A data transmission method, system and electronic device
Patent Information
- Application Number
- CN202610829207.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-09
- Publication Date
- 2026-09-25
AI Technical Summary
[0011]本公开提供了一种数据传输方法、系统及电子设备,该数据传输方法首先建立遵循国际标准的传输层加密协议的加密隧道,确保加密隧道建立过程的流量特征与普通HTTPS业务完全一致,不会被安全阻断设备的DPI引擎识别并阻断;其次,将所有源隔离网段内待发送至目的隔离网段的数据流,拆解为符合标准应用层协议格式的标准应用层协议帧,使所有跨网传输数据包的格式和大小分布均符合正常互联网业务特征,从而避开DPI引擎的深度检测;最后,将来自不同数据流的标准应用层协议帧在应用层进行交错排列,通过同一条加密隧道传输,既实现了单端口同时承载多路独立内网数据流,又将TCP协议固有队头阻塞的影响范围限制在单个受影响的数据流内,提升了高并发场景下的传输稳定性和吞吐量。
Smart Images

Figure CN122824428A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network communication technology, and in particular to a data transmission method, system and electronic device. Background Technology
[0002] In high-security network environments such as government, enterprise, military, and financial institutions, strict firewalls or gateways are typically deployed between isolated network segments of different physical areas or security levels. For security reasons, these gateways usually only open a very small number of specific communication ports and are often accompanied by rigorous deep packet inspection.
[0003] Current cross-isolated network segment data transmission commonly employs conventional port forwarding or simple proxy technologies. These technologies are based on a one-to-one mapping mechanism, where a single target port opened by a security blocking device can only be fixedly mapped to and carry a specific service node or a single service connection within the internal network. However, in practical applications, the source isolated network segment typically contains hundreds or thousands of network nodes, generating a large number of independent data streams that need to communicate across networks. Faced with the stringent limitation of security blocking devices opening only a very small number of target ports, existing single-port mapping mechanisms have extremely poor scalability and cannot efficiently transmit multiple data streams generated by different network addresses and application ports within the source isolated network segment to the destination isolated network segment through a limited number of target ports. Summary of the Invention
[0004] This disclosure provides a data transmission method, system, and electronic device; it enables data exchange between two isolated network segments through a small number of open ports.
[0005] The technical solution disclosed herein is implemented as follows: In a first aspect, this disclosure provides a data transmission method applied to a sending device. The method includes: establishing an encrypted tunnel based on a standard transport layer encryption protocol with a receiving device by securely blocking the open target port of the device, wherein the number of encrypted tunnels is consistent with the number of target ports; acquiring multiple data streams to be sent to the destination isolated network segment within the source isolated network segment, and assigning a stream identifier to each data stream; encapsulating each data stream into at least one standard application layer protocol frame, wherein each standard application layer protocol frame carries the stream identifier corresponding to its data stream; and interleaving the standard application layer protocol frames belonging to different data streams to the receiving device through the same encrypted tunnel.
[0006] Secondly, this disclosure provides a data transmission method applied to a receiving device. The method includes: establishing an encrypted tunnel based on a standard transport layer encryption protocol with a sending device by securely blocking the open target port of the receiving device, wherein the number of encrypted tunnels is consistent with the number of target ports; receiving multiple standard application layer protocol frames sent by the sending device through the encrypted tunnel, wherein each standard application layer protocol frame carries a flow identifier corresponding to its data stream; reassembling standard application layer protocol frames with the same flow identifier to obtain multiple data streams; and forwarding the multiple data streams to the corresponding destination device within the destination isolated network segment.
[0007] Thirdly, this disclosure provides a data transmission apparatus applied to a transmitting device. The apparatus includes: a tunnel establishment section, an acquisition section, an encapsulation section, and a transmission section. The tunnel establishment section is configured to establish an encrypted tunnel based on a standard transport layer encryption protocol with a receiving device through a target port opened by a security blocking device, wherein the number of encrypted tunnels is consistent with the number of target ports. The acquisition section is configured to acquire multiple data streams to be sent to a destination isolated network segment within a source isolated network segment and assign a stream identifier to each data stream. The encapsulation section is configured to encapsulate each data stream into at least one standard application layer protocol frame, wherein each standard application layer protocol frame carries a stream identifier corresponding to its data stream. The transmission section is configured to interleave standard application layer protocol frames belonging to different data streams through the same encrypted tunnel to the receiving device.
[0008] Fourthly, this disclosure provides a data transmission apparatus applied to a receiving device. The apparatus includes: a tunnel establishment section, a receiving section, a data reassembly section, and a sending section. The tunnel establishment section is configured to establish an encrypted tunnel based on a standard transport layer encryption protocol with the sending device through a target port opened by a security blocking device, wherein the number of encrypted tunnels is consistent with the number of target ports. The receiving section is configured to receive multiple standard application layer protocol frames sent by the sending device through the encrypted tunnel, wherein each standard application layer protocol frame carries a flow identifier corresponding to its data stream. The data reassembly section is configured to reassemble standard application layer protocol frames with the same flow identifier to obtain multiple data streams. The sending section is configured to forward the multiple data streams to the corresponding destination device within the destination isolated network segment.
[0009] Fifthly, this disclosure provides an electronic device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the data transmission method as described in the first or second aspect.
[0010] In a sixth aspect, this disclosure provides a computer-readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the data transmission method as described in the first or second aspect.
[0011] This disclosure provides a data transmission method, system, and electronic device. The data transmission method first establishes an encrypted tunnel conforming to international standard transport layer encryption protocols, ensuring that the traffic characteristics during the tunnel establishment process are completely consistent with ordinary HTTPS services and will not be identified and blocked by the DPI engine of security blocking devices. Second, it decomposes all data streams from the source isolated network segment to the destination isolated network segment into standard application layer protocol frames conforming to the standard application layer protocol format, ensuring that the format and size distribution of all cross-network transmitted data packets conform to the characteristics of normal Internet services, thereby avoiding deep detection by the DPI engine. Finally, it interleaves the standard application layer protocol frames from different data streams at the application layer and transmits them through the same encrypted tunnel. This achieves simultaneous carrying of multiple independent internal network data streams on a single port while limiting the impact of TCP's inherent head-of-line blocking to a single affected data stream, improving transmission stability and throughput in high-concurrency scenarios. Attached Figure Description
[0012] Figure 1 This is a schematic diagram of the architecture of a communication system provided in this disclosure.
[0013] Figure 2 This is a flowchart illustrating a data transmission method applied to a transmitting device provided in this disclosure.
[0014] Figure 3 This is a flowchart illustrating a data transmission method applied to a receiving device, as provided in this disclosure.
[0015] Figure 4 This disclosure provides a structural block diagram of a data transmission device applied to a transmitting device.
[0016] Figure 5 This disclosure provides a structural block diagram of a data transmission device applied to a receiving end device.
[0017] Figure 6 This is a schematic diagram of the hardware structure of an electronic device provided in this disclosure. Detailed Implementation
[0018] The technical solutions in the embodiments of this disclosure will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure are within the scope of protection of this disclosure.
[0019] Please see Figure 1 , Figure 1 This is a schematic diagram of the architecture of a communication system provided in an embodiment of this disclosure. Figure 1 As shown, the communication system may include: a source isolation network segment 110, a destination isolation network segment 120, and a security blocking device 130 disposed between the source isolation network segment 110 and the destination isolation network segment 120. A transmitting end device 111, also known as edge gateway A, is deployed at the boundary of the source isolation network segment 110, and a receiving end device 121, also known as edge gateway B, is deployed at the boundary of the destination isolation network segment 120.
[0020] Specifically, the source isolation network segment 110 and the destination isolation network segment 120 are two physically isolated private network segments with different security levels or belonging to different physical regions. The diagram exemplifies that the source isolation network segment 110 includes internal network node 1, internal network node 2, and internal network node 3, and the destination isolation network segment 120 includes internal network node a, internal network node b, and internal network node c. The number of nodes mentioned above is for illustrative purposes only; in actual applications, any number of network nodes can be deployed according to business needs.
[0021] The source isolation network segment 110 and the destination isolation network segment 120 can be private local area networks (LANs) within government, enterprise, military, medical, or financial industries, or they can be different logically isolated domains within the same company based on security levels. For example, the source isolation network segment 110, as the side initiating cross-network access requests, can include multiple private servers, workstations, or IoT terminals that generate data access requests; the destination isolation network segment 120, as the side providing core business services, can deploy database servers, confidential file storage arrays, or R&D platforms, etc.
[0022] The security blocking device 130 can be a physical one-way optical gateway, a two-way network gateway, a next-generation firewall, or a Deep Packet Inspection (DPI) gateway, among other hardware security defense devices. Under industrial-grade security standards, the security blocking device 130 typically denies all access policies by default, opening only a very limited number of target ports based on a whitelist. For example, it may only open Transmission Control Protocol (TCP) port 443 or TCP port 8080, and physically block all other ports, such as User Datagram Protocol (UDP) port 500 and TCP port 22. Furthermore, the DPI engine inside the security blocking device 130 performs Layer 7 protocol parsing on data packets flowing through the target ports in real time. Through pattern matching and entropy analysis, if the traffic characteristics do not conform to the fingerprint of standard global wide area network (Web) traffic, the data packet is immediately discarded, and an alarm may be triggered.
[0023] In this embodiment, the sending device 111 and the receiving device 121 act as edge nodes. The sending device 111 acts as a client, listening to traffic requests within the source isolation network segment 110 and actively initiating a connection to the target port mapped by the security blocking device 130. The receiving device 121 acts as a server, listening to the target port corresponding to the destination isolation network segment 120. Although this embodiment uses the sending device 111 actively initiating a connection as an example, in other embodiments, if the network topology allows, the receiving device 121 can also initiate a reverse connection as a client, and this disclosure does not limit this.
[0024] Due to the presence of security blocking device 130, if traditional Internet Protocol Security Virtual Private Network (IPsec VPN) is used directly for cross-network access, the DPI engine will identify and block these non-standard web traffic protocol and port characteristics because IPsec relies on a specific key exchange protocol, requiring the opening of UDP port 500 and the encapsulation of a secure payload protocol for data transmission. If a traditional single-port reverse proxy is used, an externally open TCP port 443 can only be mapped to a specific port of a specified server within the destination isolated network segment 120. This prevents multiple independent Internet Protocol (IP) sessions within the source isolated network segment 110 from being simultaneously carried in this single channel, thus hindering full-segment interconnection. Furthermore, if all data is carried using a single TCP connection at the software level—that is, all data is sent in a single TCP connection—then if a large file transfer blocks the TCP sending window, or if packet loss triggers the TCP retransmission mechanism, all subsequent unrelated critical business packets (such as heartbeat detection and control commands) must queue, causing TCP head-of-line congestion.
[0025] Based on this, the present disclosure provides a data transmission method that can utilize one or a few compliant open ports to enable mutual access between two isolated private network segments.
[0026] The data transmission method provided in this disclosure will be described in detail below with reference to specific embodiments and accompanying drawings.
[0027] Please see Figure 2 , Figure 2 This is a flowchart illustrating a data transmission method applied to a transmitting device according to an embodiment of this disclosure. The method can be derived from the above... Figure 1 The sending device 111 (or a computing entity such as a processor in an electronic device) executes the command. For example... Figure 2 As shown, the method may include the following steps S201 to S204.
[0028] In step S201, an encrypted tunnel based on the standard transport layer encryption protocol is established with the receiving device through the target port opened by the security blocking device.
[0029] In practice, in order for cross-network traffic to legally penetrate security blocking devices, the sending device first needs to establish at least one underlying encrypted logical connection, i.e., an encrypted tunnel. The number of these encrypted tunnels is consistent with the number of target ports.
[0030] To bypass the DPI engine's detection, this embodiment does not use the traditional VPN protocol, but instead uses a standard transport layer encryption protocol for handshake and connection establishment. The standard transport layer encryption protocol refers to the transport layer encryption protocol that is widely recognized and supported by the Internet. Its protocol format, handshake process and traffic characteristics all conform to international standards and can pass the DPI engine's inspection. For example, Transport Layer Security (TLS) 1.2, TLS 1.3, etc.
[0031] In a specific embodiment, the handshake process in step S201 may specifically include: the sending device sending a handshake packet that conforms to the standard transport layer encryption protocol and has added random length padding data to the receiving device; and establishing an encrypted tunnel when the receiving device returns the handshake packet.
[0032] Specifically, let's take the TLS 1.3 protocol, the standard transport layer encryption protocol, as an example. When the sending device initiates the "ClientHello" handshake packet, in order to conceal its true identity as the sending device, it mixes padding data of random length and random content into the extended fields or payload areas allowed by the TLS 1.3 protocol. For example, according to the TLS 1.3 RFC 8446 specification, a padding extended field can be added to the handshake message. This padding data changes dynamically with each connection establishment, making the byte length and content entropy value of the handshake packet exhibit a random distribution characteristic consistent with that of a normal user accessing a web page through a browser. As a result, when the DPI engine of the security blocking device captures the handshake packet, based on its feature matching rules, it will determine that the handshake packet is ordinary HTTPS web browsing or legitimate Application Programming Interface (API) call traffic, and thus allow it to pass.
[0033] Without adding random-length padding data to the handshake packet, traditional encrypted tunnel gateways often have a fixed-length payload or a fixed client fingerprint during the handshake. Advanced security blocking devices may use machine learning algorithms or feature database comparisons to identify that the handshake packet is a VPN node attempting to establish a connection, thus directly severing the TCP connection at the transport layer. By introducing a random padding masquerading mechanism, the embodiments of this disclosure significantly improve the success rate of cross-network traffic penetration.
[0034] In step S202, multiple data streams to be sent to the destination isolation segment within the source isolation segment are obtained, and a stream identifier is assigned to each data stream.
[0035] After the encrypted tunnel is established, the sending device begins to listen for and intercept intranet service traffic on the source isolation network segment side. Since there may be hundreds of hosts in the source isolation network segment simultaneously initiating access to the destination isolation network segment, such as host A querying the database of the destination isolation network segment, host B submitting an HTTP form to the destination isolation network segment, host C performing Secure Shell (SSH) remote login, etc., these traffic appear as multiple concurrent and independent intranet IP sessions at the network layer (L3) and transport layer (L4).
[0036] In this embodiment, the sending device can obtain multiple internal network IP sessions through virtual network devices in the operating system kernel, such as network layer virtual network interface cards (Network TUNnel, TUN), data link layer virtual network interface cards (Network TAP, TAP), or lower-level bypass traffic interception technologies. In this case, the sending device does not create a TCP connection across the security blocking device for each internal network IP session. Instead, it aggregates each independent internal network IP session into a single logical data stream and assigns a globally unique stream identifier to each independent data stream.
[0037] Multiple data streams can be implemented through different routing and mapping mechanisms. One is a direct routing mechanism at the network layer, and the other is a service mapping mechanism at the transport layer.
[0038] For direct routing at the network layer, the local routing table of the sending device includes routing information for the destination isolated network segment. For example, the sending device maintains a routing table entry for a destination isolated network segment of 10.2.0.0 / 16 and a source isolated network segment of 10.1.0.0 / 16.
[0039] The above-mentioned acquisition of multiple data streams to be sent from the source isolation network segment to the destination isolation network segment specifically includes: when the original data packet is received from the source isolation network segment, querying the local routing table; if the destination address of the original data packet matches the routing information of the destination isolation network segment in the local routing table, then the complete session corresponding to the original data packet is determined as a data stream to be sent.
[0040] No client software needs to be installed on the internal network machines. When a host in the source isolated network segment initiates a request, its network stack sends the raw data packet to the sending device according to the standard TCP / IP protocol. The sending device parses the IP header, discovers that the destination IP is located in the destination isolated network segment through a prefix matching algorithm, and then treats the complete session corresponding to the raw data packet as a single data stream. This method enables seamless communication between hosts in two private network segments.
[0041] However, for scenarios with extremely high security requirements, security policies may strictly prohibit the exposure of the entire destination isolated network segment's topology, allowing only specific services to provide external access. In such scenarios, a transport layer service mapping mechanism can be used. In this case, the sending device is pre-configured with service mapping rules, which include a one-to-one correspondence between the sending device's local ports and service addresses within the destination isolated network segment.
[0042] The process of acquiring multiple data streams to be sent from the source isolation network segment to the destination isolation network segment includes: when the original data packet is received from the source isolation network segment, extracting the destination port of the original data packet; if the destination port is the same as the local port in the service mapping rule, converting the destination address of the original data packet to the corresponding service address in the destination isolation network segment, and determining the complete session corresponding to the converted original data packet as a data stream to be sent.
[0043] For example, a policy is pre-configured on the sending device to map port 3306 of the internal database server (IP: 192.168.10.5) in the destination isolated network segment to port 5506 on the sending device. When a business system in the source isolated network segment attempts to connect to port 5506 of the sending device, the sending device captures the traffic, identifies the port match, and then converts this TCP stream into a data stream destined for 192.168.10.5:3306, assigning a flow identifier. This method allows only specific services to penetrate between two isolated network segments without changing the external physical port configuration of the firewall.
[0044] Regardless of the mechanism used, the sending device will internally start a multiplexing engine to assign an unsigned integer stream identifier to each concurrent independent intranet IP session, that is, a five-tuple of different source IP, port and destination IP, port.
[0045] In step S203, each data stream is encapsulated into at least one standard application layer protocol frame, and each standard application layer protocol frame carries the stream identifier corresponding to its data stream.
[0046] Standard application layer protocol frames refer to application layer protocol data units that conform to international standards. They have fixed frame formats and field definitions and support multiplexing. Examples include HTTP / 2 frames and HTTP / 3 frames.
[0047] In this embodiment, when there are multiple concurrent data streams, the multiplexing engine of the sending device, such as the stream mechanism based on the HTTP / 2 protocol or the gRPC underlying framework, will break down a data stream, such as transmitting a 1GB video file, into data segments of a preset length (e.g., the maximum frame length is 16KB).
[0048] Subsequently, each data segment is encapsulated into a frame conforming to a standard application layer protocol, i.e., a standard application layer protocol frame. A flow identifier for that data stream is added to the header structure of the standard application layer protocol frame. Through this encapsulation, even if the number of intranet IP session requests is large, they will be uniformly standardized into small-granularity payload units with explicit flow identifiers. For example, the original data size of data stream 1 is 100KB, which will be divided into six 16KB data segments and one 4KB data segment. Each data segment is encapsulated into an HTTP / 2 data frame, and the flow identifier of all seven frames is 1. Since each standard application layer protocol frame conforms to international standard application layer protocol specifications, the format of the encapsulated frame fully complies with international standards and will not be identified as abnormal traffic by the DPI engine. Through the above framing and encapsulation technology, logically independent data streams share the same encrypted tunnel, completely isolated from each other and without interference.
[0049] In step S204, the standard application layer protocol frames belonging to different data streams are interleaved and transmitted to the receiving device through the same encrypted tunnel.
[0050] After frame encapsulation, the sending device mixes these standard application layer protocol frames, which belong to different intranet IP sessions and have different flow identifiers, together and sends them to the receiving device through an encrypted tunnel for frame-level interleaving.
[0051] Specifically, suppose there are two data streams that need to be sent: data stream A (large file download) and data stream B (small data heartbeat packets). The sending device can send a frame with stream identifier A, followed by a frame with stream identifier B, and then send a frame with stream identifier A again. This frame-level interleaving transmission mechanism within the encrypted tunnel ensures fair concurrent transmission of various data streams. Even if high-volume service A consumes a large amount of bandwidth, frames from low-volume service B can still be interspersed and sent in a timely manner. Furthermore, because each frame is small, it does not cause prolonged transmission congestion, fundamentally solving the single-channel performance bottleneck and application-layer head-of-line blocking problem.
[0052] For example, for 6 frames corresponding to 3 data streams, in a fault scenario where frame 1 of data stream 2 is lost: the solution disclosed herein encapsulates each data stream into an independent standard application layer protocol frame, with each frame carrying a globally unique stream identifier. The in-order transmission characteristic of the TCP layer still exists, and the receiving device still needs to wait for the retransmission to complete before delivering all bytes to the application layer; however, the HTTP / 2 application layer will immediately parse the byte stream into 6 independent application layer frames according to the stream identifier and process the frames of different streams in parallel. Data streams 1 and 3 can complete all processing within 0.2ms after retransmission, while only data stream 2 needs to continue processing until 0.3ms after retransmission. Ultimately, the delay of data streams 1 and 3 is only affected by TCP layer retransmission, and the blocking range is strictly limited to a single affected data stream.
[0053] In this embodiment, firstly, an encrypted tunnel conforming to international standard transport layer encryption protocols is established to ensure that the traffic characteristics during the encrypted tunnel establishment process are completely consistent with ordinary HTTPS services and will not be identified and blocked by the DPI engine of the security blocking device. Secondly, all data streams from the source isolated network segment to the destination isolated network segment are decomposed into standard application layer protocol frames conforming to the standard application layer protocol format, so that the format and size distribution of all cross-network transmitted data packets conform to the characteristics of normal Internet services, thereby avoiding the deep detection of the DPI engine. Finally, the standard application layer protocol frames from different data streams are interleaved at the application layer and transmitted through the same encrypted tunnel. This not only enables a single port to carry multiple independent internal network data streams simultaneously, but also limits the impact of TCP protocol's inherent head-of-line blocking to a single affected data stream, improving transmission stability and throughput in high-concurrency scenarios.
[0054] Some more advanced DPI engines not only detect characteristics during the handshake phase but may also perform traffic statistics analysis on the encrypted payload after the connection is established. If the DPI engine finds that the size distribution pattern of encrypted data transmission units through the target port is highly similar to the traffic of a specific application (such as the fixed heartbeat packet length of a certain database), it may still block it.
[0055] To further enhance the concealment of data when passing through security blocking devices, in one embodiment, step S204, which involves interleaving standard application layer protocol frames through an encrypted tunnel, also includes traffic shaping and secondary masquerading mechanisms. Specifically, this includes: encapsulating the standard application layer protocol frame into a data transmission unit conforming to the standard transport layer encryption protocol, adding random-length padding data to this data transmission unit; and interleaving the data transmission unit to the receiving device through the encrypted tunnel.
[0056] A data transmission unit (DTU) refers to a Transport Layer Encryption Protocol (TLS) record that conforms to the standard TLS specification. It is the basic unit used to transmit application layer data within the TLS, consisting of a header and a payload. By adding padding data of random length, the length of each DTU captured from the network dynamically changes, thereby randomizing traffic characteristics and circumventing the traffic statistical analysis algorithms of security blocking devices.
[0057] For example, the standard transport layer encryption protocol is TLS 1.3. At the TLS record protocol layer, random-length padding bytes are added to the standard application layer protocol frame, and the resulting TLS record is the data transmission unit. The format of a TLS record is: a 5-byte header, a variable-length cryptographic payload, and variable-length padding data. The length of the padding data is randomly generated between 0 and 255 bytes, ensuring that the total length of each TLS record is randomly distributed. The padding data is generated by the operating system kernel's random number generator and consists of unpredictable random bytes, containing no identifiable characteristic information. For example, if the standard application layer protocol frame is a 1400-byte HTTP / 2 frame, adding 50 bytes of padding data will result in a TLS record with a total length of 1455 bytes.
[0058] The aforementioned multiplexing and traffic masquerading mechanisms can achieve normal communication across isolated network segments. However, the encryption of data streams is typically performed in software by the central processing unit (CPU) of the sending device. In high-concurrency cross-network transmission scenarios, such as when thousands of intranet data streams need to be transmitted across networks simultaneously, this purely software encryption method may exhaust CPU resources. Encryption is a computationally intensive task; when there are many concurrent data streams, the CPU will be fully occupied by encryption operations, leading to slow system response and even process freezes. Furthermore, traditional software encryption uses a synchronous blocking mode, requiring the previous data stream to be encrypted before the next stream can begin, and the queuing time for encryption tasks increases linearly with the number of concurrent requests.
[0059] Therefore, in this embodiment of the disclosure, before encapsulating each data stream into at least one standard application layer protocol frame in step S203, a step of accelerating the process using a local hardware encryption device is also included.
[0060] Specifically, the data transmission method further includes: submitting multiple data streams to a local hardware encryption device for concurrent encryption operations through an asynchronous non-blocking mechanism; obtaining multiple encrypted data returned by the hardware encryption device; and correspondingly, encapsulating each data stream into at least one standard application layer protocol frame, including: encapsulating each encrypted data stream into at least one standard application layer protocol frame.
[0061] Inside the sending device, the traditional kernel protocol stack is bypassed. The CPU uses a user-mode polling mode to directly intercept raw data packets from the network card's cache. The CPU employs an asynchronous, non-blocking approach, using a Direct Memory Access (DMA) circular buffer to submit data blocks (with internal identification information to distinguish the transmission source and destination) to the hardware encryption device in batches. This asynchronous, non-blocking mechanism is a program execution mode where, after submitting a task, other tasks can continue to execute without waiting for the task to complete. Upon completion, the result is returned via a callback function or event notification. The hardware encryption device refers to a hardware module that integrates a dedicated encryption computing core, possessing an independent instruction set and memory space, capable of processing multiple encryption requests in parallel. Examples include Peripheral Component Interconnect Express (PCIe) encryption accelerator cards and trusted platform modules.
[0062] After the hardware encryption device performs encryption and integrity verification hash operations on the data stream in parallel, it does not notify the CPU via a hardware interrupt. Instead, it updates the status flag of the completion queue. Once the CPU detects the flag update, it pulls the encrypted data back into memory, obtaining multiple encrypted data streams. Subsequently, the user-space multiplexing engine of the sending device encapsulates these ciphertext payloads, which have already been encrypted by the hardware encryption device, with the corresponding stream identifier and pushes them into the encrypted tunnel for transmission.
[0063] Through this mechanism, the energy-intensive end-to-end encryption operation is offloaded from the main CPU to a dedicated hardware encryption device. The CPU is only responsible for packet flow marking, queue management, and data transfer, allowing the sending device to handle more network connections and business logic simultaneously. Furthermore, hardware encryption is faster than software encryption, and the asynchronous non-blocking mechanism avoids task queuing, significantly reducing overall end-to-end transmission latency.
[0064] After describing the processing flow of the transmitting device, in order to form a complete technical loop, the data processing method of the receiving device will be explained below.
[0065] Please see Figure 3 , Figure 3 This is a flowchart illustrating a data transmission method applied to a receiving device according to an embodiment of this disclosure. The method can be derived from the above... Figure 1 The receiving device 121 in the middle performs the operation. For example... Figure 3 As shown, the method may include the following steps S301 to S304.
[0066] In step S301, an encrypted tunnel based on the standard transport layer encryption protocol is established between the target port opened by the security blocking device and the sending device.
[0067] The receiving device is configured as a server and listens on the target port mapped and assigned by the security blocking device, such as TCP 443. When it receives a handshake packet from the sending device, the receiving device completes the handshake using the corresponding standard transport layer encryption protocol, establishing an encrypted tunnel. This process corresponds to step S201 and will not be described in detail here.
[0068] In step S302, multiple standard application layer protocol frames sent by the sending device are received through an encrypted tunnel. Each standard application layer protocol frame carries the flow identifier corresponding to its data stream.
[0069] After the tunnel is established, the receiving device begins reading the byte stream from the encrypted tunnel. Because the sending device uses a frame-level interleaving transmission mechanism, the data read by the receiving device is a frame stream composed of standard application layer protocol frames from multiple different intranet IP sessions. The receiving device's protocol parsing module accurately segments each independent standard application layer protocol frame from the continuous data stream according to the frame structure definition of the standard application layer protocol (such as reading a fixed-length frame header), and extracts the stream identifier recorded in the frame header.
[0070] In step S303, standard application layer protocol frames with the same stream identifier are reassembled to obtain multiple data streams.
[0071] The receiving device maintains a context mapping table of active data streams in memory. After parsing the stream identifier of a frame, the receiving device pushes the corresponding standard application layer protocol frame into the stream's dedicated receive buffer based on that identifier. In this way, the various data fragments that were originally interleaved and mixed within the encrypted tunnel are logically reassembled. When a frame is marked as the end of the data stream, such as the HTTP / 2 END_STREAM flag, or when the complete original IP packet payload is reconstructed, the receiving device restores the complete content information, obtaining the original multi-stream data that is completely consistent with the source isolated network segment.
[0072] In step S304, the multiple data streams are forwarded to the corresponding destination devices within the destination isolation network segment.
[0073] After reconstructing the multiple data streams, the receiving device performs reverse injection according to their transmission mechanisms. If the traffic is transmitted via a direct network layer routing mechanism, the receiving device injects the reconstructed original IP packets directly into the kernel routing stack of the destination isolated network segment through its internal virtual network interface card, and then delivers them to the destination device. If the traffic is transmitted via a transport layer service mapping mechanism, the receiving device acts as a proxy client, initiating a connection to the real service address within the destination isolated network segment, such as port 3306 of 192.168.10.5, and transparently forwards the unpacked application layer business data.
[0074] Corresponding to the sending device, in order to overcome the performance limit of a single node decrypting a large number of data streams, in a highly optimized embodiment, the receiving device also employs hardware decryption acceleration. Specifically, before step S303, the data transmission method further includes: submitting encrypted standard application layer protocol frames to a local hardware decryption device for concurrent decryption operations through an asynchronous non-blocking mechanism; obtaining plaintext data returned by the hardware decryption device; and correspondingly, reassembling standard application layer protocol frames with the same stream identifier to obtain multiple data streams, including: reassembling plaintext data with the same stream identifier to obtain multiple data streams.
[0075] The hardware decryption device at the receiving end works similarly to the hardware encryption device at the sending end. After receiving consecutive encrypted application layer protocol frames from the encrypted tunnel, the receiving end device first deconstructs the protocol frames, extracts the ciphertext payload blocks, attaches a context descriptor to the ciphertext payload blocks, and pushes them in batches via the bus to the local hardware decryption device for decryption and verification. After hardware decryption is complete, the CPU retrieves the plaintext data from memory and then reassembles the plaintext data based on the stream identifier to restore the original data stream. This hardware decryption acceleration reduces CPU load fluctuations at the receiving end due to protocol parsing and decryption operations.
[0076] This disclosed embodiment can operate with only one or a very small number of open ports, disguising the underlying transmission as compliant TLS and HTTPS business traffic without exposing VPN characteristics. This allows the DPI engine of the security blocking device to judge it as normal web browsing or API calls and allow it to pass, resulting in an extremely high penetration success rate. At the same time, it solves the contradiction between limited ports and multiple internal network IP session connections through multiplexing technology. Furthermore, it combines hardware encryption and decryption technology to solve the CPU computing power limitation problem caused by software encryption and decryption.
[0077] Figure 4 This disclosure presents a structural block diagram of a data transmission apparatus applied to a transmitting device, such as... Figure 4As shown, it includes: a tunnel establishment section 401, an acquisition section 402, an encapsulation section 403, and a transmission section 404; the tunnel establishment section 401 is configured to establish an encrypted tunnel based on a standard transport layer encryption protocol with the receiving device through the target port opened by the security blocking device, and the number of encrypted tunnels is consistent with the number of target ports; the acquisition section 402 is configured to acquire multiple data streams to be sent to the destination isolated network segment within the source isolated network segment, and assign a flow identifier to each data stream; the encapsulation section 403 is configured to encapsulate each data stream into at least one standard application layer protocol frame, and each standard application layer protocol frame carries the flow identifier corresponding to its data stream; the transmission section 404 is configured to interleave standard application layer protocol frames belonging to different data streams to the receiving device through the same encrypted tunnel.
[0078] In some embodiments, the tunnel establishment section 401 is configured to send a handshake packet to the receiving device that conforms to a standard transport layer encryption protocol and has padding data of random length added; when the receiving device returns a handshake packet, an encrypted tunnel is established.
[0079] In some embodiments, the encapsulation portion 403 is configured to encapsulate a standard application layer protocol frame into a data transmission unit conforming to a standard transport layer encryption protocol, wherein random length padding data is added to the data transmission unit; the transmission portion 404 is configured to interleave the data transmission unit to the receiving device through an encrypted tunnel.
[0080] In some embodiments, the data transmission apparatus further includes: an encryption section configured to submit multiple data streams to a local hardware encryption device for concurrent encryption operations via an asynchronous non-blocking mechanism before encapsulating each data stream into at least one standard application layer protocol frame; an acquisition section 402 configured to acquire multiple encrypted data streams returned by the hardware encryption device; and an encapsulation section 403 configured to encapsulate each encrypted data stream into at least one standard application layer protocol frame.
[0081] In some embodiments, the local routing table of the sending device includes routing information of the destination isolated network segment; the acquisition part 402 is configured to query the local routing table when an original data packet is received from the source isolated network segment; if the destination address of the original data packet matches the routing information of the destination isolated network segment in the local routing table, the original data packet is determined as a data stream to be sent.
[0082] In some embodiments, the sending device is pre-configured with service mapping rules, which include a one-to-one correspondence between the sending device's local port and the service address in the destination isolation network segment; the acquisition part 402 is configured to extract the destination port of the original data packet when it receives the original data packet in the source isolation network segment; if the destination port is the same as the local port in the service mapping rules, the destination address of the original data packet is converted to the corresponding service address in the destination isolation network segment, and the converted original data packet is determined as a data stream to be sent.
[0083] Figure 5 This disclosure presents a structural block diagram of a data transmission apparatus applied to a receiving device, such as... Figure 5 As shown, it includes: a tunnel establishment section 501, a receiving section 502, a data reassembly section 503, and a sending section 504; the tunnel establishment section 501 is configured to establish an encrypted tunnel based on a standard transport layer encryption protocol with the sending device through the target port opened by the security blocking device, and the number of encrypted tunnels is consistent with the number of target ports; the receiving section 502 is configured to receive multiple standard application layer protocol frames sent by the sending device through the encrypted tunnel, each standard application layer protocol frame carrying the flow identifier corresponding to its data stream; the data reassembly section 503 is configured to reassemble standard application layer protocol frames with the same flow identifier to obtain multiple data streams; the sending section 504 is configured to forward the multiple data streams to the corresponding destination devices within the destination isolation network segment.
[0084] In some embodiments, the standard application layer protocol frame is encrypted data, and the data transmission apparatus further includes: a decryption part and an acquisition part; the decryption part is configured to submit the standard application layer protocol frames to a local hardware decryption device for concurrent decryption operations via an asynchronous non-blocking mechanism before reassembling the standard application layer protocol frames with the same stream identifier to obtain multiple data streams; the acquisition part is configured to acquire the plaintext data returned by the hardware decryption device; and the data reassembly part 503 is configured to reassemble the plaintext data with the same stream identifier to obtain multiple data streams.
[0085] It should be noted that in the embodiments of this disclosure, each part can implement the data transmission method for receiving end device and sending end device provided in the above method embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0086] Based on the above data transmission method, this disclosure also provides a data transmission system. (Continue reading...) Figure 1 The data transmission system mainly includes: a private server (e.g., a business host located in the source isolation network segment 110), a security blocking device 130 connected to the private server, and an external server (e.g., a core server located in the destination isolation network segment 120).
[0087] In this data transmission system, the security blocking device 130 is configured to allow data transmission between the external server and the private server only through a limited number of specific target ports, such as TCP port 443, while all other ports and unauthorized underlying protocols are physically blocked.
[0088] In this embodiment, the gateway devices (sender device 111 and receiver device 121) deployed at both ends serve as proxy gateways for the private server and the external server, respectively, or are directly integrated therein. The external server executes the aforementioned actions through its boundary receiver device 121. Figure 3 The data transmission method of the receiving device described in detail in the relevant embodiments; the private server, through the sending device at its boundary, performs the aforementioned... Figure 2 The data transmission method of the sending device is detailed in the relevant embodiments. In this data transmission system, secure, high-concurrency L3 subnet full access or L4 specific service mapping across physical isolation is achieved without changing the configuration of the external physical port of the existing security blocking device 130 or without reducing security audit requirements.
[0089] Corresponding to the above method embodiments, this disclosure also provides an electronic device. Please refer to... Figure 6 , Figure 6 This is a hardware structure block diagram of an electronic device provided in this disclosure. This electronic device can serve as a transmitting or receiving device in the foregoing embodiments. Figure 6 As shown, the electronic device may include at least one processor 601 and a memory 602.
[0090] The processor 601 and the memory 602 communicate with each other via a bus. This bus can be divided into an address bus, a data bus, a control bus, etc., and may also include a PCIe bus that supports high-speed data transmission.
[0091] Processor 601 may be a CPU, an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of this disclosure, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs). In embodiments with hardware encryption assistance, processor 601 is coupled to an additional cryptographic accelerator card chip (hardware encryption / decryption device, not shown) via a PCIe bus.
[0092] The memory 602 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device.
[0093] Memory 602 is used to store executable instructions. When the electronic device is running, processor 601 executes the executable instructions stored in memory 602 to achieve the aforementioned functionality. Figure 2 Implementation examples (applied to transmitting devices) or Figure 3 The various steps in the data transmission method of the embodiment (applied to the receiving device) are described in detail in the above method embodiments. The specific execution process and technical details have been described in detail in the above method embodiments, and will not be repeated here to avoid redundancy.
[0094] Furthermore, embodiments of this disclosure also provide a computer-readable storage medium. This computer-readable storage medium stores a computer program or instructions that, when executed by a processor, implement as described above. Figure 2 or Figure 3 The data transmission method described in the embodiments. Those skilled in the art will understand that all or part of the steps of the methods described above can be implemented by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. This storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0095] This disclosure also provides a computer program product including computer instructions stored in a computer-readable storage medium; a processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform the data transmission method described in the above embodiments.
[0096] This disclosure also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described data transmission method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0097] It should be understood that the chip mentioned in the embodiments of this disclosure may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0098] In the several embodiments provided in this disclosure, it should be understood that the disclosed systems, apparatuses, servers, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.
[0099] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0100] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0101] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure.
[0102] Those skilled in the art will recognize that the functions described in this disclosure in one or more of the examples above can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transfer of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.
[0103] It should be noted that the technical solutions described in this disclosure can be combined arbitrarily as long as they do not conflict.
[0104] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A data transmission method, characterized in that, Applied to a transmitting device, the method includes: By using the target ports opened by the security blocking device, an encrypted tunnel based on the standard transport layer encryption protocol is established with the receiving device, and the number of the encrypted tunnels is the same as the number of the target ports; Acquire multiple data streams within the source isolation network segment to be sent to the destination isolation network segment, and assign a stream identifier to each of the data streams; Each of the data streams is encapsulated into at least one standard application layer protocol frame, and each standard application layer protocol frame carries the stream identifier corresponding to its data stream. The standard application layer protocol frames belonging to different data streams are interleaved and transmitted to the receiving device through the same encrypted tunnel.
2. The data transmission method according to claim 1, characterized in that, The process of establishing an encrypted tunnel with the receiving device based on a standard transport layer encryption protocol via the target port opened by the security blocking device includes: Send a handshake packet to the receiving device that conforms to the standard transport layer encryption protocol and has added padding data of random length; When the handshake packet returned by the receiving device is received, the encrypted tunnel is established.
3. The data transmission method according to claim 1, characterized in that, The step of interleaving standard application layer protocol frames belonging to different data streams through the same encrypted tunnel to the receiving device includes: The standard application layer protocol frame is encapsulated into a data transmission unit conforming to the standard transport layer encryption protocol, and the data transmission unit is padded with padding data of random length. The data transmission unit is transmitted interleaved to the receiving device through the encrypted tunnel.
4. The data transmission method according to claim 1, characterized in that, Before encapsulating each of the data streams into at least one standard application layer protocol frame, the method further includes: The multiple data streams are submitted to the local hardware encryption device for concurrent encryption operations through an asynchronous non-blocking mechanism. Obtain the multi-channel encrypted data returned by the hardware encryption device; The step of encapsulating each of the data streams into at least one standard application layer protocol frame includes: Each encrypted data stream is encapsulated into at least one standard application layer protocol frame.
5. The data transmission method according to claim 1, characterized in that, The local routing table of the sending device includes the routing information of the destination isolated network segment; The acquisition of multiple data streams within the source isolation network segment to be sent to the destination isolation network segment includes: When a raw data packet from the source isolated network segment is received, the local routing table is queried. If the destination address of the original data packet matches the routing information of the destination isolated network segment in the local routing table, then the original data packet is determined as a data stream to be sent.
6. The data transmission method according to claim 1, characterized in that, The sending device is pre-configured with service mapping rules, which include a one-to-one correspondence between the local port of the sending device and the service address in the destination isolated network segment. The acquisition of multiple data streams within the source isolation network segment to be sent to the destination isolation network segment includes: When the original data packet from the source isolated network segment is received, the destination port of the original data packet is extracted; If the destination port is the same as the local port in the service mapping rule, the destination address of the original data packet is converted to the corresponding service address in the destination isolated network segment, and the converted original data packet is determined as a data stream to be sent.
7. A data transmission method, characterized in that, Applied to a receiving device, the method includes: By using the target ports opened by the security blocking device, an encrypted tunnel based on the standard transport layer encryption protocol is established with the sending device, and the number of the encrypted tunnels is the same as the number of the target ports; The encrypted tunnel receives multiple standard application layer protocol frames sent by the sending device, each standard application layer protocol frame carrying the flow identifier corresponding to its data stream; The standard application layer protocol frames with the same stream identifier are reassembled to obtain multiple data streams; The multiple data streams are forwarded to the corresponding destination devices within the destination isolation network segment.
8. The data transmission method according to claim 7, characterized in that, The standard application layer protocol frame is encrypted data. Before reassembling the standard application layer protocol frames with the same stream identifier to obtain multiple data streams, the method further includes: The standard application layer protocol frame is submitted to the local hardware decryption device for concurrent decryption operations through an asynchronous non-blocking mechanism. Obtain the plaintext data returned by the hardware decryption device; The reassembly of standard application layer protocol frames with the same stream identifier to obtain multiple data streams includes: Plaintext data with the same stream identifier are recombined to obtain the multi-stream data.
9. A data transmission system, characterized in that, include: A private server, a security blocking device connected to the private server, and an external server; The security blocking device allows the external server to transmit data with the private server through the target port; The external server is used to execute the data transmission method as described in any one of claims 1 to 6; The private server is used to execute the data transmission method as described in claim 7 or 8.
10. An electronic device, characterized in that, include: A processor and a memory; wherein the memory is used to store executable instructions, and when the processor executes the executable instructions, it implements the data transmission method as described in any one of claims 1 to 6, or implements the data transmission method as described in claim 7 or 8.