, SDC can obtain the identifier of data B based on this task. This identifier is the original data identifier. Simultaneously, knowing that the destination node is node A, an attribute retrieval request is sent to node A. Each node in the link to node A will send node attributes to SDC based on the attribute retrieval request. This allows us to obtain the attribute information of each node in the entire data transmission link established between node A and SDC. The node attribute uses the node identifier as the attribute identifier.

[0027] In step S12, the security level is configured by relevant personnel during the production of the original data. It is determined comprehensively based on the amount of sensitive data included in the original data, the importance of the business involved in the original data, and the impact of the original data being leaked. The security level is the minimum permission attribute among the nodes that can obtain the original data; that is, only nodes with permission attributes higher than or equal to the security level of the original data can obtain the original data. The historical transmission information can be extracted by SDC from its own stored data transmission history records, including the destination node attributes, transmission security values, and transmission results (whether the transmission was normal or terminated) for each transmission of the original data.

[0028] More specifically, step S13 includes: S131, determine the security value of each node in the data transmission link based on the security level, the historical transmission status, and the attributes of all nodes; S132, determine the transmission security value of the data transmission link based on the security value of each node.

[0029] For example, a storage node is a node that stores the original data, such as obtaining the original data identifier. Then, based on this original data identifier The storage location of the data is determined, and the node belonging to this location is the storage node. The original data needs to be transferred from the storage node to the destination node, forming a data transmission link. Therefore, the storage node is a node on the data transmission link and also an endpoint of that link. The transmission security value is derived based on the security values ​​of each node in the data transmission link. If the transmission security value of the data transmission link is... The data transmission link includes any node The safety value is ,So .

[0030] More specifically, if the node attributes include the node's security attributes, behavioral attributes, and permission attributes, S131 includes: S1311, Determine the permission attribute value of each node in the data transmission link based on the security level and the historical transmission information; S1312, obtain the security attribute value, behavior attribute value and corresponding attribute weight of each node, as well as the permission attribute weight of each node; S1313, determine the security value of each node in the data transmission link based on the security attribute value, behavior attribute value, permission attribute value and corresponding attribute weight of each node.

[0031] For example, if node attributes include security attributes, behavioral attributes, and permission attributes; security attributes include node vulnerability information (e.g., obtained through a vulnerability list), node attack information (e.g., obtained through attack logs), and node basic security value (e.g., obtained through security scoring by security software running on the node); behavioral attributes include node resource utilization (e.g., obtained through system logs) and access information (e.g., obtained through access logs); permission attributes include the data security permissions of the destination node, which are assigned by relevant security personnel. For example, for nodes with login activity, such as the destination node where a user logs in, the user can gain access permissions using their username and password; for nodes without login activity, such as intermediate forwarding nodes, data security permissions are configured by relevant personnel based on the node's function during initial configuration and can be modified later based on actual conditions. This access permission characterizes the security level of the data that the user is allowed to access. The higher the permission, the higher the security level that can be accessed, and the more confidential the data that can be obtained. For any node... safety value for: , In the formula, For nodes Security attribute weights; For nodes The security attribute value; For nodes behavioral attribute weights For nodes Behavioral attribute values; For nodes The weight of permission attributes; For nodes The permission attribute value.

[0032] More specifically, determining the permission attribute value of each node in the data transmission link based on the security level and the historical transmission information includes: The probability of each node obtaining the original data is determined based on the security level. Determine the minimum security level for the transmission of the original data based on the historical transmission data; The permission attribute value of each node in the data transmission link is calculated based on the probability, the minimum security level of the transmission, and the permission attribute of each node.

[0033] For example, the formula for calculating the permission attribute value is: , In the formula, For nodes The probability of obtaining the original data, if This indicates the level of security at which the original data can be obtained (i.e., the security level of the original data). ) compared to nodes A higher security level is required, indicating that the node... If you do not have permission to access the original data, then ;like This indicates that the security level at which the original data can be obtained is no higher than that of the node. The available security level indicates the node's security level. If one has the right to access the original data, then . For nodes Permission attributes; The minimum security level for the transmission of raw data is determined as follows: Based on the historical transmission history of the raw data, the security level of the destination node for each transmission and the transmission result for each transmission are determined. Among the data whose transmission result is normal, the maximum security level is determined, and this value is... .

[0034] More specifically, obtaining the security attribute value, behavior attribute value, and corresponding attribute weight of each node, as well as the permission attribute weight of each node, includes: Calculate the security attribute value and security attribute weight of each node based on the vulnerability status, attack status, and basic security value of each node; Calculate the behavioral attribute value and behavioral attribute weight of each node based on its resource utilization, access status, and occurrence of abnormal events. The permission attribute weight of each node is calculated based on the permission attribute and the maximum value of the permission attribute.

[0035] For example, the formula for calculating the weight of security attributes is as follows: , The formula for calculating security attribute values ​​is: , In the formula, For nodes The maximum CVSS value for each vulnerability in the vulnerability list; For nodes The total number of vulnerabilities in the vulnerability list; For all nodes in the data transmission link The maximum value; For nodes The basic safety value; For nodes The attack type identifier can be implemented by first clustering the attack types involved in each attack in the attack log to obtain the attack data corresponding to each attack type. That is, the identifier of the attack type corresponding to each cluster after clustering; For nodes Medium attack type Attack level; For nodes Medium attack type The total number of attacks in the corresponding type indicates the attack type recorded in the attack log. Total number of attacks; For nodes Medium attack type The maximum CVSS of the vulnerabilities involved in each attack; This represents the total number of attacks included in the attack log.

[0036] It's worth noting that CVSS (Common Vulnerability Scoring System) is an industry-open standard designed to assess the severity of vulnerabilities and help determine the urgency and importance of the required responses. Its main purpose is to establish a standard for measuring vulnerability severity, allowing for comparison of vulnerability severity and thus prioritizing their handling. CVSS scores are based on measurements across a series of dimensions called metrics. The final score for a vulnerability ranges from a maximum of 10 to a minimum of 0.

[0037] The formula for calculating the weight of behavioral attributes is: , The formula for calculating behavioral attribute values ​​is: , In the formula, For nodes obtained based on access logs Total number of visits; This represents the maximum total number of accesses across all nodes in the data transmission link. To obtain access nodes based on access logs The total number of different IP addresses; For nodes The average resource utilization rate; For nodes The maximum resource utilization rate is obtained from the resource utilization information in the system log. The resource utilization rate can be obtained based on this resource utilization information. For nodes The number of times abnormal events occurred. This represents the maximum number of abnormal events occurring across all nodes in the data transmission link. This is a pre-set minimum value to prevent exceptions caused by a denominator of 0. The system log also records system shutdown events, hardware failures, and service start / stop events. The sum of the number of system shutdown events, the number of hardware failures, and the number of service stops is determined as the number of abnormal events. For all attack nodes obtained from the attack logs IP address identifier; For attacking nodes The The number of times each IP address appears in the access logs. For the nodes in the access log Total number of visits involved.

[0038] It is worth noting that the access log records the access nodes. This includes the IP addresses and access times of each access. You can first compile statistics on the source IP addresses involved in each attack in the attack logs to obtain the attacking nodes. All IP addresses, for any IP address Identify any IP address appearing in the access logs. The number of times, that number is... The total number of accesses recorded in the access log is... .

[0039] The formula for calculating the weight of permission attributes is: , In the formula, For nodes Permission attributes, This is the maximum value for the permission attribute. This value is the maximum value determined when the permission attribute is preset, which is the theoretical value, not the node's maximum value. The maximum value of the assignable permission attributes is not the maximum value of the permission attributes of each node in the link.

[0040] Furthermore, such as Figure 3 As shown, Figure 3 This is a flowchart illustrating another data security transmission method provided by an embodiment of the present invention; after determining the transmission security value of the data transmission link, the method further includes: S101, determine whether to perform data transmission based on the transmission security value; Then step S2 is: S201, If ​​data transmission is to be performed, the encryption key for the current data transmission is determined based on the transmission security value to perform the data transmission.

[0041] For example, a transmission security value is used to determine whether to perform data transmission. If data transmission is not performed, the data transmission task is terminated, and the reason for termination is reported along with a termination warning. If data transmission is performed, the encryption key for the current data transmission is determined based on the transmission security value to enable data transmission. This embodiment of the invention adds a judgment on the security of the transmission environment, reducing the possibility of data theft during transmission and improving data transmission security.

[0042] Specifically, the method of determining whether to transmit data based on the transmission security value includes one of the following methods: Whether to transmit data is determined based on the security value of each node and the node security value threshold in the transmission security value; Whether to transmit data is determined based on the transmission security value, the security value of each node, the node security value threshold, the historical normal transmission security value, and the preset ratio threshold.

[0043] For example, when determining whether to transmit data, a comprehensive assessment is made based on the transmission security value and the security values ​​of each node in the transmission link. A node security value threshold is preset. This value is an empirical value, obtained based on sample data using existing big data processing solutions. If the original data is being transmitted for the first time, and there are no historical transmission records, it is impossible to obtain historical normal transmission security values. In this case, the security value of each node in the transmission security value is directly used. and node security threshold Determine whether to perform data transmission: like If a node with insufficient security is detected in the link, data transmission will not proceed.

[0044] like If the data transmission link is deemed secure, data transmission can proceed.

[0045] More specifically, the step of determining whether to perform data transmission based on the transmission security value, the security value of each node, the node security value threshold, historical normal transmission security values, and a preset proportion threshold includes: If the security value of each node in the transmission security value is greater than or equal to the node security value threshold, then determine whether the ratio of the standard deviation to the mean of the historical normal transmission security values ​​is greater than a preset ratio threshold. If the ratio is greater than the preset ratio threshold, no data transmission will be performed; If the ratio is not greater than the preset ratio threshold, then it is determined whether to perform data transmission based on the transmission security value, the node security value threshold, and the ratio.

[0046] For example, if there are nodes on the link If this is the case, then it is determined that there are nodes with insufficient security in the link, and data transmission will not proceed. If all nodes... All are greater than or equal to If Greater than the preset ratio threshold, or, although Not greater than the preset ratio threshold, but If the link security is insufficient, data transmission will be temporarily suspended, and relevant personnel will be alerted. If the relevant personnel confirm the transmission, the transmission process will continue; if the relevant personnel do not confirm the transmission, or confirm that they will not transmit, the data transmission will proceed.

[0047] The preset ratio threshold is also an empirical value used to characterize the normal fluctuation range of the data. For example, the preset ratio threshold is 0.3 or 0.15. The standard deviation of the security values ​​of each transmission involved in the normal transmission of the original data is the result of the original data transmission. The result of the original data transmission is the average of the security values ​​of all transmissions involved in normal transmission.

[0048] Specifically, step S2 includes: S21, send the hash value of the transmission security value and the determined time value for data transmission to the destination node, so that the destination node receives the hash value and returns the receiving time value; S22, Generate an encryption key for the current data transmission based on the hash value, the determined time value, and the received time value; S23, encrypt the original data according to the encryption key, and transmit the encrypted data to the destination node through the data transmission link, so that the destination node can decrypt the received encrypted data to obtain the original data.

[0049] For example, SDC will transmit the hash of the security value. It is sent to the destination node, along with a time value confirming the data transmission. The destination node receives the hash value. Then, the time value will be received. Feedback is sent to SDC. SDC determines that the encryption key is the default encryption key. The original data is encrypted using the encryption key, and the encrypted data is transmitted to the destination node via the data transmission link. Upon receiving the encrypted data, the destination node calculates the decryption key, which is then used as the default encryption key. The data is then decrypted to obtain the original data. The default encryption key is an existing encryption key assigned by the CA. The unit of time difference can be milliseconds.

[0050] The embodiments of the present invention dynamically determine the encryption key for each transmission by transmitting a security value, so that the key is different for each data transmission and is related to the security status of the transmission link at that time. This avoids the security risk of other data transmissions after the key is stolen once, and further improves the security of data transmission.

[0051] This invention discloses a secure data transmission method that determines the transmission security value of a data transmission link based on the security level of the original data, historical transmission data, and the attributes of all nodes in the data transmission link. The method then determines the encryption key for the current data transmission based on this security value. This approach ensures that the encryption key for each data transmission is unique and correlated with the current security status of the data transmission link. This prevents the risk of subsequent data being decrypted and stolen if a key is stolen once, thus improving data transmission security.

[0052] Please see Figure 4 , Figure 4 This is a schematic diagram of the structure of a data security transmission device 10 provided in an embodiment of the present invention. The data security transmission device 10 includes: The transmission security determination module 11 is used to determine the transmission security value of the data transmission link based on the security level of the original data, historical transmission status, and the attributes of all nodes in the data transmission link. The encryption key determination module 12 is used to determine the encryption key for the current data transmission based on the transmission security value in order to transmit the data.

[0053] Furthermore, the data security transmission device 10 also includes: The data transmission determination module is used to determine whether to transmit data based on the transmission security value.

[0054] The data security transmission device 10 provided in this embodiment of the invention can realize all the processes of the data security transmission method of the above embodiments. The functions and technical effects of each module in the device are the same as the functions and technical effects of the data security transmission method of the above embodiments, and will not be repeated here.

[0055] See Figure 5 , Figure 5 This is a schematic diagram of the structure of a data security transmission device 20 provided in an embodiment of the present invention. The data security transmission device 20 of this embodiment includes: a processor 21, a memory 22, and a computer program stored in the memory 22 and executable on the processor 21. When the processor 21 executes the computer program, it implements the steps in the above-described data security transmission method embodiment. Alternatively, when the processor 21 executes the computer program, it implements the functions of each module in the above-described data security transmission device embodiment.

[0056] For example, the computer program may be divided into one or more modules, which are stored in the memory 22 and executed by the processor 21 to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the data security transmission device 20.

[0057] The data security transmission device 20 can be a desktop computer, laptop, handheld computer, or cloud server, etc. The data security transmission device 20 may include, but is not limited to, a processor 21 and a memory 22. Those skilled in the art will understand that the schematic diagram is merely an example of the data security transmission device 20 and does not constitute a limitation on the data security transmission device 20. It may include more or fewer components than shown, or combine certain components, or different components. For example, the data security transmission device 20 may also include input / output devices, network access devices, buses, etc.

[0058] The processor 21 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor. The processor 21 is the control center of the data security transmission device 20, connecting all parts of the data security transmission device 20 via various interfaces and lines.

[0059] The memory 22 can be used to store the computer programs and / or modules. The processor 21 implements various functions of the data secure transmission device 20 by running or executing the computer programs and / or modules stored in the memory 22 and calling the data stored in the memory 22. The memory 22 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 22 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital card (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0060] If the modules integrated into the data security transmission device 20 are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by the processor 21, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted from the content as required by the legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium may not include electrical carrier signals and telecommunication signals.

[0061] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0062] This invention also provides a computer-readable storage medium, which includes a stored computer program, wherein the computer program, when running, controls the device where the computer-readable storage medium is located to perform the data secure transmission method as described in the above embodiments.

[0063] Furthermore, embodiments of the present invention also provide a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the data secure transmission method described above.

[0064] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A data secure transmission method, characterized by, The method comprises the following steps: determining a transmission security value of the data transmission link according to a security level of the original data, a history transmission condition and all node attributes in the data transmission link; determining an encryption key for current data transmission according to the transmission security value to perform data transmission.

2. The data secure transmission method of claim 1, wherein, The step of determining the transmission security value of the data transmission link according to the security level of the original data, the history transmission condition and all node attributes in the data transmission link comprises the following steps: obtaining an original data identifier of the original data to be transmitted and all node attributes in the data transmission link; determining the security level of the original data and the history transmission condition according to the original data identifier; determining the transmission security value of the data transmission link according to the security level, the history transmission condition and all node attributes.

3. The data secure transmission method as described in claim 2, characterized in that, The step of determining the transmission security value of the data transmission link according to the security level, the history transmission condition and all node attributes comprises the following steps: determining a security value of each node in the data transmission link according to the security level, the history transmission condition and all node attributes; determining the transmission security value of the data transmission link according to the security value of each node.

4. The method of claim 3, wherein the data is transmitted in a form of a plurality of data packets. If the node attributes comprise a security attribute, a behavior attribute and a permission attribute of the node, the step of determining the security value of each node in the data transmission link according to the security level, the history transmission condition and all node attributes comprises the following steps: determining a permission attribute value of each node in the data transmission link according to the security level and the history transmission condition; obtaining a security attribute value, a behavior attribute value and a corresponding attribute weight of each node, and a permission attribute weight of each node; determining the security value of each node in the data transmission link according to the security attribute value, the behavior attribute value, the permission attribute value and the corresponding attribute weight of each node.

5. The data secure transmission method as described in claim 4, characterized in that, The step of determining the permission attribute value of each node in the data transmission link according to the security level and the history transmission condition comprises the following steps: determining a probability of each node obtaining the original data according to the security level; determining a transmission minimum security level of the original data according to the history transmission condition; calculating the permission attribute value of each node in the data transmission link according to the probability, the transmission minimum security level and the permission attribute of each node.

6. The method of claim 4, wherein the data is transmitted in a form of a plurality of data packets. The step of obtaining the security attribute value, the behavior attribute value and the corresponding attribute weight of each node, and the permission attribute weight of each node comprises the following steps: calculating the security attribute value and the security attribute weight of each node according to a vulnerability condition, an attack condition and a basic security value of each node; calculating the behavior attribute value and the behavior attribute weight of each node according to a resource utilization rate, an access condition and an abnormal event occurrence condition of each node; calculating the permission attribute weight of each node according to a permission attribute and a maximum permission attribute value of each node.

7. The method of claim 1, wherein the data is transmitted in a plurality of packets. After determining the transmission security value of the data transmission link, the method further comprises the following steps: judging whether to perform data transmission according to the transmission security value; and the step of determining the encryption key for current data transmission according to the transmission security value to perform data transmission is: If data transmission is performed, an encryption key for current data transmission is determined according to the transmission security value to perform data transmission.

8. The data secure transmission method as described in claim 7, characterized in that, The manner of determining whether to perform data transmission according to the transmission security value comprises one of the following manners: whether to perform data transmission according to the security value of each node in the transmission security value and a node security value threshold; whether to perform data transmission according to the transmission security value, the security value of each node, the node security value threshold, a historical normal transmission security value and a preset proportion threshold.

9. The data secure transmission method as described in claim 8, characterized in that, The manner of determining whether to perform data transmission according to the transmission security value, the security value of each node, the node security value threshold, a historical normal transmission security value and a preset proportion threshold comprises: if the security value of each node in the transmission security value is greater than or equal to the node security value threshold, whether a ratio of a standard deviation to a mean value of the historical normal transmission security value is greater than a preset proportion threshold; if the ratio is greater than the preset proportion threshold, data transmission is not performed; if the ratio is not greater than the preset proportion threshold, whether to perform data transmission is determined according to the transmission security value, the node security value threshold and the ratio.

10. The data secure transmission method as described in claim 1, characterized in that, The manner of determining an encryption key for current data transmission according to the transmission security value to perform data transmission comprises: sending a hash value of the transmission security value and a determination time value of determining to perform data transmission to a destination node, so that the destination node returns a receiving time value when the hash value is received; generating an encryption key for current data transmission according to the hash value, the determination time value and the receiving time value; encrypting the original data according to the encryption key, and transmitting encrypted data to the destination node through the data transmission link, so that the destination node decrypts the received encrypted data to obtain the original data.

11. A data secure transmission apparatus, characterized by, The data security transmission method comprises: a transmission security determination module configured to determine a transmission security value of a data transmission link according to a security level of original data, historical transmission conditions and attributes of all nodes in the data transmission link; an encryption key determination module configured to determine an encryption key for current data transmission according to the transmission security value to perform data transmission.

12. A data secure transmission device, characterized by, The computer program is stored in the memory and configured to be executed by the processor, and the processor implements the data security transmission method in any one of claims 1-10 when executing the computer program.

13. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises a stored computer program, wherein the computer readable storage medium controls a device where the computer readable storage medium is located to execute the data security transmission method in any one of claims 1-10 when the computer program runs.

14. A computer program product, characterised in that, The computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the data security transmission method in any one of claims 1-10.