Data transmission control method and system, first end, equipment and readable storage medium
Patent Information
- Application Number
- CN202480044087.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-30
- Filing Date
- 2024-06-30
- Publication Date
- 2026-02-13
AI Technical Summary
The existing TCP/IP protocol lacks security management in data transmission, making it difficult to prevent data leaks and malicious attacks, and the physically isolated one-way transmission control method is complex and costly.
The target header information is generated based on the transaction information of the transmission transaction, the data is transmitted in a structured manner, and the target end address is hidden using the preset string, and the control device controls the data transmission capability based on the communication protocol.
It realizes the security management of data transmission, reduces the risk of malicious attacks, simplifies data transmission control, has low cost, and is suitable for flexibly configuring the data transmission direction.
Smart Images

Figure CN121532987A_ABST
Abstract
Description
Data transmission control method, system, first terminal, device and readable storage medium
[0001] Cross-references
[0002] This application cites the Chinese patent applications in the table below, which are incorporated herein by reference in their entirety. Technical Field
[0003] The present application relates to the field of computers, and in particular to a data transmission method, a data transmission control method, a system, a first end, an intermediate network device, a control device, and a computer-readable storage medium. Background Art
[0004] With the advancement of communication technology, transmitting data and information over the Internet has become an essential means of communication. Currently, data transmission between different endpoints on a network, such as clients and servers, is often implemented using TCP / IP (Transmission Control Protocol / Internet Protocol), also known as the network communication protocol. However, due to its lack of consideration for transmission security during its design, TCP / IP is unable to manage the security of transmitted data. Furthermore, its open, bidirectional nature makes networked devices vulnerable to malicious attacks and data leaks.
[0005] Summary of the Invention
[0006] In view of the above problems, embodiments of the present application provide a data transmission method, a data transmission control method, a system, a first end, an intermediate network device, a control device and a computer-readable storage medium that can at least partially improve or solve existing problems.
[0007] In one embodiment of the present application, a data transmission method is provided. The method is applicable to a first control module in a first application on a first end, and the method includes:
[0008] Determining first transaction information of a first transmission transaction corresponding to a first data flow of the first application;
[0009] When a first data block of the first data stream needs to be transmitted to a second end, determining corresponding first target header information for the first data block based on the first transaction information;
[0010] generating a first message to be sent according to the first data block and the first target header information;
[0011] Sending the first message to the second end;
[0012] The first target header information is used to verify whether the first message meets the requirements.
[0013] In another embodiment of the present application, a data transmission method is further provided. The method is applicable to a second control module outside a first application on a first end. The method includes:
[0014] In response to a first data block to be transmitted to the second end and sent by the first application, determining first transaction information of a first transmission transaction to which the first data block belongs;
[0015] determining corresponding first target header information for the first data block based on the first transaction information;
[0016] generating a first message to be sent according to the first data block and the first target header information;
[0017] Sending the first message to the second end;
[0018] The first target header information is used to verify whether the first message meets the requirements.
[0019] In yet another embodiment of the present application, a data transmission method is provided. The method is applicable to a fourth control module on an intermediate network device, and the method includes:
[0020] In response to a first data block to be transmitted to a second end and sent by the first end, determining first transaction information of a first transmission transaction to which the first data block belongs;
[0021] determining corresponding first target header information for the first data block based on the first transaction information;
[0022] generating a first message to be sent according to the first data block and the first target header information;
[0023] Sending the first message to the second end;
[0024] The first target header information is used to verify whether the first message meets the requirements.
[0025] In yet another embodiment of the present application, a data transmission method is further provided. The method is applicable to a control device connected to the first end, and the method includes:
[0026] In response to a first data block sent by the first end and to be transmitted to the second end, obtaining a first preset character string corresponding to the second end; wherein the first preset character string is used to hide address information of the second end;
[0027] acquiring address information of the second end according to the first preset character string;
[0028] The first data block is sent to the second end according to the address information of the second end.
[0029] In one embodiment of the present application, a data transmission system is further provided, the system comprising:
[0030] A first end, having a first control module within a first application, the first control module being configured to determine first transaction information of a first transmission transaction corresponding to a first data stream of the first application; when a first data block of the first data stream needs to be transmitted to a second end, determining corresponding first destination header information for the first data block based on the first transaction information; generating a first message to be sent based on the first data block and the first destination header information; and sending the first message to the second end, wherein the first destination header information is used to verify whether the first message meets requirements;
[0031] The second end is provided with a third control module, which is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, obtain and cache the first data from the first message.
[0032] In another embodiment of the present application, a data transmission system is provided, comprising:
[0033] A first end has a second control module externally provided on the first application, the second control module being configured to determine, in response to a first data block sent by the first application to be transmitted to the second end, first transaction information of a first transmission transaction to which the first data block belongs; determine corresponding first target header information for the first data block based on the first transaction information; generate a first message to be sent based on the first data block and the first target header information; and send the first message to the second end; wherein the first target header information is used to verify whether the first message meets requirements.
[0034] The second end is provided with a third control module, and the third control module is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, obtain the first data from the first message.
[0035] In another embodiment of the present application, a data transmission system is provided, comprising:
[0036] The first end is used to send a first data block to be transmitted to the second end to the intermediate network device;
[0037] An intermediate network device is provided with a fourth control module, which is used to receive the first data block and determine the first transaction information of the first transmission transaction to which the first data block belongs; based on the first transaction information, determine the corresponding first target header information for the first data block; generate a first message to be sent according to the first data block and the first target header information; and send the first message to the second end; wherein the first target header information is used to verify whether the first message meets the requirements.
[0038] The second end is provided with a third control module, which is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, obtain the first data from the first message.
[0039] In another embodiment of the present application, a data transmission system is provided, comprising:
[0040] The first end is configured to determine first transaction information of a first transmission transaction corresponding to a first data stream; when transmitting a first data block of the first data stream to the second end, determine corresponding first destination header information for the first data block based on the first transaction information; generate a first message to be sent based on the first data block and the first destination header information; and send the first message to the second end; wherein the first destination header information is used to verify whether the first message is required;
[0041] The second end is used to verify the target header information contained in the received first message to determine whether the first message meets the requirements; if it meets the requirements, obtain and cache the first data block from the first message.
[0042] In another embodiment of the present application, a data transmission system is provided, comprising:
[0043] The first end is configured to send the first data block of the first data stream to the first control device when the first data block needs to be transmitted to the second end;
[0044] The first control device is configured to determine first transaction information of a first transmission transaction corresponding to the first data flow; determine corresponding first target header information for the received first data block based on the first transaction information; generate a first message to be sent based on the first data block and the first target header information; and send the first message to the second end; wherein the first target header information is used to verify whether the first message requires
[0045] The second end is used to verify the first target header information included in the received first message to determine whether the first message meets the requirements; if it meets the requirements, obtain and cache the first data block from the first message.
[0046] In another embodiment of the present application, a data transmission system is provided, comprising:
[0047] The first end is configured to send the first data block of the first data stream to the first control device when the first data block needs to be transmitted to the second end;
[0048] a first control device, communicatively connected to the first end, configured to determine first transaction information of a first transmission transaction corresponding to the first data stream; determine corresponding first destination header information for the received first data block based on the first transaction information; generate a first message to be sent based on the first data block and the first destination header information; and send the first message to the second control device; wherein the first destination header information is used to verify whether the first message is required;
[0049] a second control device, communicatively connected to the first control device and the second end, configured to verify the first target header information included in the received first message to determine whether the first message meets requirements; and if so, cache the first message locally for waiting for acquisition by the second end;
[0050] The second end is configured to send an acquisition request to the second control device; and receive the first message fed back by the second control device in response to the acquisition request.
[0051] In another embodiment of the present application, a data transmission system is provided, comprising:
[0052] Second end;
[0053] The first end is configured to send a first data block to be transmitted to the second end to a first control device;
[0054] A first control device is configured to obtain, in response to the first data block sent by the first end, a first preset character string corresponding to the second end; wherein the first preset character string is used to hide address information of the second end; obtain the address information of the second end based on the first preset character string; and send the first data block to the second end based on the address information of the second end.
[0055] In another embodiment of the present application, a data transmission system is provided, comprising:
[0056] Target device;
[0057] The first end is configured to obtain a first preset character string corresponding to the second end when transmitting a first data block to the second end; generate a first message to be sent based on the first preset character string and the first data block; and send the first message to the first control device; wherein the first preset character string is used to hide the address information of the target device;
[0058] a first control device, configured to determine address information of the target device according to the first preset character string obtained from the first message; and send the first message to the target device according to the address information of the target device;
[0059] In another embodiment of the present application, a data transmission system is provided, comprising:
[0060] The first end is configured to, when transmitting a first data block to a second end, obtain a first preset character string corresponding to the second end; generate a first message to be sent based on the first preset character string and the first data block; and send the first message to the first control device; wherein the first preset character string is used to hide address information of the second end;
[0061] a first control device, configured to determine the address information of the second end according to the first preset character string obtained from the first message; and send the first message to the second control device according to the address information of the second end;
[0062] a second control device, configured to buffer the received first message to wait for the second end to obtain it;
[0063] The second end is configured to send an acquisition request to the second control device; and receive the first message fed back by the second control device in response to the acquisition request.
[0064] In another embodiment of the present application, a data transmission system is provided, comprising:
[0065] The first end is configured to obtain a first preset character string corresponding to the second end and a second preset character string corresponding to the first end when transmitting a first data block to the second end; and send the first preset character string, the second preset character string, and the first data block to a first control device; wherein the preset character strings are used to hide address information of the corresponding end;
[0066] The first control device is configured to determine first transaction information of a first transmission transaction corresponding to a first data stream to which the first data block belongs; determine corresponding first target header information for the first data block based on the first transaction information; generate a first message to be sent based on the first target header information and the first data block; and send the first message to the second end based on the address information of the second end obtained from the first preset character string.
[0067] The second end is used to verify the received first message; after the verification is passed, obtain and cache the first data block from the first message.
[0068] In one embodiment of the present application, a first end is further provided, the first end comprising:
[0069] a first application installed on the first terminal;
[0070] The first control module is located in the first application and is used to implement the data transmission method provided in the first embodiment of the present application.
[0071] In another embodiment of the present application, a first end is further provided, the first end comprising:
[0072] a first application installed on the first terminal;
[0073] The second control module is located outside the first application and is used to implement the data transmission method provided in the second embodiment of the present application.
[0074] In one embodiment of the present application, an intermediate network device is further provided. The intermediate network device includes: four control modules and a memory, wherein:
[0075] The memory is used to store one or more computer programs;
[0076] The fourth control module is used to execute the one or more computer programs to implement the data transmission method provided in the third embodiment of the present application.
[0077] In one embodiment of the present application, a control device is further provided, the control device comprising: a processor and a memory, wherein:
[0078] The memory is used to store one or more computer instructions;
[0079] The processor, coupled to the memory, is configured to execute the one or more computer instructions to implement the data transmission method provided in the fourth embodiment of the present application.
[0080] In yet another embodiment of the present application, a data transmission method is provided. The method is applicable to a control device connected to a first end, and the method includes:
[0081] receiving a first data block in a first data stream to be transmitted to a second end, sent by the first end;
[0082] Determining first transaction information of a first transmission transaction corresponding to the first data flow;
[0083] determining corresponding first target header information for the first data block based on the first transaction information;
[0084] generating a first message to be sent according to the first data block and the first target header information;
[0085] Sending the first message to the second end;
[0086] The first target header information is used to verify whether the first message is required.
[0087] In yet another embodiment of the present application, a data transmission method is provided. The method is applicable to a first end and includes:
[0088] When the first data block needs to be transmitted to the second end, obtaining a first preset identifier corresponding to the second end; wherein the first preset identifier is used to hide the address information of the second end;
[0089] generating a first message to be sent based on the first preset identifier and the first data block;
[0090] The first message is sent to the second end through a control device.
[0091] In another embodiment of the present application, a data transmission control method is provided, which is applicable to a control device that is communicatively connected to a first end based on a first communication protocol, wherein some of the multiple communication nodes included in the first communication protocol are unidirectional communication nodes; the method includes:
[0092] In response to a communication node configuration operation on a control device triggered for the first end, determining first configuration information; wherein the communication node included in the first configuration information is a communication node in the first communication protocol;
[0093] During data transmission in a non-handshake connection with the first end, at least one first communication node is initiated for the first end according to the first configuration information; the first communication node is a communication node in the communication protocol with the first end, and is used for data interaction with the first end during the non-handshake connection; the node type to which the first communication node belongs can reflect the data transmission function enabled by the first communication node for the first end;
[0094] According to the node type to which each of the first communication nodes belongs, the data transmission capability that the first end can perform through each of the first communication nodes is controlled.
[0095] In another embodiment of the present application, a data transmission control method is provided, which is suitable for a control device that is communicatively connected to a first end based on a first communication protocol; the method includes:
[0096] When it is determined that the preset communication node activation condition is met, activating a first communication node adapted in the first communication protocol for the first end;
[0097] The data transmission capability of the first end is controlled by starting the first communication node.
[0098] In another embodiment of the present application, a data transmission control system is provided, the system comprising:
[0099] First end;
[0100] A first control device is communicatively connected to a first end based on a first communication protocol, wherein some of the multiple communication nodes included in the first communication protocol are unidirectional communication nodes; the first control device is configured to determine first configuration information in response to a communication node configuration operation on the control device triggered for the first end; wherein the communication nodes included in the first configuration information are communication nodes in the first communication protocol; during a non-handshake data transmission process with the first end, at least one first communication node is started for the first end according to the first configuration information; the node type to which the first communication node belongs can reflect the data transmission function enabled by the first communication node to the first end; and according to the node type to which each of the first communication nodes belongs, the data transmission capability of the first end through each of the first communication nodes is controlled.
[0101] In another embodiment of the present application, a data transmission control system is provided, the system comprising:
[0102] First end;
[0103] A first control device is communicatively connected to a first end based on a first communication protocol, wherein some of the multiple communication nodes included in the first communication protocol are unidirectional communication nodes; the first control device is configured to determine first configuration information in response to a communication node configuration operation on the control device triggered for the first end; wherein the communication nodes included in the first configuration information are communication nodes in the first communication protocol; during a non-handshake connection data transmission process with the first end, at least one first communication node is started for the first end according to the first configuration information; the node type to which the first communication node belongs can reflect the data transmission function enabled by the first communication node to the first end; and according to the node type to which each of the first communication nodes belongs, the data transmission capability that the first end can perform through each of the first communication nodes is controlled;
[0104] a second control device, communicatively connected to the first control device and the second end, configured to verify the data sent by the first control device upon receipt; and send the data to the second end after passing the verification;
[0105] The second end is used to receive the data sent by the second control device.
[0106] In another embodiment of the present application, a control device is also provided, which includes: a processor and a memory, wherein the memory is used to store one or more computer instructions; the processor is coupled to the memory and is used to execute the one or more computer instructions to implement the steps in the data transmission control method provided in the above-mentioned embodiment of the present application.
[0107] In another embodiment of the present application, a computer-readable storage medium is provided, which includes: a computer program or instructions. When the computer program or instructions are executed by a processor, the steps in the data transmission control method provided in the above embodiment of the present application can be implemented.
[0108] From all the embodiments provided in this application, it can be seen that:
[0109] In a technical solution provided by an embodiment of the present application, when a first end needs to transmit a first data block in a first data stream of an application to a second end, first destination header information corresponding to the first data block is determined based on first transaction information corresponding to a first transmission transaction of the first data stream. Furthermore, a corresponding first message to be sent is generated based on the first data block and the destination header information, and the first message is sent to the second end. In the above, the first destination header information is used to verify whether the message meets the requirements, which enables this solution to achieve security management of the transmitted data content at a relatively low cost.
[0110] In another technical solution provided by an embodiment of the present application, a control device connected to a first end responds to a first data block sent by the first end to be transmitted to a second end, obtains a first preset string corresponding to the second end (used to hide the address information of the second end), and then obtains the address information of the second end according to the first preset string, and sends the first data block to the second end according to the address information of the second end. Alternatively, when the first end needs to transmit a first data block to the second end, it can generate a first message to be sent according to the obtained first preset identifier corresponding to the second end (used to hide the address information of the second end) and the first data block, and then send the first message to the second end through the corresponding control device. This solution uses a preset string (or preset identifier) to hide the address information of the corresponding end, so that the data initiator cannot know the address of the target end, thereby protecting the address information of the target end; and even if the initiator is maliciously controlled, it cannot scan or detect other devices on the network, thereby effectively avoiding malicious attacks.
[0111] In another technical solution provided by an embodiment of the present application, a control device is connected to a first end in communication based on a first communication protocol, and some of the multiple communication nodes included in the first communication protocol are unidirectional communication nodes. The control device connected to the first end in communication will first respond to a communication node configuration operation on the control device triggered for the first end and determine first configuration information. The communication nodes included in the first configuration information are communication nodes in the first communication protocol. Thereafter, based on the first configuration information, at least one first communication node will be started for the first end. The node type of the first communication node can reflect the data transmission function enabled by the first communication node to the first end. Furthermore, based on the node type of each first communication node, the data transmission capability of the first end through each first communication node can be controlled. This solution is based on the constraints of the communication protocol and realizes the startup control of the communication node for the first end through software control, thereby realizing the control of the data transmission capacity of the first end with the help of the communication node. For example, the first end can be controlled to transmit uplink data unilaterally, or downlink data unilaterally, or uplink data and downlink data. It is simple to construct and has low implementation cost, and is conducive to flexible configuration of the uplink and downlink data transmission capabilities of the first end according to different application service requirements on the first end, without the need for optical gates in existing solutions, etc., which require further deployment of corresponding physical interfaces to realize on-demand transmission control. BRIEF DESCRIPTION OF THE DRAWINGS
[0112] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0113] FIG1 is a schematic diagram showing a principle of existing data transmission between different terminals provided by an embodiment of the present application;
[0114] FIG2a is a schematic diagram showing a principle of a transmission transaction according to an embodiment of the present application;
[0115] FIG2b is a schematic diagram of a transmission method principle corresponding to FIG2a provided in an embodiment of the present application;
[0116] Figures 3a-1 to 3d are schematic structural diagrams of a data transmission system provided in one embodiment of the present application;
[0117] 4a to 4e are schematic structural diagrams of a data transmission system provided in another embodiment of the present application;
[0118] 5a to 5e are schematic structural diagrams of a data transmission system provided in another embodiment of the present application;
[0119] 6a and 6b are examples of device drivers and API interfaces of corresponding control devices deployed on the first end and the second end, respectively, according to an embodiment of the present application;
[0120] FIG6 c is an example of a control device provided in an embodiment of the present application being connectable to multiple other control devices;
[0121] 7a to 7c are schematic diagrams of specific forms of the control device provided in an embodiment of the present application;
[0122] FIG8 is a schematic diagram illustrating a flow chart of a principle for configuring the upper eight bits of a field value of a transaction attribute type field in transmission transaction attribute information according to an embodiment of the present application;
[0123] FIG9 is a schematic diagram of configuration information included in a configuration file provided in an embodiment of the present application;
[0124] FIG10 is a schematic diagram showing the principle of establishing a communication connection between a control device and a corresponding terminal according to an embodiment of the present application;
[0125] 11a to 13 are flowcharts of a data transmission method according to an embodiment of the present application;
[0126] FIG14 is a schematic structural diagram of a data transmission system provided in another embodiment of the present application;
[0127] Figures 15a to 15c are schematic diagrams of the data transmission exchange principle provided by an embodiment of the present application;
[0128] FIG16 is a schematic diagram illustrating the principle of transmitting data to be transmitted based on transmission transaction attribute information (which may be referred to as structured data transmission) according to an embodiment of the present application;
[0129] FIG17 is an application example of structured data transmission provided by an embodiment of the present application;
[0130] FIG18a is a schematic structural diagram of a control device provided in an embodiment of the present application;
[0131] FIG18b is a schematic structural diagram of a data terminal connected to a control device according to an embodiment of the present application;
[0132] 19a and 19b are flowcharts of a data transmission control method according to an embodiment of the present application;
[0133] Figures 20 to 22 are schematic diagrams of the data transmission control principle provided by embodiments of the present application;
[0134] Figures 23a to 23d and Figure 24 are schematic diagrams of the structure of a data transmission control system provided in an embodiment of the present application;
[0135] FIG25a is a schematic diagram of a first end communicating with a second end via a network card communication device provided by the present application;
[0136] FIG25 b is a schematic diagram of a first end communicating with multiple different second ends through a control device provided by the present application;
[0137] Figures 26 and 27 are schematic diagrams of the structure of a data transmission device provided in an embodiment of the present application;
[0138] FIG28 is a schematic structural diagram of a data transmission control device provided in one embodiment of the present application;
[0139] FIG29 is a schematic structural diagram of a control device provided in another embodiment of the present application;
[0140] FIG30 is a schematic diagram of the data transmission control principle provided for another embodiment of the present application. DETAILED DESCRIPTION
[0141] Currently, when different terminals transmit data information over a network, they mostly use the TCP / IP protocol and rely on network devices (such as switches and routers) deployed between the terminals. For example, referring to Figure 1, the process of using the TCP / IP protocol to transmit data between a first terminal and a second terminal is as follows: Taking the first terminal as a client and the second terminal as a server, and the client requesting data resources on the server as an example, the client enters the domain name www.####.com of the website deployed on the server, and sends a request for the domain name www.####.com to the DNS (Domain Name System, domain name resolution server) (not shown in the figure). The DNS resolves the domain name www.####.com into the IP address of the server (the target IP address) and feeds it back to the client. The client generates a request message based on its own IP address (the source IP address), the target IP address, and the request parameters (i.e., a specific data block to be transmitted). Since the request message needs to be sent to another subnet (the target subnet) where the server is located in order to be sent to the server, the request message is often sent to the switch first, and the switch then sends its own MAC (Medium / Media Access) address to the server. Control) address and the MAC address of the corresponding gateway are written into the request data packet, and after the writing is completed, the request message will be further sent to the gateway (a special router) according to the MAC address of the gateway, and then through the routing algorithm, the request message will be continuously forwarded by the router and finally sent to the target subnet to reach the server. As can be seen from the above example, the existing TCP / IP protocol is directly used for data transmission between different ends. It is simply based on some common information required for data transmission, such as source IP address, target IP address, source MAC address, target MCA address, etc., to combine the data to be transmitted and generate a corresponding message to achieve data transmission. The security of data transmission is not considered. The specific content contained in the message can be found in the specific content contained in the message A shown in Figure 1. In summary, from the perspective of network communication protocol, the above-mentioned solution of directly using the TCP / IP protocol to transmit data between different ends will have the following problems due to the lack of security considerations in the design of the TCP / IP protocol:
[0142] 1. Unable to securely manage the content of transmitted data
[0143] The TCP / IP protocol is a suite of protocols used to transmit data across multiple networks. It typically only handles data transmission, not the results of the data transmission, and cannot identify the content or type of the transmitted data. This allows malicious applications to launch network attack traffic, making data security unsafe. For example, referring to Figure 1, a client and server using the TCP / IP protocol communicate directly. If one of the client and server sends malicious command data, the other will automatically receive and execute (or process) the command data.
[0144] 2. Unable to block malicious attacks and difficult to manage network services
[0145] Because the TCP / IP protocol is open, different devices within the same network can access each other. This allows malicious attackers (hackers) to control a device within the network and use it as a springboard to launch scans, attacks, and other malicious activities against other devices within the network. Furthermore, as long as a device within the network has a network service port enabled, it can be accessed by other devices within the network, making network services difficult to manage. For example, referring to Figure 1 again, if a server has a network service port enabled, the server can be accessed by clients, potentially allowing unauthorized setup of services such as FTP (File Transfer Protocol) and file sharing. Alternatively, an open server could be accessed and attacked by malicious clients, or a malicious server could attack or access clients.
[0146] 3. The driver of TCP / IP protocol is universal, which can easily lead to the device being controlled
[0147] TCP / IP protocol drivers are typically the network communication universal public interface (network access API) programs of computer operating systems. These universal public interface programs are generally unrestricted and can be called by any program (such as a computer's network interface), making it easy for network devices to be controlled. For example, if a computer device on a network is controlled by malware such as a Trojan horse or virus, it can directly communicate using the device's network interface, leading to control of the device and potentially launching malicious attacks against other devices on the network.
[0148] 4. There is a risk of data leakage
[0149] Because the TCP / IP protocol is bidirectional, both ends of a direct TCP / IP connection can send and receive data. Therefore, even devices that only need to receive data can send data, which can lead to data leakage risks. For example, referring to Figure 1, a client and server communicating directly using the TCP / IP protocol can both receive and send data. If the server only needs to receive data, then when the client accesses the server to obtain data on the server, the server can respond to the client's access and send the corresponding data to the client. Consequently, if the server is controlled by a malicious program, data leakage on the server can occur.
[0150] To solve or partially solve the problems mentioned above when different ends directly use TCP / IP protocol for data transmission, there are currently several solutions:
[0151] The first is through communication hardware protection solutions, specifically deploying a network security firewall within the network. Existing network security firewalls are primarily categorized into two types: access control firewalls and content security firewalls. Access control firewalls control whether different devices within the network can communicate by setting policies such as blacklists and whitelists (e.g., source IP addresses and source ports, destination IP addresses (also known as sink IP addresses) and destination ports). However, in large networks, maintaining technicians using these access control firewalls face difficulties in fully implementing access control. Oversights can inevitably lead to loopholes in policy settings, making it easy for malicious actors to illegally access network devices. Content security firewalls utilize databases of malicious programs like Trojans and viruses, threat IP databases, and suspicious behavior databases to detect and block malicious communication content (e.g., source IP addresses and source ports, destination IP addresses (also known as sink IP addresses) and destination ports, and communication data content). Problems with these content security firewalls include: since sample libraries of malicious programs and threat IP addresses are often the result of analyzing existing attack behaviors, this leads to delayed detection and the need for updates. This allows malicious actors to exploit the time difference between updates and launch attacks. Furthermore, they are unable to detect unknown malicious behaviors. Furthermore, since firewalls are generally sold or downloaded publicly, malicious actors can analyze the firewall's sample libraries and modify the malicious program's program features and data traffic characteristics to bypass the firewall ("rabbit-killing" techniques) and launch attacks. Furthermore, the transmission protocols between applications in network systems are proprietary and agreed upon by the developers. Due to the large number of developers and the complex and ever-changing network systems, firewalls struggle to perform protocol analysis on a case-by-case basis, making it nearly impossible to effectively parse, audit, or intercept communication content.
[0152] The second method is to implement a security protection solution for the device. Specifically, security protection software can be installed on the device. For example, referring to Figure 1, the security of the server or client can be ensured by installing antivirus software on the server or client, deploying a security control management system, or configuring a domain control system. The problems with the aforementioned antivirus software approach are similar to those of content security firewalls. They can only detect and eliminate existing viruses or malicious behaviors, and malicious actors can also bypass antivirus software to launch attacks by modifying the program features and data traffic characteristics of malicious programs. Deploying a security control management system or configuring a domain control system transfers the operating permissions of ordinary devices within the network to the master control device to implement access control, resource access control, or the distribution of software update packages for ordinary devices. However, if the master control device is attacked and controlled by a malicious actor, all ordinary devices are at risk of being completely controlled by the malicious actor.
[0153] The third type is a device that satisfies the need for unidirectional data transmission within the network through a physical isolation control method. For example, in some data transmission application scenarios with high network security requirements, unidirectional network data transmission is often required. For this scenario, a physical isolation control method is currently often used to control and achieve unidirectional network data transmission. However, this method requires the use of physical unidirectional transmission control devices such as one-way optical gates and optical codes (QR codes). This involves the transformation of the physical layer of communication. In addition, there are the following problems:
[0154] 1) When using one-way transmission control devices such as optical shutters and optical codes (QR codes) to implement one-way data transmission control, since this is achieved through physical isolation, it can only physically control one-way data reception or one-way transmission, and cannot achieve flexible configuration of one-way transmission, one-way reception, or two-way transmission according to different service requirements. For example, one-way optical shutters often have corresponding physical interfaces based on data transmission control requirements to achieve one-way transmission control through physical interfaces. This physical limitation makes it difficult to change the function of one-way optical shutters after leaving the factory, making it difficult to flexibly control the data transmission capacity of the first end based on actual data transmission control requirements.
[0155] 2) The aforementioned one-way transmission control devices are often complex in structure (for example, they require optical modules, optical splitters, or image display or reception modules, etc.), resulting in high manufacturing costs, large size, complex configuration, and limited applicability (small scope of application). They also require multiple servers for coordination and are generally only deployed at the switch access edge of large networks (network-level deployment). For example, if data needs to be transmitted from the intranet and from the extranet, two transmission systems, including an extranet server, a one-way optical switch device, and an intranet switching server, need to be deployed, resulting in high deployment costs. Furthermore, since this is a network-level deployment, adjusting data exchange requirements is complex. Furthermore, since this is a network-level deployment, it only handles data exchange between the intranet and extranet, and does not provide data security control for individual terminal devices within the network. Furthermore, due to factors such as cost and device size, one-way transmission control devices are rarely deployed in single-client or server-side (standalone-machine deployment) scenarios (such as employee office computers, application servers, etc.). This often makes it difficult to effectively control and manage the security of individual terminal data.
[0156] The one-way optical shutter mentioned above is a device that can reliably transmit data information from a low-density network (public network) to a high-density network (intranet / private network) in one direction.
[0157] Based on the above analysis, in order to solve the problems existing in the existing network communication protocol (TCP / IP protocol), network security protection measures, security protection software, etc., each embodiment of the present application provides a new data transmission technology solution. The specific details are as follows:
[0158] One technical solution utilizes target header information determined for the data to be transmitted based on transaction information from the transaction to which the data belongs, structures the data to be transmitted, and then transmits the structured data across the network. This solution ensures that only data that meets specific structuring rules is allowed to be transmitted and exchanged across the network, enabling simple and cost-effective security management of transmitted data content and effectively enhancing data security protection and control capabilities during data transmission.
[0159] Another technical solution is to use a preset string (or preset identifier) to hide the address information of the corresponding end, so that the data initiator cannot know the address of the target end, which can protect the address information of the target end; and even if the initiator is maliciously controlled, it cannot scan or detect other devices on the network, which can effectively avoid malicious attacks.
[0160] Another technical solution is: the control device controls the data transmission capability of a certain end to another target end based on the communication protocol between the certain end and the control device, such as controlling only unidirectional uplink data transmission, only unidirectional downlink data transmission, or bidirectional uplink and downlink data transmission. Compared with the existing control method of using physical isolation to control the unidirectional transmission of data between different ends, the solution provided by this application is used to achieve functions such as unidirectional transmission of data. It is simple to construct and has low implementation cost. It can also flexibly adjust the communication direction (i.e., data transmission direction) between different ends. In other words, it can flexibly configure unidirectional transmission, unidirectional reception, or bidirectional transmission of data according to different service requirements. It can be applied to scenarios with unidirectional data transmission and strong security requirements.
[0161] It should be noted that the division of the above three technical solutions is only for the convenience of reading and understanding, and does not limit the technical solutions. In all the embodiments of this application, based on the concept of the invention of this application, in actual applications, they can be used separately, mixed, combined, or re-split and combined to form different solutions. To avoid redundancy, they are not listed one by one, and this application does not limit them. In addition, the solution of this application achieves low-cost security control and has a wide range of applications. In addition to the TCP / IP protocol, it can also be applied to various data transmission protocols.
[0162] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0163] Before introducing the present application, some of the names involved in this application as a whole are explained:
[0164] "Preset identifier" and "preset string" are both communication identifiers, but different expressions are used for "communication identifier" in different embodiments. It is mainly used to indicate the target address information. According to different embodiments, its specific form can be a string, binary value, etc., and its generation method can be a random value, a specific rule value, or directly the target address information, etc., which is not limited here. Its main function is to hide the target address. When the target address is not hidden, it can also be related information of the target address. For this reason, "preset identifier" and "preset string" are equivalent to each other, and the relevant contents of the two can be referenced to each other. To avoid redundancy, this application generally does not describe the two at the same time. In addition, in some embodiments, based on the "preset identifier", it is also equivalent to the transmission transaction attribute (with the target address information). For example, in some embodiments of the communication protocol scheme between the control device and a certain end, although it is described based on the "preset identifier", it can actually be equivalent to the "transmission transaction attribute". To avoid redundancy, "preset identifier" is used as an alternative explanation.
[0165] Before introducing the method embodiments provided in this application, the system architecture on which the technical solution provided in this application can be based is first described.
[0166] Specifically, the method provided in the embodiment of the present application can be implemented based on the system architecture shown in Figures 3a-1 to 5e. As shown in Figure 3a-1, the structural diagram of the data transmission system provided in an embodiment of the present application includes: a first end 10 and a second end 20, wherein:
[0167] The first end 10 is configured to determine first transaction information of a first transmission transaction corresponding to a first data stream; when transmitting a first data block of the first data stream to the second end 20, determine corresponding first destination header information for the first data block based on the first transaction information; generate a first message to be sent based on the first data block and the first destination header information; and send the first message to the second end 20; wherein the first destination header information is used to verify whether the first message meets requirements;
[0168] The second end 20 is configured to verify the first target header information included in the received first message to determine whether the first message meets the requirements; if it meets the requirements, obtain and cache the first data block from the first message.
[0169] During specific implementation, the first end 10 and the second end 20 are data ends that need to exchange data, and the types of the two can be the same or different. For example, one of the first end 10 and the second end 20 can be a client and the other can be a server; or, both the first end 10 and the second end 20 can be clients; or, both the first end 10 and the second end 20 can be servers, which is not limited here. Figure 3a-1 schematically shows an example in which the first end 10 is a client and the second end 20 is a server. The client can be any device such as a desktop computer with an operating system (or without an operating system), a smartphone, a laptop, a tablet computer, an industrial control device, an embedded device, a smart wearable device (such as a smart watch), a smart Internet of Things (IoT) device, etc., and the smart IoT device can include but is not limited to: smart home appliances (such as smart speakers, smart refrigerators, etc.), self-driving vehicles, etc. The server can be a physical server, a virtual server, a container server, a cloud service platform, etc., which is not specifically limited in this embodiment.
[0170] As shown in FIG3a-1, in a first feasible technical solution, the TCP / IP protocol is still used between the first end 10 and the second end 20, and a direct communication connection is established through an intermediate network device such as a switch or router. Specifically, the first end 10 and the second end 20 can each communicate with the corresponding intermediate network device using the TCP / IP protocol through its own network interface to achieve communication between the two. The network interface can be, but is not limited to, an Ethernet interface. However, unlike the existing TCP / IP protocol data transmission, which simply generates a corresponding message based on some general information required for data transmission, such as the source IP address, target IP address, source MAC address, target MAC address, and the data block to be transmitted to achieve data transmission (see the content related to FIG1 for details), this embodiment, to ensure data transmission security, when a data block a, such as data block a, needs to be transmitted to the second end 20, the corresponding target header information is determined for the data block a based on the transaction information of the transmission transaction to which the data block a belongs. Then, based on the target header information and the data block a, a corresponding message to be sent is generated to achieve transmission of the data block a. In the above description, the transmission transaction to which data block a belongs refers to the transmission transaction corresponding to the data stream to which data block a belongs. The location of the above-mentioned target header information in the message can be any of the following: between the message header (such as the general message header shown in Figure 3a-1) and the message tail (such as the general message tail shown in Figure 3a-1), at the message header, or at the message tail. The above-mentioned target header information is located between the message header and the message tail. More specifically, the target header information is located in the data area of the message (as shown in Figure 3a-1), or from the perspective of the transmission protocol, the target header information is located in the data area of the transmission protocol. In some scenarios, the message header included in the target header information can be generated based on the corresponding header information transmission method and the relevant information of data block a. For a detailed description of the header information transmission method and the specific implementation of the message header generation contained in the corresponding target header information, please refer to the relevant content described in other embodiments for steps S20 to S22 and in conjunction with Figure 2b, etc., and will not be described in detail here. The embodiment of the present application does not specifically limit the position of data block a in the message. Generally, data block a is located in the data area of the message.
[0171] The message header described above may include a common message header (e.g., an Ethernet header or a TCP / IP protocol header) and, in some embodiments, may also include a custom header; and / or the message trailer described above may include a common message trailer (e.g., an Ethernet trailer) and, in some embodiments, may also include a custom trailer. The custom header and custom trailer may be customized by the user according to actual needs.
[0172] FIG3 a-1 shows an example in which data block a and the corresponding target header information are both located between the message header and the message footer (i.e., both are located in the data area). In the example shown in FIG3 a-1 , the target header information is located near the message header and to the left of data block a. However, in other examples, the target header information may be located near the message footer and to the right of data block a.
[0173] As can be seen from Figure 1, the general message header includes an Ethernet header and a TCP / IP protocol header. The format of the TCP / IP protocol header is shown in Table 0 below:
[0174] Table 0: TCP / IP protocol header format
[0175] The above reserved fields are mainly used for future new functions or extensions and are generally set to 0. When the TCP protocol needs to be extended to add new functions, the reserved setting will not be 0.
[0176] The optional option field is mainly used when the sender and receiver negotiate the maximum message length or when applying a regulation factor in a high-speed network environment. It can also be used to store other data, such as timestamps.
[0177] For a detailed description of the contents other than reserved bits and optional options contained in the TCP / IP protocol header, please refer to the existing relevant content.
[0178] Based on this information, combined with the above description of the contents that can be included in the message header and message trailer, and as shown in Figure 3a-2, we will give a few examples to explain why the target header information can be located in the message header or message trailer. Specifically:
[0179] Example 0A1: By defining certain customizable fields within the TCP / IP protocol header, the destination header information of data block a can be inserted into the message header. For example, a reserved field within the TCP / IP protocol header can be set to non-zero to extend a new functionality, allowing the destination header information of data block a to be inserted at the location of the reserved field. For another example, an optional option field within the TCP / IP protocol header can be defined based on the data length of the destination header information of data block a, allowing the destination header information of data block a to be inserted at the location of the padding data within the optional option. Thus, the destination header information of data block a can be located within the TCP / IP protocol header, thereby achieving its intended location at the beginning of the message.
[0180] Example 0A2: If the message header includes a custom header, and the custom header has a field reserved for inserting the destination header information of data block a, the destination header information of data block a can be inserted into the custom header, thereby achieving the purpose of placing the destination header information of data block a at the beginning of the message. Of course, similarly, data block a can also be inserted into the custom header, thereby achieving the purpose of placing data block a and / or the corresponding destination header information at the beginning of the message.
[0181] Example 0A3: If the message trailer includes a custom trailer, and a field is reserved in the custom trailer for inserting the target header information of data block a, the target header information of data block a can be inserted into the custom trailer, thereby placing the target header information of data block a at the end of the message. Similarly, data block a can also be inserted into the custom header, thereby placing data block a and / or the corresponding target header information at the beginning of the message.
[0182] It should be noted that, similar to the principle of inserting target header information into the message header or tail described in Examples 0A1-0A3 above, data block a can also be inserted into the message header or tail. For example, in Example 0A1, the reserved field and optional option field in the TCP / IP protocol header can be defined simultaneously, with one field for inserting data block a and the other for inserting the target header information corresponding to data block a. This can also achieve the goal of placing data block a at the beginning of the message. For another example: by defining a reserved field or an optional option field in the TCP / IP protocol header, the target header information of data block a can be inserted into the TCP / IP protocol header; and, if the message tail includes a custom tail, and a field for inserting data block a is reserved in the custom tail, then data block a can be inserted into the custom tail, thereby achieving the purpose of having data block a and the corresponding target header information one located at the message head and the other located at the message tail; and if the message tail only contains an Ethernet tail, or also contains a custom tail but no field for inserting data block a is reserved in the custom tail, in this case, data block a is located between the message head and the message tail (that is, located in the data area of the message), achieving the purpose of having data block a and the corresponding target header information one located at the message head and the other located between the message head and the message tail.
[0183] As can be seen from the above examples, as long as there are optional spaces at the beginning and / or end of the message (the spaces may be customized or compatible with relevant protocols (such as reserved fields or optional option fields in the TCP / IP protocol header), data (such as the data block a to be transmitted and / or the corresponding target header information) can be inserted into the corresponding message beginning or end.
[0184] A data stream represents a data sequence that contains one or more data blocks. For example, when a large file, an audio or video stream, or a multimedia stream of unspecified length needs to be transmitted, the file data is often divided into several data blocks and the several data blocks are combined into a data sequence to achieve the transmission of the file, audio or video stream, or multimedia stream of unspecified length in a streaming manner.
[0185] In this embodiment, a transmission transaction is a unidirectional communication transmission behavior, which is used to complete a specific transmission task. Specifically, a transmission transaction can be understood as a set of logically related transmission operations. Each transmission operation is used to transmit a data block to be transmitted. When transmitting a data block to be transmitted, a corresponding message is generated for the data block to be transmitted using the solution provided in this embodiment. The specific structure format of the generated message will be described in detail below. For example, referring to Figure 3a-1, the first end 10 needs to transmit a file data stream (such as the data stream corresponding to the "financial report.xls" file) to the second end 20. The transmission of this file data stream corresponds to a transmission transaction. The execution of a transmission operation in this transmission transaction can only transmit one data block in the file data stream. Furthermore, after completing the reception of the file data stream, the second end 20 returns a response message to the first end 10 indicating the successful receipt of the file data stream, which constitutes another transmission transaction. As can be seen from the above example, transmission transactions also have different ends (such as the client and the server).
[0186] Of course, optionally, in some other embodiments, the transmission transaction may also be a two-way communication transmission behavior, without distinction between client and server, etc., which is not limited here.
[0187] Figure 2a illustrates a schematic diagram of a transmission transaction. The structured header included in the message shown is the target header information for the corresponding data block to be transmitted, as described in the context of this embodiment, but is expressed differently in different description scenarios. Figure 2b illustrates three different transmission modes (a first mode, a second mode, and a third mode) with respect to Figure 2a. These three transmission modes and the content that the structured header may include will be discussed in detail below when describing "target header information."
[0188] When configuring data transmission and exchange between the first end 10 and the second end 20, this embodiment also configures relevant information corresponding to the transmission transaction between the first end 10 and the second end 20, such as the transmission transaction attribute information of the transmission transaction, the correspondence between the transaction type and the transaction attribute identifier (also called the transaction attribute unique identifier), etc. The transmission transaction attribute information of a transmission transaction includes the content shown in Table 1a below. Table 1b below shows an example of the preset transmission transaction attribute information set provided by the application embodiment.
[0189] Table 1a
[0190] Table 1b
[0191] In Table 1a above, the field value types of fields such as the transaction attribute name, transaction label, and verification information in the transmission transaction attribute information are all String (representing a character string, which is a character or character string with an uncertain data length, and the length varies according to actual needs). The field value type of fields such as the preset string (or preset identifier) associated with the transaction and the transaction attribute identifier is 32 bits (representing a binary number with a length of 32 bits). The field value type of fields such as the transaction usage role, transaction attribute type information, and verification information is 16 bits (representing a binary number with a length of 16 bits). Specifically,
[0192] The transaction attribute name field is used to indicate the transaction attribute name of the transmission transaction. For example, referring to Figure 2a, the first end 10 needs to request a network file resource from the second end 20. For this "request network file resource" transmission transaction, the field value of the transaction attribute name field can be configured as "request network file resource"; for another example, the first end 10 needs to upload a jpg file to the second end. For this "upload jpg file" transmission transaction, the field value of the transaction attribute name field can be configured as "upload jpg file", and so on. When executing a data block transmission, the transaction attribute name of the transmission transaction to which the data block belongs can be displayed so that the user can clearly understand the current data transmission through the displayed transaction attribute name.
[0193] It should be noted that when configuring the transaction attribute name for a transmission transaction, the configuration can be performed based on the transmission transaction type so that the transaction attribute name can transparently convey the transaction type of the corresponding transmission transaction. Of course, other configuration methods can also be used, and this embodiment does not limit this.
[0194] The transaction annotation field is used to indicate the remark information of the transmission transaction (or annotation information, i.e., the first annotation information referred to in other embodiments below). For example, continuing the example of the transaction attribute name field above, for a "request network resource" transmission transaction, the field value of the transaction annotation field can be configured as "first end request"; for a "upload jpg file" transmission transaction, the field value of the transaction annotation field can be configured as "second end response", and so on.
[0195] The transaction-associated preset string (also called a communication identifier) field is used to indicate the preset string associated with the transmission transaction. In some embodiments, the preset string is a string corresponding to the address information of the corresponding end (such as a regular string corresponding to an IP address), that is, the preset string does not have the function of hiding the address information of the corresponding end; alternatively, in other embodiments, the preset string has the function of hiding the address information of the corresponding end, for example, the preset string is a randomly generated random string with no regularity, and its associated information includes the address information of the corresponding end. The relevant description of the preset string will be expanded on below.
[0196] The Transaction Attribute Identifier field is used to uniquely identify the transmission transaction attribute information of the transmission transaction (e.g., the unique transaction identifier given in Table 1b above is referred to as the transmission transaction attribute information ID). In this embodiment, this field is referred to as the Transaction Attribute Identifier. It is typically a random string or a binary value. The string typically consists of at least one of digits, letters, and underscores. Preferably, in this embodiment, the Transaction Attribute Identifier and the pre-set string associated with the transaction consist of at least one of digits and letters.
[0197] The Transaction Role field is used to indicate the identity of the originating end (e.g., the first or second end, etc.) that can use (or create) this transfer transaction. In specific implementations, the value corresponding to this Transaction Role field is a 16-bit binary number, with different bits representing different meanings. Specifically, viewing the 16-bit binary number from right to left, with bits 1 through 8 representing the lower eight bits, bits 1 through 4 of the lower eight bits can be used to represent the role of the originating end of the transfer transaction. For example, if the lower eight bits of the 16-bit binary number are represented in hexadecimal, if the lower eight bits are 0x01, the transfer transaction must be created by the first end (e.g., the client); if the lower eight bits are 0x00, the transfer transaction must be created by the second end (e.g., the server). The remaining bits are used to more specifically represent the role of the originating end of the transfer transaction, such as indicating that the transfer transaction can only be created or executed by clients of Class A (premium members) or Class B (ordinary members), or can only be created or executed by servers of Class A or Class B. Continuing with the above-mentioned example of the transmission transaction corresponding to "requesting network file resources", let's take a specific example. Assuming that the value corresponding to the transaction usage role of the transmission transaction corresponding to "requesting network file resources" is 0x00 0x01, it can be indicated that the transmission transaction corresponding to "requesting network file resources" can be created and executed by a Class B client.
[0198] The transaction attribute type field is used to indicate the transaction attribute type information of the transmission transaction, such as some basic operation types such as control transmission transactions (generally related to the operation of the application system, such as sending network tests and initiating heartbeat packets), download transmission transactions (such as reading network data resources), and upload transmission transactions (such as sending network data). In specific implementations, the field value corresponding to the transaction attribute type field can be a 16-bit binary number, and different bits have different representational meanings. Specifically, still looking at the 16-bit binary number from the right to the left, let the 1st to 8th bits be the lower eight bits as an example:
[0199] Bits 1 through 4 of the lower eight bits can be used to indicate the direction of the data being transmitted. In other words, they can be used to indicate the direction of the data stream to which the data being transmitted belongs. For example, if bits 1 through 4 are "0001," they can indicate that the data is being transmitted from a first end (e.g., the client) to a second end (e.g., the server); if they are "0000," they can indicate that the data is being transmitted from the second end to the first end. Furthermore, bits 5 through 8 of the lower eight bits can be used to indicate the type of data. In other words, they can be used to indicate the type of data stream to which the data being transmitted belongs. For example, if bits 5 through 8 are "0001," it indicates that the data stream is a file data stream; if they are "0000," it indicates that it is a normal data stream. From the above example, if the lower eight bits of the 16-bit binary number are represented in hexadecimal, if the lower eight bits are 0x01, it indicates that the data stream to which the data to be transmitted belongs is a normal data stream, and the data stream is transmitted from the first end (such as the client) to the second end (such as the server); if the lower eight bits are 0x10, it indicates that the data stream to which the data to be transmitted belongs is a file data stream, and the data stream is transmitted from the second end to the first end.
[0200] The remaining eight upper bits (bits 9 to 16) can be used to indicate whether a header needs to be added to the data during data transmission, and what format and type of header is required. For example, similar to the above-mentioned eight lower bits, when the eight upper bits of a 16-bit binary number are expressed in hexadecimal, if the eight upper bits are 0x00, it can indicate that no header needs to be added to the data (i.e., no header is required); if the eight upper bits are 0x01, it can indicate that a normal header in a normal data header format needs to be added to the data; if the eight upper bits are 0x02, it can indicate that a file header in a file data header format needs to be added to the data; if the eight upper bits are 0x03, it can indicate that an email header in an email data header format needs to be added to the data; if the eight upper bits are 0x04, it can indicate that a database operation header in a database operation data header format needs to be added to the data, and so on. In the above, the upper eight bits can be understood as the data header format identifier corresponding to the data header to be added to the data, so that when it is determined that a data header needs to be added to the data, the corresponding data header template can be called according to the corresponding data header format identifier, and then the multiple fields contained in the called data header template are configured to realize the addition of a data header to the data. Considering that the number of data header formats that can be represented by the upper eight bits to represent the data header format identifier is relatively limited (for example, only about 253 data header formats can be represented at most), in order to accommodate more customized extended data header formats, in this embodiment, when the upper eight bits are 0xFF, it means that a data header with an extended data header format needs to be added to the data. Accordingly, the above transmission transaction attribute information can also include an extended data header format unique identification field (not shown in the above Table 1a), which is used to indicate the unique identification of the extended data header format (such as a number). When it is determined that a data header with an extended data header format needs to be added to the data, the corresponding extended data header format template can be further called according to the field value of the corresponding extended data header format unique identification field.For example, referring to Table 1b, in the "Instant Messaging Text Message Sending" service scenario, the server needs to return the corresponding delivery status for the text message sent by the client. The field value of the transaction attribute type field in the transmission transaction attribute information configured for the "Return Delivery Status" transmission transaction is "0xFF 0x00", and the extended data header format unique identifier is "0x01 0x00 0x00 0x01". When the server initiates the "Return Delivery Status" transmission transaction to return the corresponding delivery status data to the client, based on the transaction attribute type information in the transmission transaction attribute information of the "Return Delivery Status" transmission transaction, it is first determined that the data header to be added to the delivery status data is in the extended data header format. Furthermore, based on the extended data header format unique identifier "0x01 0x00 0x00 0x01", a corresponding extended data header format template can be called from multiple pre-set data format headers. The field values of multiple fields contained in the called data header format template are configured based on the data information of the delivery status data to implement adding a data header to the delivery status data. The data type uniquely identified by the extended data header format can be changed according to actual needs. The above is 4 bytes, and it can also be single byte, double byte, 8 bytes, etc.
[0201] In summary, the transaction attribute type information of the transmission transaction indicated by the transaction attribute type field may include but is not limited to at least one of the following: data transmission direction, data type, and data header usage information.
[0202] The following Tables 2a to 2d respectively show the specific data header formats of the above-mentioned common data header, file data header, email data header, and database operation data header, and Table 2e shows the specific data header format of an extended data header.
[0203] Table 2a Data header format of common data header
[0204] The header length field is used to indicate the byte length of the header (32 bits + the number of bytes of annotation information). The annotation information field is used to indicate a tag for identification and judgment by various terminals such as the server and client, or the control device described in other embodiments below, or a string of characters for reading, such as the creation time, modification time, update time, data integrity check value (hash value), etc.
[0205] Table 2b File header format
[0206] Among them, the above-mentioned file header length field is used to indicate the total byte length of the file header and can be used to divide the file header and file data. The file size field is used to indicate the total byte length of the file data. The sender information field is used to indicate the information of the sender of the file, such as user ID, user nickname, etc. The sending time field is used to indicate the timestamp of the file sending. The file attribute field is used to indicate the attributes of the file. The extension field is used to indicate the file type, such as the field value of the extension field can be the file suffix. The file name field is used to indicate the name of the file (such as test). The file name length field is used to indicate the byte length of the file name (that is, the number of bytes, for example, test is 4 bytes, which can be compatible with long file names). The annotation information field is used to indicate the mark (that is, annotation (remark) information) for recognition and judgment by various terminals such as the client and server or the control device described in other embodiments below; or a character string for reading, such as creation time, modification time, update time, etc. The annotation information length field is used to record the number of bytes of the annotation information.
[0207] Table 2c Data header format of mail file data header
[0208] Among them, the file header length field is used to indicate the total length of the email file header. The subject field is used to indicate the subject of the email. The sender address field is used to indicate the sender's address, such as the sender's email address. The recipient address field is used to indicate the recipient's address, such as the recipient's email address. The sending time field is used to indicate the timestamp of sending the email. The attachment file type field is used to indicate the type of attached file carried in the email, such as a compressed package. For the annotation information field, please refer to the relevant content described above for Table 2a or Table 2b.
[0209] Table 2d Database operation data header format
[0210] Among them, the operation type field is used to indicate the operation performed on the database, such as deletion, addition, modification, query and other operations. The operation database address identifier field is used to indicate the address of the database, such as the IP address corresponding to the database. The operation database identification field is used to indicate the name of the database of the operation. The operation table identifier field is used to indicate the name of the data table in the database of the operation. The operation impact field is used to indicate the field in the data table affected by the operation. If the corresponding field value is *, it means that all fields in the data table are affected. For information about the file header length field and the annotation information field, please refer to the relevant content described above for Table 2a or Table 2b.
[0211] Table 2e Data header format of instant messaging message content feature data header
[0212] In Table 2e above, the message type field can be used to indicate the importance of the message. For example, a value of 0x01 indicates a normal message; a value of 0x02 indicates an important message. The message keyword field is used to indicate whether a message contains pre-set keywords or word segments. For information about the file header length field, see the description of Table 2a or Table 2b above.
[0213] Continuing with Table 1a, the group code field (a dictionary) in Table 1a can be specifically divided into a first-category code field, a second-category code field, and a third-category code field, which are used to indicate data transmission operations in different scenarios. When the field values of the first-category code field, the second-category code field, and the third-category code field are all the same (e.g., all "0x00 0x00"), it indicates that no classification is being performed. The group code field corresponds to the grouping function implemented here, similar to the friend grouping function in social networking software. This facilitates grouping and differentiation of transmission transactions when there are many transmission transactions to manage (for example, when the client, the upper-layer application, is a complex system or multiple complex systems, which may result in a large number of transmission transactions requiring management). When using the first-category code field, the second-category code field, and the third-category code field to group and divide transmission transactions, a top-down classification similar to that of provinces, cities, and counties can be adopted. The first-category code field is used to indicate the first-level classification, the second-category code field is used to indicate the second-level classification based on the first-level classification, and the third-category code field is used to indicate the third-level classification based on the second-level classification. This facilitates the management of transmission transactions. For example, the field value of the first-class coding field can be the company code A of a certain company, the field value of the second-class coding field can be the upper-layer application a1 and the upper-layer application a2 developed by the company, and the field value of the third-class coding field based on the upper-layer application a1 can be the action of a specific operation (such as HTTP request, instant messaging sending data, receiving data, uploading data, etc.), so as to facilitate maintenance personnel to view, edit and authorize various management of transmission transactions, and also facilitate the preset corresponding control device to allow or prohibit the transmission of the field value of a certain coding field, so as to directly act on the transmission transaction associated with the field value of the coding field. The above is an introduction to the first-class coding field, the second-class coding field and the third-class coding field from the perspective of affiliation. Of course, the first-class coding field, the second-class coding field and the third-class coding field can also be divided from other perspectives, for example, they can be divided according to the protocol type, application type, transmission direction, the importance of the data end such as the client or server, the importance of the data, etc. This embodiment does not limit this.
[0214] The verification information field indicates the verification information used to verify the data. The verification information can be, but is not limited to, a verification code. The verification code can be used to verify whether the specific transmitted data meets the requirements of the corresponding transmission transaction (such as whether the verification data format or data content meets the requirements). For example, referring to Figure 3a-1, continuing with the above example listed for the transaction attribute name, for the "request network file resource" transmission transaction, the field value of the data verification code field can be configured to, but not limited to, GET (or GETFIL); for the "upload jpg file" transmission transaction, the field value of the data verification code field can be configured to, but not limited to, 0xFF 0xD8 0xFF 0xE0, and so on. Verify whether the content of the transmitted data is a limited value for security control of data transmission. The introduction of using a data verification code to verify the transmitted data will be described in detail in the specific embodiments listed below in this application and will not be repeated here.
[0215] Table 1b shows an example of transmission transaction attribute information for multiple transmission transactions preset from the perspective of the first end 10, taking the first end 10 as the client and the second end 20 as the server, for data transmission between the first end 10 and the second end 20. FIG8 is a schematic flow diagram illustrating the principle of configuring the upper eight bits of the transaction attribute type field value in the transmission transaction attribute information.
[0216] It should be noted that the numerical types, lengths, and other values corresponding to the field values in the various tables in the context of this application (such as Table 1a or Tables 2a to 2e above, or Table 3 described below) can be flexibly adjusted according to actual needs. For example, the data header length (or file header length) can be 32 bytes or 32 bits. Depending on actual needs, it can also be 8, 16, 64, 128, or 256 bytes or bits. Data types of unspecified lengths, such as String, can also be used, and this is not limited.
[0217] In the technical solution provided in this embodiment, to ensure data transmission security, when processing the data to be transmitted to generate structured data that meets the structural rule requirements (i.e., the messages (such as the first message and the second message) described below), this is achieved by utilizing the transmission transaction attribute information of the transmission transaction to which the data block to be transmitted belongs. In addition, the transaction identifier of the transmission transaction may also be utilized, wherein the transaction identifier can be generated independently. Based on this, in summary of the above content, in a specific implementation scheme, the above-mentioned first end 10, when used to determine the first transaction information of the first transmission transaction corresponding to the first data stream, can specifically be used to:
[0218] S10. Generate a corresponding transaction identifier for the first transmission transaction;
[0219] S11. Obtain transmission transaction attribute information of the first transmission transaction.
[0220] That is, the first transaction information of the first transmission transaction includes: a transaction identifier of the first transmission transaction and transmission transaction attribute information of the first transmission transaction. The transaction identifier is autonomously generated by the first end for this first transmission transaction and can be a sequential number or a random string or binary value (such as a random number). In one embodiment, the above S11 "obtaining the transmission transaction attribute information of the first transmission transaction" may include the following steps:
[0221] S111. Determine a transaction attribute identifier of the first transmission transaction;
[0222] S112: Based on the transaction attribute identifier of the first transmission transaction, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
[0223] During specific implementation, the first data stream can be the data stream of the first application (such as a browser application, a social application, an office application, etc.) on the first end 10. More specifically, the first data stream can be a file data stream (such as jpg file binary data, excel spreadsheet file binary data (such as "financial report.xls")), a request data stream (such as a request for network resources), an email sending and receiving data stream (such as an email sent or received), etc., which are not limited here. According to the transmission requirement information of the first data stream, the transaction type to which the first data stream corresponds to the first transmission transaction can be determined, wherein the transmission requirement information may include but is not limited to the direction of data transmission, data type, transmission purpose (such as data storage, query data, operate database), etc. Then, according to the correspondence between the preset transaction type and the transaction attribute identifier, the transaction attribute identifier of the first data stream corresponding to the first transmission transaction can be determined. That is,
[0224] One possible implementation of the above S111 “determining the transaction attribute identifier of the first transmission transaction” is:
[0225] S1111. Determine, based on transmission requirement information corresponding to the first data flow, a transaction type to which the first transmission transaction belongs;
[0226] S1112: According to the preset correspondence between transaction types and transaction attribute identifiers (see, for example, the relevant content of Table 5 below), determine a transaction attribute identifier that has a correspondence with the transaction type to which the first transmission transaction belongs.
[0227] In a specific implementation, if, based on the preset correspondence between transaction types and transaction attribute identifiers, it is determined that there is no transaction attribute identifier corresponding to the transaction type of the first transmission transaction corresponding to the first data stream, then this indicates that the transaction attribute information corresponding to the first transmission transaction of the first data stream cannot be found in the preset multiple transmission transaction attribute information. In this case, the data transmission security control information configured between the first end and the second end in this embodiment does not allow the transmission of the data block in the first data stream, and the data transmission fails. The specific description of the configured data transmission security control between the first end and the second end will be explained in detail below.
[0228] In the above S112, the transaction attribute information of the first transmission transaction may include: transaction attribute name, transaction annotation information (first identification information), transaction attribute identification, a first preset string corresponding to the second end, transaction attribute type information, and verification information. The first preset string may be a string corresponding to the address information of the second end, or the first preset string is a string used to hide the address information of the second end. The transaction attribute type information includes at least one of the following information: data transmission direction (more specifically, the transmission direction of the first data stream, such as sending the first data stream (specifically, the data in the first data stream) from the first end to the second end), data type (more specifically, the data type of the first data stream, such as a file data stream, etc.), data header usage information (such as the need to add a data header to the data during data transmission, etc.). The introduction to the above-mentioned first preset string will be described in detail in other embodiments of the present application. In addition, in addition to the above-mentioned content, the transaction attribute information may also include other content. For an introduction to the specific content that the transaction attribute information may include, please refer to the relevant content above.
[0229] Furthermore, in order to effectively and cost-effectively protect data transmission and prevent malicious attacks, when the first end 10 needs to transmit the first data block of the first data stream to the second end 20, this embodiment will determine the corresponding first target header information to be added for the first data block based on the transaction information of the first transmission transaction corresponding to the first data stream, such as a message header that conforms to a preset message header format, and then integrate the first target header information and the first data block to generate a structured first data block (i.e., the message described below) that conforms to the preset data structure rules. Based on this, in a specific implementation scheme, the above-mentioned first end 20, when used to determine the corresponding first target header information for the first data block based on the transaction information of the first transmission transaction corresponding to the first data stream, can be specifically used to:
[0230] S20. Obtaining a header information transmission mode corresponding to a data block in the first data stream;
[0231] S21. Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block;
[0232] S22. Configure the field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block, to obtain a message header determined for the first data block.
[0233] In the above S20, the header information transmission method is the first method, the second method, the third method and the fourth method shown in Figure 2b. The first method is a transmission scheme for a full structured header, the second method and the third method are transmission schemes for a partial full structured header and a partial simplified structured header, and the fourth method is to retain only one full structured header. Taking the structured header (that is, the target header information involved in this embodiment (such as the first target header information)) including the structured message header as an example, the structured message header is generated based on the preset message header format. The full structured header refers to a message header containing all corresponding parameters in the preset message header format (that is, all parameters shown in Table 3 below. It should be noted that the following fields in the preset message header format shown in Table 3 below are all optional: the second preset identification field corresponding to the sender, the first preset identification field corresponding to the receiver, the annotation information field, and the current block number field, so that there is no need for any It is learned that the preset message header format shown in Table 3 below is only an example and does not mean that the preset message header format must be the format shown in Table 3. The preset message header format can also be a format that only includes the following fields: transaction attribute identification field, transaction identification field, message size field, and total block number field. Based on this, "all parameters" here are not limited to all parameters shown in Table 3); the simplified structure header refers to the corresponding partial parameters in the preset message header format (as shown in Table 3 below, which may include the block number of the data block currently to be transmitted (i.e., the current block number shown in Figure 2b) and the transaction identifier of the transmission transaction (i.e., the transmission transaction ID shown in Figure 2b)), where the transmission transaction attribute ID shown in Figure 2b refers to the transaction attribute identifier involved below.
[0234] In order to better understand the above contents of step S20, a more detailed description of step S20 is given below. Specifically, it is as follows:
[0235] In the above S20 , the header information transmission mode may indicate which structured header is used for each data block in the data stream for structured transmission.
[0236] In specific implementation, the above header information transmission method includes but is not limited to the first method, the second method, the third method and the fourth method shown in Figure 2b.
[0237] The first method is to use a transmission scheme of a full structured header for all data blocks in the data stream.
[0238] The second and third methods are transmission schemes that use a full structured header for some data blocks in the data stream and a simplified structured header for some data blocks. Specifically, the second method is to use a full structured header only for the last data block and a simplified structured header for other data blocks. The third method is to use a full structured header only for the first data block and a simplified structured header for other data blocks.
[0239] The fourth approach is to retain only one full structured header. Specifically, the full structured header is used only for one target data block in the data stream, while the remaining data blocks can use a common header (such as the communication message header shown in Figure 1). The target data block can be any data block in the data stream, such as the first data block, a middle data block, or the last data block. Figure 2b shows the fourth approach, which illustrates an example of using the full structured header only for the first data block in the data stream.
[0240] In addition, taking the structured header (i.e., the target header information involved in this embodiment (such as the first target header information)) including a structured message header as an example, the structured message header is generated based on the preset message header format, then: the fully quantized structured header refers to a header that includes all fields in the preset message header format (such as all field parameters shown in Table 3 below), all of which include a transaction attribute identification field and a transaction identification field; the simplified structured header refers to a header that includes some fields in the preset message header format, such as referring to Table 3 below, which may include a transaction identification of a transmission transaction (i.e., the transmission transaction ID shown in FIG2b ). In addition, it may further include the block number of the data block currently to be transmitted (i.e., the current block number shown in FIG2b ). Among them, the transmission transaction attribute ID shown in FIG2b refers to the transaction attribute identification involved below.
[0241] Since the data blocks in the data stream are transmitted normally with reliability and sequential transmission (such as when the network is normal and there are no adverse phenomena such as congestion), the data block first received by the corresponding receiver is often the data block ranked first in the data stream. Based on this, the first and third methods mentioned above, when it is necessary to transmit the data block ranked first in a data stream (such as data block 0 shown in Figure 2b), both use the full structured header to structure data block 0 (and also generate the message involved in this application for data block 0). This allows the receiver to perform verification and other processing on the data stream after receiving the first structured data block corresponding to the data stream (structured data block 0 corresponding to data block 0) without waiting. If the second method is adopted, the receiver needs to wait until it receives the structured data block with the full structured header before performing verification and other processing.
[0242] In addition, in the first method mentioned above, a full structured header transmission scheme is adopted for each data block in the data stream, which allows the receiver to perform processing such as verification based on the structured data block corresponding to any received data stream, which is beneficial for dealing with adverse phenomena such as network congestion and improving transmission reliability.
[0243] The second approach described above is well-suited for some non-sequential or unreliable transmissions. For example, referring to Figure 2b, assume a data stream includes three data blocks, namely, data block 0, data block 1, and data block 2, where data block 0 and data block 3 are the first and last data blocks of the data stream, respectively. A sender (e.g., a client) sequentially sends the structured data blocks corresponding to data blocks 0 through 2 to a receiver in accordance with the second approach. Although the structured data block 2 corresponding to the third sent data block 2 has a fully quantized structure header, due to network reasons (e.g., network congestion or jitter), the order of the structured data blocks actually received by the receiver is different from the order sent by the sender. For example, the order of the structured data blocks actually received by the receiver is: structured data block 2 corresponding to data block 2, structured data block 1 corresponding to data block 1, and structured data block 0 corresponding to data block 0. In this case, the receiver can perform processing such as verification on the data block (i.e., structured data block 2) after receiving the structured data block for the first time, without waiting. As can be seen from the above, the second method can actually be understood as a practical application extension of the third method, which is used to improve reliability and solve problems such as congestion.
[0244] In the fourth method described above, for example, only the data block that is ranked first in the data stream (such as data block 0 shown in Figure 2b) can be structured using the full structured header for transmission. Subsequent data blocks (such as data block 1, data block 2, ..., data block N) are no longer structured when transmitted, but are directly packaged into messages in the ordinary manner (the manner shown in Figure 1) for transmission. That is, when transmitting data blocks in the data stream, only the first transmitted data block is the structured data block (i.e., the structured data block obtained by structuring the first-ranked data block using the full structured header). Subsequent data blocks are no longer structured and are transmitted in the ordinary manner. However, when transmitting subsequent data blocks, the structured header corresponding to the structured data block transmitted first can be automatically associated, and the association is terminated when the association termination condition is met, and it is determined that the transmission is completed. Among them, satisfying the association end condition includes: if the data stream is a stream with a known total number of data blocks, in other words, if the data stream is data of a specific size (such as a file, etc.), then the number of transmitted data blocks can be counted during the transmission process, and the association end condition is satisfied when the number of blocks reaches the total number of data blocks in the data stream; if the data stream is a stream with an unknown total number of data blocks, in other words, if the data stream is data of no specific size (such as a real-time audio or video stream), then the association end condition can be determined to be satisfied upon receiving specific instruction data (such as an indication that the data blocks have been sent and the message header contains an end transmission transaction flag) or when no data blocks are received within a set time period.
[0245] It should be noted here that: for other methods, such as the second method and the third method, an association method similar to the fourth method can also be used to associate the corresponding full structured header with the unstructured data block. For detailed implementation, please refer to the relevant content such as Examples A1 to A3 given below.
[0246] There are some extensions to the fourth method mentioned above. They are as follows:
[0247] The first extension scheme is: before starting to transmit the data blocks in the data stream, simply send an initial message containing only the full structured header data (excluding the data blocks in the data stream) to the corresponding end (such as the second end, etc.), and then when transmitting all the data blocks in the data stream, they can be directly packaged into messages in a common manner (as shown in Figure 1) and transmitted to the corresponding end. The corresponding end can associate the data blocks contained in the subsequent received messages with the full structured header contained in the initial message received for the first time. Among them, the full structured header contained in the initial message is determined based on the flow information of the data stream and the corresponding transmission transaction. The field value of the current block number field contained in the full structured header can be a preset value or directly a null value.
[0248] The second expansion scheme is: after structuring the data block ranked first in the data stream (such as data block 0 shown in Figure 2b) using a full structured header, the structured data block 0 (i.e., containing the full structured header) can be transmitted to the first communication interface of the corresponding end (such as the second end). When other data blocks in the data stream are subsequently transmitted, they are sent to the second communication interface of the corresponding end, and the corresponding end can associate the data blocks subsequently received through the second communication interface with the full structured header (obtained from the received structured data block 0) received through the first communication interface. The first communication interface and the second communication interface mentioned above can be understood as different network communication services of the corresponding end. For example, the first communication interface is a network communication service on the corresponding end dedicated to receiving the data block ranked first in the data stream, and the second communication interface is a network communication service for subsequently receiving other data blocks in the data stream (data blocks other than the data block ranked first).
[0249] The benefit of adopting the fourth method is that network traffic can be saved.
[0250] From the above content, when this embodiment transmits data for a data stream, not all data blocks need to be structured using a full quantization structure header or a simplified structure header for transmission. For data blocks that are not structured using a full quantization structure header or a simplified structure header, contextual judgment can be made based on the total amount of data to be transmitted, the data format, etc., and they can be merged and associated into a transmission transaction containing a full quantization structure header.
[0251] Example A1: Implementing association judgment based on the total amount of transmitted data. For example, the total length of an HTML page data stream is 512 bytes * 12. This means that the HTML page data stream is divided into 12 data blocks of 512 bytes each for transmission. In other words, 12 transmission operations are required to complete the transmission of the HTML page data stream. Each transmission operation packages the corresponding data block into a message for transmission. During the transmission process, as long as at least one message containing a full structured header appears, other messages belonging to the HTML page data stream but containing only a general message header can be associated with the transmission transaction of that HTML page data stream based on the known total length of the HTML page data stream. Specifically, assuming that for the transmission of the aforementioned html page data stream, the first message received by the receiver containing the full structured header is the third message received, at this time the receiver can start to perform upper and lower association judgments to associate the first and second messages received previously (neither of which contain the full structured header) with the full structured header contained in the third message. In addition, other messages received later that do not contain the full structured header (such as the fourth message, the fifth message, the sixth message, etc.) can also be associated with the full structured header contained in the third message, until the 12th message is received to determine that the transmission of this html page data stream is completed, and the association judgment is ended.
[0252] Example A2: Implementing association judgment based on the transmitted data format. For example, assuming the data stream to be transmitted is an HTML page data stream, the appearance of a tag indicates the start of transmission of the HTML page data stream, and the appearance of a tag indicates the end of transmission of the HTML page data stream. Therefore, from the appearance of the start tag to the appearance of the end tag, as long as the receiver receives a message containing the full structured header, it can begin to perform contextual association judgment, associating the previous and subsequent messages that do not contain the full structured header with the corresponding full structured header.
[0253] Example A3, association judgment based on agreed position, the agreed position refers to which data blocks in the data stream are agreed in advance to use the full structure header, which can be understood as, it is agreed in advance in which messages the full structure header will appear. For example, when transmitting data for a data stream, it is agreed in advance that the third message contains the full structure header, or it is agreed in advance that the third message contains the full structure header, the fifth and last are simplified structure headers, etc., then the receiver can perform context association judgment based on the association method described in the above examples A1 and A2 or other association methods (such as the specific instructions described in other embodiments, the end of the transmission transaction identifier, the reaching of the set time, etc.) when receiving the third message, so as to associate the messages received before and after that do not contain the full structure header with the corresponding full structure header.
[0254] The benefit of doing this is that when transmitting data in the data stream, the positions of the full quantization structure header, or the full quantization structure header and the simplified structure header can be made non-fixed, which helps reduce the risk of malicious analysis and increases the difficulty of constructing counterfeit data.
[0255] In summary, when transmitting data blocks in the first data stream to the second end, the header of at least one data block in the first data stream is a fully structured header. Furthermore, verification processing is performed only when the header included in the first target header information of the first data block is a fully structured header.
[0256] It should be noted that the "current block number" shown in Figure 2b is optional. Block numbers can be omitted when reliable or sequential transmission of multiple data blocks within a data stream is required, or when data integrity is not a concern. Reliable transmission involves employing a series of techniques to ensure accurate and precise transmission of information (data blocks) between the sender and receiver.
[0257] In the above S21, the relevant information of the first data block may include, but is not limited to: the first data stream to which the first data block belongs, stream information of the first data stream (such as stream type, stream size, etc.), the size of the first data block, the order in which the first data block is arranged in the first data stream, etc. The preset message header format is as shown in Table 3 below:
[0258] Table 3 Preset message header format
[0259] It should be noted that in addition to the information shown in Table 3, the preset message header format may also include other information according to actual needs, such as the communication restriction information shown in Table 18-C. For a detailed description and function of the communication restriction information, please refer to the relevant content in other embodiments and will not be described in detail here. In addition, the fields involved in the tables, lists, etc. related to this application are all optional (whether marked as optional or not) and are not limited. In different scenarios, only the required fields can be selected.
[0260] Among them, the second preset string field corresponding to the sender is optional and is used to indicate the second preset string corresponding to the sender, which can be a string representing the address information of the sender (such as a public IP address, a private IP address, or a MAC address, or a string corresponding to the host name), which is used to control the device or the network intermediate device to monitor, audit or intercept; or it can be a string used to hide the address information of the sender. The first preset string field corresponding to the receiver is optional and is used to indicate the first preset string corresponding to the receiver, which can be a string representing the address information of the receiver, or it can be used to hide the address information of the receiver. In this embodiment, since the first end 10 needs to send data to the second end 10, the first end 10 is the sender and the second end 20 is the receiver. The above preset string can also be called a communication identifier, which is an identifier for communication between different ends. The specific introduction to the preset string will be elaborated in other embodiments provided in the following text application.
[0261] For a description of the transaction attribute identification fields, see the relevant content above.
[0262] The transaction identifier field is used to indicate the transaction identifier of the transmission transaction (e.g., the transmission transaction ID). The transaction identifier can be a random string or a sequential number. For example, referring to FIG3a-1 , if the first end 10 needs to initiate a transmission transaction for a data stream of a previous application, it can randomly generate a string as the transaction identifier of the initiated transmission transaction.
[0263] The message size field is preferably selected to indicate the size (or byte length) of a structured data currently being transmitted (such as the first message to be sent generated for the first data block as described below). For example, taking the first data block as an example, when only the corresponding message header needs to be determined for the first data block, the field value of the message size field is the total size of the message header and the first data block (i.e., the size of the message header + the size of the first data block). Of course, in other embodiments, the message size field can also be simply used to indicate the size of the data block currently to be transmitted (such as the first data block), and this embodiment is no longer limited to this. It should be noted here that the "message size" in Table 3 above is also referred to as "data packet size" in other embodiments below in this application (such as Table 6 or Table 72 mentioned below).
[0264] The Total Blocks field is used to indicate the total number of data blocks in the data stream corresponding to the transmission transaction. When the total block count is a set value, it indicates that the data stream is a stream with an unknown number of data blocks. For example, if the first data stream in this embodiment is composed of multiple data blocks obtained by partitioning fixed-size file data or hypertext data, then the value of the Total Blocks field is the total number of multiple data blocks (greater than 0). Conversely, if the value of the Total Blocks field is a set value, such as 0, it indicates that the first data stream is an infinite stream, such as a surveillance video stream, live audio and video stream, or other data stream from a monitoring device. Another example is -1, which indicates that the first data stream is finite but the number of data blocks it contains is currently unknown. It should be noted that since one data block corresponds to one message, the Total Blocks field here can also be understood as indicating the total number of messages to be transmitted in the transmission transaction. For example, taking the transmission transaction shown in Figure 2a as an example, the Total Blocks field can also be understood as the total number of messages 0 to N (i.e., N+1). Correspondingly, the current block number field described below can also be understood as a message number indicating the message currently being transmitted.
[0265] The current block number field (also called the data block sequence number field) is used to indicate the block number (ie, sequence number) of the data block currently being transmitted.
[0266] The annotation information field is optional and is used to indicate the annotation information (remark information) corresponding to the transmission transaction, such as the remark information of the data stream corresponding to the transmission transaction, such as the remark as "important", the remark data stream as a file stream or a normal data stream, etc., or the hash value of the data integrity check of the marked transmitted data or file, so as to facilitate the identification, reading, parsing or security control of various ends such as the second end (such as the server end) and the control devices described in other embodiments of the text below.
[0267] Based on the above description of the header information transmission method in S21, in one embodiment, the above S21 "determining a target header field for the first data block from multiple header fields included in a preset message header format based on the header information transmission method and relevant information of the first data block" may include:
[0268] S211. Determine the order of the first data block in the first data stream according to the block number of the first data block included in the relevant information;
[0269] S212: If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, then the multiple header fields are the target header fields;
[0270] S213. If the header information transmission mode is the second mode and the data block is not sorted last in the first data stream, or the header information transmission mode is the third mode and the data block is not sorted first in the first data stream, then some of the multiple header fields are the target header fields.
[0271] In the case of S212 above, that is, all header fields (multiple header fields) included in the preset message header format shown in Table 3 above are target header fields determined for the first data block, then S22 above, “configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block,” may specifically include the following steps:
[0272] S221. Determine a second preset character string corresponding to the first end for the first transmission transaction;
[0273] S222: Configure a field value of the target header field according to the second preset character string, the transaction identifier and transmission transaction attribute information included in the first transaction information, and relevant information of the first data block, to obtain a first message header determined for the first data block.
[0274] Among them, based on the above description of the preset message header format, the first message header determined for the first data may include the following contents: the second preset character string corresponding to the first end, the first preset character string corresponding to the second end, the transaction attribute identifier of the transmission transaction, the transaction identifier of the transmission transaction, the total number of data blocks in the first data stream, the block number of the first data block, the first target header information and the total size of the first data block, and the annotation information.
[0275] The second preset string corresponding to the first end is a second preset string determined to correspond to the transaction type of the transmission transaction corresponding to the first data stream based on a preset correspondence between the second preset strings and transaction types (see Table 5 below). The second preset string corresponding to the first end may be a string corresponding to the address information of the first end, or a string used to conceal the address information of the second end.
[0276] The first preset character string corresponding to the second end may be directly obtained from the transmission transaction attribute information of the first transmission transaction corresponding to the first data stream.
[0277] Furthermore, if, based on the transmission transaction attribute information of the first transmission transaction corresponding to the first data stream, more specifically, based on the transaction attribute type information in the transmission transaction attribute information, it is determined that a corresponding data header needs to be added to the data block when transmitting the data block in the first data stream, in this case, the data header can be added only to the first data block in the first data stream. If the first data stream includes multiple data blocks, the data header does not need to be added to the other data blocks located after the first data block in the multiple data blocks. Based on this, when the above-mentioned first data block is sorted first or last in the first data stream, the above-mentioned step S22 may also include the following steps:
[0278] S223: Determine whether it is necessary to add a data header to the first data block according to the transmission transaction attribute information of the first transmission transaction in the first transaction information;
[0279] S224. When it is determined that it is necessary, determine a corresponding data header for the first data block according to the stream information of the first data stream; wherein the data header is adapted to the first data stream and meets preset data header format requirements.
[0280] In S223 above, whether a header needs to be added to the first data block is determined based on the transaction attribute type information in the transmission transaction attribute information. The transaction attribute type information includes, but is not limited to, the following: header usage information, the transmission direction of the first data stream, the data type of the first data stream, etc. The header usage information includes a header format identifier for the header used. For a detailed description of the content included in the transaction attribute type information, please refer to the relevant content above. More specifically, whether a header needs to be added to the first data block is determined based on the header usage information in the transaction attribute type information.
[0281] In S224 above, when it is determined that a data header needs to be added to the first data block, an appropriate data header format may be further selected from multiple preset data header formats based on the data header usage information in the transaction attribute type information. Based on the flow information of the first data stream, a corresponding data header is generated for the first data block in accordance with the selected data header format. That is, a specific implementation of S224 above, "determining a corresponding data header for the first data block based on the flow information of the first data stream," may include the following steps:
[0282] S2241. Select an adaptive data header format from a plurality of preset data header formats based on the data header usage information included in the transmission transaction attribute information.
[0283] S2242. Generate the data header according to the selected data header format based on the flow information of the first data flow.
[0284] For descriptions of data header formats, please refer to the several preset data header formats shown in Tables 2a to 2e above. Also, for the specific implementation of S2241, please refer to the relevant content involved in the detailed description of transaction attribute type information above, which will not be repeated here.
[0285] In S242 above, the flow information of the first data stream may include, but is not limited to, the sending time of the first data stream, attribute information of the first data stream (such as the data type, size of the first data stream, name of the first data stream, etc.), sender address, receiver address, etc. Based on the flow information of the first data stream, corresponding field values can be configured for the multiple fields included in the selected data header format, thereby generating a corresponding data header for the first data.
[0286] With the above content, after determining the corresponding first target header information (such as a message header, or a message header and a data header) for the first data block, the first end 10 can integrate the first target header information and the first data to generate a first message to be sent that complies with the preset data structure rules. When specifically integrating, as shown in Figure 3a-1, an example of a message A1 to be sent generated by this embodiment is shown. If the first target header information includes a message header, the message header (i.e., the structured message header shown in the figure) can be added between the TCP / IP message header and the first data block; further, if the first target header information also includes a data header, the data header can be added between the message header and the first data block. The above-mentioned first target header information can be used to verify whether the first message meets the requirements.
[0287] For the message A1 shown in FIG3a-1, the following table 41 shows an example of the message structure format of the message A1:
[0288] Table 41
[0289] It should be noted that the message structure format of the above message A1, in addition to the contents shown in the above Table 41, may also include the TCP / IP message header, TCP / IP message tail, etc. as shown in Figure 3a-1, which are not shown in Table 41.
[0290] In the case of S213 above, that is, some header fields (such as the transaction identifier field) among all header fields (multiple header fields) included in the preset message header format shown in Table 3 above are target header fields determined for the first data block, then S22 above, “configuring a field value of the target header field according to at least one of the first transaction information and relevant information of the first data block to obtain a message header determined for the first data block,” may specifically include the following steps:
[0291] S221′: Based on the transaction identifier of the first transmission transaction in the first transaction information, configure the field value of the target header field to obtain a second message header determined for the first data block;
[0292] The second message header includes the transaction identifier.
[0293] In a specific implementation, the target header field determined by the first data block may include, in addition to the transaction identifier field in the preset message format, other header fields, such as the current block number field. In this case, the value of the target header field may be configured based on the transaction identifier of the first transmission transaction and related information of the first data block (specifically, the block number of the first data block). Accordingly, the second message header determined for the first data block includes the transaction identifier of the first transmission transaction and the block number of the first data block. Furthermore, in this example, adding a data header to the first data block is not required.
[0294] With the above content, in this example, the first end 10 integrates the first target header information (message header (including transaction identifier, block number of the first data block (optional))) determined for the first data block and the first data, and the message format of the generated first message can be seen in Table 42 below.
[0295] Table 42
[0296] After the first end 10 generates the first message to be sent, it can send the first message to the second end 20 according to the address information of the second end determined by the first preset character string corresponding to the second end. After the second end 20 receives the first message sent by the first end, it can verify the received first message based on the data transmission security control information between the first end and the second end configured in this embodiment. During the verification, it is specifically to verify whether the target header information (such as the message header, the data header) contained in the first message meets the preset requirements, for example, whether the format of the message header of the first message meets the preset requirements, whether the transaction attribute identifier in the message header has been registered, etc. The specific implementation of the data transmission security control information and the verification of the message according to the data transmission security control information will be detailed in other embodiments provided in this application and will not be repeated here. When the second end 20 determines that the received message meets the requirements after verification, it can execute the acquisition and cache of the first data block from the first message.
[0297] The above-described solution, in the scenario where the first end 10 and the second end 20 communicate directly using the TCP / IP protocol as shown in Figure 3a-1, mainly implements data security protection from the perspective of structuring the data to be transmitted. Compared with the existing data transmission solution using the TCP / IP protocol, it realizes security management of the content of the transmitted data.
[0298] In order for the first end 10 to implement the above-described solution and further improve the security management of the transmitted data content, thereby preventing the first application on the first end 10 from arbitrarily calling the network interface on the first end to arbitrarily send data directly to the second end 20, based on the scenario shown in FIG. 3a-1 , the following two technical solutions can be used to achieve the above-described further desired effect:
[0299] A specific technical solution that can be implemented is: installing "control software" on the first end 10 (its function is similar to that of the control device in the second solution described below). In specific implementation, different types of "control software" can be installed on the first end 10 according to the two situations of the preset character strings described above. Specifically,
[0300] Case 11: The preset string (such as the first preset string corresponding to the second end, the second preset string corresponding to the first end 10) does not have the function of hiding the address information of the corresponding end (such as the preset string is the IP address of the corresponding end)
[0301] As shown in Figure 3b, in the above-mentioned scenario 11, a first control module 11 can be installed within the application on the first end 10 to perform various control functions, such as generating and sending a corresponding first message to be transmitted for data that the application needs to transmit to the second end 20, as well as identifying, verifying (auditing), and other control functions for received messages (such as the second message sent from the second end 20). The above-mentioned first control module 11 is pre-configured with various preset information, including the multiple transmission transaction attribute information (as shown in Table 1b), a preset message header format, a preset data header format, and so on. When the first end 10 transmits a first data block in a first data stream (the data stream of the first application on the first end) to the second end 20, the first data block is first sent to the first control module 11 in the corresponding first application. The first control module 11 then generates a corresponding first message to be transmitted for the first data block and, based on the address information of the second end 20, sends the first message to the second end 20 via an intermediate network device. For the specific implementation of the first control module 11 generating the first message, please refer to the relevant content in the context of this application.
[0302] Furthermore, a fourth control module (not shown) can also be installed in an intermediate network device (such as a switch, router, firewall, etc.) to further identify and verify (or monitor and intercept) the first message. The preset information and corresponding achievable functions in the fourth control module can be similar to the first control module 11 described above or the second control module 12 described below. In specific implementation, after the first control module 11 in the first application generates the first message to be sent, it can call the network interface on the first end 10 and, based on the address information of the second end (the first preset string corresponding to the second end), first send the first message to the intermediate network device according to the TCP / IP protocol. The fourth control module in the intermediate network device verifies the first target header information contained in the first message based on the preset information stored in it (such as multiple transmission transaction attribute information, message header format, etc.) to determine whether the first message meets the requirements. If it meets the requirements, it will execute the first message to be sent to the second end 20 based on the address information of the second end.
[0303] Alternatively, the fourth control module on the intermediate network device may not have the functions of generating messages, checking, intercepting, etc. as the first control module 11, but may simply have a log audit function for recording and analyzing received messages to generate log information of the corresponding transmission transaction. For example, after the intermediate network device receives the first message sent by the first end, it can use the fourth control module within itself to parse the first message, so as to generate a log corresponding to the first data block and the first target header information of the first data block according to the parsed data, and record it in the log table of the first transmission transaction, wherein the log content of each log in the log table may include but is not limited to: the message header of the corresponding data block, the data header (optional), the transmission transaction attribute information of the first transmission transaction, etc. Through the log table of the first transmission transaction, the network data traffic related to the first transmission transaction can be intuitively analyzed.
[0304] Based on the above content, in the case shown in FIG. 3 b , when the first control module 11 on the first end 10 is used to send the generated first message to the second end 20 according to the address information of the second end, it can be specifically used to:
[0305] Sending the first message to an intermediate network device according to the address information of the second end, so as to be sent to the second end through the intermediate network device;
[0306] Before sending the first message to the second end, the intermediate network device further performs any one of the following: verifying the first target header information contained in the first message; generating log information of the first transmission transaction based on the first message.
[0307] For the description of the log information, please refer to the description of the log table above. For the specific implementation of the first target header information verification, please refer to the relevant content in other embodiments of the present application, which will not be repeated here.
[0308] It should be noted that the first control module 11 needs to be developed by the application developer to implement the above functions, and in the scenario shown in FIG3 b , only the application participates in the communication activity.
[0309] In case 12, the preset string is used to hide the address information of the corresponding end (for example, the preset string is a randomly generated random string, and its associated information includes the address information of the corresponding end)
[0310] In the above situation, as shown in FIG3c , an independent second control module 12 can be installed externally on the first end 10 to complete various control functions such as generating corresponding messages to be transmitted for data to be transmitted to the second end 20 and sending them, as well as identifying and verifying (monitoring, intercepting) received messages (such as messages sent from the second end 20). In this way, all communications applied on the first end 10 need to be carried out through the second control module 12, and a preset string (such as a random string) can be used to hide the address information (such as the IP address) of the corresponding end, and preset in the second control module 12. For example, the first preset string corresponding to the second end included in the multiple transmission transaction attribute information preset in the second control module 12 is used to hide the address information of the second end. When the first end 10 needs to transmit the first data block of the first data stream of the application to the second end 20, the first data block will first be sent to the second control module 12. The second control module 12 generates a corresponding message to be sent for the received first data block based on preset information preset in the module (such as multiple transmission transaction attribute information, message header format, etc.), and sends the generated message to the second end. For the specific implementation of the second control module 12 generating the message, please refer to the relevant content in the context of this application.
[0311] Alternatively, as shown in FIG3d , a first control module 11 can be installed within the application on the first end 10 while a second control module 12 can also be installed outside the application. When the first end 10 needs to transmit the first data block of the first data stream of the application to the second end 20, the first control module 11 can be used to determine the transaction attribute identifier of the transmission transaction corresponding to the first data stream based on its own preset information, and send the transaction attribute identifier and the first data block to the second control module 12. The second control module 12 then generates a first message to be sent to the second end 20 based on the transaction attribute identifier and the first data block. For the specific implementation of the second control module 12 generating the first message, please refer to the relevant content in the context of this application.
[0312] It should be noted that, with respect to the above-mentioned scenario 12, in conjunction with the two solutions described in FIG3c and FIG3d , further, similar to the above-mentioned scenario 11, the aforementioned fourth control module can also be installed in an intermediate network device (such as a switch, router, firewall, etc.) to further identify and verify (or monitor and intercept) the first message. For specific implementation details, please refer to the relevant content of scenario 11. Alternatively, the above-mentioned intermediate network device may not have a verification function, but only have a log audit function (as a log audit software application for analyzing transmission transaction data).
[0313] In addition, the second control module 12 is an independent control program that can obtain the first preset string corresponding to the second end based on preset information pre-set within itself, and obtain the real address information of the second end based on the first preset string. It then calls the network interface corresponding to the first end 10 and forwards the first message to the second end 20 via the TCP / IP protocol according to the real address information of the second end. Regarding the specific implementation principle of the second control module 12 sending the first message to the second end 20, please refer to the principle of the first control device 31 sending the first message to the second end 20 described in other embodiments below in conjunction with Figure 4a. The second control module 12 is similar to the network control function of software firewalls and antivirus software, and can control network traffic for applications with ordinary permissions, such as those with ordinary permissions, so that ordinary permission applications cannot directly call the universal first end network interface to access the network, and must access the network through the interface provided by the second control module 12.
[0314] Another specific technical solution is to add a corresponding control device between the first end 10 and the second end 20, and use physical special control methods to further improve data security protection and control capabilities. In some embodiments, the control device can be an external device between the first end 10 and the second end 20. In this case, as shown in Figures 7a and 7b, the specific form of the control device 30 can be a desktop form as shown in Figure 7a, or a portable form as shown in Figure 7b, without limitation. In specific implementations, as shown in Figures 7a or 7b, the control device 30 may include, but is not limited to, the following structural components: a display touch screen (or display screen), a wireless module (such as a WiFi (Wireless Fidelity) module deployed at the physical layer, a mobile cellular network (3G, 4G, 5G) module, a Bluetooth module, a LoRa (a long-distance wireless transmission technology based on spread spectrum technology) module, etc. (not shown in Figures 7a and 7b, see wireless module 32f shown in Figure 7c), an operation button 33, an antenna 34, and a peripheral interface 31g. The antenna 34 is used for receiving and transmitting network signals of wireless communications such as Bluetooth, WiFi, and mobile cellular networks (such as 3G, 4G, and 5G). The peripheral interface 31g is an interface for wired transmission, which is used to connect the control device to other devices via a data line. From the above, the peripheral interface 31g can also be called a wired interface. In specific implementations, the peripheral interface 31g may include a network cable interface 311 (also called a local area network interface, such as an Ethernet interface, a fiber optic interface, a twisted pair interface, etc.) for connecting to the network, and a bus interface 312 for bus communication (such as a USB (Universal Serial Bus) interface, an SPI (Serial Peripheral Interface) interface, etc.). For the specific functions of the structural components included in the control device 30 described above, please refer to the relevant content below.
[0315] In other embodiments, the control device can also be a device that can be integrated within the first end 10 and / or the second end 20. In this case, the control device can be in the form of a single chip or expansion card, similar to an integrated graphics card, and can be integrated into the motherboard of the first end 10 or the second end 20. Alternatively, the control device can be in the form of a discrete graphics card, and can be integrated into the host of the first end 10 or the second end 20, without limitation. In a specific implementation, as shown in FIG7c , when the control device is in the form of a chip or expansion card, the control device 30 may include, but is not limited to, the following structural components: a wireless module 32f, an inter-board interface 313, an antenna 34, and a peripheral interface 31g'. The inter-board interface 313 can be, but is not limited to, a PCIE (Peripheral Component Interconnect Express) interface, a high-speed serial computer expansion bus standard interface. In this embodiment, the PCIE interface can be used to connect the control device 30 to the motherboard of the first end 10. The peripheral interface 31g' may include a first-type peripheral interface 311' and a second-type peripheral interface 312'. The first type of peripheral interface 311' can be a USB composite device interface, through which the control device can be connected to a display screen such as the first end and control operations can be performed, so that corresponding content (such as displaying inquiry information, displaying the name of the transmission transaction, etc.) can be displayed through the display screen such as the first end, and operations can be performed. By performing independent display and operation on the control device, it can be effectively isolated from the computer's driver to avoid important operations being performed on the computer (the computer may be maliciously controlled). The second type of peripheral interface 312' can be, but is not limited to, a USB interface, a network cable interface, etc. For a detailed introduction to the wireless module 32f, the antenna 34 and the network cable interface, please refer to the relevant content above.
[0316] When introducing another specific achievable technical solution provided by this embodiment below, this solution will be described in detail by taking the control device 30 as an external device of the first end 10 and the second end 20 as an example.
[0317] It should be added here that when additional control devices are used to improve the protection and control of data transmission security between different terminals, device drivers (also called device drivers) or API (Application Programming Interface) interfaces or SDK (Software Development Kit) of the corresponding control devices are deployed on different terminals. Applications on the terminals can access the device drivers of the corresponding control devices through the API (or SDK) interface. Figure 6a shows an example of device drivers and API interfaces for corresponding control devices deployed on the first terminal 10 and the second terminal 20, respectively. This example is shown for the second possible embodiment described below (i.e., adding two control devices between the first terminal 10 and the second terminal 20).
[0318] Based on the above, in a first possible embodiment, a first control device can be added between the first and second ends, and the first end 10 can use this first control device to send the first message to the second end 20. Specifically, as shown in Figures 4a to 4c, the system provided in this embodiment may further include a first control device 31, which is communicatively connected to both the first end 10 and the second end 20.
[0319] In a specific implementation, scenarios in which the first control device 31 communicates with the first end 10 and the second end 20 may include but are not limited to the following specific scenarios:
[0320] Scenario 11: As shown in Figures 4a and 4b, assuming that the first end 10 and the second end 20 are remote from each other and the first control device 31 is deployed at a location such as the first end 10, the first end 10 can be connected to the first control device 31 through a non-network-connected communication interface for short-range communication; wherein the non-network-connected communication interface can be a bus interface (such as a USB interface, an SPI interface) or a wireless interface (such as an interface implemented by a Wifi module, a Bluetooth module, etc.). To reduce the cost of remote communication, the second end 20 can be connected to the first control device 31 through a network interface and with the help of an intermediate network device (such as a switch, a router), still using the TCP / IP protocol, for long-range communication. The above-mentioned network interface can be a wired interface, such as a twisted pair Ethernet interface, an optical fiber interface, or a network cable interface; or it can be a wireless interface, such as an interface implemented by a 3G module, a 4G module, a 5G module, or a satellite communication module.
[0321] In this scenario 11, the first end can completely avoid network communication (not using a network card), but of course it can also use the network to communicate normally with other ends (such as a third end). In response to this, the following supplementary scenario description for scenario 11 is provided: As shown in Figure 4e, the first end can simultaneously establish a non-network connection with the control device and a normal network connection with the third end (while also using a network card). This allows the first end to conceal its communication with the second end through the non-network connection and the control device, while simultaneously communicating with the third end through the network connection, without affecting normal network communication.
[0322] For a detailed description of the benefits of this scenario 11, please refer to the relevant content described below in conjunction with Figures 6a and 6b.
[0323] Scenario 12: As shown in Figure 4c, assuming that the first end 10 and the second end 20 are near each other, for example, they are located in the same site, and the first control device 31 is deployed at the site where the first end 10 and the second end 20 are located, the first control device 31 can be connected to the first end 10 and the second end 20 using a wired communication method using wired interfaces (such as bus interfaces such as USB interfaces, network interfaces such as twisted pair Ethernet interfaces) on the first end 10, the first control device 31, and the second end 20. Of course, in other embodiments, wireless modules on the first end 10, the first control device 31, and the second end 20 can also be used to connect the first control device 31 to the first end 10 and the second end 20 using a wireless method such as near-field communication (NFC) such as WiFi or Bluetooth.
[0324] Scenario 13: As shown in Figure 4d or Figure 5a, assuming that the first end 10 and the second end 20 are remote from each other and the first control device 31 is deployed in a location that is relatively far away from both the first end 10 and the second end 20, then: the first control device 31 uses the TCP / IP protocol to establish a network connection with the first end 10 and the second end 20 respectively.
[0325] The following takes the connection between the first terminal 10 and the first control device 31 via a USB interface as an example to describe in detail the specific implementation of the first terminal 10 accessing the first control device 31 .
[0326] Before introducing the specific implementation of the first terminal 10 accessing the first control device 31, we first introduce the configuration file that needs to be pre-created for the first terminal 10. As shown in Figure 9, the configuration file pre-created for the first terminal 10 contains at least the following content information: device access configuration information, data transmission and exchange configuration information, and data transmission security control information;
[0327] 1. Device access configuration information, including but not limited to the following:
[0328] 1) A descriptor set for controlling a device, including but not limited to the following:
[0329] ① Device descriptors, such as the class code and protocol used by the control device (such as TCP / IP protocol, USB protocol, Bluetooth protocol, etc.), the manufacturer ID, device ID, and product model ID of the control device.
[0330] ② Configuration descriptors, such as the number of interfaces of the control device, the properties of the control device (such as current requirements), etc.
[0331] ③Interface descriptors, such as the interface type and the protocol used by the interface (for example, the USB interface uses the USB protocol, the network interface uses the TCP / IP protocol, etc.).
[0332] ④ Endpoint descriptors, such as: a set of endpoints with enabled transmission directions of IN, OUT, or IN / OUT, as well as attribute information (or configuration information, such as endpoint number, endpoint type, etc.) of each endpoint, and transmission mode (for example, taking the USB protocol as an example, it can include control transmission, bulk transmission, interrupt transmission, isochronous transmission, etc.). It should be noted that a control device can have multiple groups of IN / OUT endpoints, such as 5 groups, 5 IN endpoints (input endpoints) and 5 OUT endpoints (output endpoints), or asymmetric, such as 3 IN endpoints and 7 OUT endpoints, for high-speed data transmission; it can also have only IN endpoints or only OUT endpoints for unidirectional data transmission, which is not limited here.
[0333] ⑤String descriptor, which is a string related to display, such as the manufacturer name, device name, device product name, etc. corresponding to the displayed control device.
[0334] 2) Connection verification information (or access verification information)
[0335] The connection verification information includes a first verification value (verification value 1) and a second verification value (verification value 2), which are used for mutual verification when the corresponding end (e.g., the first end) connects to the corresponding control device. For example, referring to Figure 4a, during the process of establishing a communication connection between the first end 10 and the first control device 31, the first end 10 sends the first verification value to the first control device 31 for matching verification. In response, when the first control device 31 determines that the received first verification value meets the preset requirements, it will feedback the second verification value to the first end 10.
[0336] 3) Login credential information. Login credential information includes the following items:
[0337] The verification information corresponding to the device driver of the control device, such as the device driver's account and password, is used to verify the login credentials automatically sent by the corresponding end (i.e., the verification information corresponding to the device driver) when the corresponding end establishes a communication connection with the corresponding control device.
[0338] Verification information related to the application that the user enters to control the device, such as the user's user account and password, or the user's fingerprint, voiceprint, portrait and other biometric data, so that the login credentials entered by the user on the corresponding end can be verified.
[0339] 2. Data transmission and exchange configuration information may include, but is not limited to, the following items:
[0340] 1) A set of transmission transaction attribute information of multiple supported transmission transactions, which is used by the corresponding end to create a corresponding transmission transaction when transmitting data to its peer end. For details about the transmission transaction attribute information set, see Table 1b.
[0341] 2) A preset string transmission transaction set can be understood as a set of transmission transactions associated (or bound) with a preset string. In other words, a preset string corresponds to one or more (two or more) transmission transactions for data transmission interaction and verification. A preset string is a string preset for a pre-registered service (or service available) on the corresponding end.
[0342] In one embodiment, the preset string can be a randomly generated, irregular (or irregular) random string or binary value, which has the effect of hiding the address information of the corresponding terminal or making it impossible to infer the target address access method. For example, referring to FIG4b and taking the example of a first terminal 10 communicating with a first control device 31 via a USB interface, assuming that a file exchange service is pre-registered on the first terminal 10, and the file exchange service points to the first control device 31 with a network address of 192.***.1.2 and an endpoint number of 1, and the file exchange service authorizes the second terminal 20 to access it, then a second preset string C corresponding to the first terminal 10 can be preset for the service pre-registered on the first terminal 10. The associated information associated with the second preset string C may include, but is not limited to: the address information of the first terminal 10, the file exchange service, and the access permission information (such as the IP address of the second terminal), wherein the address information of the first terminal 10 points to the IP address of the first control device 31 (192.***.1.2:1). Furthermore, if the data interaction allowed under the above-mentioned file exchange service includes requesting network file resources from the second end and uploading jpg files to the second end, it can be understood that the file exchange service includes a "request network file resources" transmission transaction and a "upload jpg file" transmission transaction, then the transmission transaction bound to the second preset string C corresponding to the first end 10 is the "request network file resources" transmission transaction and the "upload jpg file" transmission transaction. In other words, there is a correspondence between the preset string C corresponding to the first end 10 and the two transmission transactions of "request network file resources" transmission transaction and "upload jpg file" transmission transaction.
[0343] In another example, as shown in FIG4a , the preset string may not conceal the address information of the corresponding end and may directly represent the address information of the corresponding end (e.g., IP address). For example, continuing with the example in 2) above, the second preset string C corresponding to the first end 10 may also refer to 192.***.1.2:1. As a preferred example, this embodiment preferably selects a randomly generated preset string as the preset string, which can be used to conceal the address information of the corresponding end.
[0344] In summary, the preset string corresponding to the first end is called the second preset string. Taking the first end as an example, the transmission transaction set of the second preset string for the first end (or the corresponding relationship between the second preset string and the transmission transaction) can be seen in the following Table 5:
[0345] Table 5 Transmission transaction set of the second preset character string
[0346] It should be noted that, in order to facilitate the query of the corresponding transmission transaction attribute information, the transmission transaction set of the second preset character string shown in Table 5 above may also include a transaction attribute identifier of the transmission transaction. That is, the data storage format in the transmission transaction set of the second preset character string may be, but is not limited to, the following formats:
[0347] [Second preset character string: transmission transaction name (or transaction type): transaction attribute identifier]
[0348] Through this format, the corresponding relationship between the second preset character string and the preset transaction type, as well as the corresponding relationship between the transaction type and the transaction attribute identifier can be represented.
[0349] 3) Communication configuration set of preset strings,
[0350] Configure communication for a preset string. The configured information includes but is not limited to:
[0351] ① The network interface number of the corresponding end to which the preset string is bound (if the corresponding end has multiple network cards, the network interface numbers of multiple network cards can be bound), which is used to establish a physical communication connection with the network interface of the corresponding end. For example, continuing with the example in 2) above, the network interface number bound to a second preset string C can be the network interface number corresponding to the network card of the first end.
[0352] ② The target address information (e.g., domain name or IP, port number, MAC address, host name, etc.) bound to the preset string is used to exchange data with the corresponding network target. For example, continuing with the above example 2), a second preset string C can also be bound to the IP address corresponding to the second end, the target domain name of the target website deployed on the second end, such as www.####.com, and so on.
[0353] ③ is the device endpoint number bound to the preset string, used for data exchange with the connected end (e.g., client or server). For example, continuing with the example in 2) above and referring to Figure 4b, a second preset string C can be bound to an endpoint number, such as the OUT endpoint, of the first control device 31, such as endpoint number 1 in the example in 2) above.
[0354] In addition to binding the above-mentioned communication information to the preset string, other information can also be bound, such as communication capability information (or data transmission direction control capability information (which may be referred to as data transmission direction control information)), string alias information of the preset string, and preset string remark information. The above-mentioned data transmission direction control information is used to indicate any one of the following: only allowing the control device to forward messages to the target end (such as the second end), prohibiting the control device from forwarding messages to the target end, allowing the control device to forward messages to the target end, and allowing the control device to forward messages sent by the target device. The above-mentioned string alias information of the preset string is used to hide the real preset string and can be used when encrypting the message.
[0355] The following is an example of communication configuration information of the second preset string corresponding to the first end, taking the first end as the client and the second end as the server as an example (Note: the content after the symbol " / / " is an explanation of the corresponding configuration item).
[0356] Example 11
[0357] "Second preset string comment": "Client one-way upload (uplink)"
[0358] "Second preset string": "0x0A" / / Actually, it is a long byte string or binary value generated randomly or according to specific rules
[0359] "Destination address": "192.###.1.1:8000" / / Destination IP address and port of communication, such as the IP address and port number of the server
[0360] "Communication capability information": "TX" / / represents data transmission only. In other words, the control device connected to the client is only allowed to forward (or upload) the data sent by the first end to the server. If the server returns the corresponding data, the control device connected to the client will not send the data returned by the server to the client.
[0361] "Submitted parameters": [{"token":"Control****=###1" / / Parameter data uploaded by the control device connected to the client to the server (optional). The parameter data includes the data received from the client and some data of the control device}];
[0362] "String alias information": ["0x1A", "0x2A", "0x3A"] / / The alias of the second preset string is used to hide the real 0x0A string. For example, 0x1A sent by the client or the control device connected to the client is equal to 0x0A
[0363] Example 12
[0364] "Second preset string note": "Client one-way download (downlink), that is, the client receives data"
[0365] "Second preset string": "0x0B"
[0366] "Destination address": "192.###.1.2:8001"
[0367] "Communication Capability Information": "RX" / / Indicates data reception only (i.e., one-way data download). The client-connected control device can periodically request data from the server using a preset request method and related parameters. It then stores the received data locally (such as a memory buffer or external storage area) pending further client requests. Even if the client actively sends request parameter data, the client-connected control device will not forward the received client request parameter data to the server. In other words, the client-connected control device is prohibited from forwarding data (such as messages) received from the client to the server.
[0368] "Submitted parameters": [
[0369] {"token":"Control****=###1",
[0370] "query":"getDataID=1" / / is a preset query parameter used to obtain data from the server. Since the client cannot upload data (including query data parameters) when downloading data using one-way transmission, or even if the client actively uploads query data parameters, the control device connected to the client will not forward them to the server. Therefore, in order to obtain data from the server, the corresponding query parameters will be preset in the control device connected to the client, and the control device connected to the client will automatically submit them to the server. Here, getDataID=1 means sending a query request with the getDataID parameter value 1.
[0371] "setTime": "1000" / / Time to automatically submit query parameters, in milliseconds}]
[0372] "String alias information": ["0x1B", "0x2B", "0x3B"] / / Alias of the second preset string
[0373] Example 13
[0374] "Second preset string note": "Client bidirectional transmission"
[0375] "Second preset character": "0x0C"
[0376] "Destination Address":"192.168.1.3:8002"
[0377] "Communication capability information": "RXTX" / / represents the ability to both receive and send data. This means that the control device connected to the client is allowed to forward data (or messages) to the target end (such as the server), and the control device connected to the client is allowed to forward data received from the target end to the client.
[0378] "Submitted parameters": [{"token":"Control****=###1" / / For two-way transmission and one-way download, the query and setTime parameters mentioned above can be omitted}]
[0379] "String alias information": ["0x1C","0x2C","0x3C"]
[0380] 3. Data transmission security control information may include, but is not limited to, the following items:
[0381] 1) A blacklist / whitelist of network communications that is bound (or associated) to a preset string, for example, an IP address or port number that is allowed or blocked.
[0382] 2) A blacklist / whitelist of interfaces and endpoint numbers bound to a preset string. For example, under this preset string, operations on the IN endpoint, OUT endpoint, or IN / OUT endpoint of the corresponding control device are allowed or blocked.
[0383] 3) Blacklist / whitelist of transfer transactions bound to a preset string. For example, under this preset string, data interactions corresponding to specific transfer transactions are allowed or blocked. For example, transfer transactions with the file type .exe are prohibited, or only transfer transactions with the file types DOC and XLS are allowed.
[0384] 3) Data backup conditions for backing up data flows corresponding to transmission transactions in the control device, such as "important", Excel files, etc.
[0385] 4) The data type information allowed / blocked to be transmitted, the message structure of the transmission complies with the preset rules, the transmission transaction attributes contained in the transmission message comply with the preset, the preset character string complies with the preset, etc.
[0386] It should be noted here that the configuration file pre-created for the first end 10 mentioned above can be a file in any format, such as JSON (JavaScript Object Notation, JS object notation, a lightweight data exchange format), HSON, XML (Extensible Markup Language) YAML (a data description language similar to the subset of Standard Generalized Markup Language XML), binary data structure, PROPERTIES and other files; or executable scripts, etc. This embodiment does not limit the format of the configuration file. The configuration file can be generated by a user with administrative authority using editing software (such as a configuration file editor) in a static manual editing manner; or it can also be automatically generated by clicking on the corresponding configuration interface, etc., which is not limited here.
[0387] With reference to the configuration file pre-created for the first terminal 20 described above, a corresponding configuration file may also be pre-created for the second terminal. Specifically, the contents of the configuration file pre-created for the second terminal may be referenced to the contents of the configuration file pre-created for the first terminal 10, and will not be further detailed here.
[0388] The following is an example of communication configuration information of the first preset string corresponding to the second end, taking the first end as the client and the second end as the server as an example (Note: the content after the symbol " / / " is an explanation of the corresponding configuration item).
[0389] Example 21
[0390] "First preset string comment": "8000" / / 8000 server sends data in one direction (uplink)
[0391] "First Preset String": "0x0A" / / Note: Although the first preset string corresponding to the server here is the same as the second preset string corresponding to the client in Example 11 above (including string alias information), they are actually different. The first preset string only applies to communication between the server and its connected control device, while the second preset string only applies to communication between the client and its connected control device. Therefore, the first preset string and the second preset string can be the same or different.
[0392] "Monitoring Number": "8000" / / The number that the server monitors (such as the number corresponding to the control device connected to it), used for network services
[0393] "Communication capability information": "TX" / / represents sending data only
[0394] "Submitted parameters": [{"token":"Control****=###t2",
[0395] "check":"getDataID=1" / / The control device connected to the server is used to verify parameter data (optional). Because the server cannot receive data after the client connects when using one-way upload from the server, the judgment logic after the server receives client data is preset in the control device connected to the server. After the connected control device makes a judgment, it extracts the data in the data buffer and uploads it to the client (the buffer data is sent in advance by the server to its corresponding connected control device). Here, it is used to determine whether getDataID is equal to 1; it can also be used as a parameter for database or buffer data query.}];
[0396] "Character string alias information": ["0x1A","0x2A","0x3A"]
[0397] Example 22
[0398] "First preset string note": "8001 server one-way reception (downlink)"
[0399] "First preset character": "0x0B"
[0400] "Monitoring Number": "8001"
[0401] "Communication capability information": "RX" / / represents only receiving data
[0402] "Submitted parameters": [{"token":"Control****=###2,
[0403] "answer": "ACK" / / The server automatically responds after receiving data from the client (optional). Because the server cannot send data after the client connects when using one-way download from the server, the data to be responded to is pre-set in the connected control device.}],
[0404] "Character string alias information": ["0x1B", "0x2B", "0x3B"]
[0405] Example 23
[0406] "First preset string note": "8002 server-side two-way transmission"
[0407] "First preset string": "0x0C"
[0408] "Monitoring Number": "8002"
[0409] "Communication capability information": "RXTX" / / represents the ability to receive and send data at the same time
[0410] "Submitted parameters": [{"token":"Control****=###2" / / Since the upload or download of the server depends on the connection with the client, the setTime automatic sending is optional here}
[0411] "Character string alias information": ["0x1C", "0x2C", "0x3C"]
[0412] For details not detailed in Examples 21 to 23 above, please refer to the corresponding contents of Examples 11 to 13, and also refer to Figures 19a and 18b, and S201-S2012 of this application for controlling the communication capabilities, and also refer to the relevant contents of this application regarding limiting the enabling (startup) or response timing of specific communication nodes. In addition, the configuration file pre-configured for the first end 10 and the configuration file pre-configured for the second end can also be integrated into the same configuration file, which is not limited here.
[0413] After the configuration file is created, it can be sent to the corresponding control device in the following three ways.
[0414] Method 1: Offline distribution (manual copy) method. Specifically, the configuration file can be encrypted (stored in a distributor (such as a physical device similar to a USB flash drive), and connected to the corresponding control device for distribution through offline distribution (manual copy), wherein. The configuration file can be a set of configuration files of the first end and the second end, specifically, it can be a set of configuration files of the server and all clients. In specific implementation, for example, a normal copy method can be adopted, after the distributor is connected (i.e., connected) to the corresponding control device, the corresponding configuration file is manually selected and copied to the corresponding control device, such as the configuration file configured for the first end 10 as described above can be copied to the control device connected to the first end 10. For another example, automatic distribution can be performed through the distributor, specifically, as shown in Figure 4b, when the distributor (not shown in the figure) ) is connected to the first control device 31 connected to the first end, the distributor can match the device hardware feature identifier (such as the device ID) sent by the first control device 31, and return the configuration file corresponding to the first control device 31 (such as the configuration file pre-created for the first end 10 and the configuration file pre-created for the second end 20). After receiving the corresponding configuration file, the first control device 31 verifies and decrypts it, and after confirming that it is authentic and valid, it sets the first control device 31 according to the configuration file. In this way, it can be ensured that after the configuration file is generated and before the control device recognizes it, the configuration file is encrypted and signed with a certificate, and cannot be stolen or tampered with. The user of the distributor cannot obtain the configuration file information, which can ensure the security of the configuration file.
[0415] Method 2: Network distribution. The configuration file can be encrypted and stored in a configuration server (such as a TFTP (Trivial File Transfer Protocol) server, which is a file download server), and the configuration file can be encrypted and distributed using the original network configuration or by establishing a second network physical interface (secure control network). Specifically, in one instance, a full-distribution network distribution method can be adopted. For example, after receiving a configuration data request parameter sent by the control device connected to the first end, the configuration server can send all corresponding configuration files to the control device connected to the first end at one time. In another instance, an on-demand distribution network distribution method can be adopted, that is, through the network, the required configuration data can be issued in real time according to the request parameters received from the corresponding control device, such as the connection verification information such as the first verification value and the second verification value in the corresponding configuration file, login credentials and other important data.
[0416] Method 3: Other wireless distribution methods: The distribution terminal or control device encrypts the configuration data and shares the configuration data based on wireless signals such as Bluetooth, LoRa, and WiFi.
[0417] In addition, the following two points need to be further explained for the configuration file:
[0418] P1. The transmission configuration information can exist in the form of configuration data, which can be hard-coded in the firmware program (e.g., before leaving the factory). Hard coding refers to embedding data directly into the program code during software development. Using this hard-coding approach, when the transmission configuration information needs to be updated, it can be updated uniformly according to the firmware program, thereby achieving a unified update of the firmware program and the transmission configuration information. The control device can include the firmware program. Alternatively, the transmission configuration information can exist in the form of files, binary data, etc., so that when the transmission configuration information needs to be updated, only the corresponding files, binary data, etc. can be updated to obtain the updated transmission configuration information and send it to the control device.
[0419] P2. If the transmission configuration information contains multiple configuration information configured for a certain end (such as the first end), the multiple configuration information can be switched back and forth according to the preset switching conditions. The preset switching conditions include external switching conditions and internal switching conditions. The external switching conditions include but are not limited to at least one of the following: receiving a switching instruction sent by the data end (such as the first end, the second end), the configuration server, etc., and detecting that the switching interaction function on the control device is triggered; wherein the switching interaction function on the control device includes but is not limited to switching interactive physical controls and voice functions. The internal switching conditions include but are not limited to: GPS information, clock information, etc. of the control device. For how to implement switching, please refer to the relevant content described in combination with Table 17c in other embodiments (such as the example B11 given), which will not be repeated here.
[0420] Furthermore, the control device can synchronize some of the configuration data in the configuration file to the corresponding connected end. For example, referring to Figure 4b, taking the first end 10 as the client, after the first control device 31 connected to the client completes the configuration according to the corresponding configuration file, when the client requests to update the configuration status, the first control device 31 can send the client name, the client's corresponding preset string and access credentials (such as a 2048-byte random number), the client's corresponding preset string, the correspondence between the preset string, the transaction attribute name (or transaction type) and the transaction attribute identifier to the client, so that the client can register with the device driver installed on it (the device driver of the first control device 31, see Figure 6a), and subsequently the application on it can call it through the device driver's API (Application Programming Interface). There can be multiple access credentials (for example, credential 1 is used for data encryption and decryption, and credential 2 is used for communication verification), for example, a password for subsequent communication between the client and the first control device 31. The credentials are recorded by the device driver and used for encryption or decryption when the first control device sends or receives data, which also prevents other applications from bypassing the device driver to send or receive data to the first control device 31.
[0421] After the configuration file described above is sent, the control device and the corresponding terminal can establish a communication connection based on the configuration data (such as the configuration file data) stored in the device.
[0422] Example 1, continuing with FIG4b , assume that the first terminal 10 is connected to the first control device 31 via a USB interface, and the first terminal 10 and the first control device 31 are in a master-slave mode, that is, the first terminal 10 is the master and the first control device 31 is the slave. Referring to FIG10 , which shows a schematic diagram of the principle of establishing a communication connection between a control device and a corresponding terminal, the specific process of establishing a communication connection between the first control device 31 and the first terminal 10 (or the first control device 31 accessing the first terminal 10) can be as follows:
[0423] When the first control device 31 (slave) is powered on and started, it will first read the relevant configuration data used to establish the connection (the device access configuration information mentioned above), such as a descriptor set (such as the device descriptor, configuration descriptor, endpoint descriptor, string descriptor, etc. of the first control device), endpoint activation information (such as setting up to use 6 endpoints, namely endpoint 1 to endpoint 6, where, for example, the 6 endpoints can all be unidirectional endpoints (such as endpoint 1 to endpoint 3 are OUT endpoints, and endpoint 4 to endpoint 6 are IN endpoints), or, for example, the 6 groups of endpoints can all be bidirectional endpoints (i.e., IN / OUT endpoints)), relevant verification information (such as connection verification information (such as a first verification value and a second verification value), device driver verification information (such as the device driver account and password, etc.), the user account and password of the user corresponding to the first end, etc.);
[0424] After the relevant configuration data is read, the first control device 31 sends a signal to the first terminal 10 (host) to start enumeration, and enters the enumeration process of the standard request of the USB protocol rules. Specifically, the enumeration process of the standard request includes the following steps:
[0425] Step 11: The first end 10 (host) sends a command to obtain a device descriptor to the first control device 31 (slave). In response, the first control device 31 returns a corresponding device descriptor (such as the ID of the first control device 31 and the manufacturer ID).
[0426] Step 12: The first terminal 10 sends a setting address instruction to the first control device 31, where the setting address instruction carries the corresponding address; the first control device 31 responds to the setting address instruction and performs settings according to the corresponding address;
[0427] Step 13: The first end 10 sends an instruction to obtain a device descriptor again; accordingly, the first control device 31 returns the device descriptor to the first end 10;
[0428] Step 14: The first end 10 sends a command to obtain a configuration descriptor to the first control device 31; accordingly, the first end returns a configuration descriptor to the first end 10 in response to the command.
[0429] Step 15: The first terminal 10 sends a command for obtaining a string descriptor to the first control device 31; accordingly, the first terminal returns a string descriptor to the first terminal 10 in response to the command for obtaining a string descriptor.
[0430] Step 16: The first terminal 10 sends a related setting instruction to the first control device 31; accordingly, the first control device responds to the setting instruction, performs settings, and starts the transmission endpoint.
[0431] It should be noted that the order of enumeration in the above-mentioned standard request enumeration process may not be the same as that in steps 11 to 15 described above. The order may be changed according to the operating system of the first end, for example, the order of steps 13 to 15 may be changed. For a detailed description of the returned device descriptors, configuration descriptors, string descriptors, etc., please refer to the relevant content above.
[0432] After the standard request enumeration process is completed, the enumeration process for the special request for the first control device will be further entered. The special request enumeration process may include the following steps:
[0433] Step 21: The first end 10 (host) sends a verification instruction (carrying a first verification value, for example) to the first control device 31 (slave); in response, the first control device 31 returns a second verification value to the first end 10;
[0434] Step 22: The first terminal 10 sends the device driver account and password to the first control device 31; accordingly, the first control device 31 returns a verification success or failure code to the first terminal 10;
[0435] Step 23: The first terminal 10 determines the result returned by the first control device 31 in step 22. If the result meets a specific result (e.g., verification is successful), the enumeration is considered successful and the terminal enters a standby state, waiting for data exchange with the first terminal 10.
[0436] Step 24: The first end 10 sends a test data packet or a heartbeat packet, such as a TEST string or binary data; accordingly, the first control device 31 returns a normal status to the first end 10;
[0437] Step 25 : The first terminal 10 sends the user account and password input by the user to the first control device 31 ; correspondingly, the first control device 31 returns a verification success or failure code to the first terminal 10 .
[0438] It should be noted here that the first control device 31 receives the device driver account and password sent by the first end 10 and the user account and password entered by the user. The first control device 31 can verify it locally according to the preset information, or it can use the remote server to verify it, which is not limited here.
[0439] Furthermore, the first control device 31 can determine whether the first end has been successfully enumerated based on the verification result and the instruction sent by the first end 10. For example, after the first control device 31 completes the verification in step 25 above, the first end 10 will continue to periodically send heartbeat packets in the standby state to inquire whether the first control device 31 is ready to exchange data. If the first control device 31 receives the heartbeat packet, it can be considered that the first end 10 has been successfully enumerated.
[0440] Furthermore, the first control device 31 may also send a signal indicating that the first end 10 is enumerated successfully (or failed) to the second end 20 (eg, the server), so as to inform the second end 20 that the first end 10 can perform data interaction.
[0441] Based on the above, if a communication connection is successfully established between the first terminal 10 and the first control device 31, the data exchange (i.e., data transmission) process begins, i.e., the data exchange waiting state is entered. During the data exchange process, data transmission is indicated by token packets (e.g., OUT token packets and IN token packets). For more information about token packets, please refer to the relevant content below.
[0442] The specific implementation of the first end 10 establishing a communication connection with the first control device 31 through other types of interfaces is similar to the above-mentioned establishment of a communication connection with the first control device through the USB interface, except that: when establishing a communication connection with the first control device through other types of interfaces such as a Bluetooth interface (or TCP / IP protocol), a PCIE interface or a SATA interface, the enumeration process of the USB protocol standard request shown in Figure 10 needs to be replaced with the standard communication handshake process of the interface protocol rules of the corresponding type of interface.
[0443] Example 2, continuing to refer to Figure 4b, assuming that the first end 10 establishes a communication connection with the first control device 31 through the Bluetooth interface, the process of establishing the communication connection can be as follows: the first end 10 can first read the relevant configuration data required to establish the connection, such as pairing connection parameters. The pairing connection parameters can include Bluetooth-related parameters of the first control device 31, such as the Bluetooth device name (device name of the first control device), Mac address, pairing verification information (such as a pre-configured pairing password credential, which can be the verification value (first verification value, second verification value) mentioned above), etc.; then, according to the standard communication handshake process of the Bluetooth protocol, start automatically scanning the first control device based on the pairing connection parameters (specifically, such as the Bluetooth device name, Mac address); when the first control device is scanned, the first verification value can be sent to the first control device for pairing verification, and if the verification is passed based on the feedback information returned by the first control device, it is determined that the pairing is successful and a communication link is successfully established with the first control device.
[0444] The above examples 1 and 2 are both described from the perspective that the first control device 31 is an external device of the first end 10, and the communication connection between the two is established. If the first control device 31 is an internal device of the first end 10, for example 3: Assuming that the first end 10 is connected to the first control device 31 via a PCIE interface, the implementation process of establishing a communication connection between the two can be as follows: the first end 10 scans the first control device based on the pre-configured characteristic parameters of the PCIE interface of the first control device, such as VID (Vendor Identification); and after scanning the first control device, it can perform connection verification with the first control device based on the pre-configured connection verification information (such as password credentials) read. After the verification is passed, a communication link is successfully established with the first control device.
[0445] Regarding the specific implementation of establishing the communication connection between the first control device 31 and the second end 20, please refer to the above-mentioned process of establishing the communication connection between the first end 10 and the first control device 31.
[0446] In summary, in the case where the system provided in this embodiment further includes a first control device 31, and the first end control 31 is an external device of the first end 10,
[0447] If the first terminal 10 communicates with the first control device via a first communication method, where the first communication method uses an external wired communication protocol (such as a USB protocol, where the signaling is a token packet) that is transmitted using signaling instructions, then
[0448] The first terminal 10 may also be configured to: when establishing a communication connection with the first control device 31, send connection verification information to the first control device, the connection verification information including at least one of the following: a verification instruction carrying a verification value, and verification data related to a device driver of the first control device;
[0449] The first control device 31 is configured to feed back a corresponding verification result to the first end based on the connection verification information;
[0450] The first end 10 is further configured to determine whether to establish a communication link with the first control device based on the verification result.
[0451] In a specific embodiment, the verification value carried in the verification instruction can be the first verification value (or second verification value) described above, or verification data related to the device driver, such as the device driver's account number and password. For the specific implementation of establishing a communication connection between the first terminal 10 and the first control device, please refer to the content related to Example 1 described above.
[0452] After the communication link is successfully established, the first end 10 can use the communication link established with the first control device 31 to send the generated first message to the first end 10 through the first control device 31. Based on this, in this case, when the first end 10 is used to send the first message to the second end 20, it can specifically be used to: obtain a first signaling that instructs the first control device to receive the message; send the first signaling and the first message to the first control device via the communication link with the first control device;
[0453] Correspondingly, the first control device 31 is configured to receive the first message in response to the first signaling; and send the first message to the second end.
[0454] In specific implementations, signaling is initiated by the first terminal 10 and is used to inform the first control device 31 of the next task to be performed, such as sending or receiving a message. The type of signaling depends on the communication protocol used between the first terminal 10 and the first control device 31. For example, if the USB protocol is used, the signaling takes the form of a token packet (sent by the host (e.g., the first terminal) to initiate a USB transmission). In this example, the first signaling may be an OUT token packet (also called an OUT output data packet), which is used to notify the first control device 31 that the first terminal 10 is about to send it a data packet and is ready to receive it. When the first terminal 10 needs to send the corresponding OUT token packet and the corresponding first message to the first control device 31, it can first determine the second preset string that has a corresponding relationship with the transmission transaction to which the first data stream belongs based on the preset correspondence between the second preset string and the transmission transaction (such as shown in Table 5); then, based on the association information associated with the second preset string, determine the endpoint number of the first control device 31 bound to the second preset string; finally, according to the determined endpoint number, send the OUT token packet and the corresponding first message to the corresponding endpoint of the first control device 31. For example, continuing with the example of endpoint activation information of the first control device 31 given above when describing the establishment of a communication connection between the first terminal 10 and the first control device 31, the determined endpoint can be, for example, endpoint 1 (an OUT endpoint or an IN / OUT endpoint). By monitoring endpoint 1, for example, the first control device 31 can obtain data such as the OUT token packet and the first message that arrive at endpoint 1, and in response to the obtained OUT token packet, execute the operation of forwarding the first message to the second terminal.
[0455] If the first end communicates with the first control device via a second communication method, and the second communication method uses a wireless communication protocol for pairing connection (such as Bluetooth protocol), then
[0456] The first end 10 may also be configured to: when establishing a communication connection with the first control device, search for the first control device according to preset control device pairing connection parameters; upon finding the first control device, perform a pairing verification with the first control device; and, after the pairing verification passes, establish a communication link with the first control device. For details on how the first end 10 establishes a communication link with the first control device in this case, please refer to the above content related to Example 2.
[0457] Correspondingly, the first end 10 can utilize the communication link established with the first control device 31 to send the generated first message to be sent to the first end 10 through the first control device 31. For the specific implementation of the sending, refer to the relevant content of the above description of the first end 10 communicating with the first control device through the first communication method.
[0458] In the case where the system provided in this embodiment further includes a first control device 31, and the first end control 31 is an internal device of the first end 10, then
[0459] The first terminal 10 communicates with the first control device 31 via a third communication method, where the third communication method uses an internal wired communication protocol (such as a PCIE protocol corresponding to a PCIE interface); and in this case,
[0460] The first end 10 may also be configured to: when establishing a communication connection with the first control device, scan for the first control device based on preset control device characteristic information; and upon detecting the first control device, establish a communication link with the first control device. For details on how the first end establishes a communication link with the first control device in this case, see Example 3 above.
[0461] Correspondingly, the first end 10 can utilize the communication link established with the first control device 31 to send the generated first message to be sent to the first end 10 through the first control device 31. For the specific implementation of the sending, refer to the relevant content of the above description of the first end 10 communicating with the first control device through the first communication method.
[0462] To ensure data security, the first control device 31 may verify the first message using the data transmission security control information in the corresponding configuration file (the configuration file created for the first end 10 described above) before forwarding the received first message to the second end 20. If the verification passes, the first message forwarding operation is performed. Based on this, the first control device 31 may also be configured to perform the following steps:
[0463] S11. Obtaining preset data transmission security control information;
[0464] S12. Verify the first message according to the data transmission security control information;
[0465] S13. If the verification passes, triggering the operation of sending the first message to the second terminal 20;
[0466] S14. If the verification fails, the first message is not sent, or an inquiry message is output to inquire the user whether to allow the first message to be transmitted.
[0467] For the specific content that the data transmission security control information in the above S11 may include, please refer to the relevant content above.
[0468] In the above S12, based on the data transmission security control information, at least one of the following items may be verified, but not limited to:
[0469] Whether the endpoint sending the first message (such as endpoint 1 described in the above example) meets the preset requirements of the first preset string corresponding to the first end 10, for example, whether the endpoint number of endpoint 1 is in the endpoint number whitelist bound to the first preset string. If so, it is determined to comply with the preset rules; otherwise, if not, it does not comply with the preset rules.
[0470] Check whether the structure format of the first message meets the requirements, such as whether the message header, data header, etc. meet the preset format requirements.
[0471] Whether the content in the first message meets the requirements. For example, whether the second preset string corresponding to the first end 10 and the first preset string corresponding to the second end 20 contained in the message header (which can be obtained from the transmission transaction attribute information of the first transmission transaction corresponding to the first data stream) meet the preset requirements. For example, if the preset corresponding preset string set contains the second preset string and the first preset string, if so, it means that the first preset string and the second preset string are registered preset strings and meet the preset requirements; otherwise, if not, it means that the first preset string and the second preset string are unregistered preset strings and do not meet the preset requirements. For another example, whether the transaction unique identifier contained in the message header meets the preset requirements, such as whether the preset corresponding transmission transaction attribute information set contains the transaction unique identifier in the message header, if so, it means that the transaction unique identifier in the message header has been registered and meets the requirements; otherwise, if not, the transaction unique identifier contained in the message header is unregistered and does not meet the requirements. For another example, whether the data in the message is the data type specified by the corresponding transmission transaction attribute. For example, if the transmission transaction corresponding to the first data stream is a "request network resources" transmission transaction, then determine whether the first 3 bytes of the data in the message are GET specified in the transmission transaction attribute information of the "request network resources" transmission transaction.
[0472] It should be supplemented here that: the transmission transaction involved in the various embodiments of the context of this application can actually be understood as a kind of penetration indication for data. For example, the transmission attribute name, transaction usage role, transaction attribute type information, etc. contained in the transmission transaction attribute information of the transmission transaction, the transmission attribute name can be transparently transmitted with the data type allowed to be transmitted, the transaction usage role can be transparently transmitted with the identity information of the creation end that is allowed to use this transmission transaction (such as allowing the server to create, or allowing the client to create), and the transaction attribute type information can be transparently transmitted with the direction of allowed data transmission, the data header used when allowing data to be transmitted, the data type allowed to be transmitted, etc. The above-described transmission transaction's transparent transmission indication of data, in other words, is a specific function of the transmission transaction. Therefore, based on the above-mentioned transmission transaction's penetration indication of data, the verification of the first message involved in the various embodiments of the context of this application, such as the verification of the first message by the above-mentioned first control device (or the second control device, first control module, second control module, intermediate network device, etc. described above), from the perspective of the transmission transaction, the verification may include but is not limited to the following items:
[0473] 1) Verify whether the transmission transaction corresponding to the first message is a registered transmission transaction, so as to determine whether the transmission transaction corresponding to the first message meets the requirements based on the verification result. Specifically, the transaction attribute identifier (which is the unique identifier of the transmission transaction) can be parsed from the target header information contained in the first message, and then the transaction attribute identifier contained in the target header information can be searched from the transmission transaction attribute information set to see whether it exists. If it exists, it indicates that the transmission transaction corresponding to the first message has been registered, and the transmission transaction corresponding to the first message meets the requirements. If it meets the requirements, the corresponding forwarding operation (or storage) can be directly performed on the first message, or further verification can be performed. In any case, if it does not exist, it indicates that the transmission transaction corresponding to the first message is not registered, and the transmission transaction corresponding to the first message does not meet the requirements, and the first message will not be forwarded (or stored).
[0474] 2) If the transmission transaction corresponding to the first message is determined to be a registered transmission transaction as verified in 1) above, the format of the target header information may be further verified to see if it meets the preset format requirements. For example, the message header format (or data header format) in the target header information may be verified to see if it meets the preset format requirements. If so, the corresponding forwarding operation (or storage) may be directly performed on the first message, or further verification may be performed. If not, the first message is not forwarded (or stored).
[0475] 3) If the target header information contained in the first message is verified to conform to the preset format requirements as determined in step 2), further verification may be performed to determine whether the current transmission conforms to the corresponding transmission transaction attribute requirements. If so, the corresponding forwarding operation (or storage) may be directly performed on the first message; otherwise, the first message is not forwarded (or stored). This verification may be performed based on the transaction attribute type information obtained from the transmission transaction attribute information of the transmission transaction corresponding to the first message.
[0476] For example, it is checked whether the current transmission direction complies with the data transmission direction specified by the transmission transaction attributes. Specifically, assuming that the previous transmission direction is that the first end sends data to the second end, then: if the data transmission direction included in the transaction attribute type information indicates that the first end can transmit uplink data (i.e., can send data outward), the current transmission direction complies with the data transmission direction specified by the transmission transaction attributes; conversely, if the data transmission direction included in the transaction attribute type information indicates that the first end can only transmit downlink data (i.e., can only receive data), the current transmission direction does not comply with the data transmission direction specified by the transmission transaction attributes.
[0477] For another example, the data type of the currently transmitted data is checked to see if it complies with the data type specified by the transmission transaction attributes. Specifically, assuming the data type of the currently transmitted data is a jpg file, if the data type included in the transaction attribute type information is image, the data type of the currently transmitted data complies with the data type specified by the transmission transaction attributes; conversely, if the data type included in the transaction attribute type information is text, the data type of the currently transmitted data does not comply with the data type specified by the transmission transaction attributes.
[0478] Another example is to verify whether the header information contained in the currently transmitted message meets the requirements specified by the transmission attributes. Specifically, assuming that the currently transmitted message contains a data header and the format of the data header is a common data header format, then: if the data header usage information contained in the transaction attribute type information indicates that a common data header is required, the header information contained in the currently transmitted message meets the requirements specified by the transmission transaction attributes; conversely, if the data header usage information contained in the transaction attribute type information indicates that no data header is required or the data header format is a file data header format, the header information contained in the currently transmitted message does not meet the requirements specified by the transmission transaction attributes.
[0479] In addition to verifying messages, data transparent transmission instructions based on transmission transactions can also be used for, but are not limited to, the following other aspects:
[0480] Used for data backup (backup of important data). Specifically, if the data type allowed to be transmitted through the transmission transaction is an important type (such as a file type), the control device can back up the data in the message.
[0481] Used for transparent transmission display, log retention, and analysis. For example, the control device can display the transaction attribute name of the transmission transaction so that the user can clearly understand the current data transmission through the displayed transaction attribute name. For another example, the control device can record and analyze received messages to generate log information for the corresponding transmission transaction.
[0482] In S13 and S14 above, the first message is verified in step S12. If the verification passes, it indicates that the message meets the preset requirements, and the first control device 31 triggers the operation of sending the first message to the second terminal 20. Conversely, if the verification fails, it indicates that the first message does not meet the preset requirements. If the requirements are not met, in one embodiment, the first message may not be sent, but a log or other processing may still be performed; or, in another embodiment, a query message may be output to inquire whether the user allows the transmission of the first message. For example, if the data in the first message belongs to an executable program file (such as an .exe program) whose transmission is prohibited, the first control device 31 will not automatically perform the transmission operation. Instead, it will output a query message on its display screen (as shown in Figure 7a or Figure 7b) or the first terminal display, asking the user whether to allow the transmission. Only after receiving the user's confirmation transmission instruction in response to the query message will the first control device 31 send the first message to the second terminal 20. This manual confirmation method can prevent the spread of viruses and Trojans.
[0483] In a specific implementation, as shown in FIG4b , when the first control device 31 triggers the sending of the first message to the second end 20, the first control device 31 determines the address information of the second end based on the first preset character string corresponding to the second end obtained from the first message (more specifically, the message header of the first message); and sends the first message to the second end 20 according to the address information of the second end 20. The more specific implementation principle is divided into the following two cases:
[0484] In case 21, if the first preset string is directly the address information of the second end (that is, the preset string mentioned above does not have the address information of the hidden corresponding end), the first control device 31 directly uses the TCP / IP protocol or other corresponding protocols according to the first preset string to send the verified message to the second end 20.
[0485] Case 22: If the first preset string is a preset random string used to hide the address information of the second end. In this case, in this embodiment, the first end 10 is considered an untrusted device and the first control device 31 is considered a trusted device. The purpose of the first preset string is to hide the real address information (such as the IP address) of the second end 20 in the first end 10. In this way, even if the first end 10 is attacked by a malicious person, the malicious person cannot launch a scan or detection attack on the second end 20 or other devices in the network through the first end 10, making it difficult to attack the second end 20. In the above description, the first control device 31 can contain all the data required for data transmission, including the real address information (such as the IP address) of the second end 20. In other words, the configuration files created for the first end 10 and the configuration files created for the second end 20 described above are both preset in the first control device 31. Based on the data information preset in the first control device 31, the first control device 31 can directly obtain the corresponding real address information of the second end 20 according to the first preset string. Alternatively, in other embodiments, the first control device 31 may also send a resolution request to a corresponding resolution server (such as the configuration server described above) for the first preset character to obtain the corresponding real IP address of the second end from the resolution server, which is not specifically limited here.
[0486] After the first control device 31 obtains the real IP address of the second end 20 based on the first preset string, it can use the TCP / IP protocol to send the real IP address of the second end and the corresponding message to the intermediate network device (as shown in Figure 4b), so that the intermediate network device can send the verified first message to the second end 20. Generally, because the first control device 31 has completed the conversion between the first preset string and the real address information of the second end 20, when the first message is forwarded to the second end 20 using the TCP / IP protocol based on the address information of the second end, the forwarded first message does not need to carry the preset string. However, in this embodiment, the first message is kept carrying the preset string, so that the second end 20 can verify the preset string and other information contained in the first message. Or in other embodiments below, such as the case described in other embodiments where there is a first control device 31 and a second control device 32 between the first end 10 and the second end 20 (as shown in Figure 5e), the first control device 31 continues to make the first message carry the corresponding preset string when forwarding the first message, so that the second control device 32 can verify the preset identifier and other information contained in the first message; or when the second control device 32 is connected to multiple second ends 20, it is convenient for the second control device 32 to obtain the address information of the corresponding second end 20 according to the corresponding preset string (first preset string); or it is convenient for the second end 20 to identify a specific program, etc.
[0487] It should be noted that in order to further ensure the security of data transmission, the intermediate network device can also have the function of a control device to verify the received first message again, and send the first message to the second end after the verification is passed. Alternatively, the intermediate network device may only have a log audit function, and can generate log information of the first transmission transaction based on the received first message, and send the first message to the second end. In specific implementation, the above-mentioned functions can be achieved by deploying a fourth control module in the intermediate network device. For a detailed introduction to the fourth control module and the specific implementation of the above-mentioned intermediate network device functions, please refer to the relevant content above.
[0488] Furthermore, in addition to verifying the first message, corresponding data transmission direction control information can also be obtained from the associated information associated with the second preset character string corresponding to the first end, so as to determine whether the first message needs to be forwarded to the second end 20, or whether the second end 20 needs to forward the data fed back in response to the first message to the first end 10, and so on, based on the data transmission direction control information. For example, taking the case where the first transmission transaction corresponding to the first data stream is a "request network resource" transmission transaction, and assuming that the transmission direction control information included in the association information associated with the second preset string corresponding to the first end is "RX" (representing data reception only, in other words, prohibiting the first control device 31 from forwarding received messages sent by the first end to the second end 20, see Example 12 above), in this case, although the first end 10 receives the message sent by the first end 10 for "request network resource", it does not forward the received message to the second end 20 (that is, it does not forward the request parameters actively sent by the first end 10 to the second end 10). Instead, it obtains the corresponding preset request parameter information (including the request method and related parameters) from the association information associated with the corresponding second preset string, generates a new message based on the obtained preset request parameters, and sends the new message to the second end 20. For the specific implementation of the above-mentioned new message generation, see the above-described process of the first end 10 generating the first message to be sent corresponding to the first data. Based on the above example, before triggering the operation of sending the first message to the second end 20, the first control device 31 may further include the following steps:
[0489] S131. Acquire data transmission direction control information from association information associated with a second preset character string corresponding to the first end;
[0490] S132. If the data transmission direction control information indicates that the first control device 31 is prohibited from sending the received first message to the second end, and the message type of the first message is a request message, then obtain the preset request parameters from the associated information; and based on the first target header information obtained from the first message and the preset request parameters, generate a new message to be sent, so as to trigger the operation of sending the first message to the second end 20 based on the new message.
[0491] For the description of the data transmission direction control information, please refer to the content related to Examples 11 to 13 described above. With the above content and in combination with the content related to Examples 11 to 13 described above, the transmission direction control method provided by this embodiment is used to implement, for example, a one-way transmission function of data. Compared with the existing use of one-way transmission equipment to implement one-way transmission functions, it has the following benefits: using one-way transmission equipment (such as optical gates, optical codes (QR codes), etc.) to implement one-way transmission functions, although it can completely isolate two-way transmission physically, the equipment is often more complex. For example, the equipment requires an optical module, a splitter module, or a display or receiving module for an image, etc., with high manufacturing costs, large equipment size, and limited scope of application. Moreover, the use of one-way transmission equipment cannot physically achieve flexible configuration of one-way sending, one-way receiving, or two-way transmission of data according to different service requirements. The direction provided in this embodiment can realize a one-way data transmission function without the aid of any external device. It is simple to construct and the manufacturing cost of the control device is relatively low. In addition, the control device can flexibly adjust the communication direction (i.e., the data transmission direction) corresponding to different preset strings based on the transmission direction control information associated with different preset strings.
[0492] Furthermore, after the first message passes verification, if the data contained in the first message is relatively important, the first control device 31 can also back up the first message to prevent the first end 10 from accidentally deleting the corresponding data or being encrypted by a ransomware virus. Based on this, in the system provided in this embodiment, the first control device 31 can also be used to:
[0493] After the verification is passed, judging whether the first message meets the data backup condition in the data transmission security control information according to the marking information included in the first message;
[0494] If the data backup condition is met, the first message is backed up.
[0495] For example, when the marking information contained in the message header and / or data header of the first message indicates that the data contained in the first message is "important" (such as the data is financial report.xls), the first control device can back up the first message.
[0496] In a second possible embodiment, as shown in FIG5c and FIG5d , in addition to the first control device 31, a second control device 32 may be provided between the first end 10 and the second end 20. The second control device 32 is communicatively connected to the second end 20 and the first control device 31. For details on how to establish a communication connection between the second control device 32 and the second end 20, refer to the process for establishing a communication connection between the first end 10 and the first control device 31 described above.
[0497] Accordingly, the first control device 31 described above determines that the address information of the second end points to the second control device according to the first preset string corresponding to the second end. Based on this, the first control device 31, when used to send the first message to the second end 20, is specifically used to: send the first message to the second control device 32. And
[0498] The second control device 32 is configured to verify the received first message; and after the verification passes, send the first message to the second end in response to the acquisition request sent by the second end.
[0499] In a specific implementation, taking the second end 20 as an example of being connected to the second control device 32 via a USB interface, when the second end 20 needs to obtain data, the acquisition request sent to the second end can be a second signaling. The second signaling is used to instruct the second control device to send data to the second end 20. Specifically, the second signaling can be an IN token packet (also called an IN input data packet). The IN token packet can be understood as an instruction packet used by the host (such as the second end 20) to notify the slave (such as the second control device 32) that a data packet is to be sent to it. In this embodiment, the second control device 32 does not actively send a verified message to the second end. It only sends a message adapted to the request of the second end 20 to the second end after the second end requests it.
[0500] It should be noted that the first control device 31 and the second control device 32 can communicate using, but are not limited to, the TCP / IP protocol. In this case, as shown in FIG5 d , an intermediate network device can be provided between the first control device 31 and the second control device 32. Specifically, the first control device 31 sends the first message to the second control device 32 via the intermediate network device. For the functions of the intermediate network device, please refer to the relevant content described in the first possible embodiment.
[0501] In addition, the above content is mainly explained from the example of the first end needing to send data to the second end. Of course, the second end can also send data to the first end. In this case, the first end 10 can also be used for:
[0502] receiving a second message sent by the second end;
[0503] The second message is generated on the second end based on the second transaction information of the second transmission transaction corresponding to the second data stream, and the corresponding second target header information is determined for the second data block of the second data stream. The second target header information is used to verify whether the second message meets the requirements.
[0504] The second data stream is data generated by the second application on the second end. For a description of the first application and the second data stream, as well as the implementation of the second end generating the second message and sending the second message to the second end, refer to the above-mentioned detailed description of the first application and the second data stream, and the detailed description of the first end generating the first message and sending the first message to the second end, and are not further described here.
[0505] It should be noted that the generation of the second message can be specifically implemented by a third control module on the second end, and the third control module can be located within the second application or outside the second application. When the third control module is located within the second application, a fifth control module can also be provided outside the second application on the second end; or when the third control module is located outside the second application, a fifth control module can also be provided within the second application on the second end. Regarding how the third control module and the fifth control module cooperate to process the second data block and generate the second message when the third control module and the fifth control module coexist, please refer to the other embodiments of the above application regarding the cooperation between the first control module and the second control module on the first end to process the first data block and generate the first message.
[0506] Based on the above-mentioned content related to the data transmission system provided by one embodiment of the present application, several other embodiments of the present application also provide a data transmission system. Specifically,
[0507] FIG3b shows a schematic diagram of the structure of a data transmission system provided by another embodiment of the present application. Referring to FIG3b, the data transmission system includes: a first end 10 and a second end 20, wherein:
[0508] A first end 10 includes a first control module 11 within a first application, the first control module 11 being configured to determine first transaction information of a first transmission transaction corresponding to a first data stream of the first application; when a first data block of the first data stream needs to be transmitted to a second end, determining corresponding first destination header information for the first data block based on the first transaction information; generating a first message to be sent based on the first data block and the first destination header information; and sending the first message to the second end; wherein the first destination header information is used to verify whether the first message meets requirements;
[0509] The second end 20 is provided with a third control module (not shown in the figure), which is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, the first data is obtained and cached from the first message.
[0510] Furthermore, the system provided in this embodiment may further include: an intermediate network device, communicatively connected to the first end and the second end;
[0511] The first control module 11 is specifically configured to send the first message to the intermediate network device;
[0512] The intermediate network device is used to generate log information of the first transmission transaction based on the received first message; and send the first message to the second end.
[0513] FIG3c shows a schematic diagram of the structure of a data transmission system provided by another embodiment of the present application. Referring to FIG3c, the data transmission system includes: a first end 10 and a second end 20, wherein:
[0514] A first end 10 has a second control module 12 provided outside the first application, the second control module 12 being configured to determine, in response to a first data block sent by the first application to be transmitted to the second end, first transaction information of a first transmission transaction to which the first data block belongs; based on the first transaction information, determine corresponding first target header information for the first data block; generate a first message to be sent based on the first data block and the first target header information; and send the first message to the second end; wherein the first target header information is used to verify whether the first message meets the requirements.
[0515] The second end 20 is provided with a third control module (not shown in the figure), which is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, the first data is obtained from the first message.
[0516] Furthermore, the system provided in this embodiment may further include: an intermediate network device, communicatively connected to the first end and the second end;
[0517] The second control module is specifically configured to send the first message to the intermediate network device;
[0518] The intermediate network device is used to generate log information of the first transmission transaction based on the received first message; and send the first message to the second end.
[0519] Another embodiment of the present application provides a schematic diagram of the structure of a data transmission system, the system architecture of which is similar to the architecture shown in FIG3a-1. Specifically, the data transmission system includes: a first end and a second end, wherein:
[0520] The first end is used to send a first data block to be transmitted to the second end to the intermediate network device;
[0521] An intermediate network device is provided with a fourth control module, which is used to receive the first data block and determine the first transaction information of the first transmission transaction to which the first data block belongs; based on the first transaction information, determine the corresponding first target header information for the first data block; generate a first message to be sent according to the first data block and the first target header information; and send the first message to the second end; wherein the first target header information is used to verify whether the first message meets the requirements.
[0522] The second end is provided with a third control module, which is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, obtain the first data from the first message.
[0523] Furthermore, a first control module is provided in the first application on the first end or a second control module is provided outside the first application;
[0524] The first control module or the second control module is configured to send the first data block that the first application needs to transmit to the first end, and transaction attribute information of the first transmission transaction to which the first data block belongs, to the intermediate network device;
[0525] The intermediate network device, when used to determine the first transaction information of the first transmission transaction described in the first data block, is specifically used to: generate a corresponding transaction identifier for the first transmission transaction; and based on the received transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
[0526] It should be noted that, in addition to being able to implement the functions described above, each terminal / device / module in each of the above-mentioned data transmission systems can also implement related functions in other embodiments of the present application. For an introduction to the specific functions that can be implemented by each terminal / device / module in each of the above-mentioned data transmission systems, please refer to the relevant content above.
[0527] Figures 4a to 4c show a schematic diagram of the structure of a data transmission system provided by another embodiment of the present application. As shown in Figures 4a to 4c, the data transmission system includes: a first end 10, a first control device 31 and a second end 20, wherein:
[0528] The first end 10 is configured to send the first data block of the first data stream to the first control device when the first data block needs to be transmitted to the second end;
[0529] The first control device 31 is used to determine the first transaction information of the first transmission transaction corresponding to the first data stream; based on the first transaction information, determine the corresponding first target header information for the received first data block; generate a first message to be sent according to the first data block and the first target header information; and send the first message to the second end; wherein the first target header information is used to verify whether the first message is required.
[0530] The second end 20 is used to verify the target header information included in the received first message to determine whether the first message meets the requirements; if it meets the requirements, obtain and cache the first data block from the first message.
[0531] For a detailed introduction to the first terminal 10, the first control device 31 and the second terminal 20 and the specific implementation of their respective functions, please refer to the relevant content above.
[0532] Figures 5d and 5e show a schematic diagram of the structure of a data transmission system provided by another embodiment of the present application. As shown in Figures 5d to 5e, the data transmission system includes: a first end 10, a first control device 31, a second control device 32 and a second end 20, wherein:
[0533] The first end 10 is configured to send the first data block of the first data stream to the first control device when the first data block needs to be transmitted to the second end;
[0534] a first control device 31, communicatively connected to the first end, configured to determine first transaction information of a first transmission transaction corresponding to the first data stream; determine corresponding first destination header information for the received first data block based on the first transaction information; generate a first message to be sent based on the first data block and the first destination header information; and send the first message to the second control device; wherein the first destination header information is used to verify whether the first message is required;
[0535] a second control device 32, communicatively connected to the first control device and the second end, configured to verify the first destination header information contained in the received first message to determine whether the first message meets requirements; and if so, cache the first message locally for retrieval by the second end;
[0536] The second end 20 is configured to send an acquisition request to the second control device; and receive the first message fed back by the second control device in response to the acquisition request.
[0537] For a detailed introduction to the first terminal 10, the first control device 31, the second control device 22 and the second terminal 20 and the specific implementation of their respective functions, please refer to the relevant content above.
[0538] Other embodiments of the present application also provide corresponding data transmission methods, which are specifically as follows:
[0539] Figure 11a shows a flow chart of a data transmission method provided by an embodiment of the present application. The data transmission method is suitable for the first end 10 shown in Figure 3b, and more specifically, for the first control module 11 in the first application on the first end 10. The preset information pre-set in the first control module 11 includes the configuration file created for the first end 10 as described above, and further, may also include a configuration file created for the second end 20. Taking the configuration file created for the first end as an example, the configuration file may include but is not limited to at least one of the following configuration data: data exchange configuration data, data transmission security control information, etc., wherein the data exchange configuration data may include but is not limited to: transmission transaction attribute information of multiple transmission transactions; the correspondence between the transaction type of the transmission transaction, the second preset string corresponding to the first end, and the transaction attribute identifier of the transmission transaction, wherein the transaction attribute identifier is a unique identifier of the transmission transaction attribute information of the corresponding transmission transaction; a message header format, multiple data header formats, and so on. In this embodiment, the preset character string involved is a character string corresponding to the address information of the corresponding end. For example, the second preset character string corresponding to the first end is a character string corresponding to the address information (such as an IP address) of the second end. For ease of description, this embodiment directly uses the address information of the corresponding end to describe the preset character string. For a detailed introduction to the first control module 11 and the preset information preset in the first control module 11, please refer to the relevant content above and will not be repeated here. As shown in Figure 11a, the data transmission method provided in this embodiment includes the following steps:
[0540] 101. Determine first transaction information of a first transmission transaction corresponding to a first data flow of the first application;
[0541] 102. When a first data block of the first data stream needs to be transmitted to a second end, determine corresponding first target header information for the first data block based on the first transaction information;
[0542] 103. Generate a first message to be sent according to the first data block and the first target header information;
[0543] 104. Send the first message to the second end
[0544] The first target header information is used to verify whether the first message meets the requirements.
[0545] In the above 101, as shown in Figure 3b, the first application on the first end 10 may refer to but is not limited to a business platform system application, a browser application, a social application, a video application, an office application, etc. Different types of first data streams will be generated during the use of different first applications. For example, if the first application is a browser application (modified by security access control and having a first control module therein), and the browser application needs to obtain resources on the second end, then correspondingly, the first data stream of the browser application may be but is not limited to a request data stream (such as a request network resource data stream, etc.). In order to ensure data transmission security and avoid the first application directly and arbitrarily calling the network interface on the first end to send data arbitrarily, the first application must use the first control module 11 therein to implement the call of the network interface on the first end 10 and to send data. In other words, the first data stream of the first application must be processed by the first control module 11 within the first application before it can be sent. During specific implementation, for the first data stream of the first application, the first control module 11 can determine the first transaction information of the first transmission transaction corresponding to the first data stream, so as to process the first data block in the first data stream to be transmitted to the second end 20 based on the first transaction information, thereby realizing the transmission of the first data block. The above-mentioned first transaction information may include the transaction identifier and transmission transaction attribute information of the first transmission transaction, and the transmission transaction attribute information includes but is not limited to: transaction attribute name, first tag information, address information of the second end, transaction attribute identifier, and transaction attribute type information; wherein the transaction attribute type information includes at least one of the following: the transmission direction of the first data stream, the data type of the first data stream, and the data header usage information. For a detailed introduction to the transmission transaction attribute information, please refer to the relevant content in other embodiments above.
[0546] In one possible technical solution, the above-mentioned step 101 of “determining first transaction information of a first transmission transaction corresponding to the first data flow of the application” may specifically include:
[0547] 1010. Generate a corresponding transaction identifier for the first transmission transaction;
[0548] 1011. Obtain transmission transaction attribute information of the first transmission transaction.
[0549] The above-mentioned 1011 “obtaining transmission transaction attribute information of the first transmission transaction” may include:
[0550] 10111. Determine a transaction attribute identifier of the first transmission transaction;
[0551] 10112. Based on the transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
[0552] The above 10111 can determine the transaction attribute identifier of the first transmission transaction based on the preset correspondence between the transaction type and the transaction attribute identifier of the transmission transaction. That is, in a specific implementation scheme, the above 1011 "determining the transaction attribute identifier of the first transmission transaction" can be implemented by the following steps:
[0553] 101111. Determine the transaction type to which the first transmission transaction belongs based on the transmission requirement information of the first data flow;
[0554] 101112. Based on the second correspondence between transaction types and transaction attribute identifiers, determine a transaction attribute identifier that corresponds to the transaction type to which the first transmission transaction belongs.
[0555] For the specific implementation description of the above 101111 to 101112, please refer to the relevant content in other embodiments above.
[0556] In the above-mentioned 10112, the preset multiple transmission transaction attribute information can be referred to as the example set of transmission transaction implementation information for multiple transmission transactions shown in FIG4a. If, based on the transaction attribute identifier of the first transmission transaction corresponding to the first data stream, the transmission transaction attribute information corresponding to the first transmission transaction of the first data stream cannot be retrieved from the preset multiple transmission transaction attribute information, this indicates that the data transmission security control information configured between the first end and the second end according to this embodiment does not allow the transmission of the data block in the first data stream, the data transmission fails, and the transmission is terminated.
[0557] A possible technical solution for implementing the step 102 of “determining corresponding first target header information for the first data block based on the first transaction information” may include the following steps:
[0558] 1021. Obtain a header information transmission mode corresponding to a data block in the first data stream;
[0559] 1022. Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block;
[0560] 1023. Configure a corresponding field value of the target header field according to at least one of the first transaction information and relevant information of the first data block, to obtain a message header determined for the first data block.
[0561] For an introduction to the header information transmission method in the above 1021, please refer to the relevant content above.
[0562] In one possible implementation, the above-mentioned 1022 “determining a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block” may specifically include:
[0563] 10221. Determine, according to the block number of the first data block included in the relevant information, the order of the first data block in the first data stream.
[0564] 10222. If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, then the multiple header fields are the target header fields.
[0565] 10223. If the header information transmission mode is the second mode and the data block is not sorted last in the first data stream, or the header information transmission mode is the third mode and the data block is not sorted first in the first data stream, then some of the multiple header fields are the target header fields.
[0566] It should be noted that in addition to the header information transmission method described in steps 10222 to 10223 above, other header information transmission methods may also be included, such as the fourth method described in conjunction with FIG2b. For a detailed description of the header information transmission method, please refer to the relevant content described in other embodiments with respect to steps S20 to S22 and FIG2b, and will not be further described here.
[0567] In the case described in 10222 above, that is, when the multiple header fields are the target header fields, the above 1023 "configuring a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block" may include:
[0568] 10231. Determine address information of the first end for the first transmission transaction;
[0569] 10232. Configure a corresponding field value of the target header field according to the address information of the first end, the first transaction information, and related information of the first data block, to obtain a first message header determined for the first data block.
[0570] The first message header includes: address information of the first end, address information of the second end, transaction attribute identifier of the first transmission transaction, transaction identifier of the second transmission transaction, total number of data blocks in the first data stream, block number of the first data block, total size of the first target header information and the first data block, and annotation information;
[0571] When the total number is a set value, it indicates that the first data stream is a stream in which the number of data blocks is unknown.
[0572] In a more specific implementation, the above-mentioned step 10231 “determining the address information of the first end for the first transmission transaction” can be implemented by the following steps:
[0573] 102311. Obtain a first correspondence between the address information of the first end and the transaction type;
[0574] 102311. Based on the second corresponding relationship, determine the address information of the first end that has a corresponding relationship with the transaction type to which the transmission transaction belongs.
[0575] For the specific implementation description of the above 102311~102311, please refer to the relevant content in other embodiments above.
[0576] Furthermore, if the first data block is sorted first or last in the first data stream, the above 102 may further include the following steps:
[0577] 1024. Determine whether it is necessary to add a data header to the first data block according to the transaction attribute type information of the first transmission transaction in the first transaction information.
[0578] 1025. When it is determined to be necessary, determine a corresponding data header for the first data block according to the stream information of the first data stream; wherein the data header is adapted to the first data stream and meets preset data header format requirements.
[0579] For the specific implementation description of the above 1024, please refer to the relevant content in other embodiments above.
[0580] A specific implementation of “determining a corresponding data header for the first data block according to the stream information of the first data stream” in 1025 includes:
[0581] 10251. Select an adaptive data header format from a plurality of preset data header formats based on the data header usage information included in the transaction attribute type information;
[0582] 10252. Generate the data header according to the selected data header format based on the flow information of the first data flow.
[0583] In the case described in 10223 above, that is, when some of the multiple header fields are the target header fields, the above 1023 "configuring a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block" may include:
[0584] 10231′. Configuring a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block, including:
[0585] 10232′. Based on the transaction identifier of the first transmission transaction in the first transaction information, configure a corresponding field value of the target header field to obtain a second message header determined for the first data block.
[0586] The second message header includes the transaction identifier.
[0587] A possible technical solution for implementing the step 104 of “sending the first message to the second end” may include the following steps:
[0588] 1041. Send the first message to a second control module. The second control module verifies the first destination header information included in the first message and sends the first message to the second end if the verification finds that the first message meets the requirements.
[0589] The second control module is a module external to the first application on the first end (such as the second control module 12 shown in FIG3 d ).
[0590] For a detailed description of the second control module in 1041 and a detailed implementation of 1041 , please refer to the relevant content above.
[0591] Furthermore, the solution provided in this embodiment may also include:
[0592] 105. Receive a second message sent by the second end;
[0593] The second message is generated by the third control module on the second end based on the second transaction information of the second transmission transaction corresponding to the second data flow of the second application on the second end, by determining corresponding second destination header information for the second data block of the second data flow, and based on the second data block and the second destination header information; the second destination header information is used to verify whether the second message meets the requirements;
[0594] The third control module is located within the second application or outside the second application.
[0595] For a detailed introduction to the third control module, please refer to the relevant content in other embodiments of this application. For the second application and the second message generation, please refer to the detailed introduction to the first application and the first message generation, respectively.
[0596] It should be noted that when the third control module is located within the second application, a fifth control module may be provided outside the second application on the second end. Alternatively, when the third control module is located outside the second application, a fifth control module may be provided within the second application on the second end. For details on how the third and fifth control modules, when coexisting, collaborate to process the second data block, please refer to the other embodiments of the aforementioned application regarding the collaboration between the first and second control modules on the first end to process the first data block.
[0597] In the technical solution provided by this embodiment, when a first end needs to transmit a first data block from a first data stream applied on the first end to a second end, a first control module 11 within the first application on the first end determines corresponding first destination header information for the first data block based on first transaction information corresponding to the first data stream. Furthermore, a corresponding first message to be sent is generated based on the first data block and the first destination header information, and the first message is sent to the second end. The first destination header information is used to verify whether the message meets the requirements, which enables this solution to achieve security management of the transmitted data content at a low cost.
[0598] It should be noted that for any steps not fully described in detail in the data transmission method provided in the embodiments of this application, reference may be made to the corresponding contents in the other embodiments provided in this application, and will not be repeated here. Furthermore, in addition to the aforementioned steps, the method provided in the embodiments of this application may also include some or all of the other steps in the aforementioned embodiments, and for details, reference may be made to the corresponding contents in the aforementioned embodiments, and will not be repeated here.
[0599] Figure 11b shows a flow chart of a data transmission method provided by another embodiment of the present application. This data transmission method is suitable for the first end 10 shown in Figure 3c, and more specifically, for the second control module 12 outside the first application on the first end 10. The second control module 12 will have preset information preset in advance, and the preset information is the information required to implement the data transmission method provided by this embodiment. For the preset information in the second control module 12, please refer to the above description of the preset information preset in the first control module 11. For a detailed introduction to the second control module 12, please refer to the relevant content in other embodiments above, and no further details will be given here. As shown in Figure 11b, the data transmission method provided by this embodiment may include the following steps:
[0600] 201. In response to a first data block to be transmitted to a second end and sent by the first application, determine first transaction information of a first transmission transaction to which the first data block belongs;
[0601] 202. Determine corresponding first target header information for the first data block based on the first transaction information;
[0602] 203. Generate a first message to be sent according to the first data block and the first target header information;
[0603] 204. Send the first message to the second end;
[0604] The first target header information is used to verify whether the first message meets the requirements.
[0605] In the above 201, as shown in FIG3d, a first control module 11 may also be deployed within the first application. For a detailed description of the first control module 11 and the preset information that may be preset therein, please refer to the relevant content in other embodiments above. The first control module 11 may be used to perform a pre-audit (or pre-verification) on the first data block to determine whether the first data block is permitted for transmission. For example, the first control module 11 can audit the data type, transmission transaction, etc. of the received first data block to determine whether they meet the requirements. Specifically, the first control module 11 can audit whether the data type, transmission transaction, etc. of the first data block are allowed to be transmitted based on the data transmission security control information contained in the preset information preset within the first control module 11, such as information on data types allowed / blocked for transmission. If they are allowed to be transmitted, the requirements are met. Alternatively, the first control module 11 can first determine a second preset character string corresponding to the first end for the transmission transaction to which the first data block belongs. Then, the transmission transaction to which the first data block belongs is analyzed based on a transmission transaction blacklist / whitelist bound to the second preset character string corresponding to the first end contained in the preset data transmission security control information. If they are, the requirements are met, etc. For the specific implementation of determining the second preset character string corresponding to the first end for the transmission transaction to which the first data block belongs, please refer to the relevant content above. If the first control module 11 determines that the first data block meets the requirements and is a data block that is allowed to be transmitted, it can send the first data block and the transaction attribute identifier of the transmission transaction to which the first data block belongs to the second control module 12. The second control module obtains the transmission transaction attribute information to which the first data block belongs based on the transaction attribute identifier, and processes the first data block based on the obtained transmission transaction attribute information before sending it. Based on this, in one feasible technical solution, the above-mentioned step 201 of "determining the first transaction information corresponding to the first transmission transaction to which the first data block belongs in response to the first application sending the first data block to be transmitted to the second end" may include:
[0606] 2010. Generate a corresponding transaction identifier for the first transmission transaction;
[0607] 2011. Receive the first data block and the transaction attribute identifier of the first transmission transaction to which the first data block belongs, sent by the first control module in the application;
[0608] 2012. Based on the transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
[0609] In the above 2011, the first transmission transaction to which the first data block belongs specifically refers to the transmission transaction corresponding to the first data stream to which the first data block belongs. For the specific implementation of the first control module determining the transaction attribute identifier of the first transmission transaction to which the first data block belongs, please refer to the relevant content in other embodiments above.
[0610] In the aforementioned 2012, the transmission transaction attribute information includes, but is not limited to, a transaction attribute name, first annotation information, a first preset string corresponding to the second end, a transaction attribute identifier, and transaction attribute type information. The transaction attribute type information includes the transmission direction of the first data stream to which the first data block belongs, the data type of the first data stream, and data header usage information. For a detailed description of the transmission transaction attribute information and the specific implementation of the aforementioned 2012, please refer to the relevant content in other embodiments above.
[0611] In an implementable technical solution, the above-mentioned 202 “determining corresponding first target header information for the first data block based on the first transaction information” may specifically include:
[0612] 2021. Obtain a header information transmission mode corresponding to a data block in a first data stream to which the first data block belongs;
[0613] 2022. Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block;
[0614] 2023. Configure a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block, to obtain a message header determined for the first data block.
[0615] In one specific implementation, the above-mentioned 2022 “determining a target header field for the first data block from multiple header fields included in a preset message header format based on the header information transmission mode and relevant information of the first data block” may specifically include:
[0616] 20221. Determine, according to the block number of the first data block included in the relevant information, the order of the first data block in the first data stream;
[0617] 20222. If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, then the multiple header fields are the target header fields;
[0618] 20223. If the header information transmission mode is the second mode and the data block is not sorted last in the first data stream, or the header information transmission mode is the third mode and the data block is not sorted first in the first data stream, then some of the multiple header fields are the target header fields.
[0619] It should be noted that in addition to the header information transmission method described in steps S20221 to S20223 above, other header information transmission methods may also be included, such as the fourth method described in conjunction with FIG2b. For detailed descriptions of the header information transmission methods, please refer to the relevant content described in other embodiments with respect to steps S20 to S22 and FIG2b, and will not be further described here.
[0620] In the case given in 20222 above, that is, when the multiple header fields are the target header fields, the above 2023 "configuring a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block" may specifically include:
[0621] 20231. Determine a second preset character string corresponding to the first end for the first transmission transaction;
[0622] 20232. Configure a corresponding field value of the target header field according to the second preset character string, the first transaction information, and related information of the first data block, to obtain a first message header determined for the first data block;
[0623] The first message header includes: a first preset character string corresponding to the second end, the second preset character string, a transaction attribute identifier of the first transmission transaction, a transaction identifier of the first transmission transaction, a total number of data blocks in the first data stream, a block number of the first data block, a total size of the first target header information and the first data block, and annotation information; when the total number is a set value, it indicates that the first data stream is a stream with an unknown number of data blocks.
[0624] For the specific implementation of the above 203 "generating the first message to be sent according to the first data block and the first target header information", please refer to the relevant content in other embodiments above.
[0625] In this embodiment, the preset character strings (e.g., the first preset character string and the second preset character string) are used to indicate the address information of the corresponding end. "Indication" herein includes the following two meanings: the preset character string is directly a character string corresponding to the address information of the corresponding end; or the preset character string is used to conceal the address information of the corresponding end, for example, by causing the associated information associated with the preset character string to include the address information of the corresponding end. In the case where the preset character string is used to conceal the address information of the corresponding end, a possible implementation of the above-mentioned step 204 of "sending the first message to the second end" may include the following steps:
[0626] 2041. Obtain a first preset character string corresponding to the second end from the transmission transaction attribute information of the first transmission transaction included in the first transaction information;
[0627] 2042. Acquire address information of the second end according to the first preset character string;
[0628] 2043. Send the first message to the second end according to the address information of the second end.
[0629] For the specific implementation of the above 2041-2042, please refer to the relevant content in other embodiments above.
[0630] In a specific feasible technical solution, the above-mentioned step 2043 “sending the first message to the second end according to the address information of the second end” can be implemented by the following steps:
[0631] 20431. Send the first message to an intermediate network device according to the address information of the second end, so that the first message is sent to the second end through the intermediate network device.
[0632] Before sending the first message to the second end, the intermediate network device further performs any one of the following: verifying the first target header information contained in the first message; generating log information of the first transmission transaction based on the first message.
[0633] In the case given in 20223 above, that is, when some of the multiple header fields are the target header fields, the above 2023 "configuring a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block" may specifically include:
[0634] 20231′. Configuring a corresponding field value of the target header field according to at least one of the first transaction information and the related information of the first data block to obtain a message header determined for the first data block, including:
[0635] 20232′. Based on the transaction identifier of the first transmission transaction in the first transaction information, configure a corresponding field value of the target header field to obtain a second message header determined for the first data block.
[0636] The second message header includes a transaction identifier of the first transmission transaction.
[0637] Furthermore, the method provided in this embodiment may further include:
[0638] 205. Receive a second message sent by the second end;
[0639] The second message is generated by the third control module on the second end based on the second transaction information of the second transmission transaction corresponding to the second data flow of the second application on the second end, by determining corresponding second destination header information for the second data block of the second data flow, and based on the second data block and the second destination header information; the second destination header information is used to verify whether the second message meets the requirements;
[0640] The third control module is located within the second application or outside the second application.
[0641] The technical solution provided in this embodiment determines, when a first end needs to transmit a first data block in a first data stream of an application to a second end, first destination header information corresponding to the first data block is determined based on first transaction information corresponding to the first transmission transaction of the first data stream. A first message to be sent is then generated based on the first data block and the first destination header information, and the first message is sent to the second end. The first destination header information is used to verify whether the message meets the requirements, enabling this solution to achieve security management of the transmitted data content at a low cost.
[0642] It should be noted that for any steps not fully described in detail in the data transmission method provided in the embodiments of this application, reference may be made to the corresponding contents in the other embodiments provided in this application, and will not be repeated here. Furthermore, in addition to the aforementioned steps, the method provided in the embodiments of this application may also include some or all of the other steps in the aforementioned embodiments, and for details, reference may be made to the corresponding contents in the aforementioned embodiments, and will not be repeated here.
[0643] Figure 12 shows a flow chart of a data transmission method provided in another embodiment of the present application. This data transmission method is suitable for the fourth control module (not shown in the figure) on the intermediate network device as shown in Figure 3c. The fourth control module will have preset information pre-set in advance, and the preset information is the information required to implement the data transmission method provided in this embodiment. For the preset information in the fourth control module, please refer to the above description of the preset information preset in the first control module 11. For a detailed introduction to the fourth control module 12, please refer to the relevant content in other embodiments above, and no further details will be given here. Specifically, as shown in Figure 12, the data transmission method provided in this embodiment may include the following steps:
[0644] A11. In response to a first data block sent by the first end and to be transmitted to the second end, determine first transaction information of a first transmission transaction to which the first data block belongs;
[0645] A12. Determine corresponding first target header information for the first data block based on the first transaction information;
[0646] A13. Generate a first message to be sent based on the first data block and the first target header information;
[0647] A14. Send the first message to the second end;
[0648] The first target header information is used to verify whether the first message meets the requirements.
[0649] In one possible implementation, the above-mentioned A11 “determining, in response to a first data block sent by the first end and to be transmitted to the second end, first transaction information of a first transmission transaction to which the first data block belongs” may specifically include:
[0650] A111. Generate a corresponding transaction identifier for the first transmission transaction;
[0651] A112. Receive the first data block and the transaction attribute identifier of the first transmission transaction to which the first data block belongs, sent by a first control module in the first application on the first end or a second control module outside the first application on the first end;
[0652] A113. Based on the transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
[0653] In one possible implementation, the above-mentioned A12 “determining corresponding first target header information for the first data block based on the first transaction information” may specifically include:
[0654] A121. Obtain a header information transmission mode corresponding to a data block in a first data stream to which the first data block belongs;
[0655] A122. Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block;
[0656] A123. Configure the corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block.
[0657] A specific implementation of A122 above, “determining a target header field for the first data block from multiple header fields included in a preset message header format based on the header information transmission mode and relevant information of the first data block”, may include:
[0658] A1221. Determine, according to the block number of the first data block included in the relevant information, the order of the first data block in the first data stream;
[0659] A1222: If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, the multiple header fields are the target header fields.
[0660] A1223. If the header information transmission mode is the second mode and the data block is not sorted last in the first data stream, or the header information transmission mode is the third mode and the data block is not sorted first in the first data stream, then some of the multiple header fields are the target header fields.
[0661] It should be noted that in addition to the header information transmission method described in steps A1222 to A1223 above, other header information transmission methods may also be included, such as the fourth method described in conjunction with FIG2b. For detailed descriptions of header information transmission methods, please refer to the relevant content described in other embodiments with respect to steps S20 to S22 and FIG2b, and will not be further described here.
[0662] In the case given in A1222 above, that is, when the multiple header fields are the target header fields, the above A123 "configuring a corresponding field value of the target header field according to at least one item of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block" may specifically include:
[0663] A1231. Determine a second preset character string corresponding to the first end for the first transmission transaction;
[0664] A1232. Configure a corresponding field value of the target header field according to the second preset character string, the first transaction information, and related information of the first data block to obtain a first message header determined for the first data block.
[0665] The first message header includes: a first preset character string corresponding to the second end, the second preset character string, a transaction attribute identifier of the first transmission transaction, a transaction identifier of the first transmission transaction, a total number of data blocks in the first data stream, a block number of the first data block, a total size of the first target header information and the first data block, and annotation information;
[0666] When the total number is a set value, it indicates that the first data stream is a stream in which the number of data blocks is unknown; the preset character string is the address information of the corresponding end, or the preset character string is used to hide the address information of the corresponding end.
[0667] Furthermore, when the preset character string is used to hide the address information of the corresponding end, the above-mentioned A14 "sending the first message to the second end" includes:
[0668] A141. Obtain a first preset character string corresponding to the second end from the transmission transaction attribute information of the first transmission transaction included in the first transaction information.
[0669] A142. Acquire address information of the second end according to the first preset character string;
[0670] A143. Send the first message to the second end according to the address information of the second end.
[0671] In the case given in A1223 above, that is, when some of the multiple header fields are the target header fields, the above A123 "configuring a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block" may specifically include:
[0672] A1231′, configuring a corresponding field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block, to obtain a message header determined for the first data block, including:
[0673] A1232′: Based on the transaction identifier of the first transmission transaction in the first transaction information, configure a corresponding field value of the target header field to obtain a second message header determined for the first data block;
[0674] The second message header includes a transaction identifier of the first transmission transaction.
[0675] Furthermore, the method provided in this embodiment also includes:
[0676] A15. Receive a second data block to be transmitted to the first end from the second end, and determine second transaction information of a second transmission transaction to which the second data block belongs;
[0677] A16. Determine corresponding second target header information for the second data block based on the second transaction information;
[0678] A17. Generate a second message to be sent based on the second data block and the second target header information;
[0679] A18. Send the second message to the first end;
[0680] The second destination header information is used to verify whether the second message meets the requirements.
[0681] It should be noted that for any steps not fully described in detail in the data transmission method provided in the embodiments of this application, reference may be made to the corresponding contents in the other embodiments provided in this application, and will not be repeated here. Furthermore, in addition to the aforementioned steps, the method provided in the embodiments of this application may also include some or all of the other steps in the aforementioned embodiments, and for details, reference may be made to the corresponding contents in the aforementioned embodiments, and will not be repeated here.
[0682] Another embodiment of the present application also provides a data transmission method. This data transmission method is connected to a control device (such as the first control device described above) connected to the first end, and the control device will have preset information pre-set in advance. This preset information is the information needed to implement the data transmission method provided by this embodiment. For the preset information in the control device, please refer to the above description of the preset information preset in the first control module 11. For a detailed introduction to the control device, please refer to the relevant content in other embodiments above, and no further details will be given here. Specifically, the data transmission method provided in this embodiment may include the following steps:
[0683] A21. Receive a first data block in a first data stream sent by the first end and to be transmitted to the second end;
[0684] A22. Determine first transaction information of a first transmission transaction corresponding to the first data stream;
[0685] A23. Determine corresponding first target header information for the first data block based on the first transaction information;
[0686] A24. Generate a first message to be sent based on the first data block and the first target header information;
[0687] A25. Send the first message to the second end;
[0688] The first target header information is used to verify whether the first message is required.
[0689] It should be noted that for any steps not fully described in detail in the data transmission method provided in the embodiments of this application, reference may be made to the corresponding contents in the other embodiments provided in this application, and will not be repeated here. Furthermore, in addition to the aforementioned steps, the method provided in the embodiments of this application may also include some or all of the other steps in the aforementioned embodiments, and for details, reference may be made to the corresponding contents in the aforementioned embodiments, and will not be repeated here.
[0690] Below, this application introduces the technical solution provided by this application from the perspective of the role of "preset character strings" in hiding the address information of the corresponding end. Before introducing the data transmission method provided by this application from the perspective of "preset character strings", we first introduce and explain the specific system architecture on which the method can be based.
[0691] Specifically, from the perspective of "preset character strings", the data transmission method provided by the present application can be based on the system architecture shown in Figures 5a to 5c. As shown in Figure 5a, a structural diagram of a data transmission system provided by an embodiment of the present application, the data transmission system includes: a first end 10, a first control device 31 and a second end 20, wherein,
[0692] The first end 10 is configured to send a first data block to be transmitted to the second end to the first control device 31;
[0693] The first control device 31 is used to obtain a first preset character string corresponding to the second end in response to the first data block sent by the first end; wherein the first preset character string is used to hide the address information of the second end; obtain the address information of the second end based on the first preset character string; and send the first data block to the second end based on the address information of the second end.
[0694] For a detailed introduction to the first end 10, the first control device 31 and the second end 20, as well as the communication connection method therebetween, please refer to the above related content, which will not be described in detail here.
[0695] The first data block sent by the first end 10 to the first control device 31 is a data block in the first data stream of the first application on the first end. For a detailed description of the first application and the first data stream, please refer to the relevant content above. When the first end 10 needs to transmit the first data block to the second end 20, it can call the device driver of the first control device 31 deployed therein and, using the configuration data pre-registered within the device driver, determine a first preset string corresponding to the second end for the first data block. Furthermore, it can determine a second preset string corresponding to the first end for the first data block, and then send the first preset string and the second preset string along with the first data block to the first control device 31. The configuration data pre-registered within the device driver may include, but is not limited to: multiple second preset strings corresponding to the first end; the correspondence between the second preset strings, the transaction type of the transmission transaction, and the transaction attribute identifier of the transmission transaction; the name of the second end, access credentials, and transmission transaction attribute information of multiple transmission transactions; and so on. By invoking the device driver of the first control device 31 deployed therein, the first end 10 can obtain the first preset string corresponding to the second end from the transmission transaction attribute information corresponding to the first transmission transaction of the first data stream to which the first data block is determined (i.e., determine the first preset string corresponding to the second end for the first data block). Furthermore, based on the correspondence between the transaction type and the second preset string, the first end 10 can determine the second preset string corresponding to the first end that corresponds to the transaction type of the transmission transaction corresponding to the first data stream (i.e., determine the second preset string corresponding to the first end for the first data block). For specific implementations of determining the transaction type, transmission transaction attribute information, etc. of the transmission transaction corresponding to the first data stream, please refer to the relevant content in other embodiments above.
[0696] Alternatively, the first end 10 may send only the first data block to the first control device, without sending the first preset character string corresponding to the second end and the second preset character string corresponding to the first end to the first control device 31 , which is determined independently by the first control device 31 .
[0697] Based on the above content, when the first control device 31 is used to obtain the first preset character string corresponding to the second end, it can be specifically used for any one of the following:
[0698] 11) Receive a first preset character string corresponding to the second end sent by the first end.
[0699] 12) Determine transmission transaction attribute information of a first transmission transaction corresponding to a first data stream to which the first data block belongs; and obtain a first preset character string corresponding to the second end from the transmission transaction attribute information.
[0700] For the specific implementation of determining the transmission transaction attribute information of the first transmission transaction corresponding to the first data stream, and the specific introduction of the transmission transaction attribute information, please refer to the relevant content in other embodiments above.
[0701] In this embodiment, the first preset string is used to hide the address information of the second end. The purpose of doing so can be referred to the content related to "Case 22" described in other embodiments above. The specific method of achieving the hiding can be, but is not limited to: the associated information associated with the first preset string includes the address information of the second end. Based on this,
[0702] The first control device 31 , when used to “obtain address information of the second end according to the first preset character string corresponding to the second end”, can specifically be used to: obtain association information associated with the first preset character string; and obtain address information of the second end from the association information.
[0703] After the first control device 31 obtains the address information of the second end, as shown in FIG5a, the first data block can be directly sent to the second end according to the address information of the second end. Alternatively, as shown in FIG5b and FIG5c, in order to further improve the security control of data transmission, a corresponding message to be transmitted can be generated for the first data block ...
Claims
1. A data transmission method, characterized in that: Suitable for a first control module in a first application on a first end, the method includes: Determine first transaction information of a first transmission transaction corresponding to a first data flow of the first application; When a first data block of the first data stream needs to be transmitted to the second end, determining corresponding first target header information for the first data block based on the first transaction information; Generate a first message to be sent according to the first data block and the first target header information; Sending the first message to the second end; The first target header information is used to verify whether the first message meets the requirements.
2. The method according to claim 1, characterized in that Determining corresponding first target header information for the first data block based on the first transaction information includes: Obtaining a header information transmission mode corresponding to a data block in the first data stream; Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block; According to at least one of the first transaction information and the relevant information of the first data block, the field value of the target header field is configured to obtain a message header determined for the first data block.
3. The method according to claim 2, characterized in that Determining a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block includes: Determining, according to the block number of the first data block included in the relevant information, the order of the first data block in the first data stream; If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, the multiple header fields are the target header fields; If the header information transmission mode is the second mode and the data block is not the last one in the first data stream, or the header information transmission mode is the third mode and the data block is not the first one in the first data stream, then some of the multiple header fields are the target header fields.
4. The method according to claim 3, characterized in that When the plurality of header fields are the target header fields, The method further comprises configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block, including: determining address information of a first end for the first transmission transaction; According to the address information of the first end, the first transaction information and the related information of the first data block, configure the corresponding field value of the target header field to obtain a first message header determined for the first data block; The first message header includes: address information of the first end, address information of the second end, transaction attribute identifier of the first transmission transaction, transaction identifier of the first transmission transaction, total number of data blocks in the first data stream, block number of the first data block, total size of the first target header information and the first data block, and annotation information; When the total number is a set value, it indicates that the first data stream is a stream in which the number of data blocks is unknown.
5. The method according to claim 4, characterized in that Determining address information of the first end for the first transmission transaction includes: Acquire a first correspondence between address information of the first end and a transaction type; Based on the first corresponding relationship, address information of a first end having a corresponding relationship with the transaction type to which the first transmission transaction belongs is determined.
6. The method according to claim 4, characterized in that When the first data block is sorted first or last in the first data stream, Determining corresponding first target header information for the first data block based on the first transaction information further includes: determining whether it is necessary to add a data header to the first data block according to the transmission transaction attribute information of the first transmission transaction in the first transaction information; When it is determined that it is necessary, determining a corresponding data header for the first data block according to the stream information of the first data stream; The data header is adapted to the first data stream and complies with preset data header format requirements.
7. The method according to claim 6, characterized in that Determining a corresponding data header for the first data block according to the stream information of the first data stream includes: Based on the data header usage information included in the transmission transaction attribute information, selecting an adaptive data header format from a plurality of preset data header formats; The data header is generated according to the stream information of the first data stream and in accordance with the selected data header format.
8. The method according to claim 3, characterized in that When some of the header fields in the plurality of header fields are target header fields, The method further comprises configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block, including: Based on the transaction identifier of the first transmission transaction in the first transaction information, configure the field value of the target header field to obtain a second message header determined for the first data block; The second message header includes the transaction identifier.
9. The method according to any one of claims 1 to 8, characterized in that Determining first transaction information of a first transmission transaction corresponding to a first data flow of the first application includes: generating a corresponding transaction identifier for the first transmission transaction; Acquire transmission transaction attribute information of the first transmission transaction.
10. The method according to claim 9, characterized in that Acquiring transmission transaction attribute information of the first transmission transaction, including: Determining a transaction attribute identifier of the first transmission transaction; Based on the transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
11. The method according to claim 10, characterized in that Determining a transaction attribute identifier of the first transmission transaction includes: determining, according to the transmission requirement information of the first data flow, a transaction type to which the first transmission transaction belongs; Based on the second correspondence between the transaction type and the transaction attribute identifier, a transaction attribute identifier that has a correspondence with the transaction type to which the first transmission transaction belongs is determined.
12. The method according to any one of claims 1 to 8, characterized in that: Sending the first message to the second end includes: Sending the first message to a second control module, which verifies the first target header information contained in the second message, and sends the first message to the second end when it is verified that the first message meets the requirements; The second control module is a module outside the first application on the first end.
13. The method according to any one of claims 1 to 8, characterized in that Also includes: receiving a second message sent by the second end; The second message is generated by the third control module on the second end according to the second transaction information of the second transmission transaction corresponding to the second data flow of the second application on the second end, determining the corresponding second target header information for the second data block of the second data flow, and according to the second data block and the second target header information; the second target header information is used to verify whether the second message meets the requirements; The third control module is located in the second application or outside the second application.
14. A data transmission method, characterized in that: A second control module adapted to be external to the first application on the first end; the method comprising: In response to a first data block to be transmitted to the second end and sent by the first application, determining first transaction information of a first transmission transaction to which the first data block belongs; Based on the first transaction information, determining corresponding first target header information for the first data block; Generate a first message to be sent according to the first data block and the first target header information; Sending the first message to the second end; The first target header information is used to verify whether the first message meets the requirements.
15. The method according to claim 14, characterized in that Determining corresponding first target header information for the first data block based on the first transaction information includes: Obtaining a header information transmission mode corresponding to a data block in a first data stream to which the first data block belongs; Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block; According to at least one of the first transaction information and the relevant information of the first data block, a corresponding field value of the target header field is configured to obtain a message header determined for the first data block.
16. The method according to claim 15, characterized in that Determining a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block includes: Determining, according to the block number of the first data block included in the relevant information, the order of the first data block in the first data stream; If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, the multiple header fields are the target header fields; If the header information transmission mode is the second mode and the data block is not the last one in the first data stream, or the header information transmission mode is the third mode and the data block is not the first one in the first data stream, then some of the multiple header fields are the target header fields.
17. The method according to claim 16, characterized in that When the plurality of header fields are the target header fields, The method further comprises configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block, including: Determine a second preset character string corresponding to the first end for the first transmission transaction; According to the second preset character string, the first transaction information and the related information of the first data block, configure the corresponding field value of the target header field to obtain a first message header determined for the first data block; The first message header includes: a first preset character string corresponding to the second end, the second preset character string, a transaction attribute identifier of the first transmission transaction, a transaction identifier of the first transmission transaction, a total number of data blocks in the first data stream, a block number of the first data block, a total size of the first target header information and the first data block, and annotation information; When the total number is a set value, it indicates that the first data stream is a stream in which the number of data blocks is unknown; the preset character string is the address information of the corresponding end, or the preset character string is used to hide the address information of the corresponding end.
18. The method according to claim 17, characterized in that When the preset string is used to hide the address information of the corresponding end, Sending the first message to the second end includes: acquiring, from the transmission transaction attribute information of the first transmission transaction included in the first transaction information, a first preset character string corresponding to the second end; Acquire address information of the second end according to the first preset character string; The first message is sent to the second end according to the address information of the second end.
19. The method according to claim 18, characterized in that Sending the first message to the second end according to the address information of the second end includes: Sending the first message to an intermediate network device according to the address information of the second end, so as to send the first message to the second end through the intermediate network device; Before sending the first message to the second end, the intermediate network device further performs any one of the following: Verifying the first target header information included in the first message; Generate log information of the first transmission transaction according to the first message.
20. The method according to claim 16, characterized in that When some of the header fields in the plurality of header fields are the target header fields, According to at least one of the first transaction information and the relevant information of the first data block, configuring a corresponding field value of the target header field to obtain a message header determined for the first data block, including: Based on the transaction identifier of the first transmission transaction in the first transaction information, configure a corresponding field value of the target header field to obtain a second message header determined for the first data block; The second message header includes a transaction identifier of the first transmission transaction.
21. The method according to any one of claims 14 to 20, characterized in that In response to a first data block to be transmitted to the second end and sent by the first application, determining first transaction information corresponding to a first transmission transaction to which the first data block belongs includes: generating a corresponding transaction identifier for the first transmission transaction; receiving the first data block sent by the first control module in the first application and a transaction attribute identifier of a first transmission transaction to which the first data block belongs; Based on the transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
22. The method according to any one of claims 14 to 20, characterized in that Also includes: receiving a second message sent by the second end; The second message is generated by the third control module on the second end according to the second transaction information of the second transmission transaction corresponding to the second data flow of the second application on the second end, determining the corresponding second target header information for the second data block of the second data flow, and according to the second data block and the second target header information; the second target header information is used to verify whether the second message meets the requirements; The third control module is located in the second application or outside the second application.
23. A data transmission method, characterized in that: A fourth control module adapted for use on an intermediate network device, the method comprising: In response to a first data block to be transmitted to a second end and sent by a first end, determining first transaction information of a first transmission transaction to which the first data block belongs; Based on the first transaction information, determining corresponding first target header information for the first data block; Generate a first message to be sent according to the first data block and the first target header information; Sending the first message to the second end; The first target header information is used to verify whether the first message meets the requirements.
24. The method according to claim 23, characterized in that Determining corresponding first target header information for the first data block based on the first transaction information includes: Obtaining a header information transmission mode corresponding to a data block in a first data stream to which the first data block belongs; Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block; According to at least one of the first transaction information and the relevant information of the first data block, a corresponding field value of the target header field is configured to obtain a message header determined for the first data block.
25. The method according to claim 24, characterized in that Determining a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block includes: Determining, according to the block number of the first data block included in the relevant information, the order of the first data block in the first data stream; If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, the multiple header fields are the target header fields; If the header information transmission mode is the second mode and the data block is not the last one in the first data stream, or the header information transmission mode is the third mode and the data block is not the first one in the first data stream, then some of the multiple header fields are the target header fields.
26. The method according to claim 25, characterized in that When the plurality of header fields are the target header fields, The method further comprises configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block, including: Determine a second preset character string corresponding to the first end for the first transmission transaction; According to the second preset character string, the first transaction information and the related information of the first data block, configure the field value of the target header field to obtain a first message header determined for the first data block; The first message header includes: a first preset string corresponding to the second end, the second preset string, a transaction attribute identifier of the first transmission transaction, a transaction identifier of the first transmission transaction, a number in the first data stream, the total number of data blocks, the block number of the first data block, the total size of the first target header information and the first data block, and the marking information; When the total number is a set value, it indicates that the first data stream is a stream in which the number of data blocks is unknown; the preset character string is the address information of the corresponding end, or the preset character string is used to hide the address information of the corresponding end.
27. The method according to claim 26, characterized in that When the preset string is used to hide the address information of the corresponding end, Sending the first message to the second end includes: acquiring, from the transmission transaction attribute information of the first transmission transaction included in the first transaction information, a first preset character string corresponding to the second end; Acquire address information of the second end according to the first preset character string; The first message is sent to the second end according to the address information of the second end.
28. The method according to claim 25, characterized in that When some of the header fields in the plurality of header fields are the target header fields, According to at least one of the first transaction information and the relevant information of the first data block, configuring a corresponding field value of the target header field to obtain a message header determined for the first data block, including: Based on the transaction identifier of the first transmission transaction in the first transaction information, configure a corresponding field value of the target header field to obtain a second message header determined for the first data block; The second message header includes a transaction identifier of the first transmission transaction.
29. The method according to any one of claims 23 to 28, characterized in that In response to a first data block to be transmitted to a second end and sent by a first end, determining first transaction information of a first transmission transaction to which the first data block belongs includes: generating a corresponding transaction identifier for the first transmission transaction; receiving the first data block and a transaction attribute identifier of a first transmission transaction to which the first data block belongs, sent by a first control module in a first application on the first end or a second control module outside the first application on the first end; Based on the transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
30. The method according to any one of claims 23 to 28, characterized in that Also includes: receiving a second data block to be transmitted to the first end and sent by the second end, and determining second transaction information of a second transmission transaction to which the second data block belongs; Based on the second transaction information, determining corresponding second target header information for the second data block; Generate a second message to be sent according to the second data block and the second target header information; Sending the second message to the first end; The second target header information is used to verify whether the second message meets the requirements.
31. A data transmission method, characterized in that: A control device suitable for first end connection, the method comprising: In response to a first data block sent by the first end and to be transmitted to the second end, obtaining a first preset character string corresponding to the second end; wherein the first preset character string is used to hide address information of the second end; Acquire address information of the second end according to the first preset character string; The first data block is sent to the second end according to the address information of the second end.
32. The method according to claim 31, characterized in that Obtaining a first preset character string corresponding to the second end includes: Determine first transaction information of a first transmission transaction corresponding to a first data stream to which the first data block belongs; The first preset character string is acquired from the transmission transaction attribute information included in the first transaction information.
33. The method according to claim 32, characterized in that Sending the first data block to the second end according to the address information of the second end includes: Based on the first transaction information, determining corresponding first target header information for the first data block; Generate a first message to be sent according to the first target header information and the first data block; Sending the first message to the second end according to the address information of the second end; The first target header information is used to verify whether the first message meets the requirements. If it meets the requirements, the second end obtains and caches the first data block from the first message.
34. The method according to claim 33, characterized in that Determining corresponding first target header information for the first data block based on the first transaction information includes: Obtaining a header information transmission mode corresponding to a data block in the first data stream; Determine a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block; According to at least one of the first transaction information and the relevant information of the first data block, a corresponding field value of the target header field is configured to obtain a message header determined for the first data block.
35. The method according to claim 34, characterized in that Determining a target header field for the first data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and relevant information of the first data block includes: Determining, according to the block number of the first data block included in the relevant information, the order of the first data block in the first data stream; If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, the multiple header fields are the target header fields; If the header information transmission mode is the second mode and the data block is not the last one in the first data stream, or the header information transmission mode is the third mode and the data block is not the first one in the first data stream, then some of the multiple header fields are the target header fields.
36. The method according to claim 35, characterized in that When the plurality of header fields are the target header fields, The method further comprises configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block, including: Acquire a second preset character string corresponding to the first end, where the second preset character string is used to hide the address information of the first end; Based on the first preset character string, the second preset character string, the first transaction information, and related information of the first data, configure the field value of the target header field to obtain a first message header determined for the first data block; The first message header includes: the first preset character string, the second preset character string, the transaction attribute identifier of the first transmission transaction, the transaction identifier of the first transmission transaction, the total size of the target header information and the first data block, the total number of data blocks in the first data stream, the sequence number of the first data block, and annotation information; When the total number is a set value, it indicates that the first data stream is a stream in which the number of data blocks is unknown.
37. The method according to claim 35, characterized in that When some of the header fields in the plurality of header fields are the target header fields, The method further comprises configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the first data block to obtain a message header determined for the first data block, including: Based on the transaction identifier in the first transaction information, configure the field value of the target header field to obtain a second message header determined for the first data block; The second message header includes the transaction identifier.
38. The method according to any one of claims 31 to 37, characterized in that Also includes: acquiring data transmission direction control information from association information associated with a second preset character string corresponding to the first end; If the data transmission direction control information indicates that the control device is allowed to forward the received data to the second end, triggering the operation of sending the first data block to the second end according to the address information of the second end; If the data transmission direction control information indicates that the control device is prohibited from forwarding the received data to the second end, then according to the data type of the first data stream to which the first data block belongs, the operation of sending the first data block to the second end according to the address information of the second end is triggered.
39. The method according to claim 38, characterized in that The step of triggering, according to a data type of a first data stream to which the first data block belongs, the operation of sending the first data block to the second end according to the address information of the second end includes: When the data type is a request type, obtaining a preset request parameter from the associated information; and sending the preset request parameter to the second end according to the address information of the second end; When the data type is a non-request type, no sending process is performed.
40. The method according to claim 38, characterized in that If the data transmission direction control information indicates that the control device is allowed to forward the received data to the second end, but the control device is prohibited from forwarding the received data sent by the second end, then The method further comprises: When feedback information returned by the second end for the first data block is received, the feedback information is not sent for processing.
41. The method according to any one of claims 31 to 37, characterized in that Also includes: When establishing a communication connection with the first end, receiving connection verification information sent by the first end; Feedback a corresponding verification result to the first end for the connection verification information, so that the first end determines whether to establish a communication link with the control device based on the verification result to send the first data block through the communication link; The connection verification information includes at least one of the following: a verification instruction carrying a verification value, and verification data related to a device driver of the first control device.
42. The method according to any one of claims 31 to 37, characterized in that The first data block is a data block in a data stream of a first application on the first end, and the order of the business logic layers of the first application is: the first application, the operating system of the first end, the device driver of the control device on the first end, and the hardware interface of the first end; The hardware interface of the first end is used to communicate with the hardware interface of the control device, and the communication connection does not use the TCP / IP protocol; the control device and the second end use the TCP / IP protocol for communication connection; The device driver can authenticate the first application to determine whether to receive the function call sent by the first data block.
43. The method according to claim 42, characterized in that Also includes: After receiving the first data block, verifying the first data block to determine whether the first data block is data sent by an official device driver; If yes, performing sending processing on the first data block; If not, the first data block will not be sent.
44. The method according to claim 43, characterized in that Verifying the first data block to determine whether the first data block is data sent by an official device driver includes: determining whether the first data block is accompanied by a valid access credential; When attached, the first data block is data sent by the official device driver; When not attached, the first data block is not data sent by the official device driver; The access credential includes at least one of the following: a digital signature and a password.
45. A data transmission system, characterized in that: include: A first end, on which a first control module is provided in a first application, the first control module being used to determine first transaction information of a first transmission transaction corresponding to a first data flow of the first application; When a first data block of the first data stream needs to be transmitted to the second end, determining corresponding first target header information for the first data block based on the first transaction information; Generate a first message to be sent according to the first data block and the first target header information; send the first message to the second end; wherein the first target header information is used to verify whether the first message meets the requirements; The second end is provided with a third control module, and the third control module is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, the first data is obtained and cached from the first message.
46. The system according to claim 45, characterized in that Also includes: an intermediate network device, communicatively connected to the first end and the second end; The first control module is specifically configured to send the first message to the intermediate network device; The intermediate network device is used to generate log information of the first transmission transaction according to the received first message; and send the first message to the second end.
47. A data transmission system, characterized in that: include: a first end, on which a second control module is provided outside the first application, the second control module being used to determine, in response to a first data block sent by the first application and to be transmitted to the second end, first transaction information of a first transmission transaction to which the first data block belongs; and to determine corresponding first target header information for the first data block based on the first transaction information; Generate a first message to be sent according to the first data block and the first target header information; send the first message to the second end; wherein the first target header information is used to verify whether the first message meets the requirements; The second end is provided with a third control module, and the third control module is used to verify the first target header information contained in the first message received by the second end; after the verification is passed, the first data is obtained from the first message.
48. The system according to claim 47, characterized in that Also includes: an intermediate network device, communicatively connected to the first end and the second end; The second control module is specifically configured to send the first message to the intermediate network device; The intermediate network device is used to generate log information of the first transmission transaction according to the received first message; and send the first message to the second end.
49. A data transmission system, characterized in that: include: The first end is used to send a first data block to be transmitted to the second end to the intermediate network device; an intermediate network device, on which a fourth control module is provided, configured to receive the first data block, determine first transaction information of a first transmission transaction to which the first data block belongs; and determine corresponding first target header information for the first data block based on the first transaction information; Generate a first message to be sent according to the first data block and the first target header information; send the first message to the second end; wherein the first target header information is used to verify whether the first message meets the requirements; The second end is provided with a third control module, which is used to control the first message received by the second end to include The first target header information is verified; after the verification passes, the first data is obtained from the first message.
50. The system according to claim 49, characterized in that A first control module is provided in the first application on the first end, or a second control module is provided outside the first application; The first control module or the second control module is used to send the first data block that the first application needs to transmit to the first end, and the transaction attribute information of the first transmission transaction to which the first data block belongs, to the intermediate network device; The intermediate network device, when used to determine the first transaction information of the first transmission transaction described in the first data block, is specifically used to: generating a corresponding transaction identifier for the first transmission transaction; Based on the received transaction attribute identifier, query the transmission transaction attribute information of the first transmission transaction from multiple preset transmission transaction attribute information.
51. A data transmission system, characterized in that: include: A first end, used to determine first transaction information of a first transmission transaction corresponding to a first data stream; When a first data block of the first data stream needs to be transmitted to the second end, determining corresponding first target header information for the first data block based on the first transaction information; Generate a first message to be sent according to the first data block and the first target header information; Sending the first message to the second end; wherein the first target header information is used to verify whether the first message is required; The second end is used to verify the first target header information contained in the received first message to determine whether the first message meets the requirements; if it meets the requirements, obtain and cache the first data block from the first message.
52. The system according to claim 51, characterized in that Also includes: a first control device; The first end is specifically used to send the first message to the first control device; The first control device is used to receive the first message; Obtaining preset data transmission security control information; Verifying the first target header information included in the first message according to the data transmission security control information; If the verification passes, sending the first message to the second end; If the verification fails, the first message will not be sent, or an inquiry message is output to inquire the user whether to allow the first message to be sent.
53. The system according to claim 52, characterized in that The first control device is further used for: After the verification is passed, judging whether the first message meets the data backup condition in the data transmission security control information according to the marking information included in the first message; If the data backup condition is met, the first message is backed up.
54. The system according to claim 52 or 53, characterized in that The first control device is an external device of the first end; and, If the first end communicates with the first control device via a first communication method, and the first communication method uses an external wired communication protocol transmitted by signaling, then The first end is further used to send connection verification information to the first control device when a communication connection needs to be established with the first control device, and the connection verification information includes at least one of the following: a verification instruction carrying a verification value, and verification data related to a device driver of the first control device; The first control device is used to feed back a corresponding verification result to the first end according to the connection verification information; The first end is further specifically used to determine whether to establish a communication link with the first control device according to the verification result.
55. The system according to claim 54, characterized in that The first end, when used to send the first message to the first control device, is specifically used to: obtain a first signaling, where the first signaling is used to instruct the first control device to receive a message; and send the first signaling and the first message to the first control device through a communication link with the first control device; The first control device is configured to receive the first message in response to the first signaling.
56. The system according to claim 54, characterized in that If the first end communicates with the first control device via a second communication method, and the second communication method uses a wireless communication protocol for a paired connection, then The first end is further used to search for the first control device according to preset control device pairing connection parameters when a communication connection needs to be established with the first control device; and perform pairing verification with the first control device when the first control device is found; After the pairing verification passes, a communication link is established with the first control device.
57. The system according to claim 52 or 53, characterized in that The first control device is an internal device of the first end, the first end communicates with the first control device via a third communication method, and the third communication method uses an internal wired communication protocol; and The first end is also used to scan the first control device according to preset control device characteristic information when a communication connection needs to be established with the first control device; and to establish a communication link with the first control device when the first control device is scanned.
58. The system according to claim 52 or 53, characterized in that Also includes: an intermediate network device, communicatively connected to the first control device and the second end; The first control device is specifically configured to send the first message to the intermediate network device; The intermediate network device is used to verify the first message received, and after the verification is passed, send the first message to the second end; or, to generate log information of the first transmission transaction based on the first message received, and send the first message to the second end.
59. The system according to claim 58, characterized in that Also includes: A second control device, communicatively connected to the second end and the intermediate network device; and The intermediate network device is specifically configured to send the first message to the second control device; The second control device is used to verify the received first message; and after the verification passes, in response to the acquisition request sent by the second end, send the first message to the second end.
60. A data transmission system, characterized in that: include: The first end is configured to send the first data block to the first control device when the first data block of the first data stream needs to be transmitted to the second end; A first control device, configured to determine first transaction information of a first transmission transaction corresponding to the first data flow; Determining corresponding first target header information for the received first data block based on the first transaction information; Generate a first message to be sent according to the first data block and the first target header information; Sending the first message to the second end; wherein the first target header information is used to verify whether the first message is required; The second end is used to verify the first target header information contained in the received first message to determine whether the first message meets the requirements; if it meets the requirements, obtain and cache the first data block from the first message.
61. A data transmission system, characterized in that: include: The first end is configured to send the first data block to the first control device when the first data block of the first data stream needs to be transmitted to the second end; a first control device, communicatively connected to the first end, and configured to determine first transaction information of a first transmission transaction corresponding to the first data stream; Determining corresponding first target header information for the received first data block based on the first transaction information; Generate a first message to be sent according to the first data block and the first target header information; Sending the first message to the second control device; wherein the first target header information is used to verify whether the first message is required; a second control device, connected to the first control device and the second end in communication, for verifying the first target header information contained in the received first message to determine whether the first message meets the requirements; if the first message meets the requirements, caching the first message locally to wait for the second end to obtain it; The second end is used to send an acquisition request to the second control device; and receive the first message fed back by the second control device in response to the acquisition request.
62. A data transmission system, characterized in that: include: The second end; A first end, used for sending a first data block to be transmitted to the second end to a first control device; A first control device is used to obtain a first preset character string corresponding to the second end in response to the first data block sent by the first end; wherein the first preset character string is used to hide the address information of the second end; obtain the address information of the second end according to the first preset character string; and send the first data block to the second end according to the address information of the second end.
63. The system according to claim 62, characterized in that The first control device, when used to send the first data block to the second end according to the address information of the second end, is specifically used to: Determine first transaction information of a first transmission transaction corresponding to a first data stream to which the first data block belongs; Based on the first transaction information, determining corresponding first target header information for the first data block; Generate a first message to be sent according to the first target header information and the first data block; Sending the first message to the second end according to the address information of the second end; The second preset character string is used to hide the address information of the first end; and the first target header information is used to verify whether the first message meets the requirements.
64. The system according to claim 63, characterized in that Also includes: A second control device is communicatively connected with the second end and the first control device; the address information of the second end points to the second control device; And, the first control device is specifically configured to send the first message to the second control device according to the address information of the second end; The second control device is used to verify the received first message; If the verification passes and the acquisition request sent by the second end is received, the first message is sent to the second end; if the verification fails, the sending process is not performed.
65. A data transmission system, characterized in that: include: Target device; The first end is used to obtain a first preset character string corresponding to the target device when a first data block needs to be transmitted to the target device; Generate a first message to be sent based on the first preset character string and the first data block; Sending the first message to a first control device; wherein the first preset character string is used to hide the address information of the target device; The first control device is used to determine the address information of the target device according to the first preset character string obtained from the first message; and send the first message to the target device according to the address information of the target device.
66. The system according to claim 65, characterized in that The target device includes a second terminal; The first control device is specifically configured to determine the address information of the second end according to the first preset character string; and send the first message to the second end according to the address information of the second end.
67. The system according to claim 66, characterized in that The target device further includes a second control device, which is in communication connection with the second end and the first control device; the address information of the second end points to the second control device; The first control device is specifically configured to send the first message to the second control device according to the address information of the second end; A second control device, used to verify the received first message; After the verification is passed, the first message is cached to wait for the second end to obtain it; The second end is used to send an acquisition request to the second control device; and receive the first message fed back by the second control device in response to the acquisition request.
68. A data transmission system, characterized in that: include: The first end is used to obtain a first preset character string corresponding to the second end when a first data block needs to be transmitted to the second end; Generate a first message to be sent based on the first preset character string and the first data block; Sending the first message to the first control device; wherein the first preset character string is used to hide the address information of the second end; a first control device, configured to determine address information of the second end according to the first preset character string obtained from the first message; and send the first message to the second end according to the address information of the second end; A second control device, used for buffering the received first message to wait for the second end to obtain it; The second end is used to send an acquisition request to the second control device; and receive the first message fed back by the second control device in response to the acquisition request.
69. A data transmission system, characterized in that: include: The first end is used to obtain a first preset character string corresponding to the second end and a second preset character string corresponding to the first end when a first data block needs to be transmitted to the second end; Sending the first preset character string, the second preset character string and the first data block to a first control device; wherein the preset character string is used to hide the address information of the corresponding end; a first control device, configured to determine first transaction information of a first transmission transaction corresponding to a first data stream to which the first data block belongs; determine corresponding first target header information for the first data block based on the first transaction information; generate a first message to be sent according to the first target header information and the first data block; and send the first message to the second end according to the address information of the second end obtained by the first preset character string; The second end is used to verify the received first message; after the verification passes, obtain and cache the first data block from the first message.
70. A first end, characterized in that include: a first application installed on the first end; The first control module is located in the first application and is used to implement the data transmission method described in any one of claims 1 to 13.
71. A first end, characterized in that include: a first application installed on the first end; The second control module is located outside the first application and is used to implement the data transmission method described in any one of claims 14 to 22.
72. An intermediate network device, characterized in that: include: The fourth control module and memory, wherein: The memory is used to store one or more computer programs; The fourth control module is used to execute the one or more computer programs to implement the data transmission method described in any one of claims 23 to 30.
73. A control device, characterized in that: include: A processor and a memory, wherein: The memory is used to store one or more computer instructions; The processor, coupled to the memory, is configured to execute the one or more computer instructions to implement the data transmission method described in any one of claims 31 to 44.
74. A data transmission method, characterized in that: A control device adapted to be connected to the first end, the method comprising: receiving a first data block in a first data stream to be transmitted to a second end and sent by the first end; Determine first transaction information of a first transmission transaction corresponding to the first data flow; Based on the first transaction information, determining corresponding first target header information for the first data block; Generate a first message to be sent according to the first data block and the first target header information; Sending the first message to the second end; The first target header information is used to verify whether the first message is required.
75. A control device, characterized in that: include: A processor and a memory, wherein: The memory is used to store one or more computer instructions; The processor, coupled to the memory, is used to execute the one or more computer instructions to implement the data transmission method described in claim 74 above.
76. A data transmission method, characterized in that: Applicable to the first end, the method comprises: When the first data block needs to be transmitted to the second end, obtaining a first preset identifier corresponding to the second end; wherein the first preset identifier is used to hide the address information of the second end; Generate a first message to be sent based on the first preset identifier and the first data block; The first message is sent to the second end through a control device.
77. The method according to claim 76, characterized in that Generating a first message to be sent based on the first preset identifier and the first data block includes: Determine first transaction information of a first transmission transaction corresponding to a first data stream to which the first data block belongs; Determine corresponding first target header information for the first data block based on the first transaction information and the first preset identifier; Generate the first message according to the first target header information and the first data block; The first target header information is used to verify whether the first message meets the requirements.
78. A first end, characterized in that include: A processor and a memory, wherein: The memory is used to store one or more computer instructions; The processor, coupled to the memory, is used to execute the one or more computer instructions to implement the steps in the data transmission method described in claim 76 or 77.
79. A data transmission control method, characterized in that: Applicable to a control device that is communicatively connected to a first end based on a first communication protocol, wherein some of the multiple communication nodes included in the first communication protocol are unidirectional communication nodes, the method comprising: In response to a communication node configuration operation on a control device triggered for the first end, determining first configuration information; wherein the communication node included in the first configuration information is a communication node in the first communication protocol; In the process of data transmission in a non-handshake connection with the first end, according to the first configuration information, at least one first communication node is started for the first end; wherein the node type to which the first communication node belongs can reflect the data transmission function enabled by the first communication node for the first end; According to the node type to which each of the first communication nodes belongs, the data transmission capability that the first end can perform through each of the first communication nodes is controlled.
80. The method according to claim 79, characterized in that The target communication node is a communication node among the at least one first communication node; as well as Controlling the data transmission capability that the first end can perform through the target communication node according to the node type to which the target communication node belongs, includes: Determine a target end for data transmission by the first end through the target communication node; When the node type to which the target communication node belongs is the first type, controlling the first end to be able to uplink data to the target end; When the node type to which the target communication node belongs is the second type, controlling the first end to be able to downlink data to the target end; When the node type to which the target communication node belongs is the third type, controlling the first end to be able to transmit uplink data and transmit downlink data to the target end; and, and / or: Acquire communication restriction information corresponding to the target communication node; According to the communication restriction information, the communication capability that the first end can perform when transmitting data to the target end through the target communication node is controlled.
81. The method according to claim 80, characterized in that Also includes: When it is monitored that the target communication node receives a data block sent by the first end and needs to be transmitted to the target end, acquiring data transmission capacity control information set for the first end by the target communication node; Determine the data communication capability of the first end indicated by the data transmission capability control information; performing a sending processing operation on the data block according to the data communication capability of the first end; The data communication capability includes at least one of an uplink data communication capability and a downlink data communication capability.
82. The method according to claim 81, characterized in that According to the data communication capability of the first end, performing a transmission processing operation on the data block includes: If the first end has uplink data communication capability, sending the data block to the target end; If the first end does not have uplink data communication capability but has downlink data communication capability, the data block is not sent.
83. The method according to claim 82, characterized in that If the first end does not have uplink data communication capability but has downlink data communication capability, the method further includes: Determine the data type of the data stream to which the data block belongs; When the data type is a request type, performing a search operation in a data buffer area corresponding to the target communication node according to the request parameters contained in the data block, so as to return adapted data to the first end; And, if the first end has uplink data communication capability but does not have downlink data communication capability, the method further includes: When feedback information returned by the target end for the data block is received, the feedback information is not sent for processing.
84. The method according to any one of claims 80 to 83, characterized in that When the node type to which the target communication node belongs is the second type, controlling the first end to be able to transmit downlink data includes: Acquire a timing parameter for triggering data acquisition set for the target communication node; According to the timing parameters, data is acquired from the target end in preparation for sending the acquired data to the first end.
85. The method according to claim 84, characterized in that Acquiring data from the target end according to the timing parameter includes: If the timing parameter is a first value, obtaining data from the target end at a regular time; If the timing parameter is a second value, then upon monitoring signaling sent by the first end to the target communication node to indicate that data needs to be sent to the first end, data is acquired from the target end.
86. The method according to claim 85, characterized in that Acquiring data from the target end includes: Obtaining preset request parameters set for the target communication node; Generate a request based on the preset request parameters and send it to the target end The data returned by the target end in response to the acquisition request is received and stored in a data buffer area corresponding to the target communication node.
87. The method according to any one of claims 80 to 83, characterized in that Determining a target end for data transmission by the first end through the target communication node includes: Determine a target address corresponding to the target communication node; Determining the target end according to the target address; The target address corresponding to the target communication node is determined by any of the following: Determine a target address having a binding relationship with the target communication node according to the one-to-one binding relationship between the communication node and the target address contained in the first configuration information; or Determine a preset identifier for the target communication node; determine the target address according to the preset identifier; The preset identifier is a preset identifier corresponding to the first end or a preset identifier corresponding to the target end, and is used to hide the address of the corresponding end or is the address of the corresponding end.
88. The method according to claim 87, characterized in that Determining a preset identifier for the target communication node includes: acquiring, according to the first configuration information, a preset identifier bound to the target communication node; or Receive a preset identifier sent by the first end; wherein the preset identifier is determined by the first end according to a transmission transaction corresponding to a data flow to which a data block to be transmitted belongs.
89. The method according to claim 87, characterized in that If the preset identifier is the preset identifier corresponding to the first end, then Determining the target address according to the preset identifier includes: Obtaining association information associated with the preset identifier; A target address is obtained from the associated information.
90. The method according to any one of claims 80 to 83, characterized in that Also includes: After power-on is detected, starting the second communication node according to the first configuration information to establish a handshake connection with the first end through the second communication node; During the process of establishing the handshake connection, determining whether the instruction sent by the first end to the second communication node meets the requirements; When in compliance, respond to the instructions; If it does not comply, the instruction will not be responded to.
91. The method according to claim 90, characterized in that In the control device, a corresponding data buffer area is independently provided for the second communication node; And, the method further comprises: After the handshake connection is successful, the step of starting at least one first communication node for the first end according to the first configuration information is triggered, and whether to shut down the second communication node is determined according to the node type to which the at least one first communication node belongs and the determination method of the target end.
92. The method according to claim 90, characterized in that Also includes: In the process of establishing a handshake connection with the first end, receiving connection verification information sent by the first end; Feedback a corresponding verification result to the first end for the connection verification information, so that the first end determines whether the verification is passed based on the verification result, and when the verification is passed, the control device and the first end are connected by handshake successfully; The connection verification information includes at least one of the following: a verification instruction carrying a verification value, and verification data related to a device driver of the control device.
93. The method according to any one of claims 79 to 83, characterized in that The first communication protocol is any one of the following: An external wired communication protocol that is transmitted using signaling instructions, and a wireless communication protocol that is connected in a pairing manner.
94. The method according to any one of claims 80 to 83, characterized in that The control device is also connected to the target end in communication based on a second communication protocol, and some of the multiple communication nodes included in the second communication protocol are unidirectional communication nodes; And, the method further comprises: In response to a communication node configuration operation on the control device triggered for the target end, determining second configuration information; wherein the communication node included in the second configuration information is a communication node in the second communication protocol; During the non-handshake connection data transmission process with the target end, at least one third communication node is started for the target end according to the second configuration information; the node type to which the third communication node belongs can reflect the data transmission function enabled by the third communication node for the target end; According to the node type to which each of the third communication nodes belongs, the data transmission capability of the target end through each of the third communication nodes is controlled.
95. The method according to any one of claims 80 to 83, characterized in that Determining a target end for data transmission by the first end through the target communication node includes: After receiving the data block to be transmitted sent by the first end through the target communication node, determining, based on the first configuration information, first transaction information of the first transmission transaction corresponding to the first data stream to which the data block belongs; Acquire a preset identifier corresponding to the target end from the transmission transaction attribute information included in the first transaction information; wherein the preset identifier is used to hide the address of the target end; Acquire the address of the target end according to the preset identifier corresponding to the target end; And, if the first end has uplink data communication capability, sending the data block to the target end includes: The data block is sent to the target end according to the address of the target end.
96. The method according to claim 95, characterized in that According to the address of the target end, sending the data block to the target end includes: Based on the first transaction information, determining corresponding first target header information for the data block; Generate a first message to be sent according to the first target header information and the data block; Sending the first message to the target end according to the address corresponding to the target end; The first target header information is used to verify whether the first message meets the requirements. If it meets the requirements, the target end obtains and caches the data block from the first message.
97. The method according to claim 96, characterized in that Determining corresponding first target header information for the data block based on the first transaction information includes: Obtaining a header information transmission mode corresponding to a data block in the first data stream; Determine a target header field for the data block from a plurality of header fields included in a preset message header format according to the header information transmission mode and the relevant information of the data block; According to at least one of the first transaction information and the relevant information of the data block, the field value of the target header field is configured to obtain a message header determined for the data block.
98. The method according to claim 97, characterized in that According to the header information transmission mode and the relevant information of the data block, determining a target header field for the data block from a plurality of header fields included in a preset message header format includes: Determining the order of the data blocks in the first data stream according to the block numbers of the data blocks included in the relevant information; If the header information transmission mode is the first mode, or the header information transmission mode is the second mode and the first data block is sorted last in the first data stream, or the header information transmission mode is the third mode and the first data block is sorted first in the first data stream, the multiple header fields are the target header fields; If the header information transmission mode is the second mode and the data block is not the last one in the first data stream, or the header information transmission mode is the third mode and the data block is not the first one in the first data stream, then some of the multiple header fields are the target header fields.
99. The method according to claim 98, characterized in that When the plurality of header fields are the target header fields, The method further comprises configuring a field value of the target header field according to at least one of the first transaction information and the relevant information of the data block to obtain a message header determined for the first data block, including: Acquire a preset identifier corresponding to the first end, where the preset identifier corresponding to the first end is used to hide address information of the first end; Based on the preset identifier corresponding to the target end, the preset identifier corresponding to the first end, the first transaction information and the relevant information of the data block, configure the field value of the target header field to obtain a first message header determined for the first data block; Among them, the first message header includes: a preset identifier corresponding to the target end, a preset identifier corresponding to the first end, a transaction attribute identifier of the first transmission transaction, a transaction identifier of the first transmission transaction, target header information and the total size of the data block, the total number of data blocks in the first data stream, the sequence number of the data block, and marking information; when the total number is a set value, it indicates that the first data stream is a stream in which the number of data blocks is unknown.
100. The method according to claim 98, characterized in that When some of the header fields in the plurality of message fields are the target header fields, The target header character is configured according to at least one of the first transaction information and the relevant information of the data block. The field value of the segment is used to obtain a message header determined for the data block, including: Based on the transaction identifier in the first transaction information, configure the field value of the target header field to obtain a second message header determined for the data block; The second message header includes the transaction identifier.
101. A data transmission control method, characterized in that: A control device that is communicatively connected to a first end based on a first communication protocol, the method comprising: When it is determined that the preset communication node startup condition is met, starting the first communication node adapted in the first communication protocol for the first end; By starting the first communication node, the data transmission capability of the first end is controlled.
102. The method according to claim 101, characterized in that The data transmission capability includes at least one of the following: uplink and downlink data transmission capability, communication capability; the communication capability includes communication rate. And, the communication nodes included in the first communication protocol include unidirectional communication nodes; The first communication node started is used for data transmission with the first end through non-handshake connection; 103. The method according to claim 102, controlling the uplink and downlink data transmission capabilities of the first end by starting the first communication node, comprising: According to the input and output capabilities of the first communication node, the uplink and downlink data transmission capabilities that the first end can perform to the target end through the first communication node are controlled.
104. The method according to claim 103, characterized in that If the first communication node is a unidirectional communication node, the first communication node has input capability or output capability; If the first communication node is a bidirectional communication node, the first communication node has input capability and output capability. And, according to the input and output capabilities of the first communication node, controlling the uplink and downlink data transmission capabilities that the first end can perform to the target end through the first communication node, including: When the first communication node has an output capability, controlling the first end to be able to upload data to the target end; When the first communication node has input capability, controlling the first end to transmit data to the target end; When the first communication node has input and output capabilities, the first end is controlled to be able to transmit uplink data and downlink data to the target end.
105. The method according to claim 102, characterized in that Controlling the communication capability of the first end by starting the first communication node includes: Obtaining the communication restriction information corresponding to the first communication node Controlling the communication capability that can be performed when the first end transmits data to the target end according to the communication restriction information; The communication restriction information includes at least one of the following: the protocol version of the first communication protocol, the communication Communication restriction time period, transmission data limit, and transmission delay method.
106. The method according to any one of claims 101 to 105, characterized in that Determining that a preset communication node startup condition is met includes at least one of the following: Complete a handshake connection with the first end; Verifying the first end; Determine that the timing period has been reached; Determining, based on the positioning information of the control device, that the control device is within a preset geographical location range; Detecting that a communication node startup control on the control device is triggered; Receive a communication node startup instruction; Receive specified specific data.
107. The method according to any one of claims 101 to 105, characterized in that Starting a first communication node adapted in the first communication protocol for the first end includes: The adapted first communication node is started according to the communication node enabling information of the control device configured for the first end read from the transmission configuration information.
108. The method according to claim 107, characterized in that Also includes: Read the stored transmission configuration information locally or from a configuration data provider, so as to obtain communication node activation information of a control device configured for the first end from first configuration information related to the first end included in the transmission configuration information; The locally stored transmission configuration information is acquired by responding to a communication node configuration operation on a triggered control device.
109. The method according to claim 108, characterized in that In response to a triggered communication node configuration operation on the control device, acquiring the transmission configuration information includes: In response to an import operation triggered by a user, acquiring the imported transmission configuration information; or Receive the transmission configuration information sent by the configuration data provider.
110. The method according to claim 107, characterized in that Also includes: Obtaining a target address corresponding to the first communication node from the transmission configuration information; The target end is determined according to the target address to trigger the step of controlling the data transmission capability of the first end to the target end through the activated first communication node.
111. The method according to claim 110, characterized in that Acquiring a target address corresponding to the first communication node from the transmission configuration information includes: Acquire, from the transmission configuration information, at least one preset identifier of the first end configured for the first communication node; At least one of the target addresses is determined according to the at least one preset identifier; wherein one preset identifier is used to determine one of the target addresses, and different target addresses correspond to different target terminals.
112. A data transmission control system, characterized in that: include: First end; A first control device is communicatively connected to the first end based on a first communication protocol, wherein some of the multiple communication nodes included in the first communication protocol are unidirectional communication nodes; The first control device is used to determine first configuration information in response to a communication node configuration operation on the control device triggered for the first end; wherein the communication node included in the first configuration information is a communication node in the first communication protocol; during a non-handshake connection data transmission process with the first end, at least one first communication node is started for the first end according to the first configuration information; wherein the node type to which the first communication node belongs can reflect the data transmission function enabled by the first communication node for the first end; and according to the node type to which each of the first communication nodes belongs, the data transmission capability that the first end can perform through each of the first communication nodes is controlled.
113. The system according to claim 112, characterized in that The first control device is also used to start the second communication node according to the first configuration information after monitoring power-on, so as to establish a handshake connection with the first end through the second communication node; in the process of establishing the handshake connection, determine whether the instruction sent by the first end to the second communication node meets the requirements; if it meets the requirements, respond to the instruction; if it does not meet the requirements, do not respond to the instruction.
114. The system according to claim 112 or 113, characterized in that Also includes: a second control device, connected to the first control device and the second end for communication, and configured to receive data sent by the first control device; Verifying the received data; After the verification is passed, the data is sent to the second end.
115. The method according to claim 114, characterized in that The second control device is communicatively connected to the second end based on a second communication protocol, and some of the multiple communication nodes included in the second communication protocol are unidirectional communication nodes; as well as The second control device is also used to determine second configuration information in response to a communication node configuration operation on the second control device triggered for the second end; wherein the communication node included in the second configuration information is a communication node in the second communication protocol; during non-handshake connection data transmission with the second end, at least one third communication node is started for the second end according to the second configuration information; the node type to which the third communication node belongs can reflect the data transmission function enabled by the third communication node for the second end; and according to the node type to which each of the third communication nodes belongs, the data transmission communication capability that the second end can perform through each of the third communication nodes is controlled.
116. A data transmission control system, characterized in that: include: First end; A first control device is connected to the first end in communication based on a first communication protocol, wherein some of the communication nodes included in the first communication protocol are unidirectional communication nodes; The first control device is used to determine first configuration information in response to a communication node configuration operation on the control device triggered for the first end; wherein the communication node included in the first configuration information is a communication node in the first communication protocol; in the process of non-handshake connection data transmission with the first end, according to the first configuration information, at least one first communication node is started for the first end; the node type to which the first communication node belongs can reflect the data transmission function enabled by the first communication node to the first end; according to the node type to which each of the first communication nodes belongs, the data transmission capability that the first end can perform through each of the first communication nodes is controlled; a second control device, which is communicatively connected with the first control device and the second end, and is used to verify the data sent by the first control device when receiving the data; after the verification passes, the data is sent to the second end; The second end is used to receive the data sent by the second control device.
117. A control device, characterized in that: include: A memory and a processor; wherein, The memory is used to store computer programs; The processor, coupled to the memory, is used to execute the computer program stored in the memory to implement the steps in the data transmission control method described in any one of claims 79 to 100 or claims 101 to 111.
118. A computer-readable storage medium, characterized in that: It includes a computer program or instructions, which, when executed by a processor, can implement the steps in the data transmission method described in any one of claims 1 to 13, or implement the steps in the data transmission method described in any one of claims 14 to 22, or implement the steps in the data transmission method described in any one of claims 23 to 30, or implement the steps in the data transmission method described in any one of claims 31 to 44, or implement the steps in the data transmission method described in any one of claims 76 or 77, or implement the steps in the data transmission control method described in any one of claims 79 to 100 or claims 101 to 111.