A network fault traffic optimization method and system based on security protocol scheduling
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SUZHOU SUIHUOYUN TECHNOLOGY CO LTD
- Filing Date
- 2026-06-02
- Publication Date
- 2026-08-07
AI Technical Summary
[0005]因此,本发明提供了一种基于安全协议调度的网络故障流量优化方法解决网络故障流量迁移中安全协议状态续接和安全等级不降级协同约束不足的问题
[0016]本发明有益效果为:通过对候选承载路径执行联合核验,实现网络故障流量的安全化续接匹配。通过从协议承载安全要素中提取加密承载信息、身份认证信息和协议审计信息并形成安全等级不降级约束,同时将协议握手续接要素中的已握手续接内容、待握手续接内容和协议连接中断位置按照安全协议交互顺序形成握手续接承载约束,锚定候选承载路径在协议连接中断位置后的续接入口和承接顺序,使安全匹配路径数据能够准确记录候选承载路径对网络故障流量的安全承载能力、握手状态承接能力和协议续接适配关系,从而提高迁移调度数据的安全连续性和故障流量优化数据的稳定性。
Smart Images

Figure CN122533935A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of digital information transmission technology, and in particular to a method and system for optimizing network fault traffic based on security protocol scheduling. Background Technology
[0002] In recent years, with the development of content delivery networks, software-defined networks, edge computing node scheduling, transport layer security protocols, and zero-trust access control architectures, methods for optimizing network fault traffic have been continuously improved. In the field of network communication, business traffic typically needs to pass through multiple bearer locations, such as content delivery nodes, gateway nodes, load balancing nodes, edge forwarding nodes, and security protocol proxy nodes. Network transmission operation data not only includes link status, node reachability status, path switching status, transmission latency, retransmission count, and packet loss status, but also involves security protocol connection content such as session recovery, key negotiation, endpoint authentication, protocol auditing, and security bearer level. Related research has gradually covered areas such as link status awareness, node reachability monitoring, fault path location, traffic path reselection, session persistence, encrypted bearer, authentication continuity, and protocol auditing records. It has also conducted data analysis on the correspondence between network transmission operation status and security protocol interaction status, providing a technical foundation for traffic migration, secure bearer, and connection recovery in complex network fault scenarios.
[0003] However, existing methods for optimizing network fault traffic often focus on network layer metrics such as path reachability, bandwidth load, transmission latency, and link switching costs. They lack unified scheduling and processing for the relationship between fault bearer paths, protocol connection interruption locations, protocol handshake connection elements, and protocol bearer security elements. This makes it difficult to maintain the continuous security protocol state after fault traffic migration, and the protocol bearer security level is prone to decoupling from the migration path, affecting the security, continuity, and stability of the network fault traffic optimization results. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, this invention provides a network fault traffic optimization method based on security protocol scheduling to solve the problem of insufficient collaborative constraints on security protocol state continuation and security level non-degradation in network fault traffic migration.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: In a first aspect, the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising: performing transmission status collection and path anomaly identification on network transmission operation data during the security protocol scheduling process to obtain fault transmission association data; locating the fault bearer path and protocol connection interruption position based on the fault transmission association data, and extracting protocol handshake connection elements and protocol bearer security elements from the fault transmission association data; reconnecting the protocol handshake connection elements and protocol bearer security elements according to the protocol connection interruption position, and outputting handshake connection status data; labeling the network transmission operation data corresponding to the fault bearer path as network fault traffic, and reconnecting it according to the handshake connection position. The status data is used to match candidate bearer paths for network fault traffic. Protocol bearer security elements serve as the constraint for non-degradation of security level, and protocol handshake connection elements serve as the constraint for handshake connection bearing. The security protocol bearing capacity and handshake state acceptance capacity of the candidate bearer paths are verified to generate secure matching path data. A successor bearer path is selected from the secure matching path data. A successor relationship is established between the handshake connection status data and the successor bearer path. The successor relationship is then arranged according to the protocol connection interruption position, and migration scheduling data is output. Network fault traffic is migrated from the faulty bearer path to the successor bearer path according to the migration scheduling data, and fault traffic optimization data is output.
[0007] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps for obtaining fault transmission correlation data are as follows: The bearer path status record, protocol connection status record, traffic transmission status record, and transmission record identifier are extracted from the network transmission operation data. Based on the transmission record identifier, the bearer path status record, protocol connection status record, and traffic transmission status record are aggregated to form transmission status aggregated data. Information identification is performed on the transmission status collection data to obtain path anomaly identification data; The path anomaly identification data is written back to the transmission status collection data according to the transmission record identifier to generate fault transmission association data.
[0008] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps for extracting protocol handshake connection elements and protocol bearer security elements are as follows: Verify the path anomaly identification data and bearer path status records in the fault transmission association data to determine the faulty bearer path; Using the fault-bearing path as the location object, the protocol connection status records in the fault transmission associated data are checked according to the interaction order of the security protocol to determine the location of the protocol connection interruption. Based on the fault bearer path and the location of the protocol connection interruption, the protocol interaction content before the location of the protocol connection interruption is collected in the fault transmission associated data, and the security bearer information corresponding to the fault bearer path is collected to generate protocol handshake connection elements and protocol bearer security elements.
[0009] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps for outputting the handshake connection status data are as follows: Using the location where the protocol connection is interrupted as the dividing point, the protocol handover elements are divided into already-handled connection content and pending handover content. Establish an association relationship between the already secured connection content, the pending connection content, and the security elements carried by the protocol, match the association relationship to the location where the protocol connection is interrupted, and output the connection status data.
[0010] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps of matching candidate bearer paths are as follows: Search for the network transmission operation data corresponding to the fault bearer path in the fault transmission association data, and use it as the network fault traffic; Based on the handshake connection status data, faulty bearer paths are eliminated from the network transmission operation data, and reachable bearer path data is generated. Based on the pending connection information in the connection status data, the reachable bearer path data is matched with network fault traffic to obtain candidate bearer paths.
[0011] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps for generating secure matching path data are as follows: The encrypted bearer information, identity authentication information, and protocol audit information of the fault bearer path are extracted from the security elements of the protocol bearer, and the security level is maintained and calibrated according to the bearer relationship of the fault bearer path to form a constraint that the security level does not degrade. The already-handled connection content, the connection to be handed over, and the location of the connection interruption in the protocol handover connection elements are marked as handover connection bearers according to the interaction order of the security protocol, thus forming handover connection bearer constraints. The breakpoint mapping data is generated by mapping the security level non-downgrade constraint, the handshake connection bearer constraint and the candidate bearer path, anchoring the continuation entry and acceptance order of the candidate bearer path after the protocol connection is interrupted. The relationship between the security protocol carrying capacity and the security level non-degradation constraint of the candidate bearer path is verified according to the breakpoint mapping data. The relationship between the handshake state carrying capacity and the handshake handshake carrying constraint of the candidate bearer path is also verified to form path verification result data. Based on the path verification results, candidate bearer paths that simultaneously meet the constraints of no security level degradation and handshake connection bearing are matched with network fault traffic to generate secure matching path data.
[0012] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps for establishing the continuation relationship are as follows: In the secure matching path data, the corresponding candidate bearer path is selected as the continuation bearer path according to the matching relationship of network fault traffic; Using network fault traffic as the associated object, the handover status data and the continuation bearer path are bound together to establish a continuation relationship.
[0013] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps for outputting migration scheduling data are as follows: According to the location of the interruption in the protocol connection, the already secured connection content and the pending connection content in the continuation relationship are divided into sequential order to form protocol continuation sequence data; The protocol continuation sequence data is jointly orchestrated with the continuation bearer path and network fault traffic to output migration scheduling data.
[0014] As a preferred embodiment of the network fault traffic optimization method based on security protocol scheduling described in this invention, the specific steps for outputting the fault traffic optimization data are as follows: According to the migration scheduling data, the network fault traffic is switched from the faulty bearer path to the continued bearer path, and the migration process of the network fault traffic is recorded to form migration execution data. In the reconnected bearer path, perform protocol status acceptance confirmation and transmission bearer confirmation for network fault traffic, and obtain migration confirmation data; The migration confirmation data, network fault traffic, resumed bearer paths, and migration execution data are aggregated to output fault traffic optimization data.
[0015] Secondly, this invention provides a network fault traffic optimization system based on security protocol scheduling, comprising, The anomaly detection module is used to collect transmission status and identify path anomalies in the network transmission operation data during the security protocol scheduling process, and to obtain fault transmission related data. The reconnection calibration module is used to locate the fault bearer path and the protocol connection interruption location based on the fault transmission correlation data, extract the protocol handshake connection elements and protocol bearer security elements from the fault transmission correlation data, perform reconnection calibration on the protocol handshake connection elements and protocol bearer security elements according to the protocol connection interruption location, and output the handshake connection status data. The path matching module is used to identify the network transmission operation data corresponding to the faulty bearer path as network fault traffic, match candidate bearer paths for network fault traffic according to the handshake connection status data, use protocol bearer security elements as security level non-degradation constraints, use protocol handshake connection elements as handshake connection constraints, verify the security protocol bearer capability and handshake status acceptance capability of candidate bearer paths, and generate secure matching path data. The continuation scheduling module is used to select a continuation bearer path from the security matching path data, establish a continuation acceptance relationship between the handshake connection status data and the continuation bearer path, arrange the continuation acceptance relationship according to the protocol connection interruption position, and output migration scheduling data. The traffic migration module is used to migrate network fault traffic from the faulty bearer path to the continued bearer path according to the migration scheduling data, and output fault traffic optimization data.
[0016] The beneficial effects of this invention are as follows: By performing joint verification on candidate bearer paths, secure reconnection matching for network fault traffic is achieved. By extracting encrypted bearer information, authentication information, and protocol audit information from protocol bearer security elements and forming a non-degradation constraint on security level, and simultaneously forming a handshake connection bearer constraint by combining the already-handled connection content, the pending connection content, and the protocol connection interruption position in the protocol handshake connection elements according to the security protocol interaction order, the reconnection entry point and acceptance order of candidate bearer paths after the protocol connection interruption position are anchored. This allows the secure matching path data to accurately record the candidate bearer path's secure bearer capability for network fault traffic, handshake state acceptance capability, and protocol reconnection adaptation relationship, thereby improving the security continuity of migration scheduling data and the stability of fault traffic optimization data. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Fig. 1 This is a flowchart of a network fault traffic optimization method based on security protocol scheduling.
[0019] Fig. 2 This is a schematic diagram of a network fault traffic optimization system based on security protocol scheduling.
[0020] Fig. 3 This is a flowchart for outputting the handshake connection status data.
[0021] Fig. 4A flowchart for optimizing output fault traffic. Detailed Implementation
[0022] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0023] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0024] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0025] Reference Figs. 1-4 As one embodiment of the present invention, this embodiment provides a network fault traffic optimization method based on security protocol scheduling, comprising the following steps: S1. Perform transmission status collection and path anomaly identification on the network transmission operation data during the security protocol scheduling process to obtain fault transmission related data.
[0026] S1.1 Extract bearer path status records, protocol connection status records, traffic transmission status records, and transmission record identifiers from network transmission operation data, and aggregate the bearer path status records, protocol connection status records, and traffic transmission status records based on the transmission record identifiers to form transmission status aggregation data.
[0027] Specifically, from network transmission operation data, record entries corresponding to the same transmission process are read according to transmission occurrence time, source node, destination node, and security protocol connection relationship. Transmission record identifiers used to distinguish traffic distributing the same content are extracted. The corresponding path bearer entry is located according to the transmission record identifier, and the bearer node, bearer link, path connection status, node reachability status, and path switching status are read as bearer path status records. The corresponding security protocol interaction entry is located according to the transmission record identifier, and the handshake initiation status, handshake response status, session recovery status, key negotiation status, endpoint authentication status, and protocol audit status are read as protocol connection status records. The corresponding traffic transmission entry is located according to the transmission record identifier, and the traffic sending status, traffic receiving status, transmission delay, retransmission count, packet loss status, and transmission completion status are read as traffic transmission status records. Using the transmission record identifier as the corresponding benchmark, the bearer path status record, protocol connection status record, and traffic transmission status record are written into the same record location, so that the path status, protocol connection status, and traffic transmission status under the same transmission record identifier form a correspondence, forming transmission status aggregation data.
[0028] Furthermore, network transmission operation data is collected and aggregated by content distribution nodes, gateway nodes, load balancer nodes, switches, SDN controllers, firewalls, security protocol proxy nodes, terminal proxies, and security protocol terminal nodes respectively. Specifically, SDN controllers, switches, gateway nodes, and load balancer nodes collect data on bearer nodes, bearer links, path connection status, node reachability status, and path switching status to form bearer path status records. Content distribution nodes and gateway nodes collect data on traffic sending status, traffic receiving status, transmission latency, retransmission count, packet loss status, and transmission completion status to form traffic transmission status records. Terminal proxies, security protocol terminal nodes, and authorized security protocol proxy nodes collect data on handshake initiation status, handshake response status, session recovery status, key negotiation status, endpoint authentication status, and protocol audit status to form protocol connection status records. For end-to-end encrypted security protocol connections, intermediate bearer nodes only collect path status and traffic transmission status, without reading plaintext content and key values. Key negotiation status and endpoint authentication status are provided by terminal proxies or security protocol terminal nodes using status markers, and are organized according to the transmission record identifier and correspondence between the bearer path status record and the traffic transmission status record.
[0029] Simultaneously, terminal agents, security protocol terminal nodes, and authorized security protocol agent nodes also collect encrypted bearer information, identity authentication information, protocol audit information, and protocol bearer security level. Encrypted bearer information includes encryption suite identifier, key negotiation confirmation mark, session ticket identifier, and integrity verification method, but does not contain plaintext key value. Identity authentication information includes endpoint identity identifier, certificate verification status, authentication completion mark, and authentication acceptance result. Protocol audit information includes security protocol interaction record number, interaction status record, audit time, and audit completion mark. The protocol bearer security level is formed based on the encryption suite identifier, certificate verification status, integrity verification method, and protocol audit completion status, and is written into the protocol connection status record according to the transmission record identifier.
[0030] S1.2. Perform information identification on the transmission status collection data to obtain path anomaly identification data.
[0031] Specifically, the system reads the bearer path status record, protocol connection status record, and traffic transmission status record item by item based on the transmission record identifier. In the bearer path status record, it checks the path connection status, node reachability status, and path switching status, and marks the locations corresponding to link connection interruption, bearer node no response, path switching failure, and bearer link unreachability as path anomaly candidate locations. In the protocol connection status record, it reads the handshake initiation status, handshake response status, session recovery status, key negotiation status, and endpoint authentication status, and marks the locations corresponding to missing handshake response, incomplete session recovery, stalled key negotiation, and unaccepted endpoint authentication as protocol connection anomaly candidate locations.
[0032] Read the traffic sending status, traffic receiving status, transmission delay, retransmission count, packet loss status, and transmission completion status from the traffic transmission status record. Mark the locations corresponding to discontinuous traffic sending and receiving status, continuously increasing transmission delay, continuously increasing retransmission count, continuous packet loss status, and missing transmission completion status as traffic transmission anomaly candidate locations. Group the path anomaly candidate locations, protocol connection anomaly candidate locations, and traffic transmission anomaly candidate locations into the same anomaly record according to the transmission record identifier, and record the anomaly occurrence time, anomaly bearer node, anomaly bearer link, anomaly protocol connection status, and anomaly traffic transmission status to generate path anomaly identification data.
[0033] It should be noted that the determination of path anomaly candidate locations, protocol connection anomaly candidate locations, and traffic transmission anomaly candidate locations is based on the completion of the sampling period record under the same transmission record identifier; the lack of response from the bearer node is determined by the absence of heartbeat confirmation for three consecutive sampling periods and the failure to receive acknowledgments for probe packets; the link connection interruption is determined by the connection status of the bearer nodes at both ends of the bearer link being recorded as disconnected; the discontinuity between traffic transmission status and traffic reception status is determined by the break in the sequence number of transmission, the sequence number of reception, or the transmission time; the continuous increase in transmission delay is determined by the transmission delay of three consecutive sampling periods being higher than the previous sampling period and exceeding the reference transmission delay formed by the stable transmission segment of the same transmission record identifier; the continuous increase in retransmission count is determined by the retransmission count of three consecutive sampling periods being higher than the previous sampling period; and the continuous recording of packet loss status is determined by the recording of packet loss status for three consecutive sampling periods.
[0034] Before grouping candidate locations for path anomalies, protocol connection anomalies, and traffic transmission anomalies into the same anomaly record, it is necessary to verify whether there is any overlap in the anomaly occurrence time, the anomaly bearer node, and the anomaly bearer link. Independent anomaly markers corresponding to server load anomalies, certificate anomalies, key expiration, rate limiting policies, congestion control, and application layer interruptions are excluded. Only when the anomaly occurrence time is adjacent, the anomaly bearer node or anomaly bearer link is consistent, and there are no independent anomaly markers, are the candidate locations for protocol connection anomalies and traffic transmission anomalies grouped into the same anomaly record as the candidate locations for path anomalies, thus generating path anomaly identification data.
[0035] S1.3 Write the path anomaly identification data back to the transmission status collection data according to the transmission record identifier to generate fault transmission association data.
[0036] Specifically, the path anomaly identification data and transmission status collection data are compared item by item according to the transmission record identifier to locate the record position under the same transmission record identifier; the path anomaly candidate position is written into the bearer path status record, the protocol connection anomaly candidate position is written into the protocol connection status record, and the traffic transmission anomaly candidate position is written into the traffic transmission status record. The anomaly occurrence time, the abnormal bearer node, the abnormal bearer link, the abnormal protocol connection status, and the abnormal traffic transmission status are written into the anomaly record area under the same transmission record identifier to generate fault transmission association data.
[0037] S2. Locate the fault bearer path and protocol connection interruption location based on the fault transmission association data, extract the protocol handshake connection elements and protocol bearer security elements from the fault transmission association data, perform reconnection calibration on the protocol handshake connection elements and protocol bearer security elements according to the protocol connection interruption location, and output the handshake connection status data.
[0038] S2.1 Verify the path anomaly identification data and bearer path status records in the fault transmission association data to determine the faulty bearer path.
[0039] Specifically, path anomaly identification data and bearer path status records at the same record location are read from the fault transmission association data according to the transmission record identifier; a path location sequence is established based on the connection order of bearer nodes and bearer links in the bearer path status records, and each path location records adjacent bearer nodes, bearer links, path connection status, node reachability status, and path switching status; based on the path anomaly candidate locations, abnormal bearer nodes, and abnormal bearer links in the path anomaly identification data, path locations with the same bearer node identifier and the same bearer node identifier at both ends of the link are searched in the path location sequence; the path connection status, node reachability status, and path switching status in the found path locations are read, and the path locations corresponding to link connection interruption, bearer node no response, path switching failure, and bearer link unreachable are marked; the marked path locations are continuously concatenated according to the connection relationship in the path location sequence to form the fault bearer path.
[0040] It should be noted that the bearer node in the path location sequence is verified primarily based on the bearer node identifier, with the node name serving as a secondary verification criterion. The bearer node identifier consists of the node device number, network address, and interface identifier. When node names are identical but bearer node identifiers are inconsistent, the corresponding bearer nodes are determined to be different bearer nodes, and the consistency of node names is not used as the sole criterion for the same path location. After marking path locations based on path anomaly identification data, the marked path locations are grouped according to their adjacency in the path location sequence. Only when adjacent path locations are all marked as having broken link connections, unresponsive bearer nodes, failed path switching, or unreachable bearer links are they continuously connected to form a faulty bearer path. A single marked bearer node or bearer link forms a separate faulty bearer path record. Multiple discontinuous anomaly locations form corresponding faulty bearer path records, and unmarked path locations are not included in the faulty bearer path.
[0041] S2.2. Using the fault-bearing path as the location object, check the protocol connection status records in the fault transmission associated data according to the interaction order of the security protocol to determine the location of the protocol connection interruption.
[0042] Specifically, the security protocol in this embodiment is limited to Transport Layer Security Protocol 1.3 (TLS 1.3). Using the faulty bearer path as the location object, protocol connection status records under the same transmission record identifier are read from the faulty transmission association data. Following the handshake interaction sequence of TLS 1.3, the handshake initiation state, handshake response state, session recovery state, key negotiation state, endpoint authentication state, and protocol audit state are organized into a protocol interaction status sequence. For each interaction position in the protocol interaction status sequence, the interaction bearer node, status result, and status time are recorded. The connection relationship between adjacent interaction positions is checked item by item along the protocol interaction status sequence. If the previous interaction position is recorded as completed, and the next interaction position has not formed a corresponding status result, or if the status result of the current interaction position shows a missing handshake response, incomplete session recovery, stalled key negotiation, or unaccepted endpoint authentication, the break point between the current interaction position and the next interaction position is marked as the breakpoint position. If the interaction bearer node associated with the breakpoint position belongs to the faulty bearer path, the breakpoint position is determined as the protocol connection interruption position.
[0043] Furthermore, the status result is determined according to the interaction return record, status confirmation record, and completion flag in the protocol connection status record; the handshake response status is based on the existence of a corresponding handshake return record, the session recovery status is based on the existence of a session recovery completion flag, the key negotiation status is based on the existence of a key negotiation confirmation record, the endpoint authentication status is based on the existence of an endpoint authentication pass record, and the protocol audit status is based on the existence of a protocol audit record completion flag.
[0044] S2.3. Based on the fault bearer path and the location of the protocol connection interruption, collect the protocol interaction content before the location of the protocol connection interruption in the fault transmission associated data, and collect the security bearer information corresponding to the fault bearer path to generate protocol handshake connection elements and protocol bearer security elements.
[0045] Specifically, based on the faulty bearer path and the location of the protocol connection interruption, the protocol connection state record and bearer path state record corresponding to the same transmission record identifier are locked in the faulty transmission association data; using the location of the protocol connection interruption as the dividing boundary, the handshake initiation state, handshake response state, session recovery state, key negotiation state, endpoint authentication state, and protocol audit state that are located before the dividing boundary and have state results are collected into completed protocol interaction records according to the interaction order of the security protocol; the interaction location, interaction bearer node, state result, and state time corresponding to the completed protocol interaction record are included in the protocol handshake connection elements; and the state records that have not yet formed at the location of the protocol connection interruption are... The protocol interaction content of the status result and the protocol interaction content that needs to be continued after the protocol connection is interrupted are collected into a protocol interaction record to be accepted according to the interaction order of the security protocol. The interaction position and interaction bearer node corresponding to the protocol interaction record to be accepted are included in the protocol handshake connection element. The protocol handshake connection element includes the protocol interaction record that has been completed and the protocol interaction record to be accepted. Taking the fault bearer path as the bearer scope, the bearer node, bearer link, path connection status, node reachability status and path switching status corresponding to the bearer path status record are collected with the encrypted bearer information, identity authentication information, protocol audit information and protocol bearer security level in the protocol connection status record into the protocol bearer security element.
[0046] S2.4. Using the location where the protocol connection is interrupted as the dividing point, the protocol handover connection elements are divided into already-handled connection content and pending handover connection content.
[0047] Specifically, the protocol interaction content in the protocol handshake elements is sequentially divided based on the position of the protocol connection interruption point in the protocol interaction state sequence. The handshake initiation state, handshake response state, session recovery state, key negotiation state, endpoint authentication state, and protocol audit state, which are located before the protocol connection interruption point and already have state results, are classified as already-handled connection content. The protocol interaction content that has not formed a state result at the protocol connection interruption point, as well as the handshake response state, session recovery state, key negotiation state, endpoint authentication state, and protocol audit state, which still need to be continued after the protocol connection interruption point, are classified as pending-handled connection content. The already-handled connection content represents the security protocol interaction content that has been completed before the failure occurred.
[0048] S2.5 Establish an association relationship between the already secured connection content, the pending connection content, and the security elements carried by the protocol, match the association relationship to the location where the protocol connection is interrupted, and output the connection status data.
[0049] Specifically, taking the protocol connection interruption position as the corresponding position, the interaction positions, status results, status times, and interaction bearer nodes in the already-handled connection content before the protocol connection interruption position are arranged sequentially with the interaction positions, status results, status times, and interaction bearer nodes in the pending connection content at and after the protocol connection interruption position, according to the interaction order of the security protocol. In the arrangement result, the encrypted bearer information in the protocol bearer security elements is written into the key negotiation status record, the identity authentication information is written into the endpoint identity authentication status record, the protocol audit information is written into the protocol audit status record, and the protocol bearer security level is written into the protocol interaction content record under the same transmission record identifier. Through the correspondence between interaction positions, status results, status times, interaction bearer nodes, and protocol bearer security elements, an associated inheritance relationship is formed. The associated inheritance relationship is marked in the record position corresponding to the protocol connection interruption position, and the handover connection status data is output.
[0050] S3. Label the network transmission operation data corresponding to the faulty bearer path as network fault traffic, match candidate bearer paths for network fault traffic according to the handshake connection status data, use protocol bearer security elements as security level non-degradation constraints, use protocol handshake connection elements as handshake connection constraints, verify the security protocol bearer capability and handshake status acceptance capability of candidate bearer paths, and generate security matching path data.
[0051] S3.1. Locate the network transmission operation data corresponding to the fault bearer path in the fault transmission association data, and use it as the network fault traffic.
[0052] Specifically, based on the bearer nodes and bearer links in the faulty bearer path, the system locates the bearer path status record, protocol connection status record, and traffic transmission status record corresponding to the faulty bearer path under the same transmission record identifier in the faulty transmission association data. From the traffic transmission status record, it reads the traffic sending status, traffic receiving status, transmission delay, retransmission count, packet loss status, and transmission completion status corresponding to the faulty bearer path. From the protocol connection status record, it extracts the handshake initiation status, handshake response status, session recovery status, key negotiation status, endpoint authentication status, and protocol audit status corresponding to the faulty bearer path under the same transmission record identifier. Finally, it identifies the network transmission operation data belonging to the faulty bearer path in the traffic transmission status record and protocol connection status record as network fault traffic.
[0053] S3.2. Based on the handshake connection status data, eliminate faulty bearer paths from the network transmission operation data and generate reachable bearer path data.
[0054] Specifically, based on the protocol connection interruption location, already secured connection content, and pending connection content in the handover connection status data, path bearer entries associated with the transmission record identifier of network fault traffic are filtered from the network transmission operation data. If a path bearer entry contains the bearer node and bearer link of a faulty bearer path, the corresponding path bearer entry is excluded. If a path bearer entry contains candidate locations for path anomalies, protocol connection anomalies, or traffic transmission anomalies, the corresponding path bearer entry is excluded. The path bearer entries that are retained are examined for path connection status, node reachability status, and path switching status. Path bearer entries with continuous path connection status, valid node reachability status, and path switching status capable of handling the handover connection content are aggregated to generate reachable bearer path data.
[0055] It should be noted that the screening of path bearer entries associated with the transmission record identifier of network fault traffic is based primarily on the transmission record identifier corresponding to the network fault traffic. Path bearer entries with the same transmission record identifier are searched in the network transmission operation data. When there are path bearer entries that do not directly contain the same transmission record identifier, auxiliary verification is performed according to the source node, destination node, and security protocol connection relationship corresponding to the network fault traffic. Path bearer entries with consistent source nodes, consistent destination nodes, and consistent security protocol connection relationships are identified as path bearer entries associated with the transmission record identifier of the network fault traffic.
[0056] S3.3. Based on the pending connection content in the handover connection status data, the reachable bearer path data is matched with the network fault traffic to obtain candidate bearer paths.
[0057] Specifically, based on the interaction location, status result, status time, and interaction bearer node in the pending connection content, examine the bearer node, bearer link, path connection status, node reachability status, and path switching status of each path bearer entry in the reachable bearer path data. If the interaction bearer node in the pending connection content can be found in the bearer node of the path bearer entry, if the interaction location in the pending connection content can be connected to the bearer node of the path bearer entry according to the interaction order of the security protocol, and if the traffic sending status and traffic receiving status of the network fault traffic can remain continuous along the path bearer entry, it is determined that the path bearer entry and the network fault traffic have a connection matching relationship. The path bearer entry with the connection matching relationship is selected as the candidate bearer path.
[0058] S3.4 Extract the encrypted bearer information, identity authentication information and protocol audit information of the fault bearer path from the protocol bearer security elements, and perform security level maintenance calibration according to the bearer relationship of the fault bearer path to form a security level non-degradation constraint.
[0059] Specifically, the protocol bearer security elements already include encrypted bearer information, authentication information, protocol audit information, and protocol bearer security level corresponding to the faulty bearer path. According to the connection relationship between bearer nodes and bearer links in the faulty bearer path, encrypted bearer information is marked to the bearer link, authentication information is marked to the bearer node, protocol audit information is marked to the protocol interaction content record, and protocol bearer security level is marked to the faulty bearer path. Based on the corresponding results after marking, the encrypted bearer requirements, authentication requirements, protocol audit requirements, and protocol bearer security level requirements that candidate bearer paths need to maintain in subsequent verification are determined. The encrypted bearer requirements, authentication requirements, protocol audit requirements, and protocol bearer security level requirements are summarized to form a security level non-degradation constraint.
[0060] It should be noted that determining the encryption requirements, authentication requirements, protocol auditing requirements, and protocol security level requirements that candidate bearer paths need to maintain in subsequent verification involves: First, reading the encryption information link by link along the faulty bearer path, taking the encryption method, key negotiation status, and integrity verification status already used in the faulty bearer path as the encryption requirements. Second, reading the authentication information node by node along the faulty bearer path, taking the authenticated endpoint identity, authentication status, and authentication acceptance result as the authentication requirements. Third, reading the protocol audit information according to the same transmission record identifier, taking the established protocol audit status as the protocol audit requirements. Finally, reading the protocol security level corresponding to the faulty bearer path, taking this protocol security level as the minimum protocol security level requirement that candidate bearer paths must maintain.
[0061] The protocol's security level is generated based on the combined status of encrypted bearer information, authentication information, and protocol audit information. Specifically, a high security level is defined when the encryption suite identifier, key negotiation confirmation flag, and integrity verification method meet the secure protocol connection requirements, the certificate verification status is passed, the authentication completion flag is valid, and the audit completion flag is valid. A medium security level is defined when the encryption suite identifier, key negotiation confirmation flag, and integrity verification method meet the secure protocol connection requirements, the certificate verification status is passed, but the audit completion flag is not fully received. A basic security level is defined when there are records indicating that the encryption suite identifier, key negotiation confirmation flag, integrity verification method, certificate verification status, authentication completion flag, or audit completion flag is not met.
[0062] S3.5. The already-handled connection content, the connection to be handled, and the location of the protocol connection interruption in the handover connection elements are marked according to the interaction order of the security protocol to form handover connection bearing constraints.
[0063] Specifically, the already-handled connection content in the protocol handover connection elements is arranged according to the interaction order of the security protocol up to before the protocol connection interruption point. The connection content to be handled is arranged according to the interaction order of the security protocol up to the protocol connection interruption point and after the protocol connection interruption point. The interaction position, status result, status time, and interaction bearer node in the already-handled connection content are read, and the last interaction position with a status result is marked as the continuation start point. The interaction position, status result, status time, and interaction bearer node in the connection content to be handled are read, and the interaction position corresponding to the protocol connection interruption point but without a status result is marked as the start point to be accepted. The continuation start point, protocol connection interruption point, and start point to be accepted are concatenated according to the interaction order of the security protocol, and the interaction position order, status result continuity, status time connection relationship, and interaction bearer node acceptance relationship that the candidate bearer path needs to maintain are marked to form the handover connection bearer constraints.
[0064] It should be noted that the continuity of state results is judged based on the order of interaction positions in the protocol interaction state sequence. If the final interaction position of the already secured connection content has already formed a state result, and the starting interaction position of the pending connection content continues recording state results from the protocol connection interruption position, and there are no skipped interaction positions, inverted interaction positions, or missing state results, then the state results are considered continuous. The state time continuity is judged based on the chronological order of state times. If the state time corresponding to the starting interaction position of the pending connection content is not earlier than the state time corresponding to the protocol connection interruption position, and the state times corresponding to subsequent interaction positions of the pending connection content increase sequentially according to the interaction order of the security protocol, then the state time continuity is considered complete. The interaction bearer node succession relationship is judged based on the bearer node identifier and bearer link connection relationship. If the interaction bearer nodes in the pending connection content can find the same bearer node identifier among the bearer nodes of the candidate bearer path, and there are corresponding bearer link connections between adjacent interaction bearer nodes, then the interaction bearer node succession is considered complete.
[0065] S3.6. Map the security level non-degradation constraint, handshake connection bearer constraint and candidate bearer path to breakpoints, anchor the continuation entry and acceptance sequence of the candidate bearer path after the protocol connection is interrupted, and generate breakpoint mapping data.
[0066] Specifically, the encryption requirements, authentication requirements, protocol auditing requirements, and protocol bearer security level requirements in the no-downgrade security level constraint are marked on the bearer links, bearer nodes, and protocol interaction content records corresponding to the candidate bearer paths, respectively. The continuation start point, protocol connection interruption position, pending start point, interaction position order, state result continuity, state time connection relationship, and interaction bearer node acceptance relationship in the handshake connection bearer constraint are marked on the bearer node and bearer link connection order of the candidate bearer paths. The bearer node in the candidate bearer path that matches the interaction bearer node corresponding to the pending start point is found, and the found bearer node is determined as the continuation entry point after the protocol connection interruption position. Starting from the continuation entry point, the subsequent bearer nodes and bearer links of the candidate bearer path are arranged according to the interaction position order in the handshake connection bearer constraint, and the marked content corresponding to the no-downgrade security level constraint is retained simultaneously to generate breakpoint mapping data.
[0067] It should be noted that the breakpoint mapping data also synchronously records the transmission record identifier, source node, destination node, and security protocol connection relationship corresponding to the network failure traffic. After determining the reconnection entry point, the path bearer entries in the candidate bearer paths are checked according to the transmission record identifier to see if they can take over the same network failure traffic. The transmission objects before and after the reconnection are checked according to the source node, destination node, and security protocol connection relationship. The traffic transmission status after the protocol connection interruption point is checked according to the traffic sending status and traffic receiving status to see if the traffic transmission status can be continuously recorded. The candidate bearer paths are checked according to the path switching status to see if they have the conditions for switching over. Only when the transmission record identifier, source node, destination node, security protocol connection relationship, traffic sending status, traffic receiving status, and path switching status can all be taken over accordingly, is the reconnection entry point confirmed to be valid and the corresponding results are written into the breakpoint mapping data.
[0068] S3.7. Verify the relationship between the security protocol carrying capacity and the security level non-degradation constraint of the candidate bearer path according to the breakpoint mapping data, and verify the continuation relationship between the handshake state carrying capacity and the handshake handshake carrying constraint of the candidate bearer path to form path verification result data.
[0069] Specifically, candidate bearer paths are expanded one by one according to the breakpoint mapping data. The continuation entry point, acceptance order, and the corresponding encryption bearer requirements, authentication requirements, protocol auditing requirements, and protocol bearer security level requirements are examined, along with the security level non-downgrade constraint. If the encryption method, key negotiation status, and integrity verification status recorded in the candidate bearer path's encryption bearer capability meet the encryption bearer requirements; if the endpoint identity, authentication status, and authentication acceptance result recorded in the candidate bearer path's authentication capability meet the authentication requirements; if the candidate bearer path's protocol auditing capability can continue the protocol auditing status under the same transmission record identifier; and if the candidate bearer path's protocol bearer security level is not lower than the protocol bearer security level requirement, then the candidate bearer path is recorded as meeting the requirements. Security level does not degrade constraint; examine the pending connection content item by item according to the continuation entry and acceptance order. The interaction position in the pending connection content can be connected to the bearer node connection order of the candidate bearer path. The status result can continue to be formed according to the interaction order of the security protocol. The status time can be connected with the time after the protocol connection interruption position. When the interaction bearer node can be accepted by the bearer node in the candidate bearer path, the corresponding pending connection content is recorded as accepted content. Count the number of accepted content and calculate the path matching index value together with the total number of pending connection content. Collect the security level does not degrade constraint satisfaction value, the number of accepted content, the total number of pending connection content and the path matching index value to form path verification result data.
[0070] Furthermore, it should be noted that the security protocol carrying capacity and handshake state acceptance capacity of the candidate bearer path are derived from the path bearer entries, protocol connection state records, and breakpoint mapping data under the same transmission record identifier. Among them, the encryption bearer capacity is determined based on the encryption suite identifier, key negotiation confirmation mark, and integrity verification method in the protocol connection state record; the identity authentication capacity is determined based on the endpoint identity identifier, certificate verification status, authentication completion mark, and authentication acceptance result in the protocol connection state record; the protocol auditing capacity is determined based on the security protocol interaction record number, interaction state record, audit time, and audit completion mark in the protocol connection state record; and the handshake state acceptance capacity is determined based on the continuation entry point, acceptance order, interaction position order, state result continuity, state time connection relationship, and interaction bearer node acceptance relationship in the breakpoint mapping data.
[0071] The formula for calculating the path matching index value is as follows: ; in, An identifier representing a candidate bearer path. Indicates the first The path matching index value of the candidate bearer paths, This represents the weighting coefficient of the constraint that prevents the security level from being downgraded. Indicates the first The safety level of each candidate bearer path must not be downgraded, and the constraint must be satisfied. Indicates the first The number of contents already accepted for each candidate hosting path. This indicates the total number of pending procedures.
[0072] It should be noted that the weighting coefficient of the security level no-downgrade constraint is 0.7 in this embodiment. The value is based on the fact that during the network fault traffic migration process, the security protocol bearer cannot be lower than the encrypted bearer information, identity authentication information, protocol audit information, and protocol bearer security level already possessed by the fault bearer path. Security maintenance is a prerequisite constraint for path selection. Therefore, the proportion of the security level no-downgrade constraint is higher than that of the handshake connection bearer constraint. The security level no-downgrade constraint satisfaction value is determined based on the verification results of the candidate bearer path. The value is 1 when the candidate bearer path simultaneously meets the encrypted bearer requirements, identity authentication requirements, protocol audit requirements, and protocol bearer security level requirements. The value is 0 when any requirement is not met. The value is based on the fact that the security level no-downgrade constraint requires the candidate bearer path to fully maintain the security bearer capability of the fault bearer path.
[0073] S3.8. Based on the path verification results, candidate bearer paths that simultaneously meet the security level non-degradation constraint and the handshake connection bearer constraint are matched with network fault traffic to generate secure matching path data.
[0074] Specifically, the verification status of candidate bearer paths is screened based on the security level non-degradation constraint satisfaction value, the number of accepted contents, the total number of pending connections, and the path matching index value in the path verification results data. The security level non-degradation constraint satisfaction value indicates that the candidate bearer path meets the security level non-degradation constraint, and when the number of accepted contents is consistent with the total number of pending connections, the candidate bearer path is determined as a candidate bearer path that simultaneously meets the security level non-degradation constraint and the connection holding constraint. According to the transmission record identifier, fault bearer path, protocol connection interruption location, and pending connection content corresponding to the network fault traffic, the screened candidate bearer paths and network fault traffic are classified into the same matching record. The matching record saves the network fault traffic, candidate bearer path, reconnection entry, acceptance order, security level non-degradation constraint satisfaction value, the number of accepted contents, the total number of pending connections, and the path matching index value, forming secure matching path data.
[0075] Furthermore, the verification status of candidate bearer paths is screened by reading the security level non-degradation constraint satisfaction value, the number of accepted contents, the total number of contents to be accepted, and the path matching index value of each candidate bearer path in the path verification result data. When the security level non-degradation constraint satisfaction value indicates that the security level non-degradation constraint is met, the candidate bearer path is retained as a security verification passed path. When the number of accepted contents is consistent with the total number of contents to be accepted, the security verification passed path is retained as a connection-handling passed path. The connection-handling passed paths are sorted according to the path matching index value, and the sorted connection-handling passed paths are used as the screened candidate bearer paths.
[0076] It should be noted that, compared to existing methods that migrate faulty traffic solely based on link reachability, remaining bandwidth, or the shortest path, this solution transforms protocol bearer security elements into non-degradation security level constraints and protocol handshake connection elements into handshake connection bearer constraints. This ensures that the selection of candidate bearer paths is no longer solely based on path reachability, but is simultaneously constrained by encryption bearer requirements, authentication requirements, protocol auditing requirements, protocol bearer security level requirements, and the capacity to accept the content to be handed over. By anchoring the reconnection entry point and acceptance sequence after the protocol connection interruption location through breakpoint mapping data, and by quantifying the security maintenance status and handshake connection integrity of candidate bearer paths using path verification results data, this solution guarantees the continuity of security protocol status, the non-degradation of protocol bearer level, and the traceability of the handshake connection process during network faulty traffic migration. This improves the accuracy, reliability, and stability of security matching path data and faulty traffic migration.
[0077] S4. Select a continuation bearer path from the security matching path data, establish a continuation relationship between the handshake connection status data and the continuation bearer path, and arrange the continuation relationship according to the protocol connection interruption position to arrange the protocol continuation order, and output migration scheduling data.
[0078] S4.1 Select the corresponding candidate bearer path as the continuation bearer path in the security matching path data according to the matching relationship of network fault traffic.
[0079] Specifically, the security matching path data stores matching records between network failure traffic and candidate bearer paths. Matching records are searched according to the transmission record identifier of the network failure traffic, the failure bearer path, the location of the protocol connection interruption, and the content of the pending connection. The candidate bearer path, the continuation entry point, the acceptance order, the security level non-degradation constraint satisfaction value, the number of accepted contents, the total number of pending connection contents, and the path matching index value are read from the matching records. Among the matching records where the security level non-degradation constraint satisfaction value indicates that the security level non-degradation constraint is met, and the number of accepted contents matches the total number of pending connection contents, candidate bearer paths are arranged from highest to lowest according to the path matching index value. The candidate bearer path ranked first is selected as the continuation bearer path corresponding to the network failure traffic.
[0080] S4.2. Using network fault traffic as the associated object, bind the handover status data with the reconnection bearer path to establish a reconnection relationship.
[0081] Specifically, based on the transmission record identifier corresponding to the network fault traffic, the selected continuation bearer path in the security matching path data and the handshake connection status data under the same transmission record identifier are placed in the same acceptance record. In the acceptance record, the protocol connection interruption position in the handshake connection status data is mapped to the continuation entry point in the continuation bearer path, the end interaction position of the already handshake connection content is mapped to the protocol connection interruption position, the start interaction position of the content to be handshake connection is mapped to the continuation entry point, and the subsequent interaction positions of the content to be handshake connection are mapped to the bearer node and bearer link of the continuation bearer path in the order of acceptance. The protocol bearer security elements are mapped to the security bearer positions that need to be maintained in the continuation bearer path, so that the network fault traffic, handshake connection status data, and continuation bearer path form a continuation acceptance relationship under the same transmission record identifier.
[0082] S4.3 According to the location of the interruption in the protocol connection, divide the already secured connection content and the pending connection content in the continuation relationship into sequential order to form protocol continuation sequence data.
[0083] Specifically, in the continuation and succession relationship, the protocol connection interruption position is used as the dividing line. The interaction position, status result, status time, and interaction bearer node in the already secured connection content are read and arranged before the protocol connection interruption position according to the interaction order of the security protocol. The interaction position, status result, status time, and interaction bearer node in the pending connection content are read and arranged at the protocol connection interruption position and after the protocol connection interruption position according to the interaction order of the security protocol. The end interaction position of the already secured connection content and the start interaction position of the pending connection content are connected at the protocol connection interruption position, and the continuation entry is mapped to the start interaction position of the pending connection content. The succession order is mapped to the subsequent interaction positions of the pending connection content, forming the protocol continuation order data.
[0084] S4.4. Combine the protocol continuation sequence data with the continuation bearer path and network fault traffic, and output migration scheduling data.
[0085] Specifically, the protocol continuation sequence data, continuation bearer path, and network fault traffic are grouped into the same record location according to the transmission record identifier; the protocol connection interruption location is used as the migration scheduling starting point, and the starting interaction position of the pending connection content in the protocol continuation sequence data is mapped to the continuation entry point in the continuation bearer path, and the subsequent interaction positions of the pending connection content are mapped to the bearer nodes and bearer links of the continuation bearer path according to the acceptance order; the traffic transmission status record corresponding to the network fault traffic is determined according to the traffic sending status, traffic receiving status, transmission delay, retransmission count, packet loss status, and transmission completion status in the network fault traffic; the protocol connection interruption location, already accepted connection content, pending connection content, continuation entry point, acceptance order, continuation bearer path, and network fault traffic are organized and the migration scheduling data is output.
[0086] It should be noted that by incorporating the reconnection bearer path, handshake connection status data, and network fault traffic into the same reconnection and acceptance relationship, the path migration object and the security protocol reconnection status are made consistent and correspond to each other. This avoids problems such as handshake status disconnection, protocol interaction sequence misalignment, and unclear security bearer location after network fault traffic completes path switching. By using protocol reconnection sequence data to express the content of already-handled and pending handshakes in a sequential manner, the migration scheduling data can clearly define the reconnection entry point, acceptance sequence, and subsequent interaction acceptance location, thereby improving the protocol continuity, scheduling executability, and migration result traceability during the network fault traffic migration process.
[0087] S5. Migrate the network fault traffic from the faulty bearer path to the continued bearer path according to the migration scheduling data, and output the fault traffic optimization data.
[0088] S5.1. According to the migration scheduling data, switch the network fault traffic from the faulty bearer path to the continued bearer path, and record the migration process of the network fault traffic to form migration execution data.
[0089] Specifically, based on the network fault traffic, fault bearer path, resume bearer path, resume entry point, and acceptance sequence already determined in the migration scheduling data, the transmission direction of the network fault traffic after the protocol connection interruption point is switched from the fault bearer path to the resume bearer path. During the switch, the transmission record identifier corresponding to the network fault traffic and the already formed traffic transmission status record are retained. The traffic sending status and traffic receiving status to be continued are accessed to the resume bearer path according to the resume entry point, and mapped to the bearer node and bearer link of the resume bearer path according to the acceptance sequence. The fault bearer path, resume bearer path, protocol connection interruption point, resume entry point, acceptance sequence, path switching status, and switching time are recorded synchronously to form migration execution data.
[0090] S5.2. In the continued bearer path, perform protocol status acceptance confirmation and transmission bearer confirmation for network fault traffic, and obtain migration confirmation data.
[0091] Specifically, based on the transmission record identifier, reconnection bearer path, reconnection entry point, and acceptance order recorded in the migration execution data, the protocol connection status record and traffic transmission status record of the network fault traffic are read from the record position corresponding to the reconnection bearer path; according to the protocol reconnection order data in the migration scheduling data, it is verified whether the status results of the already-handed-off connection content are retained under the same transmission record identifier, and whether the connection content to be handled has formed a handshake response status, session recovery status, key negotiation status, endpoint authentication status, and protocol audit status from the reconnection entry point in the acceptance order; the key negotiation status is continuous, and the endpoint authentication status is inherited. The continuous recording of the connection and protocol audit status is determined as the protocol status acceptance confirmation result; according to the connection order of the bearer nodes and bearer links of the continued bearer path, it is verified whether the traffic sending status and traffic receiving status of the network fault traffic are continuously recorded along the continued bearer path, and whether the packet loss status, retransmission count, and transmission completion status correspond to the transmission process after migration; the continuous traffic sending status, continuous traffic receiving status, and transmission completion status are combined to form the transmission bearer confirmation result; the protocol status acceptance confirmation result, transmission bearer confirmation result, transmission record identifier, continued bearer path, and switching time are grouped into the same record to form migration confirmation data.
[0092] S5.3. Collect migration confirmation data, network fault traffic, resumed bearer paths, and migration execution data, and output fault traffic optimization data.
[0093] Specifically, using the transmission record identifier in the migration confirmation data as the aggregation basis, network fault traffic, resumed bearer paths, and migration execution data under the same transmission record identifier are grouped into the same data record. Within the same data record, the traffic transmission status record, fault bearer path, protocol connection interruption location, resumed bearer path, resumed entry point, acceptance sequence, path switching status, and switching time corresponding to the network fault traffic are retained. The protocol status acceptance confirmation result and transmission bearer confirmation result in the migration confirmation data are written into the same data record, and the security protocol resumed status is marked according to the protocol status acceptance confirmation result, and the transmission bearer status is marked according to the transmission bearer confirmation result. The transmission record identifier, network fault traffic, resumed bearer path, migration execution data, migration confirmation data, security protocol resumed status, and transmission bearer status are aggregated to form fault traffic optimization data.
[0094] This embodiment also provides a network fault traffic optimization system based on security protocol scheduling, including: The anomaly detection module is used to collect transmission status and identify path anomalies in the network transmission operation data during the security protocol scheduling process, and to obtain fault transmission related data. The reconnection calibration module is used to locate the fault bearer path and the protocol connection interruption location based on the fault transmission correlation data, extract the protocol handshake connection elements and protocol bearer security elements from the fault transmission correlation data, perform reconnection calibration on the protocol handshake connection elements and protocol bearer security elements according to the protocol connection interruption location, and output the handshake connection status data. The path matching module is used to identify the network transmission operation data corresponding to the faulty bearer path as network fault traffic, match candidate bearer paths for network fault traffic according to the handshake connection status data, use protocol bearer security elements as security level non-degradation constraints, use protocol handshake connection elements as handshake connection constraints, verify the security protocol bearer capability and handshake status acceptance capability of candidate bearer paths, and generate secure matching path data. The continuation scheduling module is used to select a continuation bearer path from the security matching path data, establish a continuation acceptance relationship between the handshake connection status data and the continuation bearer path, arrange the continuation acceptance relationship according to the protocol connection interruption position, and output migration scheduling data. The traffic migration module is used to migrate network fault traffic from the faulty bearer path to the continued bearer path according to the migration scheduling data, and output fault traffic optimization data.
[0095] In summary, this invention achieves secure reconnection matching for network fault traffic by performing joint verification on candidate bearer paths. It extracts encrypted bearer information, authentication information, and protocol audit information from protocol bearer security elements to form a non-degradation security level constraint. Simultaneously, it forms a handshake bearer constraint by arranging the already-handled, pending-handled, and protocol connection interruption locations in the protocol handshake handshake elements according to the security protocol interaction sequence. This anchors the reconnection entry point and acceptance sequence of candidate bearer paths after the protocol connection interruption location, enabling the secure matching path data to accurately record the candidate bearer path's secure bearer capability for network fault traffic, handshake state acceptance capability, and protocol reconnection adaptation relationship. This improves the security continuity of migration scheduling data and the stability of fault traffic optimization data.
[0096] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A network fault traffic optimization method based on security protocol scheduling, characterized in that: include, Perform transmission status collection and path anomaly identification on network transmission operation data during the security protocol scheduling process, and obtain fault transmission related data; Based on the fault transmission correlation data, locate the fault bearer path and the protocol connection interruption location, extract the protocol handshake connection elements and protocol bearer security elements from the fault transmission correlation data, perform reconnection calibration on the protocol handshake connection elements and protocol bearer security elements according to the protocol connection interruption location, and output the handshake connection status data. The network transmission operation data corresponding to the faulty bearer path is labeled as network fault traffic. Candidate bearer paths are matched for network fault traffic according to the handshake connection status data. Protocol bearer security elements are used as security level non-degradation constraints, and protocol handshake connection elements are used as handshake connection constraints. The security protocol bearer capability and handshake status acceptance capability of the candidate bearer paths are verified, and security matching path data is generated. Select a continuation bearer path from the security matching path data, establish a continuation relationship between the handshake connection status data and the continuation bearer path, and arrange the continuation relationship according to the protocol connection interruption position to arrange the protocol continuation order and output migration scheduling data. The network fault traffic is migrated from the faulty bearer path to the continued bearer path according to the migration scheduling data, and the fault traffic optimization data is output.
2. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for obtaining fault transmission-related data are as follows: The bearer path status record, protocol connection status record, traffic transmission status record, and transmission record identifier are extracted from the network transmission operation data. Based on the transmission record identifier, the bearer path status record, protocol connection status record, and traffic transmission status record are aggregated to form transmission status aggregated data. Information identification is performed on the transmission status collection data to obtain path anomaly identification data; The path anomaly identification data is written back to the transmission status collection data according to the transmission record identifier to generate fault transmission association data.
3. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for extracting the protocol handshake connection elements and protocol bearer security elements are as follows: Verify the path anomaly identification data and bearer path status records in the fault transmission association data to determine the faulty bearer path; Using the fault-bearing path as the location object, the protocol connection status records in the fault transmission associated data are checked according to the interaction order of the security protocol to determine the location of the protocol connection interruption. Based on the fault bearer path and the location of the protocol connection interruption, the protocol interaction content before the location of the protocol connection interruption is collected in the fault transmission associated data, and the security bearer information corresponding to the fault bearer path is collected to generate protocol handshake connection elements and protocol bearer security elements.
4. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for outputting the handshake connection status data are as follows: Using the location where the protocol connection is interrupted as the dividing point, the protocol handover elements are divided into already-handled connection content and pending handover content. Establish an association relationship between the already secured connection content, the pending connection content, and the security elements carried by the protocol, match the association relationship to the location where the protocol connection is interrupted, and output the connection status data.
5. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for matching candidate bearer paths are as follows: Search for the network transmission operation data corresponding to the fault bearer path in the fault transmission association data, and use it as the network fault traffic; Based on the handshake connection status data, faulty bearer paths are eliminated from the network transmission operation data, and reachable bearer path data is generated. Based on the pending connection information in the connection status data, the reachable bearer path data is matched with network fault traffic to obtain candidate bearer paths.
6. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for generating secure matching path data are as follows: The encrypted bearer information, identity authentication information, and protocol audit information of the fault bearer path are extracted from the security elements of the protocol bearer, and the security level is maintained and calibrated according to the bearer relationship of the fault bearer path to form a constraint that the security level does not degrade. The already-handled connection content, the connection to be handed over, and the location of the connection interruption in the protocol handover connection elements are marked as handover connection bearers according to the interaction order of the security protocol, thus forming handover connection bearer constraints. The breakpoint mapping data is generated by mapping the security level non-downgrade constraint, the handshake connection bearer constraint and the candidate bearer path, anchoring the continuation entry and acceptance order of the candidate bearer path after the protocol connection is interrupted. The relationship between the security protocol carrying capacity and the security level non-degradation constraint of the candidate bearer path is verified according to the breakpoint mapping data. The relationship between the handshake state carrying capacity and the handshake handshake carrying constraint of the candidate bearer path is also verified to form path verification result data. Based on the path verification results, candidate bearer paths that simultaneously meet the constraints of no security level degradation and handshake connection bearing are matched with network fault traffic to generate secure matching path data.
7. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for establishing a continuation and succession relationship are as follows: In the secure matching path data, the corresponding candidate bearer path is selected as the continuation bearer path according to the matching relationship of network fault traffic; Using network fault traffic as the associated object, the handover status data and the continuation bearer path are bound together to establish a continuation relationship.
8. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for outputting migration scheduling data are as follows: According to the location of the interruption in the protocol connection, the already secured connection content and the pending connection content in the continuation relationship are divided into sequential order to form protocol continuation sequence data; The protocol continuation sequence data is jointly orchestrated with the continuation bearer path and network fault traffic to output migration scheduling data.
9. The network fault traffic optimization method based on security protocol scheduling as described in claim 1, characterized in that: The specific steps for outputting faulty traffic optimization data are as follows: According to the migration scheduling data, the network fault traffic is switched from the faulty bearer path to the continued bearer path, and the migration process of the network fault traffic is recorded to form migration execution data. In the reconnected bearer path, perform protocol status acceptance confirmation and transmission bearer confirmation for network fault traffic, and obtain migration confirmation data; The migration confirmation data, network fault traffic, resumed bearer paths, and migration execution data are aggregated to output fault traffic optimization data.
10. A network fault traffic optimization system based on security protocol scheduling, based on the network fault traffic optimization method based on security protocol scheduling according to any one of claims 1 to 9, characterized in that: include, The anomaly detection module is used to collect transmission status and identify path anomalies in the network transmission operation data during the security protocol scheduling process, and to obtain fault transmission related data. The reconnection calibration module is used to locate the fault bearer path and the protocol connection interruption location based on the fault transmission correlation data, extract the protocol handshake connection elements and protocol bearer security elements from the fault transmission correlation data, perform reconnection calibration on the protocol handshake connection elements and protocol bearer security elements according to the protocol connection interruption location, and output the handshake connection status data. The path matching module is used to identify the network transmission operation data corresponding to the faulty bearer path as network fault traffic, match candidate bearer paths for network fault traffic according to the handshake connection status data, use protocol bearer security elements as security level non-degradation constraints, use protocol handshake connection elements as handshake connection constraints, verify the security protocol bearer capability and handshake status acceptance capability of candidate bearer paths, and generate secure matching path data. The continuation scheduling module is used to select a continuation bearer path from the security matching path data, establish a continuation acceptance relationship between the handshake connection status data and the continuation bearer path, arrange the continuation acceptance relationship according to the protocol connection interruption position, and output migration scheduling data. The traffic migration module is used to migrate network fault traffic from the faulty bearer path to the continued bearer path according to the migration scheduling data, and output fault traffic optimization data.