WO2025020437A1 - 数据传输方法、装置、计算机设备、存储介质和程序产品 - Google Patents

数据传输方法、装置、计算机设备、存储介质和程序产品 Download PDF

Info

Publication number
WO2025020437A1
WO2025020437A1 PCT/CN2023/140207 CN2023140207W WO2025020437A1 WO 2025020437 A1 WO2025020437 A1 WO 2025020437A1 CN 2023140207 W CN2023140207 W CN 2023140207W WO 2025020437 A1 WO2025020437 A1 WO 2025020437A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
verification
zero
user
data packet
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2023/140207
Other languages
English (en)
French (fr)
Inventor
陈文华
陈鸿杰
王爱宝
蒋春元
李澄宇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Telecom Corp Ltd
Original Assignee
China Telecom Corp Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Telecom Corp Ltd filed Critical China Telecom Corp Ltd
Publication of WO2025020437A1 publication Critical patent/WO2025020437A1/zh
Anticipated expiration legal-status Critical
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/126Applying verification of the received information the source of the received data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02DCLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D30/00Reducing energy consumption in communication networks
    • Y02D30/50Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate

Definitions

  • the present application relates to the field of information security technology, and in particular to a data transmission method, apparatus, computer equipment, storage medium and program product.
  • Zero-trust networks refer to networks where there is no trust between users and data is transmitted anonymously.
  • TCP/IP protocol Transmission Control Protocol/Internet Protocol
  • the present application provides a data transmission method. Applied to a zero-trust gateway in a zero-trust communication network, the method comprises:
  • the verification data includes user session information and user signature information
  • the user session information is used to indicate the address information and session count information generated during the process of establishing a session connection with the zero-trust proxy node
  • the user signature information is used to indicate the identity parameters of the user who sent the initial data packet
  • the data verification rules include user session information verification rules and data signature verification rules; the verification data in the data packet to be transmitted is verified according to the data verification rules to obtain a data verification result, including:
  • the data verification result is generated according to the first data verification result and the second data verification result.
  • performing data verification on the user session information in the data packet to be transmitted according to the user session information verification rule to generate a first data verification result includes:
  • the network address type includes a public network address type and a private network address type
  • the network address type of the data packet to be transmitted determining whether it is necessary to update the source network address in the data packet to be transmitted, and generating an intermediate data packet
  • the session count information in the intermediate data packet is verified according to the user session information verification rule to generate the first data verification result.
  • determining whether it is necessary to update the source network address in the data packet to be transmitted according to the network address type of the data packet to be transmitted and generating the intermediate data packet includes:
  • the network address type of the data packet to be transmitted is the private network address type
  • the data packet to be transmitted is used as the intermediate data packet
  • the source network address in the data packet to be transmitted is updated to the public network address corresponding to the data packet to be transmitted, so as to generate the intermediate data packet.
  • performing data verification on the user signature information in the data packet to be transmitted according to the data signature verification rule to generate a second data verification result includes:
  • the user signature information in the intermediate data packet is verified according to the data signature verification rule to generate the second data verification result.
  • the method further comprises:
  • the abnormal session information is sent to the zero trust controller; the abnormal session information is used to instruct the zero trust controller to analyze the abnormal session information and send a session termination instruction to the zero trust agent node.
  • the data verification rule is generated based on user standard signature information and user standard session information, wherein the user standard signature information includes user public key information and user identity standard information.
  • the user standard signature information is obtained from the user certificate when the user certificate is verified.
  • the present application further provides a data transmission method. Applied to a zero-trust controller in a zero-trust communication network, the method comprises:
  • the data verification rule is sent to the zero trust gateway; the data verification rule is used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rule to obtain a data verification result; and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • generating the data verification rule according to the user certificate and the user standard session information includes:
  • the certificate verification result is that the certificate verification is passed, obtaining user standard signature information from the user certificate, wherein the user standard signature information includes user public key information and user standard identity information;
  • the data verification rule is generated according to the user standard signature information and the user standard session information.
  • the present application also provides a data transmission method. Applied in a zero-trust proxy node in a zero-trust communication network, the method comprises:
  • the zero trust controller when the user certificate is verified, obtains the user standard signature information from the user certificate and generates data verification rules based on the standard signature information and the user standard session information, wherein the user standard signature information includes user public key information and user identity standard information.
  • the present application further provides a data transmission device. Applicable to a zero-trust gateway in a zero-trust communication network, the device comprising:
  • a module for receiving data packets to be transmitted used to receive data verification rules sent by a zero-trust controller and data packets to be transmitted sent by a zero-trust agent node; the data packets to be transmitted are obtained by adding verification data to the initial data packets by the zero-trust agent node;
  • a data verification module used to perform data verification on the verification data in the data packet to be transmitted according to the data verification rule to obtain a data verification result
  • the data transmission module is used to determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the present application further provides a data transmission device. Applicable to a zero-trust controller in a zero-trust communication network, the device comprising:
  • An information receiving module used to receive a user certificate and user standard session information sent by a zero-trust agent node
  • a data verification rule generation module used to generate data verification rules according to the user certificate and user standard session information
  • a data verification rule sending module is used to send the data verification rule to the zero trust gateway; the data verification rule is used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rule to obtain a data verification result; and determine whether to transmit the data packet to be transmitted to the database based on the data verification result.
  • the present application further provides a data transmission device. Applicable to a zero-trust proxy node in a zero-trust communication network, the device comprising:
  • An information acquisition module used to obtain user certificates, user standard session information and initial data packets
  • the information sending data verification module is used to send the user certificate and the user standard session information to the zero trust controller so that The zero trust controller generates a data verification rule based on the user certificate and the user standard session information, and sends the data verification rule to the zero trust gateway;
  • the module for generating data packets to be transmitted is used to add verification data to the initial data packet to generate a data packet to be transmitted, and send the data packet to be transmitted to the zero-trust gateway; the data packet to be transmitted is used to instruct the zero-trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rule to obtain a data verification result; and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the present application also provides a zero-trust gateway, including a transceiver, a processor and a memory, the memory stores a computer program, and the processor executes the computer program to perform the steps of the method in any one of the embodiments of the first aspect above.
  • the present application further provides a zero-trust controller, comprising a transceiver, a processor, and a memory, wherein the memory stores a computer program, and the processor executes the computer program to control the transceiver to receive a user certificate and user standard session information sent by a zero-trust agent node;
  • the data verification rules are used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain a data verification result; determine whether to transmit the data packet to be transmitted to the database based on the data verification result.
  • the present application further provides a zero-trust proxy node, comprising a transceiver, a processor, and a memory, wherein the memory stores a computer program, and the processor executes the computer program to control the transceiver to obtain a user certificate, user standard session information, and an initial data packet;
  • the zero trust controller Used to control the transceiver to send the user certificate and the user standard session information to the zero trust controller, so that the zero trust controller generates a data verification rule based on the user certificate and the user standard session information, and sends the data verification rule to the zero trust gateway;
  • the present application further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the method in any one of the embodiments of the first to third aspects above are implemented.
  • the present application further provides a computer program product, wherein the computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the method in any one of the embodiments of the first to third aspects are implemented.
  • the present application also provides a device configured to execute the method steps in any one of the embodiments of the first to third aspects above.
  • FIG1 is an application environment diagram of a data transmission method according to an embodiment
  • FIG2 is a flow chart of a data transmission method corresponding to a zero-trust gateway in one embodiment
  • FIG3 is a schematic diagram of a flow chart of a data verification step in an embodiment
  • FIG4 is a schematic flow chart of a step of generating a first data verification result in one embodiment
  • FIG5 is a schematic flow chart of a step of sending abnormal session information in one embodiment
  • FIG6 is a flow chart of a data transmission method corresponding to a zero-trust controller in another embodiment
  • FIG7 is a flow chart of a data transmission method corresponding to a zero-trust proxy node in another embodiment
  • FIG8 is a schematic diagram of the structure of a data packet to be transmitted in one embodiment
  • FIG9 is a schematic flow chart of a data transmission method corresponding to a zero-trust gateway in an optional embodiment
  • FIG10 is a schematic diagram of the structure of a communication system corresponding to a zero-trust communication network in one embodiment
  • FIG11 is a schematic diagram of a process of performing data verification and data transmission in a zero-trust communication network in one embodiment
  • FIG12 is a structural block diagram of a data transmission device corresponding to a zero-trust gateway in one embodiment
  • FIG13 is a structural block diagram of a data transmission device corresponding to a zero-trust controller in one embodiment
  • FIG14 is a structural block diagram of a data transmission device corresponding to a zero-trust proxy node in one embodiment
  • FIG15 is a schematic diagram of the internal structure of a zero-trust gateway in one embodiment
  • FIG16 is a schematic diagram of the internal structure of a zero-trust controller in another embodiment
  • FIG17 is a schematic diagram of the internal structure of a zero-trust proxy node in yet another embodiment.
  • Zero-trust networks refer to networks where there is no trust between users and data is transmitted anonymously.
  • TCP/IP protocol Transmission Control Protocol/Internet Protocol
  • the communication system 100 corresponding to the zero-trust communication network includes a zero-trust agent node 102, a zero-trust controller 104, a zero-trust gateway 106 and a database.
  • the zero-trust agent node 102 can obtain data from the user terminal, and the zero-trust agent node 102 can send data to the zero-trust gateway 106 through the communication network, and the zero-trust agent node 102 can also send data to the zero-trust controller 104.
  • the communication network includes a public network and a local area network.
  • the zero-trust controller 104 can send data to the zero-trust gateway 106.
  • the zero-trust gateway 106 can transmit data to the database, or the zero-trust gateway 106 can also transmit data to the zero-trust controller 104.
  • the zero trust gateway 106 receives the data verification rules sent by the zero trust controller 104 and the data packet to be transmitted sent by the zero trust agent node 102; the data packet to be transmitted is obtained after the zero trust agent node 102 adds verification data to the initial data packet; the zero trust gateway 106 performs data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain a data verification result; the zero trust gateway 106 determines whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the user terminal may be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, IoT devices and portable wearable devices.
  • the IoT devices may be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc.
  • Portable wearable devices may be smart watches, smart bracelets, head-mounted devices, etc.
  • the zero-trust proxy node 102, the zero-trust controller 104, and the zero-trust gateway 106 may all be implemented using an independent server or a server cluster consisting of multiple servers.
  • a data transmission method is provided, which is described by taking the method applied to the zero trust gateway 106 in the zero trust communication network in FIG. 1 as an example, including the following steps:
  • the zero-trust communication network is the zero-trust network, which refers to a network in which there is no trust between users and data is transmitted anonymously.
  • the communication system corresponding to the zero-trust communication network includes zero-trust agent nodes, zero-trust controllers, zero-trust gateways and databases.
  • Data verification rules are rules generated by zero-trust agent nodes, and data verification rules are used to verify the data in the data packets to be transmitted.
  • the data packets to be transmitted refer to data packets that need to be verified first and can only be transmitted after the data verification passes.
  • the data packets to be transmitted are the data packets obtained after the zero-trust agent node adds verification data to the initial data packets.
  • the initial data packet refers to the data packet obtained from the user terminal.
  • Verification data refers to the data used for data verification in the data packets to be transmitted.
  • the communication system 100 corresponding to the zero-trust communication network includes a zero-trust proxy node 102, a zero-trust controller 104, a zero-trust gateway 106, and a database, and both the zero-trust proxy node 102 and the zero-trust controller 104 can send data to the zero-trust gateway 106.
  • the zero-trust gateway 106 can simultaneously receive the data verification rules sent by the zero-trust controller 104 and the data packet to be transmitted sent by the zero-trust proxy node 102; or, the zero-trust gateway 106 can also first receive the data verification rules sent by the zero-trust controller 104, and then receive the data packet to be transmitted sent by the zero-trust proxy node 102; or, the zero-trust gateway 106 can also first receive the data packet to be transmitted sent by the zero-trust proxy node 102, and then receive the data verification rules sent by the zero-trust controller 104. It should be noted that in the embodiment of the present application, the time sequence of the zero-trust gateway 106 receiving the data verification rules and receiving the data packet to be transmitted is not limited.
  • the zero-trust gateway 106 can perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain a data verification result.
  • the data verification rule includes a verification data threshold
  • the data verification rule is: if the verification data is less than or equal to the verification data threshold, it means that the data verification is passed. Then, the zero-trust gateway 106 can compare the verification data threshold with the verification data in the data packet to be transmitted to generate a data verification result.
  • the data verification rules and the verification data threshold can be set according to the data packet, which is not limited in the embodiment of the present application.
  • the data verification result includes the data verification passed and the data verification result. The data verification failed.
  • S260 Determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the zero-trust gateway 106 may determine whether to transmit the data packet to be transmitted to the database based on the data verification result. For example, if the data verification result is that the data verification passes, the zero-trust gateway 106 may transmit the data packet to be transmitted to the database. If the data verification result is that the data verification fails, the zero-trust gateway 106 may discard the data packet to be transmitted.
  • the data verification rules sent by the zero-trust controller and the data packet to be transmitted sent by the zero-trust proxy node are received; the data packet to be transmitted is obtained after the zero-trust proxy node adds verification data to the initial data packet; the verification data in the data packet to be transmitted is verified according to the data verification rules to obtain the data verification result; and it is determined whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the zero-trust proxy node in the embodiment of the present application can add verification data to the initial data packet to obtain a repackaged data packet to be transmitted.
  • the zero-trust gateway can receive the data verification rules sent by the zero-trust controller and the repackaged data packet to be transmitted sent by the zero-trust proxy node, and perform data verification on the verification data in the repackaged data packet to be transmitted according to the data verification rules to obtain a more accurate data verification result. Furthermore, it can be determined whether to transmit the data packet to be transmitted to the database according to the more accurate data verification result. Since the present application needs to first perform data verification on the verification data in the repackaged data packet to be transmitted according to the data verification rules, and the present application can only transmit the data packet to be transmitted that passes the data verification, the security of the data transmission process can be improved.
  • the verification data includes user session information and user signature information.
  • the user session information is used to indicate the address information and session count information generated during the establishment of a session connection with the zero-trust proxy node.
  • the user signature information is used to indicate the identity parameters of the user who sent the initial data packet.
  • the data verification rules include user session information verification rules and data signature verification rules; as shown in Figure 3, S240 includes:
  • the verification data may include but is not limited to user session information and user signature information.
  • the user session information is used to indicate the address information and session count information generated during the process of establishing a session connection with the zero-trust proxy node.
  • the address information includes information such as the source network address, the destination network address, and the network address of the data packet to be transmitted.
  • the session count information refers to the number of session information.
  • the user signature information is used to indicate the identity parameters of the user who sent the initial data packet.
  • the identity parameters may include but are not limited to the user name, the user's identity authentication identifier, etc.
  • the zero-trust gateway 106 can receive verification data such as address information, session count information, and the user's identity parameters.
  • the data verification rules include user session information verification rules and data signature verification rules.
  • the user session information verification rules refer to the rules for performing data verification on user session information such as address information and session count information
  • the data signature verification rules refer to the rules for performing data verification on user signature information.
  • the zero-trust gateway 106 may perform data verification on the user session information in the data packet to be transmitted according to the user session information verification rule to generate a first data verification result.
  • the user session information verification rule includes a session information threshold
  • the user session information verification rule is: if the user session information is less than or equal to the session information threshold, it means that the session information verification has passed.
  • the zero-trust gateway 106 may compare the session information threshold with the user session information in the data packet to be transmitted, thereby generating a first data verification result.
  • the user session information verification rule and the session information threshold may be set according to the data packet, which is not limited in the embodiment of the present application.
  • the first data verification result includes a passed session information verification and a failed session information verification.
  • the zero-trust gateway 106 can perform data verification on the user signature information in the data packet to be transmitted according to the data signature verification rule to generate a second data verification result.
  • the data signature verification rule includes a data signature threshold
  • the data signature verification rule is: if the user signature information is less than or equal to the data signature threshold, it means that the data signature verification passes.
  • the zero-trust gateway 106 can compare the data signature threshold with the user signature information in the data packet to be transmitted, thereby generating a second data verification result.
  • the data signature verification rule and the data signature threshold can be set according to the data packet, and the embodiment of the present application does not limit this.
  • the second data verification result includes the data signature verification passing and the data signature verification failing.
  • the zero-trust gateway 106 can determine whether the session information verification has passed and whether the data signature verification has passed based on the first data verification result and the second data verification result. If the first data verification result is that the session information verification has passed, and the second data verification result is that the data signature verification has passed, that is, both the session information verification and the data signature verification have passed, then the data verification result is determined to be that the data verification has passed. If the first data verification result is that the session information verification has not passed, and/or the second data verification result is that the data signature verification has not passed, that is, at least one of the session information verification and the data signature verification has not passed, then the data verification result is determined to be that the data verification has not passed.
  • the verification data includes user session information and user signature information
  • the data verification rules include user session information verification rules and data signature verification rules
  • the user session information in the transmission data packet is verified according to the user session information verification rules.
  • a first data verification result can be generated more accurately; and by performing data verification on the user signature information in the data packet to be transmitted according to the data signature verification rule, a second data verification result can be generated more accurately.
  • a more accurate data verification result can be generated based on the more accurate first data verification result and the more accurate second data verification result.
  • S320 includes:
  • the network address type includes a public network address type and a private network address type.
  • the zero-trust gateway 106 can obtain the network address of the data packet to be transmitted from the address information of the data packet to be transmitted, and determine the network address type of the data packet to be transmitted based on the network address of the data packet to be transmitted.
  • the network address type includes a public network address type and a private network address type.
  • a public network address refers to an address that can be directly accessed on the Internet.
  • a private network address refers to an address that can be directly accessed on a private network.
  • a private network is a local area network, which is a regional network formed in a local area, and only computer devices in a specific area can access the private network.
  • the zero-trust gateway 106 can determine that the network address type of the data packet to be transmitted is a private network address type; if the network address of the data packet to be transmitted is a public network address, the zero-trust gateway 106 can determine that the network address type of the data packet to be transmitted is a public network address type.
  • the zero-trust gateway 106 can determine whether the network address of the data packet to be transmitted is a public network address or a private network address based on the network address type of the data packet to be transmitted, thereby determining whether it is necessary to update the source network address in the data packet to be transmitted, and then generate an intermediate data packet.
  • the intermediate data packet is a data packet generated based on the network address type of the data packet to be transmitted.
  • S440 includes:
  • the data packet to be transmitted is used as an intermediate data packet.
  • the source network address in the data packet to be transmitted is updated to the public network address corresponding to the data packet to be transmitted, and an intermediate data packet is generated.
  • the network address type of the data packet to be transmitted is a private network address type, that is, the network address sending the data packet to be transmitted is a private network address, it means that the network address translation (NAT) of the data packet to be transmitted has not been performed.
  • NAT network address translation
  • the source network address in the data packet to be transmitted is the same as the private network address. Therefore, the zero trust gateway 106 can directly use the data packet to be transmitted as an intermediate data packet without updating the data packet to be transmitted.
  • the network address type of the data packet to be transmitted is a public network address type, that is, the network address of the data packet to be transmitted is a public network address, it means that the data packet to be transmitted has been subjected to network address translation (NAT).
  • NAT network address translation
  • the source network address in the data packet to be transmitted is still a private network address, but the real network address of the data packet to be transmitted is a public network address, that is, the source network address in the data packet to be transmitted is different from the real network address (i.e., the public network address). Therefore, the zero-trust gateway 106 can update the source network address in the data packet to be transmitted to the public network address corresponding to the data packet to be transmitted, thereby generating an intermediate data packet.
  • the zero-trust gateway 106 may perform data verification on the session count information in the intermediate data packet according to the user session information verification rule to generate a first data verification result.
  • the user session information verification rule includes a standard session count
  • the user session information verification rule includes: if the session count information in the intermediate data packet is less than or equal to the standard session count, it means that the session information verification is passed. Then, the zero-trust gateway 106 may compare the standard session count with the session count information in the intermediate data packet to generate a first data verification result.
  • the user session information verification rule and the standard session count may be set according to the data packet, and the embodiment of the present application does not limit this.
  • the zero-trust gateway 106 can determine whether redundant session information is received. If redundant session information is received, it indicates that a replay attack has occurred. At this time, the first data verification result is that the session information verification has not passed, thereby effectively avoiding the phenomenon of replay attacks.
  • the network address type of the data packet to be transmitted is determined according to the address information, and it is possible to more accurately determine whether the network address type is a public network address type or a private network address type. Therefore, it is possible to more accurately determine whether the source network address in the data packet to be transmitted needs to be updated according to the network address type of the data packet to be transmitted, thereby generating an intermediate data packet containing an accurate source network address. Furthermore, according to the user session information verification rule, data verification is performed on the session count information in the intermediate data packet containing the accurate source network address, and the first data verification result can be more accurately generated.
  • S340 includes:
  • the user signature information in the intermediate data packet is verified according to the data signature verification rule to generate a second data verification result.
  • the zero-trust gateway 106 may verify the user signature information in the intermediate data packet according to the data signature verification rule. Perform data verification to generate a second data verification result.
  • the user session information verification rule includes a user standard signature
  • the user session information verification rule includes: if the user signature information in the intermediate data packet is equal to the user standard signature, it means that the session information verification passes.
  • the zero trust gateway 106 can compare the user standard signature with the user signature information in the intermediate data packet to generate a second data verification result.
  • the user session information verification rule and the user standard signature can be set according to the data packet, and the embodiment of the present application is not limited to this.
  • data verification is performed on the user signature information in the intermediate data packet containing the accurate source network address according to the data signature verification rule, so that the second data verification result can be generated more accurately.
  • the above data transmission method also includes:
  • the zero-trust gateway 106 can determine that the data packet to be transmitted is a data packet that fails the verification. Based on this, the zero-trust gateway 106 can determine the data packet that fails the verification from the data packets to be transmitted, and generate abnormal session information corresponding to the data packet that fails the verification based on the data packet that fails the verification. Afterwards, the zero-trust gateway 106 can also discard the data packet that fails the verification.
  • the zero trust gateway 106 may send abnormal session information to the zero trust controller 104.
  • the abnormal session information indicates that the session information corresponding to the data packet to be transmitted is abnormal, and the abnormal session information is used to instruct the zero trust controller 104 to analyze the abnormal session information and send a session termination instruction to the zero trust proxy node 102.
  • the session termination instruction is used to instruct the session corresponding to the abnormal session information to be terminated.
  • data packets that fail to pass the verification are determined from the data packets to be transmitted, and abnormal session information is generated more accurately based on the data packets that fail to pass the verification.
  • the more accurate abnormal session information is sent to the zero trust controller, so that the zero trust controller analyzes the abnormal session information and sends a session termination instruction to the zero trust proxy node, so that the abnormal session can be terminated according to the abnormal session information.
  • a data transmission method is further provided, which is described by taking the method applied to the zero trust controller 104 in the zero trust communication network in FIG1 as an example, and includes the following steps:
  • the zero trust controller 104 may receive a user certificate and user standard session information sent by the zero trust proxy node 102.
  • the user certificate is a certificate issued to the user by a certificate authority (CA).
  • the user standard session information may include but is not limited to the user's real five-tuple information.
  • the five-tuple information may generally include a source network address, a source port, a destination network address, a destination port, and a transport layer protocol.
  • S640 Generate data verification rules according to the user certificate and the user standard session information.
  • the zero trust controller 104 may perform certificate verification on the user certificate and generate a certificate verification result.
  • the zero trust controller 104 may obtain the user standard signature information from the user certificate.
  • the zero trust controller 104 may generate data verification rules based on the user standard signature information and the user standard session information.
  • the user standard signature information includes the user public key information and the user standard identity information.
  • the user public key information is used to encrypt the user standard identity information.
  • the user standard identity information may include the user's real identity parameters.
  • the data verification rules include verification rules corresponding to the user standard signature information and verification rules corresponding to the user standard session information.
  • S660 sending data verification rules to the zero trust gateway; the data verification rules are used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain a data verification result; and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the zero-trust controller 104 may send a data verification rule to the zero-trust gateway 106, so that the zero-trust gateway 106 performs data verification on the verification data in the data packet to be transmitted according to the data verification rule to obtain a data verification result; thereby, the zero-trust gateway 106 determines whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the steps of data verification and data transmission by the zero-trust gateway 106 are detailed in the above embodiment and are not described in detail here.
  • the user certificate and user standard session information sent by the zero-trust proxy node are received, and more accurate user certificate and user standard session information can be obtained. Therefore, data verification rules can be generated more accurately based on more accurate user certificates and user standard session information, and more accurate data verification rules can be sent to the zero-trust gateway.
  • the more accurate data verification rules are used to instruct the zero-trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain the data verification result; determine whether to transmit the data packet to be transmitted to the database based on the data verification result.
  • a data transmission method is further provided, which is described by taking the method applied to the zero trust agent node 102 in the zero trust communication network in FIG. 1 as an example, and includes the following steps:
  • the zero trust proxy node 102 may obtain a user certificate from a user terminal.
  • the zero trust proxy node 102 may also establish a session connection with the zero trust gateway 106 to generate user standard session information.
  • the zero trust proxy node 102 may also obtain an initial data packet from the user terminal.
  • the initial data packet refers to a data packet without verification data added.
  • the zero trust proxy node 102 may register a user with the zero trust controller 104 to send the user certificate to the zero trust controller 104.
  • the zero trust proxy node 102 may establish a session connection with the zero trust gateway 106, the zero trust proxy node 102 may perform a standard session information verification on the user standard session information through the zero trust gateway 106 to generate a standard session information verification result.
  • the zero trust proxy node 102 may send the verified standard session information to the zero trust controller 104 through the zero trust gateway 106, so that the zero trust controller 104 generates a data verification rule based on the user certificate and the user standard session information, and sends the data verification rule to the zero trust gateway 106.
  • S760 add verification data to the initial data packet, generate a data packet to be transmitted, and send the data packet to be transmitted to the zero trust gateway; the data packet to be transmitted is used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules, obtain the data verification result, and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • FIG8 is a schematic diagram of the structure of a data packet to be transmitted in an embodiment.
  • the initial data packet includes the version of the initial data packet (generally 4 bits), the header length (generally 4 bits), the service type (generally 8 bits), the total length (generally 16 bits), the identifier (generally 16 bits), the flag (generally 3 bits), the offset (generally 13 bits), the survival time TTL (Time To Live, used to indicate the maximum number of network segments allowed to pass before the initial data packet is discarded, generally 8 bits), the protocol (generally 8 bits), the check bit (generally 16 bits), the source network address (generally 32 bits), the destination network address (generally 32 bits), options, data, etc.
  • the protocol generally 8 bits
  • the check bit generally 16 bits
  • the source network address generally 32 bits
  • the destination network address generally 32 bits
  • options data, etc.
  • the zero trust proxy node 102 can add verification data at the end of the initial data packet to generate a data packet to be transmitted.
  • the verification data includes user session information and user signature information.
  • the user session information may include a session counter field, and the session counter field is used to count the number of session information.
  • the user signature information may include a data signature information field, and the data signature information field may generally be a 32-bit field.
  • the zero-trust proxy node 102 can send the data packet to be transmitted to the zero-trust gateway 106.
  • the data packet to be transmitted is used to instruct the zero-trust gateway 106 to perform data verification on the verification data in the data packet to be transmitted according to the data verification rule to obtain a data verification result; the zero-trust gateway 106 determines whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the steps of data verification and data transmission by the zero-trust gateway 106 are detailed in the above embodiment and will not be repeated here.
  • the zero trust controller In the above data transmission method, it is possible to obtain more accurate user certificates, user standard session information and initial data packets; send more accurate user certificates and user standard session information to the zero trust controller, so that the zero trust controller generates data verification rules based on the more accurate user certificates and user standard session information, and sends the data verification rules to the zero trust gateway. It is also possible to add more accurate verification data to the initial data packet, generate a more accurate data packet to be transmitted, and send the more accurate data packet to be transmitted to the zero trust gateway.
  • the more accurate data packet to be transmitted is used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain the data verification result; determine whether to transmit the data packet to be transmitted to the database based on the data verification result.
  • a data transmission method is provided, which is applied to a zero-trust gateway 106 in a zero-trust communication network.
  • the data transmission method includes:
  • the network address type includes a public network address type and a private network address type
  • the data packet to be transmitted is used as an intermediate data packet
  • the network address type of the data packet to be transmitted is a public network address type, then the source network address in the data packet to be transmitted is updated to the public network address corresponding to the data packet to be transmitted, and an intermediate data packet is generated;
  • S920 send the abnormal session information to the zero trust controller; the abnormal session information is used to instruct the zero trust controller to analyze the abnormal session information and send a session termination instruction to the zero trust agent node.
  • FIG10 is a schematic diagram of the structure of a communication system corresponding to a zero-trust communication network in an embodiment.
  • the communication system 100 corresponding to the zero-trust communication network includes a zero-trust proxy node 102, a zero-trust controller 104, a zero-trust gateway 106, and a database.
  • control flow message data or business flow message data can be transmitted between the zero-trust proxy node 102 and the zero-trust gateway 106 through the communication network; control flow message data can be transmitted between the zero-trust controller 104 and the zero-trust gateway 106; and business flow message data can be transmitted between the zero-trust gateway 106 and the database.
  • Control flow message data refers to messages containing a certain sequence
  • business flow message data refers to messages containing certain actions or transactions.
  • the zero-trust proxy node 102 can perform data signing (i.e., add verification information) on the initial data packet, generate a data packet to be transmitted, and can send the data packet to be transmitted to the zero-trust gateway 106.
  • the data signing process can include a PKI (Public Key Infrastructure) digital signature process.
  • the zero-trust gateway 106 can perform data verification on the data packet to be transmitted and generate a data verification result.
  • FIG11 is a flow chart of data verification and data transmission in a zero-trust communication network in one embodiment.
  • the zero-trust proxy node 102 can obtain a user certificate, and can register a user with the zero-trust controller 104 to send the user certificate to the zero-trust controller 104.
  • the zero-trust controller 104 can receive the user certificate sent by the zero-trust proxy node 102, and perform certificate verification on the user certificate to generate a certificate verification result.
  • the zero-trust controller 104 can obtain the user standard signature information from the user certificate.
  • the zero-trust proxy node 102 can also establish a session connection with the zero-trust gateway 106 to generate user standard session information.
  • the zero-trust proxy node 102 can perform standard session information verification on the user standard session information through the zero-trust gateway 106 to generate a standard session information verification result.
  • the zero-trust proxy node 102 can send the verified standard session information to the zero-trust controller 104 through the zero-trust gateway 106.
  • the zero trust controller 104 can generate a data verification rule based on the user standard signature information and the user standard session information.
  • the zero trust controller 104 can send the data verification rule to the zero trust gateway 106.
  • the zero-trust proxy node 102 can also obtain an initial data packet from the user terminal, and can add verification data at the end of the initial data packet to generate a data packet to be transmitted. Afterwards, at S1116, the zero-trust proxy node 102 can send the data packet to be transmitted to the zero-trust gateway 106.
  • the zero-trust gateway 106 receives the data verification rules sent by the zero-trust controller 104 and the data packet to be transmitted sent by the zero-trust proxy node 102, and determines the network address type of the data packet to be transmitted based on the address information in the verification data; the network address type includes a public network address type and a private network address type.
  • the network address type of the data packet to be transmitted is a private network address type
  • the data packet to be transmitted is used as an intermediate data packet
  • the session count information in the intermediate data packet is data-verified according to the user session information verification rule to generate a first data verification result
  • the user signature information in the intermediate data packet is data-verified according to the data signature verification rule to generate a second data verification result
  • a data verification result is generated based on the first data verification result and the second data verification result.
  • the network address type of the data packet to be transmitted is a public network address type
  • the source network address in the data packet to be transmitted is updated to the public network address corresponding to the data packet to be transmitted, and an intermediate data packet is generated
  • the session count information in the intermediate data packet is data-verified according to the user session information verification rule to generate a first data verification result
  • the user signature information in the intermediate data packet is data-verified according to the data signature verification rule to generate a second data verification result
  • a data verification result is generated according to the first data verification result and the second data verification result.
  • the zero trust gateway 106 can transmit the data packet to be transmitted that has passed the verification to the database.
  • the zero trust gateway 106 can determine the data packet that has not passed the verification from the data packet to be transmitted, generate abnormal session information according to the data packet that has not passed the verification, and send the abnormal session information to the zero trust controller 104. The zero trust gateway 106 can also discard the data packet that has not passed the verification. S1126, the zero trust controller 104 can analyze the abnormal session information and send a session termination instruction to the zero trust agent node 102, so that the zero trust agent node 102 terminates the session according to the session termination instruction.
  • the zero-trust proxy node in the embodiment of the present application can perform data signing on the initial data packet, that is, it can add user session information and user signature information to the initial data packet to obtain a repackaged data packet to be transmitted.
  • the zero-trust controller in the embodiment of the present application can generate more accurate data verification rules.
  • the zero-trust gateway can receive the more accurate data verification rules sent by the zero-trust controller and the repackaged data packet to be transmitted sent by the zero-trust proxy node, and perform data verification on the user session information and user signature information in the repackaged data packet to be transmitted according to the more accurate data verification rules to obtain a more accurate data verification result.
  • the present application needs to first perform data verification on the verification data in the repackaged data packet to be transmitted according to the more accurate data verification rules, and the present application can only transmit the data packet to be transmitted that has passed the data verification, therefore, the security of the data transmission process can be improved.
  • the embodiment of the present application also provides a data transmission method for implementing the above-mentioned data transmission method.
  • the implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations of one or more data transmission device embodiments provided below can refer to the limitations of the data transmission method above, and will not be repeated here.
  • a data transmission device 1200 is provided, which is applied to a zero-trust gateway in a zero-trust communication network, and includes: a data packet receiving module 1220 to be transmitted, a data verification module 1240 and a data transmission module 1260, wherein:
  • the module 1220 for receiving data packets to be transmitted is used to receive data verification rules sent by the zero trust controller and data packets to be transmitted sent by the zero trust agent node; the data packets to be transmitted are obtained after the zero trust agent node adds verification data to the initial data packet.
  • the data verification module 1240 is used to perform data verification on the verification data in the data packet to be transmitted according to the data verification rule to obtain a data verification result.
  • the data transmission module 1260 is used to determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the verification data includes user session information and user signature information
  • the user session information is used to indicate the address information and session count information generated during the process of establishing a session connection with the zero-trust proxy node
  • the user signature information is used to indicate the identity parameters of the user who sent the initial data packet
  • the data verification rules include user session information verification rules and data signature verification rules
  • the data verification module 1240 includes:
  • a first data verification result generating unit configured to perform data verification on the user session information in the data packet to be transmitted according to the user session information verification rule, and generate a first data verification result
  • a second data verification result generating unit used to perform data verification on the user signature information in the data packet to be transmitted according to the data signature verification rule, and generate a second data verification result
  • the data verification unit is used to generate a data verification result according to the first data verification result and the second data verification result.
  • the first data verification result generating unit includes:
  • a network address type determination subunit is used to determine the network address type of the data packet to be transmitted according to the address information; the network address type includes a public network address type and a private network address type;
  • the intermediate data packet generation subunit is used to determine whether the source network address in the data packet to be transmitted needs to be updated according to the network address type of the data packet to be transmitted, and generate the intermediate data packet;
  • the first data verification result generating subunit is used to perform data verification on the session counting information in the intermediate data packet according to the user session information verification rule to generate a first data verification result.
  • the intermediate data packet generation subunit includes:
  • a first intermediate data packet generating subunit is used to use the data packet to be transmitted as an intermediate data packet when the network address type of the data packet to be transmitted is a private network address type;
  • the second intermediate data packet generating subunit is used to update the source network address in the data packet to be transmitted to the public network address corresponding to the data packet to be transmitted, so as to generate an intermediate data packet when the network address type of the data packet to be transmitted is a public network address type.
  • the second data verification result generating unit includes:
  • the second data verification result generating subunit is used to perform data verification on the user signature information in the intermediate data packet according to the data signature verification rule to generate a second data verification result.
  • the data transmission device 1200 further includes:
  • the abnormal session information generating module is used to determine the data packets that have not passed the verification from the data packets to be transmitted, and generate abnormal session information according to the data packets that have not passed the verification;
  • the abnormal session information sending module is used to send the abnormal session information to the zero trust controller; the abnormal session information is used to instruct the zero trust controller to analyze the abnormal session information and send a session termination instruction to the zero trust agent node.
  • a data transmission device 1300 is further provided, which is applied to a zero-trust controller in a zero-trust communication network, and includes: an information receiving module 1320, a data verification rule generating module 1340, and a data verification rule sending module 1360, wherein:
  • the information receiving module 1320 is used to receive the user certificate and user standard session information sent by the zero trust agent node.
  • the data verification rule generation module 1340 is used to generate data verification rules according to the user certificate and the user standard session information.
  • the data verification rule sending module 1360 is used to send data verification rules to the zero trust gateway; the data verification rules are used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain the data verification result; and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • a data transmission device 1400 is further provided, which is applied to a zero-trust proxy node in a zero-trust communication network, and includes: an information acquisition module 1420, an information transmission data verification module 1440, and a data packet generation module 1460 to be transmitted, wherein:
  • the information acquisition module is used to obtain user certificates, user standard session information and initial data packets.
  • the information sending data verification module is used to send the user certificate and user standard session information to the zero trust controller, so that the zero trust controller generates data verification rules based on the user certificate and user standard session information, and sends the data verification rules to the zero trust gateway.
  • the module for generating data packets to be transmitted is used to add verification data to the initial data packet, generate the data packet to be transmitted, and send the data packet to be transmitted to the zero trust gateway; the data packet to be transmitted is used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain the data verification result; and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • Each module in the above data transmission device can be implemented in whole or in part by software, hardware, or a combination thereof.
  • Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module.
  • FIG15 is a schematic diagram of the structure of a zero-trust gateway provided in an embodiment of the present invention.
  • the zero-trust gateway 1500 shown in FIG15 includes: at least one processor 1501, a memory 1502, and at least one network interface 1504.
  • the various components in the zero-trust gateway 1500 are coupled together through a bus system 1505. It can be understood that the bus system 1505 is used to realize the connection and communication between these components.
  • the bus system 1505 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, various buses are labeled as bus systems 1505 in FIG15.
  • the zero-trust gateway 1500 also includes a transceiver 1506, which can be a plurality of elements, namely, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium.
  • a transceiver 1506 can be a plurality of elements, namely, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium.
  • the memory 1502 in the embodiment of the present invention can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories.
  • the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
  • the volatile memory can be a random access memory (RAM), which is used as an external cache.
  • RAM static RAM
  • DRAM dynamic RAM
  • SDRAM synchronous DRAM
  • DDR SDRAM double data rate synchronous DRAM
  • ESDRAM enhanced SDRAM
  • SLDRAM synchronous link DRAM
  • DRRAM direct RAM bus DRAM
  • the memory 1502 stores the following elements, executable modules or data structures, or their subsets, or their extensions: operating system 1502a.
  • the operating system 1502a includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., which are used to implement various basic services and process hardware-based tasks.
  • the receiver is used to receive the data verification rules sent by the zero trust controller and the data packet to be transmitted sent by the zero trust agent node; the data packet to be transmitted is obtained after the zero trust agent node adds verification data to the initial data packet; the processor 1501 is used to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain a data verification result; the transmitter is used to determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the processor 1501 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method may be completed by an integrated logic circuit of hardware in the processor 1501 or by instructions in the form of software.
  • the above processor 1501 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
  • DSP digital signal processor
  • ASIC application-specific integrated circuit
  • FPGA field programmable gate array
  • the methods, steps and logic block diagrams disclosed in the embodiments of the present invention may be implemented or executed.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
  • the steps of the method disclosed in conjunction with the embodiments of the present invention may be directly embodied as being executed by a hardware decoding processor, or may be executed by a combination of hardware and software modules in a decoding processor.
  • the software module may be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc.
  • the storage medium is located in the memory 1502, and the processor 1501 reads the information in the memory 1502 and completes the steps of the above method in combination with its hardware.
  • the embodiments described in the embodiments of the present invention can be implemented by hardware, software, firmware, middleware, microcode or a combination thereof.
  • the processing unit can be implemented in one or more application specific integrated circuits (Application Specific Integrated Circuits, ASIC), digital signal processors (Digital Signal Processing, DSP), digital signal processing devices (DSP Device, DSPD), programmable logic devices (Programmable Logic Device, PLD), field programmable gate arrays (Field-Programmable Gate Array, FPGA), general processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions of the present application or a combination thereof.
  • ASIC Application Specific Integrated Circuits
  • DSP Digital Signal Processing
  • DSP Device digital signal processing devices
  • PLD programmable logic devices
  • FPGA field programmable gate array
  • general processors controllers, microcontrollers, microprocessors, other electronic units for performing the functions of the present application or a combination thereof.
  • the technology of the embodiments of the present invention can be implemented by a module (such as a process, function, etc.) that performs the functions of the embodiments of the present invention.
  • the software code can be stored in a memory and executed by the processor 1501.
  • the memory can be implemented in the processor 1501 or outside the processor 1501.
  • the verification data includes user session information and user signature information
  • the user session information is used to indicate the address information and session count information generated during the process of establishing a session connection with the zero-trust proxy node
  • the user signature information is used to indicate the identity parameters of the user who sent the initial data packet
  • the data verification rules include user session information verification rules and data signature verification rules
  • the processor is specifically used to perform data verification on the user session information in the data packet to be transmitted according to the user session information verification rules to generate a first data verification result
  • the processor is further used to determine the network address type of the data packet to be transmitted based on the address information; the network address type includes a public network address type and a private network address type; based on the network address type of the data packet to be transmitted, determine whether it is necessary to update the source network address in the data packet to be transmitted and generate an intermediate data packet; perform data verification on the session count information in the intermediate data packet according to the user session information verification rule to generate a first data verification result.
  • the processor is also used to use the data packet to be transmitted as an intermediate data packet if the network address type of the data packet to be transmitted is a private network address type; if the network address type of the data packet to be transmitted is a public network address type, update the source network address in the data packet to be transmitted to the public network address corresponding to the data packet to be transmitted, and generate an intermediate data packet.
  • the processor is further configured to perform data verification on the user signature information in the intermediate data packet according to a data signature verification rule to generate a second data verification result.
  • the processor is further used to determine the data packets that fail the verification from the data packets to be transmitted, and generate abnormal session information based on the data packets that fail the verification; the transmitter is further used to send the abnormal session information to the zero trust controller; the abnormal session information is used to instruct the zero trust controller to analyze the abnormal session information and send a session termination instruction to the zero trust agent node.
  • FIG16 is a schematic diagram of the structure of a zero-trust controller provided in an embodiment of the present invention.
  • the zero-trust controller 1600 shown in FIG16 includes: at least one processor 1601, a memory 1602, and at least one network interface 1604.
  • the various components in the zero-trust controller 1600 are coupled together through a bus system 1605.
  • the bus system 1605 is used to realize the connection and communication between these components.
  • the bus system 1605 also includes a power bus, a control bus, and a status signal bus.
  • various buses are labeled as bus systems 1605 in FIG16.
  • a transceiver 1606 is also included.
  • the transceiver can be a plurality of elements, that is, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium.
  • the memory 1602 in the embodiment of the present invention can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories.
  • the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
  • the volatile memory can be a random access memory (RAM), which is used as an external cache.
  • RAM static RAM
  • DRAM dynamic RAM
  • SDRAM synchronous DRAM
  • DDR SDRAM double data rate synchronous DRAM
  • ESDRAM enhanced SDRAM
  • SLDRAM synchronous link DRAM
  • DRRAM direct RAM bus DRAM
  • the memory 1602 stores the following elements, executable modules or data structures, or their subsets, or their extensions: operating system 1602a.
  • the operating system 1602a includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., which are used to implement various basic services and process hardware-based tasks.
  • the receiver is used to receive the user certificate and user standard session information sent by the zero trust agent node; the processor 1601 is used to generate data verification rules based on the user certificate and user standard session information; the transmitter is used to send the data verification rules to the zero trust gateway; the data verification rules are used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain the data verification result; and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the processor 1601 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method may be completed by an integrated logic circuit of hardware in the processor 1601 or by instructions in the form of software.
  • the above processor 1601 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
  • DSP digital signal processor
  • ASIC application-specific integrated circuit
  • FPGA field programmable gate array
  • the methods, steps and logic block diagrams disclosed in the embodiments of the present invention may be implemented or executed.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
  • the steps of the method disclosed in conjunction with the embodiments of the present invention may be directly embodied as being executed by a hardware decoding processor, or may be executed by a combination of hardware and software modules in the decoding processor.
  • Software module It can be located in a random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, or other mature storage media in the art.
  • the storage medium is located in the memory 1602, and the processor 1601 reads the information in the memory 1602 and completes the steps of the above method in combination with its hardware.
  • the embodiments described in the embodiments of the present invention can be implemented by hardware, software, firmware, middleware, microcode or a combination thereof.
  • the processing unit can be implemented in one or more application specific integrated circuits (Application Specific Integrated Circuits, ASIC), digital signal processors (Digital Signal Processing, DSP), digital signal processing devices (DSP Device, DSPD), programmable logic devices (Programmable Logic Device, PLD), field programmable gate arrays (Field-Programmable Gate Array, FPGA), general processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions of the present application or a combination thereof.
  • ASIC Application Specific Integrated Circuits
  • DSP Digital Signal Processing
  • DSP Device digital signal processing devices
  • PLD programmable logic devices
  • FPGA field programmable gate array
  • general processors controllers, microcontrollers, microprocessors, other electronic units for performing the functions of the present application or a combination thereof.
  • the technology of the embodiments of the present invention can be implemented by a module (such as a process, function, etc.) that performs the functions of the embodiments of the present invention.
  • the software code can be stored in a memory and executed by the processor 1601.
  • the memory can be implemented in the processor 1601 or outside the processor 1601.
  • FIG17 is a schematic diagram of the structure of a zero-trust proxy node provided in an embodiment of the present invention.
  • the zero-trust proxy node 1700 shown in FIG17 includes: at least one processor 1701, a memory 1702, and at least one network interface 1704.
  • the various components in the zero-trust proxy node 1700 are coupled together through a bus system 1705.
  • the bus system 1705 is used to realize the connection and communication between these components.
  • the bus system 1705 also includes a power bus, a control bus, and a status signal bus.
  • various buses are labeled as bus systems 1705 in FIG17.
  • a transceiver 1706 is also included, and the transceiver can be a plurality of elements, that is, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium.
  • the memory 1702 in the embodiment of the present invention can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories.
  • the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
  • the volatile memory can be a random access memory (RAM), which is used as an external cache.
  • RAM static RAM
  • DRAM dynamic RAM
  • SDRAM synchronous DRAM
  • DDR SDRAM double data rate synchronous DRAM
  • ESDRAM enhanced SDRAM
  • SLDRAM synchronous link DRAM
  • DRRAM direct RAM bus DRAM
  • the memory 1702 stores the following elements, executable modules or data structures, or their subsets, or their extensions: operating system 1702a.
  • the operating system 1702a includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., which are used to implement various basic services and process hardware-based tasks.
  • the receiver by calling the program or instruction stored in the memory 1702, the receiver is used to obtain the user certificate, the user standard session information and the initial data packet; the transmitter is used to send the user certificate and the user standard session information to the zero trust controller, so that the zero trust controller generates data verification rules based on the user certificate and the user standard session information, and sends the data verification rules to the zero trust gateway; the processor 1701 and the transmitter are used to add verification data to the initial data packet, generate a data packet to be transmitted, and send the data packet to be transmitted to the zero trust gateway; the data packet to be transmitted is used to instruct the zero trust gateway to perform data verification on the verification data in the data packet to be transmitted according to the data verification rules to obtain a data verification result; and determine whether to transmit the data packet to be transmitted to the database according to the data verification result.
  • the processor 1701 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method may be completed by an integrated logic circuit of hardware in the processor 1701 or by instructions in the form of software.
  • the above processor 1701 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components.
  • DSP digital signal processor
  • ASIC application-specific integrated circuit
  • FPGA field programmable gate array
  • the methods, steps and logic block diagrams disclosed in the embodiments of the present invention may be implemented or executed.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
  • the steps of the method disclosed in conjunction with the embodiments of the present invention may be directly embodied as being executed by a hardware decoding processor, or may be executed by a combination of hardware and software modules in a decoding processor.
  • the software module may be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc.
  • the storage medium is located in the memory 1702, and the processor 1701 reads the information in the memory 1702 and completes the steps of the above method in combination with its hardware.
  • the embodiments described in the embodiments of the present invention can be implemented by hardware, software, firmware, middleware, microcode or a combination thereof.
  • the processing unit can be implemented in one or more dedicated integrated circuits.
  • ASIC Application Specific Integrated Circuits
  • DSP digital signal processor
  • DSP Device digital signal processing device
  • DPD digital signal processing device
  • PLD programmable logic device
  • FPGA field programmable gate array
  • controller microcontroller, microprocessor, other electronic units or their combinations for executing the functions of the present application.
  • the technology of the embodiments of the present invention can be implemented by a module (such as a process, function, etc.) that performs the functions of the embodiments of the present invention.
  • the software code can be stored in a memory and executed by the processor 1701.
  • the memory can be implemented in the processor 1701 or outside the processor 1701.
  • a computer-readable storage medium on which a computer program is stored.
  • the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
  • a computer program product including a computer program, which implements the steps in the above method embodiments when executed by a processor.
  • user information including but not limited to user device information, user personal information, etc.
  • data including but not limited to data used for analysis, stored data, displayed data, etc.
  • any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory.
  • Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc.
  • Volatile memory can include random access memory (RAM) or external cache memory, etc.
  • RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
  • SRAM static random access memory
  • DRAM dynamic random access memory
  • the database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database.
  • Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this.
  • the processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, etc., but are not limited to this.
  • the above-mentioned data transmission method, device, computer equipment, storage medium and program product receive the data verification rules sent by the zero-trust controller and the data packet to be transmitted sent by the zero-trust proxy node; the data packet to be transmitted is obtained after the zero-trust proxy node adds verification data to the initial data packet; the verification data in the data packet to be transmitted is verified according to the data verification rules to obtain the data verification result; and whether to transmit the data packet to be transmitted to the database is determined according to the data verification result.
  • the zero-trust proxy node in the embodiment of the present application can add verification data to the initial data packet to obtain a re-encapsulated data packet to be transmitted.
  • the zero-trust gateway can receive the data verification rules sent by the zero-trust controller and the re-encapsulated data packet to be transmitted sent by the zero-trust proxy node, and perform data verification on the verification data in the re-encapsulated data packet to be transmitted according to the data verification rules to obtain a more accurate data verification result. Furthermore, it can be determined whether to transmit the data packet to be transmitted to the database according to the more accurate data verification result. Since the present application needs to first perform data verification on the verification data in the re-encapsulated data packet to be transmitted according to the data verification rules, and the present application can only transmit the data packet to be transmitted that passes the data verification, therefore, the security of the data transmission process can be improved.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请涉及一种数据传输方法、装置、计算机设备、存储介质和程序产品。上述方法包括:接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的;根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。

Description

数据传输方法、装置、计算机设备、存储介质和程序产品
相关申请
本申请要求2023年7月25日申请的,申请号为2023109131905,名称为“数据传输方法、装置、计算机设备、存储介质和程序产品”的中国专利申请的优先权,在此将其全文引入作为参考。
技术领域
本申请涉及信息安全技术领域,特别是涉及一种数据传输方法、装置、计算机设备、存储介质和程序产品。
背景技术
随着计算机技术的发展,出现了零信任网络。零信任网络是指用户之间没有信任,通过匿名的方式来进行数据传输的网络。
传统技术,可以在零信任网络中基于TCP/IP协议(Transmission Control Protocol/Internet Protocol,传输控制协议/网际协议)进行IP数据包的传输,从而实现数据的传输。
数据传输过程中的安全问题至关重要。
发明内容
第一方面,本申请提供了一种数据传输方法。应用于零信任通信网络中的零信任网关中,所述方法包括:
接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;所述待传输数据包为所述零信任代理节点在初始数据包中添加校验数据后得到的;
根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;
根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
在其中一个实施例中,所述校验数据包括用户会话信息和用户签名信息,所述用户会话信息用于指示与所述零信任代理节点建立会话连接过程中生成的地址信息和会话计数信息,所述用户签名信息用于指示发送所述初始数据包的用户的身份参数,所述数据校验规则包括用户会话信息校验规则及数据签名校验规则;所述根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果,包括:
根据所述用户会话信息校验规则对所述待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果;
根据所述数据签名校验规则对所述待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果;
根据所述第一数据校验结果及所述第二数据校验结果,生成所述数据校验结果。
在其中一个实施例中,所述根据所述用户会话信息校验规则对所述待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果,包括:
根据所述地址信息确定所述待传输数据包的网络地址类型;所述网络地址类型包括公网地址类型及私网地址类型;
根据所述待传输数据包的网络地址类型,确定是否需要对所述待传输数据包中的源网络地址进行更新,生成中间数据包;
根据所述用户会话信息校验规则对所述中间数据包中的会话计数信息进行数据校验,生成所述第一数据校验结果。
在其中一个实施例中,所述根据所述待传输数据包的网络地址类型,确定是否需要对所述待传输数据包中的源网络地址进行更新,生成中间数据包,包括:
若所述待传输数据包的网络地址类型为所述私网地址类型,则将所述待传输数据包作为所述中间数据包;
若所述待传输数据包的网络地址类型为所述公网地址类型,则将所述待传输数据包中的源网络地址更新为所述待传输数据包对应的公网地址,生成所述中间数据包。
在其中一个实施例中,所述根据所述数据签名校验规则对所述待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果,包括:
根据所述数据签名校验规则对所述中间数据包中的用户签名信息进行数据校验,生成所述第二数据校验结果。
在其中一个实施例中,所述方法还包括:
从所述待传输数据包中确定校验未通过的数据包,根据所述校验未通过的数据包生成异常会话信息;
将所述异常会话信息发送至零信任控制器;所述异常会话信息用于指示所述零信任控制器对所述异常会话信息进行分析及向所述零信任代理节点发送会话终止指令。
在其中一个实施例中,所述数据校验规则是根据用户标准签名信息和用户标准会话信息生成的,其中,所述用户标准签名信息包括用户公钥信息以及用户身份标准信息。
在其中一个实施例中,所述用户标准签名信息是在用户证书验证通过的情况下,从所述用户证书中获取的。
第二方面,本申请还提供了一种数据传输方法。应用于零信任通信网络中的零信任控制器中,所述方法包括:
接收零信任代理节点发送的用户证书和用户标准会话信息;
根据所述用户证书和用户标准会话信息,生成数据校验规则;
向零信任网关发送所述数据校验规则;所述数据校验规则用于指示所述零信任网关根据所述数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
在其中一个实施例中,所述根据所述用户证书和所述用户标准会话信息,生成所述数据校验规则,包括:
对所述用户证书进行验证,生成证书验证结果;
在证书验证结果为证书验证通过的情况下,从所述用户证书中获取用户标准签名信息,其中,所述用户标准签名信息包括用户公钥信息以及用户标准身份信息;以及
根据所述用户标准签名信息和所述用户标准会话信息,生成所述数据校验规则。
第三方面,本申请还提供了一种数据传输方法。应用于零信任通信网络中的零信任代理节点中,所述方法包括:
获取用户证书、用户标准会话信息和初始数据包;
将所述用户证书及所述用户标准会话信息发送至零信任控制器,以使所述零信任控制器基于所述用户证书及所述用户标准会话信息,生成数据校验规则,向零信任网关发送所述数据校验规则;
向所述初始数据包中添加校验数据,生成待传输数据包,并将所述待传输数据包发送至所述零信任网关;所述待传输数据包用于指示所述零信任网关根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
在其中一个实施例中,所述用户证书在验证通过的情况下,使得所述零信任控制器从所述用户证书中获取用户标准签名信息并基于所述标准签名信息和所述用户标准会话信息生成数据校验规则,其中,所述用户标准签名信息包括用户公钥信息以及用户身份标准信息。
第四方面,本申请还提供了一种数据传输装置。应用于零信任通信网络中的零信任网关中,所述装置包括:
待传输数据包接收模块,用于接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;所述待传输数据包为所述零信任代理节点在初始数据包中添加校验数据后得到的;
数据校验模块,用于根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;
数据传输模块,用于根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
第五方面,本申请还提供了一种数据传输装置。应用于零信任通信网络中的零信任控制器中,所述装置包括:
信息接收模块,用于接收零信任代理节点发送的用户证书和用户标准会话信息;
数据校验规则生成模块,用于根据所述用户证书和用户标准会话信息,生成数据校验规则;
数据校验规则发送模块,用于向零信任网关发送所述数据校验规则;所述数据校验规则用于指示所述零信任网关根据所述数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
第六方面,本申请还提供了一种数据传输装置。应用于零信任通信网络中的零信任代理节点中,所述装置包括:
信息获取模块,用于获取用户证书、用户标准会话信息和初始数据包;
信息发送数据校验模块,用于将所述用户证书及所述用户标准会话信息发送至零信任控制器,以使 所述零信任控制器基于所述用户证书及所述用户标准会话信息,生成数据校验规则,向零信任网关发送所述数据校验规则;
待传输数据包生成模块,用于向所述初始数据包中添加校验数据,生成待传输数据包,并将所述待传输数据包发送至所述零信任网关;所述待传输数据包用于指示所述零信任网关根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
第七方面,本申请还提供了一种零信任网关,包括收发器、处理器和存储器,所述存储器存储有计算机程序,所述处理器执行所述计算机程序,用于执行上述第一方面中任一项实施例中的方法的步骤。
第八方面,本申请还提供了一种零信任控制器,包括收发器、处理器和存储器,所述存储器存储有计算机程序,所述处理器执行所述计算机程序,用于控制所述收发器接收零信任代理节点发送的用户证书和用户标准会话信息;
用于控制所述处理器根据所述用户证书和用户标准会话信息,生成数据校验规则;
用于控制所述收发器向零信任网关发送所述数据校验规则;所述数据校验规则用于指示所述零信任网关根据所述数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
第九方面,本申请还提供了一种零信任代理节点,包括收发器、处理器和存储器,所述存储器存储有计算机程序,所述处理器执行所述计算机程序,用于控制所述收发器获取用户证书、用户标准会话信息和初始数据包;
用于控制所述收发器将所述用户证书及所述用户标准会话信息发送至零信任控制器,以使所述零信任控制器基于所述用户证书及所述用户标准会话信息,生成数据校验规则,向零信任网关发送所述数据校验规则;
用于控制所述处理器和所述收发器向所述初始数据包中添加校验数据,生成待传输数据包,并将所述待传输数据包发送至所述零信任网关;所述待传输数据包用于指示所述零信任网关根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
第十方面,本申请还提供了一种计算机可读存储介质。所述计算机可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现上述第一方面至第三方面中任一项实施例中的方法的步骤。
第十一方面,本申请还提供了一种计算机程序产品。所述计算机程序产品,包括计算机程序,该计算机程序被处理器执行时实现上述第一方面至第三方面中任一项实施例中的方法的步骤。
第十二方面,本申请还提供了一种装置,被配置为执行上述第一方面至第三方面任一项实施例中的方法步骤。
本申请的一个或多个实施例的细节在下面的附图和描述中提出。本申请的其他特征、目的和优点将从说明书、附图以及权利要求书变得明显。
附图说明
为了更清楚地说明本申请实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据公开的附图获得其他的附图。
图1为一个实施例中数据传输方法的应用环境图;
图2为一个实施例中零信任网关对应的数据传输方法的流程示意图;
图3为一个实施例中数据校验步骤的流程示意图;
图4为一个实施例中第一数据校验结果生成步骤的流程示意图;
图5为一个实施例中异常会话信息发送步骤的流程示意图;
图6为另一个实施例中零信任控制器对应的数据传输方法的流程示意图;
图7为另一个实施例中零信任代理节点对应的数据传输方法的流程示意图;
图8为一个实施例中待传输数据包的结构示意图;
图9为一个可选的实施例中零信任网关对应的数据传输方法的流程示意图;
图10为一个实施例中零信任通信网络对应的通信系统的结构示意图;
图11为一个实施例中在零信任通信网络中进行数据校验及数据传输的流程示意图;
图12为一个实施例中零信任网关对应的数据传输装置的结构框图;
图13为一个实施例中零信任控制器对应的数据传输装置的结构框图;
图14为一个实施例中零信任代理节点对应的数据传输装置的结构框图;
图15为一个实施例中零信任网关的内部结构示意图;
图16为另一个实施例中零信任控制器的内部结构示意图;
图17为又一个实施例中零信任代理节点的内部结构示意图。
具体实施方式
为了使本申请的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本申请进行进一步详细说明。应当理解,此处描述的具体实施例仅仅用以解释本申请,并不用于限定本申请。
随着计算机技术的发展,出现了零信任网络。零信任网络是指用户之间没有信任,通过匿名的方式来进行数据传输的网络。
传统技术,可以在零信任网络中基于TCP/IP协议(Transmission Control Protocol/Internet Protocol,传输控制协议/网际协议)进行IP数据包的传输,从而实现数据的传输。
然而,在传统的数据传输过程中,数据存在被伪冒、被篡改、出现重放攻击等安全问题。因此,传统的数据传输方法,存在安全性较低的问题。
本申请实施例提供的数据传输方法,可以应用于如图1所示的应用环境中。其中,零信任通信网络(即零信任网络)对应的通信系统100中包括零信任代理节点102、零信任控制器104、零信任网关106和数据库。零信任代理节点102可以从用户终端处获取数据,且零信任代理节点102可以通过通信网络向零信任网关106发送数据,零信任代理节点102还可以向零信任控制器104发送数据。其中,通信网络包括公网和局域网。零信任控制器104可以向零信任网关106发送数据。零信任网关106可以将数据传输至数据库,或者,零信任网关106也可以将数据传输至零信任控制器104。在本申请实施例中,零信任网关106接收零信任控制器104发送的数据校验规则和零信任代理节点102发送的待传输数据包;待传输数据包为零信任代理节点102在初始数据包中添加校验数据后得到的;零信任网关106根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;零信任网关106根据数据校验结果确定是否将待传输数据包传输至数据库。
其中,用户终端可以但不限于是各种个人计算机、笔记本电脑、智能手机、平板电脑、物联网设备和便携式可穿戴设备,物联网设备可为智能音箱、智能电视、智能空调、智能车载设备等。便携式可穿戴设备可为智能手表、智能手环、头戴设备等。零信任代理节点102、零信任控制器104、零信任网关106均可以用独立的服务器或者是多个服务器组成的服务器集群来实现。
在一个实施例中,如图2所示,提供了一种数据传输方法,以该方法应用于图1中的零信任通信网络中的零信任网关106为例进行说明,包括以下步骤:
S220,接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的。
其中,零信任通信网络即零信任网络,零信任网络是指用户之间没有信任,通过匿名的方式来进行数据传输的网络。零信任通信网络对应的通信系统中包括零信任代理节点、零信任控制器、零信任网关和数据库。数据校验规则是由零信任代理节点生成的规则,数据校验规则用于对待传输数据包中的数据进行数据校验。待传输数据包是指需要先进行数据校验、且只有在数据校验通过之后才能进行传输的数据包。待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的数据包。初始数据包是指从用户终端处获取的数据包。校验数据是指待传输数据包中用于进行数据校验的数据。
在一些实施方式中,由于零信任通信网络对应的通信系统100中包括零信任代理节点102、零信任控制器104、零信任网关106和数据库,且零信任代理节点102和零信任控制器104均可以向零信任网关106发送数据。因此,可选地,零信任网关106可以同时接收零信任控制器104发送的数据校验规则和零信任代理节点102发送的待传输数据包;或者,零信任网关106也可以先接收零信任控制器104发送的数据校验规则,再接收零信任代理节点102发送的待传输数据包;或者,零信任网关106还可以先接收零信任代理节点102发送的待传输数据包,再接收零信任控制器104发送的数据校验规则。需要说明的是,在本申请实施例中,对于零信任网关106接收数据校验规则和接收待传输数据包的时间顺序不做限定。
S240,根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果。
一些实施方式中,零信任网关106可以根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果。示例性的,假设数据校验规则中包括校验数据阈值,且数据校验规则为:若校验数据小于或者等于校验数据阈值,则表示数据校验通过。那么,零信任网关106可以将校验数据阈值与待传输数据包中的校验数据进行比较,从而生成数据校验结果。其中,数据校验规则和校验数据阈值可以是根据数据包进行设置的,本申请实施例对此不做限定。数据校验结果包括数据校验通过以及数 据校验未通过。
S260,根据数据校验结果确定是否将待传输数据包传输至数据库。
一些实施方式中,零信任网关106可以根据数据校验结果确定是否将待传输数据包传输至数据库。示例性的,若数据校验结果为数据校验通过,则零信任网关106可以将待传输数据包传输至数据库。若数据校验结果为数据校验未通过,则零信任网关106可以丢弃待传输数据包。
上述数据传输方法中,接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的;根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。本申请实施例中的零信任代理节点能够在初始数据包中添加校验数据,得到重新封装的待传输数据包。从而,零信任网关能够接收零信任控制器发送的数据校验规则以及零信任代理节点发送的、重新封装的待传输数据包,并根据数据校验规则对重新封装的待传输数据包中的校验数据进行数据校验,得到较准确的数据校验结果。进而,能够根据较准确的数据校验结果,确定是否将待传输数据包传输至数据库。由于本申请需要先根据数据校验规则对重新封装的待传输数据包中的校验数据进行数据校验,且本申请只能对数据校验通过的待传输数据包进行传输,因此,能够提高数据传输过程的安全性。
在上面的实施例中,涉及到了根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果,下面对其具体方法进行介绍。在一个实施例中,校验数据包括用户会话信息和用户签名信息,用户会话信息用于指示与零信任代理节点建立会话连接过程中生成的地址信息和会话计数信息,用户签名信息用于指示发送初始数据包的用户的身份参数,数据校验规则包括用户会话信息校验规则及数据签名校验规则;如图3所示,S240包括:
S320,根据用户会话信息校验规则对待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果。
其中,校验数据可以包括但不局限于用户会话信息和用户签名信息,用户会话信息用于指示与零信任代理节点建立会话连接过程中生成的地址信息和会话计数信息。地址信息包括源网络地址、目的网络地址以及发送待传输数据包的网络地址等信息。会话计数信息是指会话信息的数量。用户签名信息用于指示发送初始数据包的用户的身份参数。身份参数可以包括但不局限于用户名称、用户的身份认证标识等。从而,零信任网关106可以接收地址信息、会话计数信息及用户的身份参数等校验数据。数据校验规则包括用户会话信息校验规则及数据签名校验规则。用户会话信息校验规则是指对地址信息、会话计数信息等用户会话信息进行数据校验的规则,数据签名校验规则是指对用户签名信息进行数据校验的规则。
一些实施方式中,零信任网关106可以根据用户会话信息校验规则对待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果。示例性的,假设用户会话信息校验规则中包括会话信息阈值,且用户会话信息校验规则为:若用户会话信息小于或者等于会话信息阈值,则表示会话信息校验通过。那么,零信任网关106可以将会话信息阈值与待传输数据包中的用户会话信息进行比较,从而生成第一数据校验结果。其中,用户会话信息校验规则和会话信息阈值可以是根据数据包进行设置的,本申请实施例对此不做限定。第一数据校验结果包括会话信息校验通过以及会话信息校验未通过。
S340,根据数据签名校验规则对待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果。
一些实施方式中,零信任网关106可以根据数据签名校验规则对待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果。示例性的,假设数据签名校验规则中包括数据签名阈值,且数据签名校验规则为:若用户签名信息小于或者等于数据签名阈值,则表示数据签名校验通过。那么,零信任网关106可以将数据签名阈值与待传输数据包中的用户签名信息进行比较,从而生成第二数据校验结果。其中,数据签名校验规则和数据签名阈值可以是根据数据包进行设置的,本申请实施例对此不做限定。第二数据校验结果包括数据签名校验通过以及数据签名校验未通过。
S360,根据第一数据校验结果及第二数据校验结果,生成数据校验结果。
一些实施方式中,零信任网关106可以根据第一数据校验结果及第二数据校验结果,确定会话信息校验是否通过以及数据签名校验是否通过。若第一数据校验结果为会话信息校验通过,且第二数据校验结果为数据签名校验通过,即会话信息校验和数据签名校验均通过,则确定数据校验结果为数据校验通过。若第一数据校验结果为会话信息校验未通过,和/或,第二数据校验结果为数据签名校验未通过,即会话信息校验和数据签名校验中存在至少一次校验未通过,则确定数据校验结果为数据校验未通过。
本实施例中,由于校验数据包括用户会话信息和用户签名信息,且数据校验规则包括用户会话信息校验规则及数据签名校验规则。因此,根据用户会话信息校验规则对待传输数据包中的用户会话信息进 行数据校验,能够较准确地生成第一数据校验结果;根据数据签名校验规则对待传输数据包中的用户签名信息进行数据校验,能够较准确地生成第二数据校验结果。从而,能够根据较准确的第一数据校验结果及较准确的第二数据校验结果,生成较准确的数据校验结果。
在上面的实施例中,涉及到了根据用户会话信息校验规则对待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果,下面对其具体方法进行介绍。在一个实施例中,如图4所示,S320包括:
S420,根据地址信息确定待传输数据包的网络地址类型;网络地址类型包括公网地址类型及私网地址类型。
一些实施方式中,零信任网关106可以从待传输数据包地址信息中获取发送待传输数据包的网络地址,并根据该发送待传输数据包的网络地址,确定待传输数据包的网络地址类型。其中,网络地址类型包括公网地址类型及私网地址类型。公网地址是指在因特网上可以直接进行访问的地址。私网地址是指在私网上可以直接进行访问的地址。私网即为局域网,局域网是在局部地区形成的一个区域网络,只有特定区域内的计算机设备可以访问私网。示例性的,若发送待传输数据包的网络地址为私网地址,则零信任网关106可以确定待传输数据包的网络地址类型为私网地址类型;若发送待传输数据包的网络地址为公网地址,则零信任网关106可以确定待传输数据包的网络地址类型为公网地址类型。
S440,根据待传输数据包的网络地址类型,确定是否需要对待传输数据包中的源网络地址进行更新,生成中间数据包。
一些实施方式中,零信任网关106可以根据待传输数据包的网络地址类型,确定发送待传输数据包的网络地址是公网地址还是私网地址,从而确定是否需要对待传输数据包中的源网络地址进行更新,进而生成中间数据包。其中,中间数据包为基于待传输数据包的网络地址类型所生成的数据包。
在其中一个实施例中,S440包括:
若待传输数据包的网络地址类型为私网地址类型,则将待传输数据包作为中间数据包。
若待传输数据包的网络地址类型为公网地址类型,则将待传输数据包中的源网络地址更新为待传输数据包对应的公网地址,生成中间数据包。
若待传输数据包的网络地址类型为私网地址类型,即发送待传输数据包的网络地址是私网地址,则说明未对待传输数据包进行网络地址转换(Network Address Translation,NAT)。此时,待传输数据包中的源网络地址与私网地址相同,因此,零信任网关106可以对待传输数据包不做更新处理,直接将待传输数据包作为中间数据包。
若待传输数据包的网络地址类型为公网地址类型,即发送待传输数据包的网络地址是公网地址,则说明对待传输数据包进行了网络地址转换(Network Address Translation,NAT)。此时,待传输数据包中的源网络地址仍为私网地址,但是,待传输数据包的真实网络地址为公网地址,即待传输数据包中的源网络地址与真实网络地址(即公网地址)不相同,因此,零信任网关106可以将待传输数据包中的源网络地址更新为待传输数据包对应的公网地址,从而生成中间数据包。
S460,根据用户会话信息校验规则对中间数据包中的会话计数信息进行数据校验,生成第一数据校验结果。
一些实施方式中,零信任网关106可以根据用户会话信息校验规则对中间数据包中的会话计数信息进行数据校验,生成第一数据校验结果。示例性的,假设用户会话信息校验规则中包括标准会话计数,且用户会话信息校验规则包括:若中间数据包中的会话计数信息小于或者等于标准会话计数,则表示会话信息校验通过。那么,零信任网关106可以将标准会话计数与中间数据包中的会话计数信息进行比较,从而生成第一数据校验结果。其中,用户会话信息校验规则和标准会话计数可以是根据数据包进行设置的,本申请实施例对此不做限定。需要说明的是,根据会话计数信息的校验过程,零信任网关106可以确定是否接收到多余的会话信息,若接收到多余的会话信息,则说明出现重放攻击的现象,此时,第一数据校验结果为会话信息校验未通过,从而能够有效地避免出现重放攻击的现象。
本实施例中,根据地址信息确定待传输数据包的网络地址类型,能够较准确地确定出网络地址类型为公网地址类型还是私网地址类型。从而,能够根据待传输数据包的网络地址类型,较准确地确定是否需要对待传输数据包中的源网络地址进行更新,从而生成包含准确的源网络地址的中间数据包。进而,根据用户会话信息校验规则对包含准确的源网络地址的中间数据包中的会话计数信息进行数据校验,就能够较准确地生成第一数据校验结果。
在上面的实施例中,涉及到了根据数据签名校验规则对待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果,下面对其具体方法进行介绍。在一个实施例中,S340包括:
根据数据签名校验规则对中间数据包中的用户签名信息进行数据校验,生成第二数据校验结果。
一些实施方式中,零信任网关106可以根据数据签名校验规则对中间数据包中的用户签名信息进 行数据校验,生成第二数据校验结果。示例性的,假设用户会话信息校验规则中包括用户标准签名,且用户会话信息校验规则包括:若中间数据包中的用户签名信息等于用户标准签名,则表示会话信息校验通过。那么,零信任网关106可以将用户标准签名与中间数据包中的用户签名信息进行比较,从而生成第二数据校验结果。其中,用户会话信息校验规则和用户标准签名可以是根据数据包进行设置的,本申请实施例对此不做限定。
本实施例中,根据数据签名校验规则对包含准确的源网络地址的中间数据包中的用户签名信息进行数据校验,能够较准确地生成第二数据校验结果。
在上面的实施例中,涉及到了根据数据校验结果确定是否将待传输数据包传输至数据库,下面对另一个实施例中的具体方法进行介绍。在一个实施例中,如图5所示,上述数据传输方法还包括:
S520,从待传输数据包中确定校验未通过的数据包,根据校验未通过的数据包生成异常会话信息。
一些实施方式中,若待传输数据包的数据校验结果为数据校验未通过,即会话信息校验和数据签名校验中存在至少一次校验未通过,则零信任网关106可以确定该待传输数据包是校验未通过的数据包。基于此,零信任网关106可以从待传输数据包中确定校验未通过的数据包,并根据校验未通过的数据包生成该校验未通过的数据包对应的异常会话信息。之后,零信任网关106还可以丢弃该校验未通过的数据包。
S540,将异常会话信息发送至零信任控制器;异常会话信息用于指示零信任控制器对异常会话信息进行分析及向零信任代理节点发送会话终止指令。
一些实施方式中,零信任网关106可以将异常会话信息发送至零信任控制器104。其中,异常会话信息表示的是该待传输数据包对应的会话信息存在异常,异常会话信息用于指示零信任控制器104对异常会话信息进行分析及向零信任代理节点102发送会话终止指令。会话终止指令用于指示将异常的会话信息对应的会话进行终止。
本实施例中,从待传输数据包中确定校验未通过的数据包,并根据校验未通过的数据包较准确地生成异常会话信息。之后,将较准确的异常会话信息发送至零信任控制器,以使零信任控制器对异常会话信息进行分析,并向零信任代理节点发送会话终止指令,从而能够根据异常会话信息终止异常会话。
在一个实施例中,如图6所示,还提供了一种数据传输方法,以该方法应用于图1中的零信任通信网络中的零信任控制器104为例进行说明,包括以下步骤:
S620,接收零信任代理节点发送的用户证书和用户标准会话信息。
一些实施方式中,零信任控制器104可以接收零信任代理节点102发送的用户证书和用户标准会话信息。其中,用户证书是由证书颁发机构(Certificate Authority,CA)签发给用户的证书。用户标准会话信息可以包括但不局限于用户真实的五元组信息。五元组信息通常可以包括源网络地址、源端口、目的网络地址、目的端口和传输层协议。
S640,根据用户证书和用户标准会话信息,生成数据校验规则。
一些实施方式中,零信任控制器104可以对用户证书进行证书验证,生成证书验证结果。在证书验证结果为证书验证通过的情况下,零信任控制器104可以从用户证书中获取用户标准签名信息。从而,零信任控制器104可以根据用户标准签名信息和用户标准会话信息,生成数据校验规则。其中,用户标准签名信息包括用户公钥信息以及用户标准身份信息。用户公钥信息用于对用户标准身份信息进行加密。用户标准身份信息可以包括用户真实的身份参数。数据校验规则中包括用户标准签名信息对应的校验规则和用户标准会话信息对应的校验规则。
S660,向零信任网关发送数据校验规则;数据校验规则用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。
一些实施方式中,零信任控制器104可以向零信任网关106发送数据校验规则,以使零信任网关106根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;从而,以使零信任网关106根据数据校验结果确定是否将待传输数据包传输至数据库。其中,零信任网关106进行数据校验及数据传输的步骤详见上述实施例,在此不做赘述。
上述数据传输方法中,接收零信任代理节点发送的用户证书和用户标准会话信息,能够获取较准确的用户证书和用户标准会话信息。从而,能够根据较准确的用户证书和用户标准会话信息,较准确地生成数据校验规则,并能够向零信任网关发送较准确的数据校验规则。其中,较准确的数据校验规则用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。
在一个实施例中,如图7所示,还提供了一种数据传输方法,以该方法应用于图1中的零信任通信网络中的零信任代理节点102为例进行说明,包括以下步骤:
S720,获取用户证书、用户标准会话信息和初始数据包。
一些实施方式中,零信任代理节点102可以从用户终端处获取用户证书。零信任代理节点102还可以与零信任网关106建立会话连接,生成用户标准会话信息。零信任代理节点102还可以从用户终端处获取初始数据包。其中,初始数据包是指未添加校验数据的数据包。
S740,将用户证书及用户标准会话信息发送至零信任控制器,以使零信任控制器基于用户证书及用户标准会话信息,生成数据校验规则,向零信任网关发送数据校验规则。
一些实施方式中,零信任代理节点102可以向零信任控制器104进行用户注册,以将用户证书发送至零信任控制器104。此外,由于零信任代理节点102可以与零信任网关106建立会话连接,因此,零信任代理节点102可以通过零信任网关106对用户标准会话信息进行标准会话信息校验,生成标准会话信息校验结果。在标准会话信息校验结果为标准会话信息校验通过的情况下,零信任代理节点102可以通过零信任网关106将校验通过的标准会话信息发送至零信任控制器104,以使零信任控制器104基于用户证书及用户标准会话信息,生成数据校验规则,并向零信任网关106发送数据校验规则。
S760,向初始数据包中添加校验数据,生成待传输数据包,并将待传输数据包发送至零信任网关;待传输数据包用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果,及根据数据校验结果确定是否将待传输数据包传输至数据库。
图8为一个实施例中待传输数据包的结构示意图。初始数据包中包括初始数据包的版本(一般为4位)、头部长度(一般为4位)、服务类型(一般为8位)、总长度(一般为16位)、标识符(一般为16位)、标志(一般为3位)、偏移量(一般为13位)、生存时间TTL(Time To Live,用于指示初始数据包被丢弃之前允许通过的最大网段数量,一般为8位)、协议(一般为8位)、校验位(一般为16位)、源网络地址(一般为32位)、目的网络地址(一般为32位)、选项、数据等。零信任代理节点102可以在初始数据包的末端中添加校验数据,生成待传输数据包。其中,校验数据包括用户会话信息和用户签名信息。示例性的,用户会话信息可以包括会话计数器字段,会话计数器字段用于对会话信息的数量进行计数。用户签名信息可以包括数据签名信息字段,数据签名信息字段通常可以是32位的字段。此外,还需要将初始数据包的总长度更新为添加校验数据之后的数据包的总长度。
之后,零信任代理节点102可以将待传输数据包发送至零信任网关106。待传输数据包用于指示零信任网关106根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;零信任网关106根据数据校验结果确定是否将待传输数据包传输至数据库。其中,零信任网关106进行数据校验及数据传输的步骤详见上述实施例,在此不做赘述。
上述数据传输方法中,能够获取较准确的用户证书、用户标准会话信息和初始数据包;将较准确的用户证书及用户标准会话信息发送至零信任控制器,以使零信任控制器基于较准确的用户证书及用户标准会话信息,生成数据校验规则,向零信任网关发送数据校验规则。还能够向初始数据包中添加较准确的校验数据,生成较准确的待传输数据包,并将较准确的待传输数据包发送至零信任网关。其中,较准确的待传输数据包用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。
在一个可选的实施例中,如图9所示,提供了一种数据传输方法,应用于零信任通信网络中的零信任网关106,上述数据传输方法包括:
S902,接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的;
S904,根据地址信息确定待传输数据包的网络地址类型;网络地址类型包括公网地址类型及私网地址类型;
S906,若待传输数据包的网络地址类型为私网地址类型,则将待传输数据包作为中间数据包;
S908,若待传输数据包的网络地址类型为公网地址类型,则将待传输数据包中的源网络地址更新为待传输数据包对应的公网地址,生成中间数据包;
S910,根据用户会话信息校验规则对中间数据包中的会话计数信息进行数据校验,生成第一数据校验结果;
S912,根据数据签名校验规则对中间数据包中的用户签名信息进行数据校验,生成第二数据校验结果;
S914,根据第一数据校验结果及第二数据校验结果,生成数据校验结果;
S916,根据数据校验结果确定是否将待传输数据包传输至数据库;
S918,从待传输数据包中确定校验未通过的数据包,根据校验未通过的数据包生成异常会话信息;
S920,将异常会话信息发送至零信任控制器;异常会话信息用于指示零信任控制器对异常会话信息进行分析及向零信任代理节点发送会话终止指令。
图10为一个实施例中零信任通信网络对应的通信系统的结构示意图。零信任通信网络(即零信任网络)对应的通信系统100中包括零信任代理节点102、零信任控制器104、零信任网关106和数据库。其中,可以在零信任代理节点102和零信任网关106之间通过通信网络传输控制流消息数据或者业务流消息数据;可以在零信任控制器104和零信任网关106之间传输控制流消息数据;可以在零信任网关106和数据库之间传输业务流消息数据。控制流消息数据是指包含一定顺序的消息,业务流消息数据是指包含一定动作或事务的消息。零信任代理节点102可以对初始数据包进行数据签名(即添加校验信息),生成待传输数据包,且可以将待传输数据包发送至零信任网关106。其中,数据签名的过程可以包括PKI(公钥基础设施,Public Key Infrastructure)数字签名过程。零信任网关106可以对待传输数据包进行数据校验,生成数据校验结果。
图11为一个实施例中在零信任通信网络中进行数据校验及数据传输的流程示意图。S1102,零信任代理节点102可以获取用户证书,并可以向零信任控制器104进行用户注册,以将用户证书发送至零信任控制器104。S1104,零信任控制器104可以接收零信任代理节点102发送的用户证书,并对用户证书进行证书验证,生成证书验证结果。在证书验证结果为证书验证通过的情况下,零信任控制器104可以从用户证书中获取用户标准签名信息。S1106,零信任代理节点102还可以与零信任网关106建立会话连接,生成用户标准会话信息。之后,零信任代理节点102可以通过零信任网关106对用户标准会话信息进行标准会话信息校验,生成标准会话信息校验结果。S1108,在标准会话信息校验结果为标准会话信息校验通过的情况下,零信任代理节点102可以通过零信任网关106将校验通过的标准会话信息发送至零信任控制器104。S1110,零信任控制器104可以根据用户标准签名信息和用户标准会话信息,生成数据校验规则。S1112,零信任控制器104可以向零信任网关106发送数据校验规则。
结合图11所示,S1114,零信任代理节点102还可以从用户终端处获取初始数据包,并可以在初始数据包的末端中添加校验数据,生成待传输数据包。之后,S1116,零信任代理节点102可以将待传输数据包发送至零信任网关106。零信任网关106接收零信任控制器104发送的数据校验规则和零信任代理节点102发送的待传输数据包,并根据校验数据中的地址信息确定待传输数据包的网络地址类型;网络地址类型包括公网地址类型及私网地址类型。S1118,若待传输数据包的网络地址类型为私网地址类型,则将待传输数据包作为中间数据包,并根据用户会话信息校验规则对中间数据包中的会话计数信息进行数据校验,生成第一数据校验结果;根据数据签名校验规则对中间数据包中的用户签名信息进行数据校验,生成第二数据校验结果;根据第一数据校验结果及第二数据校验结果,生成数据校验结果。
结合图11所示,S1120,若待传输数据包的网络地址类型为公网地址类型,则将待传输数据包中的源网络地址更新为待传输数据包对应的公网地址,生成中间数据包;并根据用户会话信息校验规则对中间数据包中的会话计数信息进行数据校验,生成第一数据校验结果;根据数据签名校验规则对中间数据包中的用户签名信息进行数据校验,生成第二数据校验结果;根据第一数据校验结果及第二数据校验结果,生成数据校验结果。S1122,在数据校验结果为校验通过的情况下,零信任网关106可以将校验通过的待传输数据包传输至数据库。S1124,在数据校验结果为校验未通过的情况下,零信任网关106可以从待传输数据包中确定校验未通过的数据包,根据校验未通过的数据包生成异常会话信息,并将异常会话信息发送至零信任控制器104。零信任网关106还可以将校验未通过的数据包进行丢弃。S1126,零信任控制器104可以对异常会话信息进行分析,并向零信任代理节点102发送会话终止指令,以使零信任代理节点102根据会话终止指令终止会话。
上述数据传输方法中,本申请实施例中的零信任代理节点能够对初始数据包进行数据签名,即能够在初始数据包中添加用户会话信息和用户签名信息,得到重新封装的待传输数据包。且本申请实施例中的零信任控制器能够生成较准确的数据校验规则。从而,零信任网关能够接收零信任控制器发送的较准确的数据校验规则以及零信任代理节点发送的、重新封装的待传输数据包,并根据较准确的数据校验规则对重新封装的待传输数据包中的用户会话信息和用户签名信息进行数据校验,得到较准确的数据校验结果。进而,能够根据较准确的数据校验结果,确定是否将待传输数据包传输至数据库。由于本申请需要先根据较准确的数据校验规则对重新封装的待传输数据包中的校验数据进行数据校验,且本申请只能对数据校验通过的待传输数据包进行传输,因此,能够提高数据传输过程的安全性。
应该理解的是,虽然如上的各实施例所涉及的流程图中的各个步骤按照箭头的指示依次显示,但是这些步骤并不是必然按照箭头指示的顺序依次执行。除非本文中有明确的说明,这些步骤的执行并没有严格的顺序限制,这些步骤可以以其它的顺序执行。而且,如上的各实施例所涉及的流程图中的至少一部分步骤可以包括多个步骤或者多个阶段,这些步骤或者阶段并不必然是在同一时刻执行完成,而是可以在不同的时刻执行,这些步骤或者阶段的执行顺序也不必然是依次进行,而是可以与其它步骤或者其它步骤中的步骤或者阶段的至少一部分轮流或者交替地执行。
基于同样的发明构思,本申请实施例还提供了一种用于实现上述所涉及的数据传输方法的数据传 输装置。该装置所提供的解决问题的实现方案与上述方法中所记载的实现方案相似,故下面所提供的一个或多个数据传输装置实施例中的具体限定可以参见上文中对于数据传输方法的限定,在此不再赘述。
在一个实施例中,如图12所示,提供了一种数据传输装置1200,应用于零信任通信网络中的零信任网关中,包括:待传输数据包接收模块1220、数据校验模块1240和数据传输模块1260,其中:
待传输数据包接收模块1220,用于接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的。
数据校验模块1240,用于根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果。
数据传输模块1260,用于根据数据校验结果确定是否将待传输数据包传输至数据库。
在其中一个实施例中,校验数据包括用户会话信息和用户签名信息,用户会话信息用于指示与零信任代理节点建立会话连接过程中生成的地址信息和会话计数信息,用户签名信息用于指示发送初始数据包的用户的身份参数,数据校验规则包括用户会话信息校验规则及数据签名校验规则;数据校验模块1240包括:
第一数据校验结果生成单元,用于根据用户会话信息校验规则对待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果;
第二数据校验结果生成单元,用于根据数据签名校验规则对待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果;
数据校验单元,用于根据第一数据校验结果及第二数据校验结果,生成数据校验结果。
在其中一个实施例中,第一数据校验结果生成单元包括:
网络地址类型确定子单元,用于根据地址信息确定待传输数据包的网络地址类型;网络地址类型包括公网地址类型及私网地址类型;
中间数据包生成子单元,用于根据待传输数据包的网络地址类型,确定是否需要对待传输数据包中的源网络地址进行更新,生成中间数据包;
第一数据校验结果生成子单元,用于根据用户会话信息校验规则对中间数据包中的会话计数信息进行数据校验,生成第一数据校验结果。
在其中一个实施例中,中间数据包生成子单元包括:
第一中间数据包生成子单元,用于在待传输数据包的网络地址类型为私网地址类型的情况下,将待传输数据包作为中间数据包;
第二中间数据包生成子单元,用于在待传输数据包的网络地址类型为公网地址类型的情况下,将待传输数据包中的源网络地址更新为待传输数据包对应的公网地址,生成中间数据包。
在其中一个实施例中,第二数据校验结果生成单元包括:
第二数据校验结果生成子单元,用于根据数据签名校验规则对中间数据包中的用户签名信息进行数据校验,生成第二数据校验结果。
在其中一个实施例中,数据传输装置1200还包括:
异常会话信息生成模块,用于从待传输数据包中确定校验未通过的数据包,根据校验未通过的数据包生成异常会话信息;
异常会话信息发送模块,用于将异常会话信息发送至零信任控制器;异常会话信息用于指示零信任控制器对异常会话信息进行分析及向零信任代理节点发送会话终止指令。
在一个实施例中,如图13所示,还提供了一种数据传输装置1300,应用于零信任通信网络中的零信任控制器中,包括:信息接收模块1320、数据校验规则生成模块1340和数据校验规则发送模块1360,其中:
信息接收模块1320,用于接收零信任代理节点发送的用户证书和用户标准会话信息。
数据校验规则生成模块1340,用于根据用户证书和用户标准会话信息,生成数据校验规则。
数据校验规则发送模块1360,用于向零信任网关发送数据校验规则;数据校验规则用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。
在一个实施例中,如图14所示,还提供了一种数据传输装置1400,应用于零信任通信网络中的零信任代理节点中,包括:信息获取模块1420、信息发送数据校验模块1440和待传输数据包生成模块1460,其中:
信息获取模块,用于获取用户证书、用户标准会话信息和初始数据包。
信息发送数据校验模块,用于将用户证书及用户标准会话信息发送至零信任控制器,以使零信任控制器基于用户证书及用户标准会话信息,生成数据校验规则,向零信任网关发送数据校验规则。
待传输数据包生成模块,用于向初始数据包中添加校验数据,生成待传输数据包,并将待传输数据包发送至零信任网关;待传输数据包用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。
上述数据传输装置中的各个模块可全部或部分通过软件、硬件及其组合来实现。上述各模块可以硬件形式内嵌于或独立于计算机设备中的处理器中,也可以以软件形式存储于计算机设备中的存储器中,以便于处理器调用执行以上各个模块对应的操作。
图15是本发明实施例提供的零信任网关的结构示意图。图15所示的零信任网关1500包括:至少一个处理器1501、存储器1502、至少一个网络接口1504。零信任网关1500中的各个组件通过总线系统1505耦合在一起。可理解,总线系统1505用于实现这些组件之间的连接通信。总线系统1505除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图15中将各种总线都标为总线系统1505。另外,本发明实施例中,零信任网关1500还包括收发器1506,收发器可以是多个元件,即包括发送器和接收器,提供用于在传输介质上与各种其他装置通信的单元。
可以理解,本发明实施例中的存储器1502可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-OnlyMemory,ROM)、可编程只读存储器(ProgrammableROM,PROM)、可擦除可编程只读存储器(ErasablePROM,EPROM)、电可擦除可编程只读存储器(ElectricallyEPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(RandomAccessMemory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(StaticRAM,SRAM)、动态随机存取存储器(DynamicRAM,DRAM)、同步动态随机存取存储器(SynchronousDRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(DoubleDataRate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(SynchlinkDRAM,SLDRAM)和直接内存总线随机存取存储器(DirectRambusRAM,DRRAM)。本发明实施例描述的系统和方法的存储器1502旨在包括但不限于这些和任意其它适合类型的存储器。
在一些实施方式中,存储器1502存储了如下的元素,可执行模块或者数据结构,或者他们的子集,或者他们的扩展集:操作系统1502a。其中,操作系统1502a,包含各种系统程序,例如框架层、核心库层、驱动层等,用于实现各种基础业务以及处理基于硬件的任务。
在本发明实施例中,通过调用存储器1502存储的程序或指令,使得接收器,用于接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的;处理器1501,用于根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;发送器,用于根据数据校验结果确定是否将待传输数据包传输至数据库。
上述本发明实施例揭示的部分或者全部方法还可以应用于处理器1501中,或者由处理器1501实现,或者由处理器1501与其他元件(例如收发器)配合实现。处理器1501可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器1501中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器1501可以是通用处理器、数字信号处理器(DigitalSignalProcessor,DSP)、专用集成电路(ApplicationSpecific IntegratedCircuit,ASIC)、现成可编程门阵列(FieldProgrammableGateArray,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本发明实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本发明实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器1502,处理器1501读取存储器1502中的信息,结合其硬件完成上述方法的步骤。
可以理解的是,本发明实施例描述的这些实施例可以用硬件、软件、固件、中间件、微码或其组合来实现。对于硬件实现,处理单元可以实现在一个或多个专用集成电路(ApplicationSpecificIntegratedCircuits,ASIC)、数字信号处理器(DigitalSignalProcessing,DSP)、数字信号处理设备(DSPDevice,DSPD)、可编程逻辑设备(ProgrammableLogicDevice,PLD)、现场可编程门阵列(Field-ProgrammableGateArray,FPGA)、通用处理器、控制器、微控制器、微处理器、用于执行本申请功能的其它电子单元或其组合中。
对于软件实现,可通过执行本发明实施例功能的模块(例如过程、函数等)来实现本发明实施例的技术。软件代码可存储在存储器中并通过处理器1501执行。存储器可以在处理器1501中或在处理器1501外部实现。
在一个实施例中,校验数据包括用户会话信息和用户签名信息,用户会话信息用于指示与零信任代理节点建立会话连接过程中生成的地址信息和会话计数信息,用户签名信息用于指示发送初始数据包的用户的身份参数,数据校验规则包括用户会话信息校验规则及数据签名校验规则;处理器,具体用于根据用户会话信息校验规则对待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果;根据数据签名校验规则对待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果;根据第一数据校验结果及第二数据校验结果,生成数据校验结果。
在一个实施例中,处理器,还用于根据地址信息确定待传输数据包的网络地址类型;网络地址类型包括公网地址类型及私网地址类型;根据待传输数据包的网络地址类型,确定是否需要对待传输数据包中的源网络地址进行更新,生成中间数据包;根据用户会话信息校验规则对中间数据包中的会话计数信息进行数据校验,生成第一数据校验结果。
在一个实施例中,处理器,还用于若待传输数据包的网络地址类型为私网地址类型,则将待传输数据包作为中间数据包;若待传输数据包的网络地址类型为公网地址类型,则将待传输数据包中的源网络地址更新为待传输数据包对应的公网地址,生成中间数据包。
在一个实施例中,处理器,还用于根据数据签名校验规则对中间数据包中的用户签名信息进行数据校验,生成第二数据校验结果。
在一个实施例中,处理器,还用于从待传输数据包中确定校验未通过的数据包,根据校验未通过的数据包生成异常会话信息;发送器,还用于将异常会话信息发送至零信任控制器;异常会话信息用于指示零信任控制器对异常会话信息进行分析及向零信任代理节点发送会话终止指令。
图16是本发明实施例提供的零信任控制器的结构示意图。图16所示的零信任控制器1600包括:至少一个处理器1601、存储器1602、至少一个网络接口1604。零信任控制器1600中的各个组件通过总线系统1605耦合在一起。可理解,总线系统1605用于实现这些组件之间的连接通信。总线系统1605除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图16中将各种总线都标为总线系统1605。另外,本发明实施例中,还包括收发器1606,收发器可以是多个元件,即包括发送器和接收器,提供用于在传输介质上与各种其他装置通信的单元。
可以理解,本发明实施例中的存储器1602可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-OnlyMemory,ROM)、可编程只读存储器(ProgrammableROM,PROM)、可擦除可编程只读存储器(ErasablePROM,EPROM)、电可擦除可编程只读存储器(ElectricallyEPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(RandomAccessMemory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(StaticRAM,SRAM)、动态随机存取存储器(DynamicRAM,DRAM)、同步动态随机存取存储器(SynchronousDRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(DoubleDataRate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(SynchlinkDRAM,SLDRAM)和直接内存总线随机存取存储器(DirectRambusRAM,DRRAM)。本发明实施例描述的系统和方法的存储器1602旨在包括但不限于这些和任意其它适合类型的存储器。
在一些实施方式中,存储器1602存储了如下的元素,可执行模块或者数据结构,或者他们的子集,或者他们的扩展集:操作系统1602a。其中,操作系统1602a,包含各种系统程序,例如框架层、核心库层、驱动层等,用于实现各种基础业务以及处理基于硬件的任务。
在本发明实施例中,通过调用存储器1602存储的程序或指令,使得接收器,用于接收零信任代理节点发送的用户证书和用户标准会话信息;处理器1601,用于根据用户证书和用户标准会话信息,生成数据校验规则;发送器,用于向零信任网关发送数据校验规则;数据校验规则用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。
上述本发明实施例揭示的部分或者全部方法还可以应用于处理器1601中,或者由处理器1601实现,或者由处理器1601与其他元件(例如收发器)配合实现。处理器1601可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器1601中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器1601可以是通用处理器、数字信号处理器(DigitalSignalProcessor,DSP)、专用集成电路(ApplicationSpecific IntegratedCircuit,ASIC)、现成可编程门阵列(FieldProgrammableGateArray,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本发明实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本发明实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块 可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器1602,处理器1601读取存储器1602中的信息,结合其硬件完成上述方法的步骤。
可以理解的是,本发明实施例描述的这些实施例可以用硬件、软件、固件、中间件、微码或其组合来实现。对于硬件实现,处理单元可以实现在一个或多个专用集成电路(ApplicationSpecificIntegratedCircuits,ASIC)、数字信号处理器(DigitalSignalProcessing,DSP)、数字信号处理设备(DSPDevice,DSPD)、可编程逻辑设备(ProgrammableLogicDevice,PLD)、现场可编程门阵列(Field-ProgrammableGateArray,FPGA)、通用处理器、控制器、微控制器、微处理器、用于执行本申请功能的其它电子单元或其组合中。
对于软件实现,可通过执行本发明实施例功能的模块(例如过程、函数等)来实现本发明实施例的技术。软件代码可存储在存储器中并通过处理器1601执行。存储器可以在处理器1601中或在处理器1601外部实现。
图17是本发明实施例提供的零信任代理节点的结构示意图。图17所示的零信任代理节点1700包括:至少一个处理器1701、存储器1702、至少一个网络接口1704。零信任代理节点1700中的各个组件通过总线系统1705耦合在一起。可理解,总线系统1705用于实现这些组件之间的连接通信。总线系统1705除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图17中将各种总线都标为总线系统1705。另外,本发明实施例中,还包括收发器1706,收发器可以是多个元件,即包括发送器和接收器,提供用于在传输介质上与各种其他装置通信的单元。
可以理解,本发明实施例中的存储器1702可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-OnlyMemory,ROM)、可编程只读存储器(ProgrammableROM,PROM)、可擦除可编程只读存储器(ErasablePROM,EPROM)、电可擦除可编程只读存储器(ElectricallyEPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(RandomAccessMemory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(StaticRAM,SRAM)、动态随机存取存储器(DynamicRAM,DRAM)、同步动态随机存取存储器(SynchronousDRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(DoubleDataRate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(SynchlinkDRAM,SLDRAM)和直接内存总线随机存取存储器(DirectRambusRAM,DRRAM)。本发明实施例描述的系统和方法的存储器1702旨在包括但不限于这些和任意其它适合类型的存储器。
在一些实施方式中,存储器1702存储了如下的元素,可执行模块或者数据结构,或者他们的子集,或者他们的扩展集:操作系统1702a。其中,操作系统1702a,包含各种系统程序,例如框架层、核心库层、驱动层等,用于实现各种基础业务以及处理基于硬件的任务。
在本发明实施例中,通过调用存储器1702存储的程序或指令,使得接收器,用于获取用户证书、用户标准会话信息和初始数据包;发送器,用于将用户证书及用户标准会话信息发送至零信任控制器,以使零信任控制器基于用户证书及用户标准会话信息,生成数据校验规则,向零信任网关发送数据校验规则;处理器1701和发送器,用于向初始数据包中添加校验数据,生成待传输数据包,并将待传输数据包发送至零信任网关;待传输数据包用于指示零信任网关根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。
上述本发明实施例揭示的部分或者全部方法还可以应用于处理器1701中,或者由处理器1701实现,或者由处理器1701与其他元件(例如收发器)配合实现。处理器1701可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器1701中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器1701可以是通用处理器、数字信号处理器(DigitalSignalProcessor,DSP)、专用集成电路(ApplicationSpecific IntegratedCircuit,ASIC)、现成可编程门阵列(FieldProgrammableGateArray,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本发明实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本发明实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器1702,处理器1701读取存储器1702中的信息,结合其硬件完成上述方法的步骤。
可以理解的是,本发明实施例描述的这些实施例可以用硬件、软件、固件、中间件、微码或其组合来实现。对于硬件实现,处理单元可以实现在一个或多个专用集成电路 (ApplicationSpecificIntegratedCircuits,ASIC)、数字信号处理器(DigitalSignalProcessing,DSP)、数字信号处理设备(DSPDevice,DSPD)、可编程逻辑设备(ProgrammableLogicDevice,PLD)、现场可编程门阵列(Field-ProgrammableGateArray,FPGA)、通用处理器、控制器、微控制器、微处理器、用于执行本申请功能的其它电子单元或其组合中。
对于软件实现,可通过执行本发明实施例功能的模块(例如过程、函数等)来实现本发明实施例的技术。软件代码可存储在存储器中并通过处理器1701执行。存储器可以在处理器1701中或在处理器1701外部实现。
在一个实施例中,提供了一种计算机可读存储介质,其上存储有计算机程序,该计算机程序被处理器执行时实现上述各方法实施例中的步骤。
在一个实施例中,提供了一种计算机程序产品,包括计算机程序,该计算机程序被处理器执行时实现上述各方法实施例中的步骤。
需要说明的是,本申请所涉及的用户信息(包括但不限于用户设备信息、用户个人信息等)和数据(包括但不限于用于分析的数据、存储的数据、展示的数据等),均为经用户授权或者经过各方充分授权的信息和数据,且相关数据的收集、使用和处理需要遵守相关国家和地区的相关法律法规和标准。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成的,计算机程序可存储于一非易失性计算机可读取存储介质中,该计算机程序在执行时,可包括如上述各方法的实施例的流程。其中,本申请所提供的各实施例中所使用的对存储器、数据库或其它介质的任何引用,均可包括非易失性和易失性存储器中的至少一种。非易失性存储器可包括只读存储器(Read-Only Memory,ROM)、磁带、软盘、闪存、光存储器、高密度嵌入式非易失性存储器、阻变存储器(ReRAM)、磁变存储器(Magnetoresistive Random Access Memory,MRAM)、铁电存储器(Ferroelectric Random Access Memory,FRAM)、相变存储器(Phase Change Memory,PCM)、石墨烯存储器等。易失性存储器可包括随机存取存储器(Random Access Memory,RAM)或外部高速缓冲存储器等。作为说明而非局限,RAM可以是多种形式,比如静态随机存取存储器(Static Random Access Memory,SRAM)或动态随机存取存储器(Dynamic Random Access Memory,DRAM)等。本申请所提供的各实施例中所涉及的数据库可包括关系型数据库和非关系型数据库中至少一种。非关系型数据库可包括基于区块链的分布式数据库等,不限于此。本申请所提供的各实施例中所涉及的处理器可为通用处理器、中央处理器、图形处理器、数字信号处理器、可编程逻辑器、基于量子计算的数据处理逻辑器等,不限于此。
上述数据传输方法、装置、计算机设备、存储介质和程序产品,接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;待传输数据包为零信任代理节点在初始数据包中添加校验数据后得到的;根据数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据数据校验结果确定是否将待传输数据包传输至数据库。本申请实施例中的零信任代理节点能够在初始数据包中添加校验数据,得到重新封装的待传输数据包。从而,零信任网关能够接收零信任控制器发送的数据校验规则以及零信任代理节点发送的、重新封装的待传输数据包,并根据数据校验规则对重新封装的待传输数据包中的校验数据进行数据校验,得到较准确的数据校验结果。进而,能够根据较准确的数据校验结果,确定是否将待传输数据包传输至数据库。由于本申请需要先根据数据校验规则对重新封装的待传输数据包中的校验数据进行数据校验,且本申请只能对数据校验通过的待传输数据包进行传输,因此,能够提高数据传输过程的安全性。
以上实施例的各技术特征可以进行任意的组合,为使描述简洁,未对上述实施例中的各个技术特征所有可能的组合都进行描述,然而,只要这些技术特征的组合不存在矛盾,都应当认为是本说明书记载的范围。
以上实施例仅表达了本申请的几种实施方式,其描述较为具体和详细,但并不能因此而理解为对本申请专利范围的限制。应当指出的是,对于本领域的普通技术人员来说,在不脱离本申请构思的前提下,还可以做出若干变形和改进,这些都属于本申请的保护范围。因此,本申请的保护范围应以所附权利要求为准。

Claims (21)

  1. 一种数据传输方法,应用于零信任通信网络中的零信任网关中,所述方法包括:
    接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;所述待传输数据包为所述零信任代理节点在初始数据包中添加校验数据后得到的;
    根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;以及
    根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  2. 根据权利要求1所述的方法,其中,所述校验数据包括用户会话信息和用户签名信息,所述用户会话信息用于指示与所述零信任代理节点建立会话连接过程中生成的地址信息和会话计数信息,所述用户签名信息用于指示发送所述初始数据包的用户的身份参数,所述数据校验规则包括用户会话信息校验规则及数据签名校验规则;所述根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果,包括:
    根据所述用户会话信息校验规则对所述待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果;
    根据所述数据签名校验规则对所述待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果;以及
    根据所述第一数据校验结果及所述第二数据校验结果,生成所述数据校验结果。
  3. 根据权利要求2所述的方法,其中,所述根据所述用户会话信息校验规则对所述待传输数据包中的用户会话信息进行数据校验,生成第一数据校验结果,包括:
    根据所述地址信息确定所述待传输数据包的网络地址类型;所述网络地址类型包括公网地址类型及私网地址类型;
    根据所述待传输数据包的网络地址类型,确定是否需要对所述待传输数据包中的源网络地址进行更新,生成中间数据包;以及
    根据所述用户会话信息校验规则对所述中间数据包中的会话计数信息进行数据校验,生成所述第一数据校验结果。
  4. 根据权利要求3所述的方法,其中,所述根据所述待传输数据包的网络地址类型,确定是否需要对所述待传输数据包中的源网络地址进行更新,生成中间数据包,包括:
    若所述待传输数据包的网络地址类型为所述私网地址类型,则将所述待传输数据包作为所述中间数据包;以及
    若所述待传输数据包的网络地址类型为所述公网地址类型,则将所述待传输数据包中的源网络地址更新为所述待传输数据包对应的公网地址,生成所述中间数据包。
  5. 根据权利要求3或4所述的方法,其中,所述根据所述数据签名校验规则对所述待传输数据包中的用户签名信息进行数据校验,生成第二数据校验结果,包括:
    根据所述数据签名校验规则对所述中间数据包中的用户签名信息进行数据校验,生成所述第二数据校验结果。
  6. 根据权利要求1-5任一项所述的方法,其中,所述方法还包括:
    从所述待传输数据包中确定校验未通过的数据包,根据所述校验未通过的数据包生成异常会话信息;
    将所述异常会话信息发送至所述零信任控制器;所述异常会话信息用于指示所述零信任控制器对所述异常会话信息进行分析及向所述零信任代理节点发送会话终止指令。
  7. 根据权利要求1-5任一项所述的方法,其中,所述数据校验规则是根据用户标准签名信息和用户标准会话信息生成的,其中,所述用户标准签名信息包括用户公钥信息以及用户身份标准信息。
  8. 根据权利要求7所述的方法,其中,所述用户标准签名信息是在用户证书验证通过的情况下,从所述用户证书中获取的。
  9. 一种数据传输方法,应用于零信任通信网络中的零信任控制器中,所述方法包括:
    接收零信任代理节点发送的用户证书和用户标准会话信息;
    根据所述用户证书和用户标准会话信息,生成数据校验规则;以及
    向零信任网关发送所述数据校验规则;所述数据校验规则用于指示所述零信任网关根据所述数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果,并根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  10. 根据权利要求9所述的方法,其中,所述根据所述用户证书和所述用户标准会话信息,生成所述数据校验规则,包括:
    对所述用户证书进行验证,生成证书验证结果;
    在证书验证结果为证书验证通过的情况下,从所述用户证书中获取用户标准签名信息,其中,所述用户标准签名信息包括用户公钥信息以及用户标准身份信息;以及
    根据所述用户标准签名信息和所述用户标准会话信息,生成所述数据校验规则。
  11. 一种数据传输方法,应用于零信任通信网络中的零信任代理节点中,所述方法包括:
    获取用户证书、用户标准会话信息和初始数据包;
    将所述用户证书及所述用户标准会话信息发送至零信任控制器,以使所述零信任控制器基于所述用户证书及所述用户标准会话信息,生成数据校验规则,向零信任网关发送所述数据校验规则;以及
    向所述初始数据包中添加校验数据,生成待传输数据包,并将所述待传输数据包发送至所述零信任网关;所述待传输数据包用于指示所述零信任网关根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果,并根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  12. 根据权利要求11所述的数据传输方法,其中,所述用户证书在验证通过的情况下,使得所述零信任控制器从所述用户证书中获取用户标准签名信息并基于所述标准签名信息和所述用户标准会话信息生成数据校验规则,其中,所述用户标准签名信息包括用户公钥信息以及用户身份标准信息。
  13. 一种数据传输装置,应用于零信任通信网络中的零信任网关中,所述装置包括:
    待传输数据包接收模块,用于接收零信任控制器发送的数据校验规则和零信任代理节点发送的待传输数据包;所述待传输数据包为所述零信任代理节点在初始数据包中添加校验数据后得到的;
    数据校验模块,用于根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;
    数据传输模块,用于根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  14. 一种数据传输装置,应用于零信任通信网络中的零信任控制器中,所述装置包括:
    信息接收模块,用于接收零信任代理节点发送的用户证书和用户标准会话信息;
    数据校验规则生成模块,用于根据所述用户证书和用户标准会话信息,生成数据校验规则;
    数据校验规则发送模块,用于向零信任网关发送所述数据校验规则;所述数据校验规则用于指示所述零信任网关根据所述数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  15. 一种数据传输装置,应用于零信任通信网络中的零信任代理节点中,所述装置包括:
    信息获取模块,用于获取用户证书、用户标准会话信息和初始数据包;
    信息发送数据校验模块,用于将所述用户证书及所述用户标准会话信息发送至零信任控制器,以使所述零信任控制器基于所述用户证书及所述用户标准会话信息,生成数据校验规则,向零信任网关发送所述数据校验规则;
    待传输数据包生成模块,用于向所述初始数据包中添加校验数据,生成待传输数据包,并将所述待传输数据包发送至所述零信任网关;所述待传输数据包用于指示所述零信任网关根据所述数据校验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  16. 一种零信任网关,包括收发器、处理器和存储器,所述存储器存储有计算机程序,所述处理器执行所述计算机程序,用于执行如权利要求1至8中任一项所述的方法的步骤。
  17. 一种零信任控制器,包括收发器、处理器和存储器,所述存储器存储有计算机程序,所述处理器执行所述计算机程序,用于控制所述收发器接收零信任代理节点发送的用户证书和用户标准会话信息;
    用于控制所述处理器根据所述用户证书和用户标准会话信息,生成数据校验规则;
    用于控制所述收发器向零信任网关发送所述数据校验规则;所述数据校验规则用于指示所述零信任网关根据所述数据校验规则对待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  18. 一种零信任代理节点,包括收发器、处理器和存储器,所述存储器存储有计算机程序,所述处理器执行所述计算机程序,用于控制所述收发器获取用户证书、用户标准会话信息和初始数据包;
    用于控制所述收发器将所述用户证书及所述用户标准会话信息发送至零信任控制器,以使所述零信任控制器基于所述用户证书及所述用户标准会话信息,生成数据校验规则,向零信任网关发送所述数据校验规则;
    用于控制所述处理器和所述收发器向所述初始数据包中添加校验数据,生成待传输数据包,并将所述待传输数据包发送至所述零信任网关;所述待传输数据包用于指示所述零信任网关根据所述数据校 验规则对所述待传输数据包中的校验数据进行数据校验,得到数据校验结果;根据所述数据校验结果确定是否将所述待传输数据包传输至数据库。
  19. 一种计算机可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现权利要求1至12中任一项所述的方法的步骤。
  20. 一种计算机程序产品,包括计算机程序,该计算机程序被处理器执行时实现权利要求1至12中任一项所述的方法的步骤。
  21. 一种装置,被配置为执行权利要求1至12任一项的方法。
PCT/CN2023/140207 2023-07-25 2023-12-20 数据传输方法、装置、计算机设备、存储介质和程序产品 Pending WO2025020437A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202310913190.5A CN116633698B (zh) 2023-07-25 2023-07-25 数据传输方法、装置、计算机设备、存储介质和程序产品
CN202310913190.5 2023-07-25

Publications (1)

Publication Number Publication Date
WO2025020437A1 true WO2025020437A1 (zh) 2025-01-30

Family

ID=87617455

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/140207 Pending WO2025020437A1 (zh) 2023-07-25 2023-12-20 数据传输方法、装置、计算机设备、存储介质和程序产品

Country Status (2)

Country Link
CN (1) CN116633698B (zh)
WO (1) WO2025020437A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN119652685A (zh) * 2025-02-19 2025-03-18 中体彩印务技术有限公司 一种可变数据的验证方法及其系统

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116633698B (zh) * 2023-07-25 2023-10-31 中国电信股份有限公司 数据传输方法、装置、计算机设备、存储介质和程序产品

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113051602A (zh) * 2021-01-22 2021-06-29 东南大学 一种基于零信任架构的数据库细粒度访问控制方法
KR102333553B1 (ko) * 2021-05-07 2021-12-01 프라이빗테크놀로지 주식회사 컨트롤러 기반의 네트워크 접속을 제어하기 위한 시스템 및 그에 관한 방법
CN113992402A (zh) * 2021-10-27 2022-01-28 北京房江湖科技有限公司 一种基于零信任策略的访问控制方法、系统及介质
CN114553568A (zh) * 2022-02-25 2022-05-27 重庆邮电大学 一种基于零信任单包认证与授权的资源访问控制方法
CN114679293A (zh) * 2021-06-15 2022-06-28 腾讯云计算(北京)有限责任公司 基于零信任安全的访问控制方法、设备及存储介质
CN116633698A (zh) * 2023-07-25 2023-08-22 中国电信股份有限公司 数据传输方法、装置、计算机设备、存储介质和程序产品

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103246574B (zh) * 2012-02-10 2015-11-11 阿里巴巴集团控股有限公司 数据准确性的校验方法及装置
CN105930409A (zh) * 2016-04-18 2016-09-07 深圳市永兴元科技有限公司 基于动态生成规则的数据校验方法及装置
CN111428132B (zh) * 2020-03-18 2023-09-19 腾讯科技(深圳)有限公司 数据的校验方法及装置、计算机存储介质、电子设备
CN111736811A (zh) * 2020-06-10 2020-10-02 苏宁云计算有限公司 表单数据校验方法、系统、服务器和用户终端
CN113507434B (zh) * 2021-05-28 2022-11-29 清华大学 一种通信网络中的数据安全传输方法、节点和系统
CN115701019B (zh) * 2021-07-14 2025-07-25 腾讯科技(深圳)有限公司 零信任网络的访问请求处理方法、装置及电子设备
CN113992354A (zh) * 2021-09-28 2022-01-28 新华三信息安全技术有限公司 一种身份验证方法、装置、设备及机器可读存储介质
CN114003432B (zh) * 2021-09-28 2025-03-21 济南浪潮数据技术有限公司 参数校验方法、装置、计算机设备和存储介质
CN113885876A (zh) * 2021-10-09 2022-01-04 北京沃东天骏信息技术有限公司 一种参数校验方法、装置、存储介质及计算机系统
CN116471586A (zh) * 2022-01-12 2023-07-21 腾讯科技(深圳)有限公司 一种数据处理方法、装置以及可读存储介质

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113051602A (zh) * 2021-01-22 2021-06-29 东南大学 一种基于零信任架构的数据库细粒度访问控制方法
KR102333553B1 (ko) * 2021-05-07 2021-12-01 프라이빗테크놀로지 주식회사 컨트롤러 기반의 네트워크 접속을 제어하기 위한 시스템 및 그에 관한 방법
CN114679293A (zh) * 2021-06-15 2022-06-28 腾讯云计算(北京)有限责任公司 基于零信任安全的访问控制方法、设备及存储介质
CN113992402A (zh) * 2021-10-27 2022-01-28 北京房江湖科技有限公司 一种基于零信任策略的访问控制方法、系统及介质
CN114553568A (zh) * 2022-02-25 2022-05-27 重庆邮电大学 一种基于零信任单包认证与授权的资源访问控制方法
CN116633698A (zh) * 2023-07-25 2023-08-22 中国电信股份有限公司 数据传输方法、装置、计算机设备、存储介质和程序产品

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN119652685A (zh) * 2025-02-19 2025-03-18 中体彩印务技术有限公司 一种可变数据的验证方法及其系统

Also Published As

Publication number Publication date
CN116633698B (zh) 2023-10-31
CN116633698A (zh) 2023-08-22

Similar Documents

Publication Publication Date Title
US11784788B2 (en) Identity management method, device, communications network, and storage medium
WO2022095244A1 (zh) 跨链交易方法、系统、装置、设备和存储介质
WO2022143798A1 (zh) 跨链交易的验证方法、终端设备及可读存储介质
CN110177124B (zh) 基于区块链的身份认证方法及相关设备
CN108769010B (zh) 节点受邀注册的方法和装置
WO2025020437A1 (zh) 数据传输方法、装置、计算机设备、存储介质和程序产品
CN113255014A (zh) 一种基于区块链的数据处理方法以及相关设备
CN112398798B (zh) 一种网络电话处理方法、装置及终端
CN111367923A (zh) 数据处理方法、装置、节点设备及存储介质
US12519757B2 (en) Methods, devices and system related to a distributed ledger and user identity attribute
CN117880180A (zh) 基于金融联盟链的数据传输方法、装置、设备、介质
CN119788436B (zh) 数据保护方法、设备以及存储介质
CN107332833A (zh) 校验方法及装置
CN113206746B (zh) 一种数字证书管理方法和装置
CN115333782A (zh) 数据发送方法、数据接收方法、存储介质及计算机设备
CN114978698A (zh) 网络接入方法、目标终端、凭证管理网元及验证网元
WO2025000830A9 (zh) 基于区块链的交易管理方法、装置、计算机及存储介质
CN117411858A (zh) 基于区块链的数据处理方法、装置、设备及可读存储介质
CN118474738A (zh) 认证方法、装置、相关设备及存储介质
CN115941285A (zh) 一种数据获取方法、系统、电子设备及存储介质
CN111224777A (zh) Sdn网络组播成员信息加密方法、系统、终端及存储介质
CN117675244B (zh) 基于集群环境下任务密钥分发方法及装置
CN115460223B (zh) 一种数据传输方法、节点设备及数据传输系统
CN113472561B (zh) 一种区块链数据处理方法及其设备
CN118433257A (zh) 基于区块链的节点资源处理方法、装置、设备和存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23946512

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE