Cloud-based secure data transmission system and method

By detecting transient anomalies in link load and generating a protective state identifier, locking session resources, and performing encrypted data scheduling and decryption fault tolerance processing, the problem of frequent encrypted session failures in cloud computing environments is solved, and the stability and continuity of encrypted data transmission are achieved.

CN122137759APending Publication Date: 2026-06-02GUANGZHOU JIYUN INFORMATION TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGZHOU JIYUN INFORMATION TECH CO LTD
Filing Date
2026-03-04
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In cloud computing environments, changes in cloud node load cause transient fluctuations in link load. Existing technologies struggle to effectively distinguish between transient anomalies and communication connection failures, leading to frequent encrypted session failures and unstable encrypted data transmission.

Method used

The communication transmission detection module detects transient anomalies in the link load, generates a load fluctuation protection state flag, locks session resources, performs encrypted data scheduling and decryption fault tolerance processing to avoid misjudging the encryption session failure, and restores the encryption session after the link stabilizes.

Benefits of technology

It improves the accuracy of encrypted session state determination, reduces the risk of frequent encrypted session failures and communication interruptions, and enhances the stability and continuity of encrypted data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137759A_ABST
    Figure CN122137759A_ABST
Patent Text Reader

Abstract

This invention discloses a cloud computing-based data security transmission system and method, belonging to the field of data security technology. The system includes the following steps: during data transmission, it detects whether the communication path has switched. When no switching occurs, it analyzes the abnormal communication characteristics of the sending node. When the abnormal communication characteristics of the sending node indicate a transient abnormality in link load, it performs load fluctuation protection processing on the current data transmission encryption session, performs encrypted data scheduling and generates and reconstructs encrypted fragmentation units, controls data output by receiving backpressure signals, and simultaneously performs decryption fault tolerance processing on the received encrypted fragmentation units. Thus, the sending node performs fragment-level confirmation and recovery. When the transient abnormality in link load is resolved, the transmission of the data to be sent is completed. This invention solves the technical problem in the prior art where internal cloud link load fluctuations cause transient abnormalities in communication connections, resulting in encryption session failure and unstable continuous secure transmission of encrypted data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and in particular to a data security transmission system and method based on cloud computing. Background Technology

[0002] With the widespread application of cloud computing technology, data processing and storage are gradually migrating from traditional local systems to cloud platforms. In cloud computing environments characterized by multi-tenant resource sharing, virtualization deployment, and elastic scheduling, a large number of services operate in a distributed manner, and data is frequently transmitted between multiple cloud nodes. Cloud computing platforms manage computing, storage, and network resources uniformly through virtualization and centralized scheduling mechanisms, making the operating status of cloud nodes highly dynamic, which in turn leads to transient fluctuations in the load of node inbound and outbound links. Internal cloud link load fluctuations typically manifest as momentary link congestion, queue backlogs, or forwarding latency fluctuations. Although these do not cause substantial changes to communication endpoints or network topology, they do cause instability in communication quality during cloud data transmission. Since secure data transmission in cloud computing environments generally relies on continuous communication mechanisms based on encrypted sessions, transient fluctuations in link load caused by dynamic changes in the operating status of cloud nodes can easily directly affect the transmission of encrypted data, interfering with encrypted session maintenance, state synchronization, and control message transmission. This poses a real and unavoidable impact on the continuity and stability of encrypted data transmission in cloud computing environments.

[0003] Existing cloud-based data security transmission systems typically segment the data to be transmitted and construct transmission dynamic change parameters based on the local dynamic change characteristics of each data subsequence. On this basis, they calculate the gain characteristics and mapping characteristics of the transmitted information, assign differentiated chaotic mapping strengths to different data subsequences, and encrypt the data in conjunction with advanced encryption standards, thereby achieving data security protection during transmission.

[0004] For example, the Chinese invention patent with announcement number CN118250096B discloses a method for secure data transmission of a cloud service platform based on cloud computing, which includes: acquiring data transmitted from the cloud service platform; initially dividing the data transmitted from the cloud service platform; constructing transmission dynamic change coefficients based on the local information dynamic change characteristics of each subsequence after the initial division; calculating transmission information gain characteristic coefficients based on the transmission dynamic change coefficients; calculating transmission information mapping characteristic coefficients based on the transmission information gain characteristic coefficients; determining the chaotic mapping intensity of different subsequences based on the transmission information mapping characteristic coefficients; and completing the secure transmission of cloud service platform data using advanced encryption standards based on the chaotic mapping results of different subsequences.

[0005] For example, the Chinese invention patent with announcement number CN116527382B discloses a cloud computing-based data security transmission system, which includes: pre-dividing the computing data into different individual data, then dividing the individual data into nine data streams, and then using an encryption template to encrypt the nine data streams sequentially, using a parity-opposite padding method to change the traditional logic method and improve the security of the data transmission process. Subsequently, a key is set for the transmission protocol, and the key is set by the user.

[0006] The above-mentioned technology has at least the following technical problems: In existing cloud-based data security transmission processes, the focus is typically on enhancing data security through complex encryption mechanisms, while neglecting the issues of communication state fluctuations and encrypted session stability during data transmission. In cloud computing environments, cloud nodes are prone to sudden or structural changes in communication behavior within a short period due to load variations and migration scheduling, leading to transient fluctuations in the load of node inbound and outbound links. Current technologies determine the validity of encrypted sessions based on communication state, and this determination information is susceptible to delays or jitter. This results in a lack of ability to distinguish between transient anomalies and genuine failures, easily misjudging transient anomalies caused by link load fluctuations as communication connection failures, thus triggering encrypted session failures or reconstruction operations. This not only increases communication latency and computational overhead but may also cause interruptions or loss of encrypted data transmission. Therefore, there is a technical problem where internal cloud link load fluctuations lead to transient anomalies in communication connections, causing encrypted session failures and unstable continuous secure transmission of encrypted data. Summary of the Invention

[0007] To address the technical problems of existing technologies, such as transient anomalies in communication connections caused by fluctuations in cloud internal link load, resulting in encrypted session failures and unstable continuous secure transmission of encrypted data, this invention provides a cloud-based data security transmission system and method. The technical solution is as follows: On one hand, a cloud-based data security transmission system is provided, comprising: a communication transmission detection module, an encrypted session protection module, an encryption processing module, a decryption processing module, and an encrypted session recovery module. The communication transmission detection module detects whether the communication path has switched during data transmission. If no switch has occurred, it acquires the transmission status parameters of the sending node within a preset statistical window and analyzes the abnormal communication operation characteristics of the sending node; otherwise, it determines the node to be in a suspected failure state. These abnormal communication operation characteristics include transient abnormal link load and stable link load. The encrypted session protection module performs load fluctuation protection processing on the encrypted session of the current data transmission when the abnormal communication operation characteristic of the sending node is transient abnormal link load; otherwise, it enters the encrypted session status processing flow for communication path switching. The load fluctuation protection processing includes... The system includes: a failure state freeze and session resource lock; an encryption processing module for scheduling encrypted data and generating and reconstructing encrypted fragment units during load fluctuation protection, and controlling data output by receiving backpressure signals; a decryption processing module for performing decryption fault tolerance processing on received encrypted fragment units during load fluctuation protection, obtaining corresponding decrypted fragment data, and enabling the sending node to perform fragment-level confirmation and recovery of the encrypted fragment units. During the decryption fault tolerance processing, it obtains decryption feedback information, receives backpressure signals, and sends them back to the sending node; and an encrypted session recovery module for monitoring abnormal communication operation characteristics of the sending node. The module releases the load fluctuation protection processing of the encrypted session and continues secure transmission of data to be sent in the encrypted session when the transient abnormality in the link load is detected to be resolved. Otherwise, monitoring continues.

[0008] On the other hand, a cloud-based data security transmission method is provided. This method includes: during data transmission, detecting whether a communication path has switched; if no switch has occurred, acquiring the transmission status parameters of the sending node within a preset statistical window, analyzing the abnormal communication operation characteristics of the sending node; otherwise, determining it as a suspected failure state. These abnormal communication operation characteristics include transient abnormal link load and stable link load. When the abnormal communication operation characteristic of the sending node is a transient abnormal link load, load fluctuation protection processing is applied to the encrypted session for the current data transmission; otherwise, the encrypted session state processing flow for communication path switching is entered. Load fluctuation protection processing includes failure state freezing and session resource locking. During load fluctuation protection, encrypted data scheduling and the generation and reconstruction of encrypted fragment units are performed. Data output control is achieved by receiving backpressure signals. During load fluctuation protection, decryption fault tolerance processing is performed on the received encrypted fragment units to obtain the corresponding decrypted fragment data. The sending node then performs fragment-level confirmation and recovery on the encrypted fragment units. During the decryption fault tolerance processing, decryption feedback information is obtained, backpressure signals are obtained, and sent back to the sending node. The abnormal communication operation characteristics of the sending node are monitored until the transient abnormality of the link load is detected and resolved. At this point, the load fluctuation protection processing of the encrypted session is released, and the secure transmission of the data to be sent in the encrypted session continues. Otherwise, monitoring continues.

[0009] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following: 1. The cloud computing-based secure data transmission system provided by this invention detects whether the communication path has switched. When no switch has occurred, it obtains each transmission status parameter within a statistical window, processes it to obtain the parameter fluctuation value of each transmission status parameter, compares it with the parameter fluctuation threshold set, and thus obtains the marked status of each statistical window. It counts the total number of statistical windows marked as exceeding the limit and compares it with the threshold of the number of exceeding the limit to obtain the communication operation abnormal characteristics of the sending node. This system effectively distinguishes between transient abnormalities and stable states in scenarios with fluctuating link load, and improves the accuracy of encrypted session state determination.

[0010] 2. This invention generates a load fluctuation protection state identifier for the encrypted session and writes it into the corresponding status control table. When the session indication signal is invalid, it queries the load fluctuation protection state identifier corresponding to the current encrypted session. When the load fluctuation protection state identifier is valid, the session indication signal is temporarily stored without triggering the corresponding session failure processing. At the same time, the sending node assigns the corresponding protection state session identifier to the encrypted session. When the session maintenance condition is triggered, the session maintenance processing of the encrypted session and its session key is suspended. This improves the stability of the encrypted session in complex cloud network environments and reduces the risk of communication interruption caused by frequent failures and recovery of the encrypted session.

[0011] 3. This invention obtains a preset standard window width, calculates the offset distance of the encrypted fragmentation unit at the receiving node to the sequence number, thereby obtaining the corresponding fragmentation out-of-order index, and processes it to obtain the extended window width, thus completing the decryption sequence number window expansion; at the same time, the receiving node updates the decryption failure counter and the corresponding decryption failure time sequence, calculates the cumulative failure value and the minimum failure time interval, and thereby determines the decryption status, thereby avoiding premature abnormal judgment caused by transient out-of-order or time delay jitter, and improving the fault tolerance capability of the decryption process under complex link conditions. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 A schematic diagram of the structure of a cloud computing-based secure data transmission system provided in this application embodiment; Figure 2 A flowchart illustrating the encrypted session secure transmission process of a cloud-based data security transmission system provided in this application embodiment; Figure 3 A flowchart illustrating the decryption and fault-tolerant processing of a cloud-based data security transmission system provided in this application embodiment; Figure 4 The overall flowchart of the cloud computing-based secure data transmission method provided in the embodiments of this application is shown. Detailed Implementation

[0014] The technical solution of the present invention will now be described with reference to the accompanying drawings.

[0015] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.

[0016] In the embodiments of this invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning. Similarly, the terms "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning.

[0017] In this embodiment of the invention, sometimes a subscript such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning they express is the same.

[0018] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0019] like Figure 1 The diagram shows the structure of a cloud-based secure data transmission system provided in this application embodiment. The cloud-based secure data transmission system includes: a communication transmission detection module, an encrypted session protection module, an encryption processing module, a decryption processing module, and an encrypted session recovery module. The communication transmission detection module detects whether the communication path has switched during data transmission. When no switch has occurred, it obtains the transmission status parameters of the sending node within a preset statistical window and analyzes the abnormal communication operation characteristics of the sending node. Otherwise, it determines the state as a suspected failure. The abnormal communication operation characteristics include transient abnormal link load and stable link load. The encrypted session protection module performs load fluctuation protection processing on the encrypted session of the current data transmission when the abnormal communication operation characteristic of the sending node is transient abnormal link load; otherwise, it enters the encrypted session state of communication path switching. The load fluctuation protection process includes failure state freezing and session resource locking. The encryption module performs encrypted data scheduling and generates and reconstructs encrypted fragment units during load fluctuation protection, controlling data output by receiving backpressure signals. The decryption module performs decryption fault tolerance processing on the received encrypted fragment units during load fluctuation protection, obtaining the corresponding decrypted fragment data. The sending node then performs fragment-level confirmation and recovery of the encrypted fragment units. During decryption fault tolerance processing, it obtains decryption feedback information, receives backpressure signals, and sends them back to the sending node. The encrypted session recovery module monitors abnormal communication characteristics of the sending node until the transient abnormality in the link load is detected and resolved. At this point, it releases the load fluctuation protection process for the encrypted session and continues the secure transmission of data to be sent in the encrypted session; otherwise, monitoring continues.

[0020] In this embodiment, as Figure 2 As shown, Figure 2 The flowchart of the encrypted session secure transmission process of the cloud-based data security transmission system provided in this application embodiment is as follows: During data transmission, the communication transmission detection module detects whether the communication path has switched. When no switch has occurred, the transmission status parameters of the sending node are obtained within a preset statistical window, and the communication operation abnormality characteristics of the sending node are analyzed. When the communication operation abnormality characteristic is determined to be a stable link load, normal data transmission is maintained. When the communication operation abnormality characteristic is determined to be a transient abnormality in the link load, load fluctuation protection processing is performed on the current encrypted session. During the load fluctuation protection processing, the sending node performs encrypted data scheduling and encrypted fragment unit generation and reconstruction processing, and performs data output control by receiving back pressure signals. At the same time, the receiving node performs decryption fault tolerance processing to obtain decrypted fragment data, and the sending node performs fragment-level confirmation and recovery. When the transient abnormality in the link load is resolved, the load fluctuation protection processing is released, and the secure transmission of the data to be sent in the encrypted session continues.

[0021] The method for detecting whether the communication path has been switched is as follows: During data transmission, when the encrypted session is established, the sending node records the communication connection identifier corresponding to the current encrypted session and continuously detects whether the round-trip connectivity of the encrypted heartbeat message and the corresponding communication connection identifier of the encrypted session have changed. When the communication connection identifier is detected to have changed or the round-trip connectivity of the encrypted heartbeat message is interrupted and re-established, it is determined that the communication path has been switched; otherwise, it is determined that the communication path has not been switched.

[0022] The encrypted heartbeat message round-trip connectivity refers to the fact that during the current encrypted session, the sending node sends encrypted heartbeat messages to the receiving node according to a preset heartbeat period, and receives an acknowledgment response from the receiving node within a preset response time limit. The encrypted heartbeat message round-trip connectivity indicates whether the bidirectional communication link between the sending node and the receiving node remains reachable and stable under this encrypted session.

[0023] The sending node invokes the communication protocol stack locally and obtains transmission status parameters based on the current encrypted session's transmission process. These parameters include: encrypted data packet transmission success rate, encrypted data packet retransmission ratio, encrypted heartbeat message response latency, and the number of consecutive heartbeat failures. Specifically, the encrypted data packet transmission success rate represents the proportion of successfully transmitted encrypted data packets within a preset statistical window; the encrypted data packet retransmission ratio represents the ratio between the number of retransmitted encrypted data packets within the statistical window and the total number of transmitted packets; the encrypted heartbeat message response latency represents the round-trip time from sending to receiving and returning an acknowledgment for the encrypted heartbeat message; and the number of consecutive heartbeat failures represents the number of times a heartbeat acknowledgment response is not received consecutively within the statistical window.

[0024] The encrypted session state handling process for communication path switching involves the following steps: A complete session state review is performed on the current encrypted session. This review confirms whether the original encrypted session still meets the conditions for continued use under the new communication path. This includes: verifying the consistency of the session key used in the current session to confirm that the encryption and decryption keys are consistent; verifying the validity of the encrypted session identifier to confirm that the session has not expired; and confirming the basic communication connectivity to confirm the availability of the communication path. If any of these conditions are not met, the system decides to discard the original encrypted session; otherwise, the system decides to continue using the original encrypted session. This independent handling process under communication path switching allows the system to distinguish between structural changes caused by path switching and transient anomalies caused by link load, avoiding session failure determinations and thus improving the accuracy and stability of encrypted session management.

[0025] Based on the extended decryption sequence number window, the validity of the sequence number of the arriving encrypted fragment unit is determined. Subsequently, for the encrypted fragment units falling within the range of the extended decryption sequence number window, the decryption algorithm and integrity verification are performed to obtain the corresponding decrypted fragment data, including: the decrypted fragment payload data, the status result of fragment decryption success or failure, and the fragment sequence number and session identifier corresponding to the fragment, which are used for subsequent fragment-level confirmation and recovery control.

[0026] The specific method for resolving link load transient anomalies is as follows: when the total number of exceedances is below the threshold number of exceedances within a preset statistical interval consisting of multiple continuous statistical windows, it is determined that the communication operation anomaly of the current encrypted session has recovered from link load transient anomaly to link load stability, and the link load transient anomaly is considered to be resolved.

[0027] Furthermore, within a preset statistical window, the transmission status parameters of the current encrypted session corresponding to the sending node are obtained. These parameters include the encryption data packet transmission success rate, encryption data packet retransmission ratio, encryption heartbeat message response latency, and the number of consecutive heartbeat failures. The absolute difference of the transmission status parameters in adjacent statistical window pairs is processed to obtain the parameter fluctuation value of each transmission status parameter. A preset parameter fluctuation threshold set is obtained, and each parameter fluctuation value is compared with the parameter fluctuation threshold set. When at least two transmission status parameters have parameter fluctuation values ​​greater than their corresponding parameter fluctuation thresholds, the adjacent statistical window pair is marked as... If a statistical window is marked as exceeding the limit, it is otherwise marked as not exceeding the limit. When a statistical window is marked repeatedly, if the two markings are the same, the marking of the statistical window remains unchanged; if the two markings are different, the statistical window is marked as exceeding the limit. Within a preset statistical interval consisting of multiple consecutive statistical windows, the total number of statistical windows marked as exceeding the limit is counted to obtain the total number of exceeding limits. A preset threshold for the number of exceeding limits is obtained. The total number of exceeding limits is compared with the threshold for the number of exceeding limits. If the total number of exceeding limits is greater than the threshold for the number of exceeding limits, the communication operation abnormality of the current encrypted session is determined to be a transient abnormality in the link load; otherwise, it is determined to be a stable link load. The specific method is as follows: In this embodiment, since parameter mutations within a single statistical window may be caused by occasional jitter or instantaneous scheduling, to avoid a single anomaly excessively affecting the judgment result, the system performs different processing based on the results of repeated marking when the statistical window is repeatedly marked: if the results of multiple markings are consistent, the original marking remains unchanged; if the results of multiple markings are inconsistent, the statistical window is marked as out of limit. This causes the marking results of the statistical window to converge in the direction of anomalies, quickly identifying fluctuations in link load when a continuous abnormal trend occurs.

[0028] By judging the abnormal characteristics of the communication operation of the sending node, transient abnormal states caused by link load can be identified in advance and distinguished from structural changes such as communication path switching. This improves the continuity, stability and overall reliability of encrypted sessions and secure data transmission in the cloud computing environment.

[0029] Furthermore, when the communication operation anomaly of the sending node is characterized by transient link load anomaly, the sending node generates a corresponding load fluctuation protection state identifier for the encrypted session and writes the load fluctuation protection state identifier into the state control table of the corresponding encrypted session; it retrieves the session failure judgment condition and performs session state judgment on the session indication signal. If the session state judgment result is non-failure, the current encrypted session is maintained in a valid state; otherwise, it queries the load fluctuation protection state identifier corresponding to the current encrypted session. When the load fluctuation protection state identifier is valid, the session indication signal is temporarily stored, and the corresponding session failure processing is not triggered, thus completing the failure of the current encrypted session. The state is frozen; otherwise, the corresponding session invalidation process is triggered. Simultaneously, when the communication operation anomaly of the sending node is characterized by a transient link load anomaly, the sending node assigns a corresponding protected session identifier to the encrypted session and binds the protected session identifier to the encrypted session object and its corresponding session key object. During the validity period of the protected session identifier, when the session maintenance condition of the current encrypted session is triggered, the session maintenance process for the encrypted session and its session key is suspended. After the transient link load anomaly corresponding to the sending node is resolved, the above session maintenance process is executed; otherwise, the current valid state of the encrypted session and its session key is maintained. The specific method is as follows: In this embodiment, the state control table is used to record the current operating state and control flags of the encrypted session during data transmission. Its contents include the session's valid state, load fluctuation protection status, and state flag information related to session management. The state control table allows for centralized management of state changes in the encrypted session.

[0030] The fluctuation values ​​of parameters such as the number of consecutive heartbeat failures, the success rate of encrypted data packet transmission, and the retransmission ratio of encrypted data packets in the transmission status parameters are compared with the parameter fluctuation threshold set. When the parameter fluctuation value of any transmission status parameter is greater than its corresponding parameter fluctuation threshold, the session indication signal is determined to be invalid; otherwise, it is valid, and the current encrypted session is maintained in a valid state.

[0031] When the communication operation anomaly of the sending node is characterized by a transient abnormality in link load, the sending node assigns a corresponding protected session identifier to the encrypted session and writes the protected session identifier as a session state attribute field into the session state information of the current encrypted session object. At the same time, the protected session identifier is written into the key state information of the session key object corresponding to the encrypted session, thus completing the binding process of the protected session identifier.

[0032] Session maintenance conditions refer to the conditions that trigger maintenance operations such as session key update, key rotation, session renegotiation, or validity period check during the operation of an encrypted session. When any one of these conditions is met, session maintenance of the current encrypted session is triggered.

[0033] Session maintenance refers to routine management actions performed during the lifecycle of an encrypted session to maintain session security and availability, including but not limited to session validity verification and session parameter updates.

[0034] Session validity verification refers to the periodic or triggered checks performed during the lifecycle of an encrypted session to determine whether the current encrypted session can continue to be used. Specific operations include, but are not limited to, checking whether the session identifier is valid and confirming whether the session key versions used by the sending node and the receiving node are consistent. Session parameter update refers to adjusting or refreshing some session parameters related to the operation of the encrypted session during the lifecycle of the encrypted session.

[0035] By freezing the failure state when the link load experiences transient anomalies, the encrypted session remains in a valid state under short-term communication fluctuations, avoiding false failure judgments triggered by transient communication anomalies. This can suppress frequent session failures and reconstructions caused by unstructured anomalies such as link jitter, queuing delays, and instantaneous packet loss, reduce unnecessary session switching and overhead, and improve the continuity and stability of encrypted sessions in complex cloud network environments.

[0036] By locking resources for encrypted sessions and their associated session keys during load fluctuation protection, session-related resources remain controllable during periods of unstable communication, preventing management actions such as key updates and session rotations from overlapping with transient anomalies, which could lead to state inconsistencies and additional security risks.

[0037] Furthermore, the sending node sets a pre-encryption scheduling gate at the security layer and classifies the data to be sent according to its data attributes to obtain data types. These data types include session control data, encrypted heartbeat data, ordinary service data, and continuous service data. During load fluctuation protection processing, the sending node performs encryption processing on session control data and encrypted heartbeat data through the pre-encryption scheduling gate. Based on a preset baseline injection rate, ordinary service data is encrypted at the same rate. Encryption processing of continuous service data is paused, and the data is temporarily stored in the sending-side buffer queue as data to be sent until the load fluctuation protection state of the current encrypted session is lifted, at which point encryption processing resumes. The specific method is as follows: In this embodiment, the data to be sent is classified into session control data, encrypted heartbeat data, ordinary service data, and continuous service data according to the service type identifier marked within the sending node. The service type identifier is an attribute tag attached to the data to be sent by the sending node, indicating whether the data to be sent belongs to session control data, encrypted heartbeat data, ordinary service data, or continuous service data.

[0038] The pre-encryption scheduling gate is set before the data at the sending node undergoes encryption processing. It does not change the encryption algorithm or method, but rather acts as a control node for data entering the encryption process, constraining the order and rate of encryption for different data types. This prevents uncontrolled data accumulation or resource contention during fluctuating communication environments. Since session control data and encrypted heartbeat data are directly related to the maintenance of the encrypted session's state and connectivity confirmation, prioritizing the continuous entry of this type of data into the encryption and transmission process during transient fluctuations in link load helps maintain the observability of the encrypted session's state.

[0039] It should be noted that the thresholds and division scales preset in this invention are all uniformly preset by the system based on historical operational statistics. For example, the specific method for obtaining the preset benchmark injection rate is as follows: the sending node performs statistical analysis on the stability of the communication link based on historical operational data. During a historical period when the communication link is in normal working condition and the encrypted session has not entered the load fluctuation protection state, the encryption injection rate corresponding to a good situation is determined based on the data transmission situation during that period, and this rate is used as the preset benchmark injection rate.

[0040] Among them, the system obtains the preset capacity limit of the sending-side buffer queue. When the buffer queue reaches the capacity limit, the sending node suspends the addition of new continuous service data to the queue, and the system issues an alarm.

[0041] Continuous business data is typically characterized by large data volume, high encryption computation overhead, and long continuous injection time. When the link load experiences transient fluctuations, the continued entry of continuous business data into the encryption process will exacerbate the computational and buffering pressure on the sending node and amplify the impact of link jitter on the overall transmission. Therefore, suspending the encryption processing of this type of data during the load fluctuation protection process can reduce the system load peak, prevent encryption processing resources from being occupied for a long time, and thus reserve sufficient processing capacity for session control data, heartbeat data, and necessary ordinary business data. This effectively alleviates resource competition in a short period of time and enables the encrypted session to maintain basic stable operation in a fluctuating environment.

[0042] Furthermore, during the load fluctuation protection process, the jitter characteristics of each link within the statistical interval of the sending node are calculated, and a preset set of link jitter thresholds is obtained. The link jitter characteristics of each sending node are compared with the corresponding link jitter thresholds in the set. When all link jitter characteristics are below their respective thresholds, the encrypted data blocks are divided according to a preset first unit partitioning scale to obtain each encrypted fragment unit. When a link jitter characteristic is greater than its corresponding threshold, a link jitter characteristic difference value is obtained. All link jitter characteristic difference values ​​are averaged to obtain a comprehensive link jitter difference value. A scale mapping process is then performed to obtain a second unit partitioning scale, and the encrypted data blocks are divided according to this scale to obtain each encrypted fragment unit. Session association identification information is marked for each encrypted fragment unit by the sending node. The link jitter characteristics include the fluctuation amplitude of the round-trip delay of adjacent encrypted heartbeat messages, the dispersion of the sending and acknowledgment intervals of adjacent data packets, and the frequency of out-of-order data packets. The specific method is as follows: In this embodiment, the fluctuation amplitude of the round-trip delay of adjacent encrypted heartbeat messages is calculated as follows: within the statistical interval, the round-trip delay values ​​of multiple consecutive encrypted heartbeat messages are obtained in the order of their sending time. The round-trip delay value is the time taken for a single encrypted heartbeat message to be sent from the sending node to the receiving node for confirmation and return. The absolute difference between the round-trip delay values ​​of two adjacent heartbeat messages is calculated to obtain the difference between adjacent round-trip delays. The average of all adjacent round-trip delay differences is taken as the fluctuation amplitude of the round-trip delay of adjacent encrypted heartbeat messages. This link jitter feature is used to reflect the intensity of the change in link delay over a short period of time.

[0043] The dispersion of the interval between sending and acknowledging adjacent data packets is calculated as follows: within the statistical interval, the time interval between sending and acknowledging multiple consecutive encrypted data packets is obtained in the order of sending time; the absolute difference between adjacent time interval values ​​is calculated to obtain the difference value between adjacent intervals; the standard deviation is calculated based on all the difference values ​​between adjacent intervals to obtain the dispersion of the interval between sending and acknowledging adjacent data packets. This link jitter feature is used to characterize the stability of the link at the acknowledgment feedback level.

[0044] The method for calculating the out-of-order packet frequency is as follows: Within the statistical interval, the sending node assigns an incremental fragmentation sequence number to each encrypted data packet. Based on the fragmentation-level acknowledgment information returned by the receiving node, it determines whether the acknowledgment order is consistent with the sending order. When an inconsistency between the acknowledgment sequence number and the sending sequence number is detected, an out-of-order event is recorded; otherwise, a normal order event is recorded. Within the statistical interval, the total number of out-of-order events is divided by the total number of data packets sent to obtain the out-of-order packet frequency. This link jitter characteristic is used to reflect the stability of the link in terms of transmission order.

[0045] The encrypted data block is divided according to the preset first unit division scale. The specific method is as follows: starting from the starting position of the data sequence, the data is truncated sequentially according to the first unit division scale. Each truncation forms an encrypted fragment unit until the entire encrypted data block is divided. When the length of the remaining data at the end is less than the length of a complete fragment, the remaining data is taken as the last encrypted fragment unit.

[0046] The second unit division scale is obtained by performing scale mapping processing. The specific method is as follows: obtain the comprehensive link jitter difference value and the preset link jitter difference reference set, map and match the comprehensive link jitter difference value with the link jitter difference interval in the link jitter difference reference set, and select the corresponding unit division scale as the second unit division scale according to the interval where the comprehensive link jitter difference value is located. The jitter difference reference set includes the link jitter difference interval and the corresponding unit division scale.

[0047] The first unit partitioning scale is larger than the second unit partitioning scale. When all link jitter characteristics are below their corresponding thresholds, the link stability is high. Using a larger first unit partitioning scale can reduce the number of fragments and improve the overall throughput efficiency of encrypted data while ensuring transmission reliability. When at least one link jitter characteristic is greater than its corresponding threshold, it indicates that the link has a significant risk of fluctuation. In this case, by averaging the differences in link jitter characteristics and performing scale mapping, a smaller second unit partitioning scale is obtained, making the generated encrypted fragment units more accurate. This helps to reduce the impact of single fragment loss or out-of-order delivery on the reconstruction of the overall encrypted data, thereby improving transmission stability under load fluctuation conditions.

[0048] Session association identification information includes: fragment sequence number, length information, integrity identifier, and session identifier information. Through this session association identification information, the receiving node can accurately identify the fragment ownership relationship, verify fragment integrity, and support subsequent decryption fault tolerance processing and fragment-level confirmation and recovery in the presence of out-of-order, delayed, and fragment reconstruction conditions. This ensures the correct decryption and orderly reassembly of encrypted data in the context of link jitter.

[0049] Furthermore, the sending node receives a backpressure signal returned from the receiving node, which includes the receiving credit limit and the receiving pressure level; a preset credit limit threshold is obtained, and the receiving credit limit received by the sending node is divided by this threshold to obtain the credit limit ratio. This credit limit ratio is mapped and matched with a preset credit limit ratio reference table to obtain the corresponding rate adjustment factor. The baseline injection rate is multiplied by this rate adjustment factor to obtain the target injection rate. If the data type is ordinary business data, encryption processing is performed according to the target injection rate; a preset pressure level reference set is obtained, and the receiving pressure level of the sending node is matched and mapped with this pressure level reference set to obtain the fragmentation rule corresponding to the current interval. The encrypted fragmentation unit is then divided to obtain each encrypted fragmentation reconstruction unit; the pressure level reference set includes the receiving pressure level and the fragmentation rule, specifically as follows: In this embodiment, the receiving credit limit is calculated as follows: During the decryption process, the receiving node continuously records the total capacity of the receiving buffer used to store encrypted fragment units and the currently occupied capacity. The difference between the total buffer capacity and the currently occupied capacity is processed to obtain the current available buffer balance. The buffer balance mapping factor is obtained, and the current available buffer balance is multiplied by the buffer balance mapping factor to obtain the corresponding receiving credit limit. The receiving credit limit refers to the number of newly added encrypted fragment units that the receiving node can accommodate, and can dynamically reflect the real-time carrying capacity of the receiving node.

[0050] By encrypting ordinary business data according to the target injection rate, the data output rate of the sending node is matched with the real-time receiveability of the receiving node. This avoids buffer overflow and queuing delay accumulation caused by the sending node continuing to inject data at a fixed rate when the receiving node's processing capacity decreases, thus ensuring the continuity and stability of encrypted data transmission.

[0051] The receiving pressure level is calculated as follows: Within a statistical interval, the receiving node analyzes and records the decryption processing rate and the frequency of decryption failure events. The decryption processing rate and the frequency of decryption failure events are then matched with a pressure reference set to obtain the interval in which the decryption processing rate and the frequency of decryption failure events occur. The receiving pressure level corresponding to this interval is then obtained. The pressure reference set includes: decryption processing rate, frequency of decryption failure events, and receiving pressure level. The receiving pressure level represents the overall pressure state that the receiving node is currently under in terms of decryption processing and buffer usage.

[0052] During the decryption process, the receiving node uses the current encryption session as the statistical object. Within the statistical interval, it accumulates the number of encrypted fragment units that have successfully completed decryption processing, obtaining the total number of decrypted fragments within the statistical interval. Dividing this number of decrypted fragments by the interval duration corresponding to the statistical interval yields the decryption processing rate. The receiving node updates the decryption failure counter in real time based on the current encryption session. When a decryption failure of an encrypted fragment unit is detected, the receiving node only records the corresponding decryption failure event and adds it to the decryption failure counter. Within the statistical interval, the receiving node accumulates the number of decryption failures to obtain the cumulative failure value. Dividing this cumulative failure value by the interval duration corresponding to the statistical interval yields the frequency of decryption failure events.

[0053] Fragmentation rules specify how multiple consecutive encrypted fragment units are combined at the sending node, including but not limited to equal-division, equal-division, and equal-trivision rules. For example, the equal-division rule treats two adjacent encrypted fragment units as a single transmission and reconstruction unit. Under low receiving pressure, the equal-division rule helps maintain finer-grained fragmentation transmission, improving transmission flexibility and acknowledgment accuracy. Under increased receiving pressure, the equal-division or equal-trivision rule reduces the actual number of transmitted fragment reconstruction units, lowering the instantaneous pressure on the receiving node in decryption, buffering, and acknowledgment processing. This allows the sending node to dynamically adjust the fragmentation transmission granularity without changing the encrypted session structure, thereby improving overall transmission stability under fluctuating link load conditions.

[0054] Furthermore, such as Figure 3 As shown, Figure 3 The flowchart of the decryption fault tolerance processing of the cloud-based data security transmission system provided in this application embodiment illustrates that during load fluctuation protection processing, the receiving node performs decryption fault tolerance processing on the received encrypted fragment units. This decryption fault tolerance processing includes expanding the decryption sequence number window and determining abnormal decryption delays. Based on the standard window width, the offset distance of the encrypted fragment unit to its sequence number is calculated to obtain a fragment out-of-order index. The standard window width is then adjusted based on this index to form an expanded decryption sequence number window. Decryption processing is performed on encrypted fragment units falling within this expanded decryption sequence number window. The decryption result is used to determine whether the abnormal decryption delay condition is met. If the condition is met, the abnormal fragment is retransmitted; otherwise, decryption processing continues, thus completing the decryption fault tolerance processing.

[0055] The decryption fault tolerance process includes decryption sequence number window expansion and decryption anomaly delay judgment. A preset standard window width is obtained, and the offset distance of the encrypted fragment unit to the sequence number at the receiving node is calculated. The corresponding fragment out-of-order index is calculated, including the average fragment sequence number offset and the maximum sequence number offset. The maximum sequence number offset is divided by the corresponding average fragment sequence number offset to obtain the window adjustment ratio. The standard window width is multiplied by this window adjustment ratio to obtain the expanded window width, thus forming the expanded decryption sequence number window, completing the decryption sequence number window expansion. For encrypted fragment units whose fragment sequence numbers fall within the expanded decryption sequence number window range, the receiving node performs the corresponding decryption processing without immediately judging it as an anomaly. The specific method is as follows: In this embodiment, a preset standard window width is obtained and used as the width of the standard decryption sequence number window for the current encryption session, thereby limiting the acceptable range of encryption fragment sequence numbers during the decryption process.

[0056] The average offset of the fragment sequence number is obtained by the following method: within the statistical interval, the receiving node reads the fragment sequence number carried by each arriving encrypted fragment unit and records the actual arrival order of the encrypted fragment unit. For each arriving encrypted fragment unit, the receiving node performs absolute difference processing between the fragment sequence number it carries and the corresponding actual arrival order to obtain the offset distance of the encrypted fragment unit.

[0057] Specifically, when the average offset of the fragment sequence number is zero, it indicates that the decryption is in good condition, the standard window width is maintained, and the receiving node continues to perform decryption processing.

[0058] The maximum sequence number offset is obtained by comparing the offset distances of each encrypted fragment unit within the statistical interval, and taking the maximum value among all offset distances as the maximum sequence number offset. The maximum sequence number offset represents the most extreme out-of-order situation that occurs within the statistical interval.

[0059] Through decryption fault tolerance processing, the receiving node can tolerate a certain range of fragment out-of-order and delayed arrival under conditions of link load fluctuation or short-term jitter, avoiding misjudging transient anomalies as decryption anomalies and improving the overall stability of encrypted data transmission.

[0060] Furthermore, the receiving node updates the decryption failure counter and the corresponding decryption failure time sequence in real time based on the current encryption session. When a decryption failure of an encrypted fragment unit is detected, the receiving node only records the corresponding decryption failure event and adds it to the decryption failure counter. Within the statistical interval, the cumulative number of decryption failures in the receiving node's decryption failure counter is counted to obtain the cumulative failure value, and the time interval between adjacent decryption failure events in the receiving node's decryption failure time sequence is counted to obtain the minimum failure time interval. A preset failure count threshold and failure time threshold are obtained. When the cumulative failure value of the receiving node is greater than the failure count threshold and the minimum failure time interval is less than the failure time threshold, the receiving node determines that the encrypted fragment unit in the current extended decryption sequence window has a decryption anomaly and triggers the corresponding abnormal retransmission. The specific method is as follows: In this embodiment, if the receiving node fails to obtain a valid decryption result when performing decryption processing on a certain encrypted fragment unit, the decryption of that encrypted fragment unit fails. Specifically, this includes any of the following situations: decryption integrity verification failure, session key or session parameter mismatch, and fragment content format verification failure. Decryption integrity verification failure means that the decrypted fragment data does not pass the preset integrity verification rules, indicating that the encrypted fragment unit was damaged, truncated, or had abnormal content during transmission. Session key or session parameter mismatch means that the receiving node cannot effectively decrypt the encrypted fragment unit based on the currently held encryption session key and related session parameters. Fragment content format verification failure means that the decryption result does not meet the preset fragment structure requirements and cannot be recognized as valid decrypted fragment data.

[0061] The decryption failure counter and decryption failure time series represent the number of decryption failure events and their time distribution characteristics in the encrypted fragment unit.

[0062] By handling decryption anomaly delays, it is possible to avoid decryption misjudgments caused by short-term link jitter, fragment out-of-order delivery, and sudden increases in decryption pressure. This reduces unnecessary retransmissions and session interventions. Furthermore, decryption anomaly handling is only triggered when there are too many decryption failures and the time interval between failures is short. This helps maintain the continuity of encrypted sessions and improves the overall reliability of encrypted data transmission in a cloud computing environment.

[0063] When the receiving node determines that a decryption error has occurred in the encrypted fragment unit within the current extended decryption sequence number window, it triggers the corresponding error retransmission. Otherwise, before the decryption error determination condition is met, the encrypted session remains valid, and the receiving node continues to perform decryption fault tolerance processing on each subsequent encrypted fragment unit.

[0064] Furthermore, the fragment-level acknowledgment information of the current encrypted session of the sending node is obtained. This fragment-level acknowledgment information includes the cumulative acknowledgment sequence number and the selected acknowledgment interval. Based on this fragment-level acknowledgment information, the number of unacknowledged fragments and the out-of-order severity index of the encrypted session are calculated. Preset unacknowledged fragment thresholds and out-of-order severity thresholds are obtained and compared with the number of unacknowledged fragments and the out-of-order severity index of the encrypted session, respectively. When the number of unacknowledged fragments is less than the unacknowledged fragment threshold and the out-of-order severity index is below the out-of-order severity threshold, the current fragment loss is determined to be a minor fragment loss, and the sending node enters an acknowledgment observation period. During the acknowledgment observation period, it prioritizes waiting for new fragment-level acknowledgment information. Only when unacknowledged fragments are within the acknowledgment observation period... If the fragment is still unconfirmed after the period ends, it will be resent at a preset first resentment speed with the fragment sequence number increasing. If the number of unconfirmed fragments is less than the unconfirmed fragment threshold and the out-of-order index is greater than the out-of-order index, the current fragment loss is determined to be a transient out-of-order loss caused by link jitter. Only encrypted fragment units whose fragment sequence numbers are not covered by the selected confirmation interval will be resent, and the resentment will be performed at a preset second resentment speed with the fragment sequence number increasing. If the number of unconfirmed fragments is greater than the unconfirmed fragment threshold, the current fragment loss is determined to be a transient fragment loss caused by link load fluctuation. Unconfirmed fragments will be resent at a preset third resentment speed with the fragment sequence number increasing. The specific method is as follows: In this embodiment, the cumulative confirmation number is obtained by the following method: the receiving node counts the encrypted fragment units that have been successfully decrypted and continuously confirmed in the order of fragment number, determines the maximum fragment number value that has been continuously confirmed without interruption starting from the starting fragment number, and uses the maximum continuous fragment number as the cumulative confirmation number of the current encryption session. The cumulative confirmation number indicates that in the current encryption session, all encrypted fragment units with fragment numbers not greater than this number have been successfully received and confirmed by the receiving node.

[0065] The selection confirmation interval is obtained by the following method: For encrypted fragment units whose fragment sequence number is greater than the cumulative confirmation sequence number but have been successfully decrypted and confirmed, the receiving node organizes these confirmed fragment sequence numbers into discrete consecutive sequence number intervals according to their corresponding fragment sequence numbers. Each consecutive sequence number interval constitutes a selection confirmation interval, which indicates which encrypted fragment units have been confirmed within the range of non-consecutive fragment sequence numbers.

[0066] For example, in a certain encrypted session, the sending node sends the following encrypted fragment units in sequence: Fragment sequence numbers: {1, 2, 3, 4, 5, 6, 7, 8, 9, 10}. Due to link jitter and load fluctuations, the receiving node actually successfully decrypts and passes the integrity check. The fragment sequence numbers that have been successfully received and acknowledged are: {1, 2, 3, 5, 6, 8}. The encrypted fragment units with fragment sequence numbers: {4, 7, 9, 10} have not yet been successfully received or acknowledged. Starting from the smallest fragment sequence number, the receiving node checks whether there is a continuous and uninterrupted sequence of acknowledged fragments. Starting from the initial fragment, the largest fragment sequence number that can be continuously acknowledged is 3, so the cumulative acknowledged sequence number is 3. The receiving node continues to check which fragment numbers greater than the cumulative confirmation number have been successfully confirmed. Among them, the encrypted fragment units with fragment number 5 and fragment number 6 are confirmed consecutively, and the encrypted fragment unit with fragment number 8 is confirmed separately. These confirmed fragment numbers are organized into discrete consecutive number intervals, and each consecutive number interval constitutes a selection confirmation interval, which is: {[5, 6], [8, 8]}.

[0067] The number of unconfirmed fragments is obtained by the following method: the sending node marks the fragment sequence numbers that have been covered by the accumulated confirmation sequence numbers as confirmed fragments, and similarly marks the fragment sequence numbers that fall within the selected confirmation interval as confirmed fragments. The remaining fragment sequence numbers that are not marked as confirmed fragments are marked as unconfirmed fragments. The number of unconfirmed fragments is counted to obtain the number of unconfirmed fragments corresponding to the current encrypted session.

[0068] The out-of-order index is obtained as follows: Within the statistical interval, the sequence numbers of each confirmed but not covered by the cumulative confirmation sequence number are obtained. The receiving node records the actual arrival order of the encrypted fragment units corresponding to the fragment sequence numbers. For each arriving encrypted fragment unit, the receiving node performs absolute difference processing between the fragment sequence number it carries and the corresponding actual arrival order to obtain the offset distance of the encrypted fragment unit. The average of the offset distances of each encrypted fragment unit is taken to obtain the out-of-order index, which represents the degree of deviation between the arrival order and the sending order of the encrypted fragment units.

[0069] The first, second, and third retransmission speeds increase sequentially in value. The first retransmission speed indicates minor fragment loss, where conservative retransmission is performed when the link is in order and the loss is small, to avoid additional load on stable links. The second retransmission speed indicates transient out-of-order fragment loss caused by link jitter, where recovery of missing fragments is accelerated when there is significant out-of-order loss but the loss is under control. The third retransmission speed indicates transient fragment loss caused by link load fluctuations, where rapid retransmission is performed when there is a large number of unconfirmed fragments, to shorten the data recovery time of encrypted sessions.

[0070] like Figure 4 As shown, Figure 4 The overall flowchart of the cloud-based secure data transmission method provided in this application embodiment includes the following steps: During data transmission, detecting whether the communication path has switched; when no switch has occurred, acquiring the transmission status parameters of the sending node within a preset statistical window and analyzing the communication operation anomaly characteristics of the sending node; otherwise, determining it as a suspected failure state. The communication operation anomaly characteristics include transient abnormal link load and stable link load. When the communication operation anomaly characteristic of the sending node is transient abnormal link load, performing load fluctuation protection processing on the current data transmission encryption session; otherwise, entering the encryption session state processing flow for communication path switching. The load fluctuation protection processing includes failure state freezing and session resource... Locking; During load fluctuation protection processing, encrypted data scheduling and encrypted fragmentation unit generation and reconstruction are performed, and data output control is performed by receiving back pressure signals; During load fluctuation protection processing, decryption fault tolerance processing is performed on the received encrypted fragmentation units to obtain the corresponding decrypted fragmentation data. The sending node then performs fragment-level confirmation and recovery on the encrypted fragmentation units. During the decryption fault tolerance processing, decryption feedback information is obtained, back pressure signals are obtained and sent back to the sending node; The abnormal characteristics of the sending node's communication operation are monitored until the transient abnormality of the link load is detected and resolved. At this point, the load fluctuation protection processing of the encrypted session is released, and the secure transmission of the data to be sent in the encrypted session continues. Otherwise, monitoring continues.

[0071] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0072] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0073] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0074] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0075] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.

[0076] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A cloud computing-based secure data transmission system, characterized in that, include: Communication transmission detection module, encrypted session protection module, encryption processing module, decryption processing module, and encrypted session recovery module; The communication transmission detection module is used to detect whether the communication path has been switched during data transmission. When no switch has occurred, it obtains the transmission status parameters of the sending node within a preset statistical window and analyzes the abnormal communication operation characteristics of the sending node. Otherwise, it is determined to be in a suspected failure state. The abnormal communication operation characteristics include transient abnormal link load and stable link load. The encrypted session protection module is used to perform load fluctuation protection processing on the encrypted session of the current data transmission when the communication operation abnormality feature of the sending node is a transient abnormality of the link load; otherwise, it enters the encrypted session state processing flow of communication path switching. The load fluctuation protection processing includes failure state freezing and session resource locking. The encryption processing module is used to perform encrypted data scheduling and the generation and reconstruction of encrypted sharding units during the load fluctuation protection process, and to control data output by receiving back pressure signals. The decryption processing module is used to perform decryption fault tolerance processing on the received encrypted fragment unit during the load fluctuation protection process to obtain the corresponding decrypted fragment data. The sending node then performs fragment-level confirmation and recovery on the encrypted fragment unit. During the decryption fault tolerance process, the module obtains decryption feedback information, receives a back pressure signal, and sends it back to the sending node. The encrypted session recovery module is used to monitor the abnormal characteristics of the communication operation of the sending node. When the transient abnormality of the link load is detected and resolved, the load fluctuation protection process of the encrypted session is released, and the secure transmission of the data to be sent in the encrypted session continues. Otherwise, monitoring continues.

2. The cloud computing-based secure data transmission system as described in claim 1, characterized in that, The specific method for obtaining the communication operation anomaly characteristics of the sending node is as follows: Within a preset statistics window, obtain the transmission status parameters of the current encrypted session corresponding to the sending node. The transmission status parameters include the encrypted data packet transmission success rate, the encrypted data packet retransmission ratio, the response delay of the encrypted heartbeat message, and the number of consecutive heartbeat failures. The absolute difference of the transmission status parameters of adjacent statistical window pairs is processed to obtain the parameter fluctuation value of each transmission status parameter. A preset parameter fluctuation threshold set is obtained. The parameter fluctuation value is compared with the parameter fluctuation threshold set. When there are at least two transmission status parameters whose parameter fluctuation values ​​are greater than their corresponding parameter fluctuation thresholds, the adjacent statistical window pair is marked as an out-of-limit state. Otherwise, it is marked as a non-out-of-limit state. When a statistical window is marked repeatedly, if the two marks are the same, the marking of the statistical window remains unchanged; if the two marks are different, the statistical window is marked as out of limit. Within a preset statistical interval consisting of multiple consecutive statistical windows, the total number of statistical windows marked as exceeding the limit is counted to obtain the total number of exceeding limits. A preset threshold for the number of exceeding limits is obtained. The total number of exceeding limits is compared with the threshold for the number of exceeding limits. When the total number of exceeding limits is greater than the threshold for the number of exceeding limits, the communication operation abnormality of the current encrypted session is determined to be a transient abnormality of the link load; otherwise, it is determined to be a stable link load.

3. The cloud computing-based secure data transmission system as described in claim 1, characterized in that, The specific method for implementing load fluctuation protection is as follows: When the communication operation anomaly of the sending node is characterized by a transient abnormality in the link load, the sending node generates a corresponding load fluctuation protection state identifier for the encrypted session and writes the load fluctuation protection state identifier into the status control table of the corresponding encrypted session; Retrieve the session failure determination conditions, determine the session status of the session indication signal. If the session status determination result is non-failure, maintain the current encrypted session's valid state. Otherwise, query the load fluctuation protection status identifier corresponding to the current encrypted session. When the load fluctuation protection status identifier is valid, temporarily store the session indication signal and do not trigger the corresponding session failure processing, thus freezing the failure status of the current encrypted session. Otherwise, trigger the corresponding session failure processing. Meanwhile, when the communication operation anomaly of the sending node is characterized by a transient abnormality in the link load, the sending node assigns a corresponding protected session identifier to the encrypted session and binds the protected session identifier to the encrypted session object and its corresponding session key object. During the validity period of the protected session identifier, when the session maintenance condition of the current encrypted session is triggered, the session maintenance process for the encrypted session and its session key is suspended. After the transient abnormality of the link load corresponding to the sending node is resolved, the above session maintenance process is performed. Otherwise, the current valid state of the encrypted session and its session key is maintained.

4. The cloud computing-based secure data transmission system as described in claim 1, characterized in that, The specific method for the encrypted data scheduling is as follows: The sending node sets a pre-encryption scheduling gate at the security layer, and at the same time classifies the data to be sent according to data attributes to obtain data types; The data types include session control data, encrypted heartbeat data, general business data, and continuous business data; During the load fluctuation protection process, the sending node performs encryption processing on session control data and encrypted heartbeat data through the pre-encryption scheduling gate. Based on the preset baseline injection rate, ordinary service data is encrypted according to the baseline injection rate, and the encryption processing of continuous service data is suspended. The data is temporarily stored in the sending-side buffer queue as data to be sent until the load fluctuation protection state of the current encrypted session is released, and then the encryption processing continues.

5. The cloud computing-based secure data transmission system as described in claim 1, characterized in that, The specific method for generating and reconstructing the encrypted fragmentation unit is as follows: During the load fluctuation protection process, the jitter characteristics of each link of the transmitting node within the statistical interval are calculated, and a preset set of link jitter thresholds is obtained. The link jitter features of each sending node are compared with the corresponding link jitter thresholds in the link jitter threshold set. When all link jitter features are below the corresponding link jitter thresholds, the encrypted data block is divided according to the preset first unit division scale to obtain each encrypted fragment unit. When there is a link jitter feature greater than the corresponding link jitter threshold, the link jitter feature difference value is obtained. All the link jitter feature difference values ​​are averaged to obtain the comprehensive link jitter difference value. The scale mapping process is performed to obtain the second unit division scale, and the encrypted data block is divided according to the second unit division scale to obtain each encrypted fragment unit. The sending node marks each encrypted fragment unit with session association identification information; The link jitter characteristics include the fluctuation range of round-trip delay between adjacent encrypted heartbeat messages, the dispersion of the interval between the sending and acknowledgment of adjacent data packets, and the frequency of out-of-order data packets.

6. The cloud computing-based secure data transmission system as described in claim 1, characterized in that, The specific method for performing data output control is as follows: The sending node receives a back pressure signal returned from the receiving node, the back pressure signal including the received credit limit and the received pressure level; Obtain a preset credit limit threshold, divide the received credit limit received by the sending node by the credit limit threshold to obtain the credit limit ratio, map and match the credit limit ratio with the preset credit limit ratio reference table to obtain the corresponding rate adjustment factor, multiply the baseline injection rate by the rate adjustment factor to obtain the target injection rate, and if the data type is ordinary business data, perform encryption processing according to the target injection rate. Obtain a preset pressure level reference set, match and map the receiving pressure level of the sending node with the pressure level reference set, obtain the fragmentation rule corresponding to the interval, divide the encrypted fragmentation unit, and obtain each encrypted fragmentation reconstruction unit. The pressure level reference set includes the received pressure level and the segmentation rules.

7. The cloud computing-based secure data transmission system as described in claim 1, characterized in that, The specific method for performing the decryption fault tolerance processing is as follows: The decryption fault tolerance processing includes decryption sequence number window expansion and decryption abnormal delay determination; Obtain the preset standard window width, count the offset distance of the encrypted fragment unit at the receiving node to the sequence number, and calculate the corresponding fragment out-of-order index. The fragment out-of-order index includes the average fragment sequence number offset and the maximum sequence number offset. Divide the maximum sequence number offset by the corresponding average segment sequence number offset to obtain the window adjustment ratio. Multiply the standard window width by the window adjustment ratio to obtain the extended window width, thus forming the extended decryption sequence number window and completing the decryption sequence number window extension. For encrypted fragment units whose fragment sequence number falls within the range of the extended decryption sequence number window, the receiving node performs the corresponding decryption process without immediately determining it as an anomaly.

8. The cloud computing-based secure data transmission system as described in claim 7, characterized in that, The specific method for determining the abnormal decryption delay is as follows: The receiving node updates the decryption failure counter and the corresponding decryption failure time sequence in real time based on the current encryption session. When a decryption failure of an encrypted fragment unit is detected, the receiving node only records the corresponding decryption failure event and adds the decryption failure event to the decryption failure counter. Within the statistical interval, the cumulative number of decryption failures of the receiving node is counted to obtain the cumulative failure value, and the time interval between adjacent decryption failure events in the decryption failure time series of the receiving node is counted to obtain the minimum failure time interval. Obtain the preset failure count threshold and failure time threshold. When the cumulative failure value of the receiving node is greater than the failure count threshold and the minimum failure time interval is less than the failure time threshold, the receiving node determines that the encrypted fragment unit in the current extended decryption sequence window has a decryption abnormality and triggers the corresponding abnormal retransmission.

9. The cloud computing-based secure data transmission system as described in claim 1, characterized in that, The specific method for performing fragment-level confirmation and recovery is as follows: Obtain the fragment-level confirmation information of the current encrypted session of the sending node. The fragment-level confirmation information includes the cumulative confirmation sequence number and the selected confirmation interval. Based on the fragment-level confirmation information, calculate the number of unconfirmed fragments and the out-of-order index of the encrypted session. The preset unconfirmed fragment threshold and out-of-order severity threshold are obtained and compared with the number of unconfirmed fragments and the out-of-order severity index of the encrypted session, respectively. When the number of unconfirmed fragments is less than the unconfirmed fragment threshold and the out-of-order severity index is below the out-of-order severity threshold, the current fragment loss is determined to be a minor fragment loss, and the sending node enters the confirmation observation period. During the confirmation observation period, new fragment-level confirmation information is waited for first. Only when the unconfirmed fragment is still not confirmed after the confirmation observation period ends, it is resent according to the preset first resentment speed and the fragment sequence number is increased. When the number of unconfirmed fragments is less than the unconfirmed fragment threshold and the out-of-order index is greater than the out-of-order index, the current fragment loss is determined to be a transient out-of-order loss caused by link jitter. Only encrypted fragment units whose fragment sequence numbers are not covered by the selected confirmation interval are resent, and the resentment is performed according to the preset second resentment speed and the fragment sequence number is increased. When the number of unconfirmed fragments exceeds the unconfirmed fragment threshold, the current fragment loss is determined to be a transient fragment loss caused by link load fluctuations. The unconfirmed fragments are then resent at a preset third resentment speed with the fragment sequence number increasing.

10. A cloud computing-based secure data transmission method, applied to the cloud computing-based secure data transmission system according to any one of claims 1-9, characterized in that, Includes the following steps: During data transmission, it is detected whether the communication path has been switched. If no switch has occurred, the transmission status parameters of the sending node are obtained within a preset statistical window, and the abnormal communication operation characteristics of the sending node are analyzed. Otherwise, it is determined to be in a suspected failure state. The abnormal communication operation characteristics include transient abnormal link load and stable link load. When the communication operation abnormality of the sending node is characterized by a transient abnormality in the link load, the encrypted session for the current data transmission is subjected to load fluctuation protection processing; otherwise, the encrypted session state processing flow for communication path switching is entered. The load fluctuation protection processing includes failure state freezing and session resource locking. During the load fluctuation protection process, encrypted data scheduling and encrypted fragmentation unit generation and reconstruction are performed, and data output control is performed by receiving reverse voltage signals; During the load fluctuation protection process, the received encrypted fragment unit is decrypted and fault-tolerant, and the corresponding decrypted fragment data is obtained. The sending node then performs fragment-level confirmation and recovery on the encrypted fragment unit. During the decryption and fault-tolerant process, decryption feedback information is obtained, a back pressure signal is obtained, and it is sent back to the sending node. The system monitors abnormal communication characteristics of the sending node until a transient abnormality in the link load is detected and resolved. Then, it removes the load fluctuation protection process for the encrypted session and continues to securely transmit the data to be sent in the encrypted session. Otherwise, it continues to monitor.