Dynamic encryption method and dynamic encryption device for secure transmission

Through dynamic encryption methods and devices, the problem that encryption at rest cannot adapt to complex environments is solved, and the security and reliability of data transmission is improved, adapted to complex network environments, and the risk of data leakage is reduced.

CN120342725APending Publication Date: 2025-07-18LINGSHU TECH CO LTD
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510559671.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, static encryption lacks flexibility and cannot adapt to changes in complex transmission environments. The transmission path security risk assessment is insufficient, resulting in insufficient data transmission security and reliability.

Method used

Provides a dynamic encryption method for secure transmission, and performs security risk fuzzy detection by receiving secure transmission tasks from the user, and performs encryption optimization configuration based on encrypted multimodal factors, and combines transmission path monitoring data to perform dynamic encryption optimization to generate highly adaptable encryption strategies.

Benefits of technology

It improves the security and reliability of data transmission, can dynamically adapt to complex network environments, and effectively reduces the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342725A_ABST
    Figure CN120342725A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic encryption method and a dynamic encryption device for secure transmission, and relates to the technical field of secure encryption and transmission, and the method comprises the steps: receiving a secure transmission task sent by a user side; performing security risk fuzzy detection to obtain a path risk fuzzy detection result; performing encryption optimization configuration to obtain an initial encryption strategy; obtaining current node update monitoring data corresponding to the current transmission node; inputting a transmission security risk prediction channel to obtain a current node prediction risk coefficient; and performing dynamic encryption optimization according to the current node update monitoring data to obtain a current node optimization encryption strategy, and performing secure transmission on communication transmission data. The technical problems that in the prior art, static encryption lacks flexibility, cannot adapt to complex transmission environment changes and transmission path safety risk assessment is insufficient, so that data transmission safety and reliability are insufficient are solved, and the technical effect of improving data transmission safety and reliability is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of security encryption and transmission, and specifically relates to a dynamic encryption method and a dynamic encryption device for secure transmission. Background Art

[0002] The transmission frequency and scale of data in the network are increasing exponentially, and the security threats faced by data transmission are becoming increasingly severe. Incidents of hackers using transmission path vulnerabilities, encryption algorithm defects, etc. to steal, tamper with, and maliciously damage data occur frequently. Traditional static encryption methods and fixed transmission strategies are difficult to cope with the complex and changeable network security environment. On the one hand, most existing encryption methods use fixed encryption algorithms and key management mechanisms. Once cracked or the key is leaked, the security risk of data transmission is serious, and it cannot be dynamically adjusted according to the changes in the transmission environment and the real-time security status during the transmission process, lacking flexibility and adaptability. On the other hand, existing data transmission paths often neglect the comprehensive evaluation and dynamic monitoring of path security risks, and do not fully consider potential security hazards such as network attacks, link failures, and malicious nodes in the transmission path, resulting in data transmission on high-risk paths, thereby increasing the risk of data leakage and transmission; making data unable to be transmitted efficiently and securely.

[0003] Therefore, in the current related technologies, there are technical problems such as the lack of flexibility in static encryption, the inability to adapt to complex transmission environment changes, and insufficient evaluation of transmission path security risks, resulting in insufficient security and reliability of data transmission. Summary of the Invention

[0004] By providing a dynamic encryption method and a dynamic encryption device for secure transmission, this application solves the technical problems in the prior art, such as the lack of flexibility in static encryption, the inability to adapt to complex transmission environment changes, and insufficient evaluation of transmission path security risks, resulting in insufficient security and reliability of data transmission, and achieves the technical effect of improving the security and reliability of data transmission.

[0005] The present application provides a dynamic encryption method for secure transmission. The method includes: receiving a secure transmission task sent by a client, where the secure transmission task includes communication transmission data and a communication transmission path; performing fuzzy detection of security risks according to the communication transmission path to obtain a fuzzy detection result of path risks; based on encryption multimodal factors, performing encryption optimization configuration on the communication transmission data according to the fuzzy detection result of path risks to obtain an initial encryption policy; based on the communication transmission path, transmitting the communication transmission data according to the initial encryption policy to obtain current node update monitoring data corresponding to the current transmission node; inputting the current node update monitoring data into a transmission security risk prediction channel to obtain a current node prediction risk coefficient; if the current node prediction risk coefficient is greater than or equal to a transmission security risk threshold, performing dynamic encryption optimization on the initial encryption policy according to the current node update monitoring data to obtain an optimized encryption policy for the current node, and performing secure transmission on the communication transmission data according to the optimized encryption policy for the current node.

[0006] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: performing feature analysis on the communication transmission data according to transmission data feature factors to establish a transmission data feature vector, where the transmission data feature factors include data sensitivity, data structure, and data transmission requirements; performing support degree analysis on the encryption multimodal factors according to the fuzzy detection result of path risks and the transmission data feature vector to obtain an encryption mode support factor; performing encryption configuration on the communication transmission data according to the encryption mode support factor to obtain an encryption configuration space, and performing optimization analysis on the encryption configuration space according to the fuzzy detection result of path risks to generate the initial encryption policy.

[0007] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: using the fuzzy detection result of path risks and the transmission data feature vector as encryption mode retrieval constraints; performing encryption mode record retrieval according to the encryption mode retrieval constraints to obtain a constrained mapped encryption mode retrieval set; calculating the support degree of each encryption mode in the encryption multimodal factors according to the constrained mapped encryption mode retrieval set to obtain a plurality of mode support coefficients; cleaning the encryption multimodal factors according to the plurality of mode support coefficients to obtain the encryption mode support factor greater than or equal to a predetermined support coefficient.

[0008] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: Based on the path risk fuzzy detection result, respectively simulate the transmission of the communication transmission data according to each encryption configuration scheme in the encryption configuration space to obtain multiple transmission simulation data; perform a security evaluation on each encryption configuration scheme according to the multiple transmission simulation data to obtain multiple encryption configuration security degrees; perform iterative optimization on the encryption configuration space according to the multiple encryption configuration security degrees to obtain the initial encryption policy.

[0009] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: Dynamically encrypt and adjust the initial encryption policy according to the current node updated monitoring data to obtain the first encryption policy adjustment space; perform optimization to minimize the transmission security risk on the first encryption policy adjustment space with the current node updated monitoring data as the transmission scenario constraint to obtain a candidate optimized encryption policy; if the predicted transmission security risk coefficient corresponding to the candidate optimized encryption policy is less than the transmission security risk threshold, add the candidate optimized encryption policy to the current node optimized encryption policy.

[0010] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: If the predicted risk coefficient of the current node is less than the transmission security risk threshold, obtain the next node updated monitoring data corresponding to the next transmission node; input the next node updated monitoring data into the transmission security risk prediction channel to obtain the next node predicted risk coefficient; if the next node predicted risk coefficient is greater than or equal to the transmission security risk threshold, perform dynamic encryption optimization on the initial encryption policy according to the next node updated monitoring data.

[0011] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: According to the communication transmission path, read multiple node monitoring data corresponding to multiple transmission nodes; perform a security risk prediction on the multiple transmission nodes according to the multiple node monitoring data to obtain multiple node risk prediction coefficients; perform an importance evaluation on the multiple transmission nodes to obtain multiple node transmission importance degrees, and perform weight allocation on the multiple transmission nodes according to the multiple node transmission importance degrees to obtain multiple node allocated weights; according to the multiple node allocated weights, perform weighted fusion on the multiple node risk prediction coefficients to generate the path risk fuzzy detection result.

[0012] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: extracting first node monitoring data according to the monitoring data of the multiple nodes; inputting the first node monitoring data into the transmission security risk prediction channel, and outputting Q transmission security risk prediction coefficients according to Q transmission security risk prediction models in the transmission security risk prediction channel, where Q is a positive integer greater than 1; performing fusion calculation on the Q transmission security risk prediction coefficients according to the Q risk prediction accuracies corresponding to the Q transmission security risk prediction models to obtain a first node risk prediction coefficient, and adding the first node risk prediction coefficient to the multiple node risk prediction coefficients.

[0013] In a possible implementation, the dynamic encryption method for secure transmission further performs the following processing: the encryption multimodal factors include electronic codebook mode, cipher block chaining mode, counter mode, cipher feedback mode, output feedback mode, GCM, cipher block chaining mode, adaptive encryption mode, multiple block chaining mode, and XOR stream encryption mode.

[0014] The present application further provides a dynamic encryption device for secure transmission. The device includes: a secure transmission task receiving module, configured to receive a secure transmission task sent by a user terminal, where the secure transmission task includes communication transmission data and a communication transmission path; a security risk fuzzy detection module, configured to perform security risk fuzzy detection according to the communication transmission path to obtain a path risk fuzzy detection result; an encryption optimization configuration module, configured to perform encryption optimization configuration on the communication transmission data based on encryption multimodal factors according to the path risk fuzzy detection result to obtain an initial encryption policy; an updated monitoring data acquisition module, configured to transmit the communication transmission data based on the communication transmission path according to the initial encryption policy to obtain current node updated monitoring data corresponding to the current transmission node; a predicted risk coefficient acquisition module, configured to input the current node updated monitoring data into a transmission security risk prediction channel to obtain a current node predicted risk coefficient; and a dynamic encryption optimization module, configured to, if the current node predicted risk coefficient is greater than or equal to a transmission security risk threshold, perform dynamic encryption optimization on the initial encryption policy according to the current node updated monitoring data to obtain a current node optimized encryption policy, and perform secure transmission on the communication transmission data according to the current node optimized encryption policy.

[0015] The dynamic encryption method and device for secure transmission proposed in this application receive a secure transmission task sent by a user terminal; perform fuzzy detection of security risks to obtain a fuzzy detection result of path risks; perform encryption optimization configuration to obtain an initial encryption policy; obtain current node update monitoring data corresponding to the current transmission node; input it into a transmission security risk prediction channel to obtain a current node prediction risk coefficient; perform dynamic encryption optimization based on the current node update monitoring data to obtain an optimized encryption policy for the current node, and perform secure transmission on communication transmission data. This solves the technical problems in the prior art, such as the lack of flexibility in static encryption, the inability to adapt to changes in complex transmission environments, and insufficient assessment of transmission path security risks, resulting in insufficient data transmission security and reliability, and achieves the technical effect of improving data transmission security and reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings of the embodiments of the present disclosure will be briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the devices according to the embodiments of the application. It should be understood that the operations described above or below do not necessarily need to be executed precisely in sequence. On the contrary, according to the needs, they can be executed in reverse order or simultaneously. At the same time, other operations can also be added to these processes, or one or several steps can be removed from these processes.

[0017] Figure 1 It is a schematic flowchart of the dynamic encryption method for secure transmission provided by the embodiment of the present application.

[0018] Figure 2 It is a schematic structural diagram of the dynamic encryption device for secure transmission provided by the embodiment of the present application.

[0019] Description of the reference numerals: Secure transmission task receiving module 10, security risk fuzzy detection module 20, encryption optimization configuration module 30, updated monitoring data obtaining module 40, predicted risk coefficient obtaining module 50, dynamic encryption optimization module 60. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] The above description is only an overview of the technical solutions of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the description. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically gives the detailed description of the present application.

[0021] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. The described embodiments should not be regarded as limitations of the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0022] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments and can be combined with each other without conflict. The terms "first" and "second" involved are only used to distinguish similar objects and do not represent a specific order for the objects. The terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or server comprising a series of steps or units need not be limited to those steps or units clearly listed, but may include other steps or modules not clearly listed or inherent to these processes, methods, products or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application.

[0023] Embodiments of this application provide a dynamic encryption method for secure transmission, as Figure 1 shown, the method includes:

[0024] Step S100, receiving a secure transmission task sent by a client, where the secure transmission task includes communication transmission data and a communication transmission path.

[0025] Preferably, the client refers to a terminal device capable of initiating a data transmission request, such as a personal computer, a smart phone, a tablet computer, etc. The client sends a task request to a platform for performing secure transmission based on service requirements or operation instructions to securely transmit certain data. For example, an employee sends a task request from his own computer (client) to the company's server to send an important financial statement data to the server of a partner; obtaining the secure transmission task sent by the client, including communication transmission data and a communication transmission path, where the communication transmission data is the core content of the secure task, that is, the data that the user hopes to be transmitted, and may be various types of information, such as text files (such as contract documents, reports, etc.), image files (photos, design drawings, etc.), audio files, video files, or database records, etc.; the communication transmission path refers to the network route that the data passes through from the client to the target end, and may include multiple network nodes, routers, switches and other network devices. Different transmission paths vary in terms of security, transmission speed, stability, etc. For example, the data may reach the target server through an enterprise internal local area network, the Internet backbone network, a specific virtual private network (VPN), etc. Determining the communication transmission path helps to evaluate the security risks during the transmission process. If a transmission path with lower security is selected, more stringent encryption measures need to be taken to ensure the secure transmission of the data.

[0026] Step S200: Perform fuzzy detection of security risks based on the communication transmission path to obtain the fuzzy detection result of path risks.

[0027] Preferably, use the determined communication transmission path for fuzzy detection of security risks. Among them, there are many and complex factors affecting path security in actual network transmission, and it is difficult to accurately determine the impact degree of each factor on security risks and the final risk status. Fuzzy detection of security risks is used to evaluate risks for the uncertain and fuzzy factors existing in the network environment. Specifically, first establish indicators for evaluating the security risks of communication transmission paths, which may include the security of each node in the path (such as whether there are known vulnerabilities, whether it is vulnerable to attacks, etc.), the stability of the network link (such as whether there are frequent packet losses, whether the delay is too high), the network traffic situation (whether there are abnormal traffic fluctuations, which may imply potential attacks), the security of the network areas passed by the path (such as some areas may have a higher incidence of network criminal activities), etc.

[0028] Preferably, then collect data related to evaluation indicators through network monitoring tools. For example, use network monitoring software to obtain the running status information of nodes, monitor the network traffic situation through traffic analysis tools, query the vulnerability information of each node in the path from the security vulnerability database, etc.; then convert the collected accurate monitoring data into fuzzy information. For example, convert the CPU usage rate, memory usage rate, etc. of nodes into fuzzy states such as "high", "medium", "low", etc. Similarly, perform similar fuzzy processing on network delay, packet loss rate, etc. to better reflect the uncertainty in actual network transmission; then use fuzzy inference algorithms (such as Mamdani algorithm, Sugeno algorithm, etc.) to calculate the security risk degree of the network transmission path to obtain the fuzzy evaluation result of path security risks. That is, if the detection result shows that the path risk is high, take stronger encryption measures and security protection means to ensure the transmission security of data on this path; if the risk is low, appropriately optimize the encryption strategy on the premise of ensuring security to improve the transmission efficiency and reduce costs, thereby enhancing the security and reliability of network transmission.

[0029] Further, step S200 further includes step S210: Read the monitoring data of multiple nodes corresponding to the communication transmission path; step S220: Perform security risk prediction on the multiple transmission nodes according to the multiple node monitoring data to obtain multiple node risk prediction coefficients; step S230: Perform importance evaluation on the multiple transmission nodes to obtain multiple node transmission importance degrees, and perform weight allocation on the multiple transmission nodes according to the multiple node transmission importance degrees to obtain multiple node allocated weights; step S240: Weightedly fuse the multiple node risk prediction coefficients according to the multiple node allocated weights to generate the path risk fuzzy detection result.

[0030] Preferably, according to the communication transmission path, obtain the operating status corresponding to each transmission node before data transmission, such as the CPU usage rate of the node, the memory occupancy, the usage amount of network bandwidth, the data transmission delay, the packet loss rate, etc., to form node monitoring data, and then use the node monitoring data to evaluate the security risks of each transmission node, that is, according to the various indicators in the node monitoring data, analyze the degree of security risks that the node may face, and obtain multiple node risk prediction coefficients. For example, if the CPU usage rate of a node is too high for a long time and the network traffic shows abnormal fluctuations at the same time, a relatively high node risk prediction coefficient is predicted, indicating that the node has a high security risk; different transmission nodes play different roles and have different importance in the communication transmission path. Evaluate the importance of each transmission node, that is, according to the location, function, data volume transmitted, etc. of the node, comprehensively evaluate its importance in the entire transmission process, and obtain the node transmission importance. For example, a node located in a critical position and undertaking a large number of core data transmission tasks has a higher importance. Then, assign corresponding weights to each node according to the node transmission importance. Nodes with higher importance are given larger weights, while nodes with lower importance have smaller weights to reflect the relative importance of the node in the communication transmission path; finally, according to the assigned weights of each node, weighted fusion of multiple node risk prediction coefficients is performed to obtain the path risk fuzzy detection result, which can more comprehensively and accurately reflect the security risk status of the communication transmission path, so as to ensure that corresponding measures can be taken according to the overall risk status to guarantee the security of communication transmission.

[0031] Step S300, based on the encrypted multi-modal factor, perform encrypted optimization configuration on the communication transmission data according to the path risk fuzzy detection result to obtain an initial encryption policy.

[0032] Step S300 further includes that the encrypted multi-modal factor includes the electronic codebook mode, the cipher block chaining mode, the counter encryption mode, the cipher feedback mode, the output feedback encryption mode, GCM, the encrypted block chaining mode, the adaptive encryption mode, the multiple block chaining mode, and the XOR stream encryption mode.

[0033] Preferably, the encrypted multi-modal factor includes a variety of different encryption modes, specifically including the Electronic Codebook mode (ECB), Cipher Block Chaining mode (CBC), Counter mode (CTR), Cipher Feedback mode (CFB), Output Feedback mode (OFB), Galois / Counter Mode (GCM), Cipher Block Chaining mode (CBC), Adaptive Encryption mode, Multiple Block Chaining mode, and XOR stream encryption mode. Among them, in the Electronic Codebook mode (ECB), the plaintext is divided into groups of fixed length, and each group is encrypted independently. The same plaintext group is encrypted into the same ciphertext group, which has certain security risks and is suitable for simple data encryption with low security requirements; the Cipher Block Chaining mode (CBC) means that each plaintext group is first XORed with the previous ciphertext group and then encrypted. The same plaintext group is encrypted into different ciphertext groups, enhancing security; the Counter mode (CTR) generates a key stream through a counter and performs an XOR operation with the plaintext to obtain the ciphertext, which can be encrypted in parallel with high efficiency; the Cipher Feedback mode (CFB) takes the previous ciphertext block as input, generates a key stream, and then XORs it with the current plaintext block to obtain the ciphertext, which can be encrypted by bytes and is suitable for encrypting data with variable lengths; the Output Feedback mode (OFB) means continuously generating a key stream and performing an XOR operation with the plaintext. The encryption and decryption processes are independent and are used for encrypting noisy channels; GCM combines the counter mode and the authentication mechanism of the Galois field, which can not only provide encryption functions but also perform data integrity verification; the Adaptive Encryption mode can dynamically adjust the encryption strategy according to the actual situation to adapt to different security requirements and environmental changes; the Multiple Block Chaining mode improves the security of encryption through multiple chaining operations; the XOR stream encryption mode uses a key stream to perform an XOR operation with the plaintext to achieve encryption, which is simple and efficient but has high requirements for key management.

[0034] Preferably, according to the path risk fuzzy detection result, an encrypted optimization configuration is performed on the communication transmission data, that is, the most suitable encryption mode or combination is selected to achieve a balance between security and performance. Specifically, if the path risk fuzzy detection result shows a high path risk, an encryption mode with high security is preferably selected to ensure data security, such as GCM, Multiple Block Chaining mode, or multiple encryption combining multiple encryption modes; for medium-risk paths, an encryption mode with relatively balanced security and performance is selected, such as CBC, CTR, etc., which can improve the encryption and decryption efficiency while ensuring a certain level of security; when the path risk is low, a simple and efficient encryption mode is selected, such as ECB, OFB, etc., to reduce the encryption cost and improve the data transmission efficiency. Through the encrypted optimization configuration, specific encryption modes, key lengths, block sizes, etc. are determined, and then an initial encryption strategy matching the current communication transmission data is formulated and used in the data encryption and transmission process to ensure the security and reliability of data transmission in different network environments. For example, the initial encryption strategy may stipulate the use of the CBC encryption mode, a key length of 256 bits, a block size of 128 bits, etc.

[0035] Further, step S300 further includes step S310 of performing feature analysis on the communication transmission data according to the transmission data feature factors, establishing a transmission data feature vector, where the transmission data feature factors include data sensitivity, data structure, and data transmission requirements; step S320 of performing support degree analysis on the encrypted multi-modal factors according to the path risk fuzzy detection result and the transmission data feature vector to obtain an encrypted mode support factor; and step S330 of performing encryption configuration on the communication transmission data according to the encrypted mode support factor to obtain an encryption configuration space, and performing optimization analysis on the encryption configuration space according to the path risk fuzzy detection result to generate the initial encryption policy.

[0036] Preferably, feature analysis is performed on the communication transmission data according to the transmission data feature factors. Among them, the transmission data feature factors include data sensitivity, data structure, and data transmission requirements. Data sensitivity refers to the confidentiality and importance of the data; the data structure refers to the organization form and format of the data, which can be structured data (such as tabular data in a database, with clear field and record structures), semi-structured data (such as XML, JSON format data), or unstructured data (such as text files, images, videos, etc.); the data transmission requirements include real-time requirements for transmission, bandwidth requirements, etc. Performing feature analysis on the communication transmission data means quantifying each feature factor into classification labels. For example, data sensitivity can be divided into levels 1-5, with level 1 being low sensitivity and level 5 being high sensitivity; the data structure is represented by 0-2, where 0 represents structured data, 1 represents semi-structured data, and 2 represents unstructured data; the data transmission requirements are divided into high, medium, and low categories according to real-time requirements, represented by 3, 2, and 1 respectively; then the quantified features are combined to form a transmission data feature vector, such as [3, 1, 2], indicating that the communication transmission data has a certain sensitivity, belongs to semi-structured data, and has medium real-time transmission requirements.

[0037] Preferably, combining the path risk fuzzy detection result and the transmission data feature vector, evaluate the adaptability of each encrypted multi-modal factor to the current communication transmission situation. Specifically, for high-sensitivity data transmitted on a high-risk path, encryption modes with high security but relatively low performance (such as GCM, multiple block chaining mode) have a higher support degree; while for low-sensitivity data transmitted on a low-risk path, simple and efficient encryption modes (such as electronic codebook mode) have a higher support degree; calculate the support degree of each encryption mode through the fuzzy comprehensive evaluation method or the analytic hierarchy process, and then obtain the encrypted mode support factor.

[0038] Preferably, according to the encryption mode support factor, a suitable encryption mode and its parameters (such as key length, packet size, etc.) are selected to encrypt the communication transmission data. Different encryption modes and parameter combinations form a variety of encryption configuration schemes, which constitute an encryption configuration space. Then, based on the path risk fuzzy detection results, the encryption configuration schemes in the encryption configuration space are searched and compared through optimization algorithms (such as genetic algorithms, simulated annealing algorithms, etc.) in order to meet data security requirements and maximize encryption efficiency and reduce encryption costs as the optimization goal, and finally determine the optimal encryption mode and parameter combination, thereby generating an initial encryption strategy to guide data encryption and transmission and ensure the security and reliability of data during transmission.

[0039] Furthermore, step S320 also includes step S321, using the path risk fuzzy detection result and the transmission data feature vector as encryption mode retrieval constraints; step S322, performing encryption mode record retrieval according to the encryption mode retrieval constraints to obtain a constraint mapping encryption mode retrieval set; step S323, performing support calculation for each encryption mode in the encryption multimodal factor according to the constraint mapping encryption mode retrieval set to obtain multiple mode support coefficients; step S324, cleaning the encryption multimodal factor according to the multiple mode support coefficients to obtain the encryption mode support factor greater than or equal to the predetermined support coefficient.

[0040] Preferably, the path risk fuzzy detection results and the transmission data feature vector are used as conditions for retrieving encryption modes (i.e., encryption mode retrieval constraints), that is, the risk status of the current transmission path and the characteristics of the data itself should be considered in the process of determining a suitable encryption mode; then the encryption mode retrieval constraints are used to search and match the encryption mode records. For example, if the network transmission path risk is high, the data sensitivity is high and the real-time requirement is high, the corresponding encryption mode is matched in the record, and then a set of all encryption modes that meet the encryption mode retrieval constraints is obtained, i.e., a constraint mapping encryption mode retrieval set, wherein the encryption mode records store relevant data of different encryption modes and their applicable scenarios, including the performance and applicability of various encryption modes under different path risks and data characteristics.

[0041] Preferably, according to the retrieval set of constraint mapping encryption modes, the support degree of each encryption mode in the encrypted multi-modal factor is calculated, that is, the frequency of each encryption mode appearing in the retrieval set of constraint mapping encryption modes is counted, and it is used as the mode support coefficient corresponding to this encryption mode. For example, in the retrieval set of constraint mapping encryption modes, the cipher block chaining mode appears 10 times, and there are a total of 50 encrypted mode records in the retrieval set, then the mode support coefficient of the cipher block chaining mode is 10÷50 = 0.2. The support degree of each encryption mode in the encrypted multi-modal factor is calculated, and finally a plurality of mode support coefficients are obtained, each corresponding to an encryption mode; the predetermined support coefficient is a threshold set in advance according to actual requirements, and is used to judge whether a certain encryption mode is sufficiently suitable for the current transmission situation. The mode support coefficient of each encryption mode is compared with the predetermined support coefficient. If the mode support coefficient of a certain encryption mode is greater than or equal to the predetermined support coefficient, this encryption mode is added to the encrypted mode support factor. If the mode support coefficient of a certain encryption mode is less than the predetermined support coefficient, it is cleaned. Finally, an encrypted mode set with a support coefficient greater than or equal to the predetermined support coefficient, which is relatively more suitable for the current path risk and data characteristics, is obtained. Finally, according to these encryption modes, the communication transmission data is encrypted and configured to formulate an initial encryption policy.

[0042] Further, step S330 further includes step S331, based on the path risk fuzzy detection result, respectively simulating the transmission of the communication transmission data according to each encryption configuration scheme in the encryption configuration space to obtain a plurality of transmission simulation data; step S332, performing a security evaluation on each encryption configuration scheme according to the plurality of transmission simulation data to obtain a plurality of encryption configuration security degrees; step S333, performing iterative optimization on the encryption configuration space according to the plurality of encryption configuration security degrees to obtain the initial encryption policy.

[0043] Preferably, according to the path risk fuzzy detection results, for each encryption configuration scheme in the encryption configuration space, various impacts that path risks may bring, such as network attacks, unstable links, etc., are considered in the simulation environment, and the communication transmission data is simulated for transmission. Each time a simulation transmission is performed, corresponding transmission simulation data is generated, which records various performances of the communication transmission data during the simulation transmission under this encryption configuration scheme, such as whether the data arrives completely, whether it is tampered with during the transmission process, the transmission time, etc. Finally, multiple transmission simulation data are generated; then, based on the multiple transmission simulation data, the security of each encryption configuration scheme during the simulation transmission process is evaluated, specifically including evaluating the confidentiality of the data (whether it can effectively prevent the data from being stolen), integrity (whether the data remains complete during the transmission process without being tampered with), and availability (whether the data can reach the receiving end on time and accurately to meet the transmission requirements), so as to obtain the security level of each encryption configuration scheme, that is, the encryption configuration security degree, which reflects the security performance of each encryption configuration scheme in the simulation transmission environment. With the goal of maximizing the encryption configuration security degree, the encryption configuration space is iteratively optimized multiple times. In each iteration, according to the current multiple encryption configuration security degrees, it is analyzed which encryption configuration schemes have a higher security degree and which have a lower security degree. Then, for the schemes with a lower security degree, their encryption modes or parameters are tried to be adjusted to generate new encryption configuration schemes, and the simulation transmission and security evaluation are carried out again. After multiple iterations of optimization, the encryption configuration scheme that maximizes the encryption configuration security degree is found in the encryption configuration space and is determined as the initial encryption strategy for encrypting the actual communication transmission data to meet the data transmission requirements under different path risks and ensure the security and reliability of the data during the transmission process.

[0044] Step S400, based on the communication transmission path, transmit the communication transmission data according to the initial encryption strategy to obtain the current node update monitoring data corresponding to the current transmission node.

[0045] Preferably, the communication transmission data is transmitted along the communication transmission path according to the initial encryption policy, passing through each node on the path in turn (such as router nodes, server nodes, etc.). During the data transmission process, the current transmission node (i.e., the node through which the data is passing) is monitored in real time, which may include but is not limited to monitoring the operating status of the node (such as CPU usage rate, memory usage rate), the data transmission situation (such as data reception rate, transmission rate, packet loss rate), the processing situation of encrypted data (such as encryption and decryption time, whether errors occur), etc., to reflect the real-time status of the current transmission node, form the updated monitoring data of the current node, and timely discover possible problems in the data transmission process, such as node performance bottlenecks, abnormal data transmission, etc. For example, the communication transmission path is user side -> Router A -> Server B -> receiving end, the initial encryption policy adopts the cipher block chaining mode and the key length is 256 bits. The user side encrypts the data according to the initial encryption policy and then sends the encrypted data to Router A. When the data is transmitted to Router A, Router A is monitored to obtain the updated monitoring data of the current node such as its CPU usage rate and data forwarding rate. Then the data is forwarded from Router A to Server B, and Server B is monitored to obtain the corresponding monitoring data, and so on until the data reaches the receiving end.

[0046] Step S500, input the updated monitoring data of the current node into the transmission security risk prediction channel to obtain the predicted risk coefficient of the current node.

[0047] Preferably, the updated monitoring data of the current node is input into the transmission security risk prediction channel including multiple transmission security risk prediction models. Among them, the transmission security risk prediction model may be based on the neural network algorithm in machine learning. By learning a large amount of historical monitoring data and corresponding security events, potential patterns and relationships in the data are discovered, so as to predict the security risk of the current node. Specifically, the updated monitoring data of the current node is simultaneously input into multiple transmission security risk prediction models in the transmission security risk prediction channel. Each model processes and analyzes the input data and predicts and outputs the analysis result of the security risk of the current node, that is, the predicted risk coefficient of the current node, which can help timely understand the security status of the current node during the data transmission process, so as to take targeted measures to ensure the security and stability of data transmission.

[0048] Further, step S500 further includes step S510 of extracting first node monitoring data according to the multiple node monitoring data; step S520 of inputting the first node monitoring data into the transmission security risk prediction channel, and outputting Q transmission security risk prediction coefficients according to Q transmission security risk prediction models in the transmission security risk prediction channel, where Q is a positive integer greater than 1; step S530 of performing a fusion calculation on the Q transmission security risk prediction coefficients according to the Q risk prediction accuracies corresponding to the Q transmission security risk prediction models to obtain a first node risk prediction coefficient, and adding the first node risk prediction coefficient to the multiple node risk prediction coefficients.

[0049] Preferably, one node's monitoring data is randomly extracted from the multiple node monitoring data as the first node monitoring data, and then the first node monitoring data is input into the transmission security risk prediction channel. The transmission security risk prediction channel integrates Q transmission security risk prediction models, where Q is a positive integer greater than 1 representing the number of transmission security risk prediction models. Each transmission security risk prediction model analyzes and processes the input monitoring data and outputs the corresponding transmission security risk prediction coefficient, that is, Q transmission security risk prediction coefficients. Finally, the risk prediction accuracy corresponding to each transmission security risk prediction model is obtained, which reflects the accuracy of the model's prediction result. A fusion calculation is performed on the Q transmission security risk prediction coefficients according to the risk prediction accuracies of the Q models. For example, weighted average is used, that is, a larger weight is given to the prediction coefficient output by the model with a higher accuracy, and a smaller weight is given to the prediction coefficient output by the model with a lower accuracy, to calculate the first node risk prediction coefficient, and add it to the multiple node risk prediction coefficients, so as to ensure the accuracy and reliability of node risk prediction.

[0050] Step S600, if the current node prediction risk coefficient is greater than or equal to the transmission security risk threshold, dynamically encrypt and optimize the initial encryption policy according to the current node updated monitoring data to obtain the current node optimized encryption policy, and perform secure transmission of the communication transmission data according to the current node optimized encryption policy.

[0051] Preferably, a transmission security risk threshold is preset to measure the level of risk. If the predicted risk coefficient of the current node is greater than or equal to the transmission security risk threshold, it indicates that the current node has a relatively high security risk, which may pose a threat to the security of data transmission. For example, if the transmission security risk threshold is set to 0.6 (assuming the risk coefficient ranges from 0 to 1), and the predicted risk coefficient of the current node is 0.7, an encryption policy optimization operation is triggered. That is, based on the updated monitoring data of the current node, the initial encryption policy is dynamically encrypted and optimized, which may include changing the encryption mode (changing from the relatively simple Electronic Codebook mode to the more secure Cipher Block Chaining mode), adjusting encryption parameters (such as increasing the key length), or using multiple encryptions, etc., to enhance the security of data transmission at the current high-risk node and obtain an encryption policy more suitable for the high-risk situation of the current node, that is, the current node optimizes the encryption policy to minimize the security risk faced by the data during transmission at this node; finally, the optimized encryption policy of the current node is used to securely transmit the communication transmission data, that is, according to the requirements of the optimized encryption policy of the current node, the data is re-encrypted or the encryption method is adjusted, and then the data continues to be sent along the communication transmission path. Even when there is a relatively high security risk at the current node, the security of the data can be guaranteed through the optimized encryption policy, reducing the possibility of the data being stolen, tampered with, or suffering other security threats, and ensuring that the data can be securely transmitted to the next node.

[0052] Further, step S600 further includes step S610, if the predicted risk coefficient of the current node is less than the transmission security risk threshold, obtaining the updated monitoring data of the next transmission node corresponding to the next node; step S620, inputting the updated monitoring data of the next node into the transmission security risk prediction channel to obtain the predicted risk coefficient of the next node; step S630, if the predicted risk coefficient of the next node is greater than or equal to the transmission security risk threshold, dynamically encrypting and optimizing the initial encryption policy according to the updated monitoring data of the next node.

[0053] Preferably, if the predicted risk coefficient of the current node is less than the transmission security risk threshold, it indicates that the security risk of the current node is at a relatively low level, and the data transmission at the current node is relatively safe. To continue to ensure the security of the data throughout the transmission path, the relevant information of the next transmission node in the data transmission path is obtained, that is, the next node updates the monitoring data, including the real-time operating status of the next node (such as CPU usage rate, memory occupancy, etc.), data transmission-related parameters (such as transmission rate, packet loss rate, etc.), etc.; then the next node update monitoring data is input into the transmission security risk prediction channel, and the transmission security risk prediction model is used to evaluate the security risk of the next node to obtain the predicted risk coefficient of the next node, which reflects the degree of security risk faced by the next node. The higher the value, the greater the risk; if the predicted risk coefficient of the next node is greater than or equal to the transmission security risk threshold, it indicates that the next node has a relatively high security risk and may pose a threat to the security of data transmission. Then, based on the actual operation and transmission conditions of the node reflected by the next node update monitoring data, the initial encryption policy is adjusted and optimized, which may include changing the encryption mode (switching from a simple encryption mode to a more complex and secure mode), adjusting the encryption parameters (such as increasing the key length), or using multiple encryption, etc., to enhance the security of the data when it is transmitted through the next high-risk node and ensure that the data can continue to be transmitted safely through this node.

[0054] Further, step S600 further includes step S640 of dynamically encrypting and adjusting the initial encryption policy according to the current node update monitoring data to obtain the first space for encrypting policy adjustment; step S650 of minimizing the transmission security risk for the first space for encrypting policy adjustment with the current node update monitoring data as the transmission scenario constraint to obtain a candidate optimized encryption policy; step S660 of adding the candidate optimized encryption policy to the current node optimized encryption policy if the predicted transmission security risk coefficient corresponding to the candidate optimized encryption policy is less than the transmission security risk threshold.

[0055] Preferably, the initial encryption policy is dynamically encrypted and adjusted according to the updated monitoring data of the current node, such as changing the encryption mode, adjusting the encryption parameters, increasing or decreasing the encryption levels, etc., thereby generating a variety of possible encryption policy combinations, constituting the first encryption policy adjustment space, which contains various adjusted encryption policies; then the updated monitoring data of the current node is used as the transmission scenario constraint condition, and the first encryption policy adjustment space is optimized with the goal of minimizing the transmission security risk. Specifically, considering multiple factors, such as the ability to resist various network attacks, the possibility of data leakage, etc., the security of different encryption policies in the current transmission scenario is evaluated. Through comparison and screening, a relatively optimal encryption policy, that is, a candidate optimized encryption policy, is determined from the first encryption policy adjustment space; finally, the transmission security risk of the candidate optimized encryption policy is evaluated. If the predicted transmission security risk coefficient of the candidate optimized encryption policy is less than the transmission security risk threshold, it means that the policy can effectively reduce the transmission security risk and make it within an acceptable range, then the candidate optimized encryption policy is added to the optimized encryption policy of the current node to ensure the secure transmission of data at the current node.

[0056] In the above text, reference is made to Figure 1 The dynamic encryption method for secure transmission according to the embodiments of the present invention is described in detail. Next, reference will be made to Figure 2 Describe the dynamic encryption device for secure transmission according to the embodiments of the present invention.

[0057] The dynamic encryption device for secure transmission according to the embodiments of the present invention is used to solve the technical problems existing in the prior art, such as the lack of flexibility of static encryption, the inability to adapt to the changes in complex transmission environments, and the insufficient evaluation of transmission path security risks, resulting in insufficient data transmission security and reliability, and achieves the technical effect of improving data transmission security and reliability. As Figure 2 shown, the dynamic encryption device for secure transmission includes: a secure transmission task receiving module 10, a security risk fuzzy detection module 20, an encryption optimization configuration module 30, an updated monitoring data acquisition module 40, a predicted risk coefficient acquisition module 50, and a dynamic encryption optimization module 60.

[0058] The secure transmission task receiving module 10 is used to receive the secure transmission task sent by the user terminal, and the secure transmission task includes communication transmission data and a communication transmission path; the security risk fuzzy detection module 20 is used to perform security risk fuzzy detection according to the communication transmission path to obtain a path risk fuzzy detection result; the encryption optimization configuration module 30 is used to perform encryption optimization configuration on the communication transmission data based on encryption multimodal factors according to the path risk fuzzy detection result to obtain an initial encryption policy; the updated monitoring data acquisition module 40 is used to transmit the communication transmission data based on the communication transmission path according to the initial encryption policy to obtain the current node updated monitoring data corresponding to the current transmission node; the predicted risk coefficient acquisition module 50 is used to input the current node updated monitoring data into the transmission security risk prediction channel to obtain the current node predicted risk coefficient; the dynamic encryption optimization module 60 is used to, if the current node predicted risk coefficient is greater than or equal to the transmission security risk threshold, perform dynamic encryption optimization on the initial encryption policy according to the current node updated monitoring data to obtain the current node optimized encryption policy, and perform secure transmission on the communication transmission data according to the current node optimized encryption policy.

[0059] Next, the specific configuration of the encryption optimization configuration module 30 will be described in detail. The encryption optimization configuration module 30 further includes: performing feature analysis on the communication transmission data according to the transmission data feature factors to establish a transmission data feature vector, where the transmission data feature factors include data sensitivity, data structure, and data transmission requirements; performing support degree analysis on the encryption multimodal factors according to the path risk fuzzy detection result and the transmission data feature vector to obtain an encryption mode support factor; performing encryption configuration on the communication transmission data according to the encryption mode support factor to obtain an encryption configuration space, and performing optimization analysis on the encryption configuration space according to the path risk fuzzy detection result to generate the initial encryption policy.

[0060] Next, the specific configuration of the encryption optimization configuration module 30 will be further described in detail. The encryption optimization configuration module 30 further includes: using the path risk fuzzy detection result and the transmission data feature vector as encryption mode retrieval constraints; performing encryption mode record retrieval according to the encryption mode retrieval constraints to obtain a constraint mapping encryption mode retrieval set; calculating the support degree of each encryption mode in the encryption multimodal factors according to the constraint mapping encryption mode retrieval set to obtain a plurality of mode support coefficients; cleaning the encryption multimodal factors according to the plurality of mode support coefficients to obtain the encryption mode support factor greater than or equal to the predetermined support coefficient.

[0061] Next, the specific configuration of the encryption optimization configuration module 30 will be further described in detail. The encryption optimization configuration module 30 further includes: based on the path risk fuzzy detection result, respectively simulating the transmission of the communication transmission data according to each encryption configuration scheme in the encryption configuration space to obtain a plurality of transmission simulation data; performing a security evaluation on each encryption configuration scheme according to the plurality of transmission simulation data to obtain a plurality of encryption configuration security degrees; performing iterative optimization on the encryption configuration space according to the plurality of encryption configuration security degrees to obtain the initial encryption policy.

[0062] Next, the specific configuration of the dynamic encryption optimization module 60 will be described in detail. The dynamic encryption optimization module 60 further includes: dynamically encrypting and adjusting the initial encryption policy according to the current node update monitoring data to obtain a first encryption policy adjustment space; taking the current node update monitoring data as a transmission scenario constraint, performing optimization to minimize the transmission security risk on the first encryption policy adjustment space to obtain a candidate optimized encryption policy; if the predicted transmission security risk coefficient corresponding to the candidate optimized encryption policy is less than the transmission security risk threshold, adding the candidate optimized encryption policy to the optimized encryption policy of the current node.

[0063] Next, the specific configuration of the dynamic encryption optimization module 60 will be further described in detail. The dynamic encryption optimization module 60 further includes: if the predicted risk coefficient of the current node is less than the transmission security risk threshold, obtaining the next node update monitoring data corresponding to the next transmission node; inputting the next node update monitoring data into the transmission security risk prediction channel to obtain the next node predicted risk coefficient; if the next node predicted risk coefficient is greater than or equal to the transmission security risk threshold, dynamically encrypting and optimizing the initial encryption policy according to the next node update monitoring data.

[0064] Next, the specific configuration of the security risk fuzzy detection module 20 will be described in detail. The security risk fuzzy detection module 20 further includes: reading a plurality of node monitoring data corresponding to a plurality of transmission nodes according to the communication transmission path; performing a security risk prediction on the plurality of transmission nodes according to the plurality of node monitoring data to obtain a plurality of node risk prediction coefficients; performing an importance evaluation on the plurality of transmission nodes to obtain a plurality of node transmission importance degrees, and performing a weight assignment on the plurality of transmission nodes according to the plurality of node transmission importance degrees to obtain a plurality of node assigned weights; weighted-fusing the plurality of node risk prediction coefficients according to the plurality of node assigned weights to generate the path risk fuzzy detection result.

[0065] Next, the specific configuration of the security risk fuzzy detection module 20 will be further described in detail. The security risk fuzzy detection module 20 further includes: extracting first node monitoring data according to the multiple node monitoring data; inputting the first node monitoring data into the transmission security risk prediction channel, and outputting Q transmission security risk prediction coefficients according to Q transmission security risk prediction models in the transmission security risk prediction channel, where Q is a positive integer greater than 1; performing a fusion calculation on the Q transmission security risk prediction coefficients according to the Q risk prediction accuracies corresponding to the Q transmission security risk prediction models to obtain a first node risk prediction coefficient, and adding the first node risk prediction coefficient to the multiple node risk prediction coefficients.

[0066] Next, the specific configuration of the encryption optimization configuration module 30 will be further described in detail. The encryption multimodal factors include electronic codebook mode, cipher block chaining mode, counter encryption mode, cipher feedback mode, output feedback encryption mode, GCM, encrypted block chaining mode, adaptive encryption mode, multiple block chaining mode, and XOR stream encryption mode.

[0067] The dynamic encryption device for secure transmission provided by the embodiments of the present invention can execute the secure transmission dynamic encryption method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0068] Although this application makes various references to certain modules in the device according to the embodiments of this application, however, any number of different modules can be used and run on the user terminal and / or server. The various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.

[0069] The above specific embodiments do not constitute a limitation to the protection scope of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principle of this application shall be included within the protection scope of this application.

Claims

1. A dynamic encryption method for secure transmission, characterized in that The method includes: Receiving a secure transmission task sent by a client, where the secure transmission task includes communication transmission data and a communication transmission path; Performing fuzzy detection of security risks according to the communication transmission path to obtain a fuzzy detection result of path risks; Based on an encrypted multimodal factor, performing encrypted optimization configuration on the communication transmission data according to the fuzzy detection result of path risks to obtain an initial encryption policy; Based on the communication transmission path, transmitting the communication transmission data according to the initial encryption policy to obtain current node update monitoring data corresponding to the current transmission node; Inputting the current node update monitoring data into a transmission security risk prediction channel to obtain a current node prediction risk coefficient; If the current node prediction risk coefficient is greater than or equal to a transmission security risk threshold, dynamically encrypt and optimize the initial encryption policy according to the current node update monitoring data to obtain a current node optimized encryption policy, and perform secure transmission of the communication transmission data according to the current node optimized encryption policy.

2. The dynamic encryption method for secure transmission according to claim 1, wherein, Based on an encrypted multimodal factor, performing encrypted optimization configuration on the communication transmission data according to the fuzzy detection result of path risks to obtain an initial encryption policy, including: Performing feature analysis on the communication transmission data according to transmission data feature factors to establish a transmission data feature vector, where the transmission data feature factors include data sensitivity, data structure, and data transmission requirements; Performing support degree analysis on the encrypted multimodal factor according to the fuzzy detection result of path risks and the transmission data feature vector to obtain an encrypted mode support factor; Performing encryption configuration on the communication transmission data according to the encrypted mode support factor to obtain an encryption configuration space, and performing optimization analysis on the encryption configuration space according to the fuzzy detection result of path risks to generate the initial encryption policy.

3. The dynamic encryption method for secure transmission according to claim 2, wherein, Performing support degree analysis on the encrypted multimodal factor according to the fuzzy detection result of path risks and the transmission data feature vector to obtain an encrypted mode support factor, including: Using the fuzzy detection result of path risks and the transmission data feature vector as encryption mode retrieval constraints; Performing encrypted mode record retrieval according to the encryption mode retrieval constraints to obtain a constrained mapping encrypted mode retrieval set; Calculating the support degree of each encryption mode in the encrypted multimodal factor according to the constrained mapping encrypted mode retrieval set to obtain a plurality of mode support coefficients; Cleaning the encrypted multimodal factor according to the plurality of mode support coefficients to obtain the encrypted mode support factor greater than or equal to a predetermined support coefficient.

4. The dynamic encryption method for secure transmission according to claim 2, characterized in that, Performing optimization analysis on the encryption configuration space according to the fuzzy detection result of path risks to generate the initial encryption policy, including: Based on the fuzzy detection result of path risks, performing simulated transmission on the communication transmission data according to each encryption configuration scheme in the encryption configuration space to obtain a plurality of transmission simulation data; Performing security evaluation on each encryption configuration scheme according to the plurality of transmission simulation data to obtain a plurality of encryption configuration security degrees; Performing iterative optimization on the encryption configuration space according to the plurality of encryption configuration security degrees to obtain the initial encryption policy.

5. The dynamic encryption method for secure transmission according to claim 1, characterized in that, Dynamically encrypt and optimize the initial encryption policy according to the updated monitoring data of the current node to obtain an optimized encryption policy for the current node, including: Dynamically adjust the initial encryption policy according to the updated monitoring data of the current node to obtain a first space for encryption policy adjustment; Using the updated monitoring data of the current node as a constraint for the transmission scenario, perform optimization to minimize the transmission security risk for the first space of encryption policy adjustment to obtain a candidate optimized encryption policy; If the predicted transmission security risk coefficient corresponding to the candidate optimized encryption policy is less than the transmission security risk threshold, add the candidate optimized encryption policy to the optimized encryption policy for the current node.

6. The dynamic encryption method for secure transmission according to claim 1, characterized in that The method further includes: If the predicted risk coefficient of the current node is less than the transmission security risk threshold, obtain the updated monitoring data of the next node corresponding to the next transmission node; Input the updated monitoring data of the next node into the transmission security risk prediction channel to obtain the predicted risk coefficient of the next node; If the predicted risk coefficient of the next node is greater than or equal to the transmission security risk threshold, dynamically encrypt and optimize the initial encryption policy according to the updated monitoring data of the next node.

7. The dynamic encryption method for secure transmission according to claim 1, characterized in that, Perform fuzzy detection of security risks according to the communication transmission path to obtain a fuzzy detection result of path risks, including: According to the communication transmission path, read multiple node monitoring data corresponding to multiple transmission nodes; Perform security risk prediction on the multiple transmission nodes according to the multiple node monitoring data to obtain multiple node risk prediction coefficients; Perform importance evaluation on the multiple transmission nodes to obtain multiple node transmission importance levels, and allocate weights to the multiple transmission nodes according to the multiple node transmission importance levels to obtain multiple node allocated weights; According to the multiple node allocated weights, perform weighted fusion of the multiple node risk prediction coefficients to generate the fuzzy detection result of path risks.

8. The dynamic encryption method for secure transmission according to claim 7, wherein, Performing security risk prediction on the multiple transmission nodes according to the multiple node monitoring data to obtain multiple node risk prediction coefficients, including: Extract first node monitoring data according to the multiple node monitoring data; Input the first node monitoring data into the transmission security risk prediction channel, and according to Q transmission security risk prediction models in the transmission security risk prediction channel, output Q transmission security risk prediction coefficients, where Q is a positive integer greater than 1; Perform fusion calculation on the Q transmission security risk prediction coefficients according to the Q risk prediction accuracies corresponding to the Q transmission security risk prediction models to obtain a first node risk prediction coefficient, and add the first node risk prediction coefficient to the multiple node risk prediction coefficients.

9. The dynamic encryption method for secure transmission according to claim 1, characterized in that, The encryption multimodal factors include electronic codebook mode, cipher block chaining mode, counter encryption mode, cipher feedback mode, output feedback encryption mode, GCM, encrypted block chaining mode, adaptive encryption mode, multiple block chaining mode, and XOR stream encryption mode.

10. Dynamic encryption device for secure transmission, characterized in that, The device is used to implement the dynamic encryption method for secure transmission according to any one of claims 1 to 9, and the device includes: A secure transmission task receiving module, which is used to receive the secure transmission tasks sent by the user terminal, and the secure transmission tasks include communication transmission data and a communication transmission path; A security risk fuzzy detection module, which is used to perform fuzzy detection of security risks according to the communication transmission path to obtain a fuzzy detection result of path risks; An encryption optimization configuration module, which is used to perform encryption optimization configuration on the communication transmission data based on encryption multimodal factors according to the fuzzy detection result of path risks to obtain an initial encryption strategy; An updated monitoring data acquisition module, which is used to transmit the communication transmission data based on the initial encryption strategy according to the communication transmission path to obtain current node updated monitoring data corresponding to the current transmission node; A predicted risk coefficient acquisition module, which is used to input the current node updated monitoring data into a transmission security risk prediction channel to obtain a current node predicted risk coefficient; A dynamic encryption optimization module, which is used to, if the current node predicted risk coefficient is greater than or equal to the transmission security risk threshold, perform dynamic encryption optimization on the initial encryption strategy according to the current node updated monitoring data to obtain a current node optimized encryption strategy, and perform secure transmission on the communication transmission data according to the current node optimized encryption strategy.

Citation Information

Cited By

  • Adaptive enhancement method and system for vehicle-mounted TLS configuration

    CN121711190A

  • Electric power archive management method and system based on man-machine interaction

    CN121744371A

  • Password strategy self-adaptive arrangement method, system, equipment and medium

    CN121750229A

  • A password policy self-adaption arrangement method, system, device and medium

    CN121750229B