Network information security encryption method and system
Through dynamic matrix reorganization and multi-layer encryption technology, traditional encryption algorithms are solved, and efficient and secure real-time encryption of big data is achieved.
Patent Information
- Application Number
- CN202510650974.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-07-08
AI Technical Summary
In the existing encryption methods, traditional symmetric encryption algorithms are susceptible to man-in-the-middle attacks, asymmetric encryption algorithms are inefficient in computing efficiency, and fixed encryption granularity is susceptible to brute-force cracking, making it difficult to meet the real-time encryption needs of big data.
Dynamic matrix recombination technology is adopted, based on data uniformity parameters and neighborhood complexity analysis, combined with dynamic random number generation algorithm and asymmetric key, multi-layer protection is formed through multiple rounds of permutation encryption and AES-CBC mode, and the encryption granularity is dynamically adjusted and the dynamic key is generated.
It improves the anti-brute force cracking ability, reduces the success rate of man-in-the-middle attacks, improves encryption efficiency and security, and adapts to the real-time encryption needs of big data.
Smart Images

Figure CN120281566A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information encryption technology, and particularly relates to a network information security encryption method and system. Background Art
[0002] Today in the era of big data, the Internet is further developing towards mobility, and emerging content such as social networks is also constantly emerging. People can easily obtain the information they want. However, with the continuous development of demands and businesses, the data generated is also growing geometrically. Large-scale data sets have inestimable value, and the relationships between data will play an important role in the operation and decision-making of companies and enterprises. While big data centrally processes and stores massive amounts of data, its security issues will also face increasing challenges. The data saved by users is easily stolen by others, causing losses to users.
[0003] The existing encryption methods have the following drawbacks: Traditional symmetric encryption algorithms (such as AES, DES) are fast, but there are security risks in key distribution and management, and the keys are easily intercepted by man-in-the-middle attacks. Asymmetric encryption (such as RSA, ECC) solves the key distribution problem, but has low computational efficiency and is difficult to meet the real-time big data encryption requirements. In addition, the fixed encryption granularity and static key mechanism are vulnerable to brute-force cracking threats.
[0004] Therefore, there is an urgent need to design a network information security encryption method and system to solve the above problems. Summary of the Invention
[0005] The purpose of the present invention is to provide a network information security encryption method and system to solve the above deficiencies in the prior art.
[0006] To achieve the above purpose, the present invention provides the following technical solutions:
[0007] A network information security encryption method and system, comprising the following steps:
[0008] Step 1, convert network information data into a decimal sequence and construct a matrix to be encrypted;
[0009] Step 2, generate a reconstructed merged row set based on the uniformity parameter of the elements in the matrix to be encrypted and the difference value of adjacent row features;
[0010] Step 3, determine the basic unit row sequence and the basic unit column sequence through neighborhood complexity analysis;
[0011] Step 4, perform multi-round permutation encryption on the basic unit rows and columns in combination with a dynamic random number generation algorithm, and output a ciphertext matrix;
[0012] Among them, for the multi-round permutation encryption, an asymmetric key is used to dynamically update the permutation parameters for each encryption round.
[0013] Preferably, the construction of the matrix to be encrypted includes: converting the original data into a binary sequence, grouping it by 8 bits, converting it into a decimal value, and constructing an m×n matrix with a preset number of row elements n.
[0014] Preferably, the calculation of the uniformity parameter satisfies: where Ha is the uniformity parameter of the elements in the a-th row, and Xa,i is the corresponding element value.
[0015] Preferably, the calculation of the feature difference value uses: Δa = e -∣Sa-Sa-1∣ +e -∣Sa-Sa+1∣
[0016] In the formula, Sa is the feature parameter of the a-th row, and the threshold th is set to 0.85±0.05.
[0017] Preferably, the neighborhood complexity analysis includes: calculating the mean difference degree of adjacent elements for each element, and determining the distribution characteristics of the element values through the information entropy formula: C(u) = -∑p(u)log2p(u).
[0018] Preferably, the dynamic random number generation algorithm includes: generating a permutation sequence based on the SHA-256 hash chain, and updating the hash seed for each encryption round.
[0019] Preferably, in the multi-round permutation encryption: after each round of encryption, the basic unit rows and columns are reconstructed, and the AES-CBC mode encryption is superimposed in the last round of encryption.
[0020] Preferably, it further includes a data destruction mechanism: marking the encrypted data that has not responded overdue in blocks, and performing physical deletion through a secure erasure algorithm.
[0021] Preferably, it includes: a matrix conversion module, a feature analysis module, a dynamic encryption module, and a key management server cluster; the key management server cluster stores the key version information using blockchain technology.
[0022] Preferably, the dynamic encryption module includes: a parallel computing unit accelerated by GPU, supporting hardware-level encryption of both the SM4 / AES algorithms.
[0023] In the above technical solution, a network information security encryption method and system provided by the present invention adopt dynamic matrix recombination, and based on the data uniformity parameter and neighborhood complexity analysis, realize the adaptive adjustment of the encryption granularity, improve the anti-brute-force cracking ability compared with the traditional fixed matrix encryption, and at the same time, for the asymmetric fusion encryption, the permutation parameters for each round are dynamically generated by the RSA public key, combined with the AES-CBC mode to form a multi-layer protection, reducing the success rate of resisting man-in-the-middle attacks. Description of the Drawings
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings.
[0025] Figure 1 It is a schematic diagram of steps provided for an embodiment of a network information security encryption method and system of the present invention.
[0026] Figure 2 It is a schematic diagram of the comparison of the time-consuming of mainstream encryption algorithms provided for an embodiment of a network information security encryption method and system of the present invention.
[0027] Figure 3 It is a schematic diagram of the anti-brute-force cracking ability test provided for an embodiment of a network information security encryption method and system of the present invention. Detailed Embodiments
[0028] In order to enable those skilled in the art to better understand the technical solutions of the present invention, the following will further introduce the present invention in detail in conjunction with the drawings.
[0029] As Figures 1-3 shown, a network information security encryption method and system provided by an embodiment of the present invention include the following steps:
[0030] Step 1: Convert the network information data into a decimal sequence and construct a matrix to be encrypted;
[0031] Step 2: Generate a reconstructed merged row set based on the uniformity parameter of the elements in the matrix to be encrypted and the difference value of adjacent row features;
[0032] Step 3: Determine the basic unit row sequence and the basic unit column sequence through neighborhood complexity analysis;
[0033] Step 4: Combine the dynamic random number generation algorithm to perform multi-round permutation encryption on the basic unit rows and columns, and output the ciphertext matrix;
[0034] Among them, the multi-round permutation encryption uses an asymmetric key to dynamically update the permutation parameters for each encryption round.
[0035] Preferably, the construction of the matrix to be encrypted includes: converting the original data into a binary sequence, grouping it by 8 bits, converting it into a decimal value, and constructing an m×n matrix with a preset number of row elements n.
[0036] Preferably, the calculation of the uniformity parameter satisfies: Among them, Ha is the uniformity parameter of the elements in the a-th row, and Xa,i is the corresponding element value.
[0037] Preferably, the calculation of the feature difference value adopts: Δa = e -∣Sa-Sa-1∣ +e -∣Sa-Sa+1∣
[0038] In the formula, Sa is the feature parameter of the a-th row, and the threshold th is set to 0.85 ± 0.05.
[0039] Preferably, the neighborhood complexity analysis includes: calculating the mean difference degree of adjacent elements for each element, and determining the distribution characteristics of element values through the information entropy formula: C(u) = -∑p(u)log2p(u).
[0040] Preferably, the dynamic random number generation algorithm includes: generating a permutation sequence based on the SHA-256 hash chain, and updating the hash seed in each encryption round; generating a dynamic permutation sequence based on the SHA-256 hash chain, reducing the computational redundancy of multiple rounds of permutation, and the computational amount is reduced compared with the traditional method.
[0041] Preferably, in the multi-round permutation encryption: the basic unit rows and columns are reconstructed after each round of encryption, and the last round of encryption is superimposed with AES-CBC mode encryption.
[0042] Preferably, it further includes a data destruction mechanism: block-marking the encrypted data that has not responded overdue, and performing physical deletion through a secure erasure algorithm.
[0043] Preferably, it includes: a matrix conversion module, a feature analysis module, a dynamic encryption module, and a key management server cluster; the key management server cluster stores key version information using blockchain technology; the master key is distributedly stored in blockchain nodes, the session key is dynamically generated by the KDC center and encrypted for transmission, supporting a 72-hour automatic destruction mechanism, and reducing the risk of key leakage.
[0044] Preferably, the dynamic encryption module includes: a parallel computing unit accelerated by GPU, supporting hardware-level encryption of SM4 / AES dual algorithms.
[0045] The GPU parallel computing unit is used to accelerate matrix recombination and encryption operations, and the encryption time is shortened compared with the pure software solution.
[0046] Embodiment 1
[0047] (1) Data preprocessing and matrix construction
[0048] Data encoding conversion
[0049] Convert the original network data into a binary sequence through Unicode encoding, and convert every 8-bit binary code into a decimal value (e.g., binary "10101011" → decimal "171") to construct an m×n matrix to be encrypted. For example, after conversion, a financial transaction message forms a 128×128 matrix, and each row contains the decimal encoding of elements such as transaction amount and timestamp.
[0050] Calculation of uniformity parameter
[0051] Calculate the uniformity parameter based on the maximum value, minimum value, and degree of dispersion of the elements within the matrix rows:
[0052]
[0053] The parameter is used to identify the data distribution characteristics. When Ha < 0.3 for a certain row, it is determined as a low-dispersion row and needs to be merged preferentially;
[0054] Dynamic row reconstruction mechanism
[0055] Based on the difference value Δa = e of adjacent row features -∣Sa-Sa-1∣ +e -∣Sa-Sa+1∣ , set the threshold th = 0.85, and merge the rows with difference values lower than the threshold. For example, if the difference value between two consecutive rows of blood pressure monitoring values in a medical data matrix is 0.72, the row merging operation is triggered;
[0056] (2) Multi-level encryption process
[0057] Generation of basic unit rows and columns
[0058] Determine the basic encryption unit through neighborhood complexity analysis:
[0059] C(u) = -∑p(u)log2p(u)
[0060] Calculate the mean difference degree information entropy of an element and its adjacent elements. When C(u) > 2.5, it is determined as a high-complexity area and used as an independent encryption unit.
[0061] Dynamic permutation encryption algorithm
[0062] Use the SHA-256 hash chain to generate a random number sequence, and the permutation parameters in each round are dynamically updated by the asymmetric key;
[0063] Adopt the AES-CBC and RSA hybrid encryption mode: After the first-round permutation, the matrix is encrypted by AES, and in the second round, the public key of the receiver is used for RSA secondary encryption.
[0064] Key lifecycle management
[0065] The master key is stored in a blockchain in a distributed manner, and each session key is generated by the KDC center and encrypted for transmission
[0066] Key destruction mechanism: For keys that have not been used for more than 72 hours, the magnetic traces on the storage medium are erased through physical overwrite technology.
[0067] Example 2
[0068] Comparison of the time consumption of mainstream encryption algorithms (tested based on a 10TB dataset)
[0069]
[0070]
[0071] Example 3
[0072] Test of anti-brute-force cracking ability (based on the NIST test suite)
[0073] (I) Algorithm-level protection ability
[0074]
[0075] (II) System-level protection mechanism
[0076] 1. Dynamic matrix reorganization technology
[0077] By calculating the uniformity parameter of the data matrix in real time (reconstruction is triggered when H a < 0.3), the encryption form of the same data changes 1200 times per second, and the success rate of brute-force cracking is reduced to 0.03%;
[0078] 2. Multi-factor authentication mechanism
[0079] Biometric authentication extends the cracking time to 30 years
[0080] Dynamic token authentication makes the success rate of replay attacks < 0.01%;
[0081] 3. Key round optimization strategy
[0082] When the number of rounds of AES-256 increases from 10 rounds to 14 rounds, the cracking time increases from 1000 hours to 1400 hours, but the encryption time only increases by 0.08m.
[0083] Only some exemplary embodiments of the present invention are described in an illustrative manner above. Undoubtedly, for those of ordinary skill in the art, the described embodiments can be modified in various different ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.
Claims
1. A network information security encryption method, characterized in that, It includes the following steps: Step 1: Convert network information data into a decimal sequence and construct a matrix to be encrypted; Step 2: Generate a reconstructed merged row set based on the uniformity parameter of the elements in the matrix to be encrypted and the difference value of adjacent row features; Step 3: Determine the basic unit row sequence and the basic unit column sequence through neighborhood complexity analysis; Step 4: Combine the dynamic random number generation algorithm to perform multi-round permutation encryption on the basic unit rows and columns, and output the ciphertext matrix; Among them, the multi-round permutation encryption dynamically updates the permutation parameters for each encryption round using an asymmetric key.
2. A network information security encryption method according to claim 1, characterized in that, The construction of the matrix to be encrypted includes: converting the original data into a binary sequence, grouping it by 8 bits, converting it into a decimal value, and constructing an m×n matrix with a preset number of row elements n.
3. A network information security encryption method according to claim 1, characterized in that, The calculation of the uniformity parameter satisfies: Among them, Ha is the uniformity parameter of the elements in the a-th row, and Xa,i is the corresponding element value.
4. A network information security encryption method according to claim 1, characterized in that The calculation of the characteristic difference value adopts: Δa = e -∣Sa-Sa-1∣ + e -∣Sa-Sa+1∣ In the formula, Sa is the feature parameter of the a-th row, and the threshold th is set to 0.85±0.
05.
5. A network information security encryption method according to claim 1, characterized in that, The neighborhood complexity analysis includes: calculating the mean difference degree of adjacent elements for each element, and determining the element value distribution characteristics through the information entropy formula: C(u)=-∑p(u)log2p(u).
6. A network information security encryption method according to claim 1, characterized in that, The dynamic random number generation algorithm includes: generating a permutation sequence based on the SHA-256 hash chain, and updating the hash seed for each encryption round.
7. A network information security encryption method according to claim 1, characterized in that, In the multi-round permutation encryption: the basic unit rows and columns are reconstructed after each round of encryption, and the last round of encryption is superimposed with AES-CBC mode encryption.
8. A network information security encryption method according to claim 1, characterized in that, It also includes a data destruction mechanism: block-marking the encrypted data that fails to respond overdue, and performing physical deletion through a secure erasure algorithm.
9. A network information security encryption system according to claim 1, comprising the method according to any one of claims 1-9, characterized in that, It includes: A matrix conversion module, a feature analysis module, a dynamic encryption module, and a key management server cluster; the key management server cluster stores key version information using blockchain technology.
10. A network information security encryption system according to claim 1, characterized in that, The dynamic encryption module includes: a parallel computing unit accelerated by GPU, supporting hardware-level encryption of both SM4 / AES algorithms.
Citation Information
Patent Citations
Method and device for generating replacement table
CN115801227A
Enterprise information image encryption method based on chaotic system and biological evolution strategy
CN116346302A
Network information security encryption method and system
CN117201020A
Hardware implementation device and method for Ascon lightweight encryption algorithm
CN118118160A
Information management system and encryption system
WO2008056667A1