Adaptive encryption system based on AI intelligent safety management

Through an adaptive encryption system based on AI, data acquisition, risk assessment and encryption policy feedback mechanisms are used to solve the problem that existing encryption systems cannot be dynamically adjusted, and the intelligent and adaptive adjustment of encryption policies is realized, which improves data security and system performance.

CN120372658APending Publication Date: 2025-07-25HEBI CRYPTOADVANCED TECH RES INST
View PDF 0 Cites 8 Cited by

Patent Information

Application Number
CN202510485845.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Existing encryption systems cannot dynamically adjust encryption methods based on real-time changing security risks, resulting in insufficient encryption strength in complex network environments or increasing system resource consumption at low risk, reducing system performance.

Method used

Adaptive encryption system based on AI intelligent security management is adopted, and system data is collected through the data acquisition module, and the risk assessment module is used to evaluate the security risk level based on deep learning convolutional neural network model, select the adaptive encryption algorithm, and generate the encryption key through the key generation and management module, perform encryption operations, monitor the encryption effect in real time and feedback to adjust the encryption strategy.

Benefits of technology

It realizes intelligent and adaptive adjustment of encryption policies, improves the targetedness and effectiveness of encryption, reduces system resource consumption, and improves the overall performance and data security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372658A_ABST
    Figure CN120372658A_ABST
Patent Text Reader

Abstract

The invention discloses a self-adaptive encryption system based on AI intelligent security management, which relates to the technical field of information security, and comprises a data acquisition module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module and an encryption effect feedback module, the data collection module is used for collecting various data in a system operation environment, including but not limited to network flow data, equipment state data and user behavior data; and the risk assessment module analyzes the collected data based on an AI algorithm and assesses the security risk level faced by the current system. The operation environment data is comprehensively collected through the data acquisition module, the security risk level is evaluated in real time through the risk evaluation module based on the AI algorithm, the adaptive encryption algorithm can be dynamically selected according to the risk, the defect that a traditional encryption system is fixed in strategy is overcome, and encryption pertinence and effectiveness are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to an adaptive encryption system based on AI intelligent security management. Background Art

[0002] In today's digital age, data security is of utmost importance and is widely applied in many fields such as finance, healthcare, and the Internet. With the explosive growth of data volume and the increasing complexity and diversity of network attack means, the requirements for data encryption technology are also constantly rising. Efficient and intelligent encryption management can ensure the security of data during transmission and storage, safeguard user privacy and the core interests of enterprises, and is a key link to ensure the stable operation of various information systems.

[0003] Currently, common encryption systems mostly adopt fixed encryption strategies and are difficult to dynamically adjust the encryption method according to real-time changing security risks. On the one hand, in the face of a complex and changeable network environment, traditional encryption systems may fail to timely perceive new security threats, resulting in insufficient encryption strength and the risk of data being stolen or tampered with; on the other hand, some encryption systems still use high-strength encryption algorithms when the security risk is low, which undoubtedly increases the consumption of system computing resources and operating costs and reduces the overall performance of the system. Summary of the Invention

[0004] To solve the above technical problems, an adaptive encryption system based on AI intelligent security management is provided, and this technical solution solves the above problems.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0006] An adaptive encryption system based on AI intelligent security management, the system includes a data collection module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module, and an encryption effect feedback module, wherein:

[0007] The data collection module is used to collect various types of data in the system operation environment, including but not limited to network traffic data, device status data, and user behavior data;

[0008] The risk assessment module analyzes the collected data based on an AI algorithm to evaluate the security risk level faced by the current system, and the AI algorithm uses a convolutional neural network model of deep learning;

[0009] The encryption algorithm selection module selects an appropriate encryption algorithm from a preset encryption algorithm library according to the risk level output by the risk assessment module, and the encryption algorithm library contains a variety of mainstream algorithms;

[0010] The key generation and management module generates corresponding encryption keys according to the selected encryption algorithm and securely manages the keys, including storage, update, and distribution of the keys;

[0011] The encryption execution module encrypts the data to be protected by using the selected encryption algorithm and the generated key;

[0012] The encryption effect feedback module monitors the security of the encrypted data in real time and feeds back the encryption effect to the risk assessment module for adjusting subsequent encryption strategies.

[0013] Preferably, the convolutional neural network model formula of the risk assessment module is:

[0014] Y = f(WX + b)

[0015] where Y is the risk assessment result, X is the input data, W is the weight matrix, b is the bias vector, and f is the activation function.

[0016] Preferably, when the data acquisition module collects data, it includes:

[0017] Obtaining network traffic data through a network traffic monitoring tool and analyzing information such as the size, flow direction, and protocol type of the traffic;

[0018] Communicating with the device management system to collect the operating status data of the device, including device load, temperature, and memory usage;

[0019] Using user behavior monitoring software to record the operation behaviors of users in the system, including login time, operation frequency, and accessed resources.

[0020] Preferably, when the encryption algorithm selection module selects an encryption algorithm, the specific steps are as follows:

[0021] Establish a mapping relationship table between the risk level and the encryption algorithm strength;

[0022] According to the risk level output by the risk assessment module, query the mapping relationship table to determine the appropriate encryption algorithm;

[0023] If the risk level is in the fuzzy interval between two adjacent levels, comprehensively consider factors such as system performance and data importance, and determine the encryption algorithm through weighted calculation.

[0024] Preferably, when the key generation and management module generates keys, it adopts the following method:

[0025] For symmetric encryption algorithms, use a pseudo-random number generator to generate keys of a specified length;

[0026] For the asymmetric encryption algorithm, a public key and a private key pair are generated based on the elliptic curve cryptosystem.

[0027] Preferably, when the encryption execution module performs the encryption operation, it includes:

[0028] For data with a small amount and high real-time requirements, stream encryption is used for encryption;

[0029] For data with a large amount, block encryption is used, and the data is divided into blocks and encrypted sequentially.

[0030] Preferably, when the encryption effect feedback module monitors the encryption effect, it includes:

[0031] Detect whether the encrypted data is illegally accessed, which is achieved by setting access logs and an anomaly detection mechanism;

[0032] Evaluate the three performance indicators of the transmission delay, storage occupancy, and encryption / decryption operation time of the encrypted data, and compare them with the corresponding preset performance thresholds respectively.

[0033] Preferably, the system further includes an encryption policy update module, and the encryption policy update module is used for:

[0034] According to the feedback information provided by the encryption effect feedback module and combined with the real-time operation situation of the system, adjust the parameters of the risk assessment module and the mapping table of the encryption algorithm selection module;

[0035] Regularly update the encryption algorithm library, introduce new encryption algorithms or eliminate insecure algorithms.

[0036] Preferably, when the encryption policy update module adjusts the parameters of the risk assessment module, the following algorithm is adopted:

[0037]

[0038] where θ new is the updated parameter, θ old is the old parameter, α is the learning rate, is the gradient of the loss function with respect to the old parameter.

[0039] Preferably, when the encryption policy update module updates the encryption algorithm library, it includes:

[0040] Collect the latest research results of encryption algorithms and security vulnerability reports;

[0041] Conduct security and performance tests on the new algorithms, and add the algorithms that meet the requirements to the encryption algorithm library;

[0042] For algorithms with security vulnerabilities, remove them from the encryption algorithm library and notify relevant modules for adjustment.

[0043] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0044] The adaptive encryption system based on AI intelligent security management proposed by the present invention comprehensively collects operation environment data through a data collection module, and uses a risk assessment module to real-time evaluate the security risk level based on AI algorithms. It can dynamically select an appropriate encryption algorithm according to the risk, changing the drawback of the fixed strategy of the traditional encryption system and improving the pertinence and effectiveness of encryption. During the encryption process, the key generation and management module accurately generates keys according to different encryption algorithms, ensuring the security of the keys; the encryption execution module flexibly adopts stream encryption or block encryption methods according to different data characteristics, improving the encryption efficiency. The encryption effect feedback module real-time monitors the security of the encrypted data and performance indicators such as transmission delay and storage occupancy, and feeds them back to the risk assessment module. The encryption strategy update module adjusts the risk assessment parameters and encryption algorithm selection rules accordingly, regularly updates the encryption algorithm library, and continuously optimizes the encryption strategy. In summary, the present invention realizes the intelligent and adaptive adjustment of the encryption strategy, effectively guarantees the data security while reducing the system resource consumption and improving the overall performance of the system, providing a reliable guarantee for the data security of various information systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is a flowchart of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0046] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.

[0047] Referring to Figure 1 shown, an adaptive encryption system based on AI intelligent security management, the system includes a data collection module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module and an encryption effect feedback module, wherein:

[0048] The data collection module is used to collect various data in the system operation environment, including but not limited to network traffic data, device status data, user behavior data;

[0049] The risk assessment module analyzes the collected data based on AI algorithms to evaluate the security risk level faced by the current system. The AI algorithm uses a convolutional neural network model of deep learning;

[0050] An encryption algorithm selection module selects a suitable encryption algorithm from a preset encryption algorithm library according to the risk level output by the risk assessment module. The encryption algorithm library contains a variety of mainstream algorithms;

[0051] A key generation and management module generates a corresponding encryption key according to the selected encryption algorithm and securely manages the key, including key storage, update, and distribution;

[0052] An encryption execution module encrypts the data to be protected by using the selected encryption algorithm and the generated key;

[0053] An encryption effect feedback module monitors the security of the encrypted data in real time and feeds back the encryption effect to the risk assessment module for adjusting subsequent encryption strategies.

[0054] Specifically, through the mutual cooperation of each module, a closed-loop intelligent encryption management system is constructed. The data collection module widely collects various types of data in the system operation environment to provide a comprehensive basis for risk assessment. The risk assessment module uses a convolutional neural network model of deep learning to deeply analyze the data and accurately evaluate the security risk level. The encryption algorithm selection module selects a suitable algorithm from the preset algorithm library according to the risk level. The key generation and management module generates and properly manages the key according to the selected algorithm. The encryption execution module encrypts the data by using the algorithm and the key. The encryption effect feedback module monitors the status of the encrypted data in real time and feeds it back to the risk assessment module to adjust the encryption strategy. Each module cooperates with each other to realize the dynamic adaptive adjustment of the encryption strategy. Compared with the traditional fixed encryption strategy system, this system can perceive the changes of security risks in real time and flexibly adjust the encryption means.

[0055] The formula of the convolutional neural network model of the risk assessment module is:

[0056] Y = f(Y + b)

[0057] Where Y is the risk assessment result, X is the input data, W is the weight matrix, b is the bias vector, and f is the activation function.

[0058] Specifically, the convolutional neural network model adopted by the risk assessment module constructs a multi-layer convolutional layer and pooling layer structure to extract and abstract features layer by layer from the collected data. The input data undergoes operations with weight matrices and bias vectors, and nonlinear transformations are performed through activation functions. During the continuous training of the model, it gradually learns the key features related to security risks in the data and finally outputs the risk assessment result. The powerful feature learning ability of this model enables risk assessment to get rid of the limitations of traditional methods that rely on simple rules or a small number of features. It can discover complex and hidden security risk patterns in the data, greatly improving the accuracy and comprehensiveness of risk assessment. This provides a more reliable basis for subsequent encryption algorithm selection and encryption strategy adjustment, helps detect potential security threats in advance, and effectively prevents security incidents from occurring.

[0059] When the data acquisition module collects data, it includes:

[0060] Obtain network traffic data through network traffic monitoring tools and analyze key information such as traffic volume, traffic direction, and protocol type;

[0061] Communicate with the device management system to collect the operating status data of the device, including device load, temperature, and memory usage;

[0062] Use user behavior monitoring software to record the operation behavior of users in the system, including login time, operation frequency, and accessed resources.

[0063] Specifically, through network traffic monitoring tools, based on network protocol parsing technology, network traffic data is captured in real time, and key information such as traffic volume, traffic direction, and protocol type is analyzed. These information reflect the basic characteristics of network communication; communicate with the device management system, use the system interface to obtain the device operating status data, and the physical parameters and resource usage of the device operation intuitively reflect the device health status; with the help of user behavior monitoring software, through techniques such as system hooks or log records, record the operation behavior data of users in the system, reflecting user operation habits and behavior trajectories. Through multi-dimensional data acquisition methods, all levels of system operation are comprehensively covered. Network traffic data can promptly detect network attacks and abnormal communications; device status data helps predict device failures in advance and ensure the stable operation of the system; user behavior data can effectively prevent internal personnel from performing illegal operations and account theft.

[0064] When the encryption algorithm selection module selects an encryption algorithm, the specific steps are as follows:

[0065] Establish a mapping relationship table between risk levels and encryption algorithm strengths;

[0066] According to the risk level output by the risk assessment module, query the mapping relationship table to determine the appropriate encryption algorithm;

[0067] If the risk level is in the fuzzy interval between two adjacent levels, the encryption algorithm is determined by weighted calculation, taking into account factors such as system performance and data importance.

[0068] Specifically, the encryption algorithm selection module first establishes a mapping relationship table between the risk level and the encryption algorithm strength, and matches according to different security risk levels and the characteristics of various encryption algorithms. When the risk assessment module outputs the risk level, this module directly queries the mapping table to determine the applicable algorithm. For the case where the risk level is in the fuzzy interval, factors such as system performance and data importance are comprehensively considered, corresponding weights are assigned to each factor, and a weighted calculation is used for quantitative evaluation to determine the most suitable encryption algorithm. Through this encryption algorithm selection mechanism, while ensuring data security, system performance and resource utilization are taken into account, avoiding a decline in system performance caused by using a high-strength encryption algorithm at low risk, and also preventing security risks brought about by insufficient encryption strength under high risk. This makes the selection of the encryption algorithm more flexible and reasonable, improving the adaptability and efficiency of the entire encryption system.

[0069] When generating keys, the key generation and management module adopts the following method:

[0070] For the symmetric encryption algorithm, a pseudo-random number generator is used to generate a key of a specified length;

[0071] For the asymmetric encryption algorithm, a public key and a private key pair are generated based on the elliptic curve cryptosystem.

[0072] Specifically, the randomness of the symmetric encryption key generation enhances the key security and reduces the risk of being cracked. The public and private key pairs generated by the elliptic curve cryptosystem have the advantages of short key length and high operation efficiency while ensuring security.

[0073] When performing the encryption operation, the encryption execution module includes:

[0074] For data with a small amount and high real-time requirements, stream encryption is used for encryption;

[0075] For data with a large amount, block encryption is used, and the data is divided into blocks and encrypted sequentially.

[0076] Specifically, stream encryption meets the requirements of real-time scenarios, ensuring timely encrypted transmission of data without affecting business real-time performance. Block encryption is suitable for processing large amounts of data. The block operation can utilize the system's parallel computing ability to accelerate the encryption speed. At the same time, the security of the block encryption algorithm guarantees the privacy of large amounts of data. Reasonably selecting the encryption method according to the data characteristics improves the processing ability of the encryption system for different data types and the overall performance.

[0077] When monitoring the encryption effect, the encryption effect feedback module includes:

[0078] Detect whether the encrypted data is illegally accessed, which is achieved by setting up access logs and an anomaly detection mechanism;

[0079] Evaluate three performance metrics of the encrypted data, namely data transmission delay, storage space occupancy, and encryption / decryption operation time consumption, and compare them with the corresponding preset performance thresholds respectively.

[0080] Specifically, timely detection of illegal access can effectively prevent data leakage. Monitoring of performance metrics can evaluate the impact of encryption operations on system performance. If the performance metrics exceed the thresholds, the encryption strategy can be adjusted in a timely manner, such as replacing the encryption algorithm or optimizing key management, to ensure a balance between the security and performance of the encryption system and improve the overall stability and reliability of the system.

[0081] The system also includes an encryption policy update module, which is used for:

[0082] According to the feedback information provided by the encryption effect feedback module and combined with the real-time operating conditions of the system, adjust the parameters of the risk assessment module and the mapping relationship table of the encryption algorithm selection module;

[0083] Regularly update the encryption algorithm library, introduce new encryption algorithms or eliminate insecure algorithms.

[0084] Specifically, the encryption policy update module works based on the information from the encryption effect feedback module and the real-time operating conditions of the system. According to the feedback information and real-time operating conditions, adjust the parameters of the risk assessment module to optimize the training and prediction effects of the convolutional neural network model. At the same time, update the mapping relationship table of the encryption algorithm selection module to make it adapt to the new risk assessment results and encryption requirements. Regularly pay attention to the research results and security vulnerability reports in the field of encryption algorithms, conduct security and performance tests on new algorithms, add those that meet the requirements to the algorithm library, and eliminate algorithms with security vulnerabilities. Continuous update of the encryption policy ensures that the encryption system keeps up with the development trend of security technologies. Dynamically adjust risk assessment and encryption algorithm selection so that the system can adapt to the changing security environment. Regularly update the algorithm library, introduce new algorithms to enhance the encryption ability, and eliminate insecure algorithms to reduce security risks, comprehensively ensuring the security, effectiveness, and adaptability of the encryption system.

[0085] When the encryption policy update module adjusts the parameters of the risk assessment module, the following algorithm is adopted:

[0086]

[0087] where θ new is the updated parameter, θ old is the old parameter, α is the learning rate, is the gradient of the loss function with respect to the old parameter.

[0088] Specifically, when adjusting the parameters of the risk assessment module, the encryption strategy update module uses an optimization algorithm to calculate the error between the encryption effect feedback data and the risk assessment model prediction results. According to the optimization algorithm principle, the parameter adjustment direction and step size are determined, and the parameters of the risk assessment module are continuously updated iteratively to make the model prediction results closer to the actual security risk situation. The use of the optimization algorithm improves the adaptability and accuracy of the risk assessment module.

[0089] When the encryption policy update module updates the encryption algorithm library, it includes:

[0090] Collect the latest encryption algorithm research results and security vulnerability reports;

[0091] Conduct security and performance tests on new algorithms, and add algorithms that meet the requirements to the encryption algorithm library;

[0092] Algorithms with security vulnerabilities are removed from the encryption algorithm library, and related modules are notified to make adjustments.

[0093] Specifically, new algorithms should be introduced in a timely manner to utilize cutting-edge encryption technology to enhance data protection capabilities; algorithms with vulnerabilities should be eliminated in a timely manner to prevent security risks. The high quality of the encryption algorithm library should be maintained to ensure that the encryption system maintains strong security protection capabilities in the ever-changing network security environment, providing solid protection for data security.

[0094] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments, and the above embodiments and descriptions only describe the principles of the present invention. The present invention may be subject to various changes and improvements without departing from the spirit and scope of the present invention, and these changes and improvements fall within the scope of the present invention claimed.

Claims

1. An adaptive encryption system based on AI intelligent security management, characterized in that, The system includes a data acquisition module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module, and an encryption effect feedback module, where: The data acquisition module is used to collect various types of data in the system operating environment, including but not limited to network traffic data, device status data, and user behavior data; The risk assessment module analyzes the collected data based on an AI algorithm to evaluate the security risk level faced by the current system. The AI algorithm uses a convolutional neural network model for deep learning; The encryption algorithm selection module selects an appropriate encryption algorithm from a preset encryption algorithm library according to the risk level output by the risk assessment module. The encryption algorithm library contains a variety of mainstream algorithms; The key generation and management module generates a corresponding encryption key according to the selected encryption algorithm and securely manages the key, including key storage, update, and distribution; The encryption execution module uses the selected encryption algorithm and the generated key to perform encryption operations on the data to be protected; The encryption effect feedback module monitors the security of the encrypted data in real time and feeds back the encryption effect to the risk assessment module for adjusting subsequent encryption strategies.

2. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, The formula for the convolutional neural network model of the risk assessment module is: Y = f(WX + b) where Y is the risk assessment result, X is the input data, W is the weight matrix, b is the bias vector, and f is the activation function.

3. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, When the data acquisition module collects data, it includes: Obtaining network traffic data through a network traffic monitoring tool and analyzing information such as the size, flow direction, and protocol type of the traffic; Communicating with the device management system to collect the operating status data of the device, including device load, temperature, and memory usage; Using user behavior monitoring software to record the operation behavior of users in the system, including login time, operation frequency, and accessed resources.

4. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, When the encryption algorithm selection module selects an encryption algorithm, the specific steps are as follows: Establish a mapping relationship table between the risk level and the encryption algorithm strength; According to the risk level output by the risk assessment module, query the mapping relationship table to determine the appropriate encryption algorithm; If the risk level is in the fuzzy interval between two adjacent levels, then comprehensively consider factors such as system performance and data importance, and determine the encryption algorithm through weighted calculation.

5. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, When the key generation and management module generates a key, it adopts the following method: For symmetric encryption algorithms, use a pseudo-random number generator to generate a key of a specified length; For asymmetric encryption algorithms, generate a public key and private key pair based on the elliptic curve cryptosystem.

6. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, When the encryption execution module performs encryption operations, it includes: For data with a small amount and high real-time requirements, use stream encryption for encryption; For data with a large amount, use block encryption, and encrypt the data in blocks sequentially.

7. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, When the encryption effect feedback module monitors the encryption effect, it includes: Detect whether the encrypted data is illegally accessed, which is achieved by setting access logs and an anomaly detection mechanism; Evaluate three performance indicators of the encrypted data, namely data transmission delay, storage space occupancy, and encryption and decryption operation time consumption, and compare them with the corresponding preset performance thresholds respectively.

8. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, The system further includes an encryption policy update module, and the encryption policy update module is configured to: According to the feedback information provided by the encryption effect feedback module, and in combination with the real-time operation status of the system, adjust the parameters of the risk assessment module and the mapping relationship table of the encryption algorithm selection module; Regularly update the encryption algorithm library, introduce new encryption algorithms or eliminate insecure algorithms.

9. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, When the encryption policy update module adjusts the parameters of the risk assessment module, the following algorithm is adopted: Among them, θ new is the updated parameter, θ old is the old parameter, α is the learning rate, is the gradient of the loss function with respect to the old parameter.

10. An adaptive encryption system based on AI intelligent security management according to claim 1, characterized in that, When the encryption policy update module updates the encryption algorithm library, it includes: Collect the latest research results of encryption algorithms and security vulnerability reports; Conduct security and performance tests on the new algorithms, and add the algorithms that meet the requirements to the encryption algorithm library; For algorithms with security vulnerabilities, remove them from the encryption algorithm library and notify the relevant modules for adjustment.

Citation Information

Cited By

  • Data security encryption method and system based on high-security machine learning

    CN120632920A

  • A data security encryption method and system based on high-security machine learning

    CN120632920B

  • AI-driven transport layer security protocol adaptive optimization system

    CN121012670A

  • Ai-driven transport layer security protocol adaptive optimization system

    CN121012670B

  • API security verification method and system based on dynamic algorithm pool and intelligent scheduling

    CN121770907A