Self-adaptive transmission method for mobile authorization of wide-area distributed data
By performing multi-dimensional verification and real-time feedback control before data transmission, the transmission strategy is dynamically adjusted, solving the problem that existing technologies cannot adapt to network changes. This achieves a dynamic balance between security and efficiency in a wide-area distributed environment, providing highly reliable data mobility services.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-03-27
AI Technical Summary
Existing data security transmission solutions cannot dynamically respond to network performance fluctuations, changes in terminal device status, and external security threats in a wide-area distributed environment. This results in fixed security policies that cannot achieve the optimal balance between security and effectiveness in a changing environment.
Access verification ensures a basic level of security for transmission initiation, while dynamic decision-making based on multi-dimensional quantification and policy weights achieves a fine balance between security and efficiency. Closed-loop control based on performance and status feedback optimizes the transmission process, dynamically adjusting encryption strength, data segmentation, and protocol selection.
In complex and open wide area network environments, it achieves adaptive adjustment of transmission strategies, ensuring the security and efficiency of data transmission, and providing elastic, resilient and highly reliable data mobility services.
Smart Images

Figure CN121750359A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security transmission, and particularly relates to a self-adaptive transmission method for wide-area distributed data mobile authorization. BACKGROUND
[0002] In the digital era, data mobility across regions and networks has become the norm, especially in cloud computing, mobile office and Internet of Things scenarios. Data owners need to securely distribute data to authorized users in different geographical locations using different devices. This raises the core challenge of wide-area distributed data mobile authorization transmission: how to ensure the security, reliability and efficiency of controlled data throughout the transmission process in an open, complex and unstable wide-area network environment.
[0003] Current common data security transmission schemes rely on static or semi-static security policies. For example, identity authentication and authorization verification are completed through digital certificates, tokens, etc. before transmission starts, and fixed encryption algorithms (such as AES-256) and transmission protocols (such as TLS / HTTPS) are used throughout the transmission session. This type of scheme has obvious limitations: first, the security policy is fixed after the session is established and cannot respond to the dramatic fluctuations in network performance (such as bandwidth reduction and increased latency), dynamic changes in terminal device status (such as insufficient power and network switching), and real-time escalation of external security threats (such as attack events on the current access network); second, the authorization mechanism usually only focuses on whether the "identity" is legal, lacking continuous assessment of whether the "environment" is safe, resulting in authorized users accessing sensitive data on malicious networks or high-risk devices, creating security vulnerabilities; finally, existing schemes often take a compromise or fixed preference between security and transmission efficiency, and cannot dynamically and finely adjust encryption strength, data blocking, protocol selection, etc. according to the sensitivity of the data itself and the real-time environment, making it difficult to continuously achieve the optimal balance between security and utility in changing environments. Therefore, the present application proposes a self-adaptive transmission method for wide-area distributed data mobile authorization to solve the problems in the prior art. SUMMARY
[0004] To solve the above problems, the present application proposes a self-adaptive transmission method for wide-area distributed data mobile authorization. The present application ensures the basic security baseline of transmission start through admission verification, realizes fine balance between security and efficiency through dynamic decision-making based on multi-dimensional quantification and policy weight, and realizes continuous optimization and security guardianship of the transmission process through closed-loop regulation based on performance and state feedback, thereby achieving the purpose of self-adaptive transmission of wide-area distributed data mobile authorization and solving the problems in the prior art.
[0005] In order to achieve the purpose of the present application, the present application realizes the adaptive transmission method for wide-area distributed data mobile authorization through the following technical solutions: a wide-area distributed data mobile authorization adaptive transmission method, comprising the following steps:
[0006] Step one: receiving a transmission request from a data owner, the transmission request comprising an authorization token, a target data identifier and an authorized user identifier, and then verifying the validity of the authorization token to confirm the transmission authority;
[0007] Step two: after verification, collecting the network connectivity state of the transmission path at the current time, the device compliance state of the authorized user equipment and the security risk state of the current environment, then querying and obtaining the data sensitivity level of the target data based on the target data identifier, and then matching the network connectivity state, the device compliance state and the security risk state with the pre-defined admission rule set associated with the data sensitivity level, and generating a transmission admission credential after successful matching;
[0008] Step three: after obtaining the transmission admission credential, collecting real-time network performance data of the transmission path, real-time device state data of the authorized user equipment and real-time security threat data, then generating a transmission strategy instruction based on the data sensitivity level through a decision model;
[0009] Step four: executing data transmission according to the transmission strategy instruction, and monitoring the transmission process to generate performance indicators and state signals, and when the performance indicators and state signals meet the pre-defined re-decision trigger condition, triggering and re-executing step three to generate and apply updated transmission strategy instructions.
[0010] Further improvement lies in that in the step two, the data sensitivity level is divided into public, internal, secret and top secret.
[0011] Further improvement lies in that in the step two, the pre-defined admission rule set is composed of a plurality of admission rules, each admission rule being associated with a data sensitivity level and specifying a first condition to be met by the network connectivity state of the transmission path, a second condition to be met by the device compliance state and a third condition to be met by the environmental security risk state at this level.
[0012] Further improvement lies in that the first condition is that the network reachability is true, the second condition is that the device remaining power is higher than a first threshold and the current network type of the device belongs to an allowed type list, and the third condition is that the environmental security risk level is not higher than the allowed highest risk level.
[0013] Further improvement lies in that in the step three, the specific way of the decision model to generate the transmission strategy instruction is:
[0014] S1: quantifying real-time network performance data, real-time device status data and real-time security threat data into network quality score, device reliability score and environment security score respectively through pre-set scoring function;
[0015] S2: obtaining weight configuration according to data sensitivity level from pre-set weight strategy table, thereby weighting and summing network quality score, device reliability score and environment security score to obtain comprehensive score, and selecting transmission path according to comprehensive score;
[0016] S3: inputting data sensitivity level and environment security score into rule engine, and determining encryption algorithm, key length and data block size according to pre-set rule;
[0017] S4: selecting transmission protocol based on network quality score, and finally generating transmission strategy instruction containing transmission path, encryption algorithm, key length, data block size and transmission protocol-when network quality score is higher than protocol switching threshold, selecting high-performance transmission protocol based on UDP, and when network quality score is lower than protocol switching threshold, selecting high-reliability transmission protocol based on TCP.
[0018] Further improvement lies in that in step three, real-time network performance data includes available bandwidth, round-trip delay and packet loss rate, real-time device status data includes device remaining power percentage and available storage space, and real-time security threat data includes malicious IP address activity score, threat feature matching frequency and regional threat warning level.
[0019] Further improvement lies in that the weight strategy table defines weight coefficients of network quality score, device reliability score and environment security score under different data sensitivity levels, wherein weight coefficient of environment security score increases with the increase of data sensitivity level.
[0020] Further improvement lies in that the pre-set rule in the rule engine is that the combination of data sensitivity level and environment security score is mapped to determined encryption algorithm, key length and data block size.
[0021] Further improvement lies in that in step four, performance index is actual transmission throughput and actual transmission delay, and re-decision trigger condition is that actual transmission throughput continuously falls below expected throughput threshold or actual transmission delay continuously rises above expected delay threshold.
[0022] Further improvement lies in that in step four, state signal is validity state of authorization token, and re-decision trigger condition further includes monitoring of invalidation of authorization token.
[0023] The beneficial effects of the present application are: the present application constructs a dynamic security defense line before transmission starts through a multi-level access verification mechanism that integrates network connectivity, device compliance and environmental security, ensuring that only requests that meet the preset security baseline can be granted access, thereby avoiding the risk of starting transmission in an unsafe environment from the source. Then, during the transmission execution process, real-time data of network performance, device status and security threats are continuously collected and quantified into comparable scores, and then comprehensive evaluation is carried out according to the weight strategy determined by the inherent sensitivity level of the data, so as to dynamically select the optimal transmission path. At the same time, the same sensitivity level is accurately matched with the real-time security situation by means of the rule engine, and the most appropriate encryption strength, block size and other security parameters are dynamically determined to make the transmission process achieve a dynamic balance between security and efficiency. Finally, by monitoring the actual transmission performance and authorized state, and feeding back to trigger a new round of perception and decision, a complete adaptive closed loop is formed, which not only makes the optimal decision at the beginning of transmission, but also can respond to network jitter, device power decline, sudden security threats and other dynamic changes during transmission, realize the adjustment and seamless switching of transmission strategy, thereby continuously guaranteeing the service quality and security compliance of data transmission throughout the whole process, and finally realizing the data mobile service capability with flexibility, resilience and high reliability for mobile authorized users in a complex and open wide area network environment. BRIEF DESCRIPTION OF DRAWINGS
[0024] Figure 1 is the overall process flowchart of the steps of the present application.
[0025] Figure 2 is the workflow diagram of step one of the present application.
[0026] Figure 3 is the workflow diagram of step two of the present application.
[0027] Figure 4 is the workflow diagram of step three of the present application.
[0028] Figure 5 is the workflow diagram of step four of the present application. DETAILED DESCRIPTION
[0029] In order to deepen the understanding of the present application, the present application will be further described in combination with the embodiments below, and the present embodiments are only used to explain the present application and do not constitute a limitation on the protection scope of the present application.
[0030] According to Figures 1-5 , the present embodiment proposes an adaptive transmission method for wide-area distributed data mobile authorization, including the following steps:
[0031] Step one, receiving data mobile transmission request and verification
[0032] The data owner initiates a data movement transmission request through a client, which contains three core elements, namely:
[0033] Authorization token: a digitally signed token issued by a central authorization server, which proves that the data owner has authorized the specified user to access the target data;
[0034] Target data identifier: a unique ID that identifies the data to be transmitted;
[0035] Authorized user identifier: the ID of the user or device that receives the data.
[0036] After receiving the request, the digital signature validity and timeliness of the authorization token are verified. If the verification fails, the process terminates and an error is returned. If the verification is passed, it is confirmed that the transmission has legal authority, and the next step is entered.
[0037] Step two, generate transmission access credentials after verification
[0038] The purpose of this step is to perform a "safety and environmental health" check before transmission to ensure that the basic conditions are met. Therefore, after verification, the network connectivity state of the transmission path at the current time, the device compliance state of the authorized user device, and the safety risk state of the current environment are collected, specifically:
[0039] Network connectivity state: an ICMP Ping probe is initiated to the target user device to confirm that the network it is currently connected to is reachable, and the initial round-trip delay (e.g. 45ms) is obtained;
[0040] Device compliance state: through a lightweight agent installed on the user device, its remaining power (e.g. 65%) and current network connection type (e.g. "5G") are obtained;
[0041] Safety risk state: query threat intelligence service to obtain the comprehensive safety risk level (e.g. "medium") related to the user device's current IP address and geographic location, which is divided into low, medium and high.
[0042] Then, according to the target data identifier, the data sensitivity level (public, internal, secret and top secret) of the data is queried from the authorization and policy service module, and this embodiment takes secret as an example, that is, the network connectivity state, device compliance state and safety risk state are matched with the pre-defined access rule set associated with the data sensitivity level.
[0043] So the data collected in this embodiment is (initial round-trip delay 45ms, remaining power 65%, network connection type 5G, safety risk level medium).
[0044] Correspondingly, the predefined admission rule set defines the minimum hard conditions that must be met for initiating transmission under different sensitivity levels, as shown in Table 1 below:
[0045] Table 1
[0046]
[0047] Then, match the collected data with the content of Table 1, then:
[0048] First condition: network is reachable (true) and latency 45ms < 150ms (true), so it is satisfied;
[0049] Second condition: power 65% > 30% (true) and network type "5G" belongs to {Wi-Fi, 5G} (true), so it is satisfied;
[0050] Third condition: environmental safety risk "medium" ≠ "low" (false), so it is not satisfied.
[0051] Thus, due to the third condition not being satisfied, this admission check fails, and the transmission request is rejected, and the data owner is notified that the current environmental safety risk level does not meet the transmission requirements of secret-level data.
[0052] Correspondingly, assuming another scenario, the safety risk level is low. All conditions are satisfied, the admission check is passed, and then a transmission admission credential is generated, which is a temporary and encrypted session ticket.
[0053] Step three, adaptive strategy decision
[0054] After obtaining the transmission admission credential, collect real-time network performance data of the transmission path, real-time device state data of the authorized user equipment, and real-time security threat data, and then generate transmission strategy instructions based on the data sensitivity level through the decision model. Specifically:
[0055] Real-time network performance data includes available bandwidth, round-trip latency, and packet loss rate, i.e., the available bandwidth (A: 50Mbps, B: 30Mbps), round-trip latency (A: 50ms, B: 80ms), and packet loss rate (A: 0.1%, B: 0.5%) of each selectable path (such as path A, path B) from the probe to the target user;
[0056] Real-time device state data includes device remaining battery percentage and available storage space, with the remaining battery percentage (60%) and available storage space (5GB) obtained from the device agent;
[0057] The real-time security threat data includes malicious IP address activity score, threat feature matching frequency, and regional threat warning level (low, medium, and high), i.e., the malicious IP activity score (40 / 100), threat feature matching frequency (5 times / minute), and regional threat warning level ("low") obtained from the threat intelligence service.
[0058] Further, the specific way in which the decision model generates the transmission strategy instruction is:
[0059] S1: Through a pre-set scoring function, the real-time network performance data, real-time device status data, and real-time security threat data are quantified into network quality scores, device reliability scores, and environment security scores (0-100 points, the higher the score, the better), in particular:
[0060] The network quality score = f1(bandwidth, latency, packet loss rate), for example, path A score = 85, path B score = 70;
[0061] The device reliability score = f2(electricity, storage space), for example, score = 80;
[0062] The environment security score = f3(malicious IP score, threat frequency, warning level), for example, score = 75.
[0063] S2: According to the data sensitivity level, the pre-set weight strategy table (which defines the weight coefficients of the network quality score, device reliability score, and environment security score under different data sensitivity levels, and the weight coefficient of the environment security score increases with the data sensitivity level) is queried to obtain the weight configuration, so as to weight and sum the network quality score, device reliability score, and environment security score to obtain a comprehensive score, and the transmission path is selected according to the comprehensive score. The weight strategy table is shown in Table Two below:
[0064] Table Two
[0065]
[0066] Then, according to the weight strategy corresponding to the secret shown in the table, the comprehensive score of each path is calculated, for example:
[0067] The path A comprehensive score = 85 * 0.3 + 80 * 0.3 + 75 * 0.4 = 79.5;
[0068] The path B comprehensive score = 70 * 0.3 + 80 * 0.3 + 75 * 0.4 = 75.0;
[0069] Therefore, path A is selected as the current optimal transmission path.
[0070] S3: Input the data sensitivity level and the environment security score into the rule engine (i.e., "secret" "75"), and determine the encryption algorithm, key length, and data block size according to the preset rules. The rules preset in the rule engine are specifically the combination of the data sensitivity level and the environment security score mapped to the determined encryption algorithm, key length, and data block size, as shown in Table Three below:
[0071] Table Three
[0072]
[0073] According to the content of Table Three, the encryption algorithm is determined to be AES-256-GCM, the key length is 256 bits, and the data block size is 1MB.
[0074] S4: Select the transmission protocol based on the network quality score. When the network quality score is higher than the protocol switching threshold, select the high-performance transmission protocol based on UDP; when the network quality score is lower than the threshold, select the high-reliability transmission protocol based on TCP, i.e., select the protocol based on the network quality score of Path A (85 points). The preset protocol switching threshold is 70 points. Since 85 > 70, the high-performance transmission protocol based on QUIC is selected to pursue higher efficiency. Finally, the transmission strategy instruction containing the transmission path, encryption algorithm, key length, data block size, and transmission protocol is generated, as follows: { "transmission path": "Path A", "encryption algorithm": "AES-256-GCM", "key length": 256, "block size": "1MB", "transmission protocol": "QUIC"}.
[0075] Step Four, Strategy Execution and Monitoring Optimization
[0076] According to the transmission strategy instruction, perform data transmission and monitor the transmission process to generate performance indicators and status signals. When the performance indicators and status signals meet the predefined re-decision trigger conditions, trigger and re-execute Step Three to generate and apply updated transmission strategy instructions. The performance indicators are actual transmission throughput and actual transmission latency, and the re-decision trigger conditions are that the actual transmission throughput continuously falls below the expected throughput threshold or the actual transmission latency continuously exceeds the expected latency threshold.
[0077] The status signal is the validity status of the authorization token, and the re-decision trigger condition also includes monitoring that the authorization token is invalid.
[0078] Specifically, during the transmission, performance indicators (actual average throughput and actual average latency are calculated every 10 seconds) and status signals (the status of the authorization token is continuously monitored) are continuously collected. Assuming that the transmission has been going on for 2 minutes, the monitoring finds that the actual average throughput has dropped from the stable 45 Mbps to 20 Mbps, and has been below the expected throughput threshold (40 Mbps) for 30 seconds, while the actual average latency has risen to 120 ms. Thus, the performance indicators (low throughput and high latency) trigger the predefined re-decision condition.
[0079] The current transmission strategy optimization process is immediately interrupted, and then step three is entered, i.e., the latest real-time environment data is immediately collected (it may be found that the bandwidth of path A has suddenly dropped and path B has become relatively stable), and the complete decision-making process is re-run in combination with the unchanged "secret" level. Under this process, a new strategy instruction is output, and then the transmission is continued according to the new strategy instruction until the transmission task is completed.
[0080] The basic principles, main features and advantages of the present application are shown and described above. It should be understood by those skilled in the art that the present application is not limited by the above examples, and the above examples and descriptions in the specification are only to illustrate the principles of the present application. Without departing from the framework and scope of application of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the present application. The scope of protection of the present application is defined by the appended claims and their equivalents.
Claims
1. An adaptive transmission method for wide-area distributed data movement authorization, characterized in that: Includes the following steps: Step 1: Receive a transfer request from the data owner, which includes an authorization token, a target data identifier, and an authorized user identifier. Then verify the validity of the authorization token to confirm the transfer permission. Step 2: After successful verification, collect the network connectivity status of the transmission path at the current moment, the device compliance status of the authorized user device, and the security risk status of the current environment. Then, based on the target data identifier, query and obtain the data sensitivity level of the target data. Then, match the network connectivity status, device compliance status, and security risk status with the predefined access rule set associated with the data sensitivity level. If the match is successful, generate a transmission access credential. Step 3: After obtaining the transmission access credentials, collect real-time network performance data of the transmission path, real-time device status data of authorized user devices, and real-time security threat data. Then, based on the data sensitivity level, generate transmission policy instructions through a decision model. Step 4: Execute data transmission according to the transmission policy instructions and monitor the transmission process to generate performance indicators and status signals. When the performance indicators and status signals meet the predefined re-decision triggering conditions, trigger and re-execute Step 3 to generate and apply updated transmission policy instructions.
2. The adaptive transmission method for wide-area distributed data movement authorization according to claim 1, characterized in that: In step two, the data sensitivity levels are divided into public, internal, secret, and top secret.
3. The adaptive transmission method for wide-area distributed data movement authorization according to claim 1, characterized in that: In step two, the predefined access rule set consists of several access rules. Each access rule is associated with a data sensitivity level and specifies the first condition that the network connectivity status of the transmission path must meet, the second condition that the device compliance status must meet, and the third condition that the environmental security risk status must meet under that level.
4. The adaptive transmission method for wide-area distributed data movement authorization according to claim 1, characterized in that: The first condition is that network reachability is true; the second condition is that the device's remaining battery power is higher than a first threshold and the device's current network type belongs to the allowed type list; and the third condition is that the environmental safety risk level is not higher than the highest allowed risk level.
5. The adaptive transmission method for wide-area distributed data movement authorization according to claim 1, characterized in that: In step three, the decision model generates the transmission strategy instructions in the following specific way: S1: Using a pre-set scoring function, real-time network performance data, real-time device status data, and real-time security threat data are quantified into network quality score, device reliability score, and environmental security score, respectively. S2: Based on the data sensitivity level, query the preset weight strategy table to obtain the weight configuration, and then perform a weighted summation of the network quality score, equipment reliability score and environmental security score to obtain a comprehensive score, and select the transmission path based on the comprehensive score; S3: Then input the data sensitivity level and environmental security score into the rule engine, and determine the encryption algorithm, key length and data block size according to the preset rules; S4: Select the transmission protocol based on the network quality score, and finally generate a transmission policy instruction containing the transmission path, encryption algorithm, key length, data block size and transmission protocol. When the network quality score is higher than the protocol switching threshold, select the high-performance transmission protocol based on UDP; when it is lower than the threshold, select the high-reliability transmission protocol based on TCP.
6. The adaptive transmission method for wide-area distributed data movement authorization according to claim 1, characterized in that: In step three, the real-time network performance data includes available bandwidth, round-trip latency, and packet loss rate; the real-time device status data includes the remaining battery percentage and available storage space; and the real-time security threat data includes malicious IP address activity score, threat feature matching frequency, and regional threat warning level.
7. The adaptive transmission method for wide-area distributed data movement authorization according to claim 5, characterized in that: The weighting strategy table defines the weight coefficients of network quality score, device reliability score, and environmental security score under different data sensitivity levels, wherein the weight coefficient of environmental security score increases as the data sensitivity level increases.
8. The adaptive transmission method for wide-area distributed data movement authorization according to claim 5, characterized in that: The rules pre-set in the rule engine specifically map the combination of data sensitivity level and environmental security score to a determined encryption algorithm, key length, and data block size.
9. The adaptive transmission method for wide-area distributed data movement authorization according to claim 1, characterized in that: In step four, the performance indicators are actual transmission throughput and actual transmission latency. The re-decision trigger condition is that the actual transmission throughput is consistently lower than the expected throughput threshold or the actual transmission latency is consistently higher than the expected latency threshold.
10. The adaptive transmission method for wide-area distributed data movement authorization according to claim 1, characterized in that: In step four, the status signal is the validity status of the authorization token, and the re-decision triggering condition also includes detecting that the authorization token has expired.