Summary of the invention
In view of this, the main purpose of the embodiment of the present invention is to provide a kind of double net emerging systems and transmission side data
Method, to realize the purpose for improving internet security.
To achieve the above object, the embodiment of the invention provides a kind of double net emerging systems, the system comprises at least one
A network access equipment, is located in first network at least one client that network connection is realized with the network access equipment
At least one first server, at least one second server in the second network and data switching center;It is described
First network is point-to-point type network, and second network is broadcast type network, and the first server, which has, stores described the
The resources bank of Internet resources in one network, the second server have the resource for storing Internet resources in second network
Library;
The second server, for pushing the number in second network to the network access equipment with broadcast mode
According to so that the client obtains data from the network access equipment;
The client, for passing sequentially through the network access equipment, the first network and the data exchange
Center sends data to the second server.
Optionally, the client is also used to make the network access equipment and the client by physics mode
It, will be to second clothes after user is carried out authentication and passed through by the network access equipment in the case where secure and trusted
The data that business device is sent are sent to the network access equipment;
The network access equipment, the data sent for receiving the client, and will through the second network uplink channel
The data received are sent to the second server.
Optionally, the network access equipment is also used to work as the data in second server described in the client request
When, the data of the client request are extracted from the data that second server push comes, and the data of extraction are sent out
It send to the client;
Alternatively,
The network access equipment when data being also used in the second server described in the client request, passes through
The first network is to the second server request data;After receiving the request that the second server responds the client
By the first network or the data returned by the second network downstream channel, and received data are sent to the visitor
Family end;
Alternatively, the network access equipment, when the data being also used in the second server described in the client request,
By the second network uplink channel to the second server request data;It receives the second server and responds the client
Request after the data that are returned by the second network downstream channel, and received data are sent to the client.
Optionally, the client is also used to send data to the first network through the network access equipment;
The client is also used to obtain data from the first network through the network access equipment.
Optionally, the broadcast mode is satellite broadcasting or terrestrial broadcasting or optical fibre broadcast.
Optionally, the second server is specifically used for pushing described second to the network access equipment by satellite
Data in network;
Alternatively, the second server, pushes specifically for passing sequentially through satellite and base station to the network access equipment
Data in second network;
Alternatively, the second server, sets specifically for passing sequentially through satellite and hovering aircraft to the network insertion
The standby data pushed in second network;
Alternatively, the second server, it is specifically used for pushing described the to the network access equipment by quantum network
Data in two networks.
Optionally, the data switching center, for the data for flowing to second network from the first network or
The data for flowing to the first network from second network carry out safe handling.
The embodiment of the invention also provides a kind of data transmission method, the method is applied to a kind of double net emerging systems,
At least one client of network connection is realized the system comprises at least one network access equipment, with the network access equipment
End, at least one first server in first network, at least one second server in the second network and
Data switching center;The first network is point-to-point type network, and second network is broadcast type network, the first service
Device has the resources bank for storing Internet resources in the first network, and the second server, which has, to be stored in second network
The resources bank of Internet resources;The described method includes:
The second server pushes the data in second network to the network access equipment with broadcast mode, with
Toilet states client and obtains data from the network access equipment;
The client passes sequentially through the network access equipment, the first network and the data switching center
Data are sent to the second server.
Optionally, the method also includes:
In the case where making the network access equipment and the believable situation of the client secure by physics mode, by the net
After network access device carries out authentication and pass through to user, the client sends out the data sent to the second server
It send to the network access equipment;
The network access equipment receives the data that the client is sent, and will receive through the second network uplink channel
Data be sent to the second server.
Optionally, the method also includes:
When data in the second server described in the client request, the network access equipment is from second clothes
The data of the client request are extracted in the data that business device push comes, and the data of extraction are sent to the client;
Alternatively,
When data in the second server described in the client request, the network access equipment passes through described first
Network is to the second server request data;The second server is received to respond after the request of the client by described
First network or the data returned by the second network downstream channel, and received data are sent to the client;
Alternatively, when data in the second server described in the client request, the network access equipment passes through the
Two network uplink channels are to the second server request data;Receive the request that the second server responds the client
The data returned afterwards by the second network downstream channel, and received data are sent to the client.
Optionally, the method also includes:
The client sends data to the first network through the network access equipment;
The client obtains data from the first network through the network access equipment.
Optionally, the broadcast mode is satellite broadcasting or terrestrial broadcasting or optical fibre broadcast.
Optionally, the second server is pushed in second network with broadcast mode to the network access equipment
Data, comprising:
The second server pushes the data in second network by satellite to the network access equipment;
Alternatively, the second server, which passes sequentially through satellite and base station, pushes second net to the network access equipment
Data in network;
Alternatively, the second server passes sequentially through satellite and hovering aircraft to described in network access equipment push
Data in second network;
Alternatively, the second server is pushed in second network by quantum network to the network access equipment
Data.
Optionally, the method also includes:
The data switching center is to the data for flowing to second network from the first network or from second net
The data that network flows to the first network carry out safe handling.
Double net emerging systems and data transmission method provided in an embodiment of the present invention are by second in the second network
Server with the forms of broadcasting to network access equipment propelling data, due to second server to network access equipment transmission data only
A jump is needed, network access equipment also only needs a jump to client transmission data, is also likely to be present one between second server
The data of jump are transmitted, so the three low jump networks for jumping left and right can be achieved by broadcast in the second network, this low jump network this one
Determine to reduce a possibility that network is by attack in degree, improves the safety of network.
Specific embodiment
In order to make the object, technical scheme and advantages of the embodiment of the invention clearer, below in conjunction with the embodiment of the present invention
In attached drawing, technical scheme in the embodiment of the invention is clearly and completely described, it is clear that described embodiment is
A part of the embodiment of the present invention, instead of all the embodiments.Based on the embodiments of the present invention, those of ordinary skill in the art
Every other embodiment obtained without making creative work, shall fall within the protection scope of the present invention.
The embodiment of the invention provides a kind of double net emerging systems, which includes point-to-point type network and wide
Formula network is broadcast, the point-to-point type network can be the TCP/IP network of address driving, and the broadcast type network can be content
U-CDN (Ubiquitous Content Driven Nenwork, pervasive content driven network) network of driving.The present invention is real
Example is applied by combining the TCP/IP structure of address driving and the U-CDN structure of content driven, forms " double structure " new network frame
Structure, on the basis of not changing original internet TCP/IP, pass through content construction drive network U-CDN and make U-CDN with it is original
Address driving TCP/IP network is worked in coordination work, both can use the popularization, resourceful of existing internet architecture
The advantage of aspect, also may be implemented the safety control of Web content that is public, controlling altogether, is formed and interconnects, is safely controllable new
Type network.
It is one of the composition schematic diagram of double net emerging systems provided in an embodiment of the present invention referring to Fig. 1, double net fusions
System includes at least one network access equipment 200, realizes at least one visitor being connected to the network with the network access equipment 200
Family end 100, at least one first server 300 in first network take positioned at least one of second network second
Be engaged in device 400 and data switching center 500.Wherein, the first network is point-to-point type network, and second network is wide
Formula network is broadcast, the first server 300 has the resources bank for storing Internet resources in the first network, the second service
Device 400 has the resources bank for storing Internet resources in second network.
In embodiments of the present invention, the network access equipment 200 provides user the nets such as unified Wifi, LAN
Network access service, the access service that user client can be provided by the network access equipment 200 access network.
In embodiments of the present invention, the first network can be the TCP/IP network of address driving, i.e. conventional the Internet,
It is the main structure of double net emerging systems, the first network is routing multihop network, and specific network implementations can be with
It selects as the case may be, the present invention is not specifically limited herein.Second network can be U-CDN network, the master of U-CDN
Dry network is a broadcasting network, is the secondary structure of double net emerging systems.
The first network and second network can be, but not limited to be TCP/IP network and U-CDN network, can be with
It is other types of point-to-point type network and broadcast type network.Two kinds of networks interdepend, but mutually indepedent, a kind of network mistake
Effect, another network can be with isolated operation, two kinds of group of networks mixing U-CDN structures in pairs driven in network, in conjunction with two kinds of networks
Unique advantage joint offer service, can also for certain U-CDN can meet demand specific application, can be by pure U-CDN
Network structure provides service.
The two of the composition schematic diagram of double net emerging systems shown in Figure 2.
Assuming that the first network is TCP/IP network, there is an address driving network resources system in TCP/IP network,
It is the resources bank constructed in conventional the Internet that the address, which drives network resources system, the Internet resources source multiplicity in resources bank,
Its content is safe believable or dangerous incredible.Address drives network resources system can be by multiple Distributed Autonomous
Word bank composition can in each first server 300 there may be one or more first servers 300 in TCP/IP network
To be used to store the word bank of TCP/IP Internet resources with one of them.
Assuming that second network be U-CDN network, be credible and secure network, specifically can by specially releasing news,
The network of the contents such as government affairs information, public service information, there are a content driven network resources system in U-CDN network, this is interior
Holding driving network resources system is the resources bank constructed in credible and secure network, and the Internet resources in resources bank are safety and can
Letter.Content driven network resources system can be made of the word bank of multiple Distributed Autonomous, in U-CDN network there may be one or
Multiple second servers 400 can have one of them in each second server 400 for storing U-CDN Internet resources
Word bank.
Based on above-mentioned dual network framework, lower mask body introduction is based on the data transfer mode under the network architecture:
1, the downlink data that the second network is sent
The second server 400, for pushing second network to the network access equipment 200 with broadcast mode
In data, so that the client 100 obtains data from the network access equipment 200, wherein the broadcast mode is
Satellite broadcasting or terrestrial broadcasting or optical fibre broadcast.
For all the elements in the second network (such as U-CDN network), it is stored in each second server 400
In resources bank, second server 400 is understood by these Web content broadcast distributions in resources bank into network access equipment 200,
It is i.e. that the Web content difference in the second network is labelled, and by the abstract of each label and corresponding network content and right
The Web content answered is pushed to network access equipment 200 in the form broadcasted, and 400 jumps of need 1 of second server can be by content
It is pushed to network access equipment 200.Second network is low jump network, and satellite, similar radiated television can be used or have
The modes such as the terrestrial broadcasting of line television network or optical fibre broadcast based on light splitting, directly distribute data with broadcast mode, exist in this way
All users in the broadcast coverages such as satellite can directly obtain from the local i.e. network access equipment 200 (can be simultaneously
Row obtains) Web content in second network, avoid the channel competition that traditional network can not be avoided.In addition, U-CDN net
The trunk of network is an autonomous controllable hub-and-spoke configuration, and default only has down going channel to pass through central nodule without direct data feedback channel
Point control, neither influence performance, and arbitrarily network attack path can be blocked well.
For the data communication mode of U-CDN network, data downstream uses broadcast transmission methods, second server 400
When with broadcast mode to 200 propelling data of network access equipment, satellite or satellite-base station or satellite-specifically can be used
The traffic channels data such as hovering aircraft, even quantum network, data pass through above-mentioned communication channel by second server 400
It is broadcast to receiving end i.e. network access equipment 200, by once broadcasting, so that the users from networks access under full broadcast area is set
Standby middle Parallel download data, will not generate channel congestion.As it can be seen that the second server, it is specifically used for through satellite to described
Network access equipment pushes the data in second network;Alternatively, the second server, specifically for passing sequentially through satellite
The data in second network are pushed to the network access equipment with base station;Alternatively, the second server, is specifically used for
It passes sequentially through satellite and hovering aircraft and pushes data in second network to the network access equipment;Alternatively, described
Second server, specifically for pushing the data in second network to the network access equipment by quantum network.
2, user passes through the upstream data that client is sent to the second network
For the upstream data that client is sent to the second network, indirect free uplink transmission mode and directly can be divided into
Connect uplink transmission mode.
(1), indirect free uplink
The indirect free uplink needs client 100 by first network (traditional address network) by data exchange
The heart 500 is by data feedback to the second network (U-CDN network), and the data transfer path is at low cost, but real-time is weaker.That is, institute
Client 100 is stated, for passing sequentially through the network access equipment 200, the first network and the data switching center
500 send data to the second server 400, wherein the number that the client 100 is sent to the second server 400
According to the data that can be data acquisition request or be written to the second server 400.
(2), direct uplink
The direct uplink then passes through broadcasting link (such as satellite uplink) and data is directly uploaded to second server
Resources bank in, the path cost is high, can guarantee certain real-time, but has security risk, so the second network (U-CDN net
Network) default and does not open the data feedback channel to general user, unless extremely credible and safe user and environment.So working as user
When uploading data to the second network, needs to carry out necessary authentication to user by network access equipment 200, specifically can be used
Based on physiological signals such as fingerprint, pupil, faces, or the characteristic fingerprint for including using chip interior physics micro-structure, or using eventually
The authentication techniques for holding the information such as network behavior feature carry out authentication using user to client, to guarantee that terminal accesses
The safety of network and credible row.That is, the client 100, is also used to make the network access equipment by physics mode
200 with the client 100 it is secure and trusted in the case where (for example set client 100 and network insertion in the way of circuit etc.
Standby 200 use environment is secure and trusted), it, will be to after user is carried out authentication and passed through by the network access equipment 200
The data that the second server 400 is sent are sent to the network access equipment 200;The network access equipment 200, is used for
Receive the data that the client 100 is sent, and (for example network access equipment 200 takes with second through the second network uplink channel
The dedicated uplink of point-to-point type between business device 400) data received are sent to the second server 400,
In, the client 100 to the data that the second server 400 is sent can be data acquisition request or to described second
The data that server 400 is written.
3, user passes through the upstream data that client is sent to first network
The client 100, be also used to through the network access equipment 200 to the first network (i.e. it is described first clothes
Business device 300) send data.Wherein, the client 100 can be data acquisition request to the data that the first network is sent
Or the data being written to the first network, when the client 100 through the network access equipment 200 to first net
When the data that network is sent are write-in data, it can write data into corresponding first server 300, when the client 100
Through the network access equipment 200 to the data that the first network is sent be data acquisition request when, ask parameter following 4.
4, the downlink data that first network is sent
The client 100 is also used to obtain data from the first network through the network access equipment 200.When
The client 100 through the network access equipment 200 to the data that the first network is sent be data acquisition request when, institute
The first server 300 for being used to store requested data in first network is stated, requested data can be connect by the network
Enter equipment 200 and is issued to the client 100.
In embodiments of the present invention, it when user requests the data in second network, can be used according to specific strategy
One of three kinds of modes below:
1, second server can be saved in network access equipment 200 and pushes the data to come, when user passes through network insertion
When equipment 200 requests the data in the second network, network access equipment 200 can extract user's request from the data of storage
Data, and by the data distributing of extraction to client 100.That is, the network access equipment 200, is also used to when the client
When data in the 100 request second servers 400, institute is extracted from the data that the second server 400 push comes
The data that client 100 is requested are stated, and the data of extraction are sent to the client 100.
2, user's request can be sent to the by the data transfer mode of above-mentioned indirect free uplink by client 100
(transmission path is followed successively by the node device in client 100- network access equipment 200- first network such as to two servers 400
First server 300- data switching center 500- second server 400), second server 400 is to 100 returned data of client
When, the data that user requests can be returned to client by the data transfer mode of indirect free downlink by second server 400
End 100, i.e., by first network, to 100 returned data of client, (transmission path is followed successively by second server 400- data exchange
Node device such as first server 300- network access equipment 200- client 100 in the 500- first network of center);When
So, second server 400 can also pass through the direct down going channel of the second network (such as network access equipment 200 and the second clothes
The exclusive downlink or broadcast channel of point-to-point type between business device 400), to 100 returned data of client.That is, the net
Network access device 200 is also used to when the client 100 requests the data in the second server 400, passes through described
One network is to 400 request data of second server;It receives the second server 400 and responds asking for the client 100
By the first network or the data returned by the second network downstream channel after asking, and received data are sent to institute
State client 100.
3, user's request can be sent directly to the by the data transfer mode of above-mentioned direct uplink by client 100
Two servers 400 (transmission path is followed successively by client 100- network access equipment 200- second server 400), second server
400 to 100 returned data of client when, second server 400 can be asked user by the data transfer mode of direct downlink
The data asked return to client 100, i.e., directly to 100 returned data of client, (transmission path is followed successively by second server
400- network access equipment 200- client 100).That is, the network access equipment 200, is also used to ask when the client 100
When seeking the data in the second server 400, pass through dedicated uplink (such as network access equipment 200 and second service
Broadcasting link between device 400) 400 request data of Xiang Suoshu second server;Receive the second server 400 respond it is described
After the request of client 100 by the second network downstream channel (such as between network access equipment 200 and second server 400
Point-to-point type exclusive downlink or broadcast channel) data that return, and received data are sent to the client
100。
In summary, content timing in its resources bank can be broadcast to network access equipment 200 by second server 400, be used
Family can directly obtain the content of the second network from network access equipment 200, if the content for the second network that user wants does not exist
In network access equipment 200, the interior of first network (address driving network) the second network of activly request (U-CDN network) can be passed through
Hold, then sends the content by the broadcasting network of the second network (U-CDN network) or traditional address network and set to network insertion
Standby 200, and it is ultimately passed to user client 100.
In addition, by second server 400 to the data transmission procedure of network access equipment 200, it can the interconnection of the world Bu Shou
The control of net rhizosphere name system DNS (Domain Name System, domain name system), can be with independent operating and management, can be certainly
Define the library structure and control strategy in second server 400.
In embodiments of the present invention, the data switching center 500 is that double drive Web content merges and interact generation
Place, double net information exchanges based on big data are the key mechanisms for solving content exchange between double net information banks.Based on this, by
First network flows to the data of the second network (flowing to U-CDN network from TCP/IP network), need by screening, discarding the dross and selecting the essential,
It eliminates the false and retains the true, increase the treatment processes such as profession and authoritative information;Conversely, flowing to first network (from U-CDN network by the second network
Flow to TCP/IP network) data, then can carry out such as necessary safe handling of secret protection, Information hiding.As it can be seen that described
Data switching center 500, for the data for flowing to second network from the first network or from second network flow
Safe handling is carried out to the data of the first network.
In embodiments of the present invention, the network access equipment 200 is as cable television or telephone terminal
Real-name authentication equipment carries out real-name authentication to the client of access 100.The network access equipment 200 also has domain name solution
Analysis (such as to user request in domain name parse), content storage exchange (store the second network push data and
Upload or issue data etc.), unified content label (Uniform Content Label, UCL) screening is (such as according to user couple
The request of second network data filtered out from the data of storage user request data), individual function customization (such as according to
The interest of family setting, which services, for user provides content of interest) etc. abilities, meanwhile, the network access equipment 200 also supports height
The resource management and task schedule of performance.Content service for any one user can connect there are two types of network structure in network
Enter and selected automatically in equipment 200, one is the second network (U-CDN networks), another is first network (traditional address
Drive network).
Double net emerging systems provided in an embodiment of the present invention are the second servers by being located in the second network to broadcast shape
Formula is to network access equipment propelling data, since second server only needs a jump, network to network access equipment transmission data
Access device also only needs a jump to client transmission data, and the data transmission of a jump is also likely to be present between second server,
So the second network by broadcast can be achieved three jump left and right low jump networks, this low jump network this reduce to a certain extent
A possibility that network is by attack, improves the safety of network.
The embodiment of the present invention also provides a kind of data transmission method, and the method is applied to above-mentioned double net emerging systems, institute
The system of stating includes at least one network access equipment, at least one client with network access equipment realization network connection
End, at least one first server in first network, at least one second server in the second network and
Data switching center;The first network is point-to-point type network, and second network is broadcast type network, the first service
Device has the resources bank for storing Internet resources in the first network, and the second server, which has, to be stored in second network
The resources bank of Internet resources.
One of the flow diagram of data transmission method also provided referring to Fig. 3 embodiment of the present invention, comprising:
Step 301: the second server is pushed in second network with broadcast mode to the network access equipment
Data, so that the client obtains data from the network access equipment.
The two of the flow diagram for the data transmission method that the embodiment of the present invention also provides referring to fig. 4, comprising:
Step 401: the client passes sequentially through the network access equipment, the first network and the data
Switching centre sends data to the second server.
In embodiments of the present invention, the method also includes:
In the case where making the network access equipment and the believable situation of the client secure by physics mode, by the net
After network access device carries out authentication and pass through to user, the client sends out the data sent to the second server
It send to the network access equipment;
The network access equipment receives the data that the client is sent, and will receive through the second network uplink channel
Data be sent to the second server.
In embodiments of the present invention, the method also includes:
When data in the second server described in the client request, the network access equipment is from second clothes
The data of the client request are extracted in the data that business device push comes, and the data of extraction are sent to the client;
Alternatively,
When data in the second server described in the client request, the network access equipment passes through described first
Network is to the second server request data;The second server is received to respond after the request of the client by described
First network or the data returned by the second network downstream channel, and received data are sent to the client;
When data in the second server described in the client request, the network access equipment passes through the second network
Data feedback channel is to the second server request data;It receives after the second server responds the request of the client and passes through
The data that second network downstream channel returns, and received data are sent to the client.
In embodiments of the present invention, the method also includes:
The client sends data to the first network through the network access equipment;
The client obtains data from the first network through the network access equipment.
In embodiments of the present invention, the broadcast mode is satellite broadcasting or terrestrial broadcasting or optical fibre broadcast.
In embodiments of the present invention, the second server is with broadcast mode to network access equipment push described the
Data in two networks, comprising:
The second server pushes the data in second network by satellite to the network access equipment;
Alternatively, the second server, which passes sequentially through satellite and base station, pushes second net to the network access equipment
Data in network;
Alternatively, the second server passes sequentially through satellite and hovering aircraft to described in network access equipment push
Data in second network;
Alternatively, the second server is pushed in second network by quantum network to the network access equipment
Data.
In embodiments of the present invention, the method also includes:
The data switching center is to the data for flowing to second network from the first network or from second net
The data that network flows to the first network carry out safe handling.
As seen through the above description of the embodiments, those skilled in the art can be understood that above-mentioned implementation
All or part of the steps in example method can be realized by means of software and necessary general hardware platform.Based on such
Understand, substantially the part that contributes to existing technology can be in the form of software products in other words for technical solution of the present invention
It embodies, which can store in storage medium, such as ROM/RAM, magnetic disk, CD, including several
Instruction is used so that a computer equipment (can be the network communications such as personal computer, server, or Media Gateway
Equipment, etc.) execute method described in certain parts of each embodiment of the present invention or embodiment.
It should be noted that for the method disclosed in the embodiment, since it is corresponding with system disclosed in embodiment,
So being described relatively simple, related place illustrates referring to components of system as directed.
It should also be noted that, herein, relational terms such as first and second and the like are used merely to one
Entity or operation are distinguished with another entity or operation, without necessarily requiring or implying between these entities or operation
There are any actual relationship or orders.Moreover, the terms "include", "comprise" or its any other variant are intended to contain
Lid non-exclusive inclusion, so that the process, method, article or equipment including a series of elements is not only wanted including those
Element, but also including other elements that are not explicitly listed, or further include for this process, method, article or equipment
Intrinsic element.In the absence of more restrictions, the element limited by sentence "including a ...", it is not excluded that
There is also other identical elements in process, method, article or equipment including the element.
The foregoing description of the disclosed embodiments enables those skilled in the art to implement or use the present invention.
Various modifications to these embodiments will be readily apparent to those skilled in the art, as defined herein
General Principle can be realized in other embodiments without departing from the spirit or scope of the present invention.Therefore, of the invention
It is not intended to be limited to the embodiments shown herein, and is to fit to and the principles and novel features disclosed herein phase one
The widest scope of cause.